A distributed quantum network management system

By using a distributed quantum network management system, data is transmitted with end-to-end encryption through key identification codes and encryption mechanisms. This solves the scalability and security issues of centralized architectures and enables high-performance, flexible, and highly available quantum network management.

CN119766550BActive Publication Date: 2025-10-31CHINA TELECOM QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411954668.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-10-31
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Existing quantum network management systems mostly adopt a centralized architecture, which has poor scalability and flexibility, and insufficient security for data transmission between devices.

Method used

A distributed quantum network management system is adopted. Data acquisition requests and responses are encrypted through key identification codes between the network management center and the proxy server. The encryption key is negotiated between the encryption machine and the security server to ensure that the data is transmitted in encrypted form throughout the process. Device data acquisition and monitoring are realized through a unified northbound interface.

Benefits of technology

It achieves high performance, flexible scalability, and high availability between systems and devices, ensures the security of data transmission, and enables monitoring and maintenance of quantum networks, guaranteeing system stability and compatibility with various devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766550B_ABST
    Figure CN119766550B_ABST
Patent Text Reader

Abstract

This invention provides a distributed quantum network management system, comprising: a network management center, a proxy server, and devices; the network management center, configured to send a data acquisition request to the proxy server based on a first key identification code corresponding to the network management center and a second key identification code corresponding to the proxy server; the data acquisition request carries a first encrypted ciphertext and a second key identification code, wherein the first encrypted ciphertext is obtained by encrypting a data acquisition signal using the first key identification code, and the data acquisition signal is used to indicate the acquisition of device data of the target device; the proxy server, configured to decrypt the first encrypted ciphertext based on the second key identification code to obtain the data acquisition signal; acquire device data of the target device; encrypt the device data to obtain a second encrypted ciphertext, and send it to the network management center; the network management center, configured to further decrypt the second encrypted ciphertext to obtain the device data of the target device, thereby achieving data transmission security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure communication technology, and in particular to a distributed quantum network management system. Background Technology

[0002] With the development of the internet, critical data concerning personal privacy, business information, and national security is constantly carried on massive and diverse modern communication networks. Ensuring network information security is in the interests of individuals, businesses, nations, and the global community. With the continuous development of quantum communication and the application of quantum key distribution technology, the scale and service scope of quantum networks are constantly expanding. To ensure secure compatibility with multiple connected devices, network management systems are deployed in quantum networks. Most existing network management systems use traditional centralized architectures, which suffer from poor scalability and flexibility, low availability, and insufficient security for data transmission between devices. Summary of the Invention

[0003] To address the aforementioned problems, this invention discloses a distributed quantum network management system.

[0004] In a first aspect, embodiments of the present invention provide a distributed quantum network management system, the system comprising: a network management center, a proxy server, and devices;

[0005] The network management center is used to obtain a first key identification code corresponding to the network management center and a second key identification code corresponding to the proxy server; and to send a data acquisition request to the proxy server according to the first key identification code and the second key identification code; the data acquisition request carries a first encrypted ciphertext and the second key identification code, wherein the first encrypted ciphertext is obtained by encrypting the data acquisition signal with the first key identification code, and the data acquisition signal is used to indicate the acquisition of device data of the target device;

[0006] The proxy server is configured to receive the data collection request sent by the network management center; decrypt the first encrypted ciphertext according to the second key identification code to obtain the data collection signal; collect device data of the target device according to the data collection signal; encrypt the device data of the target device to obtain the second encrypted ciphertext; and send the second encrypted ciphertext to the network management center.

[0007] The network management center is also used to receive the second encrypted ciphertext sent by the proxy server; and to decrypt the second encrypted ciphertext to obtain the device data of the target device.

[0008] Optionally, it further includes: a first encryption machine, a first security server, a second encryption machine, and a second security server; the first encryption machine and the first security server are associated with the network management center, and the second encryption machine and the second security server are associated with the proxy server;

[0009] The network management center is also used to send an encryption key acquisition request to the first security server;

[0010] The first security server is configured to negotiate an encryption key with the second security server based on the encryption key acquisition request sent by the network management center; and send the encryption key to the first encryption machine.

[0011] The second security server is used to negotiate an encryption key with the first security server and send the encryption key to the second encryption machine.

[0012] The first encryption machine is used to generate the first key identification code corresponding to the network management center based on the first identifier corresponding to the network management center; and send the first key identification code to the first security server.

