Quantum key expansion method, device and equipment, and computer program product
Patent Information
- Application Number
- CN202510176361.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2045-02-18
AI Technical Summary
以目前商用QKDN为例,为一对用户QKD提供的量子密钥输出性能约每24小时1KB,若单对用户跨域量子密钥分发性能需求高于这个值,则需增加接入QKDN的QKD设备,或可能超过网络整体负载能力,扩容能力有限且不灵活
[0038]The at least one technical solution adopted in this application embodiment can achieve the following beneficial effects: The quantum key expansion method of this application embodiment is executed by the local node connected to the quantum key distribution network. First, multiple backup quantum keys are obtained from the local cryptographic device of the local node. The backup quantum keys are negotiated by the quantum key distribution network. Then, the original quantum key is obtained based on the negotiation of the quantum key distribution network. Finally, multiple expanded quantum keys are generated based on the multiple backup quantum keys and the original quantum key. The quantum key expansion method of this application embodiment, by using the quantum key distribution network to negotiate and generate multiple backup quantum keys, and using the multiple backup quantum keys to expand the original quantum key, can realize flexible expansion of quantum keys in a low-cost manner without increasing QKD device resources, thereby improving the performance of QKD device in generating quantum keys.
Smart Images

Figure CN120017261B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum key distribution technology, and in particular to a quantum key expansion method, apparatus and device, and computer program product. Background Technology
[0002] Currently, users can achieve secure cross-domain quantum key distribution by deploying QKD (Quantum Key Distribution) devices to access QKDN (Quantum Key Distribution Network). The security of the QKD protocol utilizes the inherent randomness of quantum mechanics and the quantum no-cloning theorem. The former is used to generate truly random keys, while the latter ensures that the key cannot be eavesdropped on during transmission. Furthermore, if any key transmission channel is intercepted, it will be detected by both communicating parties, and the intercepted key will then be used for security enhancement protocols.
[0003] QKDN (Quantum Key Distribution Network) uses technologies such as quantum key distribution protocols and secure key relay for quantum key distribution. The quantum key generation and output performance of two remote QKD devices for a user is mainly limited by the secure key relay capability of QKDN. Taking a currently commercially available QKDN as an example, the quantum key output performance provided to a pair of user QKDs is approximately 1KB every 24 hours. If the cross-domain quantum key distribution performance requirement for a single pair of users exceeds this value, it is necessary to add more QKD devices to the QKDN, which may exceed the overall network load capacity, resulting in limited and inflexible scalability. Summary of the Invention
[0004] This application provides a quantum key expansion method, apparatus, device, and computer program product to reduce the cost of quantum key expansion and improve the flexibility of quantum key expansion.
[0005] The embodiments of this application adopt the following technical solutions:
[0006] In a first aspect, embodiments of this application provide a quantum key augmentation method, wherein the quantum key augmentation method is executed by a local node accessing a quantum key distribution network, and the quantum key augmentation method includes:
[0007] Obtain multiple backup quantum keys from the local cryptographic device of this node, wherein the backup quantum keys are negotiated by the quantum key distribution network;
[0008] The original quantum key is obtained through negotiation using a quantum key distribution network;
[0009] Multiple extended quantum keys are generated based on the multiple backup quantum keys and the original quantum key.
[0010] Optionally, generating multiple expanded quantum keys based on the multiple backup quantum keys and the original quantum key includes:
[0011] Construct the quantum key expansion sequence for this node based on multiple of the aforementioned backup quantum keys;
[0012] Multiple expanded quantum keys are generated based on the quantum key expansion sequence and the original quantum key.
[0013] Optionally, the local node in the access quantum key distribution network is divided into a master node and a slave node, and the step of constructing the quantum key expansion sequence of the local node based on multiple backup quantum keys includes:
[0014] When the local node is the master node, multiple backup quantum keys are obtained from the local cryptographic device of the master node;
[0015] Construct a quantum key expansion sequence for the master node based on multiple backup quantum keys;
[0016] The identifiers of multiple backup quantum keys are sent to all target slave nodes.
