Quantum key management method and device, equipment and storage medium
By dynamically adjusting the key quantity of the quantum key pool in the power system and selecting a suitable quantum key distribution protocol, the problem of insufficient key resource supply in the power system is solved, and the differentiated business security needs are met and information security is improved.
Patent Information
- Application Number
- CN202510331118.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-05-13
AI Technical Summary
Due to the wide variety of services and complex operating environment in power systems, traditional static key distribution methods are difficult to meet differentiated security needs, and the key generation rate of quantum communication systems is limited, so there may be insufficient supply of key resources.
A quantum key management method is proposed. By dynamically adjusting the key quantity in the key pool, selecting the target protocol according to the service importance and code formation rate, calculating the key length of each service, and generating quantum keys to ensure the sustainable supply of the key quantity in the key pool.
It realizes dynamic adjustment of quantum key resources in the power system, meets the differentiated security needs of different services, and ensures the information security and communication quality of the power system.
Smart Images

Figure CN119995878A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of power distribution networks and relates to a key management method, and in particular to a quantum key management method, device, equipment and storage medium. Background Art
[0002] With the rapid development of information technology, network security issues have gradually become a hot topic of global concern. Especially in the field of core infrastructure such as power systems, the confidentiality of data transmission is of vital importance. The rapid development of power systems is accompanied by the access of a large number of intelligent devices, which puts forward new requirements for the security of network communications. Under this trend, quantum communication technology has attracted much attention due to its unique security properties and has shown great potential in the communication security of power systems. The power system is one of the infrastructures of modern society. As the scale of the power system continues to expand, its structure has become more complex. Driven by informatization, efficient coordination and management are achieved through information technology between various links of the power system. This informatization brings higher efficiency and optimization space, but at the same time it also makes the power system face greater information security challenges. The information security of the power system is of great significance to national security, economic development and social stability. Any information security loopholes may lead to serious economic losses and even personal safety risks. Therefore, protecting the information security of the power system has become a top priority.
[0003] As a revolutionary communication technology, quantum communication is based on the principles of quantum mechanics and has the characteristics of theoretically unconditional security. Quantum key distribution technology uses the non-cloning property of quantum states to establish absolutely secure keys between the communicating parties, providing reliable protection for information encryption transmission. This unique security feature makes quantum communication very suitable for the security protection of key infrastructure such as power systems. Introducing quantum communication technology into the power business system can effectively prevent various security threats faced by traditional cryptographic systems and build a solid security barrier for power data transmission. At the same time, quantum communication has the advantages of good real-time performance and strong anti-interference ability, which can meet the strict requirements of the power system for communication quality. Therefore, the application of quantum communication in the power field has important practical significance and development prospects.
[0004] However, the deep integration of power business systems and quantum communication technology still faces many challenges. First, there are many types of power system services, and different services have different requirements for communication security and real-time performance. The traditional static key distribution method is difficult to meet differentiated security needs. Secondly, the key generation rate of the quantum communication system is limited by physical conditions, and there may be insufficient key resource supply in large-scale power business scenarios. The operating environment of the power system is complex and changeable, and the network topology structure is dynamically adjusted, which brings huge challenges to the distribution and management of quantum keys. Therefore, studying the dynamic key pool adjustment and business encryption key distribution strategy, ensuring the supply of quantum keys, optimizing the business encryption strategy and adjusting it in time when the quantum keys are insufficient, and allocating reasonable encryption methods to the business have important theoretical value and practical significance for promoting the large-scale application of quantum communication technology in the power system. Summary of the invention
[0005] In view of this, the present invention discloses a quantum key management method, device, equipment and storage medium, which can solve the deficiencies in the related technology.
[0006] To achieve the above purpose, the present invention discloses the following technical solutions:
[0007] According to a first aspect of the present invention, a method for managing a quantum key is proposed, the method comprising:
[0008] When the current key amount in the key pool is less than a preset threshold, the overall service importance of all services corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol are obtained, and a target protocol is selected from the various quantum key distribution protocols according to the overall service importance;
[0009] Switching the quantum key distribution protocol applied by the key pool to the target protocol, and calculating the key length corresponding to each service with the overall service security of all services as the optimization target when the target protocol is applied;
[0010] Generate quantum keys based on the calculated key lengths corresponding to each business.
[0011] According to a second aspect of the present invention, a quantum key management device is provided, the device comprising:
[0012] A selection unit: when the current key amount in the key pool is less than a preset threshold, obtains the overall business importance of all businesses corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol, and selects a target protocol from the various quantum key distribution protocols according to the overall business importance;
[0013] A switching unit: switching the quantum key distribution protocol applied by the key pool to the target protocol, and when applying the target protocol, calculating the key length corresponding to each service with the overall service security of all services as the optimization target;
[0014] Generation unit: Generates quantum keys according to the calculated key lengths corresponding to each business.
[0015] According to a third aspect of the present invention, an electronic device is provided, comprising:
[0016] processor;
[0017] a memory for storing processor-executable instructions;
[0018] The processor implements the steps of the method described in the first aspect by running the executable instructions.
[0019] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method described in the first aspect are implemented.
[0020] It can be seen from the above technical solutions that the quantum key management method disclosed in the present invention, on the one hand, proposes an overall strategy for dynamic adjustment of quantum keys in power systems, divides the adjustment process into two parts, input and output, uses the input adjustment result to provide a basis for output adjustment, and then uses the output adjustment result to feed back the adjustment input, and determines the sign of successful adjustment by establishing a model, thereby ensuring the sustainable supply of quantum key resources and improving the security of the power system; on the other hand, a method for optimizing quantum key input is proposed, the adjustable parameters of the quantum key distribution protocol are optimized in advance according to the real-time parameters of the key pool, and a suitable quantum key distribution protocol is selected as input, and a strategy for triggering the optimization process is proposed to provide a basis for dynamic adjustment of the output; in addition, a method for optimizing the encryption method of business data is proposed, and a calculation formula for the current overall business security is obtained according to the power business security evaluation method and the current business specific parameters, and the quantum key distribution method under the security optimization condition is calculated by a multi-parameter optimization algorithm, and mapped to a specific business encryption method, so as to maximize the security of business data under the condition of limited quantum key resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a flowchart of a quantum key management method provided by an exemplary embodiment.
