Optical service unit physical layer encryption system
By adopting an optical service unit physical layer encryption system based on real-time optical signal time domain scrambling and decoy state quantum key distribution in the M-OTN network, the problem of lack of effective QKD implementation in the M-OTN network in the communication rate range of 2Mbps to 10Gbps is solved, and the network is high security and reliability are achieved.
Patent Information
- Application Number
- CN202510294215.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-13
AI Technical Summary
The existing M-OTN network lacks an effective quantum key distribution (QKD) implementation method in the communication rate range of 2Mbps to 10Gbps, and cannot effectively resist the descrambling attacks of quantum computers.
The optical service unit physical layer encryption system based on real-time optical signal time domain scrambling and decoupling quantum key distribution methods is adopted. The quantum random key is transmitted through the quantum channel, and the optical service unit optical signals are scrambled and descrambled at the transmitting and receiving ends. The decoupling BB84 protocol and polarization encoding method are used to realize key distribution.
It improves the security of the M-OTN network, protects communication data from descrambling attacks, realizes the end-to-end data transmission security of the optical physical layer of the M-OTN network, and enhances the security and reliability of the network.
Smart Images

Figure CN119995875A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to an optical service unit physical layer encryption system. Background Art
[0002] In China, China Telecom has proposed M-OTN based on optical service units (OSUs). By introducing flexibly mapped optical service units, it can provide flexible bearing for various types of government and enterprise services at different rates. It has now entered the stage of large-scale commercial deployment. A large amount of domestic data is transmitted and shared through the metropolitan optimized optical transmission network (M-OTN), accompanied by an explosive growth in network security attacks. Public key cryptography provides a security barrier for optical transmission networks, making it impossible for eavesdroppers to obtain valuable data. However, quantum computers make the "collect first and then decrypt" attack possible. Using quantum computers to record, store and calculate scrambled data can easily crack public key scrambling.
[0003] Quantum key distribution (QKD) technology, by transmitting a single photon between the two parties, enables the communicating parties to agree on the same shared key scrambling, detects whether a third party attempts to eavesdrop on the key negotiation protocol, and protects data from attacks by the powerful computing resources of quantum computers. Therefore, integrating QKD into M-OTN will protect communication data from descrambling attacks.
[0004] Currently, there is still no QKD implementation method that meets the 2Mbps to 10Gbps communication rate requirements of the already operational M-OTN network. Summary of the invention
[0005] The object of the present invention is to provide an optical service unit physical layer encryption system, which adopts a quantum key distribution method based on real-time optical signal time domain scrambling and decoy state to improve the security of the M-OTN network and protect communication data from descrambling attacks.
[0006] To achieve the above object, the present invention provides an optical service unit physical layer encryption system, including a transmitting end and a receiving end, the transmitting end and the receiving end are connected through a quantum channel and a classical channel respectively, wherein the quantum random key is transmitted through the quantum channel, and the conventional signal is transmitted through the classical channel, the devices in the transmitting end and the receiving end are arranged symmetrically, and the shared seed key is updated between the transmitting end and the receiving end, and only the transmitting and receiving ends know it;
[0007] The transmitting end includes a DS-QKD transmitter, a field programmable gate array, a scrambler, an erbium-doped fiber amplifier and a wavelength division multiplexer, and the receiving end also includes a field programmable gate array, an erbium-doped fiber amplifier and a wavelength division multiplexer. The corresponding different devices are a DS-QKD receiver and a descrambler.
[0008] The DS-QKD transmitter sends a quantum random key to the DS-QKD receiver through a quantum channel without transmitting any message data, and the random scrambler scrambles the optical service unit optical signal using a running key generated by a field programmable gate array.
[0009] Among them, the DS-QKD receiver receives quantum bits from the DS-QKD transmitter and generates a seed key through a protocol channel. The field programmable gate array in the DS-QKD transmitter generates a running key from the seed key and the synchronization mark. The descrambler uses the same running key generated from the same seed key to descramble the scrambled optical service unit optical signal.