[0017] Optionally, constructing the quantum key augmentation sequence for this node based on the plurality of backup quantum keys includes:
[0018] When this node is a slave node, it receives the identifiers of multiple backup quantum keys sent by the master node;
[0019] Based on the identifiers of the multiple backup quantum keys, obtain the corresponding multiple backup quantum keys from the local cryptographic device of the slave node;
[0020] A quantum key expansion sequence for a slave node is constructed based on a plurality of the said backup quantum keys, wherein the quantum key expansion sequence of the slave node is the same as that of the master node.
[0021] Optionally, before obtaining multiple backup quantum keys from the local cryptographic device of this node, the quantum key expansion method further includes:
[0022] Multiple backup quantum keys are obtained based on the quantum key distribution network;
[0023] Multiple backup quantum keys are sequentially stored in the local cryptographic device of this node.
[0024] Optionally, the quantum key distribution method further includes:
[0025] When this node is the master node, multiple new backup quantum keys are reacquired based on the quantum key distribution network according to preset update conditions;
[0026] Multiple new backup quantum keys are sequentially stored in the local cryptographic device of the master node;
[0027] An expansion update command is sent to the slave node so that the slave node synchronously acquires multiple new backup quantum keys according to the expansion update command and stores them sequentially in the slave node's local cryptographic device.
[0028] Optionally, after initiating an expansion update instruction to the slave node, the quantum key expansion method further includes:
[0029] Receive the quantum key update result from the slave node;
[0030] If the quantum key update result is successful, multiple new extended quantum keys are generated based on multiple new backup quantum keys and the original quantum key.
[0031] Secondly, embodiments of this application also provide a quantum key expansion device, which is applied to a local node accessing a quantum key distribution network. The quantum key expansion device includes:
[0032] The first acquisition unit is used to acquire multiple backup quantum keys from the local cryptographic device of this node, wherein the backup quantum keys are negotiated by the quantum key distribution network;
[0033] The second acquisition unit is used to acquire the original quantum key through negotiation based on the quantum key distribution network;
[0034] A generation unit is used to generate multiple expanded quantum keys based on multiple backup quantum keys and the original quantum key.
[0035] Thirdly, embodiments of this application also provide an apparatus, comprising:
[0036] A processor; and a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform any of the aforementioned quantum key augmentation methods.
[0037] Fourthly, embodiments of this application also provide a computer program product, including a computer program / instructions, which, when executed by a processor, implement any of the aforementioned quantum key expansion methods.
[0038] The at least one technical solution adopted in this application embodiment can achieve the following beneficial effects: The quantum key expansion method of this application embodiment is executed by the local node connected to the quantum key distribution network. First, multiple backup quantum keys are obtained from the local cryptographic device of the local node. The backup quantum keys are negotiated by the quantum key distribution network. Then, the original quantum key is obtained based on the negotiation of the quantum key distribution network. Finally, multiple expanded quantum keys are generated based on the multiple backup quantum keys and the original quantum key. The quantum key expansion method of this application embodiment, by using the quantum key distribution network to negotiate and generate multiple backup quantum keys, and using the multiple backup quantum keys to expand the original quantum key, can realize flexible expansion of quantum keys in a low-cost manner without increasing QKD device resources, thereby improving the performance of QKD device in generating quantum keys. Attached Figure Description
[0039] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0040] Figure 1 This is a flowchart illustrating a quantum key augmentation method according to an embodiment of this application;
[0041] Figure 2 This is a schematic diagram of a quantum key expansion process in an embodiment of this application;
[0042] Figure 3 This is a schematic diagram of the structure of a quantum key distribution device according to an embodiment of this application;
[0043] Figure 4 This is a schematic diagram of the structure of a device according to an embodiment of this application. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0045] The technical solutions provided by the various embodiments of this application are described in detail below with reference to the accompanying drawings.
[0046] The technical terms used in this application mainly include:
[0047] 1) QKD: Quantum Key Distribution, a technology that uses quantum mechanics as the information transmission carrier and the microscopic state of quantum mechanics as the information encoding basis to generate symmetric keys at both ends of the transmission. It refers to quantum key distribution technology or quantum key distribution equipment.
[0048] 2) QKDN: Quantum Key Distribution Network, is a new type of network technology that uses the principles of quantum mechanics to achieve secure key distribution.