[0013] The second encryption machine is used to generate a second key identification code corresponding to the proxy server based on the second identifier corresponding to the proxy server; and send the second key identification code to the second security server so that the second security server sends the second key identification code to the first security server.

[0014] The first security server is also used to send the first key identification code and the second key identification code to the network management center.

[0015] Optionally, the network management center is configured to: obtain the first key identification code and the second key identification code sent by the first security server; send a first encryption request carrying the data acquisition signal to the first encryption machine; obtain the first encrypted ciphertext generated by the first encryption machine based on the first key identification code; and send the data acquisition request carrying the first encrypted ciphertext and the second key identification code to the proxy server.

[0016] The proxy server is configured to: receive the data acquisition request sent by the network management center; send a first decryption request carrying the first encrypted ciphertext to the second encryption machine; obtain the data acquisition signal decrypted by the second encryption machine according to the second key identification code; acquire device data of the target device according to the data acquisition signal; send a second encryption request carrying the device data of the target device to the second encryption machine; obtain the second encrypted ciphertext generated by the second encryption machine according to the second encryption request; and send the second encrypted ciphertext to the network management center.

[0017] The network management center is used to receive the second encrypted ciphertext sent by the proxy server; send a second decryption request carrying the second encrypted ciphertext to the first encryption machine; and obtain the device data of the target device obtained by the first encryption machine after decryption.

[0018] Optionally, the proxy server includes multiple proxy servers, and the network management center deploys multiple proxy controllers; each proxy controller corresponds to one proxy server.

[0019] The proxy controller is configured to receive the data collection request sent by the network management center according to a preset association relationship, wherein the preset association relationship is used to indicate the proxy controller corresponding to the target device; send the data collection request to the corresponding proxy server; receive the device data of the target device returned by the proxy server according to the data collection request; and send the device data of the target device to the network management center.

[0020] Optionally, the proxy server is deployed with a northbound interface; the proxy server includes a first mode and a second mode;

[0021] The proxy server is used to collect device data of the target device by calling the northbound interface according to the data acquisition signal in the first mode; and to send the device data of the target device to the network management center by calling the northbound interface in the second mode.

[0022] Optionally, the northbound interface corresponding to the first mode includes at least one of the following: a basic information collection interface, a performance information collection interface, a service information collection interface, a log information collection interface, and a configuration distribution interface.

[0023] The proxy server is configured to: invoke the basic information acquisition interface to acquire the preset hardware data of the target device when the data acquisition signal indicates that the target device's preset hardware data is to be acquired; and / or invoke the performance information acquisition interface to acquire the software performance data of the target device when the data acquisition signal indicates that the target device's software performance data is to be acquired; and / or invoke the service information acquisition interface to acquire the communication transmission data of the target device when the data acquisition signal indicates that the target device's communication transmission data is to be acquired; and / or invoke the log information acquisition interface to acquire the historical data of the target device when the data acquisition signal indicates that the target device's historical data is to be acquired; and / or invoke the configuration distribution interface to acquire the configuration information data of the target device when the data acquisition signal indicates that the target device's configuration information data is to be acquired.

[0024] Optionally, the northbound interface corresponding to the second mode includes: an alarm information reporting interface;

[0025] The proxy server is used to call the alarm information reporting interface to send the alarm information of the target device to the network management center.

[0026] Optionally, the proxy server is further configured to collect network data of the quantum network where the device is located according to a preset period; call the northbound interface to send the network data to the network management center; the network data includes at least one of the following: encryption key generation amount, encryption key consumption amount, real-time key generation rate, original key generation rate, average key generation rate, ground state misjudgment rate, bit error rate, quantum bit state, entanglement quality, quantum channel decay, network throughput, and network latency.

[0027] Optionally, the network management center is further configured to receive the network data sent by the proxy server; output alarm information when the network data reaches a first preset condition; and adjust the quantum network according to a preset strategy when the network data reaches a second preset condition.

[0028] Optionally, the network management center further includes a data management module and a data storage module;

[0029] The data management module is used to classify the device data of the target device and display the device data of the target device.

[0030] The data storage module is used to store the device data of the target device.

