Quantum key management method, device, equipment, system and storage medium

By introducing a key manager and controller into the QKD network, determining the application's key service identity and providing differentiated key service strategies, the problem of poor flexibility in the QKD network key service model is solved, and service efficiency and adaptability are improved.

CN120342605AActive Publication Date: 2025-07-18CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510686711.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-07-18
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

The existing quantum key distribution network (QKD network) has poor flexibility and low efficiency in key service mode, and cannot effectively meet the differentiated needs of multiple encryption services.

Method used

By introducing a key manager and controller in the QKD network, determining the key service identity of the application, and providing a differentiated key service policy based on the first correspondence, including key transmission priority, key relay transmission path and truncated pipe layer slice, etc., the key service policy is dynamically adjusted to meet the needs of different encryption services.

Benefits of technology

It realizes perception and differentiated key services for different encryption services, improves the service efficiency and flexibility of the QKD network, and ensures that each application can obtain the key service strategy that is most suitable for its own needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342605A_ABST
    Figure CN120342605A_ABST
Patent Text Reader

Abstract

The invention provides a quantum key management method, device, equipment and system and a storage medium, and relates to the technical field of communication. The method comprises: a key manager of a QKD node determines a key service identifier of an application, the key service identifier being determined by key application information sent by the application; a key service strategy of the application is determined based on a first corresponding relation according to the key service identifier of the application, the first corresponding relation comprises a corresponding relation between the key service identifier and the key service strategy, and the first corresponding relation is determined by the QKD network controller based on the QKD network state information and the key service identifier; and providing a key service according to the applied key service strategy. According to the invention, perception for different encryption businesses is realized, differentiated key services are provided for different encryption businesses, and the service efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the large-scale deployment of QKD (Quantum Key Distribution) networks, QKD networks can serve as a cryptographic infrastructure. Third parties can utilize the QKD networks deployed by operators to encrypt their business data, thereby realizing corresponding confidentiality service functions.

[0003] The types of encryption services supported by QKD networks are increasing, such as quantum secure video conferencing, quantum secure voice calls, quantum secure email, quantum secure file transfer, etc.

[0004] The current key service mode has poor flexibility and low efficiency. Summary of the Invention

[0005] The present disclosure provides a quantum key management method, apparatus, device, system, and storage medium, which at least overcome the problem of low efficiency in related technologies to a certain extent.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a quantum key management method is provided. The method is applied to the key manager of each QKD node in the QKD network and includes: determining a key service identifier, where the key service identifier is determined by the key application information sent by the application; determining the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; providing a key service according to the key service policy of the application.

[0008] In some possible embodiments of the present disclosure, when the QKD node is an edge node, determining the key service identifier of the application includes: receiving the key application information sent by the application; generating a key service identifier according to the key application information.

[0009] In some possible embodiments of the present disclosure, when the QKD node is a relay node or an access node, determining the key service identifier of the application includes: receiving the key relay packet sent by the edge node; reading the key service identifier encapsulated in the header part of the key relay packet.

[0010] In some possible embodiments of the present disclosure, providing a key service according to the key service policy of the application includes: processing the key relay packet according to the key service policy, providing a key relay service, and generating an end-to-end key for the application; sending the end-to-end key to the application.

[0011] In some possible embodiments of the present disclosure, providing a key service based on an application's key service policy includes: generating a key relay packet for the application based on the application's key service identifier; processing the key relay packet based on the key service policy to provide a key relay service and generate an end-to-end key for the application; and sending the end-to-end key to the application.

[0012] In some possible embodiments of the present disclosure, the key service policy includes at least one of the following: key transmission priority, key relay transmission path, and cipher management layer slicing.

[0013] In some possible embodiments of the present disclosure, the first correspondence is periodically sent by the QKD network controller to the key manager of the QKD node, where the QKD node includes one of the following: an edge node, an access node, and a relay node.

[0014] In some possible embodiments of the present disclosure, the method further includes: sending a key service policy distribution request to the QKD network controller, so that the QKD network controller sends the first correspondence to the key manager of the QKD node based on the key service policy distribution request; and receiving the first correspondence sent by the QKD network controller.

[0015] In some possible embodiments of the present disclosure, the key application information includes an application identifier and / or a device identifier for deploying the application.

[0016] According to another aspect of the present disclosure, there is also provided a quantum key management method, which is applied to a QKD network controller and includes: obtaining QKD network status information and a key service identifier; determining a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; and sending the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node determine the key service policy of the application from the first correspondence and provide the key service according to the key service policy of the application.

[0017] In some possible embodiments of the present disclosure, obtaining the key service identifier includes: obtaining a second correspondence sent by the QKD network management system, where the second correspondence includes the correspondence between the key service identifier and the password application requirement information; and determining the first correspondence based on the QKD network status information includes: determining the key service policy corresponding to each key service identifier based on the QKD network status information and the password application requirement information corresponding to each key service identifier.

[0018] In some possible embodiments of the present disclosure, obtaining the QKD network status information includes: periodically sending a network status request to the QKD network management system, where the network status request is used to instruct the QKD network management system to send the QKD network status information to the QKD network controller; receiving the QKD network status information sent by the QKD network management system.

[0019] According to another aspect of the present disclosure, there is also provided a quantum key management system, which includes: key managers of each QKD node of the QKD network and a QKD network controller; wherein, the QKD network controller is configured to obtain the QKD network status information and the key service identifier; determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; send the first correspondence to the key managers of each QKD node; the key managers of each QKD node are configured to determine the applied key service identifier, where the key service identifier is determined by the key application information sent by the application; determine the key service policy of the application based on the applied key service identifier according to the first correspondence, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; provide the key service according to the key service policy of the application.

[0020] In some possible embodiments of the present disclosure, the system further includes: a QKD network management system; the QKD network management system is configured to send the QKD network status information and the key service identifier to the QKD network controller.

[0021] According to another aspect of the present disclosure, there is also provided a quantum key management device, which is configured in the key manager of a QKD node in the QKD network, and includes: a key service identifier determination module, configured to determine the applied key service identifier, where the key service identifier is determined by the key application information sent by the application; a key service policy determination module, configured to determine the key service policy of the application based on the applied key service identifier according to the first correspondence, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; a key service provision module, configured to provide the key service according to the key service policy of the application.

[0022] According to another aspect of the present disclosure, there is also provided a quantum key management device configured in a QKD network controller, including: an acquisition module configured to acquire QKD network status information and a key service identifier; a first correspondence determination module configured to determine a first correspondence based on the QKD network status information, where the first correspondence includes a correspondence between the key service identifier and the key service policy; and a first correspondence sending module configured to send the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node determine the applied key service policy from the first correspondence and provide key services according to the applied key service policy.

[0023] According to another aspect of the present disclosure, there is also provided an electronic device, including: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute the quantum key management method of any one of the above via executing the executable instructions.

[0024] According to another aspect of the present disclosure, there is also provided a computer-readable storage medium having a computer program stored thereon, and the computer program, when executed by a processor, implements the quantum key management method of any one of the above.

[0025] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, and the computer program or instruction, when executed by a processor, implements the quantum key management method of any one of the above.

[0026] The technical solutions provided by the embodiments of the present disclosure may include the following beneficial effects:

[0027] In the quantum key management method provided by the embodiments of the present disclosure, the QKD node determines the applied key service identifier, where the key service identifier is determined by the key application information sent by the application, and then determines the applied key service policy from the correspondence between the key service identifier and the key service policy, and provides key services according to the applied key service policy, realizing the perception of different encryption services and providing differentiated key services for different encryption services, thereby improving the service efficiency.