[0049] The QKD protocol requires dedicated QKD equipment and optical fibers, or it can be implemented via quantum satellites and free space. In fiber-optic QKD networks, the point-to-point distance of the QKD protocol is generally no more than 100 kilometers. For long-distance communication, it is necessary to overcome the impact of transmission medium loss on the signal. In classical communication, amplifiers can be used to enhance the signal. However, in quantum networks, amplifiers cannot be used due to the no-cloning theorem. Based on quantum entanglement swapping, quantum entanglement relay can be realized, thereby achieving long-distance quantum communication. However, quantum relay technology is very difficult and not yet practical. Currently, the transitional solution used to build long-distance quantum key distribution infrastructure is the trusted repeater scheme.
[0050] The specific principle is as follows: Consider two end nodes A and B, and a trusted repeater R between them. A and R generate a key KAR through quantum key distribution. Similarly, R and B generate a key KRB through quantum key distribution. The process by which A and B generate a shared session key KAB through R is as follows: A encrypts KAB using KAR with a one-time pad (OTP) and sends it to R. R decrypts it to obtain KAB. R re-encrypts KAB using the key KRB and sends it to B. B decrypts it to obtain KAB. A and B then communicate encrypted using the shared key KAB.
[0051] This method of transmitting the key from A to B using a one-time pad technique achieves theoretically secure key distribution, which can theoretically prevent attacks from arbitrary external eavesdroppers. However, this scheme requires that every relay node be secure and trustworthy, resulting in low efficiency in practical key security relay. The performance of relay key generation is far lower than that of point-to-point quantum key generation via quantum key distribution protocols.
[0052] Taking a cryptographic application X by users Alice and Bob as an example, the two users access QKDN through a single QKD device. If the performance of synchronously outputting quantum keys on both sides is 1KB / h, and the key application uses the national cryptographic SM4 algorithm and the quantum key is fully utilized, then 1KB*1024 / 16B=64 keys can be generated at both ends per hour, and cryptographic application X can update the key approximately once per minute.
[0053] Assuming Alice and Bob add a new cryptographic application Y, and Y updates the SM4 key 64 times per hour, consistent with X, then when the quantum network's key output performance is 1KB / h, it's necessary to request twice the network resources from the QKDN operator, add one QKD device, and add a pair of fiber optic connections to provide higher quantum key output capabilities. The overall hardware and network service costs increase exponentially, necessitating expansion and upgrades to the user-side quantum network.
[0054] Since the security of existing quantum keys distributed via QKDN is based on the physical principle and information theory of "one-time pad", it is necessary to implement a low-cost quantum key expansion scheme with practical security on the basis of existing secure quantum key resources to support the flexible expansion of quantum key services.
[0055] Based on this, embodiments of this application provide a quantum key distribution method, such as... Figure 1 The diagram illustrates a flowchart of a quantum key distribution method according to an embodiment of this application. The quantum key distribution method is executed by the local node connected to the quantum key distribution network, and includes at least the following steps S110 to S130:
[0056] Step S110: Obtain multiple backup quantum keys from the local cryptographic device of this node. The backup quantum keys are negotiated by the quantum key distribution network.
[0057] Combination Figure 2 This application provides a schematic diagram of a quantum key expansion process according to an embodiment of the present application. The quantum key expansion method of this embodiment can be executed by any service node connected to a quantum key distribution network (QKDN) and requiring network transmission based on the QKDN. During quantum key expansion, multiple pre-generated backup quantum keys need to be obtained from the local cryptographic device of the node. These backup quantum keys can be understood as being generated based on existing QKD devices and the QKDN network according to existing quantum key output performance. Each node can negotiate and obtain multiple quantum keys based on QKDN, serving as the basis for subsequent quantum key expansion.
[0058] Step S120: Obtain the original quantum key through negotiation using a quantum key distribution network.
[0059] The quantum key augmentation object in this application embodiment is the original key generated in the "one-time pad" form in the original quantum key distribution scheme. Therefore, it is necessary to further negotiate and obtain the original quantum key based on the quantum key distribution network as the base key to be augmented.
[0060] Step S130: Generate multiple extended quantum keys based on the multiple backup quantum keys and the original quantum key.