[0022] Figure 2 It is a schematic diagram of a preset adjustment threshold provided by an exemplary embodiment.
[0023] Figure 3It is a schematic diagram of a quantum key dynamic adjustment strategy provided by an exemplary embodiment.
[0024] Figure 4 It is a schematic diagram of a protocol optimization provided by an exemplary embodiment.
[0025] Figure 5 It is a schematic structural diagram of a device provided by an exemplary embodiment.
[0026] Figure 6 It is a block diagram of a quantum key management device provided by an exemplary embodiment. DETAILED DESCRIPTION
[0027] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with one or more embodiments of the present invention. Instead, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of the present invention as detailed in the appended claims.
[0028] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in the present invention. In some other embodiments, the steps included in the method may be more or less than those described in the present invention. In addition, a single step described in the present invention may be decomposed into multiple steps for description in other embodiments; and multiple steps described in the present invention may be combined into a single step for description in other embodiments.
[0029] To further illustrate the present invention, the following examples are provided:
[0030] In order to solve the deficiencies in the related art, the present invention proposes a quantum key management method.
[0031] Figure 1 FIG. 1 is a flowchart of a method for managing a quantum key provided by an exemplary embodiment. Figure 1 As shown, the method may include the following steps:
[0032] Step 102: When the current amount of keys in the key pool is less than a preset threshold, the overall business importance of all businesses corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol are obtained, and a target protocol is selected from the various quantum key distribution protocols according to the overall business importance.
[0033] The goal of dynamic quantum key supply is to ensure that the amount of keys R in the key pool is kept within a reasonable range as much as possible. The upper limit of the range is the key pool capacity, and the lower limit is R p , R p It is also the preset threshold. If the key quantity is detected to be lower than R p , dynamic adjustment begins. The increase or decrease of the key quantity in the pool depends on the net key growth rate ΔR, that is, the difference between the key generation rate and the key consumption rate. When ΔR>0, the key quantity in the pool increases over time, and vice versa. In order to prevent the adjustment cycle from being too long and causing a continuous shortage of quantum keys, different dynamic adjustment success flags need to be determined according to different key quantities R and net key growth rates.
[0034] In order to better maintain sufficient key quantity in the key pool, the present invention proposes a spring model for dynamic adjustment of the key pool, such as Figure 2 As shown. The key amount of the key pool is used as the length of the "spring", and the preset threshold R p As its natural length. When the amount of keys in the key pool is detected to be R <R p The dynamic adjustment is triggered when the net key growth rate ΔR is expected to be achieved during the dynamic adjustment process. e As the force of the "spring" under this key amount, it is the sign of successful dynamic adjustment.
[0035] ΔR e = k(R p -R);
[0036] Among them, k is the elastic coefficient. The monitoring behavior of the key amount in the key pool has a certain time interval. When the key amount is first monitored to be lower than the preset threshold R p , R not only reflects the key reserve at the current moment, but also reflects the changing trend of the key quantity in the previous period of time. From the definition of the success mark, it can be seen that when the key quantity in the key pool is low, the expected net key growth rate required for dynamic adjustment is higher, and the key recovery speed will be faster after the adjustment is completed. This will restore the system to a normal state faster while ensuring business security as much as possible. If the insufficient key quantity is related to external factors, this strategy will also eliminate the influence of external factors to avoid their continued effect causing the dynamic adjustment cycle to be too long. The key quantity in the key pool can only be adjusted indirectly through quantum key distribution input and business encryption output, and the adjustment ability is limited. In order to ensure the expected net key growth rate ΔR e Will not exceed the maximum adjustment capacity, k is defined as
[0037]
[0038] Among them, ΔR mIt is the rate at which the quantum key distribution protocol with the largest code rate inputs keys into the key pool, that is, the key growth rate when the quantum key distribution protocol with the largest code rate is used as input and all business encryption uses classical encryption methods.
[0039] In the extreme case, the amount of keys in the key pool is 0, and no quantum key encryption task can be completed, so all services use classical encryption. At this time, the quantum key consumption rate is 0, and the maximum expected net key growth rate is ΔR m . During the period from the completion of dynamic adjustment to the full recovery of the key quantity, maintaining the expected net key growth rate will relatively reduce the overall security of the current business, but as long as it is not lower than the preset lower limit, the cost of dynamic adjustment based on the real-time key quantity will be significantly higher than the security cost. At the same time, changes in business traffic are unlikely to cause a sharp drop in the key quantity. The reason for the extremely low key quantity in the quantum key pool is usually a system failure. It is necessary to maintain a continuous increase in the key quantity to buy time for the recovery of system functions. Taking into account the above key requirements, dynamic adjustment makes the net key growth rate reach ΔR e After that, the system will maintain the adjusted strategy until the key pool is full and reset, switching to the initial quantum key distribution protocol and business data encryption method.
