Multi-dimensional resource allocation method and system based on security level
By prioritizing the allocation of resources according to the security level of communication requirements in the QKD optical network, the problems of low key resource utilization efficiency and high computational complexity are solved, and stable transmission and rational resource utilization of high security communication requirements are achieved.
Patent Information
- Application Number
- CN202510460472.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, in the quantum key distribution (QKD) optical network, the utilization efficiency of key resources is low and the calculation complexity is high, and the in-depth analysis and rational utilization of key resources are lacking.
By initializing the communication resource list, the path, wavelength, time slot and key resources are allocated first according to the security level of communication requirements, the transmission path is determined using the shortest path algorithm, and the resource allocation performance is evaluated through high security requirements blocking rate, average key consumption required, and the number of calculations.
The key resource utilization and transmission quality of high-security communication requirements are improved, and the stable key distribution capability under high load conditions is ensured, resource waste is reduced and computational complexity is reduced.
Smart Images

Figure CN120301587A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the technical field of communication resource allocation, and in particular, to a multi-dimensional resource allocation method and system based on security levels. Background Art
[0002] In recent years, with the continuous improvement of network security requirements, quantum key distribution (QKD) has gradually become an important research hotspot for ensuring information security. Based on the basic principles of quantum mechanics, especially the quantum no-cloning theorem and the Heisenberg uncertainty principle, QKD technology ensures the security of key distribution and realizes security in the sense of information theory. Therefore, introducing QKD technology into optical communication networks can not only meet the growing security requirements but also significantly enhance the overall network security.
[0003] To reduce the deployment cost of QKD infrastructure, researchers usually adopt wavelength division multiplexing (WDM) technology to share quantum signals and classical signals on the same optical fiber, thereby constructing a QKD-WDM network. In addition, the introduction of time division multiplexing (TDM) technology also helps to improve resource utilization. In the case of limited resources, efficiently and reasonably allocating wavelength, time slot, and key resources has become the core issue for ensuring the performance of QKD-WDM networks.
[0004] Regarding the above resource allocation problem, various resource allocation methods have been proposed in the prior art. For example, Cao Yuan et al. proposed a strategy of on-demand allocation based on required time slots, effectively solving the problem of resource waste caused by dedicated channels (i.e., specific wavelengths corresponding to specific demands); Zhao Yongli et al. proposed JPL-RWTA based on joint path and link, which significantly reduces the computational complexity under similar resource utilization rates.
[0005] Although certain progress has been made in the research related to resource allocation in QKD optical networks, most of them still focus on the allocation of time slot and wavelength resources, and less attention is paid to the utilization of key resources. Related research mostly stays at the discussion of the impact of key resource timing refresh on other resource allocations, and there is still a lack of in-depth analysis of key utilization efficiency and how to reasonably utilize key resources.
[0006] Therefore, it is necessary to improve one or more problems existing in the above related technical solutions.
[0007] It should be noted that this section aims to provide background or context for the technical solutions of the present disclosure stated in the claims. The description herein is not admitted to be prior art merely because it is included in this section. Summary of the Invention
[0008] The purpose of the embodiments of the present disclosure is to provide a multi-dimensional resource allocation method and system based on security levels, thereby at least to some extent overcoming one or more problems caused by the limitations and deficiencies of related technologies.
[0009] The embodiments of the present disclosure provide a multi-dimensional resource allocation method based on security levels, including:
[0010] Initialize a communication resource list, where the communication resources include: path resources, wavelength resources, time slot resources, and key resources;
[0011] Receive a communication request, which contains multiple communication requirements. The multiple communication requirements are sorted according to their corresponding security levels, and the security level is determined by the number of updates of the key resources corresponding to the communication requirements;
[0012] For each communication requirement, according to the source node and target node information of the communication requirement, use the shortest path algorithm to determine multiple feasible paths corresponding to the communication requirement in the path resources;
[0013] Among the multiple feasible paths, determine whether the communication resources corresponding to the communication requirement on each feasible path meet the transmission requirements of the communication requirement, determine the feasible path that meets the transmission requirements as the transmission path, and allocate the communication resources in descending order of the security levels of the communication requirements;
[0014] Use the transmission path to transmit the communication request and allocate the communication resources;
[0015] Evaluate the resource allocation performance using the high-security requirement blocking rate, the average consumed key amount of the requirements, and the number of calculations.
