Optical information security encryption transmission system and method based on quantum key distribution
By adopting an optical information secure encryption transmission system based on quantum key distribution in the optical network, and using dynamic encoding driven by quantum keys for optical domain encryption, the need for anti-interceptance in the optical network is solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510427271.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-06-10
AI Technical Summary
There is an urgent need for information resistance to interception in high-speed and large-capacity data transmission, and existing quantum optical communications cannot completely replace the information basic status of classic optical communications.
The optical information secure encryption transmission system based on quantum key distribution is adopted. Through the combination of software and hardware, the user data is optically encrypted using dynamic encoding driven by quantum keys to achieve secure transmission of information.
It greatly improves the security transmission capability of information, can effectively resist interception, and meets the security needs of high-speed, large-capacity data transmission.
Smart Images

Figure CN120128337A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of optical information security encryption, and particularly relates to an optical information security encryption transmission system and method based on quantum key distribution. Background Art
[0002] With the development of technology, while improving network performance, optical networks also bring new hidden dangers to network security. Unsafe characteristics such as fiber optic eavesdropping have become prominent, and there are already more and more technologies and products for attacking and eavesdropping on optical networks. Although optical quantum communication and optical quantum key technologies have been introduced to solve the optical network security problem, quantum optical communication cannot replace the information foundation status of classical optical communication. In view of the urgent need for information anti-interception in current high-speed and large-capacity data transmission, combining the advantages of quantum key distribution security and optical domain encryption of optical information, those skilled in the art have carried out research on optical information security encryption transmission technology based on quantum key distribution to solve the existing optical network information transmission security problem.
[0003] For example, the invention patent with the publication number CN202311013856 discloses an OTN encryption communication method and system based on quantum key distribution, which encrypts on the frame structure; the invention patent with the publication number CN202411053792 discloses a one-time pad high-speed secure optical communication method based on space division multiplexing technology, and this scheme realizes one-time pad high-speed secure communication through the exclusive-or encryption of a true random encryption key stream and plaintext data; the invention patent with the publication number CN202110849002 discloses a method and device for quantum secure communication, and this scheme performs bit-by-bit logical operations on the plaintext electrical signal through a data key to obtain a ciphertext electrical signal, and then uses a modulation key to generate a modulation control signal to modulate the ciphertext electrical signal to obtain a ciphertext optical signal, that is, first performs electrical domain encryption on the plaintext electrical signal and then optical domain encryption. Summary of the Invention
[0004] The present invention provides an optical information security encryption transmission system and method based on quantum key distribution, and provides a more reliable solution to solve the existing optical network information transmission security problem. This solution combines software and hardware, and adopts a dynamic coding driven by a quantum key for optical domain encryption of user data based on the optical information flow processing mechanism, greatly improving the secure transmission ability of information.
[0005] To achieve the above object, the technical solution adopted by the present invention is as follows:
[0006] An optical information security encryption transmission system based on quantum key distribution, comprising a sending end, an optical fiber link, a key negotiation link, and a receiving end;
[0007] The sending end is used for dynamically encrypting user data in the optical domain through an operating key;
[0008] The optical fiber link is used for the transmission of optical signals;
[0009] The key negotiation link is used for the negotiation of the seed key;
[0010] The receiving end is used to recover and output data from the encrypted optical signal through the decryption key.
[0011] Preferably, the sending end includes a quantum key generation module, a sending end control module, a sending end clock synchronization module, a sending end signal processing module, an optical domain encryption module, and a sending end wavelength division multiplexer;
[0012] The quantum key generation module is used to distribute the key sequence and send the generated quantum bits to the sending end wavelength division multiplexer;
[0013] The sending end control module is used to control the quantum key generation module to generate quantum random numbers, as well as the generation, caching, output, and consistency negotiation information interaction of the seed key, and the signal synchronization at both ends;
[0014] The sending end signal processing module is used to load the key synchronization signal and the clock synchronization signal as the frame header onto the user data and send it to the optical domain encryption module;
[0015] The optical domain encryption module is used to perform optical domain encryption on the user data processed by the signal processing module and send the securely encrypted optical signal to the sending end wavelength division multiplexer;
[0016] The sending end clock synchronization module is used to complete the generation, distribution, and synchronization of the system clock.
