Quantum key scheduling method, system and device

By separating the storage function of the quantum key management machine into external large-capacity storage devices and using load balancing technology to realize parallel computing of multiple quantum key management devices, the problem of insufficient storage space and performance in the prior art is solved, and the system's business capabilities and equipment utilization are improved.

CN120238295APending Publication Date: 2025-07-01CHINA SOUTHERN POWER GRID COMPANY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311872203.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

When faced with a large number of users and high traffic volume, existing quantum key management machines lack storage space and performance, resulting in increased equipment complexity, increased volume, complex installation and maintenance, and low equipment utilization.

Method used

Separate the storage function from the quantum key management device, realize it using external large-capacity storage devices, and select multiple quantum key management devices in parallel computing through load balancing technology to improve system business capabilities and equipment utilization.

Benefits of technology

By separating key computing and storage, the design of the quantum key management machine is simplified, the system's key storage capabilities and service capabilities are improved, the utilization rate of equipment is improved, and key services can be provided to more users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238295A_ABST
    Figure CN120238295A_ABST
Patent Text Reader

Abstract

The invention provides a quantum key scheduling method, system and device, and the method comprises the steps: separating a storage function from a quantum key management device, achieving the storage function through independent storage equipment, and selecting one of a plurality of quantum key management devices for parallel operation through load balancing to execute an instruction, the service capability is not limited by a single quantum key management device any more, the overall service capability is greatly improved, the key storage capability is not limited by the quantum key management device any more, and key services can be provided for more users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of quantum key management, and particularly relates to a quantum key scheduling method, system and device. Background Art

[0002] The statements in this part only provide background technical information related to the present invention, and do not necessarily constitute prior art.

[0003] Quantum key distribution forms a shared quantum key between two endpoints by preparing optical quanta at one endpoint and measuring optical quanta at the other endpoint. After the quantum key is generated, it is stored in the quantum key management machine. Compared with traditional key management devices, the quantum key management machine requires a larger storage space to store keys. As the amount of data transmitted by the user business system increases, more and more keys are needed.

[0004] To ensure a large number of key requirements in case of emergencies and enable a single device to support more users, the performance and storage space of the quantum key management machine have been continuously improved. In addition, to ensure the high availability of the quantum key management machine, generally two quantum key management machines are connected in a hot standby mode, one is in the working state and the other is in the standby state, and the key data is synchronized in real time between them so that the standby machine can immediately enter the working state when the host fails.

[0005] As Figure 1 shown, the existing quantum key management device mainly consists of a CPU, a memory, a large-capacity hard disk, a cryptographic card, a random number source, etc. on the hardware. The large-capacity hard disk is mainly used to store quantum keys; the cryptographic card is mainly used for encryption and decryption calculations; the random number source is mainly used to generate random numbers, which can be a quantum random number source or a non-quantum random number source; the CPU and the memory, as the carriers of the basic operating environment, are responsible for establishing the basic operating environment, parsing external instructions, and scheduling the cryptographic card and the random number source to complete relevant services.

[0006] The quantum key management device is connected to the key scheduling platform through the service instruction interaction interface to control the quantum key management machine to complete the corresponding key acquisition service, such as scheduling the stored keys, including ciphertext import, ciphertext export, exclusive OR calculation, etc.

[0007] However, with the increase in business volume, users need more and more keys. The quantum key management machine has to increase the storage space of the hard disk. The increase in the number of hard disks increases the complexity of the device on the one hand, and on the other hand, makes the volume of the device larger and larger, increasing the complexity of installation and maintenance. In addition, frequent requests for session keys by a large number of users also pose higher performance requirements for the CPU, memory, etc. of the device, that is, the overall performance of the device needs to be improved. It is becoming increasingly difficult for a single device to meet the needs of users.