[0010] The optical service unit adopts an optical channel payload unit division method based on payload blocks. For a given optical channel payload unit, each transmission cycle consists of P consecutive payload blocks, and the payload block size of each optical channel payload unit is 192 bytes.
[0011] The time domain scrambling of the optical signal of the optical service unit is realized by a fiber delay device and is scrambled by N cascaded fiber delay devices. Each fiber delay device has an independent temperature control module for adjusting the parameters of the cavity.
[0012] The optical service unit physical layer encryption system adopts a decoy state BB84 protocol with a polarization encoding method, and provides a seed key through a quantum channel and a protocol channel.
[0013] The present invention provides an optical service unit physical layer encryption system, including a transmitting end and a receiving end, wherein the transmitting end and the receiving end are connected via a quantum channel and a classical channel respectively, wherein a quantum random key is transmitted via the quantum channel, and a conventional signal is transmitted via a classical channel; specifically, the optical signal of the optical service unit is subjected to time domain scrambling processing, and a decoy state BB84 protocol and a polarization encoding method are used to implement key distribution to provide a seed key. In the case of real-time key update, secure end-to-end data transmission of the optical physical layer of the M-OTN network is achieved during the access side M-OTN network. The present invention makes unpredictable time domain scrambling an effective and flexible high-speed optical signal scrambling method, thereby enhancing the security and reliability of the M-OTN optical physical layer. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0015] Figure 1 It is a principle block diagram of an optical service unit physical layer encryption system of the present invention.
[0016] Figure 2 It is a schematic diagram of the OSU-based M-OTN network hierarchy structure of the present invention.
[0017] Figure 3 It is a schematic diagram of the OPU frame structure based on the payload block (PB) of the present invention.
[0018] Figure 4 4(a) is a schematic diagram of the principle block diagram of the OSU optical signal time domain scrambling / descrambling of the present invention, 4(a) is a TCM array; 4(b) is a single TCM.
[0019] Figure 5 It is a schematic diagram of the structure of an experimental device of the optical service unit physical layer encryption system in a specific embodiment of the present invention.
[0020] Figure 6 6(a) is the eye diagram of the experimental results of scrambling and descrambling of OSU optical signals in a specific embodiment of the present invention, 6(b) is before scrambling; 6(c) is after descrambling with mismatched keys; 6(d) is after descrambling with matched keys.
[0021] Figure 7 It is a schematic diagram of the bit error rate of the OSU received signal in a specific embodiment of the present invention. DETAILED DESCRIPTION
[0022] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.
[0023] The present invention provides an optical service unit physical layer encryption system, comprising a transmitting end and a receiving end, wherein the transmitting end and the receiving end are connected via a quantum channel and a classical channel respectively, wherein a quantum random key is transmitted via the quantum channel, and a conventional signal is transmitted via the classical channel, and the devices in the transmitting end and the receiving end are symmetrically arranged, and a shared seed key is updated between the transmitting end and the receiving end, and only the transmitting and receiving ends know it; the transmitting end comprises a DS-QKD transmitter, a field programmable gate array, a scrambler, an erbium-doped fiber amplifier and a wavelength division multiplexer, and the receiving end also comprises a field programmable gate array, an erbium-doped fiber amplifier and a wavelength division multiplexer, and the corresponding different devices are a DS-QKD receiver and a descrambler.
[0024] For specific framework principles, please refer to Figure 1, at the transmitter, the DS-QKD transmitter sends a quantum random key to the receiver through a quantum channel without transmitting any message data, and the random scrambler scrambles the optical service unit (OSU) optical signal using a running key generated by a field programmable gate array (FPGA). At the receiver, the DS-QKD receiver receives the quantum bits from the transmitter and generates a seed key through a protocol channel, and the descrambler descrambles the scrambled OSU optical signal using the same running key as the transmitter. By using the synchronization channel of the FPGA, symmetric scrambling and descrambling between the transmitter and the receiver are achieved. In fact, the messages in the protocol channel, synchronization channel, and data channel are all regular signals. Therefore, it can be multiplexed through a wavelength division multiplexer (WDM) and transmitted in a classical channel. Usually, at the beginning of the transmission, the quantum key is exchanged and stored between the DS-QKD transmitter and the receiver. The FPGA in the transmitter generates a running key from the seed key and the synchronization mark. The OSU optical signal input to the scrambler is scrambled by adjusting the physical parameters in real time through the running key. At the same time, a synchronization marker transmitted over the synchronization channel is used to synchronize the start of scrambling and descrambling signals. The receiving end demodulates the received signal using the same running key generated from the same seed key, which is triggered by the synchronization marker. This dynamic key approach enhances security because an eavesdropper not only needs to crack the ultra-high-speed scrambled signal, but also needs to find the key before the key is updated.