[0031] The embodiments of the present invention have the following advantages:

[0032] The distributed quantum network management system of this invention includes: a network management center, a proxy server, and devices. The distributed architecture system features high performance, flexible scalability, and high availability. The network management center sends a data acquisition request to the proxy server based on a first key identification code corresponding to the network management center and a second key identification code corresponding to the proxy server. The data acquisition request carries a first encrypted ciphertext and a second key identification code. The first encrypted ciphertext is obtained by encrypting the data acquisition signal using the first key identification code. The data acquisition signal is used to indicate the acquisition of device data from the target device. The proxy server decrypts the first encrypted ciphertext based on the second key identification code to obtain the data acquisition signal; acquires the device data from the target device; encrypts the device data to obtain a second encrypted ciphertext, and sends it to the network management center. The network management center also decrypts the second encrypted ciphertext to obtain the device data from the target device, thus achieving end-to-end encryption during signal and data transmission, ensuring the security of data transmission between the system and devices. Simultaneously, this invention can also monitor and maintain the quantum network to ensure system stability. Furthermore, this invention can set a unified northbound interface based on the distributed quantum network management system, thereby flexibly expanding the access area subnet and being compatible with various devices. Attached Figure Description

[0033] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0034] Figure 1 This is a structural block diagram of a distributed quantum network management system according to an embodiment of the present invention;

[0035] Figure 2 This is a structural block diagram of another distributed quantum network management system according to an embodiment of the present invention;

[0036] Figure 3 This is a logic diagram of a distributed quantum network management system according to an embodiment of the present invention;

[0037] Figure 4 This is a structural block diagram of another distributed quantum network management system according to an embodiment of the present invention.

[0038] Explanation of reference numerals in the attached figures:

[0039] Network management center 11, proxy server 12, device 13, proxy controller 21, first encryption machine 31, first security server 32, second encryption machine 33, second security server 34, data management module 41, data storage module 42. Detailed Implementation

[0040] This invention proposes a distributed quantum network management system aimed at improving the security of data transmission between the system and devices. To achieve this goal, embodiments of this invention encrypt the data acquisition signals from the network management center and the device data collected by the proxy server, thereby ensuring the security of data transmission within a distributed quantum network management system.

[0041] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0042] Reference Figure 1 The diagram illustrates a structural block diagram of a distributed quantum network management system according to an embodiment of the present invention. The system includes: a network management center 11, a proxy server 12, and a device 13.

[0043] The network management center 11 is used to obtain the first key identification code corresponding to the network management center 11 and the second key identification code corresponding to the proxy server 12; and to send a data acquisition request to the proxy server 12 according to the first key identification code and the second key identification code; the data acquisition request carries a first encrypted ciphertext and the second key identification code, wherein the first encrypted ciphertext is obtained by encrypting the data acquisition signal with the first key identification code, and the data acquisition signal is used to indicate the acquisition of device data of the target device 13;

[0044] The proxy server 12 is used to receive the data collection request sent by the network management center 1; decrypt the first encrypted ciphertext according to the second key identification code to obtain the data collection signal; collect the device data of the target device 13 according to the data collection signal; encrypt the device data of the target device 13 to obtain the second encrypted ciphertext; and send the second encrypted ciphertext to the network management center 11.

[0045] The network management center 11 is also used to receive the second encrypted ciphertext sent by the proxy server 12; and to decrypt the second encrypted ciphertext to obtain the device data of the target device 13.

[0046] In this embodiment of the invention, the distributed quantum network management system includes a network management center, proxy servers, and devices, featuring high performance, flexible scalability, and high availability. The network management center can send a data acquisition request to the proxy server based on a first key identification code corresponding to the network management center and a second key identification code corresponding to the proxy server. The data acquisition request carries a first encrypted ciphertext and a second key identification code, wherein the first encrypted ciphertext is obtained by encrypting the data acquisition signal using the first key identification code, and the data acquisition signal is used to indicate the acquisition of device data from the target device. The proxy server can decrypt the first encrypted ciphertext based on the second key identification code to obtain the data acquisition signal, acquire the device data of the target device according to the indication of the data acquisition signal, then encrypt the device data to obtain the second encrypted ciphertext, and return the second encrypted ciphertext to the network management center so that the network management center can decrypt the second encrypted ciphertext to obtain the device data of the target device. This embodiment of the invention encrypts the signal and data transmission process throughout, thereby achieving the security of data transmission between the system and devices.

[0047] Reference Figure 2 This diagram illustrates a structural block diagram of another distributed quantum network management system according to an embodiment of the present invention. The proxy server 12 includes multiple proxy servers, and the network management center 11 is deployed with multiple proxy controllers 21. Each proxy controller 21 corresponds to one of the proxy servers 12.