[0017] Preferably, the receiving end includes a quantum key detection module, a receiving end control module, a receiving end clock synchronization module, a receiving end signal processing module, an optical domain decryption module, and a receiving end wavelength division multiplexer;
[0018] The quantum key detection module is used to randomly detect the quantum optical signal demultiplexed by the receiving end wavelength division multiplexer and send the received quantum bits to the receiving end control module;
[0019] The receiving end control module is used to control the quantum key detection module to extract quantum random numbers, as well as the generation, caching, output, and consistency negotiation information interaction of the seed key, and the signal synchronization at both ends;
[0020] The optical domain decryption module is used to perform optical domain decryption on the optical signal demultiplexed by the receiving end wavelength division multiplexer according to the secure encryption rules and send the decrypted signal to the receiving end signal processing module;
[0021] The receiving - end signal processing module is used to process the decrypted signal and then send a key synchronization signal to the receiving - end control module and a clock synchronization signal to the receiving - end clock synchronization module;
[0022] The receiving - end clock synchronization module is used to receive the clock synchronization signal and provide a clock signal decision for the quantum key detection module.
[0023] The present invention also provides an optical information security encryption transmission method based on quantum key distribution, including the optical information security encryption transmission system based on quantum key distribution according to any one of claims 1 - 3. The transmission method includes the following steps:
[0024] S1. The system powers on and runs;
[0025] S2. The sending and receiving ends establish synchronization through a handshake protocol. At this time, the running keys of the sending and receiving ends are set to the initial value K 0 ;
[0026] S3. The quantum random numbers generated by the quantum key generation module at the sending end are sent to the receiving end through an optical fiber link;
[0027] S4. The quantum key detection module at the receiving end receives the quantum bits from the sending end. The quantum bit receiving method is transmitted by the receiving - end control module to the sending - end control module at the sending end through a key negotiation link;
[0028] S5. The sending - end control module and the receiving - end control module negotiate and obtain seed keys with the same serial numbers through the key negotiation link and save them synchronously;
[0029] S6. The saved seed keys are finally expanded through key expansion to obtain a group of high - speed running keys;
[0030] S7. The key synchronization signal generated by the sending - end control module and the clock synchronization signal generated by the sending - end clock synchronization module are loaded as frame headers onto the user data and sent;
[0031] S8. After t time, the optical domain encryption module performs optical domain encryption on the user data based on optical information flow processing driven by the dynamically encoded random running key Ki selected;
[0032] S9. Within t time, if the receiving end receives the frame header information, it performs step S10. If not, it returns to step S2;
[0033] S10. After t time, the receiving - end control module selects the same running key Ki according to the received key synchronization signal and demodulates the received signal through the optical domain decryption module to restore the user data.
[0034] Preferably, in step S7, the key synchronization signal includes a randomly selected key sequence number i and a time delay t.
[0035] Preferably, in step S10, meanwhile, the receiving - end clock synchronization module provides a clock signal decision for the quantum key detection module according to the received clock synchronization signal, so as to realize the synchronization of the clock signals at both ends.
[0036] Compared with the prior art, the present invention has the following advantages:
[0037] The present invention utilizes the unconditional security feature of quantum key distribution and combines it with the optical - domain encryption technology in the physical layer of the optical network to realize the secure transmission of information; specifically, through the combination of software and hardware, a dynamic coding driven by quantum keys is adopted for optical - domain encryption mechanism of user data based on optical information flow processing, so as to realize the secure encrypted transmission of information and greatly improve the secure transmission ability of information. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is a block diagram of a module of an optical information secure encryption transmission system based on quantum key distribution.
[0039] Figure 2 It is a flowchart of an optical information secure encryption transmission method based on quantum key distribution. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] In order to make the purpose and advantages of the present invention clearer, the present invention will be described in detail below with reference to the drawings and embodiments.
[0041] As Figure 1 shown, the present invention is an optical information secure encryption transmission system based on quantum key distribution, which includes a sending end, an optical fiber link, a key negotiation link, and a receiving end. The sending end is used to perform dynamic optical - domain encryption on user data through an operating key; the optical fiber link is used for the transmission of optical signals; the key negotiation link is used for the negotiation of seed keys; the receiving end is used to recover and output the data from the encrypted optical signal through a decryption key. The sending end performs dynamic optical - domain encryption on user data through an operating key; the optical fiber link transmits the encrypted optical signal to the receiving end; the receiving end recovers and outputs the data from the encrypted optical signal through a decryption key; the key negotiation link is used for the negotiation of seed keys. The present invention adopts a dynamic encryption method, and through the combination of software and hardware, a dynamic coding driven by quantum keys is adopted for optical - domain encryption mechanism of user data based on optical information flow processing, so as to realize the secure encrypted transmission of information, thus solving the urgent need for information anti - interception in high - speed large - capacity data transmission.
