Optical network service protection method for physical layer eavesdropping risk and related equipment

By evaluating the eavesdropping risks of optical cables/pipes and designing heuristic algorithms, the optical network service protection method solves the physical layer eavesdropping risks faced by optical networks, realizes effective business path survivability calculation and eavesdropping risk resistance, and improves network security and carrying capacity.

CN120074653APending Publication Date: 2025-05-30BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510137113.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Optical networks face the risk of physical layer eavesdropping, and the existing technology is difficult to effectively resist the incidents of illegal attackers obtaining user privacy data through eavesdropping.

Method used

A method for business protection of optical networks oriented to the physical layer eavesdropping risk is proposed. By evaluating the eavesdropping risk of optical cables/pipelines, dividing shared eavesdropping risk link groups, determining symbiotic protection mechanisms, and designing heuristic algorithms to calculate the survivability path of service requests to resist eavesdropping attacks.

Benefits of technology

It realizes effective resistance to eavesdropping attacks, ensure transmission security, and improve network bearing capacity and security under low cost and low deployment complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074653A_ABST
    Figure CN120074653A_ABST
Patent Text Reader

Abstract

The invention provides a physical layer eavesdropping risk-oriented optical network service protection method and related equipment. The method comprises the following steps: determining an eavesdropping risk of an optical cable / pipeline based on optical cable accessibility and data confidentiality; dividing a shared eavesdropping risk link group based on the eavesdropping risk and hierarchical relationship of the optical cable / pipeline; optical fibers / links in the shared eavesdropping risk link group have risk identifiers of the same level; determining a symbiotic protection mechanism based on the shared eavesdropping risk link group and a service security demand; the symbiotic protection mechanism comprises the step of allowing a protection path of the security service to be a working path of a common service, and the working path of the common service is used as the protection path of the security service; determining a heuristic algorithm based on constraint conditions and a symbiotic protection mechanism; obtaining a service request for connecting a target node initiated by the node, an optical network topology and a risk identifier of an optical fiber / link; and calculating a survivability path of the service request through a heuristic algorithm. And the security of the optical network is improved through a survivability technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of optical network survivability, and particularly to an optical network service protection method and related devices for physical layer eavesdropping risks. Background Art

[0002] Optical networks have become the key infrastructure to support modern communications. The increasingly large optical networks carry more than 98% of the information transmission traffic. Events of eavesdropping to obtain user privacy data have been discovered, such as optical cables being eavesdropped, illegal eavesdropping devices being installed in optical networks, and a large number of undersea optical cable information interception events, etc. Illegal attackers can detect optical signals through simple operations such as bending, squeezing, or splitting. Therefore, with the increasing maturity of optical fiber eavesdropping technology, optical fiber networks face huge security threats.

[0003] Technical means mainly focused on protection can be used to resist optical network eavesdropping. Existing technical means mainly focused on protection mainly consider network failures, and there is little work targeting physical layer attacks. Moreover, the only existing work targeting physical layer attacks considers the physical layer attack type as service degradation attacks. Summary of the Invention

[0004] In view of this, the purpose of this application is to propose an optical network service protection method and related devices for physical layer eavesdropping risks.

[0005] Based on the above purpose, this application provides an optical network service protection method for physical layer eavesdropping risks, including:

[0006] Determine the eavesdropping risks of optical cables / ducts based on the reachability of optical cables and data confidentiality;

[0007] Divide shared eavesdropping risk link groups based on the eavesdropping risks of optical cables / ducts and hierarchical relationships; wherein, the optical fibers / links in the shared eavesdropping risk link groups have the same level of risk identification;

[0008] Determine a co - protection mechanism based on the shared eavesdropping risk link groups and service security requirements; the co - protection mechanism includes allowing the protection path of secure services to be the working path of ordinary services, and the working path of ordinary services to be the protection path of secure services;

[0009] Set constraint conditions; determine a heuristic algorithm based on the constraint conditions and the co - protection mechanism;

[0010] Obtain a service request from a node to connect to a target node, the optical network topology, and the risk identification of optical fibers / links; calculate the survivable path of the service request through the heuristic algorithm.

[0011] In some of these embodiments, calculating the survivable path of the service request through the heuristic algorithm includes:

[0012] Calculating an available path from the node to the target node;

[0013] In response to determining that the number of available paths is multiple, calculating the number of high-risk links in the multiple available paths, and determining the shortest available path with the number of high-risk links being 0 as the first working path;

[0014] Determining the shortest available path among the available paths that do not intersect with the first working path and do not have high-risk links as the first protection path; and adding the first protection path to the first co-survival path set; the first co-survival path set includes the working paths of secure services; or in response to determining that there are no available paths that do not intersect with the first working path and do not have high-risk links among the multiple available paths, determining the shortest available path that does not intersect with the first working path and does not have high-risk links in the second co-survival path set as the first protection path; the second co-survival path set includes the working paths of ordinary services;

[0015] Outputting the first working path and the first protection path as the survivable path of the service request.

[0016] In some of these embodiments, calculating the number of high-risk links in the multiple available paths is calculated by the formula Calculating; where is the number of high-risk links used by the working path of the secure service; κ sd is the risk identification set of the working path of the secure service; SELG H is the high-risk identification set;

[0017] The available paths that do not intersect with the first working path and do not have high-risk links among the multiple available paths satisfy where is the number of high-risk links used by the working path of the secure service; is the number of links where the working path and the protection path of the secure service intersect; κ *sd is the risk identification set of the protection path of the secure service.