[0048] The proxy controller 21 is configured to receive the data collection request sent by the network management center 11 according to a preset association relationship, wherein the preset association relationship is used to indicate the proxy controller 21 corresponding to the target device 13; send the data collection request to the corresponding proxy server 12; receive the device data of the target device 13 returned by the proxy server 12 according to the data collection request; and send the device data of the target device 13 to the network management center 11.

[0049] In this embodiment of the invention, the network management center deploys multiple proxy controllers, each corresponding one-to-one with a proxy server. The devices may include quantum devices, cryptographic devices, and classical devices. The proxy servers may include a quantum key distribution server (QKDNC), a cryptographic management server (KMS), and a classical layer signal transmission server (CLS). The preset association relationships are as follows: quantum devices are associated with the proxy controller corresponding to a quantum key distribution server, cryptographic devices are associated with the proxy controller corresponding to a cryptographic management server, and classical devices are associated with the proxy controller corresponding to a classical layer signal transmission server. The proxy controller can send data collection requests from the network management center to the proxy server corresponding to the target device, enabling the proxy server to collect device data from the target device according to the data collection request, and then filter and analyze the target device data before sending it to the network management center.

[0050] In one embodiment, the proxy server 12 is deployed with a northbound interface; the proxy server 12 includes a first mode and a second mode;

[0051] The proxy server 12 is used to collect device data of the target device 13 by calling the northbound interface according to the data acquisition signal in the first mode; and to send the device data of the target device 13 to the network management center 11 by calling the northbound interface in the second mode.

[0052] The northbound interface corresponding to the first mode includes at least one of the following: a basic information collection interface, a performance information collection interface, a service information collection interface, a log information collection interface, and a configuration distribution interface; the northbound interface corresponding to the second mode includes an alarm information reporting interface.

[0053] The proxy server 12 is configured to: call the basic information collection interface to collect the preset hardware data of the target device when the data collection signal indicates that the target device's preset hardware data is to be collected; and / or call the performance information collection interface to collect the software performance data of the target device when the data collection signal indicates that the target device's software performance data is to be collected; and / or call the service information collection interface to collect the communication transmission data of the target device when the data collection signal indicates that the target device's communication transmission data is to be collected; and / or call the log information collection interface to collect the historical data of the target device when the data collection signal indicates that the target device's historical data is to be collected; and / or call the configuration distribution interface to collect the configuration information data of the target device when the data collection signal indicates that the target device's configuration information data is to be collected.

[0054] The proxy server is used to call the alarm information reporting interface to send the alarm information of the target device to the network management center.

[0055] In this embodiment of the invention, the proxy server can securely access quantum devices, cryptographic devices, and classical devices through a unified northbound interface standard. The proxy server can define the northbound interface and design the specific protocol message structure and rules for the interface, setting a first mode and a second mode. In the first mode, i.e., when the pre-set data transmission rule is PULL mode, the proxy controller can call the northbound interface to collect device data from the target device based on the data acquisition signal. In the second mode, i.e., when the pre-set data transmission rule is PUSH mode, the proxy controller can obtain the device data pushed by the proxy server to the message middleware.

[0056] The northbound interfaces can include: basic information collection interfaces, performance information collection interfaces, business information collection interfaces, log information collection interfaces, configuration distribution interfaces, alarm information reporting interfaces, etc. All northbound interfaces are designed based on RESTful (Representational State Transfer, a software architecture style).

[0057] For example, when the data transmission rule is PULL mode, and the data acquisition signal carries deviceId (the unique identifier of the target device) to indicate the collection of preset hardware data of the target device, the proxy server can call the basic information acquisition interface to collect the preset hardware data of the target device. The preset hardware data may include deviceId (the unique identifier of the device), deviceType (the device type), deviceArea (the region to which the device belongs), deviceName (the device name), deviceEquipment (the device manufacturer), deviceVersion (the device version), and macAddress (the MAC address).

[0058] When the data transmission rule is PULL mode, and the data acquisition signal carries deviceId (a unique identifier for the target device) to indicate the collection of software performance data of the target device, the proxy server can call the performance information acquisition interface to collect the software performance data of the target device. The software performance data may include deviceId (unique identifier for the device), deviceType (device type), cpuUse (CPU utilization), memoryUse (memory utilization), diskUse (disk utilization), bandwidth, temperature (device temperature), fanSpeed ​​(fan speed), deviceStatus (device status), and deviceRunningTime (device runtime).