[0040] Step 104, switching the quantum key distribution protocol applied by the key pool to the target protocol, and when applying the target protocol, calculating the key length corresponding to each service with the overall service security of all services as the optimization target;
[0041] The dynamic adjustment process is divided into two parts: dynamic adjustment of input and dynamic adjustment of output. Figure 3 As shown. The main sources of key input in the key pool are quantum key distribution and quantum random number generator. Different quantum key distribution protocols have different code rates, and can provide different security and anti-interference capabilities. Taking into account the overall business importance and the specific parameters of the key pool, a suitable quantum key distribution protocol can be selected and optimized as the input of the key pool. The dynamic adjustment of the key pool input will provide a basis for the dynamic adjustment of the output. The theoretical code rate and expected net key growth rate ΔR of the selected quantum key distribution protocol eIt determines the upper limit of the quantum key consumption rate that can be used for business encryption. During the output adjustment process, the quantized value of the overall business security is optimized with this as the limit, and the optimized parameters are the quantum key encryption efficiency of each business. If the parameters determined by the optimization algorithm can meet the minimum standard of the overall business security, they will be mapped to the data encryption method of the corresponding business until the key pool is full. If the standard is still not met after optimization, feedback adjustments will be made to the quantum key input of the key pool, and the quantum key distribution protocol will be reselected to increase the input rate of the quantum key. If the current quantum key distribution protocol has reached the highest code rate and still cannot meet the minimum standard of the overall business security, the business encryption will be temporarily interrupted. The next time the key volume data is monitored, the dynamic adjustment will be re-triggered and the business encryption will be resumed.
[0042] Step 106: Generate a quantum key according to the calculated key length corresponding to each service.
[0043] In this embodiment, on the one hand, an overall strategy for dynamic adjustment of quantum keys in power systems is proposed, the adjustment process is divided into two parts, input and output, the input adjustment result is used to provide a basis for output adjustment, and the output adjustment result is used to feed back the adjustment input, and the sign of successful adjustment is determined by establishing a model to ensure the sustainable supply of quantum key resources and improve the security of the power system; on the other hand, an optimization method for quantum key input is proposed, the adjustable parameters of the quantum key distribution protocol are optimized in advance according to the real-time parameters of the key pool, and a suitable quantum key distribution protocol is selected as input, and a strategy for triggering the optimization process is proposed to provide a basis for dynamic adjustment of the output; in addition, an optimization method for the encryption method of business data is proposed, the calculation formula for the current overall business security is obtained according to the power business security evaluation method and the current business specific parameters, the quantum key distribution method under the security optimization condition is calculated by a multi-parameter optimization algorithm, and mapped to a specific business encryption method, so as to maximize the security of business data under the condition of limited quantum key resources.
[0044] In one embodiment, the quantum key distribution protocol includes a decoyed state BB84 protocol, a measurement device-independent BB84 protocol, a reference frame-independent BB84 protocol, and a dual-field quantum key distribution protocol;
[0045] The coding rate of the decoy BB84 protocol is:
[0046] v DBQ =n p R DBQ ;
[0047] Among them, n p is the number of pulses, R DBQ The secure bit rate of a single pulse of the BB84 protocol in a decoyed state;
[0048] R DBQ The calculation method is:
[0049]
[0050] Where μ represents the pulse intensity of the signal state, Z is the measurement basis, and P μ , P Z|μ , P Z They represent the probability that Alice sends a signal state pulse, the conditional probability that the signal state is encoded in the Z basis, and the probability that Bob chooses the Z basis measurement. and They represent the average receiving rate and average quantum bit error rate when Z is used as the measurement basis and the signal state pulse intensity is μ, respectively. e is the two-way error correction coefficient, H2(x) represents the binary Shannon entropy, Y i Z is the detection rate when sending a pulse of photon state i in Z basis, is the corresponding detection bit error rate, P1(μ) and P0(μ) satisfy the Poisson distribution:
[0051]
[0052] The measurement device is independent of the BB84 protocol coding rate:
[0053] v DMQ =n p R DMQ ;
[0054] Among them, n p is the number of pulses, R DMQ To measure the safe bit rate of a single pulse of the device-independent BB84 protocol;
[0055] R DMQ The calculation method is:
[0056]
[0057] Among them, P1(μ a ) and P1(μ b ) satisfies the Poisson distribution, μ a represents the pulse strength of Alice's signal state, μ b represents the pulse strength of the signal state sent by Bob, and They represent the probability that Alice sends a signaling pulse, the probability that Alice encodes the signaling state in the Z basis, the probability that Bob sends a signaling pulse, and the probability that Bob encodes the signaling state in the Z basis. and They represent that Z is used as the measurement basis and the signal state pulse intensities of Alice and Bob are μ a and μ b The average receiving rate and average quantum bit error rate at is the detection rate when Alice and Bob send i photons respectively in the Z basis, is the detection bit error rate when Alice and Bob send i photons respectively in the X basis;
[0058] The reference frame-independent BB84 protocol includes three sets of orthogonal bases Z, X, and Y, and the basis vectors of the communicating parties satisfy:
[0059]
[0060] The coding rate of the reference frame-independent BB84 protocol is:
[0061] v RFI =n p R RFI ;
[0062] Among them, n p is the number of pulses, R RFI The safe coding rate of a single pulse of the reference frame-independent BB84 protocol;
[0063] R RFI The calculation method is:
[0064] R RFI =1-H2(E Z )-I E (E Z ,C);
[0065] Where C = <X A X B > 2 + <X A Y B > 2 + <Y A X B > 2 + <Y A Y B > 2 , H2 represents binary information entropy, E Z is the quantum bit error rate in the Z basis, I E represents the amount of information that the attacker Eve can obtain, satisfying
[0066]
[0067] in,
[0068]
[0069] The coding rate of the dual-field quantum key distribution protocol is:
[0070] v TF =n p R TF ;
[0071] Among them, n p is the number of pulses, R TF The secure coding rate of a single pulse for the dual-field quantum key distribution protocol;
[0072] R TF The calculation method is:
[0073] R TF =Q1| μ,L [1-H(e1| μ,L )]-fQ μ,L H(E μ,L );
[0074] Where μ represents the signal strength, L represents the distance between the two communicating parties, and Q1 = p 1|μ y1 represents the single photon gain, represents the Poisson probability of emitting n photons when preparing a state with intensity μ, y1 represents the single-photon generation rate, e1 represents the single-photon phase error rate, Q and E represent the gain and quantum bit error rate in the quantum key distribution process respectively, f represents the error correction efficiency, and H is the binary entropy.