[0008] In addition, two quantum key management machines are interconnected in a hot standby mode, and their availability is mutually detected. When one of them fails, the other immediately takes over the service. One of the two quantum key management machines in the hot standby state is in the working state, and the other is in the standby state. The equipment utilization rate of this solution is relatively low. Even if the service of the equipment in the working state has reached saturation, the equipment in the standby state cannot carry out the service. Summary of the Invention

[0009] In order to solve the above problems, the present invention proposes a quantum key scheduling method, system and device. By separating the storage function from the quantum key management device and implementing it with an independent storage device, and using load balancing to select one of the multiple quantum key management devices for parallel operation to execute instructions, the service capacity of the system is effectively increased, and the equipment utilization rate is improved.

[0010] According to some embodiments, the present invention adopts the following technical solutions:

[0011] A quantum key scheduling method, applied to a scheduling end, includes the following steps:

[0012] Respond to the instruction to generate a random number;

[0013] Use the load balancing method to select any quantum key management device and send an instruction to obtain a random number;

[0014] Obtain the random number fed back by the selected quantum key management device.

[0015] A quantum key scheduling method, applied to the quantum key management device end, includes the following steps:

[0016] Respond to the selection result using the load balancing method and receive the instruction to obtain a random number;

[0017] Parse the instruction, schedule the random number source to generate a random number of a specified length, and encrypt the random number with a public key for feedback;

[0018] After encrypting the random number, send the encrypted key to an external storage device for storage.

[0019] A quantum key scheduling method, includes the following steps:

[0020] The quantum key scheduling device uses the load balancing method to select any quantum key management device and send an instruction to obtain a random number;

[0021] The quantum key management device parses the instruction, schedules the random number source to generate a random number of a specified length, and encrypts the random number with a public key and feeds it back to the quantum key scheduling device;

[0022] After encrypting the random number, the quantum key management device sends the encrypted random number to an external storage device for storage.

[0023] As an alternative embodiment, the instruction for obtaining the random number includes the ID, length, and encryption public key information of the random number.

[0024] As an alternative embodiment, the random number fed back by the quantum key management device is encrypted with the public key.

[0025] As an alternative embodiment, a cryptographic card is used to encrypt the random number.

[0026] As an alternative embodiment, a plurality of quantum key management devices are included and operate in parallel with each other.

[0027] A quantum key scheduling device includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, the steps in the above method applied to the scheduling end are completed.

[0028] The quantum key scheduling device communicates with a plurality of quantum key management devices, and the quantum key management devices operate in parallel with each other.

[0029] As an alternative embodiment, the quantum key scheduling device includes a load balancer configured to select a quantum key management device to execute an instruction using a preset load balancing algorithm.

[0030] A quantum key management device includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, the steps in the above method applied to the quantum key management device end are completed.

[0031] A quantum key scheduling system includes a plurality of quantum key management devices operating in parallel. Each quantum key management device communicates with an external storage device and with the quantum key scheduling device;

[0032] The quantum key scheduling device is configured to, in response to an instruction to generate a random number, select any quantum key management device using a load balancing method, send an instruction to obtain the random number, and obtain the random number fed back by the selected quantum key management device;

[0033] The quantum key management device is configured to, in response to the selection result using the load balancing method, receive the instruction to obtain the random number, parse the instruction, schedule a random number source to generate a random number of a specified length, encrypt the random number with the public key and feed it back; after encrypting the random number, send the encrypted random number to an external storage device for storage.

[0034] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0035] The present invention separates key calculation from key storage, simplifies the design of the quantum key management machine, and uses an external large-capacity storage device for key storage. The key storage capacity of the system is no longer limited by the quantum key management machine, and key services can be provided for more users.

[0036] The present invention uses load balancing technology to achieve parallel operation of the quantum key management machine. The service capacity is no longer limited by a single quantum key management machine, and the overall service capacity is greatly improved.

[0037] The present invention can complete multiple key scheduling actions through a single instruction, reducing information interaction between devices.

[0038] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given, and in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The accompanying drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation of the present invention.

[0040] Figure 1 is a quantum key management device and connection diagram in the prior art;

[0041] Figure 2 is a structural diagram of the quantum key scheduling system of this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] The present invention will be further described below in conjunction with the drawings and embodiments.

[0043] It should be noted that the following detailed description is illustrative and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0044] It should be noted that the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the exemplary embodiments of the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0045] Embodiment 1

[0046] Taking the quantum key injection service through the injection terminal software with a quantum key card as an example, the specific process is described to better illustrate the functions and working processes of the existing quantum key management devices.