[0028] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The accompanying drawings herein are incorporated into and form a part of this specification, showing embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0030] Figure 1 Flowchart showing a quantum key management method executed by a key manager of a QKD node in an embodiment of the present disclosure;

[0031] Figure 2 Flowchart showing another quantum key management method executed by a key manager of an edge node in an embodiment of the present disclosure;

[0032] Figure 3 Flowchart showing another quantum key management method executed by a key manager of an access node or a relay node in an embodiment of the present disclosure;

[0033] Figure 4 Flowchart showing yet another quantum key management method executed by a key manager of a QKD node in an embodiment of the present disclosure;

[0034] Figure 5 Flowchart showing a quantum key management method executed by a QKD network controller in an embodiment of the present disclosure;

[0035] Figure 6 Flowchart showing another quantum key management method executed by a QKD network controller in an embodiment of the present disclosure;

[0036] Figure 7 Block diagram showing the structure of a quantum key management system in an embodiment of the present disclosure;

[0037] Figure 8 Flowchart showing the quantum key management interaction method in an embodiment of the present disclosure;

[0038] Figure 9 Schematic diagram showing a quantum key management scenario in an embodiment of the present disclosure;

[0039] Figure 10 Flowchart showing the key distribution in a quantum key management scenario applied in an embodiment of the present disclosure;

[0040] Figure 11 Schematic diagram showing a quantum key management device in an embodiment of the present disclosure;

[0041] Figure 12 Schematic diagram showing another quantum key management device in an embodiment of the present disclosure;

[0042] Figure 13 The structural block diagram of an electronic device in an embodiment of the present disclosure is shown. Detailed implementation manners

[0043] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0044] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0045] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are explained as follows:

[0046] QKD: A technology that uses the principles of quantum mechanics to ensure that two communication parties can securely share encryption keys. The core of QKD lies in ensuring that a string of completely identical random numbers that cannot be obtained by an attacker can be generated between the two communication parties based on the basic principles of quantum mechanics as the shared key to achieve secure information exchange.

[0047] QKD network: A QKD system formed by connecting multiple QKD devices, which can cover a larger area and serve more users. The QKD network allows users in different geographical locations to securely exchange keys and supports the application of various encryption services, such as quantum secure video conferencing, quantum secure voice calls, quantum secure email, quantum secure file transfer, etc.

[0048] Figure 1 The flowchart of a quantum key management method in an embodiment of the present disclosure is shown. In an embodiment of the present disclosure, a quantum key management method is provided, and this method can be executed by the key manager of any QKD node with computing and processing capabilities. As Figure 1 shown, the quantum key management method provided in the embodiment of the present disclosure includes the following steps.

[0049] Among them, the above QKD nodes include edge nodes, access nodes, and relay nodes. Edge nodes can be understood as QKD devices located at the edge of the QKD network, and edge nodes are close to user terminals. Edge nodes can be physical devices, usually including QKD modules and key managers, etc. Access nodes and relay nodes can be understood as core network devices of the QKD network, which can be physical devices and usually include QKD modules and key managers.

[0050] S102. Determine the key service identifier of the application, where the key service identifier is determined by the key application information sent by the application.

[0051] Among them, the application can be understood as an application program that uses QKD technology to encrypt data. The above applications include, but are not limited to: quantum secure video conferencing, quantum secure voice calls, quantum secure emails, quantum secure file transfers, etc.

[0052] The key application information can be understood as relevant information that differentiates different applications or the devices where the applications are located. The key application information includes, but is not limited to: the application identifier using QKD technology or the device identifier using QKD technology.

[0053] Among them, each key service identifier corresponds to different key service requirements. The key service requirements include service quality requirements related to key services, including, but not limited to: key response latency, key response latency jitter, throughput, key transmission loss rate, and so on. Each key service identifier is determined by the key application information sent by the application according to set rules. Specifically, the key service identifier of the application is determined according to the application identifier of the application and / or the device identifier of the device where the application is deployed.

[0054] S104. Determine the key service policy of the application based on the first correspondence relationship according to the key service identifier of the application, where the first correspondence relationship includes the correspondence relationship between the key service identifier and the key service policy, and the first correspondence relationship is determined by the QKD network controller based on the QKD network status information and the key service identifier.

[0055] Among them, the first correspondence relationship refers to the mapping relationship between the key service identifier and the key service policy. Each key service identifier is associated with a set of specific key management and service policies. The key service policy defines the specific methods and processes for providing quantum key distribution services for different types of applications. The first correspondence relationship is sent by the QKD network controller to the key managers of each QKD node in the QKD network, where QKD includes edge nodes, access nodes, relay nodes, etc.

[0056] The key service policy can be understood as a series of rules or parameter configurations formulated for the cryptographic application requirement information, including, but not limited to: key transmission priority, key relay transmission path, and cipher management layer slicing.

[0057] The QKD network controller is used to manage and update the first corresponding relationship, and regularly or on demand send the latest first corresponding relationship to the key managers of each QKD node in the QKD network.

[0058] Each QKD node searches for a key service policy that matches the applied key service identifier in the locally stored first corresponding relationship. If a match is found, the corresponding key management operation is performed according to the key service policy in the record. If no match is found, a default policy can be adopted or an error can be reported to the administrator for manual intervention.

[0059] In a possible implementation, there are three applications within a third party: video conferencing, file transfer, and email. The key service identifier for video conferencing is APP_VIDEO_CONF_01, and its corresponding key service policy is "high key transfer priority, key relay transfer path is node 1 - application, real-time encryption layer". The key service identifier for file transfer is APP_FILE_XFER_02, and its key service policy is "medium key transfer priority, key relay transfer path is node 1 - node 2 - application, batch management layer". The key service identifier for email is APP_EMAIL_SEC_03, and its key service policy is "low key transfer priority, transfer key relay transfer path is node 1 - node 2 - application, batch management layer".

[0060] The key manager of each QKD node searches for APP_VIDEO_CONF_01 in the locally stored first corresponding relationship and finds the corresponding key service policy: "high key transfer priority, key relay transfer path is node 1 - node 2 - application, real-time encryption layer".

[0061] S106: Provide key services according to the key service policy of the application.

[0062] Providing key services can be understood as performing operations related to quantum key relay transmission, including but not limited to: quantum key relay, update, etc.

[0063] Performing key services includes but not limited to: for high-priority applications, giving priority to processing their key requests; using the transfer path in the key service policy for key relay transmission; performing key relay tasks on the specified cryptographic management layer slice.

[0064] The key manager of each QKD node adjusts the operations related to quantum key distribution according to the found key service policy to meet the specific requirements of the application.

[0065] In a business scenario, including Application 1 and Application 2, the key service policy found by Application 1 according to the above method is: "High key transmission priority, key relay transmission path is Node 1 - Application, real-time encryption layer", and the key service policy found by Application 2 according to the above method is: "Medium key transmission priority, key transmission path is Node 1 - Node 2 - Application, batch management layer". When the edge node receives a key request initiated by Application 1, it will be processed preferentially, and an end-to-end key will be quickly formed through the relay transmission path Node 1 - Application, and key generation and management tasks will be executed in the real-time encryption layer. When the edge node receives a key request initiated by Application 2, it will not be placed in the top priority for processing, and key transmission will be carried out through the link of the relay transmission path Node 1 - Node 2 - Application, and key generation and management tasks will be executed in the batch management layer.