[0075] Furthermore, before obtaining the coding rate of each quantum key distribution protocol, it also includes: optimizing the parameters of each quantum key distribution protocol according to a preset parameter optimization strategy.
[0076] When environmental factors change, the configuration parameters of the quantum key distribution protocol that are optimized to achieve the highest code rate will also be different. For example, as the transmission length increases, the signal state strength, the probability of signal state pulse transmission, and the probability of signal state pulse encoding under the Z basis should all decrease, and the corresponding entrapped state strength, the probability of entrapped state pulse transmission, and the probability of entrapped state pulse encoding under the Z basis need to increase. In an asymmetric quantum key distribution protocol with intermediate nodes, the distance difference between the communicating parties and the relay node will also affect the code rate and transmission distance, and thus affect the configuration of system parameters. Before making a decision on the quantum key distribution protocol to be switched, it is necessary to optimize its parameters so that it can be in the highest possible performance state immediately after deployment. Compared with the switching process of the quantum key distribution protocol, the optimization process does not require additional communication resources and takes less time. Optimizing the quantum key distribution protocol and selecting parameters in advance according to the current environmental factors before switching can achieve better operating performance.
[0077] The maximum theoretical coding rate of the quantum key distribution protocol cannot be determined before the optimization is completed. The trigger conditions for optimization need to be designed based on the estimated coding rate, such as Figure 4 As shown. Assume that the set of available quantum key distribution protocols is Q = {q1,q2,...,q n}, where protocol q i It can be a conventional quantum key distribution protocol or other protocols available in the current system. i The corresponding estimated coding rate is v i When the amount of keys in the key pool is detected to be lower than the adjustment threshold R for the first time p The optimization needs to be completed before the protocol switch, that is, when the key amount is still higher than R p When the overall business importance is S, the protocol q can be selected for dynamic adjustment. i The upper limit of the key amount interval is c i =c(v i ,S). Let the xth monitoring key amount be R x , then start optimizing protocol q i The symbol is
[0078] R x -α(R x -R x+1 ) <c i ;
[0079] That is, assuming that the amount of keys decreases exponentially, it is expected that the next monitoring will be reduced to the point where it is necessary to switch to protocol q i The key quantity is α, where α is the parameter of the key quantity reduction model under this assumption. In actual systems, the key quantity usually does not change dramatically in a short period of time. The dynamic adjustment based on the exponential decline model is sufficient to deal with the insufficient key quantity caused by single point failure in most cases.
[0080] To further ensure that the optimized parameter configuration protocol is used during the switching process, an overall optimization strategy is designed from two dimensions: key quantity and time. The optimization period t0 is set in time, and all quantum key distribution protocols are optimized once according to the current environmental conditions every time t0. The probability of unpredictable sudden key shortage is extremely low, and the optimization period t0 should be long enough to avoid unnecessary calculations. Periodic optimization in time ensures that there is a more appropriate parameter configuration as a reference when the protocol is switched. This reference cannot reflect changes in environmental conditions in real time. On this basis, the optimization percentage ρ0 is set, that is, when the key quantity is lower than R0, an overall optimization is performed, where
[0081] R0=R p +ρ0(R m -R p );
[0082] Among them, R m Indicates the upper limit of the key pool. If the key amount is lower than R for the first time, p If the protocol corresponding to the current key amount has not been optimized specifically, the parameter configuration protocol after overall optimization is adopted.
[0083] In one embodiment, selecting a target protocol from the various quantum key distribution protocols according to the overall business importance includes:
[0084] A relationship model is established among the coding rate, the overall business importance and the amount of keys in the key pool:
[0085]
[0086] Among them, f i Indicates optional protocol q i The lower limit of the key quantity interval, S H Indicates the maximum value of the overall importance of the business, protocol q i The corresponding estimated coding rate is v i , the overall business importance is S, R p is the preset threshold;
[0087] According to the relationship model, the key quantity interval corresponding to each quantum key distribution protocol that meets the standards of all the services is determined, and the quantum key distribution protocol corresponding to the key quantity interval where the current key quantity is located is selected as the target protocol.
[0088] The real-time key input rate, real-time key output rate and real-time key quantity in the key pool will affect the coding rate required by the quantum key distribution protocol, and the overall importance of the current business will affect the security required by the quantum key distribution protocol. The security of the business is jointly guaranteed by the key distribution in the key pool input stage and the business encryption in the key pool output stage. If the security of the quantum key distribution protocol does not meet the standards, even if the most secure business encryption method is used in the output stage, the overall security cannot be guaranteed. After the dynamic adjustment is triggered, it is necessary to comprehensively consider the coding rate and security and select a suitable quantum key distribution protocol.
[0089] In the protocol set Q = {q1,q2,...,q n}, first determine the protocol q that can be selected during dynamic adjustment i The lower limit of the key quantity interval. Assume that the overall importance of the current business is S, and the protocol q i The corresponding estimated coding rate is v i, i=1,2,...,n. For a certain key pool parameter and overall business importance, the selection of quantum key distribution protocol mainly considers two factors: coding rate and security. The security of quantum key distribution protocol is a broad concept. The ability to resist security attacks such as PNS attack and side channel attack, coding error rate and secure coding distance will have an impact on security, which is difficult to quantify. Considering protocol q j and q j+1 , j = 1, 2, ..., n-1, let v i <v j+1 , that is, q j With q j+1 Compared with the coding rate, the coding rate is lower. j With q j+1 The security is also worse than q. j Compared to q j+1 Always the better choice, q j should be excluded from the set of quantum key distribution protocols Q that can be selected. Excluding all protocols that cannot be selected, the security decreases with v i The increase of v can be reduced, and the protocol selection basis can be combined to select the appropriate v according to the key pool parameters and the overall importance of the business. i The corresponding protocol q i .