[0042] Further, the sending end includes a quantum key generation module, a sending end control module, a sending end clock synchronization module, a sending end signal processing module, an optical domain encryption module, and a sending end wavelength division multiplexer. The quantum key generation module is used to distribute the key sequence and send the generated quantum bits to the sending end wavelength division multiplexer. The sending end control module is used to control the quantum key generation module to generate quantum random numbers, as well as the generation, caching, output, and consistency negotiation information interaction of the seed key negotiation, and the signal synchronization at both ends. The quantum random number and the encrypted optical signal are multiplexed onto the same optical fiber link through a WDM (wavelength division multiplexer) for transmission. The sending end signal processing module is used to load the key synchronization signal and the clock synchronization signal as the frame header onto the user data and send it to the optical domain encryption module. The optical domain encryption module is used to perform optical domain encryption on the user data processed by the signal processing module and send the securely encrypted optical signal to the sending end wavelength division multiplexer. The sending end clock synchronization module is used to complete the generation, distribution, and synchronization of the system clock.
[0043] The receiving end includes a quantum key detection module, a receiving end control module, a receiving end clock synchronization module, a receiving end signal processing module, an optical domain decryption module, and a receiving end wavelength division multiplexer. The quantum key detection module is used to perform random detection on the quantum optical signal demultiplexed by the receiving end wavelength division multiplexer and send the received quantum bits to the receiving end control module. The receiving end control module is used to control the quantum key detection module to extract quantum random numbers, as well as the generation, caching, output, and consistency negotiation information interaction of the seed key negotiation, and the signal synchronization at both ends. The optical domain decryption module is used to perform optical domain decryption on the optical signal demultiplexed by the receiving end wavelength division multiplexer according to the secure encryption rules and send the decrypted signal to the receiving end signal processing module. The receiving end signal processing module is used to perform signal processing on the decrypted signal and then send the key synchronization signal to the receiving end control module and the clock synchronization signal to the receiving end clock synchronization module. The receiving end clock synchronization module is used to receive the clock synchronization signal and provide clock signal judgment for the quantum key detection module.
[0044] The present invention also provides an optical information secure encryption transmission method based on quantum key distribution, which is used for the above-mentioned optical information secure encryption transmission system based on quantum key distribution. This transmission method combines software and hardware, and uses quantum key-driven dynamic coding to process user data based on the optical information flow to achieve optical domain encryption. As Figure 2 shown, it includes the following steps:
[0045] S1. The system is powered on and runs.
[0046] S2. The receiving and sending ends establish synchronization through a handshake protocol. At this time, the running keys at the receiving and sending ends are set to the initial value K 0 .
[0047] S3. The quantum random numbers generated by the quantum key generation module at the sending end are sent to the receiving end through an optical fiber link.
[0048] S4. The quantum key detection module at the receiving end receives the quantum bits from the sending end. The quantum bit receiving method is transmitted by the receiving end control module to the sending end control module at the sending end through the key negotiation link.
[0049] S5. The sending end control module and the receiving end control module negotiate and obtain seed keys with the same serial numbers through the key negotiation link, and save them synchronously.
[0050] S6. The saved seed keys are finally expanded through key expansion to obtain a set of high-speed running keys.
[0051] S7. The key synchronization signal generated by the sending end control module and the clock synchronization signal generated by the sending end clock synchronization module are loaded as a frame header onto the user data; the key synchronization signal includes randomly selected key serial number i and time delay t.
[0052] S8. After t time, the optical domain encryption module processes the user data based on the optical information stream according to the dynamic coding driven by the randomly selected running key Ki, to achieve optical domain encryption.
[0053] S9. Within t time, if the receiving end receives the frame header information, it performs step S10; if not, it returns to step S2.
[0054] S10. After t time, the receiving end control module selects the same running key Ki according to the received key synchronization signal, and demodulates the received signal through the optical domain decryption module to restore the user data. At the same time, the receiving end clock synchronization module provides a clock signal decision for the quantum key detection module according to the received clock synchronization signal, to achieve synchronization of the two-end clock signals.
[0055] The above embodiments are only specific examples for further detailed description of the purpose, technical solution and beneficial effects of the present invention. The present invention is not limited thereto. Any modifications, equivalent replacements, improvements, etc. made within the scope of the disclosure of the present invention are all included in the protection scope of the present invention.