[0066] In the quantum key management method provided in the embodiments of the present disclosure, the key manager of the QKD node determines the key service identifier of the application, where the key service identifier is determined by the key application information sent by the application; determines the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; provides key services according to the key service policy of the application, realizes the perception of different encryption services, and provides differentiated key services for different encryption services, improving the service efficiency.

[0067] On the basis of the above embodiments, the embodiments of the present disclosure further optimize the quantum key management method, and the optimized quantum key management method is executed by the edge node. As Figure 2 shown, the optimized quantum key management method mainly includes the following steps.

[0068] S202. The edge node obtains the key application information sent by the application, where the key application information includes the application identifier and / or the device identifier of the device where the application is deployed.

[0069] The application identifier is an identifier used to uniquely identify an application program, including but not limited to: a string, a number, or other forms of identifiers, and the application identifier is used to clearly distinguish different application programs. The device identifier refers to an identifier used to uniquely identify the device where the application is deployed. The device identifier includes but not limited to: a hardware serial number, a MAC address, an IMEI number, or other types of unique codes. The device identifier is used to identify and track the specific device that is using the QKD service. The device where the application is deployed refers to the actual physical or virtual device on which the application program is installed or running, including but not limited to a personal computer, a smart phone, a tablet computer, a server, etc.

[0070] Exemplarily, if an employee of an enterprise uses their own mobile phone (with a unique device identifier, DeviceID) to participate in a quantum-secured video conference provided by the company (with a unique application identifier, App ID), then the employee's mobile phone is the user device on which the video conference application is deployed.

[0071] Receive a key request sent by an application deployed on a user device, where the key request carries an application identifier and / or a device identifier of the device on which the application is deployed.

[0072] S204. The edge node determines a key service identifier of the application based on the key application information.

[0073] In a possible implementation, use the application identifier as the key service identifier, or use the device identifier of the device on which the application is deployed as the corresponding key service identifier, or use a combination of the application identifier and the device identifier of the device on which the application is deployed as the key service identifier.

[0074] Determine the key service identifier of the application according to a set rule based on the key application information, including: determining the key service identifier of the application according to the application identifier of the application and / or the device identifier of the device on which the application is deployed.

[0075] In a possible implementation, use the application identifier as the key service identifier. Exemplarily, an enterprise uses a QKD network for data encryption, including two applications: quantum-secured video conferencing and quantum-secured email. The application identifier of the video conference is APP_VIDEO_CONF_01; the application identifier of the email is APP_EMAIL_SEC_02. In this case, directly use the application identifier as the key service identifier. For example, the key service identifier corresponding to the video conference is KEY_SERVICE_APP_VIDEO_CONF_01; the key service identifier corresponding to the email is KEY_SERVICE_APP_EMAIL_SEC_02.

[0076] In a possible implementation, use the device identifier of the device on which the application is deployed as the corresponding key service identifier. Exemplarily, a company has multiple offices, and each office has an independent encryption router to ensure local network security. Each router has a unique device identifier. The router identifier of Office A is DEVICE_ROUTER_A_001; the router identifier of Office B is DEVICE_ROUTER_B_002. The device identifier of the device on which the application is deployed can be used as the key service identifier. The key service identifier corresponding to the router in Office A is KEY_SERVICE_DEVICE_ROUTER_A_001; the key service identifier corresponding to the router in Office B is KEY_SERVICE_DEVICE_ROUTE R_B_002.

[0077] In a possible implementation, when the application identification of the application and the device identification of the device on which the application is deployed are both included in the key application information, the combination of the application identification of the application and the device identification of the device on which the application is deployed is used as the key service identification. Exemplarily, for the video conference in the router of Office A, its key service identification is KEY_SERVICE_APP_VIDEO_CONF_01_DEVICE_ROUTER_A_001; for the email in the router of Office B, its key service identification is KEY_SERVICE_APP_EMAIL_SEC_02_DEVICE_ROUTER_B_002.

[0078] In a possible implementation, when the key service requirement is included in the key application information, the key service requirement can be quantified, and the quantified key service requirement, together with the application identification and / or the device identification of the device on which the application is deployed, is used to determine the key service identification of the application. Exemplarily, the key service requirements of the quantum secure video conference include: low latency, high bandwidth, very high security level, and a key update frequency of once per hour; the key service requirements of the quantum secure video conference are quantified, and the quantified key service requirement is DELAY = LOW, BANDWIDTH = HIGH, SECURITY_LEVEL = VERY_HIGH, KEY_UPDATE_FREQ = HOURLY; the quantified key service requirement is combined with the application identification and the device identification of the device on which the application is deployed to form the final key service identification: KEY_SERVICE_APP_VIDEO_CONF_01_DEVICE_ROUTER_A_001_DELAY_LOW_BANDWIDTH_HIGH_SECURITY_VERY_HIGH_KEYUPDATE_HOURLY.

[0079] In practical applications, for the sake of easy management and identification, an encoding method or abbreviation can also be used to simplify the key service identification while retaining sufficient information to distinguish different key service configurations.

[0080] It should be noted that only an exemplary illustration of the method for determining the key service identification is provided in this embodiment, rather than a limitation.

[0081] For different applications and different devices on which the applications are deployed, there may be different key service requirements. By using the identifications alone or in combination, key service policies can be customized according to specific key service requirements to meet the key service requirements in different business scenarios.

[0082] S206. The edge node determines the key service policy of the application based on the key service identifier of the application according to the first correspondence relationship. The key service policy includes at least one of the following: key transmission priority; key relay transmission path; key management layer slice. The first correspondence relationship is periodically sent by the QKD network controller to each QKD node in the QKD network. The QKD nodes include one of the following: edge node, access node, relay node.

[0083] The first correspondence relationship is defined by the QKD network controller according to the respective cryptographic application requirement information for the detailed key service policy corresponding to each key service identifier, and the key service policy corresponding to each key service identifier is updated according to the QKD network periodically, and the updated first correspondence relationship is pushed to the key managers of all QKD nodes periodically.

[0084] Through the periodic synchronization mechanism, the QKD network controller adjusts the key service policy according to the latest QKD network status information, so that the key service policy is adapted to the latest QKD network status information, improving the efficiency and quality of the key service.

[0085] The key transmission priority refers to the priority order when processing different application key requests in the QKD network. High-priority applications will be given priority in resource competition. For applications with extremely high requirements for real-time performance and security, a higher key transmission priority is set to quickly obtain the latest keys, thus ensuring the security and timeliness of communication.

[0086] The key relay transmission path refers to the specific key relay transmission route for forming an end-to-end key between the two communication parties. The selection of the key relay transmission path is based on multiple factors, including but not limited to: latency, security, cost, etc. Selecting an appropriate key relay transmission path helps to optimize the efficiency and security of the key relay. For example, for applications that require low latency, a direct path passing through fewer nodes can be selected.

[0087] The key management layer slice can be understood as selecting an appropriate layer or module in the multi-layer network architecture to perform the key relay task. Different layers may provide different service qualities. For example, some layers focus on fast response, while other layers emphasize high encryption. By selecting the most suitable key management layer, the best service quality can be provided according to the specific requirements of the application.