[0090] When the key amount is reduced to the adjustment threshold R p When the current key quantity R is lower, the net key growth rate ΔR required to be achieved is e The higher the value, the higher the corresponding coding rate. At the same time, the higher the overall importance of the business, the higher the required security, and the corresponding protocol with a lower coding rate. To avoid repeated feedback adjustments, when the real-time key amount is close to 0, the protocol with the highest coding rate is used regardless of the importance of the business. Let f i Indicates optional protocol q i The lower limit of the key quantity interval, S H Indicates the maximum value of the overall importance of the business. Considering the above factors, a model can be established
[0091]
[0092] If the agreement q i It is not the protocol with the lowest coding rate in Q. The upper limit of the corresponding key amount interval is the coding rate second only to q i The lower limit of the key volume interval corresponding to the protocol. Let v1 <v2<…<v n , then when i>1, q i The corresponding upper limit of the key amount interval c i It can be expressed as
[0093]
[0094] The real-time key quantity R is detected for the first time <R P Dynamic adjustment is triggered when R satisfies
[0095] f(v i ,S)≤R <c(v i ,S);
[0096] Then select protocol q i As key pool input. Let R out is the key consumption rate in the output stage, R out <v i -ΔR e As a limiting condition, it triggers dynamic adjustment of the output stage.
[0097] When the real-time key quantity is close to 0, the lower limit of the key quantity interval is 0. i =0 Substituting into
[0098]
[0099] That is, by adopting the quantum key distribution protocol with the highest coding rate, the dynamic adjustment target can theoretically be achieved through dynamic adjustment of the output.
[0100] Furthermore, before calculating the key length corresponding to each service with the overall service security of all services as the optimization target, the method further includes:
[0101] Assume that the service set of the key pool is P = {p1, p2, ..., p n}, the corresponding service data length set is L = {l1,l2,...,l n}, the corresponding business comprehensive importance set is G = {g1,g2,...,g n}, the amount of real-time keys to be allocated is s, and the length of each service key to be optimized is S = {s1, s2, ..., s n}, the overall business security is:
[0102]
[0103] Among them, f(p i ) = a·r i +b·J i (t i )+c, and a and b are coefficients determined by the business, satisfying a+b=1, c is the environmental coefficient, J i (t i ) is the key reuse t iThe safety level of the second time meets:
[0104]
[0105] in, m is the key usage threshold, and α0 is the security level of the adopted security scheme;
[0106] When α0=1,
[0107]
[0108] The overall business security is transformed into:
[0109]
[0110] Next, we can take the overall security of the business as the optimization goal and n There are many multi-parameter optimization algorithms that can be used, such as the stochastic gradient descent algorithm.
[0111] In one embodiment, switching the quantum key distribution protocol applied by the key pool to the target protocol includes: for each node, prioritizing its lower-layer adjacent nodes according to traffic and importance, and diffusing the protocol switching request to the lower-layer nodes step by step starting from the core node of the network.
[0112] The switching of quantum key distribution protocol requires the negotiation of the type and parameters of the protocol to be switched between the nodes, and it cannot be done synchronously spontaneously. After the protocol switching trigger condition is met and the protocol to be switched is selected, the protocol switching request is diffused from the core node of the network to the lower nodes step by step. Each node prioritizes its lower-level adjacent nodes according to traffic, importance, etc., and interacts with nodes with higher priorities first. Assume that the current node s0 has completed the protocol switching and is ready to start notifying m lower-level nodes s1, s2, ..., s m Start switching, where s i The priority p i Satisfy p i ≥p i+1 , i=1,2,...,m-1. Assume that at this time node s0 has completed the interaction with the first i-1 lower-level adjacent nodes, and consider its notification node s i The switching process begins. First, s0 checks whether the target protocol and target protocol parameters selected at the current moment meet the requirements of s i If it is determined that it can be established, the above information will be sent to s under the condition of authentication. i ,s iCheck whether the switching requirements can be met based on the received information. If it is determined to be met, confirm to s0, and both parties begin to deploy the quantum key distribution protocol to be switched. At this time, the key supply of the original quantum key distribution protocol is not completely interrupted, and it runs in parallel with the new protocol during the switching process. Monitor the protocol parameters in real time, and interrupt the original protocol after the new protocol can run normally and the code rate is stable. This completes the communication with s i Switch between protocols and start with s according to the same process i+1 interaction.
[0113] In actual networks, each node has different traffic, functions, and hardware conditions, and the selectable key sources are not uniform. The amount of keys in the key pool measures the overall key supply and demand of nodes in the network. The selection of quantum key distribution protocols is mainly based on the parameters of the key pool, and node characteristics cannot be taken into account. When switching protocols from top to bottom, it is necessary to consider the differences in the optional key sources of nodes, that is, when s0 selects a protocol q based on the protocol selection strategy or the information of the upper node, j ∈Q={q1,q2,...,q n}, j = 1, 2, ..., n and notify the lower nodes to start switching, it may appear but This will cause switching anomalies and affect the overall dynamic adjustment effect of a certain area. Therefore, in the above switching process, if any node s x If the hardware check fails, the protocol will be switched to where j'≤j and satisfy That is, under the condition that the security level is at least the same as qj, select the protocol with the closest performance.
[0114] In one embodiment, the generating of quantum keys according to the calculated key lengths corresponding to each service includes: calculating the proportion of plaintext that can be encrypted by the quantum key according to the calculated key lengths, and mapping it to corresponding quantum key replacement levels and quantum key update frequencies; determining a service encryption method with the highest security, and generating quantum keys according to the service encryption method.