[0059] When the data transmission rule is PULL mode, and the data acquisition signal carries deviceId (a unique identifier for the target device) to indicate the target device's communication transmission data to be acquired, the proxy server can call the business information acquisition interface to acquire the target device's communication transmission data. This communication transmission data may include deviceId (unique device identifier), deviceType (device type), syKeyEncryptionRate (symmetric key encryption rate), syKeyDecryptionRate (symmetric key decryption rate), productionMacRate (MAC generation rate), verifyingMacRate (MAC verification rate), hmacGenerationRate (HMAC generation rate), verifyHmacRate (HMAC verification rate), asyPubKeyEncryptionRate (asymmetric public key encryption rate), asyPrvKeyDecryptionRate (asymmetric private key decryption rate), and asyPrvKkeySi Asymmetric private key signing rate, asymmetric public key signing rate, secret key production, secret key consumption, current code formation rate, primitive code formation rate, average code formation rate, misjudgment rate, error rate, flow rate, qubit state, entMass, quantChannelAtt, netThroughput, netDelay, algorithm, operator;

[0060] When the data transmission rule is PULL mode, the data acquisition signal carries deviceId (unique identifier of the target device), logType (log type), startTime (log start time), endTime (log end time), pageNum (log page), and pageSize (log page size), indicating that historical data of the target device is being collected, the proxy server can call the log information collection interface to collect historical data of the target device. The historical data may include logContent (log content).

[0061] When the data transmission rule is PULL mode, the data acquisition signal carries deviceId (unique identifier of the target device), configType (configuration type), and configParam (configuration parameters) to indicate that the configuration information data of the target device is to be collected. The proxy server can call the configuration distribution interface to collect the configuration information data of the target device. The configuration information data may include configResult (configuration result).

[0062] When the data transmission rule is PUSH mode, the proxy server can call the alarm information reporting interface to send the alarm information of the target device to the network management center. The alarm information may include deviceId (unique device identifier), deviceType (device type), alarmLevel (alarm level), alarmType (alarm type), alarmTime (alarm time), alarmLocation (alarm location), alarmStatus (alarm status), alarmContent (alarm content), and alarmExt (extended information).

[0063] Reference Figure 3 The diagram illustrates a logical diagram of a distributed quantum network management system provided by an embodiment of the present invention. The system further includes: a first encryption machine 31, a first security server 32, a second encryption machine 33, and a second security server 34; the first encryption machine 31 and the first security server 32 are associated with the network management center 11, and the second encryption machine 33 and the second security server 34 are associated with the proxy server 12.

[0064] The network management center 11 is also used to send an encryption key acquisition request to the first security server 32;

[0065] The first security server 32 is used to negotiate an encryption key with the second security server 34 according to the encryption key acquisition request sent by the network management center 11; and send the encryption key to the first encryption machine 31.

[0066] The second security server 34 is used to negotiate an encryption key with the first security server 32 and send the encryption key to the second encryption machine 33.

[0067] The first encryption machine 31 is used to generate the first key identification code corresponding to the network management center 11 based on the first identifier corresponding to the network management center 11; and send the first key identification code to the first security server 32.

[0068] The second encryption machine 33 is used to generate the second key identification code corresponding to the proxy server 12 according to the second identifier corresponding to the proxy server 12; and send the second key identification code to the second security server 34, so that the second security server 34 sends the second key identification code to the first security server 32;

[0069] The first security server 32 is also used to send the first key identification code and the second key identification code to the network management center 11.

[0070] The network management center 11 is used to obtain the first key identification code and the second key identification code sent by the first security server 32; send a first encryption request carrying the data acquisition signal to the first encryption machine 31; obtain the first encrypted ciphertext generated by the first encryption machine 31 according to the first key identification code; and send the data acquisition request carrying the first encrypted ciphertext and the second key identification code to the proxy server 12.

[0071] The proxy server 12 is configured to: receive the data acquisition request sent by the network management center 11; send a first decryption request carrying the first encrypted ciphertext to the second encryption machine 33; obtain the data acquisition signal decrypted by the second encryption machine 33 according to the second key identification code; acquire the device data of the target device 13 according to the data acquisition signal; send a second encryption request carrying the device data of the target device 13 to the second encryption machine 33; obtain the second encrypted ciphertext generated by the second encryption machine 33 according to the second encryption request; and send the second encrypted ciphertext to the network management center 11.

[0072] The network management center 11 is used to receive the second encrypted ciphertext sent by the proxy server 12; send a second decryption request carrying the second encrypted ciphertext to the first encryption machine 31; and obtain the device data of the target device 13 obtained by the first encryption machine 31 through decryption.