[0018] In some of these embodiments, calculating the survivable path of the service request through the heuristic algorithm includes:

[0019] Calculating multiple available paths from the node to the target node;

[0020] In response to determining that the service type corresponding to the service request is a general service, select the shortest available path among the multiple available paths as the second working path, and add the second working path to the second symbiotic path set; the second symbiotic path set includes the working paths of general services; or in response to determining that there is no available path from the node to the target node and the service type corresponding to the service request is a general service, determine the shortest available path in the first symbiotic path set as the second working path; the first symbiotic path set includes the working paths of security services;

[0021] Output the second working path as the survivable path of the service request.

[0022] In some embodiments, the influencing factors of the optical cable reachability include optical cable inspection factors, optical cable length factors, optical cable burial depth factors, optical cable installation height factors, and armored protection factors; the influencing factors of the data confidentiality include encryption strength factors, key management factors, and eavesdropping detection factors;

[0023] The eavesdropping risk of the optical cable / duct is calculated by formula B = W·A; where B is the eavesdropping risk of the optical cable / duct; W is the weight of the influencing factors of the optical cable reachability and the influencing factors of the data confidentiality; A is the evaluation matrix; where, a ij is the membership degree of the i-th factor set factor to the j-th evaluation set element through the membership function.

[0024] In some embodiments, the membership function of the optical cable inspection factor is t Period is the inspection period;

[0025] The membership function of the optical cable length factor is L Reel is the optical cable length per unit reel; l is the deployed optical cable length;

[0026] The membership function of the optical cable burial depth factor is where h1 is the burial depth;

[0027] The membership function of the optical cable installation height factor is where h2 is the installation height;

[0028] The membership function of the armored protection factor is where, n Fibers is the number of optical fibers in the duct or optical cable, D Fiber is the optical fiber diameter; d Cable is the optical cable diameter;

[0029] The membership function of the encryption strength factor is Among them, l Key is the key length; L MAX is the maximum length;

[0030] The membership function of the key management factor is

[0031] The membership function of the wiretapping detection factor is MF Detect (p Accuracy ) = p Accuracy ; where p Accuracy is the detection accuracy.

[0032] In some embodiments, the risk identifier is set in the optical network control protocol message field or the optical network control platform database.

[0033] An embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in any one of the previous items is implemented.

[0034] An embodiment of the present application further provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method described in any one of the previous items.

[0035] An embodiment of the present application further provides a computer program product, including computer program instructions. When the computer program instructions run on a computer, the computer is caused to execute the method described in any one of the previous items.

[0036] As can be seen from the above, the optical network service protection method for physical layer wiretapping risk provided by the present application evaluates the link wiretapping risk and SELG based on the FCE theory, proposes the SP mechanism based on the link differential risk and service differential security requirements, designs the SPR algorithm based on the SP mechanism, and realizes reliable transmission of services with low wiretapping risk for security requirements, coexistence transmission of services with ordinary requirements and services with security requirements, and resists wiretapping attacks under the conditions of low cost and low deployment complexity. It not only ensures the transmission security, but also improves the network carrying capacity, and improves the security of the optical network through survivability technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the present application or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following description are only embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0038] Figure 1Schematic flowchart of the optical network service protection method for physical layer eavesdropping risk in the embodiments of the present application;

[0039] Figure 2 Flowchart of the heuristic algorithm in the embodiments of the present application;

[0040] Figure 3 Schematic diagram of defining SELG based on hierarchical relationship in the embodiments of the present application;

[0041] Figure 4 Example diagram of survivable path calculation based on the SPR algorithm in the embodiments of the present application;

[0042] Figure 5 Schematic diagram of the electronic device in the embodiments of the present application. Detailed implementation manners

[0043] To make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the following further elaborates on the present application in detail with reference to specific embodiments and the accompanying drawings.

[0044] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meanings understood by those of ordinary skill in the art to which the present application belongs. The "first", "second", and similar terms used in the embodiments of the present application do not denote any order, quantity, or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.

[0045] Fiber optic eavesdropping is a process of compromising the security of fiber optic cables by extracting or injecting information (in the form of light). Fiber optic eavesdropping can be basically divided into invasive and non-invasive. Invasive fiber optic eavesdropping requires cutting the fiber optic cable and reconnecting it to the eavesdropping device, while non-invasive fiber optic eavesdropping can achieve eavesdropping without cutting the fiber optic cable or causing any service interruption.

[0046] Among them, non-intrusive eavesdropping techniques specifically include five methods: fiber bending, optical splitting, attenuation coupling, V-groove cutting, and scattering. (1) The eavesdropping principle based on fiber bending is to bend the core of the stripped fiber so that some signal light escapes from the fiber to obtain the user's optical signal. (2) The eavesdropping principle based on optical splitting is to insert the target fiber into an optical splitter to steal some optical signals. (3) The eavesdropping principle based on attenuation coupling is to closely attach an illegal fiber to the target fiber polished to the core, so that part of the signal light leaks into the illegal fiber to achieve the purpose of signal theft. (4) The eavesdropping principle based on V-groove cutting is to cut the fiber cladding so that the optical signal leaks out from the V-notch. (5) The eavesdropping principle based on scattering is to etch a Bragg grating on the fiber to reflect part of the signal out of the fiber.