[0115] The application of quantum keys is to replace keys of different levels with quantum keys. The higher the level of keys replaced, the larger the amount of data actually encrypted by the quantum key of the same length, the smaller the quantum key consumption, and the worse the security. At present, the quantum key generation rate of quantum key distribution equipment is low. If all keys in the communication process use quantum keys, the key supply will be insufficient. According to the relative importance of the power dispatching business, the application of quantum keys is divided into three forms: replacing working keys, replacing session keys, and replacing master keys, and their security levels decrease in turn.
[0116] The quantum key application method that replaces the working key is that each plaintext message is encrypted using a different quantum key. Each key can only be used once, and the amount of quantum key consumed is equal to the amount of encrypted data.
[0117] In the quantum key application method of replacing the session key, the AES-128 encryption algorithm is used, and the key length used for data grouping and each encryption is 128 bits. The key update frequency is f=B / I, where f is the quantum key update frequency, B is the business data flow per second, and I is the data transmission threshold of this type of business, which is used to indicate the maximum length of data that can be encrypted using a 128-bit quantum key. Considering that a large key data transmission threshold will reduce the key freshness, the key is updated every 8-16 encrypted packets, and the data transmission threshold value range is 1 to 2KB.
[0118] In the quantum key application method of replacing the master key, the quantum key is used to generate a session key, which can be expressed as K = prf (K M ,r,N), where K is the session key, r is a random value negotiated in advance by the two sites, and N is a pseudo-random string specified by the protocol to prevent the same key from being selected when encrypting different contexts. M The prf function is a pseudo-random function, which is usually calculated using a hash function. The more secure SHA-256 can be used to generate a session key with a length of 256 bits. From the ratio between the master key and the session key, it can be seen that when replacing the master key, the key update threshold and quantum key update frequency are 2 times and 1 / 2 of those when replacing the session key, respectively.
[0119] After obtaining the quantum key length, by calculating the proportion of plaintext that can be encrypted by the quantum key and mapping it to the appropriate quantum key replacement level and quantum key update frequency, we can finally determine the business encryption method that can currently optimize security and actually use the quantum key for business encryption.
[0120] Figure 5 is a schematic structural diagram of a device provided by an exemplary embodiment. Figure 5At the hardware level, the device includes a processor 502, an internal bus 504, a network interface 506, a memory 508, and a non-volatile memory 510, and may also include hardware required for other functions. One or more embodiments of the present invention may be implemented based on software, such as the processor 502 reading the corresponding computer program from the non-volatile memory 510 into the memory 508 and then running it. Of course, in addition to the software implementation, one or more embodiments of the present invention do not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but may also be hardware or logic devices.
[0121] Please refer to Figure 6 , a quantum key management device can be used for Figure 6 In the device shown, to implement the technical solution of the present invention, the device may include:
[0122] A selection unit 602 is used to obtain the overall service importance of all services corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol when the current key amount in the key pool is less than a preset threshold, and select a target protocol from the various quantum key distribution protocols according to the overall service importance;
[0123] A switching unit 604 is used to switch the quantum key distribution protocol applied by the key pool to the target protocol, and when the target protocol is applied, calculate the key length corresponding to each service with the overall service security of all services as the optimization target;
[0124] The generating unit 606 is used to generate a quantum key according to the calculated key length corresponding to each service.
[0125] Optionally, the quantum key distribution protocol includes a decoyed state BB84 protocol, a measurement device-independent BB84 protocol, a reference frame-independent BB84 protocol, and a dual-field quantum key distribution protocol;
[0126] The coding rate of the decoy BB84 protocol is:
[0127] v DBQ =n p R DBQ ;
[0128] Among them, n p is the number of pulses, R DBQ The secure bit rate of a single pulse of the BB84 protocol in a decoyed state;
[0129] R DBQ The calculation method is:
[0130]
[0131] Where μ represents the pulse intensity of the signal state, Z is the measurement basis, and P μ , P Z|μ , P Z They represent the probability that Alice sends a signal state pulse, the conditional probability that the signal state is encoded in the Z basis, and the probability that Bob chooses the Z basis measurement. and They represent the average receiving rate and average quantum bit error rate when Z is used as the measurement basis and the signal state pulse intensity is μ, respectively. e is the two-way error correction coefficient, H2(x) represents the binary Shannon entropy, Y i Z is the detection rate when sending a pulse of photon state i in Z basis, is the corresponding detection bit error rate, P1(μ) and P0(μ) satisfy the Poisson distribution:
[0132]
[0133] The measurement device is independent of the BB84 protocol coding rate:
[0134] v DMQ =n p R DMQ ;
[0135] Among them, n p is the number of pulses, R DMQ To measure the safe bit rate of a single pulse of the device-independent BB84 protocol;
[0136] R DMQ The calculation method is:
[0137]
[0138] Among them, P1(μ a ) and P1(μ b ) satisfies the Poisson distribution, μ a represents the pulse strength of Alice's signal state, μ b represents the pulse strength of the signal state sent by Bob, and They represent the probability that Alice sends a signaling pulse, the probability that Alice encodes the signaling state in the Z basis, the probability that Bob sends a signaling pulse, and the probability that Bob encodes the signaling state in the Z basis. and They represent that Z is used as the measurement basis and the signal state pulse intensities of Alice and Bob are μ a and μ bThe average receiving rate and average quantum bit error rate at is the detection rate when Alice and Bob send i photons respectively in the Z basis, is the detection bit error rate when Alice and Bob send i photons respectively in the X basis;
[0139] The reference frame-independent BB84 protocol includes three sets of orthogonal bases Z, X, and Y, and the basis vectors of the communicating parties satisfy:
[0140]
[0141] The coding rate of the reference frame-independent BB84 protocol is:
[0142] v RFI =n p R RFI ;
[0143] Among them, n p is the number of pulses, R RFI The safe coding rate of a single pulse of the reference frame-independent BB84 protocol;
[0144] R RFI The calculation method is:
[0145] R RFI =1-H2(E Z )-I E (E Z ,C);
[0146] Where C = <X A X B > 2 + <X A Y B > 2 + <Y A X B > 2 + <Y A Y B > 2 , H2 represents binary information entropy, E Z is the quantum bit error rate in the Z basis, I E represents the amount of information that the attacker Eve can obtain, satisfying
[0147]
[0148] in,
[0149]
[0150] The coding rate of the dual-field quantum key distribution protocol is:
[0151] vTF =n p R TF ;
[0152] Among them, n p is the number of pulses, R TF The secure coding rate of a single pulse for the dual-field quantum key distribution protocol;
[0153] R TF The calculation method is:
[0154] R TF =Q1| μ,L [1-H(e1| μ,L )]-fQ μ,L H(E μ,L );
[0155] Where μ represents the signal strength, L represents the distance between the two communicating parties, and Q1 = p 1|μ y1 represents the single photon gain, represents the Poisson probability of emitting n photons when preparing a state with intensity μ, y1 represents the single-photon generation rate, e1 represents the single-photon phase error rate, Q and E represent the gain and quantum bit error rate in the quantum key distribution process respectively, f represents the error correction efficiency, and H is the binary entropy.