[0088] In this embodiment, by setting the key service policy from different dimensions such as transmission priority, key relay transmission path, and key management layer slice, while ensuring security, the resource utilization rate is provided, thereby improving the efficiency of the key service.

[0089] S208. Generate a key relay packet, where the header part of the key relay packet encapsulates the key service identifier.

[0090] A key relay packet refers to a structured data packet that includes the key to be relayed and metadata related to the key, including but not limited to: the key service identifier of the application, the key validity timestamp, the encryption algorithm identifier, the check code, the target address or routing information, etc., so as to securely relay in the QKD network to form an end-to-end key.

[0091] S210. Provide key services according to the key service policy of the application.

[0092] When the key service policy is that it can be directly sent to the application, the edge node processes the key relay packet according to the key service policy, provides the key relay service, generates the end-to-end key of the application, and sends the end-to-end key to the application.

[0093] When the key service policy is that relay is required, the edge node sends the relay packet to the corresponding access node or relay node according to the key service policy, so that the access node or relay node executes the process of quantum key management according to the key service identifier in the relay packet.

[0094] In this embodiment, the abstract key application information is converted into a quantified key service identifier to facilitate the transmission of the key service identifier in the entire QKD network and improve the efficiency of quantum key management.

[0095] Based on the above embodiments, the embodiments of the present disclosure further optimize the quantum key management method, and the optimized quantum key management method is executed by a relay node or an access node. As Figure 3 shown, the optimized quantum key management method mainly includes the following steps.

[0096] S302. Receive the key relay packet sent by the edge node.

[0097] A key relay packet refers to a structured data packet that includes the key to be relayed and metadata related to the key, including but not limited to: the key service identifier of the application, the key validity timestamp, the encryption algorithm identifier, the check code, the target address or routing information, etc.

[0098] The key relay packet is encapsulated and generated by the edge node, and the edge node determines the relay node or access node that receives the key relay packet according to the relay transmission path in the key service policy. After the edge node sends the key relay packet, the relay node or access node receives the key relay packet.

[0099] S304. Read the key service identifier encapsulated in the header part of the key relay packet.

[0100] The structure of the key relay packet is generally divided into two parts: a packet header and a payload. The packet header part includes: the key service identifier of the application, the key validity timestamp, the encryption algorithm identifier, the check code, the target address or routing information, etc., which are used to guide the transmission and processing of the packet. The payload is the actual data content (such as keys, service data, etc.). Reading the packet header is the first step in parsing the key relay packet, which is used to identify the type and purpose of the packet.

[0101] The relay node or access node locates the identification field in the packet header according to a custom protocol or a standard key management protocol. Extracting the value of this field is the key service identifier.

[0102] S306. Determine the key service policy of the application based on the first correspondence relationship according to the key service identifier of the application, where the first correspondence relationship includes the correspondence relationship between the key service identifier and the key service policy, and the first correspondence relationship is determined by the QKD network controller based on the QKD network status information and the key service identifier.

[0103] S308. Process the key relay packet according to the key service policy, provide the key relay service, and generate the end-to-end key of the application.

[0104] In a possible implementation, the edge node sends the key relay packet to the access node or relay node according to the key service policy. The key manager on the access node or relay node reads the key service identifier in the packet header part of the key relay packet, queries the locally cached first correspondence relationship based on this key service identifier, and obtains the corresponding key service policy.

[0105] Perform the following operations according to the key service policy: priority queue selection, selection of the key relay transmission path, slice scheduling of the key management layer, etc. Exemplarily, put the key relay packet into a high-priority queue for fast forwarding, transmit the key according to the key relay transmission path in the key service policy, and guide the key relay packet into the specified key management layer for further processing.

[0106] Exemplarily, the key service policy of an online payment application is: high priority, key relay transmission path 1, real-time encryption layer; the key relay packet is immediately put into a high-priority queue, select the key relay transmission path 1 for key relay, and select the real-time encryption layer for fast key distribution to ensure the security and timeliness of high-frequency transactions.

[0107] S310. Send the end-to-end key to the application.

[0108] In this embodiment, by adding a key service identifier to the key relay packet and letting the access node and relay node perform corresponding routing selection, slice selection and other operations according to these identifiers, the refined management of the key stream is realized, and the key service efficiency is improved.

[0109] Based on the above embodiments, the embodiments of the present disclosure further optimize the quantum key management method. As Figure 4 shown, the optimized quantum key management method mainly includes the following steps.

[0110] S402. Send a key service policy distribution request to the QKD network controller, so that the QKD network controller sends a first correspondence to the key manager of the QKD node based on the key service policy distribution request.

[0111] The key service policy distribution request can be understood as a request instruction sent by any one or more nodes in the QKD node to the QKD network controller, used to request the QKD network controller to distribute the latest key service policy. The key service policy distribution request may include the identity authentication information of the QKD node, so that only authorized nodes can request policy updates.

[0112] Sending a key service policy distribution request to the QKD network controller includes: when a new application is added to the QKD network, sending a key service policy distribution request to the QKD network controller, or when the security or performance requirements of an existing application change, sending a key service policy distribution request to the QKD network controller, or periodically sending a key service policy distribution request to the QKD network controller.

[0113] After receiving the key service policy distribution request, the QKD network controller sends the most recent first correspondence to the key managers of each QKD node. The first correspondence includes the correspondence between each key service identifier, password application requirement information, and key service policy.

[0114] S404. Receive the first correspondence sent by the QKD network controller.

[0115] After each QKD node receives the first correspondence sent by the QKD network controller, it performs integrity verification to ensure that the data has not been tampered with. Verify the authenticity of the source to confirm that the information indeed comes from the QKD network controller rather than a forged data packet.

[0116] Each QKD node stores the received first correspondence in a local database or cache for subsequent quick query and use. Update the local key service policy configuration to make the new or changed key service policy take effect immediately. For example, if the key transmission priority of Application 1 changes from low to high, the corresponding key request will be placed in a higher priority queue for processing.

[0117] S406. Determine the key service identifier of the application, where the key service identifier is determined by the key application information sent by the application.

[0118] S408. Determine the key service policy of the application based on the key service identifier of the application according to the first correspondence relationship, where the first correspondence relationship includes the correspondence relationship between the key service identifier and the key service policy, and the first correspondence relationship is determined by the QKD network controller based on the QKD network status information and the key service identifier.

[0119] S410. Provide key services according to the key service policy of the application.

[0120] In this embodiment, by initiating a request through the edge node, the QKD network controller issues the first correspondence relationship, avoiding the problems of stale or redundant policies that may occur in the "full-scale broadcast" policy distribution, reducing the communication overhead between the QKD network controller and the edge node, and reducing the bandwidth occupancy.

[0121] Figure 5 The flowchart of a quantum key management method in an embodiment of the present disclosure is shown. In an embodiment of the present disclosure, a quantum key management method is provided, and this method can be executed by any QKD network controller with computing and processing capabilities. As Figure 5 shown, the quantum key management method provided in an embodiment of the present disclosure includes the following steps.

[0122] S502. Obtain QKD network status information and key service identifiers.

[0123] Among them, the QKD network status information can be understood as the current operating conditions and technical parameters of the entire QKD network, including but not limited to: the availability of each QKD link, the key generation rate of the link, channel loss, bit error rate, the current link load condition, available relay nodes, cipher management layer slice resources, remaining key amount, key consumption rate, etc.