[0061] Since the backup quantum key and the original quantum key are generated by the same principle, both satisfying the randomness inherent in quantum mechanics and the quantum no-cloning theorem, multiple backup quantum keys can be used to expand the original quantum key. The expanded quantum key also satisfies the randomness inherent in quantum mechanics and the quantum no-cloning theorem. Thus, the goal of expanding the number of quantum keys can be achieved without increasing the resources of the QKD device.
[0062] The quantum key expansion method in this application utilizes a quantum key distribution network to negotiate and generate multiple backup quantum keys, and then uses these backup quantum keys to expand the original quantum key. This enables flexible expansion of the quantum key capacity at low cost without increasing the resources of the QKD device, thereby improving the performance of the QKD device in generating quantum keys.
[0063] In some embodiments of this application, generating multiple expanded quantum keys based on multiple backup quantum keys and the original quantum key includes: constructing a quantum key expansion sequence for the current node based on multiple backup quantum keys; and generating multiple expanded quantum keys based on the quantum key expansion sequence and the original quantum key.
[0064] Continue to refer to Figure 2 When generating multiple augmented quantum keys, multiple backup quantum keys obtained from the local cryptographic device can be used to construct a quantum key augmentation sequence according to certain rules or algorithms, for example, represented as {k1, k2, ..., k...}. n It should be noted that the quantum key augmentation sequence constructed here can use the quantum key itself directly, or the quantum key can be transformed before use to further improve the key security. If the quantum key is transformed to generate the quantum key augmentation sequence, all service nodes need to agree on a consistent transformation method in advance and verify the consistency of the augmented sequence after transformation.
[0065] After obtaining the above quantum key augmentation sequence, it is necessary to construct the quantum key augmentation sequence {k1, k2, ..., k...} n The quantum key augmentation sequence is combined with the original quantum key obtained through QKDN negotiation to expand the original quantum key quantity to n times. The specific combination method between the quantum key augmentation sequence and the original quantum key can be, for example, a mathematical operation algorithm such as the XOR algorithm, etc., which is not specifically limited here.
[0066] In theory, as long as there are enough spare quantum keys, any number of augmented keys can be generated. In practical applications, the length n of the augmented sequence can be flexibly modified according to the requirements.
[0067] By expanding the original quantum key using pre-generated backup quantum keys, the number of quantum keys can be flexibly increased without increasing QKD device resources. This is particularly important for applications requiring high key update frequencies or a large number of keys. Compared to hardware expansion solutions such as adding QKD devices and fiber optic access, this avoids high hardware costs and complex network modifications, reducing the overall cost of the quantum key distribution system. Since both backup and original quantum keys are generated based on quantum mechanics principles and possess the inherent randomness and non-cloning properties of quantum mechanics, the expanded quantum keys also satisfy these security characteristics. This ensures the security of the expanded keys during transmission and use. By increasing the number of quantum keys, the performance of QKD devices in generating quantum keys can be improved, supporting more cryptographic applications and higher key update frequencies, thereby enhancing the overall security and reliability of the network.
[0068] In some embodiments of this application, the local node in the access quantum key distribution network is divided into a master node and a slave node. The step of constructing the quantum key expansion sequence of the local node based on the multiple backup quantum keys includes: when the local node is the master node, obtaining multiple backup quantum keys from the local cryptographic device of the master node; constructing the quantum key expansion sequence of the master node based on the multiple backup quantum keys; and sending the identifiers of the multiple backup quantum keys to all target slave nodes.
[0069] Continue to refer to Figure 2 In this application embodiment, the nodes can be distinguished as master nodes and slave nodes. In actual application scenarios, if two application nodes need to synchronize quantum keys, one application node must initiate the synchronization of quantum keys first. The application node that initiates the synchronization first can be defined as the master node.
[0070] When constructing the quantum key expansion sequence of this node, the master node can first obtain multiple pre-generated backup quantum keys from its own local cryptographic device, and construct the quantum key expansion sequence {k1, k2, ..., k} based on these multiple backup quantum keys. n At the same time, the IDs of these multiple backup quantum keys need to be sent to the peer node, i.e., the slave node that needs to be transmitted over the network, so that the slave node can perform the synchronous construction operation of the quantum key expansion sequence.