[0156] Optionally, before obtaining the coding rate of each quantum key distribution protocol, the following steps are further included:
[0157] The optimization unit 608 is used to optimize the parameters of each quantum key distribution protocol according to a preset parameter optimization strategy.
[0158] Optionally, the selection unit is specifically used for:
[0159] A relationship model is established among the coding rate, the overall business importance and the amount of keys in the key pool:
[0160]
[0161] Among them, f i Indicates optional protocol q i The lower limit of the key quantity interval, S H Indicates the maximum value of the overall importance of the business, protocol q i The corresponding estimated coding rate is v i , the overall business importance is S, R p is the preset threshold;
[0162] According to the relationship model, the key quantity interval corresponding to each quantum key distribution protocol that meets the standards of all the services is determined, and the quantum key distribution protocol corresponding to the key quantity interval where the current key quantity is located is selected as the target protocol.
[0163] Optionally, before calculating the key length corresponding to each service with the overall service security of all services as the optimization target, the method further includes:
[0164] The calculation unit 610 is used to set the service set of the key pool to be P = {p1, p2, ..., p n}, the corresponding service data length set is L = {l1,l2,...,l n}, the corresponding business comprehensive importance set is G = {g1,g2,...,g n}, the amount of real-time keys to be allocated is s, and the length of each service key to be optimized is S = {s1, s2, ..., s n}, the overall business security is:
[0165]
[0166] Among them, f(p i ) = a·r i +b·J i (t i )+c, and a and b are coefficients determined by the business, satisfying a+b=1, c is the environmental coefficient, J i (t i ) is the key reuse t i The safety level of the second time meets:
[0167]
[0168] in, m is the key usage threshold, and α0 is the security level of the adopted security scheme;
[0169] When α0=1,
[0170]
[0171] The overall business security is transformed into:
[0172]
[0173] Optionally, the switching unit is specifically used for:
[0174] For each node, its lower-level adjacent nodes are prioritized according to traffic and importance, and protocol switching requests are diffused to lower-level nodes step by step starting from the core node of the network.
[0175] Optionally, the generating unit is specifically used for:
[0176] Calculate the proportion of plaintext that can be encrypted by the quantum key according to the calculated key length, and map it to the corresponding quantum key replacement level and quantum key update frequency;
[0177] Determine a business encryption method with the highest security, and generate a quantum key based on the business encryption method.
[0178] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.
[0179] In a typical configuration, a computer includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0180] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0181] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0182] With respect to the computer-readable medium (or computer-readable storage medium) as described above or in any other form, computer instructions may be stored thereon, and when the instructions are executed by a processor, one or more of the above-mentioned embodiments are implemented, thereby realizing the technical solution of the present invention.
[0183] The present invention also proposes a computer program, which, when executed by a processor, implements one or more of the above embodiments, thereby realizing the technical solution of the present invention. The computer program may be specifically recorded in the above or any other form of computer-readable medium, and the present invention is not limited thereto.
[0184] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0185] The above describes specific embodiments of the present invention. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0186] The terms used in one or more embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of the present invention. The singular forms of "a", "said" and "the" used in one or more embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0187] It should be understood that although the terms first, second, third, etc. may be used to describe various information in one or more embodiments of the present invention, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0188] The above description is merely a preferred embodiment of one or more embodiments of the present invention and is not intended to limit one or more embodiments of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present invention shall be included in the scope of protection of one or more embodiments of the present invention.
Claims
1. A method for managing quantum keys, characterized in that: The method comprises: When the current key amount in the key pool is less than a preset threshold, the overall service importance of all services corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol are obtained, and a target protocol is selected from the various quantum key distribution protocols according to the overall service importance; Switching the quantum key distribution protocol applied by the key pool to the target protocol, and calculating the key length corresponding to each service with the overall service security of all services as the optimization target when the target protocol is applied; Generate quantum keys based on the calculated key lengths corresponding to each business.