[0124] Obtaining QKD network status information includes: obtaining QKD network status information sent by the QKD network management system. Among them, the QKD network management system is a centralized management platform for monitoring and managing the operation of the entire QKD network, providing comprehensive monitoring of QKD devices, network status, and the overall network topology.

[0125] The QKD network controller obtains QKD network status information from the QKD network management system, dynamically adjusts the key service policy according to the QKD network status information, and coordinates the key distribution work between the edge node, access node, and relay node.

[0126] Obtaining a key service identifier includes: obtaining the key service identifier issued by the QKD network management system. Each key service identifier corresponds to different password application requirement information. The password application requirement information includes an application identifier, a device identifier for deploying the application, and a key service requirement. The key service requirement includes the quality of service related to the key service. The quality of service related to the key service includes, but is not limited to: key response latency, key response latency jitter, throughput, key transmission loss rate, and so on.

[0127] S504. Determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy.

[0128] Among them, the key service policy contains a series of rules and parameters for providing personalized key services for applications. The key service policy includes, but is not limited to: key transmission priority, key relay transmission path selection, and cipher management layer slice configuration. The key transmission priority includes: high, medium, low, etc. The key relay transmission path includes: the shortest path, the low-latency path, the cost-effective path, etc. The cipher management layer slice configuration includes: the real-time encryption layer, the batch processing layer, etc.

[0129] In a possible implementation, each key service identifier corresponds to a key service requirement. The key service policy corresponding to the key service identifier is determined according to the QKD network status information and the key service requirement. Exemplarily, when the QKD network status information is in an idle state, for high-priority voice call encryption, an idle or better path is determined for key relay to provide end-to-end key services. For low-priority email encryption, a sub-optimal path can be determined for key relay to provide end-to-end key services. If the obtained QKD network status information is relatively busy and there is congestion in key requests or key relays, a degraded key service policy may be given according to the QKD network status information.

[0130] S506. Send the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node can determine the key service policy of the application from the first correspondence and provide key services according to the key service policy of the application.

[0131] After the QKD network controller determines the first correspondence, the QKD network controller distributes the updated first correspondence to relevant edge nodes, access nodes, and relay nodes. After receiving the first correspondence, the edge nodes, access nodes, and relay nodes immediately execute key relay, encapsulation, and forwarding tasks according to the key service policy in the updated first correspondence.

[0132] In this embodiment, the first corresponding relationship is dynamically adjusted based on the QKD network status information, so that it can flexibly respond to changes in the network environment, ensure that each application can obtain the key service strategy that best suits its own needs, and improve key security and key service efficiency.

[0133] Based on the above embodiments, the embodiments of the present disclosure further optimize the quantum key management method, such as Figure 6 As shown, the optimized quantum key management method mainly includes the following steps.

[0134] S602. Obtain a second corresponding relationship sent by the QKD network management system, wherein the second corresponding relationship includes a corresponding relationship between a key service identifier and cryptographic application requirement information.

[0135] The cryptographic application requirement information includes the application identifier that uses the key, the device identifier that deploys the application, and the key service requirement information.

[0136] The QKD network management system obtains the cryptographic application requirement information from the user network system, and then determines the key service identifier corresponding to the cryptographic application requirement information based on the application identifier in the key application requirement information and / or the device identifier of the deployed application. After determining the key service identifier, a corresponding relationship between the key service identifier and the cryptographic application requirement information is established, which is the second corresponding relationship. The second corresponding relationship is periodically sent to the QKD network controller through the QKD network management system.

[0137] The manner of determining the key service identifier according to the application identifier and / or the identifier of the device deploying the application may refer to the description in the above embodiment and will not be described in detail in this embodiment.

[0138] S604. Periodically send a network status request to the QKD network management system, wherein the network status request is used to instruct the QKD network management system to send QKD network status information to the QKD network controller.

[0139] The network status request is a network status query request sent by the QKD network controller to the QKD network management system to obtain the latest QKD network status information. The network status request includes network status information requirements or query conditions so that the QKD network management system can provide the required data in a targeted manner.

[0140] A timer is set inside the QKD network controller to trigger the sending of a network status request at a preset time interval (for example, every 5 minutes). When the QKD network management system receives the network status request, it collects and organizes the current QKD network status information and returns it to the QKD network controller through the same communication channel.

[0141] S606. Receive the QKD network status information sent by the QKD network management system.

[0142] After the QKD network controller receives the response, it parses and validates the returned data to ensure its integrity and accuracy. If the data format is JSON, an appropriate parsing library can be used to convert it into an operable object or structure. The parsed QKD network status information is stored in a local database or cache for subsequent decision-making. The QKD network controller can adjust the key service policy, select the best path, optimize resource allocation, etc. according to the QKD network status information.

[0143] By periodically sending network status requests to the QKD network management system, the QKD network controller can obtain the latest network status information in a timely manner, make more accurate decisions, and improve the efficiency of key services.

[0144] S608. Determine the key service policies corresponding to each key service identifier based on the QKD network status information and the password application requirement information corresponding to each key service identifier, where the key service policy includes at least one of the following: key transmission priority, key relay transmission path, and key management layer slicing.

[0145] The key transmission priority refers to the priority order for processing different application key requests in the QKD network. Higher-priority applications will be given priority consideration in resource competition. Applications with extremely high requirements for real-time performance and security are set with a higher key transmission priority to quickly obtain the latest keys, thereby ensuring the security and timeliness of communication.

[0146] The key relay transmission path refers to the specific key relay route for forming an end-to-end key from the edge node at the source end to the edge node at the destination end. The selection of the key relay transmission path is based on multiple factors, including but not limited to latency, security, cost, etc. Selecting an appropriate transmission path helps to optimize the key relay efficiency. For example, for applications that require low latency, a direct path passing through fewer nodes can be selected.

[0147] The key management layer slicing can be understood as dividing different levels in the key management layer where the key manager is located for key relay transmission tasks. Different levels may provide different service qualities. For example, some levels focus on quick response, while other levels provide best-effort key relay transmission. By selecting the most suitable key management layer slicing, the best service quality can be provided according to the specific requirements of the application.

[0148] In this embodiment, by setting the key service policy from different dimensions such as transmission priority, key relay transmission path, and key management layer slicing, the resource utilization rate is improved on the premise of ensuring security, and further the efficiency of key services is improved.

[0149] Determine the key service policies corresponding to each key service identifier based on the QKD network status information and the cryptographic application requirement information corresponding to each key service identifier, where the key service policies include at least one of the following: key transmission priority, key relay transmission path, and cipher management layer slicing.

[0150] The QKD network controller dynamically formulates or adjusts the key service policies for each key service identifier according to the collected QKD network status information and the cryptographic application requirement information corresponding to each key service identifier.

[0151] In a possible implementation, different priorities are set for different applications according to quality requirements such as the importance and real-time requirements of the applications. For example, the priority of the online payment application is set to high, and the priority of the email application can be set to medium.

[0152] In a possible implementation, the optimal transmission path is selected for each application according to network status such as link quality and load conditions. For example, if the QBER of a link is too high, this link should be avoided; for latency-sensitive applications, a low-latency path is selected.

[0153] In a possible implementation, the key stream is allocated to different cipher management layer slices according to the service quality, security, etc. requirements of the application. For example, high-security applications are allocated to a dedicated real-time encryption layer, and applications with lower security requirements can use the batch processing layer.