[0025] The following is a further explanation based on the M-OTN network hierarchy and OSU service mapping:
[0026] For packet services (PKT), flexible service slice adaptation and cross-connection are achieved through OSU (about 2.6Mbps) mapping and multiplexing. Figure 2 As shown in the figure, OSU is based on the extension of ITU-T G.709 technology. By abstracting a layer of container in the optical channel payload unit (OPU) payload, it can provide hard isolation, high security, low latency and elastic bandwidth transmission capabilities for services.
[0027] The ODU frame structure is decomposed into multiple payload blocks (PBs), and each OSU occupies one or more PB pairs. The OSU bit rate is related to the type of packet service transmitted. The client signal is first mapped to the OSU and then multiplexed into the OPU frame through the optical service tributary unit (OSTU) structure. The OSTU structure consists of C PB blocks in the transmission period of P consecutive OPU PB blocks. The maximum C value (in PB blocks) determines the maximum OSU bit rate for each specific client service. The maximum C value is calculated as follows:
[0028]
[0029] Where R client ,R client_tolerance ,R PB ,R PB_tolerance They represent the client bit rate, client bit rate tolerance, OSU PB reference bit rate and OSU PB reference bit rate tolerance (±20ppm) respectively. The OSU maximum bit rate is calculated as follows:
[0030] R OSU =C×R PB
[0031] The maximum payload bit rate of OSU is calculated as follows:
[0032]
[0033] OSU adopts the OPU partitioning method based on payload block (PB), such as Figure 3 As shown in the figure. For a given OPU, each transmission cycle consists of P consecutive payload blocks, and the PB size of each OPU is 192 bytes. Different OPU types correspond to different P values, see Table 1 below for details.
[0034] Table 1 P value and PB value corresponding to different OPUk
[0035]
[0036] Furthermore, the time domain scrambling of the OSU optical signal is achieved by a fiber optic delay circuit (FPC), such as Figure 4 (a) When the OSU optical signal enters a single fiber delay device, it will be reflected multiple times on the two surfaces of the cavity, as shown in Figure 4 (b). The collimated light emitted from the same side of the cavity is divided into multiple sub-beams, each with a different transmission delay, and coupled to the output fiber through a focusing lens. The variation of the total output intensity of the output fiber over time depends on the sum of all sub-beams with different delay times. For the scrambler, each fiber delay has an independent temperature control module (TCM) that is used to adjust the parameters of the cavity to achieve time domain scrambling of the optical signal. Therefore, the optical signal is rearranged to form a new waveform and overlaps adjacent bits. If the adjacent bits are mixed enough, the eavesdropping end cannot distinguish these signals due to the cross-interaction under the interference of jitter noise. When the OSU optical signal is scrambled by reflection from a single FPC, it is converted into a time domain waveform represented by the convolution between the input optical signal and the pulse response of the FPC. It can be expressed as
[0037]
[0038] where x' osu(t) is the time scrambled signal, is the convolution operation. osu (t) is the input OSU optical signal. h(t) is the FPC impulse response, and its inverse Fourier transform expression is:
[0039]
[0040] The frequency response r(ω) of FPC is
[0041]
[0042] Where r1 and r2 are the reflectivity of the two surfaces of the FPC. ω = 2π / λ is the optical frequency, and λ is the wavelength of light in vacuum. n is the refractive index of the FPC substrate. d is the thickness of the FPC substrate. θ0 is the incident angle of the optical signal entering the FPC. It can be seen from formulas (5) and (6) that the pulse response h(t) of the FPC is related to r1, r2, n and d. In order to achieve time domain randomization of the OSU optical signal, TCM can be used to adjust the optical thickness nd of the FPC.