[0071] This application embodiment clearly distinguishes between master nodes and slave nodes, with the master node responsible for actively distributing backup quantum key identifiers, while the slave node only needs to perform synchronization construction operations according to the master node's instructions, thereby significantly improving the efficiency and accuracy of key synchronization.
[0072] In some embodiments of this application, constructing the quantum key expansion sequence of the local node based on the multiple backup quantum keys includes: when the local node is a slave node, receiving the identifiers of multiple backup quantum keys sent by the master node; obtaining the corresponding multiple backup quantum keys from the local cryptographic device of the slave node based on the identifiers of the multiple backup quantum keys; and constructing the quantum key expansion sequence of the slave node based on the multiple backup quantum keys, wherein the quantum key expansion sequence of the slave node is the same as the quantum key expansion sequence of the master node.
[0073] Continue to refer to Figure 2 For slave nodes that need to conduct network transmissions with the master node, they need to construct the corresponding quantum key augmentation sequence, just like the master node. Specifically, the slave node can receive multiple backup quantum key IDs sent by the master node. Based on these backup quantum key IDs, the slave node searches for and retrieves the corresponding quantum key in its local cryptographic device. These keys in the local cryptographic device were previously generated between the master and slave nodes through the quantum distribution process of QKDN and stored in their respective cryptographic devices.
[0074] After obtaining the corresponding backup quantum key, the slave node can also use these quantum keys to construct a quantum key expansion sequence in the same way. This sequence needs to be the same as the master node's quantum key expansion sequence to ensure that both parties can use the same key for encryption and decryption operations.
[0075] By having both master and slave nodes construct their own quantum key augmentation sequences, compared to the method of directly transmitting quantum key augmentation sequences from master to slave nodes, the security of the quantum key augmentation sequences can be further ensured, thereby avoiding security issues during transmission.
[0076] In some embodiments of this application, before obtaining multiple backup quantum keys from the local cryptographic device of the local node, the quantum key expansion method further includes: obtaining multiple backup quantum keys based on the quantum key distribution network; and storing the multiple backup quantum keys sequentially in the local cryptographic device of the local node.
[0077] Continue to refer to Figure 2 Before performing quantum key expansion, each node needs to negotiate and obtain multiple quantum keys through a quantum key distribution network. These keys are stored as backup keys in the local cryptographic device of each node for subsequent expansion. Based on the backup keys stored in the local cryptographic device, each node can retrieve these backup quantum keys from the cryptographic device when it needs to expand the quantum key sequence, and use these backup quantum keys to construct the quantum key expansion sequence.
[0078] By obtaining backup quantum keys in advance based on QKDN negotiation and storing them locally, the flexibility and security of backup quantum key management are improved.
[0079] In some embodiments of this application, the quantum key expansion method further includes: when the local node is the master node, acquiring multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions; storing the multiple new backup quantum keys sequentially in the local cryptographic device of the master node; and initiating an expansion update instruction to the slave node, so that the slave node synchronously acquires multiple new backup quantum keys according to the expansion update instruction and stores them sequentially in the local cryptographic device of the slave node.
[0080] Continue to refer to Figure 2 To further enhance the security of the extended quantum key, embodiments of this application can also update the backup quantum key when preset update conditions are triggered, such as reaching a preset update frequency or detecting a potential security threat. The master node can then initiate a key update process. The key update process aims to regenerate a new backup quantum key. Therefore, this process is also based on QKDN negotiation to obtain multiple new backup quantum keys and update the local storage. Subsequently, a new extended quantum key is generated based on the new backup quantum keys.
[0081] After confirming that the preset update conditions have been triggered, the master node also needs to synchronously send an extended update command to all slave nodes in the network. This command instructs the slave nodes to perform the operation of updating the backup quantum keys. Based on the extended update command, the slave nodes also synchronously obtain multiple new backup quantum keys using QKDN and update their local storage.
[0082] By employing preset update conditions and an automated key update process, the timely updating of backup quantum keys can be ensured, preventing potential security threats such as key leakage or attacks by quantum computers, thereby enhancing the overall security of the QKDN. The master node sends expansion update commands to the slave nodes, ensuring that all nodes can synchronously acquire and store the new backup key, thus maintaining the consistency of quantum key updates.