[0016] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:
[0017] In the multi-dimensional resource allocation method and system based on security levels in the embodiments of the present disclosure, the security level is determined by the number of updates of the key resources corresponding to the communication requirements and sorted according to the security levels, so that the communication requirements with high security levels are preferentially allocated communication resources, improving the utilization rate of key resources and the transmission quality of communication requirements with high security levels, ensuring that a stable key distribution ability can still be maintained under high load conditions, thereby ensuring the reasonable utilization of key resources, reducing unnecessary resource waste, and effectively reducing the computational complexity. Description of the Drawings
[0018] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0019] Figure 1 Schematic flowchart showing the multi-dimensional resource allocation method based on security level in an exemplary embodiment of the present disclosure;
[0020] Figure 2 Diagram showing the conventional working process of a QKD system in an exemplary embodiment of the present disclosure;
[0021] Figure 3 Diagram showing the architecture of a QKD optical network in an exemplary embodiment of the present disclosure;
[0022] Figure 4 Diagram showing the NSFNET network model in an exemplary embodiment of the present disclosure;
[0023] Figure 5 Flowchart showing the resource allocation algorithm in an exemplary embodiment of the present disclosure;
[0024] Figure 6 Brief description diagram showing the differences between multi-dimensional resource allocation strategy algorithms in an exemplary embodiment of the present disclosure;
[0025] Figure 7 Diagram showing the high-security requirement blocking rate under four algorithms of the UT strategy in an exemplary embodiment of the present disclosure;
[0026] Figure 8 Diagram showing the average key consumption under four algorithms of the UT strategy in an exemplary embodiment of the present disclosure;
[0027] Figure 9 Diagram showing the number of calculations under four algorithms of the UT strategy in an exemplary embodiment of the present disclosure;
[0028] Figure 10 Diagram showing the high-security requirement blocking rate under the BF algorithm of different strategies in an exemplary embodiment of the present disclosure;
[0029] Figure 11 Diagram showing the average key consumption of requirements under the BF algorithm of different strategies in an exemplary embodiment of the present disclosure;
[0030] Figure 12 Diagram showing the number of calculations under the BF algorithm of different strategies in an exemplary embodiment of the present disclosure;
[0031] Figure 13Shows the blocking rate of UT-BF and the blocking rate of high security requirements under different SL ranges in an exemplary embodiment of the present disclosure;
[0032] Figure 14 Shows the number of calculations of UT-BF and the average amount of keys consumed by requirements under different SL ranges in an exemplary embodiment of the present disclosure;
[0033] Figure 15 Shows the blocking rate and the number of calculations of UT-B under different time slots in an exemplary embodiment of the present disclosure;
[0034] Figure 16 Shows a schematic structural diagram of an electronic device in an exemplary embodiment of the present disclosure;
[0035] Figure 17 Shows a schematic structural diagram of a program product for implementing a multi-dimensional resource allocation method based on security levels in an exemplary embodiment of the present disclosure. Detailed implementation manners
[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.
[0037] In addition, the accompanying drawings are only schematic illustrations of the embodiments of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities.
[0038] In this example embodiment, a multi-dimensional resource allocation method based on security levels is first provided. Please refer to Figure 1 , which may include: Step S101 - Step S106, specifically as follows:
[0039] Step S101, initialize the communication resource list, where the communication resources include: path resources, wavelength resources, time slot resources, and key resources;
[0040] Step S102, receive a communication request, which contains multiple communication requirements. The multiple communication requirements are sorted according to their corresponding security levels, and the security level is determined by the number of updates of the key resources corresponding to the communication requirements;
[0041] Step S103: For each communication requirement, based on the source node and target node information of the communication requirement, use the shortest path algorithm to determine multiple feasible paths corresponding to this communication requirement in the path resources;
[0042] Step S104: Among the multiple feasible paths, determine whether the communication resources corresponding to this communication requirement on each feasible path meet the transmission requirements of this communication requirement. Determine the feasible paths that meet the transmission requirements as transmission paths, and allocate the communication resources in descending order of the security level of the communication requirements;
[0043] Step S105: Use the transmission path to transmit the communication request and allocate the communication resources;
[0044] Step S106: Evaluate the resource allocation performance using the high-security requirement blocking rate, average demand key consumption amount, and number of calculations.
[0045] In this embodiment, the security level is determined by the update times of the key resources corresponding to the communication requirements, and they are sorted according to the security level. The communication requirements with higher security levels are preferentially allocated communication resources, improving the utilization rate of key resources and transmission quality of communication requirements with high security levels, ensuring that a stable key distribution ability can still be maintained under high load conditions, thereby ensuring the reasonable utilization of key resources, reducing unnecessary resource waste, and effectively reducing the computational complexity.
[0046] The following describes the specific implementation process in the above steps.
[0047] In step S101, the communication resource list is initialized and the QKD-WDM network architecture is constructed. For the four types of communication resources, namely path resources, wavelength resources, time slot resources, and key resources, this application divides them into two categories.
[0048] One category is the three general communication resources of path resources, wavelength resources, and time slot resources. These three are allocated layer by layer and are closely linked. They show a high degree of dependence during allocation. Any problem in any link requires returning to the previous level for reallocation. The measurement criteria for such resources are also relatively fixed. The security index is demand blocking, and the effectiveness index is resource utilization rate.