[0073] In embodiments of the present invention, such as Figure 3 As shown, the specific process of data transmission encryption in the distributed quantum network management system is as follows:

[0074] (1) The network management center sends an encryption key acquisition request to the first security server to establish a secure communication channel between the network management center and the proxy server;

[0075] (2) The first security server negotiates with the second security server to obtain the encryption key based on the encryption key acquisition request;

[0076] (3) The first security server sends the encryption key to the first encryption machine;

[0077] (4) The second security server sends the encryption key to the second encryption machine;

[0078] (5) The first encryption machine generates a first key identification code corresponding to the network management center based on the first identifier corresponding to the network management center; and sends the first key identification code to the first security server.

[0079] (6) The second encryption machine generates a second key identification code corresponding to the proxy server based on the second identifier corresponding to the proxy server; and sends the second key identification code to the second security server.

[0080] (7) The second security server sends the second key identification code to the first security server;

[0081] (8) The first security server sends the first key identification code and the second key identification code to the network management center;

[0082] (9) The network management center obtains the first key identification code and the second key identification code sent by the first security server; and sends a first encryption request carrying a data acquisition signal to the first encryption machine.

[0083] (10) The first encryption machine generates the first encrypted ciphertext based on the first key identification code and sends the first encrypted ciphertext to the network management center;

[0084] (11) The network management center sends a data collection request carrying the first encrypted ciphertext and the second key identification code to the proxy server.

[0085] (12) The proxy server receives the data collection request sent by the network management center; and sends the first decryption request carrying the first encrypted ciphertext to the second encryption machine;

[0086] (13) The second encryption machine decrypts the data acquisition signal according to the second key identification code and sends the data acquisition signal to the proxy server;

[0087] (14) The proxy server collects the device data of the target device according to the data collection signal; and sends a second encryption request carrying the device data of the target device to the second encryption machine;

[0088] (15) The second encryption machine generates the second encrypted ciphertext according to the second encryption request and sends the second encrypted ciphertext to the proxy server;

[0089] (16) The proxy server sends the second encrypted ciphertext to the network management center;

[0090] (17) The network management center receives the second encrypted ciphertext sent by the proxy server; and sends a second decryption request carrying the second encrypted ciphertext to the first encryption machine;

[0091] (18) The first encryption machine decrypts the target device’s device data and sends the target device’s device data to the network management center.

[0092] This invention employs an independent security server and cryptographic machine to negotiate encryption keys, and uses the encryption keys to encrypt the data acquisition signals from the network management center and the device data collected by the proxy server, thereby ensuring the security of data transmission in a distributed quantum network management system.

[0093] In one embodiment, the proxy server is further configured to collect network data of the quantum network where the device is located according to a preset period; call the northbound interface to send the network data to the network management center; the network data includes at least one of the following: encryption key generation amount, encryption key consumption amount, real-time key generation rate, original key generation rate, average key generation rate, ground state misjudgment rate, bit error rate, quantum bit state, entanglement quality, quantum channel decay, network throughput, and network latency.

[0094] The network management center is also used to receive the network data sent by the proxy server; output alarm information when the network data reaches a first preset condition; and adjust the quantum network according to a preset strategy when the network data reaches a second preset condition.

[0095] In this embodiment of the invention, the proxy server can collect network data from the quantum network where the device is located according to a preset period. After the proxy controller performs data cleaning, normalization, standardization, inheritance and aggregation, and calculation on the network data, the network data is sent to the network management center. The preset period can be flexibly set according to the data update frequency. For example, the preset period can be set shorter for data with a high update frequency and longer for data with a low update frequency. Data collection with an update frequency greater than 24 hours can be scheduled at night. The network data may include: encryption key generation amount, encryption key consumption amount, real-time key generation rate, original key generation rate, average key generation rate, ground state misjudgment rate, bit error rate, quantum bit state, entanglement quality, quantum channel decay, network throughput, network latency, etc.

[0096] The network management center can output alarm information when network data reaches a first preset condition; and adjust the quantum network according to a preset strategy when network data reaches a second preset condition. Specifically, the network management center can automatically generate alarms when network data reaches the first preset condition, such as via email, SMS, or instant messaging tools, and perform alarm record analysis and post-event tracking. Simultaneously, it can automatically adjust the quantum network's channel parameters or restart the device when network data reaches the second preset condition to locate and recover from faults. The first preset condition can be abnormal network data and data transmission failure, while the second preset condition can be abnormal network data and normal data transmission.