[0047] 1. The key scheduling platform sends a random number generation instruction to the quantum key management device, and the instruction contains the ID of the random number and the length information L.

[0048] 2. After receiving the instruction, the CPU of the quantum key management device parses it, then controls the random number source to generate a random number with a length of L, temporarily stores it in the memory and marks it as ID.

[0049] 3. The quantum key management device returns a response indicating successful random number generation to the key scheduling platform.

[0050] 4. The key scheduling platform sends a random number authorization instruction, and the instruction contains the authorization code and the random number ID.

[0051] 5. The quantum key management device correlates the key marked as ID in the memory with the authorization code, and then returns a successful response.

[0052] 6. The injection terminal software applies for a key from the quantum key management device, and the instruction carries the authorization code of the key.

[0053] 7. The quantum key management device sends the key corresponding to the authorization code to the injection terminal software.

[0054] 8. The quantum key management device encrypts the key with the cryptographic card and stores it in a large-capacity hard disk for subsequent session key distribution services.

[0055] It can be seen that the existing quantum key management devices (or quantum key management equipment) have problems such as bottlenecks in performance and storage space, low device utilization rate, and complex processes.

[0056] To solve the above problems, this embodiment proposes a quantum key scheduling method, device, and system.

[0057] First, the functions of the quantum key management device can be decomposed into two major categories: computing functions and storage functions. In this embodiment, the storage function is separated from the quantum key management device and implemented using external large-capacity storage devices such as general commercial servers or shared memories.

[0058] The quantum key management device only implements computing functions. This solves the problem of insufficient storage capacity of the quantum key management device.

[0059] In some embodiments, the external large-capacity storage device (or storage device) can also expand the storage capacity by means such as disks to further improve the storage performance.

[0060] On the other hand, this embodiment uses a method of parallel computing with multiple quantum key management devices to meet the demand for computing power after the business volume increases. As Figure 2 shown, a load balancer is added to the key scheduling platform. The load balancer can select a quantum key management device according to a certain algorithm (such as the round-robin algorithm, weighted round-robin algorithm, etc.). When the key scheduling platform (or key scheduling device) needs to send an instruction to the quantum key management device, the load balancer selects a quantum key management device to execute the instruction, enabling multiple quantum key management devices to run in parallel, increasing the business capacity of the system and improving the utilization rate of the devices.

[0061] According to the existing process, multiple instructions for a charging service must be sent to the same quantum key management device. Suppose the instruction to generate a random number is sent to quantum key management device A, but subsequent instructions are sent to quantum key management device B, then the service fails on B because there is no corresponding random number. This sequential relationship between instructions requires the load balancer to identify the service flow to which the instruction belongs, increasing the complexity of the system.

[0062] In this embodiment, instructions with a single function are expanded to enable them to complete multiple scheduling actions of quantum keys at one time according to business requirements. The specific process includes:

[0063] 1. The key scheduling platform sends a command to obtain a random number to the quantum key management device. The instruction contains the ID, length, and encrypted public key information of the random number;

[0064] 2. When the instruction passes through the load balancer, the load balancer selects a quantum key management device through a preset algorithm;

[0065] 3. After receiving the instruction, the quantum key management device parses it, then schedules the random number source to generate a random number A of the specified length and marks it as ID. Then, the random number A is encrypted with the public key and sent to the key scheduling platform; finally, the random number A is encrypted again with the cryptographic card, and the encrypted random number A is sent to an external large-capacity storage device for storage.

[0066] It can be seen that this embodiment adopts a load balancing component and only one instruction is required for charging. Therefore, when the computing performance of the quantum key management device is insufficient, quantum key management devices can be dynamically added, so that the overall computing performance of the system is no longer affected by the performance of a single device, and the entire process is greatly simplified.