[0049] Another type is the key resource, which has relative independence. In this application, the security level of the communication requirement is determined by the number of updates of the key resource corresponding to this communication requirement. Therefore, it is necessary to establish a connection between the key resource and the security of the communication requirement. This application assumes that the security of the communication request depends on the number of key updates. During the statistical time period of the system, the more frequent the key update, the higher the security of the requirement. This application sets that the slot resources required for each update of each requirement are the same, all being one slot. The more times the key of a requirement is updated, the more slots are allocated to it, and this requirement can transmit more different groups of keys for key updates. On the contrary, if insufficient slot resources required for key updates are provided for a certain requirement, this requirement will only be able to use a smaller number of security keys during this time period, and effective key updates cannot be achieved, thus reducing its security. This resource allocation strategy emphasizes the importance of slot resources in key updates and directly affects the overall security and reliability of the system.
[0050] In addition, each node between the source node and the target node of the communication requirement has a preset amount of initial key. For example, as experimental data, the initial key amount can be 100 bits, etc. For example, using the NSFNET model with a 14-node 21-link topology, each link has 15 wavelengths × 12 time slots.
[0051] In step S102, after receiving the communication request, the multiple communication requirements are sorted according to their corresponding security levels. If the security level of a certain communication requirement is higher than the median of the preset security level, then this communication requirement is set as a high-security level requirement.
[0052] In step S103, the determination process of the feasible path is described in detail.
[0053] According to the source node and target node information of the communication requirement, find multiple paths in the path resources that can be transmitted from the source node to the target node. Each path passes through different nodes, and each node has a corresponding preset amount of initial key. The key amount is limited and non-renewable. All nodes are completely trustworthy and can encrypt and decrypt the passing communication requirements. When the communication requirement passes through each node, the corresponding key resources will be consumed. Each path has multiple available wavelengths, and each wavelength is further divided into multiple time slots. Use the KSP path algorithm (K Shortest Paths Algorithm) to find the K shortest paths from the source node to the target node, which are the feasible paths.
[0054] In step S104, a path for final transmission is selected from multiple feasible paths. It is determined whether the communication resources on each path meet the communication resources required by the communication demand. For example, whether the wavelength resources, time slot resources, and key resources all meet the requirements of the communication demand. If they all meet, the path is determined as the final transmission path.
[0055] In step S105, the communication request is transmitted using the transmission path, and the communication resources are allocated. The allocation is performed according to the requirements of the communication request, and resources are preferentially allocated to communication demands with a high security level.
[0056] In step S106, the resource allocation performance is evaluated. The transmission capacity of communication demands with a high security level is evaluated using the demand blocking rate. The key usage efficiency in this resource allocation is quantified using the average key consumption per demand to evaluate the transmission quality. The computational complexity is evaluated using the number of calculations. Based on these three parameters, it is analyzed whether the allocation method of this application is excellent.
[0057] Based on the above embodiments, when transmitting a communication request according to the determined transmission path, the communication resources are allocated. If the communication resource allocation is successful, the communication resource status is updated; if the communication resource allocation fails, the transmission path is re-determined or the communication demand is marked as blocked.
[0058] The embodiment of this application also provides a multi-dimensional resource allocation system based on security levels. The system includes:
[0059] An initialization module, used to initialize the communication resource list. The communication resources include: path resources, wavelength resources, time slot resources, and key resources;
[0060] A request receiving module, used to receive a communication request. The communication request contains multiple communication demands, and the multiple communication demands are sorted according to their corresponding security levels. The security level is determined by the number of updates of the key resources corresponding to the communication demand;
[0061] A feasible path determination module, used for each communication demand, according to the source node and target node information of the communication demand, to determine multiple feasible paths corresponding to the communication demand in the path resources using the shortest path algorithm;
[0062] A transmission path determination module, used to determine whether the communication resources corresponding to the communication demand on each feasible path in the multiple feasible paths meet the transmission requirements of the communication demand, determine the feasible path that meets the transmission requirements as the transmission path, and allocate the communication resources in descending order of the security level of the communication demand;
[0063] A transmission and allocation module, configured to transmit the communication request using the transmission path and allocate the communication resources;
[0064] An evaluation module, configured to evaluate the resource allocation performance by using the high-security requirement blocking rate, the average key consumption amount of the requirement, and the number of calculations.
[0065] The technical solution and beneficial effects of the system in this embodiment are basically the same as those of the foregoing method, and will not be elaborated herein.
[0066] Next, the technical principle involved in the technical solution of this application will be described.
[0067] I. Introduction to QKD
[0068] Quantum key distribution (QKD) is a key distribution technology based on the principles of quantum mechanics. By distributing keys between two communication parties, it ensures the absolute security of the keys. The core concept of QKD is to utilize the unique properties of quantum bits, enabling any eavesdropping behavior to be detected, thereby preventing information leakage. A typical QKD system includes a sender Alice and a receiver Bob. The two parties transmit quantum states through a quantum channel and perform key negotiation and eavesdropping detection by means of a measurement basis channel.