[0047] In summary, the core principle achieved by the five eavesdropping methods of non-intrusive eavesdropping techniques is to cause physical deformation on the surface layer of the fiber, affect the reflection process of the optical signal, and then leak part of the signal. This type of non-intrusive attack method will not interrupt the transmission of the optical signal, and will not reduce or only slightly reduce the quality of the optical signal, forming the characteristic of "attacking without destroying".

[0048] Four technical means mainly including monitoring, encryption, routing, and protection can be used to resist optical network eavesdropping. (1) Eavesdropping monitoring is a technology that senses the occurrence of eavesdropping attacks from the source by deploying additional sensor devices. Combining with the remaining three technologies can greatly improve network security. (2) Physical layer signal encryption realizes the real-time encryption of electrical / optical signals by deploying encryption chips or devices. Even if illegal attackers intercept the user signal, they cannot decipher it. Although it introduces a certain encryption delay and power consumption, it greatly guarantees the security of data transmission. (3) Security routing technology avoids services passing through untrusted nodes / links by deploying a trusted routing algorithm in the control plane. Although the deployment cost is low and the deployment complexity is small, the characteristic of not changing after one-time calculation results in slightly poor security of this method. (4) Survivability technologies (including protection switching technology and restoration technology) regard the attack as a special fault in the control plane, implement pre-protection before the attack and real-time restoration after the attack to ensure service reliability and security.

[0049] Therefore, compared with the technical means of monitoring, encryption, and routing, survivability technologies have the advantages of low cost and easy deployment.

[0050] The survivability of an optical network refers to the ability of the optical network to keep the services running normally in the face of failures. To ensure the stability and reliability of the network, fault detection technology, fault location technology, service protection technology, and fault recovery technology together constitute the survivability technology. Traditional service protection technology is to use network redundant resources to plan multiple service transmission paths before a failure occurs, so as to achieve the effect that there is a path available for the service after the failure occurs. Common protection methods are divided into two types: dedicated protection and shared protection. Dedicated protection configures a separate Backup Path (BP) that is not shared with other services for each Working Path (WP), which has the advantages of simplicity and speed and the disadvantage of high cost. Shared protection allows multiple WPs to share the same one or more BPs, which has the advantage of low cost and the disadvantage of high complexity.

[0051] In addition, when calculating the survivability paths (WP and BP), the constraints of SRLG (Shared Risk Link Group) are also considered. SRLG represents a group of links or resources that share the same failure risk source, and it can be considered from the perspective of hierarchical correlation and location correlation. First, SRLG has hierarchical correlation. In an optical network divided into the physical layer, transport layer, and IP layer, the lower-layer links may carry multiple upper-layer services. When a lower-layer link fails, all services on it will be interrupted. For example, in the actual deployment of a communication network, optical fibers are usually laid in ducts, and multiple optical fibers may be laid in the same duct. When the duct is damaged, all the optical fibers inside it may fail, so these optical fibers share risks. Second, SRLG has location correlation. When disasters such as earthquakes, floods, or wars occur, adjacent links in a certain area may be damaged simultaneously, so these links share risks. By considering the SRLG constraints, the WP and BP will not pass through links with the same SRLG at the same time, so as to reduce the situation where the survivability paths are unavailable at the same time and improve the network reliability.

[0052] In a related technology, for the physical layer attack of service degradation, an attack-aware dedicated path protection technology is studied. The number of services that may be affected by a single attack at the same time is defined by the attack group identifier. An attack-aware dedicated path protection method is designed based on the concept of the attack group, with the non-intersection of attack groups as the new constraint condition and the lowest cost as the optimization goal to establish the WP and BP, enhancing the attack protection ability. In another related technology, for the single-point failure problem, a priority shared protection algorithm based on path segmentation is studied. Under the condition of considering the SRLG constraints, by preferentially using the links occupied by the BPs of other services, the network sharing degree is improved, the service blocking rate is reduced, but the service recovery time is increased.

[0053] In summary, the existing survivability technologies related to service protection mainly consider network failures, and there is little work on physical layer attacks. Moreover, the only existing work considers the physical layer attack type as service degradation attack.

[0054] However, the change of the research object from network failures to eavesdropping attacks makes traditional survivability technologies inapplicable to new scenarios. First, the impact of eavesdropping attacks on link availability is reduced, so it may not be able to trigger traditional protection mechanisms, resulting in the inability to defend against the continuous theft of user signals by eavesdropping attacks. Second, eavesdropping attacks change the link security risks, and traditional protection technologies cannot be compatible with different eavesdropping risks. Because of the differences in network construction, the risks of optical network infrastructure being eavesdropped are different. For example, there are ways such as overhead laying and buried pipeline laying for optical cable laying, so the corresponding eavesdropping difficulties are different, and the eavesdropping risks are also different. Third, eavesdropping attacks change the service requirements, and traditional protection technologies cannot handle the security requirements of diversified services. For example, government and enterprise units require high security guarantees, enterprise parks require ordinary security guarantees, and streaming media enterprises require low security guarantees, etc.