[0154] In a possible implementation, the key service policies corresponding to the above key service identifiers can be specific execution operations of the key service. For example: The key service policies corresponding to key service identifier 1 include: the key transmission priority is high, the key relay transmission path is: node 1 - node 2 - application, and the cipher management layer slice is the real-time encryption layer.

[0155] In this embodiment, the key service policies are dynamically determined based on the QKD network status information and the cryptographic application requirement information corresponding to each key service identifier, so as to be able to flexibly respond to changes in the network environment, ensure that each application can obtain the key service policy most suitable for its own needs, and thus improve the key service efficiency.

[0156] S610. Send the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node determine the key service policies of the application from the first correspondence and provide key services according to the key service policies of the application.

[0157] In this embodiment, the first correspondence includes the correspondence between the key service identifier, the cryptographic application requirement information, and the key service policy.

[0158] After the QKD network controller determines the first correspondence, it sends the updated first correspondence to the relevant edge nodes, access nodes, and relay nodes. After receiving the first correspondence, these nodes perform key relay, encapsulation, and forwarding tasks according to the key service policies included in the updated first correspondence. For example, an edge node may arrange the processing order of key requests according to a new priority queue or perform key transmission according to a new transmission path.

[0159] Embodiments of the present disclosure provide a quantum key management system. The quantum key management system mainly includes: a QKD network controller, key managers of each node in the QKD network (including edge nodes, access nodes, and relay nodes), and devices for deploying applications. Based on this quantum key management system, embodiments of the present disclosure provide an interaction method for quantum key management. As Figure 7 shown, the quantum key management method provided in the embodiments of the present disclosure includes the following steps.

[0160] S702. The QKD network controller obtains QKD network status information and key service identifiers.

[0161] The QKD network controller obtaining QKD network status information includes: obtaining QKD network status information sent by the QKD network management system.

[0162] The QKD network controller obtaining key service identifiers includes: the QKD network controller obtaining key service identifiers sent by the QKD network management system. Each key service identifier corresponds to different password application requirement information. The password application requirement information includes an application identifier, a device identifier for deploying the application, and a key service requirement. The key service requirement includes a quality of service requirement related to the key service. The quality of service requirement related to the key service includes, but is not limited to: key response latency, key response latency jitter, throughput, key transmission loss rate, and so on.

[0163] S704. The QKD network controller determines a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy.

[0164] The QKD network controller is responsible for dynamically adjusting the key service policy according to the QKD network status information obtained from the QKD network management system and coordinating the key distribution work among edge nodes, access nodes, and relay nodes.

[0165] Determine the key service policy corresponding to the key service identifier according to the QKD network status information and the key service requirements. Exemplarily, when the QKD network status information is in an idle state, for high-priority voice call encryption, determine an idle or relatively optimal path for key relay to provide end-to-end key services. For low-priority email encryption, a sub-optimal path can be determined for key relay to provide end-to-end key services. If the obtained QKD network status information is relatively busy and there is congestion in key requests or key relays, a degraded key service policy may be given according to the QKD network status information.

[0166] S706. The QKD network controller sends the first corresponding relationship to the key managers of each QKD node.

[0167] The edge node obtains the key application information sent by the application, including: receiving the key request sent by the application deployed in the user equipment, where the key request carries the key application information of the application.

[0168] In a possible implementation, use the application identifier as the key service identifier; or use the device identifier of the deployed application as the corresponding key service identifier; or use the combination of the application identifier and the device identifier of the deployed application as the key service identifier.

[0169] S708. Each QKD node on the key relay path determines the key service identifier of the application.

[0170] S710. Determine the key service policy of the application in the first corresponding relationship based on the key service identifier of the application.

[0171] S712. Each node provides key services according to the key service policy of the application.

[0172] Each node searches for the key service policy that matches the key service identifier of the application in the locally stored first corresponding relationship. If a matching item is found, perform the corresponding key management operation according to the key service policy in the record. If no matching item is found, a default policy can be adopted or an error can be reported to the administrator for manual intervention.

[0173] In an embodiment of the present disclosure, a quantum key management system is provided, which includes: key managers of each QKD node (including edge nodes, access nodes, and relay nodes) in the QKD network and a QKD network controller; wherein, the QKD network controller is configured to obtain QKD network status information and a key service identifier; determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; send the first correspondence to the key managers of each node; the key manager of the edge node is configured to obtain key application information sent by an application; determine the key service identifier of the application based on the key application information, and encapsulate the identifier into the header part of the key relay packet; the key managers of each node determine the key service policy of the application in the first correspondence based on the key service identifier of the application, and provide key services according to the key service policy of the application.

[0174] Based on the above embodiment, the embodiment of the present disclosure optimizes the quantum key management system. The optimized quantum key management system mainly includes: a QKD network controller, key managers of each node, and a QKD network management system. Based on this quantum key management system, an interaction method for quantum key management is provided in the embodiment of the present disclosure. As Figure 8 shown, the quantum key management method provided in the embodiment of the present disclosure includes the following steps.

[0175] S802. The QKD network management system sends QKD network status information and a key service identifier to the QKD network controller.

[0176] Among them, the QKD network management system is a centralized management platform for monitoring and managing the operation status of the entire QKD network, and providing comprehensive monitoring of QKD devices, network status, and the overall network topology.

[0177] In a possible implementation, the user network management system collects password application requirement information and sends the password application requirement information to the QKD network management system. The user network management system is used to collect the requirement information of password applications and provide a data basis for subsequent processes.

[0178] The QKD network management system determines a key service identifier according to the obtained password application requirement information, establishes a second correspondence between the key service identifier and the password application requirement information, and sends the second correspondence to the QKD network control.

[0179] The QKD network management system periodically sends QKD network status information to the QKD network controller.

[0180] The QKD network management system can enable the QKD controller to timely understand the operating status of each device and link in the network by regularly or real-time sending network status information, and flexibly adjust the key distribution and management methods according to specific service requirements.

[0181] S804. The QKD network controller determines a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy.

[0182] S806. The QKD network controller sends the first correspondence to the key managers of each QKD node (including edge nodes, access nodes, and relay nodes).

[0183] S808. The edge node obtains the key application information sent by the application.

[0184] S810. The edge node determines the key service identifier of the application based on the key application information and encapsulates the identifier into the packet header of the key relay packet.

[0185] S812. The edge node sends the key relay packet to the relay node or the access node. The relay node or the access node receives the key relay packet sent by the edge node.

[0186] S814. The relay node or the access node reads the key service identifier encapsulated in the packet header part of the key relay packet and determines the key service policy of the application based on the key service identifier of the application in the first correspondence.

[0187] S816. Process the key relay packet according to the key service policy, provide the key relay service, and generate the end-to-end key of the application.

[0188] S818. Send the end-to-end key to the application.

[0189] In a possible application scenario, a schematic diagram of a quantum key management scenario is provided, such as Figure 9As shown in the figure, the quantum key management scenario includes: user device A910, user device B920, user network management system 930, QKD network management system 940, QKD network controller 950, edge node A960, edge node B970, access node A980, access node B990, relay node A9100, and relay node B9110. Edge node A960 includes a key manager 961 and a QKD module 962. Edge node B970 includes a key manager 971 and a QKD module 972. Access node A980 includes a key manager 981 and a QKD module 982. Access node B990 includes a key manager 991 and a QKD module 992. Relay node A9100 includes a key manager 9101 and a QKD module 9102. Relay node B9110 includes a key manager 9111 and a QKD module 9112.