[0097] Reference Figure 4 This diagram illustrates a structural block diagram of another distributed quantum network management system provided by an embodiment of the present invention. The network management center 11 further includes a data management module 41 and a data storage module 42.

[0098] The data management module 41 is used to classify the device data of the target device 13 and display the device data of the target device 13.

[0099] The data storage module 42 is used to store the device data of the target device 13.

[0100] In this embodiment of the invention, the data management module may include a homepage dashboard unit, a resource management unit, a network topology management unit, a configuration management unit, an alarm management unit, a performance management unit, a security management unit, and a system management unit. The homepage dashboard unit displays the quantum network link distribution, performance data trends of managed devices, and an overview of alarms for managed devices. The resource management unit manages proxy controller resources, device resources, subnet resources, and acquisition and control proxy server resources. The proxy servers include a quantum key distribution server, a cryptographic management server, and a classical layer signal transmission server. The network topology management unit displays device topology diagrams and performs automatic topology discovery. The configuration management unit allows viewing and editing of important configurations for managed devices. The alarm management unit allows viewing, processing, and statistical analysis of device alarm records. The performance management unit displays, queries, edits, performs statistical analysis, and intelligently and automatically adjusts device performance in real time. The security management unit performs system threat detection and defense, periodic system vulnerability scanning and assessment, and disaster recovery and backup. The system management unit manages users, roles, tenants, menus, and dictionaries.

[0101] The data storage module may include a device information data unit, a device system performance data unit, a device service performance data unit, an alarm data unit, and a log data unit. Specifically, the device information data unit is used for unified storage of basic information data for quantum, cryptographic, and classical devices. The device system performance data unit is used for unified storage of system performance data for quantum, cryptographic, and classical devices. The device service performance data unit is used for unified storage of service performance data for quantum, cryptographic, and classical devices. The alarm data unit is used for unified storage of alarm data for quantum, cryptographic, and classical devices. The log data unit is used for unified storage of log data for quantum, cryptographic, and classical devices.

[0102] The distributed quantum network management system of this invention includes a network management center, proxy servers, and devices. Multiple proxy servers are included, and the network management center deploys multiple proxy controllers. Each proxy controller corresponds one-to-one with a proxy server, featuring high performance, flexible scalability, and high availability. Encryption key negotiation is performed through an independent security server and cryptographic machine. The encryption key is used to encrypt the data acquisition signals from the network management center and the device data collected by the proxy servers, thereby ensuring data transmission security within the distributed quantum network management system. Simultaneously, this invention can also monitor and maintain the quantum network to ensure system stability. Furthermore, this invention can set a unified northbound interface based on the distributed quantum network management system, thereby flexibly expanding access area subnets and ensuring compatibility with various devices.

[0103] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0104] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products embodied on one or more machine-readable media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0105] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0106] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0108] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0109] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0110] The above provides a detailed description of the distributed quantum network management system provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A distributed quantum network management system, characterized in that, include: Network management center, proxy servers and equipment; The network management center is used to obtain a first key identification code corresponding to the network management center and a second key identification code corresponding to the proxy server; and to send a data acquisition request to the proxy server according to the first key identification code and the second key identification code; the data acquisition request carries a first encrypted ciphertext and the second key identification code, wherein the first encrypted ciphertext is obtained by encrypting the data acquisition signal with the first key identification code, and the data acquisition signal is used to indicate the acquisition of device data of the target device; The proxy server is used to receive the data collection request sent by the network management center; and to decrypt the first encrypted ciphertext according to the second key identification code to obtain the data collection signal. Based on the data acquisition signal, collect device data of the target device; encrypt the device data of the target device to obtain a second encrypted ciphertext; send the second encrypted ciphertext to the network management center; The network management center is also used to receive the second encrypted ciphertext sent by the proxy server; Decrypt the second encrypted ciphertext to obtain the device data of the target device; It also includes: a first encryption machine, a first security server, a second encryption machine, and a second security server; the first encryption machine and the first security server are associated with the network management center, and the second encryption machine and the second security server are associated with the proxy server; The network management center is also used to send an encryption key acquisition request to the first security server; The first security server is configured to negotiate an encryption key with the second security server based on the encryption key acquisition request sent by the network management center; and send the encryption key to the first encryption machine. The second security server is used to negotiate an encryption key with the first security server and send the encryption key to the second encryption machine. The first encryption machine is used to generate the first key identification code corresponding to the network management center based on the first identifier corresponding to the network management center; and send the first key identification code to the first security server. The second encryption machine is used to generate a second key identification code corresponding to the proxy server based on the second identifier corresponding to the proxy server; and send the second key identification code to the second security server so that the second security server sends the second key identification code to the first security server. The first security server is also used to send the first key identification code and the second key identification code to the network management center.