[0083] It should be noted that within the preset update cycle, if the node's local storage still has spare quantum keys, that is, if there are no spare quantum keys to generate the quantum key augmentation sequence, then this update can obtain them from the spare quantum keys, without having to re-negotiate them based on QKDN.
[0084] In some embodiments of this application, after initiating an expansion update instruction to the slave node, the quantum key expansion method further includes: receiving the quantum key update result from the slave node; and if the quantum key update result is successful, generating multiple new expanded quantum keys based on multiple new backup quantum keys and the original quantum key.
[0085] Continue to refer to Figure 2 After the master node sends an expansion update command to the slave node, it waits for and receives the quantum key update result returned by the slave node. This result can be a status message indicating whether the slave node has successfully updated the backup quantum key. If the slave node reports a successful update, the master node will continue to the next step; if a slave node reports an update failure, the master node may need to take additional measures, such as resending the update command or manually intervening to resolve the issue. After confirming that the slave node has successfully updated the key, the master node can enable the new backup quantum key, that is, it can use the new backup quantum key and the original quantum key to generate a new expansion quantum key.
[0086] By receiving and checking the quantum key update results from slave nodes, the master node can ensure that slave nodes have successfully synchronized and updated their backup quantum keys, thus guaranteeing the accuracy of subsequent key expansions. Regularly updating backup quantum keys and generating new expansion keys prevents potential key leaks and attacks, thereby enhancing the security of the entire quantum key distribution network.
[0087] This application also provides a quantum key distribution device 300, such as... Figure 3 The diagram shows a schematic of a quantum key distribution device according to an embodiment of this application. The quantum key distribution device is applied to a node accessing a quantum key distribution network. The quantum key distribution device 300 includes: a first acquisition unit 310, a second acquisition unit 320, and a generation unit 330, wherein:
[0088] The first acquisition unit 310 is used to acquire multiple backup quantum keys from the local cryptographic device of this node, wherein the backup quantum keys are negotiated by the quantum key distribution network.
[0089] The second acquisition unit 320 is used to acquire the original quantum key through negotiation based on the quantum key distribution network;
[0090] The generation unit 330 is used to generate multiple extended quantum keys based on the multiple backup quantum keys and the original quantum key.
[0091] In some embodiments of this application, the generation unit 330 is specifically used to: construct a quantum key expansion sequence for the current node based on a plurality of the backup quantum keys; and generate a plurality of the expanded quantum keys based on the quantum key expansion sequence and the original quantum keys.
[0092] In some embodiments of this application, the local node in the access quantum key distribution network is divided into a master node and a slave node. The generation unit 330 is specifically used to: obtain multiple backup quantum keys from the local cryptographic device of the master node when the local node is the master node; construct the quantum key expansion sequence of the master node based on the multiple backup quantum keys; and send the identifiers of the multiple backup quantum keys to all target slave nodes.
[0093] In some embodiments of this application, the generation unit 330 is specifically used for: receiving the identifiers of multiple backup quantum keys sent by the master node when the local node is a slave node; obtaining the corresponding multiple backup quantum keys from the local cryptographic device of the slave node according to the identifiers of the multiple backup quantum keys; constructing a quantum key expansion sequence of the slave node according to the multiple backup quantum keys, wherein the quantum key expansion sequence of the slave node is the same as the quantum key expansion sequence of the master node.
[0094] In some embodiments of this application, the quantum key expansion device 300 further includes: a third acquisition unit, configured to acquire multiple backup quantum keys based on the quantum key distribution network before acquiring multiple backup quantum keys from the local cryptographic device of the local node; and a first storage unit, configured to sequentially store the multiple backup quantum keys in the local cryptographic device of the local node.
[0095] In some embodiments of this application, the quantum key expansion device 300 further includes: an update unit, configured to, when the local node is the master node, reacquire multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions; a second storage unit, configured to sequentially store the multiple new backup quantum keys in the local cryptographic device of the master node; and an initiation unit, configured to initiate an expansion update instruction to the slave node, so that the slave node synchronously acquires multiple new backup quantum keys according to the expansion update instruction and sequentially stores them in the local cryptographic device of the slave node.