[0190] Among them, the user device refers to the device used by the end user, running password application 1 and password application 2. The password application uses QKD technology for security operations such as data encryption and decryption to ensure the security of the user's service data.

[0191] The QKD network controller is the control center of the QKD network, used to ensure the secure, stable, efficient, and robust operation of the entire QKD network. The QKD network controller mainly includes functions such as session control, routing control, configuration control, policy control, and access control.

[0192] The QKD network management system is used to manage the QKD network, including collecting network status information and sending it to the QKD network controller.

[0193] The edge node is located at the edge of the QKD network, connecting the user device to the QKD core network. It includes: a key manager for managing local keys, and a QKD module for realizing the generation and distribution functions of quantum keys to provide secure keys for the user device.

[0194] The access node is used to connect edge nodes, etc. to the QKD core network. It also includes a key manager and a QKD module. The key manager is responsible for key relay, and the QKD module is responsible for segmented key distribution.

[0195] The relay node is used to extend the distance of quantum key distribution. It consists of a key manager and a QKD module. Similarly, the key manager is responsible for key relay, and the QKD module is responsible for segmented key distribution.

[0196] The key manager is responsible for the storage, distribution, update, and destruction of keys in each node throughout their life cycle to ensure the security and compliance of key usage. The QKD module is used to generate and distribute secure keys based on quantum key distribution technology, using the characteristics of quantum states (such as quantum entanglement and quantum superposition), and is a key component for achieving quantum secure communications.

[0197] based on Figure 9 application scenarios, providing a quantum key service process, such as Figure 10 As shown, the quantum key service process provided by this embodiment includes the following steps.

[0198] S1002. The user network management system collects cryptographic application requirement information and sends the cryptographic application requirement information to the QKD network management system.

[0199] The user network management system is responsible for collecting information on password application requirements and providing a data basis for subsequent processes.

[0200] S1004. The QKD network management system determines the key service identifier based on the collected cryptographic application requirement information, and establishes a corresponding relationship between the key service identifier and the cryptographic application requirement information.

[0201] S1006. The QKD network management system sends the correspondence between the key service identifier and the cryptographic application requirement information to the QKD network controller.

[0202] S1008. The QKD network controller sends a QKD network status information request to the QKDN network management system.

[0203] S1010. The QKDN network management system sends QKD network status information to the QKD network controller.

[0204] S1012. The QKD network controller determines the key service policy related to the key service identifier based on the QKD network status information.

[0205] S1014. The QKD network controller sends the correspondence table of key service identifier-cryptographic application requirement information-key service policy to the key manager.

[0206] It should be noted that S1008-S1014 may be executed periodically, and the cycle and execution times are not specifically limited in this embodiment.

[0207] S1016. Cryptographic application 1 initiates a key request to the key manager.

[0208] S1018. The key manager reads the cryptographic application information and determines the corresponding key service identifier and key service policy.

[0209] S1020. The key manager generates an end-to-end key according to the key service policy.

[0210] S1022. The key manager provides the generated key to the cryptographic application 1.

[0211] Among them, the key manager is deployed in an edge node, an access node, or a relay node.

[0212] In this embodiment, the service awareness capability is introduced into the QKD network, and the method and workflow for perceiving encrypted services and providing differentiated key services in the QKD network enable the QKD network to accurately perceive the key service requirements of each cryptographic application or user and provide differentiated key services.

[0213] It should be noted that in the technical solution of the present disclosure, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations. In the embodiments of the present disclosure, various types of data such as personal identity data, operation data, and behavior data related to individuals, customers, and groups have been authorized.

[0214] According to the same inventive concept, an embodiment of the present disclosure also provides a quantum key management device as described in the following embodiments. Since the principle of solving problems in this device embodiment is similar to that of the above method embodiment, the implementation of this device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0215] Figure 11 The following shows a schematic diagram of a quantum key management device in an embodiment of the present disclosure, as Figure 11 shown, the device is configured in a QKD node, and the device includes: a key service identifier determination module 1110, a key service policy determination module 1120, and a key service provision module 1130.

[0216] The key service identifier determination module 1110 is used to determine the key service identifier of the application, where the key service identifier is determined by the key application information sent by the application; the key service policy determination module 1120 is used to determine the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; the key service provision module 1130 is used to provide key services according to the key service policy of the application.

[0217] In some possible embodiments of the present disclosure, when the QKD node is an edge node, the key service identifier determination module 1110 is specifically configured to receive the key application information sent by the application; generate a key service identifier according to the key application information.

[0218] In some possible embodiments of the present disclosure, when the QKD node is a relay node or an access node, the key service identification determination module 1110 is specifically configured to receive a key relay packet sent by an edge node; and read the key service identification encapsulated in the header part of the key relay packet.

[0219] In some possible embodiments of the present disclosure, providing a key service according to the applied key service policy includes: processing the key relay packet according to the key service policy, providing a key relay service, generating an end-to-end key for the application; and sending the end-to-end key to the application.

[0220] In some possible embodiments of the present disclosure, the key service providing module 1130 is specifically configured to generate a key relay packet for the application based on the key service identification of the application; process the key relay packet based on the key service policy, provide a key relay service, generate an end-to-end key for the application; and send the end-to-end key to the application.

[0221] In some possible embodiments of the present disclosure, the key service policy includes at least one of the following: key transmission priority, key relay transmission path, and cipher management layer slicing.

[0222] In some possible embodiments of the present disclosure, the first correspondence is periodically sent by the QKD network controller to the key manager of the QKD node, where the QKD node includes one of the following: edge node, access node, relay node.

[0223] In some possible embodiments of the present disclosure, it further includes: a request module, configured to send a key service policy distribution request to the QKD network controller, so that the QKD network controller sends the first correspondence to the key manager of the QKD node based on the key service policy distribution request; and receive the first correspondence sent by the QKD network controller.

[0224] In some possible embodiments of the present disclosure, the key application information includes an application identification and / or a device identification of the deployed application.

[0225] Figure 12 The following shows a schematic diagram of a quantum key management device in an embodiment of the present disclosure, as Figure 12 shown, the device is configured in the QKD network controller, and the device includes: an acquisition module 1210, a first correspondence determination module 1220, and a first correspondence sending module 1230.

[0226] Among them, an obtaining module 1210 is configured to obtain QKD network status information and a key service identifier; a first correspondence determining module 1220 is configured to determine a first correspondence based on the QKD network status information, where the first correspondence includes a correspondence between the key service identifier and the key service policy; a first correspondence sending module 1230 is configured to send the first correspondence to the key managers of each QKD node, so that the key managers of each node determine the applied key service policy from the first correspondence and provide key services according to the applied key service policy.

[0227] In some possible embodiments of the present disclosure, the obtaining module 1210 is specifically configured to obtain a second correspondence sent by the QKD network management system, where the second correspondence includes a correspondence between the key service identifier and the password application requirement information; the first correspondence determining module 1220 is specifically configured to determine the key service policy corresponding to each key service identifier based on the QKD network status information and the password application requirement information corresponding to each key service identifier.

[0228] In some possible embodiments of the present disclosure, the obtaining module 1210 is specifically configured to periodically send a network status request to the QKD network management system, where the network status request is used to instruct the QKD network management system to send QKD network status information to the QKD network controller; and receive the QKD network status information sent by the QKD network management system.