[0055] All in all, eavesdropping attacks have caused changes in protection mechanisms, link attributes, and service requirements, while traditional protection technologies are not applicable to these changes.

[0056] Based on this, the embodiments of the present application provide an optical network service protection method and related devices for physical layer eavesdropping risks. Based on the service protection technology in optical network survivability technology, by defining eavesdropping risks and SELG (Shared Eavesdropping Risk Link Group), a SP (Symbiotic Protection) mechanism is proposed, and a heuristic algorithm is designed, which can form a service-specific protection technology with eavesdropping risk perception with the goal of improving security. It can reduce the probability of services being eavesdropped and improve network security. Compared with technical means such as monitoring, encryption, and routing, it has the advantages of low cost and easy deployment.

[0057] As Figure 1 shown, the optical network service protection method for physical layer eavesdropping risks provided by the embodiments of the present application, the optical network service protection method for physical layer eavesdropping risks may include:

[0058] S100, determine the eavesdropping risks of optical cables / pipelines based on the reachability of optical cables and data confidentiality;

[0059] S200, divide the shared eavesdropping risk link group (SELG) based on the eavesdropping risks and hierarchical relationships of optical cables / pipelines; wherein, the optical fibers / links in the shared eavesdropping risk link group (SELG) have the same level of risk identification;

[0060] S300, determine a symbiotic protection mechanism (SP) based on the shared eavesdropping risk link group and service security requirements; the symbiotic protection mechanism includes allowing the protection path (BP) of a secure service to be the working path (WP) of a normal service, and the working path (WP) of the normal service to be the protection path (BP) of the secure service;

[0061] S400, set constraint conditions; determine a heuristic algorithm based on the constraint conditions and the symbiotic protection mechanism (SP mechanism);

[0062] S500, obtain a service request initiated by a node to connect to a target node, the optical network topology, and the risk identifier of the optical fiber / link; calculate the survivable path of the service request through the heuristic algorithm.

[0063] The optical network service protection method for physical layer eavesdropping risk provided by the embodiments of the present application defines the eavesdropping risk of optical fiber cables and defines a shared eavesdropping risk link group (SELG) based on the layer relationship; a symbiotic protection mechanism (SP) is proposed, which allows multiple types of services to be each other's working path (WP) and protection path (BP), improving network resource utilization and security, and designing a heuristic algorithm based on the symbiotic protection mechanism (SP mechanism) to resist eavesdropping attacks under the conditions of low cost and low deployment complexity. It not only ensures transmission security but also improves network carrying capacity.

[0064] At the same time, the optical network service protection method for physical layer eavesdropping risk provided by the embodiments of the present application has: (1) Compatibility: The mechanism and algorithm are compatible with existing systems and can be seamlessly integrated into a software-defined controller to provide management functions; (2) Cost: The deployment cost is relatively low because it can utilize existing control and management platforms; (3) Additional requirements: No additional software resources and hardware resources are required. Therefore, the optical network service protection method for physical layer eavesdropping risk provided by the embodiments of the present application can be applied to actual systems.

[0065] In some of these embodiments, in step S100, the wiretapping risk may represent the possibility of illegally obtaining user information from an optical network link. The optical cable accessibility can be understood as an external factor for wiretapping risk assessment. Data confidentiality can be understood as an internal factor for wiretapping risk assessment. Among them, the optical cable accessibility can indicate whether the optical cable is easily accessible to illegal parties, and there are two types of factors: time and space. Among them, the time factor may include optical cable inspection, and the space factors may include optical cable length, optical cable burial depth, optical cable mounting height, and armor protection, etc. That is to say, the influencing factors of the optical cable accessibility may include the optical cable inspection factor, the optical cable length factor, the optical cable burial depth factor, the optical cable mounting height factor, and the armor protection factor. Among them, data confidentiality can indicate whether an optical signal is easily deciphered, and the influencing factors may include encryption strength, key management, and wiretapping detection, etc. That is to say, the influencing factors of the data confidentiality include the encryption strength factor, the key management factor, and the wiretapping detection factor.

[0066] In some of these embodiments, through the evaluation system composed of the above factors for wiretapping risk assessment, combined with the FCE theory, the wiretapping risk can be quantified, that is, the wiretapping risk of the optical cable / duct can be determined. Among them, FCE is a comprehensive evaluation method based on fuzzy mathematics, which can convert qualitative evaluation into quantitative evaluation. FCE usually requires a given factor set, evaluation set, evaluation matrix, and factor weights to obtain a fuzzy comprehensive evaluation.

[0067] In some of these embodiments, in the determination of the wiretapping risk of the optical cable / duct in the embodiments of the present application, the evaluation set can represent the wiretapping risk and can include elements of multiple different levels to represent multiple types of risks. Specifically, the levels of the elements that can be included can be determined according to the actual situation during actual deployment. For example, it can include two elements, "high" and "low", that is, E = {high risk, low risk}. In the following, only including two elements will be used for illustrative purposes. The factor set can represent the factors affecting the wiretapping risk, and specifically can include all the factors in the aforementioned optical cable accessibility and data confidentiality. For example, the factor set can include R = {r 1 , r 2 , …, r 7}. The factor weights can represent the importance of the aforementioned factors affecting the wiretapping risk. For example, they can be default set to 1, that is, W = {1, 1, …, 1}. The evaluation matrix can include the membership degrees of each factor affecting the wiretapping risk to the evaluation. Finally, the membership degrees of all factors affecting the wiretapping risk to the evaluation can be weighted, and finally the level of the wiretapping risk of the optical cable can be quantitatively determined.