[0043] The OSU optical signal after scrambling by N cascaded FPCs is:
[0044]
[0045] The OSU optical signal reflected from the FPC array of the descrambler is
[0046]
[0047] in is the impulse response of the scrambler. is the impulse response of the descrambler. Descramble the time-scrambled signal based on the thermo-optical effect, and use the reconfigurable encoding device to dynamically synchronize the descrambling key for descrambling. Let H'(t) = H * (-t), which can be obtained from the above formula
[0048]
[0049] The superscript "*" indicates complex conjugation. Represents the autocorrelation function of the impulse response of scrambling and descrambling, when it is equal to the Dirac function, that is, When , the output of the descrambler is the input of its corresponding scrambler, and the legitimate receiving end can completely restore the original OSU optical signal by using the correct synchronization key. If the impulse response of the descrambler is not the complex conjugate of the scrambler, that is, H'(t)≠H *At (t), the output of the descrambler is the cross-correlation function of two different FPC arrays, that is, the OSU optical signal is equivalent to being scrambled twice in the time domain. This means that the eavesdropping end cannot descramble the OSU optical signal without the correct key.
[0050] The following is a further description of the experiment of scrambling and descrambling OSU optical signals in conjunction with a specific embodiment of the present invention:
[0051] like Figure 5 As shown, the embodiment adopts the decoy state BB84 protocol with polarization encoding method, and provides seed keys through quantum channels and protocol channels. The main feature of such systems is that key generation requires single-photon quantum states and single-photon detection. These requirements are not only because such systems are extremely susceptible to losses and cannot amplify single photons, but also require a low-temperature environment. Therefore, a single G.652 standard single-mode fiber (SMF) is used as a quantum channel with a total fiber length of 50km, and no optical parametric amplifier is used. The secure seed key is pushed to the FPGA at the transmitting and receiving ends respectively. And the FPGA generates the running key that drives the scrambler / descrambler. At the same time, the key synchronization between the scrambler and the descrambler is achieved through the synchronization channel. Then, the OSU optical signal generated by the M-OTN device is encrypted using the FPC array. In addition, the decoy BB84 protocol signal for key seed, the synchronization signal for key synchronization, and the encrypted optical signal are multiplexed with the classical channel through wavelength division multiplexing (WDM) and transmitted at 1546.92nm, 1548.51nm, and 1550.12nm through the same 50km single-mode fiber. In addition, two erbium-doped fiber amplifiers (EDFAs) are used to compensate for the power loss of the encryptor / decryptor and the transmission fiber, and dispersion compensating fiber (DCF) is used to compensate for the dispersion of the 50km single-mode fiber. After decrypting the encrypted signal, the bit error rate (BER) and eye diagram after scrambling / descrambling can be tested by an Ethernet tester (MTS 5800) and an oscilloscope (TEKTRONIX DSA8200), respectively.
[0052] The experimental results of OSU optical signal scrambling and descrambling are shown in the eye diagram. Figure 6 As shown, Figure 6 (a) Figure 6 (b) shows the scrambled and descrambled signals, respectively. Since the FPC array is used for scrambling on the overlapping bits, it is significantly different from the original 10.709Gbps non-return-to-zero data modulated optical signal (NRZ). This shows that the scrambler completely breaks the time position relationship between different bits, making the OSU optical signal noisy and no longer digitizable. The eye diagrams after descrambling are shown in Figure 1. Figure 6 (c) Figure 6(d) When the correct descrambler is used, an open eye diagram is obtained. On the contrary, when an unmatched descrambler is used, the eye diagram remains closed, and the contour of the eye diagram does not show any digital features of "0" or "1". Therefore, if the eavesdropper cannot know the scrambling and descrambling strategies and the synchronization key at the same time, it is impossible to extract the OSU data through optoelectronic conversion.