2. The system according to claim 1, characterized in that, The network management center is configured to: acquire the first key identification code and the second key identification code sent by the first security server; send a first encryption request carrying the data acquisition signal to the first encryption machine; acquire the first encrypted ciphertext generated by the first encryption machine based on the first key identification code; and send the data acquisition request carrying the first encrypted ciphertext and the second key identification code to the proxy server. The proxy server is used to receive the data collection request sent by the network management center; Send a first decryption request carrying the first encrypted ciphertext to the second encryption machine; obtain the data acquisition signal obtained by the second encryption machine from decryption based on the second key identification code; and acquire device data of the target device based on the data acquisition signal. Send a second encryption request carrying the device data of the target device to the second encryption machine; Obtain the second encrypted ciphertext generated by the second encryption machine according to the second encryption request; The second encrypted ciphertext is sent to the network management center; The network management center is used to receive the second encrypted ciphertext sent by the proxy server; send a second decryption request carrying the second encrypted ciphertext to the first encryption machine; and obtain the device data of the target device obtained by the first encryption machine after decryption.

3. The system according to claim 1, characterized in that, The proxy server includes multiple instances, and the network management center deploys multiple proxy controllers; each proxy controller corresponds to one proxy server. The proxy controller is used to receive the data collection request sent by the network management center according to a preset association relationship, wherein the preset association relationship is used to indicate the proxy controller corresponding to the target device; The data collection request is sent to the corresponding proxy server; Receive device data of the target device returned by the proxy server according to the data collection request; send the device data of the target device to the network management center.

4. The system according to claim 1, characterized in that, The proxy server is equipped with a northbound interface; the proxy server includes a first mode and a second mode. The proxy server is used to collect device data of the target device by calling the northbound interface according to the data acquisition signal in the first mode; and to send the device data of the target device to the network management center by calling the northbound interface in the second mode.

5. The system according to claim 4, characterized in that, The northbound interface corresponding to the first mode includes at least one of the following: a basic information collection interface, a performance information collection interface, a business information collection interface, a log information collection interface, and a configuration distribution interface. The proxy server is configured to: invoke the basic information acquisition interface to acquire the preset hardware data of the target device when the data acquisition signal indicates that the target device's preset hardware data is to be acquired; and / or invoke the performance information acquisition interface to acquire the software performance data of the target device when the data acquisition signal indicates that the target device's software performance data is to be acquired; and / or invoke the service information acquisition interface to acquire the communication transmission data of the target device when the data acquisition signal indicates that the target device's communication transmission data is to be acquired; and / or invoke the log information acquisition interface to acquire the historical data of the target device when the data acquisition signal indicates that the target device's historical data is to be acquired; and / or invoke the configuration distribution interface to acquire the configuration information data of the target device when the data acquisition signal indicates that the target device's configuration information data is to be acquired.

6. The system according to claim 4, characterized in that, The northbound interface corresponding to the second mode includes: an alarm information reporting interface; The proxy server is used to call the alarm information reporting interface to send the alarm information of the target device to the network management center.

7. The system according to claim 4, characterized in that, The proxy server is also used to collect network data of the quantum network where the device is located according to a preset period; call the northbound interface to send the network data to the network management center; the network data includes at least one of the following: encryption key generation amount, encryption key consumption amount, real-time key generation rate, original key generation rate, average key generation rate, ground state misjudgment rate, bit error rate, quantum bit state, entanglement quality, quantum channel decay, network throughput, and network latency.

8. The system according to claim 7, characterized in that, The network management center is also used to receive the network data sent by the proxy server; output alarm information when the network data reaches a first preset condition; and adjust the quantum network according to a preset strategy when the network data reaches a second preset condition.

9. The system according to claim 1, characterized in that, The network management center also includes a data management module and a data storage module; The data management module is used to classify the device data of the target device and display the device data of the target device. The data storage module is used to store the device data of the target device.

Citation Information

Patent Citations

  • Method employing quantum secret key for IOT (Internet of Things) data encryption transmission

    CN104821874A

  • Quantum device management system

    CN113852503A