[0068] In some of these embodiments, the wiretapping risk of the optical cable / duct can be calculated by the formula B = W · A(8). Among them, B is the wiretapping risk of the optical cable / duct; W is the weight of the influencing factors of the optical cable accessibility and the influencing factors of the data confidentiality; A is the evaluation matrix. where a ij is the membership degree of the i-th factor set factor to the j-th evaluation set element through the membership function. The rows of the evaluation matrix represent the evaluation set, and the columns of the evaluation matrix represent the factor set.

[0069] In some embodiments, the membership degree of the corresponding element can be obtained through the membership function of the factors in the factor set. Among them, for the optical cable inspection factor, the inspection frequency can be used as the membership function, as shown in Equation 1, which conforms to the characteristic that the optical cable inspection is to regularly eliminate potential safety hazards of the optical cable system through the inspection system. Specifically, the membership function of the optical cable inspection factor can be t Period can be the inspection period, for example, it can be 1 month, 3 months, or 12 months, etc. MF Patrol is the membership function of the optical cable inspection factor.

[0070] In some embodiments, the membership function of the optical cable length can be the reciprocal of the number of cable reels, and the membership degree can be positively correlated with the optical cable length. Specifically, the membership function of the optical cable length factor can be where L Reel is the optical cable length per unit reel, for example, it can be 2000 km. l can be the deployed optical cable length. MF Length is the membership function of the optical cable length factor.

[0071] In some embodiments, the membership functions of the optical cable burial depth and the optical cable mounting height can be the reciprocal of the burial depth or the installation height h, as shown in Equation 3. This can conform to the characteristic that the farther the optical cable is from the ground, the more difficult it is for the attacker to deploy the eavesdropping device. Specifically, the membership function of the optical cable burial depth factor can be where h1 is the burial depth. The membership function of the optical cable mounting height factor is where h2 is the installation height. MF Distance is the membership function of the optical cable burial depth factor / optical cable mounting height factor.

[0072] In some embodiments, the membership function of the armored protection factor can be as shown in Equation (4), which can represent the high-strength protection ability composed of various materials (for example, metal conductors, XLPE insulation, semiconductors, PVC sheaths, etc.) laminated layer by layer. Specifically, the membership function of the armored protection factor can be where n Fibers can be the number of optical fibers in the pipeline or the optical cable, D Fiber can be the optical fiber diameter (for example, it can be a 250 μm optical fiber); d Cable is the optical cable diameter. Among them, MF Armor is the membership function of the armored protection factor.

[0073] In some of these embodiments, the membership function of the encryption strength factor may be determined by the key length l Key and the maximum length L MAX to evaluate the membership degree, as shown in Equation (5). Specifically, the membership function of the encryption strength factor may be where l Key is the key length; L MAX is the maximum length. MF Encrypt (l Key ) is the membership function of the encryption strength factor.

[0074] In some of these embodiments, the membership function of key management may be a probability mass function following a Bernoulli distribution. In this way, it can conform to the characteristics of the key management system in managing key generation, exchange, storage, destruction, and replacement. Among them, the membership function of the key management factor may be

[0075]

[0076] In some of these embodiments, the membership function of the wiretap detection factor may be MF Detect (p Accuracy ) = p Accuracy (7). Among them, p Accuracy is the detection accuracy. MF Detect is the membership function of the wiretap detection factor. In this way, the security of the optical network can be greatly enhanced through a high-precision anomaly detection scheme.

[0077] In some of these embodiments, in step S200, the Shared Eavesdropping Risk Link Group (SELG) may represent a group of links or resources sharing the same eavesdropping risk source. Generally, after evaluating the optical cable / duct eavesdropping risk through step S100, the optical fibers / links therein have the same SELG risk identifier. Based on the level of eavesdropping risk, there are also high and low SELG risk identifiers. Specifically, the high-risk level SELG identifier set can be represented by SELG H , for example, it can be The low-risk level SELG identifier set can also be represented by SELG L , for example, it can be

[0078] In some of these embodiments, the risk identifier may be set in the optical network management protocol message field or the optical network management platform database.

[0079] In some of these embodiments, in step S300, based on the work of evaluating the wiretapping risk on the link side in steps S100 and S200, the emerging business security requirements, and combining the changes on the link side and the requirement side, a symbiotic protection mechanism (SP mechanism) is introduced. For business security requirements: First, there are security requirements and ordinary requirements for the business. The business with security requirements needs to ensure that the wiretapping risk of the transmission path is minimized. The business with ordinary requirements can be regarded as insensitive to wiretapping, and the requirements for wiretapping risk are slightly looser. Second, a wiretapping attack can be regarded as a special type of fault, which has the characteristic of "fault but not interruption", which means that the wiretapping party will not interrupt the communication process. Although the link is still available, in the face of the problem of data leakage, it is still necessary to consider whether the service needs to be switched, whether the link should be used, and who the link should be used for. Therefore, in the face of new service types and new attack scenarios, the embodiments of the present application determine a symbiotic protection mechanism (SP mechanism) based on the shared wiretapping risk link group and business security requirements, combined with the changes on the link side and the requirement side.