[0053] The bit error rate (BER) performance of the OSU signal after backhaul (B2B) is as follows: Figure 7 As shown in the figure, the BER and the average received optical power (P R These measurements were performed at full throughput of 10.709 Gbps on the line side (NNI) and error-free performance (satisfying the bit error rate of 10 for forward error correction (FEC)). -9 ) operation. For B2B scenarios, in the case of no scrambling and scrambling, such as Figure 7 Compared with the unscrambled OSU optical signal, the introduction of scrambling driven by QKD will lead to a decrease in bit error rate performance when BER=10 -9 When the PR values of the unscrambled and scrambled OSU optical signals are approximately -21.08dBm and -20.41dBm, respectively, the optical power loss of the scrambled OSU optical signal is approximately 0.67dB. After 50km of transmission, similar bit error rate performance is shown, such as Figure 7 As shown by the solid line in the figure. When BER = 10 -9 When the PR values of the unscrambled and scrambled OSU optical signals are approximately -19.50dBm and -18.07dBm, respectively, the optical power loss of the scrambled OSU optical signal is approximately 1.43dB. This shows that at the cost of a slight loss of optical power, optical physical layer security is achieved by using the correct quantum key for synchronous scrambling and descrambling.
[0054] What is disclosed above is only one or more preferred embodiments of the present invention, which certainly cannot be used to limit the scope of rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of implementing the above embodiments and making equivalent changes according to the claims of the present invention still fall within the scope of the invention.
Claims
1. An optical service unit physical layer encryption system, characterized in that: It includes a sending end and a receiving end, which are connected via a quantum channel and a classical channel respectively, wherein the quantum random key is transmitted via the quantum channel, and the conventional signal is transmitted via the classical channel, the devices in the sending end and the receiving end are arranged symmetrically, and the shared seed key is updated between the sending end and the receiving end, and only the sending and receiving ends know it; The transmitting end includes a DS-QKD transmitter, a field programmable gate array, a scrambler, an erbium-doped fiber amplifier and a wavelength division multiplexer, and the receiving end also includes a field programmable gate array, an erbium-doped fiber amplifier and a wavelength division multiplexer. The corresponding different devices are a DS-QKD receiver and a descrambler.
2. The optical service unit physical layer encryption system according to claim 1, characterized in that: The DS-QKD transmitter sends a quantum random key to the DS-QKD receiver through a quantum channel without transmitting any message data, and the random scrambler scrambles the optical service unit optical signal using a running key generated by a field programmable gate array.
3. The optical service unit physical layer encryption system according to claim 2, characterized in that: The DS-QKD receiver receives the quantum bits from the DS-QKD transmitter and generates a seed key through a protocol channel. The field programmable gate array in the DS-QKD transmitter generates a running key from the seed key and the synchronization mark. The descrambler descrambles the scrambled optical service unit optical signal using the same running key generated from the same seed key.
4. The optical service unit physical layer encryption system according to claim 3, characterized in that: The optical service unit adopts the optical channel payload unit division method based on payload block. For a given optical channel payload unit, each transmission cycle consists of P consecutive payload blocks, where P is determined by the corresponding optical channel payload unit type level. The payload block size of each optical channel payload unit is 192 bytes.
5. The optical service unit physical layer encryption system according to claim 4, characterized in that: The time domain scrambling of the optical signal of the optical service unit is realized by a fiber delay device and is scrambled by N cascaded fiber delay devices. Each fiber delay device has an independent temperature control module for adjusting the parameters of the cavity.
6. The optical service unit physical layer encryption system according to claim 5, characterized in that: The optical service unit physical layer encryption system adopts a decoy state BB84 protocol with a polarization encoding method and provides a seed key through a quantum channel and a protocol channel.
Citation Information
Patent Citations
Method, device and equipment for safely transporting multiple services in optical transport network
CN108667526A
Sensitive data transmission protection system and method based on quantum key distribution
CN119210708A
Optical device, and optical communication module using the same
US20190285815A1
Cited By
Communication early warning method based on quantum encryption
CN121173395A
A communication early warning method based on quantum encryption
CN121173395B