[0069] Among numerous QKD protocols, BB84 is one of the most widely used. This protocol creates a shared key between the two communication parties by randomly generating and transmitting single photons (i.e., quantum bits). The uniqueness of BB84 lies in that any measurement of the quantum state will inevitably disrupt the state of the quantum bits, making it impossible for eavesdroppers to copy or fully measure these quantum bits, thus ensuring the security of the key distribution process.
[0070] The normal working process of a QKD system is as Figure 2 shown. The sender Alice sends through a polarization filter (PF1) via a quantum channel (QKCh, Quantum Key Channel) to the receiving end. The recipient Bob randomly selects a measurement basis and uses a polarization filter (PF2) to detect the received quantum bits. The quantum detector (QD) decodes these bits into binary form. Subsequently, Bob feeds back his measurement basis to Alice through the measurement basis channel (MBCh, Measurement Basis Channel). Through the MBCh, Alice and Bob can confirm whether the measurement bases they use are consistent, thereby ensuring the accuracy of key generation.
[0071] After confirming the consistent measurement bases, both parties discard the mismatched bits. Next, through steps such as error correction and privacy amplification, a secure shared key is finally generated. Subsequently, with the help of the data transmission channel (TDCh, Traffic Data Channel), the sender can encrypt the data using the generated key and transmit the ciphertext to the receiver, while the receiver decrypts it using the same key.
[0072] The working process of the QKD-based network system relies on three key channels: the quantum key channel (QKCh), the measurement basis channel (MBCh), and the data transmission channel (TDCh). The QKCh is responsible for the transmission of quantum signals to ensure the secure generation of keys; the MBCh is used to transmit classical information to ensure the consistency of the measurement bases of both parties; and the TDCh is used to transmit encrypted data to ensure the confidentiality of the communication content. Through this multi-level channel design, the QKD system can effectively cope with potential security threats and ensure information security during the key distribution and data transmission processes. Through this quantum key distribution process, even in the face of eavesdroppers, Alice and Bob can still detect and address potential security risks through the characteristics of quantum mechanics, thus ensuring the security of the communication.
[0073] In a quantum communication system, the TDCh, MBCh, and QKCh basically operate simultaneously. They occupy different wavelengths within the same optical fiber through wavelength division multiplexing technology. This design allows multiple channels to transmit information in parallel without interference, improving the utilization efficiency of the optical fiber and the overall performance of the system. Through wavelength division multiplexing, each channel can operate independently at its respective wavelength, ensuring the synchronization of data transmission, key distribution, and classical information feedback, thereby further enhancing the security and reliability of the system. Such an architecture not only optimizes resource utilization but also ensures that while quantum key distribution is carried out, it can effectively support data transmission requirements.
[0074] Based on the above QKD optical network model, in addition to the three-layer structure of the quantum key channel (QKCh), the measurement basis channel (MBCh), and the data transmission channel (TDCh), this application also introduces a quantum key pool (Quantum Key Pool, QKP) as a core module to optimize the allocation and storage management of keys. The introduction of the QKP provides an efficient resource management mechanism for quantum key distribution (QKD), especially during the key generation and allocation process, and can flexibly meet the allocation requirements of key resources.
[0075] The core role of the quantum key pool is reflected in its combination with time-division multiplexing (TDM) and wavelength-division multiplexing (WDM) technologies. Through TDM technology, a specific wavelength of the quantum signal can be divided into multiple time slots, enabling the key distribution process to occur over multiple time periods. This time slot division technology not only improves the utilization rate of key resources but also ensures that the system can maintain a stable key distribution capacity under high load conditions. The QKP can endow a QKD system with the ability to allocate key resources among different communication requirements, especially in cases where key resources are scarce, ensuring the rational use of key resources and reducing unnecessary resource waste.
[0076] II. QKD Optical Network Architecture
[0077] In the four-layer QKD optical network system architecture defined in this application, interactions and communications between different layers are achieved through specific protocols, as shown below. Figure 3 The first layer is the user layer, where users generate requirements and pass them to the second-layer resource control layer. In this layer, the controller uses protocols such as OpenFlow to control the allocation of paths, time slots, and wavelengths, ensuring the effective scheduling of resources. At the same time, the quantum key pool (QKP) located in the controller is responsible for managing key resources and sharing information with the controller to provide the required encryption resources for users. The third-layer communication node layer generates and exchanges keys through the measurement basis channel (MBCh) and the quantum key channel (QKCh). In the quantum channel, the BB84 protocol is usually used to ensure the secure distribution of keys. The measurement basis channel is responsible for transmitting feedback on measurement basis selection and error correction information. The fourth-layer data transmission layer uses the IPsec or TLS protocol to perform secure data transmission on the encrypted measurement basis channel, encrypting the transmitted content using the keys generated by the previous layers.
[0078] For ease of understanding, this application divides QKD into four layers according to function. The user layer (the first layer) generates data transmission requirements and sends them to the resource control layer (the second layer). In the resource control layer, the controller is responsible for allocating resources such as paths, time slots, wavelengths, and keys for the requirements. It should be noted that although key resources and other resources are managed by the same layer, their allocation method is somewhat special compared to other resources. For specific details, please refer to the following text. The allocated resources will be deducted from the total resources of the system.