[0229] It should be noted here that the examples and application scenarios implemented by each module in the above device embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as part of a device, can be executed in a computer system such as a set of computer executable instructions.

[0230] Those skilled in the art can understand that various aspects of the present disclosure can be specifically implemented in the following forms, that is: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module" or "system" here.

[0231] According to the same inventive concept, an electronic device is further provided in an embodiment of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the quantum key management method of any one of the above via executing the executable instructions. Since the principle of solving problems in this electronic device embodiment is similar to that of the above method embodiment, the implementation of this electronic device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0232] The following refers toFigure 13 Describe the electronic device 1300 according to this embodiment of the present disclosure. Figure 13 The displayed electronic device 1300 is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0233] As Figure 13 shown, the electronic device 1300 is presented in the form of a general-purpose computing device. The components of the electronic device 1300 may include but are not limited to: the above-mentioned processing unit 1310, the above-mentioned storage unit 1320, and a bus 1330 connecting different system components (including the storage unit 1320 and the processing unit 1310).

[0234] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1310, so that the processing unit 1310 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0235] The storage unit 1320 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 13201 and / or a cache storage unit 13202, and may further include a read-only storage unit (ROM) 13203.

[0236] The storage unit 1320 may further include a program / utilities 13204 having a set (at least one) of program modules 13205. Such program modules 13205 include but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.

[0237] The bus 1330 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.

[0238] The electronic device 1300 can also communicate with one or more external devices 1340 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1300, and / or communicate with any device that enables the electronic device 1300 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 1350. Also, the electronic device 1300 can communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1360. As shown in the figure, the network adapter 1360 communicates with other modules of the electronic device 1300 through the bus 1330. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0239] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0240] According to the same inventive concept, embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the quantum key management method of any one of the above. Since the principle of solving problems in the embodiment of the computer-readable storage medium is similar to that of the above method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0241] More specific examples of the computer-readable storage medium in the present disclosure can include but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0242] In the present disclosure, a computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0243] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0244] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0245] According to the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instruction, which, when executed by a processor, implements the quantum key management method of any one of the foregoing method embodiments. Since the principle of solving problems in the embodiments of this computer program product is similar to that of the foregoing method embodiments, the implementation of the embodiments of this computer program product may refer to the implementation of the foregoing method embodiments, and the repeated parts will not be described again.

[0246] It should be noted that although several modules or units of devices for action execution are mentioned in the foregoing detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the foregoing modules or units may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0247] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that these steps must be performed in that specific order, or that all of the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0248] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.

[0249] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A quantum key management method, characterized in that, The method is applied to the key manager of a QKD node in a quantum key distribution (QKD) network, and includes: Determine the key service identifier applied, where the key service identifier is determined by the key application information sent by the application; Determine the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; Provide key services according to the key service policy of the application.

2. The quantum key management method according to claim 1, characterized in that When the QKD node is an edge node, the determination of the key service identifier of the application includes: Receive the key application information sent by the application; Generate a key service identifier according to the key application information.

3. The quantum key management method according to claim 2, wherein When the QKD node is a relay node or an access node, the determination of the key service identifier of the application includes: Receive the key relay packet sent by the edge node; Read the key service identifier encapsulated in the header part of the key relay packet.

4. The quantum key management method according to claim 3, wherein Providing key services according to the key service policy of the application includes: Process the key relay packet according to the key service policy, provide key relay services, and generate the end-to-end key of the application; Send the end-to-end key to the application.

5. The quantum key management method according to any one of claims 1-4, characterized in that The key service policy includes at least one of the following: key transmission priority, key relay transmission path, and cipher management layer slicing.

6. The quantum key management method according to any one of claims 1-4, characterized in that, The first correspondence is periodically sent by the QKD network controller to the key managers of each QKD node, where the QKD node includes one of the following: edge node, access node, relay node.

7. The quantum key management method according to any one of claims 1-4, characterized in that It further includes: Send a key service policy distribution request to the QKD network controller, so that the QKD network controller sends the first correspondence to the key managers of the QKD nodes based on the key service policy distribution request; Receive the first correspondence sent by the QKD network controller.

8. The quantum key management method according to claim 1, wherein The key application information includes the application identifier of the application and / or the device identifier where the application is deployed.

9. A quantum key management method, characterized in that, The method is applied to a QKD network controller of a quantum key distribution (QKD) network, and includes: Obtain QKD network status information and key service identifiers; Determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; Send the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node determine the key service policy of the application from the first correspondence and provide key services according to the key service policy of the application.

10. The quantum key management method according to claim 9, wherein The obtaining of the key service identifier includes: Obtain a second correspondence sent by the QKD network management system, where the second correspondence includes the correspondence between the key service identifier and the cipher application requirement information; Determining the first correspondence based on the QKD network status information includes: Determine the key service policies corresponding to each of the key service identifiers based on the QKD network status information and the password application requirement information corresponding to each of the key service identifiers.

11. The quantum key management method according to claim 9, characterized in that, The obtaining of the QKD network status information includes: Periodically sending a network status request to the QKD network management system, where the network status request is used to instruct the QKD network management system to send the QKD network status information to the QKD network controller; Receiving the QKD network status information sent by the QKD network management system.

12. A quantum key management system, characterized in that, The system includes: key managers of each QKD node in the quantum key distribution (QKD) network and a QKD network controller; Among them, the QKD network controller is used to obtain QKD network status information and key service identifiers; determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; and send the first correspondence to the key managers of each QKD node. The key managers of each QKD node are used to determine the key service identifier to be applied, where the key service identifier is determined by the key application information sent by the application; determine the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; and provide key services according to the key service policy of the application.

13. The quantum key management system according to claim 12, characterized in that, It further includes: A QKD network management system; The QKD network management system is used to send the QKD network status information and the key service identifiers to the QKD network controller.

14. A quantum key management device, characterized in that, The device is configured in the key manager of a QKD node in the quantum key distribution (QKD) network and includes: A key service identifier determination module, which is used to determine the key service identifier to be applied, where the key service identifier is determined by the key application information sent by the application; A key service policy determination module, which is used to determine the key service policy of the application based on the first correspondence according to the key service identifier of the application, where the first correspondence includes the correspondence between the key service identifier and the key service policy, and the first correspondence is determined by the QKD network controller based on the QKD network status information and the key service identifier; A key service providing module, which is used to provide key services according to the key service policy of the application.

15. A quantum key management device, characterized in that, The device is configured in the QKD network controller and includes: An obtaining module, which is used to obtain QKD network status information and key service identifiers; A first correspondence determination module, which is used to determine a first correspondence based on the QKD network status information, where the first correspondence includes the correspondence between the key service identifier and the key service policy; The first correspondence sending module is configured to send the first correspondence to the key managers of each QKD node, so that the key managers of each QKD node determine the applied key service policy from the first correspondence and provide key services according to the applied key service policy.

16. An electronic device, characterized in that, Comprising: A processor; And A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the quantum key management method according to any one of claims 1 to 11 by executing the executable instructions.

17. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the quantum key management method according to any one of claims 1 to 11.

18. A computer program product, comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the quantum key management method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Quantum key service management system and method

    CN108809631A

  • Quantum security password system and infrastructure

    CN115567196A

  • Cooperative control method and system for quantum key output in quantum secret communication network

    CN119814294A