[0080] In some of these embodiments, the central idea of the SP mechanism is to allow secure services and ordinary services to be each other's working paths (WP) and backup paths (BP). For ordinary services, by default, their security requirements are low and they are insensitive to wiretapping. Therefore, only calculating the WP can meet the transmission requirements. For secure services, both the WP and the BP are required to ensure the leak-free transmission of data. When wiretapping occurs on the WP, it will be switched to the BP for transmission. And both the WP and the BP require a low wiretapping risk. In addition, since wiretapping does not interrupt the communication process, ordinary services can coexist with secure services, that is, the BP of a secure service can be the WP of an ordinary service. When wiretapping occurs on the WP, the two services will be switched together. Therefore, the secure service remains secure, while the ordinary service can tolerate and resist wiretapping. That is to say, the symbiotic protection mechanism may include allowing the protection path of a secure service to be the working path of an ordinary service, and the working path of an ordinary service as the protection path of a secure service.

[0081] In some of these embodiments, in step S400, the constraint mechanism may include a wiretapping risk constraint, a risk identifier (SELG) disjoint constraint, and a symbiotic constraint. Among them, the wiretapping risk constraint may indicate that a secure service should not use a link marked with a high-risk level SELG, and an ordinary service should use links marked with a high-risk SELG less frequently. The risk identifier disjoint constraint (that is, the SELG disjoint constraint) may indicate that the SELG identifiers of the links used by the WP and the BP are different. The symbiotic constraint may indicate that the WP of an ordinary service can be used as the BP of a secure service.

[0082] In some of these embodiments, based on the previously determined SP mechanism and the previously mentioned constraint mechanism, an SPR algorithm can be determined. The process of the SPR algorithm can be as Figure 2As shown. The input part of the algorithm may include: a service request F for connecting node d initiated from node s sd , an optical network topology G(V, E) including a node set V and a link set E, a low-risk SELG identifier SELG L , a high-risk SELG identifier SELG H . After the input, the calculation starts. During the calculation, first, the service should use a newly established path to ensure high reliability, and enable a symbiotic mechanism for services that cannot establish a new path to increase capacity. Therefore, K available paths P from s to d are calculated through the K-path algorithm avl . Second, if the current is an ordinary service, then select the shortest available path from the K available paths P avl as WP and add it to the symbiotic path set (such as the second symbiotic path set). It should be understood that the WP of the ordinary service is saved in the symbiotic path set and can be provided to the security service as BP. If there is no available path in P avl , then select the shortest path from the symbiotic path set (such as the first symbiotic path set). If there is no WP, the service is blocked. Finally, if the current is a security service, a new WP needs to be established according to Equation 10 to ensure security. Unless the WP exists, otherwise the service will be blocked. If a BP is also established from P avl according to Equation 11, it should be added to the symbiotic path set Otherwise, select the shortest path from the symbiotic path set . If the path calculation is successful, output the survivable path and end the algorithm

[0083] In some of these embodiments, in step S500, calculating the survivable path of the service request through the heuristic algorithm may include:

[0084] Calculating the available paths from the node to the target node (such as K available paths P avl ).

[0085] In response to determining that the number of the available paths is multiple and the service type corresponding to the service request is a security service, calculating the number of high-risk links (such as links with a high-risk SELG identifier SELG avl ) in the multiple available paths (such as K available paths P H ), and determining the shortest available path with the number of high-risk links being 0 as the first working path

[0086] Determine the shortest available path among the available paths that do not intersect with the first working path and do not have high-risk links among the multiple available paths as the first protection path; and add the first protection path to the first co-existing path set; the first co-existing path set includes the working paths of security services; or in response to determining that there is no available path among the multiple available paths that does not intersect with the first working path and does not have high-risk links, determine the shortest available path that does not intersect with the first working path and does not have high-risk links in the second co-existing path set as the first protection path; the second co-existing path set includes the working paths of ordinary services;

[0087] Output the first working path and the first protection path as the survivable paths for the service request.

[0088] In some embodiments, the number of high-risk links in the multiple available paths is calculated by the formula Calculate; where is the number of high-risk links used by the working path of the security service; κ sd is the risk identification set of the working path of the security service; SELG H is the high-risk identification set. In this way, the transmission path of the security service will not use high-risk links, but only use low-risk SELG links, which can maximize the security.

[0089] In some embodiments, the available paths among the multiple available paths that do not intersect with the first working path and do not have high-risk links satisfy where where is the number of high-risk links used by the working path of the security service; is the number of links where the working path and the protection path of the security service intersect; κ *sd is the risk identification set of the protection path of the security service. In this way, the risk that low-risk links may still be wiretapped can be considered, and the principle of non-intersection constraint of the risk identification (SELG) followed by the protection path of the security service is satisfied, that is, it is satisfied that the WP and BP of the security service will not use links with the same SELG identification.