[0079] Subsequently, the communication node layer (the third layer) sends the key through the quantum key channel (QKCh) and exchanges the basis selection information on the measurement basis channel (MBCh). After receiving the key, the communication node generates the final key through the error correction and privacy amplification processes. These keys will be distributed to the data transmission layer (the fourth layer) for encrypting the transmitted data. The encrypted data is transmitted through the measurement basis channel, and the receiving end decrypts the data using the same key, thus achieving secure data transmission.
[0080] It is worth pointing out that both the third layer and the fourth layer are actually communications between nodes. However, the main objective of the third layer is to obtain the key, while the fourth layer uses the obtained key for information encryption and transmission. To clarify the difference in functions, although they belong to the same physical layer, they are functionally divided into two layers. This process ensures the security of the entire key distribution and data transmission.
[0081] III. System Model of the Present Application
[0082] The experiment of the present application adopts the classical NSFNET network model, specifically as Figure 4 shown. This model consists of 14 communication nodes and 21 communication links. Among these 21 links, each link has 15 available wavelengths, and each wavelength is further divided into 12 time slots. Each node has a certain amount of key resources, and these resources are non-renewable. All nodes are fully trusted and can encrypt and decrypt the passing communication requirements. Specifically, each node that the communication requirement passes through will consume the corresponding key resources.
[0083] Parameters such as the starting point, ending point, security level, and key amount of each communication requirement are randomly generated. If the SL (security level) of a certain requirement is higher than the preset SL median, it is defined as a high-security-level requirement. The communication requirement occupies resources by selecting a suitable time slot in a specific wavelength of a specific link.
[0084] In the experiment, FT-RWTA (without distinguishing security levels) was used as the control group algorithm, without considering the differences in security levels of service requests; while UT-RWTA ((resource allocation based on security levels)) made a preliminary distinction of the security levels of users, optimized resource allocation, and completed the same work as FT-RWTA with fewer resources; the SL-RWTA (prioritizing high-security requirements) of this application was further improved to prioritize resource allocation for service requests with high security levels. Although it was at the cost of sacrificing some services with low security requirements, it greatly improved the success rate of resource allocation for high-security requirement requests and significantly enhanced the utilization quality of key resources. The simulation results show that the QKD key distribution methods that distinguish security levels all show advantages in some aspects over those that do not distinguish security levels, especially having great advantages when transmitting information with high encryption requirements. The parameters and their symbols involved in this application are shown in Table 1.
[0085] Table 1 Parameter Symbols and Meanings
[0086] Number of nodes 14 Link 21 Number of wavelengths 15 Number of time slots 12 Initial key amount per node <![CDATA[E initial > Required quantity Nr Blocked required quantity Nbr Resource list R(Nr, Nbr, P, W, T, E) Path resource set P Wavelength resource set W Time slot resource set T E-node key resource set E Remaining available key resource for each Ei Ei Single demand request r(s, d, sl, t, e) Number of time slots required by the demand t Security level of the demand sl Key amount required by the demand e Source node of the demand s Destination node of the demand d Demand blocking rate Br Security level Sl Average key amount consumed by the demand Akc
[0087] Among them, the calculation formula for the average key consumption Akc of the demand is as follows:
[0088]
[0089] In the formula, n represents the number of nodes, E initial represents the initial key amount of the node, E i represents the remaining key amount of the i-th node, Nr represents the number of communication requests, and Nbr represents the number of communication request blocks.
[0090] IV. The multi-dimensional resource allocation method of this application
[0091] Please refer to Figure 5 , the specific process of the resource allocation algorithm of this application is as follows:
[0092] 1. Initialize the communication resource list R, including path resource P, wavelength resource W, time slot resource T, and key resource E;
[0093] 2. Receive communication requests, and the number of communications is Nr;
[0094] 3. For each demand r(s, d, sl, t, e), use the KSP shortest path algorithm to find a feasible path in P based on the s and d information included in the demand;
[0095] 4. After determining the path, search for available wavelengths in the wavelength resource W;
[0096] 5. After determining the wavelength, find a suitable time slot resource t in the time slot resource T.
[0097] These steps all belong to the allocation of the first type of resources. If there is a problem in a certain step, return to the previous step for adjustment.
[0098] 6. For each node passed through, search for a suitable e in the key resource E.
[0099] This step belongs to the allocation of the second type of resources. If the allocation fails, directly return to the third step and try the next path; if it succeeds, it means that the demand is successfully transmitted.
[0100] If the resource allocation is successful, update the corresponding resource status in a timely manner; if the allocation fails, try other paths or mark the request as blocked. It should be noted that if any one of the first type and the second type of resources fails to meet the resource allocation conditions, the demand is blocked. Finally, record the experimental results, such as the blocking rate and the average key consumption, etc., to evaluate the system performance.