[0096] In some embodiments of this application, the quantum key expansion device 300 further includes: a receiving unit, configured to receive the quantum key update result of the slave node after initiating an expansion update instruction to the slave node; the generating unit is further configured to generate multiple new expanded quantum keys based on multiple new backup quantum keys and the original quantum key if the quantum key update result is successful.
[0097] It is understood that the above-described quantum key expansion device can implement all the steps of the quantum key expansion method provided in the foregoing embodiments. The relevant explanations of the quantum key expansion method are applicable to the quantum key expansion device, and will not be repeated here.
[0098] Figure 4 This is a schematic diagram of the structure of a device according to an embodiment of this application. For example... Figure 4 As shown, the device includes one or more processors (or processing units), and may also include one or more memories coupled to the processors, and may also include a communication module coupled to the processors.
[0099] A communication module can be used to communicate with other devices or apparatuses, such as sending or receiving data and / or signals. A communication module may have at least one communication module for communication. A communication module may include any interface necessary for communicating with other devices. Exemplarily, a communication module may be a transceiver, circuit, bus, module, or other type of communication module.
[0100] The processor may include, but is not limited to, one or more of the following: a general-purpose computer, a special-purpose computer, a microcontroller, a digital signal processor (DSP), or a controller-based multi-core controller architecture. The device may have multiple processors, such as application-specific integrated circuit (ASIC) chips, which are time-dependent on a clock synchronized with the main processor.
[0101] The memory may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: read-only memory (ROM), electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), or other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: random access memory (RAM), or other volatile memories that do not persist during the duration of a power outage.
[0102] A computer program consists of computer-executable instructions that are executed by an associated processor. Programs can be stored in ROM. A processor can perform any appropriate action and processing by loading the program into RAM.
[0103] Possible implementations of this application can be achieved through a program, enabling the communication device to execute any of the processes discussed in the foregoing embodiments. Possible implementations of this application can also be achieved through hardware or a combination of software and hardware.
[0104] In some implementations, the program may be tangibly contained in a computer-readable storage medium, which may include in a device (such as in memory) or other storage device accessible by the device. The program may be loaded from the computer-readable storage medium into RAM for execution. The computer-readable storage medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc.
[0105] This application also provides a computer-readable storage medium storing computer instructions or program code thereon, which, when executed by a processor, causes the processor to perform the methods and functions involved in any of the above embodiments. A computer-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. More detailed examples of computer-readable storage media include electrical connections with one or more wires, magnetic media (e.g., disks, floppy disks, hard disks, magnetic tapes, magnetic storage devices), optical media (e.g., optical storage devices, DVDs), semiconductor media (e.g., solid-state drives), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), or any suitable combination thereof.
[0106] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. Embodiments of this application also provide at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. This computer program product includes one or more computer-executable instructions, such as instructions included in a program module, which execute in a device on a target's real or virtual processor to perform the processes, methods, and functions involved in any of the above embodiments. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0107] This application also proposes a computer program product, including a computer program or instructions that, when run on a computer, cause the computer to perform the processes, methods, and functions described in the above embodiments. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or divided as needed. The machine-executable instructions for the program modules can be executed locally or in a distributed device. In a distributed device, the program modules can reside in both local and remote storage media.
[0108] Generally, the various embodiments of this application can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are shown and described as block diagrams, flowcharts, or represented using some other illustration, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented as, as non-limiting examples, in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0109] It should be noted that although embodiments of this application have been described above with reference to the accompanying drawings, these embodiments are not independent of each other, and they can be combined to obtain other embodiments. The methods, situations, categories, and classifications of embodiments in this application are only for the convenience of description and should not constitute a special limitation. Various methods, categories, situations, and features in embodiments can be combined with each other if logically consistent. The various embodiments of this application can be arbitrarily combined to achieve different technical effects. The embodiments of this application will not list various combinations.
[0110] Furthermore, although the operation of the methods of this disclosure is described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Rather, the steps depicted in the flowcharts may be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps. It should also be noted that the features and functions of two or more devices according to this disclosure may be embodied in one device. Conversely, the features and functions of one device described above may be further divided and embodied by multiple devices.
[0111] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0112] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.