[0090] In some embodiments, calculating the survivable path of the service request through the heuristic algorithm may include:

[0091] Calculate multiple available paths from the node to the target node (for example, K available paths P avl );

[0092] In response to determining that the service type corresponding to the service request is an ordinary service, select the shortest available path among the multiple available paths as the second working path, and add the second working path to the second co - existing path set; the second co - existing path set includes the working paths of ordinary services; or in response to determining that there is no available path from the node to the target node and the service type corresponding to the service request is an ordinary service, determine the shortest available path in the first co - existing path set as the second working path; the first co - existing path set includes the working paths of security services.

[0093] Output the second working path as the survivable path of the service request.

[0094] In this way, the SPR algorithm can establish survivable paths for ordinary services and security services. The survivable paths of security services are premised on security, ensuring the riskiness and intersection of the paths. The survivable paths of ordinary services are allowed to co - exist with the paths of security services, improving the network carrying capacity.

[0095] Embodiment

[0096] 1 SELG Evaluation

[0097] The SELG evaluation can include two aspects of work. One is to determine the risk of optical cable / pipeline eavesdropping, and the other is to divide the SELG based on the hierarchical relationship.

[0098] First, given the factor set, evaluation set, evaluation matrix, and factor weights required for FCE. The factor set includes factors such as optical cable inspection and optical cable length, as shown in the factor column of Table 1. The evaluation set includes two items: low risk and high risk. Calculate the evaluation matrix based on the membership function, as shown in the low - risk column and high - risk column of Table 1. Assuming the factor weights are (0.1, 0.1, 0.2, 0.1, 0.2, 0.1, 0.2), the eavesdropping risk is calculated as B = W·A = (73.1%, 26.9%) through the aforementioned formula 9. Therefore, it can be determined that the optical cable / pipeline is of low risk.

[0099] Table 1 Example of Evaluating the Risk of Optical Cable / Pipeline Based on FCE

[0100]

[0101] Secondly, based on the evaluated risk of optical cable / pipeline eavesdropping, all the links carried therein share the same SELG. Among them, Figure 3 shows the physical optical cable pipeline laying topology diagram. Since the optical cable pipeline connecting Building A and Building B is evaluated as having a high eavesdropping risk, the two links 1 - 2 and 1 - 3 transmitted thereon share the high eavesdropping risk and are labeled as In addition to the high eavesdropping risk, since links 1-2 and 1-3 also pass through the optical cable duct connecting buildings B and C, they also share a low eavesdropping risk, which is identified as

[0102] 2. Survivable Path Calculation

[0103] Figure 4 An example of the SP mechanism and the SPR for calculating survivable paths is shown. Given a five-node network with SELG tags, and two services successively sending requests, both connecting from node 1 to node 5. The ordinary service first sends a service request, as shown in part a of Figure 4 . There are three available transmission paths in the current network, namely 1-5, 1-2-3-5, and 1-4-5. Based on the shortest path first principle, the ordinary service selects path 1-5 as the WP. That is, the ordinary service uses the solid black arrow line as the WP based on the shortest path principle, as shown in part a of Figure 4 . Thereafter, the secure service sends a service request. Since the secure service cannot use link 1-2 with high-risk SELG, and the SELGs of links 2-3 and 1-5 intersect, only one of the transmission paths 1-2-3-5 and 1-5 can be used, and the transmission path 1-5 is occupied by the ordinary service, so only path 1-4-5 can be used as the WP, as shown in part b of Figure 4 . In addition to the WP, the secure service also needs the BP. Therefore, under the coexistence constraint of the SP mechanism, the secure service uses the dashed black arrow line as the WP, and the transmission path of the ordinary service is used as the BP of the secure service, as shown in part c of Figure 4 . In addition, assuming that link 1-2 does not contain high-risk SELG, the secure service can only select one of the transmission paths 1-2-3-5 and 1-5 for use because the SELGs of links 2-3 and 1-5 intersect. In summary, the survivable path can be calculated for the service based on the SPR algorithm.

[0104] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the optical network service protection method for physical layer eavesdropping risk described in any of the above embodiments.

[0105] Figure 5 Fig. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.

[0106] The processor 1010 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0107] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0108] The input / output interface 1030 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0109] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to achieve communication and interaction between this device and other devices. Among them, the communication module can achieve communication through a wired method (such as USB, network cable, etc.) or can also achieve communication through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).

[0110] The bus 1050 includes a path for transmitting information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0111] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and do not necessarily include all the components shown in the figure.

[0112] The electronic device of the above embodiment is used to implement the optical network service protection method for physical layer eavesdropping risk corresponding to any one of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0113] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the optical network service protection method for physical layer eavesdropping risk as described in any of the above embodiments.

[0114] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0115] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the optical network service protection method for physical layer eavesdropping risk as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0116] Based on the same inventive concept, corresponding to the optical network service protection method for physical layer eavesdropping risk described in any of the above embodiments, the present disclosure also provides a computer program product including computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of the computer to cause the computer and / or the processor to execute the optical network service protection method for physical layer eavesdropping risk. Corresponding to the execution subjects corresponding to the steps in each embodiment of the optical network service protection method for physical layer eavesdropping risk, the processor executing the corresponding steps can belong to the corresponding execution subject.

[0117] The computer program product of the above embodiment is used to cause the computer and / or the processor to execute the optical network service protection method for physical layer eavesdropping risk as described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0118] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present application (including the claims) is limited to these examples; under the concept of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and for the sake of brevity, they are not provided in detail.