[0101] The impacts of various strategies and algorithms (FF (First Fit), BF (Best Fit), WF (Worst Fit), and RF (Random Fit)) in the experiments of this application on the system, the specific differences are as Figure 6 shown.
[0102] Figure 6 The exemplary system includes a relay node and two paths. There are three available wavelengths on each path, and there are several available time slots on each wavelength. Taking the transmission process of path 1 as an example, demand 1 occupies two time slots on wavelength 1, demand 2 occupies one time slot on wavelength 2, and demand 3 occupies three time slots on wavelength 3.
[0103] In path 2, assuming the UT strategy is adopted and the FF algorithm is used, the resource allocation is as follows: demand 1 will occupy two of the three idle time slots on wavelength 2, demand 2 will occupy the idle time slot on wavelength 1, and demand 3 will be blocked due to insufficient resources.
[0104] If the UT strategy is adopted and the BF algorithm is used, then demand 1 will occupy two time slots on wavelength 3, demand 2 occupies one time slot on wavelength 1, and demand 3 occupies three time slots on wavelength 2.
[0105] If the WF algorithm under the UT strategy is adopted, demand 1 will occupy all the time slots on wavelength 2, demand 2 occupies all the time slots on wavelength 3, and demand 3 will be blocked again due to insufficient resources.
[0106] However, if the SL strategy is adopted for resource allocation, whether it is the FF, BF or WF algorithm, the final result is the best allocation result. On path 2, demand 1 will occupy two time slots on wavelength 3, demand 2 occupies one time slot on wavelength 1, and demand 3 occupies three time slots on wavelength 2.
[0107] Although all the algorithm allocation results under the SL strategy are the same as those of the BF algorithm under the UT strategy, their logics are not consistent. Various algorithms in the UT strategy do not sort according to the security levels of the requirements when allocating resources, which may cause the requirements with high security levels to be blocked. In contrast, the SL strategy allocates resources in descending order of the security levels of the requirements, ensuring that the requirements with high security levels can always obtain priority allocation, thereby guaranteeing their transmission quality.
[0108] V. Analysis of Simulation Results
[0109] This application analyzes the performance of various allocation strategies. According to the working principles of the previous model, MBCh and QKCh are responsible for transmitting the key body information, and their resource allocations are exactly the same. Therefore, this application simplifies the system model, divides the wavelength resources equally between these two channels, and only processes one of the channels, thus ensuring that there are only differences in the wavelength numbers of their resource allocations.
[0110] The high-security requirement blocking rate, the average amount of keys consumed by requirements, and the number of calculations are used to evaluate the performances of the four algorithms under the UT strategy and the three strategies under the BF method.
[0111] 1. Comparison of Multidimensional Resource Allocation Strategies
[0112] From Figure 7 it can be seen that except for the RF algorithm as the benchmark, the WF algorithm has the highest high-security requirement blocking rate because this algorithm occupies the most resources, which in turn leads to requirement blocking. Next is the BF algorithm that occupies fewer resources, while the FF algorithm does not occupy any resources.
[0113] From Figure 8 it can be seen that the WF algorithm elevates the key usage quality at the cost of occupying a large number of time slot resources. The BF algorithm, due to algorithm logic problems, is more inclined to requirements with low security requirements, so the Akc value is relatively low. The parameter performance of the FF algorithm is between that of the WF and BF algorithms.
[0114] From Figure 9 it can be seen that the WF algorithm has a difficult resource search process due to excessive resource occupation, and its computational complexity is only slightly lower than that of the RF algorithm. The BF algorithm is relatively smoother, and its number of calculations is only slightly higher than that of the FF algorithm.
[0115] Next, when the BF algorithm is used for all sub-algorithms, a vertical comparison is made of the performances of the three strategies of the UT strategy, the FT strategy, and the SL strategy.
[0116] From Figure 10It can be seen that the UT strategy is basically on par with the FT strategy. The high-security blocking rate of the UT strategy is slightly higher, while the blocking rate of the SL strategy proposed in this application is much lower than that of UT and FT. This indicates that the SL strategy has a higher resource allocation efficiency when dealing with high-security level requirements, can significantly reduce the blocking rate of high-security level requirements, and demonstrates a strong transmission ability for high-security requirements.
[0117] From Figure 11 It can be seen that the Akc of the UT strategy is basically on par with that of the FT strategy, but the UT is slightly lower. In contrast, the Akc of the SL strategy proposed in this application is significantly higher than that of the UT strategy and the FT strategy, indicating that the SL strategy is more concentrated in key distribution for high-security level requirements. Therefore, more key resources are consumed per requirement on average.
[0118] From Figure 12 It can be seen that in terms of the number of calculations, the UT strategy is significantly higher than the FT strategy, while the number of calculations of the SL strategy proposed in this application is significantly lower than that of the UT strategy and the FT strategy, showing an obvious advantage in computational complexity. The SL strategy reduces unnecessary computational operations by preferentially processing high-security level requirements, significantly reducing the computational complexity.