Claims
1. An optical information security encryption transmission system based on quantum key distribution, characterized by: It includes a transmitting end, an optical fiber link, a key negotiation link and a receiving end; The sending end is used to perform dynamic optical domain encryption on user data by running a key; The optical fiber link is used for transmission of optical signals; The key negotiation link is used for negotiation of a seed key; The receiving end is used to recover and output the encrypted optical signal using a decryption key.
2. According to claim 1, a secure optical information encryption transmission system based on quantum key distribution is characterized in that: The transmitting end includes a quantum key generation module, a transmitting end control module, a transmitting end clock synchronization module, a transmitting end signal processing module, an optical domain encryption module and a transmitting end wavelength division multiplexer; The quantum key generation module is used to distribute the key sequence and send the generated quantum bits to the transmitting end wavelength division multiplexer; The transmitting end control module is used to control the quantum key generation module to generate quantum random numbers, as well as seed key negotiation generation, caching, output, consistency negotiation information interaction, and signal synchronization at both ends; The transmitting end signal processing module is used to load the key synchronization signal and the clock synchronization signal as a frame header onto the user data and send it to the optical domain encryption module; The optical domain encryption module is used to perform optical domain encryption on the user data processed by the signal processing module, and send the securely encrypted optical signal to the wavelength division multiplexer at the transmitting end; The sending end clock synchronization module is used to complete the generation, distribution and synchronization of the system clock.
3. The optical information security encryption transmission system based on quantum key distribution according to claim 1 or 2, characterized in that: The receiving end includes a quantum key detection module, a receiving end control module, a receiving end clock synchronization module, a receiving end signal processing module, an optical domain decryption module and a receiving end wavelength division multiplexer; The quantum key detection module is used to randomly detect the quantum light signal after demultiplexing by the wavelength division multiplexer at the receiving end, and send the received quantum bits to the receiving end control module; The receiving end control module is used to control the quantum key detection module to extract quantum random numbers, as well as seed key negotiation generation, caching, output, consistency negotiation information interaction, and signal synchronization at both ends; The optical domain decryption module is used to perform optical domain decryption on the optical signal demultiplexed by the wavelength division multiplexer at the receiving end according to the security encryption rules, and send the decrypted signal to the signal processing module at the receiving end; The receiving end signal processing module is used to process the decrypted signal and then send a key synchronization signal to the receiving end control module and a clock synchronization signal to the receiving end clock synchronization module; The receiving end clock synchronization module is used to receive the clock synchronization signal and provide clock signal judgment for the quantum key detection module.
4. A method for secure encryption transmission of optical information based on quantum key distribution, characterized in that: An optical information security encryption transmission system based on quantum key distribution comprising any one of claims 1 to 3, wherein the transmission method comprises the following steps: S1. The system is powered on and running; S2. The receiving and sending ends establish synchronization through the handshake protocol. At this time, the operating key of the receiving and sending ends is set to the initial value K0; S3. The quantum random number generated by the quantum key generation module at the sending end is sent to the receiving end via the optical fiber link; S4. The quantum key detection module at the receiving end receives the quantum bit from the sending end, and the quantum bit receiving mode is transmitted by the receiving end control module to the sending end control module of the sending end via the key negotiation link; S5. The sending control module and the receiving control module negotiate the seed key with the same sequence number through the key negotiation link and save them synchronously; S6. The saved seed key is expanded through the key to finally obtain a set of high-speed operation keys; S7. The key synchronization signal generated by the transmitting control module and the clock synchronization signal generated by the transmitting clock synchronization module are loaded onto the user data as a frame header and sent; S8. After sending t time, the optical domain encryption module processes the user data based on the optical information flow according to the dynamic encoding driven by the randomly selected running key Ki to achieve optical domain encryption; If the receiving end receives the frame header information within the time S9.t, it will execute step S10, if not, it will return to step S2; After S10.t time, the receiving end control module selects the same operation key Ki according to the received key synchronization signal, demodulates the received signal through the optical domain decryption module, and recovers the user data.
5. According to claim 4, a method for secure encryption transmission of optical information based on quantum key distribution is characterized in that: In step S7, the key synchronization signal includes a randomly selected key sequence number i and a delay t.
6. According to claim 4, a method for secure encryption transmission of optical information based on quantum key distribution is characterized in that: In step S10, at the same time, the clock synchronization module at the receiving end provides a clock signal decision to the quantum key detection module according to the received clock synchronization signal, so as to achieve clock signal synchronization at both ends.
Citation Information
Patent Citations
Methods and apparatus for quantum secure communication
CN113691370B
OTN encryption communication method and system based on quantum key distribution
CN116743380A
One-time-pad high-speed secret optical communication method based on space division multiplexing technology
CN118984226A