[0119] In addition, for the sake of simplicity of description and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In the case where specific details (such as circuits) are set forth to describe the exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0120] Although the present application has been described in connection with specific embodiments of the present application, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0121] The embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application shall be included within the protection scope of the present application.

Claims

1. A method for protecting optical network services against physical layer eavesdropping risks, characterized in that: include: Determine the eavesdropping risk of optical cables / ducts based on cable accessibility and data confidentiality; Based on the eavesdropping risk and hierarchical relationship of the optical cable / pipeline, a shared eavesdropping risk link group is divided; wherein the optical fibers / links in the shared eavesdropping risk link group have the same level of risk identification; Based on the shared eavesdropping risk link group and the service security requirements, a symbiotic protection mechanism is determined; the symbiotic protection mechanism includes allowing the protection path of the security service to be the working path of the ordinary service, and the working path of the ordinary service to be the protection path of the security service; Setting constraint conditions; determining a heuristic algorithm based on the constraint conditions and the symbiotic protection mechanism; A service request initiated by a node to connect to a target node, an optical network topology, and a risk identifier of an optical fiber / link are obtained; and a survivable path of the service request is calculated by the heuristic algorithm.

2. The optical network service protection method for physical layer eavesdropping risk according to claim 1 is characterized in that: The calculating the survivability path of the service request by the heuristic algorithm comprises: Calculating available paths from the node to the target node; In response to determining that the number of available paths is multiple and the service type corresponding to the service request is a security service, calculating the number of high-risk links in the multiple available paths, and determining the shortest available path with zero high-risk links as the first working path; Determine the shortest available path among the multiple available paths that do not intersect with the first working path and do not have a high-risk link as a first protection path; and add the first protection path to a first symbiotic path set; the first symbiotic path set includes working paths for secure services; or in response to determining that there is no available path among the multiple available paths that does not intersect with the first working path and does not have a high-risk link, determine the shortest available path in a second symbiotic path set that does not intersect with the first working path and does not have a high-risk link as the first protection path; the second symbiotic path set includes working paths for ordinary services; The first working path and the first protection path are output as survivable paths requested by the service.

3. The optical network service protection method for physical layer eavesdropping risk according to claim 2 is characterized in that: The number of high-risk links in the plurality of available paths is calculated by the formula Calculate; where, The number of high-risk links used by the working path for security services; κ sd A collection of risk identifiers for work paths of security services; SELG H A collection of high-risk markers; The available paths among the multiple available paths that do not intersect with the first working path and do not have a high-risk link satisfy in, The number of high-risk links used for working paths of security services; The number of links where the working path and protection path of the security service intersect; κ *sd A collection of risk identifiers for security business protection paths.

4. The optical network service protection method for physical layer eavesdropping risk according to claim 1 is characterized in that: The calculating the survivability path of the service request by the heuristic algorithm comprises: Calculating multiple available paths from the node to the target node; In response to determining that the service type corresponding to the service request is a common service, selecting the shortest available path among the multiple available paths as a second working path, and adding the second working path to a second symbiotic path set; the second symbiotic path set includes working paths for common services; or in response to determining that there is no available path from the node to the target node, and the service type corresponding to the service request is a common service, determining that the shortest available path in the first symbiotic path set is the second working path; the first symbiotic path set includes working paths for secure services; The second working path is output as a survivability path of the service request.

5. The optical network service protection method for physical layer eavesdropping risk according to claim 1 is characterized in that: The factors affecting the accessibility of the optical cable include the factors of optical cable inspection, the factors of optical cable length, the factors of optical cable burial depth, the factors of optical cable height and the factors of armor protection; the factors affecting the data confidentiality include the factors of encryption strength, the factors of key management and the factors of eavesdropping detection; The eavesdropping risk of the optical cable / pipeline is calculated by the formula B=W·A; wherein B is the eavesdropping risk of the optical cable / pipeline; W is the weight of the influencing factors of the optical cable accessibility and the influencing factors of the data confidentiality; A is the evaluation matrix; Among them, a ij It is the membership degree of the i-th factor set factor to the j-th evaluation set element through the membership function.

6. The optical network service protection method for physical layer eavesdropping risk according to claim 5, characterized in that: The membership function of the optical cable inspection factor is: t Period is the inspection cycle; The membership function of the optical cable length factor is L Reel is the length of the optical cable per reel; l is the length of the deployed optical cable; The membership function of the optical cable burial depth factor is: Among them, h1 is the burial depth; The membership function of the optical cable height factor is: Among them, h2 is the installation height; The membership function of the armor protection factor is Among them, n Fibers is the number of optical fibers in the duct or cable, D Fiber is the fiber diameter; d Cable is the cable diameter; The membership function of the encryption strength factor is Among them, l Key is the key length; L MAX is the maximum length; The membership function of the key management factor is The membership function of the eavesdropping detection factor is MF Detect (p Accuracy )=p Accuracy ; Among them, p Accuracy For detection accuracy.

7. The optical network service protection method for physical layer eavesdropping risk according to claim 1 is characterized in that: The risk identifier is set in the optical network management and control protocol message field or in the optical network management and control platform database; The constraint mechanism includes eavesdropping risk constraint, risk identification disjoint constraint and symbiosis constraint.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 7 when executing the program.

9. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 7.

10. A computer program product, comprising computer program instructions, which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 7.