[0067] Embodiment 2

[0068] A quantum key scheduling system includes multiple quantum key management devices running in parallel. Each quantum key management device communicates with an external storage device and with a quantum key scheduling device;

[0069] The quantum key scheduling device is configured to, in response to an instruction to generate a random number, select any one of the quantum key management devices using a load balancing method, send an instruction to obtain a random number, and obtain the random number fed back by the selected quantum key management device;

[0070] The quantum key management device is configured to, in response to the selection result using the load balancing method, receive the instruction to obtain a random number, parse the instruction, schedule a random number source to generate a random number of a specified length, encrypt the random number using a public key and provide feedback; after encrypting the random number, send the encrypted random number to an external storage device for storage.

[0071] The quantum key scheduling device in this embodiment includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, it completes the following operations in response to an instruction to generate a random number;

[0072] Select any one of the quantum key management devices using a load balancing method and send an instruction to obtain a random number;

[0073] Obtain the random number fed back by the selected quantum key management device.

[0074] In this embodiment, the quantum key scheduling device communicates with multiple quantum key management devices, and the quantum key management devices run in parallel with each other.

[0075] The quantum key scheduling device includes a load balancer configured to select a quantum key management device to execute an instruction using a preset load balancing algorithm.

[0076] The quantum key management device in this embodiment includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, it completes the following operations in response to the selection result using the load balancing method and receives the instruction to obtain a random number;

[0077] Parse the instruction, schedule a random number source to generate a random number of a specified length, encrypt the random number using a public key and provide feedback;

[0078] After encrypting the random number, send the encrypted random number to an external storage device for storage.

[0079] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0080] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0081] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0082] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0083] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made by those skilled in the art without creative efforts within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A quantum key scheduling method, applied to a scheduling end, characterized in that It includes the following steps: In response to an instruction to generate a random number; Use a load balancing method to select any quantum key management device and send an instruction to obtain a random number; Obtain the random number fed back by the selected quantum key management device.

2. A quantum key scheduling method, which is applied to the quantum key management device side, is characterized in that It includes the following steps: In response to the selection result using the load balancing method, receive an instruction to obtain a random number; Parse the instruction, schedule the random number source to generate a random number of a specified length, and encrypt the random number with a public key for feedback; After encrypting the random number, send the encrypted random number to an external storage device for storage.

3. A quantum key scheduling method, characterized in that It includes the following steps: The quantum key scheduling device uses a load balancing method to select any quantum key management device and send an instruction to obtain a random number; The quantum key management device parses the instruction, schedules the random number source to generate a random number of a specified length, and encrypts the random number with a public key and feeds it back to the quantum key scheduling device; After encrypting the random number, the quantum key management device sends the encrypted random number to an external storage device for storage.

4. A quantum key scheduling method according to any one of claims 1-3, characterized in that, The instruction to obtain a random number contains the ID, length, and encrypted public key information of the random number.

5. A quantum key scheduling method according to any one of claims 1-3, characterized in that, The random number fed back by the quantum key management device is encrypted with a public key.

6. A quantum key scheduling method according to claim 2 or 3, characterized in that Encrypt the random number using a cryptographic card.

7. A quantum key scheduling device, characterized in that, It includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, the steps in the method described in claim 1 are completed.

8. A quantum key scheduling device according to claim 7, characterized in that, The quantum key scheduling device includes a load balancer configured to use a preset load balancing algorithm to select a quantum key management device to execute an instruction.

9. A quantum key management device, characterized in that, It includes a memory, a processor, and computer instructions stored on the memory and running on the processor. When the computer instructions are run by the processor, the steps in the method described in claim 2 are completed.

10. A quantum key scheduling system, characterized in that It includes multiple quantum key management devices running in parallel. Each quantum key management device communicates with an external storage device, and each quantum key management device communicates with the quantum key scheduling device; The quantum key scheduling device is used to, in response to an instruction to generate a random number, use a load balancing method to select any quantum key management device, send an instruction to obtain a random number, and obtain the random number fed back by the selected quantum key management device; The quantum key management device is used to, in response to the selection result using the load balancing method, receive an instruction to obtain a random number, parse the instruction, schedule the random number source to generate a random number of a specified length, and encrypt the random number with a public key for feedback; After encrypting the random number, send the encrypted random number to an external storage device for storage.