Claims
1. A quantum key distribution method, characterized in that, The quantum key augmentation method is executed by the local node connected to the quantum key distribution network, and the quantum key augmentation method includes: Obtain multiple backup quantum keys from the local cryptographic device of this node, wherein the backup quantum keys are negotiated by the quantum key distribution network; The original quantum key is obtained through negotiation using a quantum key distribution network; Multiple extended quantum keys are generated based on the multiple backup quantum keys and the original quantum key; This node can be either a master node or a slave node; The multiple backup quantum keys are generated based on existing QKD devices and QKDN networks according to existing quantum key output performance; The process of generating multiple expanded quantum keys based on multiple backup quantum keys and the original quantum key includes: Construct the quantum key expansion sequence for this node based on multiple of the aforementioned backup quantum keys; Multiple augmented quantum keys are generated based on the quantum key augmentation sequence and the original quantum key; The quantum key augmentation sequence is obtained either by directly using the multiple backup quantum keys themselves or by transforming the multiple backup quantum keys based on a pre-agreed consistent transformation method between the nodes.
2. The quantum key distribution method according to claim 1, characterized in that, The step of constructing the quantum key expansion sequence for this node based on the multiple backup quantum keys includes: When the local node is the master node, multiple backup quantum keys are obtained from the local cryptographic device of the master node; Construct a quantum key expansion sequence for the master node based on multiple backup quantum keys; The identifiers of multiple backup quantum keys are sent to all target slave nodes.
3. The quantum key distribution method according to claim 2, characterized in that, The step of constructing the quantum key expansion sequence for this node based on the multiple backup quantum keys includes: When this node is a slave node, it receives the identifiers of multiple backup quantum keys sent by the master node; Based on the identifiers of the multiple backup quantum keys, obtain the corresponding multiple backup quantum keys from the local cryptographic device of the slave node; A quantum key expansion sequence for a slave node is constructed based on a plurality of the said backup quantum keys, wherein the quantum key expansion sequence of the slave node is the same as that of the master node.
4. The quantum key distribution method according to any one of claims 1 to 3, characterized in that, Before obtaining multiple backup quantum keys from the local cryptographic device of this node, the quantum key expansion method further includes: Multiple backup quantum keys are obtained based on the quantum key distribution network; Multiple backup quantum keys are sequentially stored in the local cryptographic device of this node.
5. The quantum key distribution method according to claim 4, characterized in that, The quantum key distribution method further includes: When this node is the master node, multiple new backup quantum keys are reacquired based on the quantum key distribution network according to preset update conditions; Multiple new backup quantum keys are sequentially stored in the local cryptographic device of the master node; An expansion update command is sent to the slave node so that the slave node synchronously acquires multiple new backup quantum keys according to the expansion update command and stores them sequentially in the slave node's local cryptographic device.
6. The quantum key distribution method according to claim 5, characterized in that, After sending an expansion update command to the slave node, the quantum key expansion method further includes: Receive the quantum key update result from the slave node; If the quantum key update result is successful, multiple new extended quantum keys are generated based on multiple new backup quantum keys and the original quantum key.
7. A quantum key distribution device, characterized in that, The quantum key augmentation device is used by the local node accessing the quantum key distribution network, and the quantum key augmentation device includes: The first acquisition unit is used to acquire multiple backup quantum keys from the local cryptographic device of this node, wherein the backup quantum keys are negotiated by the quantum key distribution network; The second acquisition unit is used to acquire the original quantum key through negotiation based on the quantum key distribution network; A generation unit is configured to generate multiple expanded quantum keys based on the multiple backup quantum keys and the original quantum key; This node can be either a master node or a slave node; The multiple backup quantum keys are generated based on existing QKD devices and QKDN networks according to existing quantum key output performance; The generation unit is specifically used for: Construct the quantum key expansion sequence for this node based on multiple of the aforementioned backup quantum keys; Multiple augmented quantum keys are generated based on the quantum key augmentation sequence and the original quantum key; The quantum key augmentation sequence is obtained either by directly using the multiple backup quantum keys themselves or by transforming the multiple backup quantum keys based on a pre-agreed consistent transformation method between the nodes.
8. An apparatus comprising: processor; And a memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform any of the quantum key augmentation methods of claims 1 to 6.
9. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the quantum key expansion method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Quantum cryptography network key relay dynamic routing method, device and system
CN117176345A
Key expansion method
CN117201012A