[0119] From the above analysis, it can be seen that when transmitting a set of security level requirements with a certain complexity, the SL strategy demonstrates higher transmission efficiency and quality for high-security level requirements and lower computational complexity.
[0120] 2. Influence of the SL range on system parameters
[0121] First, analyze the influence of different SL ranges on the experimental results. The specific operation is to change the value range of SL under the premise of not changing the security level expectation of the randomly generated requirements.
[0122] From Figure 13 It can be seen that as the SL range expands, both the overall blocking rate and the high-security requirement blocking rate show an upward trend. This indicates that when the security level of the requirements processed by the system is higher, the difficulty of resource allocation also increases, resulting in more requirements being blocked. Especially in the case of high-security level requirements, the system has more demanding requirements for resources, so the possibility of blocking is greater.
[0123] Figure 14(a) shows that the number of calculations decreases as the SL range increases. This result is somewhat contrary to conventional intuition because, according to normal logic, the more unified the security level and the more uniform the time slot requirements, the fewer the number of calculations should be. However, the actual situation is exactly the opposite. When the allocated time slots for requirements are relatively unified, a large number of scattered time slots will be left idle, and these idle time slots cannot be effectively allocated to other similar requirements. During each resource allocation, these scattered time slots will be re-included in the calculation, although they are of no help to the actual allocation and only increase the calculation amount. Therefore, the seemingly unified allocation of demand time slots actually triggers a redundant calculation process, which instead exacerbates the computational complexity.
[0124] From Figure 14 (b) It can be seen that regarding the parameter performance of Akc (average key consumption), generally, the larger the SL range of the requirements, the more distinct the differentiation between the requirements, and the better the SL strategy can identify important requirements for transmission. Therefore, the larger the SL range, the higher the Akc.
[0125] 3. Influence of the number of available time slots on parameters
[0126] To analyze the influence of the number of time slots on various parameters, this application modifies the number of available time slots on each wavelength while ensuring that the total amount of overall time slot resources remains unchanged.
[0127] From Figure 15 It can be seen that the fewer the available time slots on a wavelength, the lower the diversity of requirements it can accommodate, the higher the probability of leaving unused fragmented time slots, the higher the demand blocking rate, and at the same time, the fewer the number of calculations.
[0128] In summary, this application proposes a technical solution for multi-dimensional resource allocation in a quantum key distribution (QKD) optical network, focusing on how to optimize the scheduling of wavelengths, time slots, and encryption keys to meet the increasing requirements for security in modern communications. Through simulation comparisons of three strategies: FT-RWTA (without distinguishing security levels), UT-RWTA (resource allocation according to security levels), and SL-RWTA (prioritizing the allocation of high-security requirements) proposed in this application, the results show that SL-RWTA significantly improves the success rate of resource allocation for high-security requirements, enhances the utilization efficiency of key resources, and effectively reduces the computational complexity, especially suitable for scenarios with strict requirements for high-security data transmission.
[0129] In addition, this application also introduces a new metric - average key consumption (Akc), which is used to quantify the key usage efficiency in the system and provides a useful reference for evaluating the quality of system services. Experiments show that the SL-RWTA strategy can significantly optimize resource consumption while ensuring high-security requirements.
[0130] This application emphasizes the importance of implementing security-level differentiated resource allocation in a QKD network, indicating that the SL-RWTA strategy can effectively improve the security and resource utilization efficiency of an optical network and has the potential to become an important solution in future QKD optical networks.
[0131] Regarding the system in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0132] It should be noted that although several modules of the system for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present invention, the features and functions of two or more of the above-described modules can be embodied in one module. Conversely, the features and functions of one module described above can be further divided into multiple modules for embodiment. The components shown as modules may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present invention. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0133] See Figure 16 , an embodiment of the present invention further provides an electronic device 300, which includes at least one memory 310, at least one processor 320, and a bus 330 connecting different platform systems.
[0134] The memory 310 may include a readable medium in the form of volatile memory, such as a random access memory (RAM) 311 and / or a cache memory 312, and may further include a read-only memory (ROM) 313.
[0135] Among them, the memory 310 further stores a computer program, which can be executed by the processor 320, so that the processor 320 executes the steps of the multi-dimensional resource allocation method based on the security level in any embodiment of the present invention. Its specific implementation manner is consistent with the implementation manner and the achieved technical effects recorded in the embodiments of the above multi-dimensional resource allocation method based on the security level, and some contents will not be elaborated.
[0136] The memory 310 may further include a utility 314 having at least one program module 315. Such program modules 315 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0137] Correspondingly, the processor 320 can execute the above computer program and can also execute the utility tool 314.
[0138] The bus 330 can represent one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of the various bus architectures.