2. The method according to claim 1, characterized in that The quantum key distribution protocol includes the entrapped state BB84 protocol, the measurement device-independent BB84 protocol, the reference frame-independent BB84 protocol, and the dual-field quantum key distribution protocol; The coding rate of the decoy BB84 protocol is: v DBQ =n p R DBQ ; Among them, n p is the number of pulses, R DBQ The secure bit rate of a single pulse of the BB84 protocol in a decoyed state; R DBQ The calculation method is: Where μ represents the pulse intensity of the signal state, Z is the measurement basis, and P μ , P Z|μ , P Z They represent the probability that Alice sends a signal state pulse, the conditional probability that the signal state is encoded in the Z basis, and the probability that Bob chooses the Z basis measurement. and They represent the average receiving rate and average quantum bit error rate when Z is used as the measurement basis and the signal state pulse intensity is μ, respectively. e is the two-way error correction coefficient, H2(x) represents the binary Shannon entropy, Y i Z is the detection rate when sending a pulse of photon state i in Z basis, is the corresponding detection bit error rate, P1(μ) and P0(μ) satisfy the Poisson distribution: The measurement device is independent of the BB84 protocol coding rate: v DMQ =n p R DMQ ; Among them, n p is the number of pulses, R DMQ To measure the safe bit rate of a single pulse of the device-independent BB84 protocol; R DMQ The calculation method is: Among them, P1(μ a ) and P1(μ b ) satisfies the Poisson distribution, μ a represents the pulse strength of Alice's signal state, μ b represents the pulse strength of the signal state sent by Bob, and They represent the probability that Alice sends a signaling pulse, the probability that Alice encodes the signaling state in the Z basis, the probability that Bob sends a signaling pulse, and the probability that Bob encodes the signaling state in the Z basis. and They represent that Z is used as the measurement basis and the signal state pulse intensities of Alice and Bob are μ a and the average receiving rate and average quantum bit error rate when μb, is the detection rate when Alice and Bob send i photons respectively in the Z basis, is the detection bit error rate when Alice and Bob send i photons respectively in the X basis; The reference frame-independent BB84 protocol includes three sets of orthogonal bases Z, X, and Y, and the basis vectors of the communicating parties satisfy: The coding rate of the reference frame-independent BB84 protocol is: v RFI =n p R RFI ; Among them, n p is the number of pulses, R RFI The safe coding rate of a single pulse of the reference frame-independent BB84 protocol; R RFI The calculation method is: R RFI =1-H2(E Z )-I E (E Z ,C); Where C = <X A X B > 2 + <X A Y B > 2 + <Y A X B > 2 + <Y A Y B > 2 , H2 represents binary information entropy, E Z is the quantum bit error rate in the Z basis, I E represents the amount of information that the attacker Eve can obtain, satisfying in, The coding rate of the dual-field quantum key distribution protocol is: v TF =n p R TF ; Among them, n p is the number of pulses, R TF The secure coding rate of a single pulse for the dual-field quantum key distribution protocol; R TF The calculation method is: R TF =Q1| μ,L [1-H(e1| μ,L )]-fQ μ,L H(E μ,L ); Where μ represents the signal strength, L represents the distance between the two communicating parties, and Q1 = p 1|μ y1 represents the single photon gain, represents the Poisson probability of emitting n photons when preparing a state with intensity μ, y1 represents the single-photon generation rate, e1 represents the single-photon phase error rate, Q and E represent the gain and quantum bit error rate in the quantum key distribution process respectively, f represents the error correction efficiency, and H is the binary entropy.
3. The method according to claim 2, characterized in that Before obtaining the coding rate of each quantum key distribution protocol, it also includes: The parameters of each quantum key distribution protocol are optimized according to the preset parameter optimization strategy.
4. The method according to claim 1, characterized in that The selecting a target protocol from the various quantum key distribution protocols according to the overall business importance includes: A relationship model is established among the coding rate, the overall business importance and the amount of keys in the key pool: Among them, f i Indicates optional protocol q i The lower limit of the key quantity interval, S H Indicates the maximum value of the overall importance of the business, protocol q i The corresponding estimated coding rate is v i , the overall business importance is S, R p is the preset threshold; According to the relationship model, the key quantity interval corresponding to each quantum key distribution protocol that meets the standards of all the services is determined, and the quantum key distribution protocol corresponding to the key quantity interval where the current key quantity is located is selected as the target protocol.
5. The method according to claim 4, characterized in that Before calculating the key length corresponding to each service with the overall service security of all services as the optimization target, the method further includes: Assume that the service set of the key pool is P = {p1, p2, ..., p n }, the corresponding service data length set is L = {l1,l2,...,l n }, the corresponding business comprehensive importance set is G = {g1,g2,...,g n }, the amount of real-time keys to be allocated is s, and the length of each service key to be optimized is S = {s1, s2, ..., s n }, the overall business security is: Among them, f(p i ) = a·r i +b·J i (t i )+c, and a and b are business-determined coefficients, satisfying a+b=1, c is the environmental coefficient, and Ji(ti) is the key reuse t i The safety level of the second time meets: in, m is the key usage threshold, and α0 is the security level of the adopted security scheme; When α0=1, The overall business security is transformed into:
6. The method according to claim 1, characterized in that The step of switching the quantum key distribution protocol applied by the key pool to the target protocol includes: For each node, its lower-level adjacent nodes are prioritized according to traffic and importance, and protocol switching requests are diffused to lower-level nodes step by step starting from the core node of the network.
7. The method according to claim 1, characterized in that Generating a quantum key according to the calculated key lengths corresponding to each service includes: Calculate the proportion of plaintext that can be encrypted by the quantum key according to the calculated key length, and map it to the corresponding quantum key replacement level and quantum key update frequency; Determine a business encryption method with the highest security, and generate a quantum key based on the business encryption method.
8. A quantum key management device, characterized in that: The device comprises: A selection unit: when the current key amount in the key pool is less than a preset threshold, obtains the overall business importance of all businesses corresponding to the key pool and the coding rate corresponding to each quantum key distribution protocol, and selects a target protocol from the various quantum key distribution protocols according to the overall business importance; A switching unit: switching the quantum key distribution protocol applied by the key pool to the target protocol, and when applying the target protocol, calculating the key length corresponding to each service with the overall service security of all services as the optimization target; Generation unit: Generates quantum keys according to the calculated key lengths corresponding to each business.
9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor implements the steps of the method according to any one of claims 1 to 7 by running the executable instructions.
10. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.