[0139] The electronic device 300 can also communicate with one or more external devices 340 such as a keyboard, a pointing device, a Bluetooth device, etc., and can also communicate with one or more devices capable of interacting with the electronic device 300, and / or communicate with any device (such as a router, a modem, etc.) that enables the electronic device 300 to communicate with one or more other computing devices. Such communication can be carried out through the input / output interface 350. Moreover, the electronic device 300 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 360. The network adapter 360 can communicate with other modules of the electronic device 300 through the bus 330. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 300, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms, etc.
[0140] Figure 17 A program product 400 for implementing the above multi-dimensional resource allocation method based on security levels provided in this embodiment is shown. It can use a portable compact disc read-only memory (CD-ROM) and includes program code, and can run on a terminal device, such as a personal computer. However, the program product 400 of the present invention is not limited to this. In the present invention, the readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or component. The program product 400 can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0141] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit of the present invention and the scope protected by the claims. All of these fall within the protection scope of the present invention.
Claims
1. A multi-dimensional resource allocation method based on security levels, characterized in that, including: Initializing a communication resource list, where the communication resources include: path resources, wavelength resources, time slot resources, and key resources; Receiving a communication request, which contains multiple communication requirements. The multiple communication requirements are sorted according to their corresponding security levels, and the security level is determined by the update times of the key resources corresponding to the communication requirements; For each communication requirement, according to the source node and destination node information of the communication requirement, using the shortest path algorithm to determine multiple feasible paths corresponding to the communication requirement in the path resources; Among the multiple feasible paths, judging whether the communication resources corresponding to the communication requirement on each feasible path meet the transmission requirements of the communication requirement, determining the feasible path that meets the transmission requirements as the transmission path, and allocating the communication resources in descending order of the security level of the communication requirements; Transmitting the communication request using the transmission path and allocating the communication resources; Evaluating the resource allocation performance using the high-security requirement blocking rate, average key consumption per demand, and the number of calculations.
2. The multi-dimensional resource allocation method based on security levels according to claim 1, wherein, Each node between the source node and the destination node of the communication requirement has a preset amount of initial keys.
3. The multi-dimensional resource allocation method based on security levels according to claim 1, wherein, Among the multiple communication requirements, the communication requirements with a security level higher than the median are set as high-security level requirements.
4. The multi-dimensional resource allocation method based on security level according to claim 1, wherein The step of transmitting the communication request using the transmission path and allocating the communication resources is followed by: If the communication resource allocation is successful, update the communication resource status; If the communication resource allocation fails, re-determine the transmission path or mark the communication requirement as blocked.
5. The multi-dimensional resource allocation method based on security levels according to claim 1, wherein, The calculation formula for the average key consumption per demand Akc is: where n represents the number of nodes, and E initial represents the initial key amount of the nodes, and E i represents the remaining key amount of the i-th node, Nr represents the number of communication requests, and Nbr represents the number of blocked communication requests.
6. The multi-dimensional resource allocation method based on security levels according to any one of claims 1 to 5, characterized in that Using the QKD optical network model to transmit the communication request and allocate the communication resources; where the QKD optical network model uses a quantum key pool to manage key resources.
7. The multi-dimensional resource allocation method based on security levels according to claim 6, wherein The QKD optical network model includes: A user layer for users to generate communication requirements; A resource control layer for using a controller to control the allocation of path resources, wavelength resources, and time slot resources, using a quantum key pool to manage key resources, and sharing information with the controller; A communication node layer for generating and exchanging keys through a measurement basis channel and a quantum key channel, and encrypting the measurement basis channel; A data transmission layer for transmitting data on the encrypted measurement basis channel and encrypting the transmission content using the keys generated by the communication node layer.
8. The multi-dimensional resource allocation method based on security level according to claim 7, wherein The quantum key channel uses the BB84 protocol for key distribution.
9. A multi-dimensional resource allocation system based on security levels, characterized in that The system includes: An initialization module for initializing a communication resource list, where the communication resources include: path resources, wavelength resources, time slot resources, and key resources; A request receiving module for receiving a communication request, which contains multiple communication requirements. The multiple communication requirements are sorted according to their corresponding security levels, and the security level is determined by the update times of the key resources corresponding to the communication requirements; A feasible path determination module, which is used for each communication requirement, according to the source node and target node information of the communication requirement, to determine multiple feasible paths corresponding to the communication requirement in the path resources by using the shortest path algorithm; A transmission path determination module, which is used to judge whether the communication resources corresponding to the communication requirement on each feasible path meet the transmission requirements of the communication requirement among the multiple feasible paths, determine the feasible paths that meet the transmission requirements as the transmission paths, and allocate the communication resources in descending order of the security level of the communication requirements; A transmission allocation module, which is used to transmit the communication request by using the transmission path and allocate the communication resources; An evaluation module, which is used to evaluate the resource allocation performance by using the high-security requirement blocking rate, the average key consumption amount of the requirement, and the number of calculations.
10. The multi-dimensional resource allocation system based on security levels according to claim 9, wherein The system further includes: A resource status update module, which is used to update the communication resource status after the communication resource allocation is successful.