Dynamic key resource scheduling method and device, electronic equipment and storage medium

By dynamically adjusting key routing and channel allocation in the quantum key distribution light network, link blocking problems caused by insufficient quantum keys are solved, and efficient management of key resources and stable transmission of data services are achieved.

CN120378091APending Publication Date: 2025-07-25CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410094783.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-23
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In a quantum key distribution light network, when a link does not have enough quantum keys, the sharing of the global key cannot be completed, resulting in the key link blocking and unable to meet the key needs of the upper-level application.

Method used

By determining the key routing path of the global key in the quantum key distribution light network, and dynamically adjusting the data service routing and quantum channel allocation based on the remaining state of the quantum key in the quantum key pool, the routing of classic data services is adjusted in real time to avoid link blockage caused by key exhaustion.

Benefits of technology

Real-time dynamic adjustment of key resources allocation is achieved, link blocking caused by imbalance in key supply and demand is avoided, key imbalance affects data services, and network stability and reliability are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378091A_ABST
    Figure CN120378091A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic key resource scheduling method and device, electronic equipment and a storage medium, and the method comprises the steps: determining a key routing path of a global key in a quantum key distribution light-emitting network after a data encryption service arrives; sharing the global key to a quantum key distribution node in the quantum key distribution light-emitting network through the key routing path; in response to a data transmission request of the target quantum key distribution node, determining a data service route based on the residual key state of the quantum key in the quantum key pool; wherein the data service route is a path for carrying out encrypted transmission on the data to be transmitted; and adjusting the distribution of quantum channels according to the data service route and the residual key state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of quantum communication. Specifically, it relates to a dynamic key resource scheduling method, apparatus, electronic device, and storage medium. Background Art

[0002] In a quantum key distribution (QKD) optical network, a quantum key pool (QKP) combined with key resources has the characteristics of "gradually accumulating and instantaneously consuming", enabling efficient storage and management of key resources. When sharing a global key, each node uses the local quantum key stored on the corresponding link to encrypt the global key using the one-time pad (OTP). Therefore, when sharing the global key, the quantum key stored on the corresponding link will be consumed additionally. If a certain link does not have enough quantum keys, the sharing of the global key cannot be completed, which will cause the key link to be blocked and unable to meet the key requirements of the upper-layer applications. Summary of the Invention

[0003] Embodiments of the present disclosure at least provide a dynamic key resource scheduling method, apparatus, electronic device, and storage medium.

[0004] In a first aspect, an embodiment of the present disclosure provides a dynamic key resource scheduling method, including:

[0005] In a quantum key distribution optical network, after a data encryption service arrives, determine the key routing path of the global key; share the global key with quantum key distribution nodes in the quantum key distribution optical network through the key routing path; in response to a data transmission request of a target quantum key distribution node, determine a data service routing based on the remaining key status of the quantum keys in the quantum key pool; where the data service routing is a path for encrypting and transmitting the data to be transmitted; adjust the allocation of quantum channels according to the data service routing and the remaining key status.

[0006] In an optional implementation manner, the determining the key routing path of the global key includes:

[0007] Determine at least one candidate routing path in the quantum key distribution optical network; determine the remaining key amounts of the quantum keys in each quantum key pool; determine the routing cost information of each candidate routing path based on the remaining key amounts; determine the key routing path from the at least one candidate routing path according to the routing cost information.

[0008] In an optional implementation manner, the determining the routing cost information of each candidate routing path based on the remaining key amounts includes:

[0009] Based on the remaining key amount, determine the link weights of each link in each of the candidate routing paths; wherein, the link weight is determined based on the ratio between the maximum capacity of the quantum key pool corresponding to the link and the remaining key amount; perform a summation operation on the link weights of each of the links to obtain the routing cost information of the candidate routing path.

[0010] In an optional implementation manner, the determining the key routing path from the at least one candidate routing path according to the routing cost information includes:

[0011] Determine the key routing path based on the candidate routing path corresponding to the minimum routing cost information in the routing cost information.

[0012] In an optional implementation manner, the determining the data service routing based on the remaining key state of the quantum keys in the quantum key pool includes:

[0013] Determine a first quantum key pool in which the remaining key amount of the quantum key is less than a key warning threshold based on the remaining key state; wherein, the key warning threshold is used to indicate that quantum keys need to be replenished to the corresponding quantum key pool; determine the first link corresponding to the first quantum key pool, and determine the data service routing in the links of the quantum key distribution optical network except the first link.

[0014] In an optional implementation manner, adjusting the allocation of quantum channels according to the data service routing and the remaining key state includes:

[0015] Determine a second quantum key pool in which the remaining key amount of the quantum key is less than a sufficient key threshold based on the remaining key state; wherein, the sufficient key threshold is used to indicate the threshold corresponding to the case where the number of keys in the corresponding quantum key pool is sufficient; determine the quantum demand degree of the second quantum key pool; determine the channel noise based on the transmission scheme of the data service routing; determine the target quantum channel added to the second quantum key pool based on the quantum demand degree and the channel noise; wherein, the target quantum channel is used to transmit new quantum keys to the second quantum key pool.

[0016] In an optional implementation manner, the determining the quantum demand degree of the second quantum key pool includes:

[0017] Calculate the target ratio between the remaining key amount of the quantum keys in the second quantum key pool and the sufficient key threshold of the second quantum key pool; wherein, the sufficient key threshold of the second quantum key pool is greater than the key warning threshold of the second quantum key pool and less than the maximum capacity of the second quantum key pool; determine the quantum demand degree based on the target difference between the target value and the target ratio.

[0018] In an alternative embodiment, the determining the target quantum channel to be added to the second quantum key pool based on the quantum demand degree and the channel noise includes:

[0019] Determine the number of quantum key distribution devices on the link corresponding to the second quantum key pool; determine the number of target quantum channels to be added to the second quantum key pool based on the product of the number of the quantum key distribution devices and the quantum demand degree; determine the position of the target quantum channel based on the channel noise.

[0020] In an alternative embodiment, the adjusting the allocation of the quantum channels according to the data service routing and the remaining key state includes:

[0021] Determine a third quantum key pool whose remaining key amount of the quantum keys is greater than the sufficient key threshold and less than the maximum capacity based on the remaining key state; determine the number and position of the target service channels of the third quantum key pool to be added based on the data service routing; wherein, the target service channel is a channel for transmitting the data to be transmitted.

[0022] In an alternative embodiment, the method further includes:

[0023] At preset time intervals, determine the average value of the key consumption rates of a plurality of historical time windows before the current time window for each link; determine the optimal key threshold of the quantum key pool corresponding to the link based on the average value of the key consumption rates; wherein, the optimal key threshold is used to indicate the optimal number of quantum keys in the quantum key pool; determine the key warning threshold, the maximum capacity of the quantum key pool, and the sufficient key threshold of the quantum key pool based on the optimal key threshold; wherein, the maximum capacity, the sufficient key threshold, the optimal key threshold, and the key warning threshold of the quantum key pool decrease in sequence.

[0024] In a second aspect, an embodiment of the present disclosure further provides a dynamic key resource scheduling device, including:

[0025] A first determination unit, configured to determine a key routing path of a global key after a data encryption service arrives in a quantum key distribution optical network; a distribution unit, configured to share the global key with quantum key distribution nodes in the quantum key distribution optical network through the key routing path; a second determination unit, configured to determine a data service routing based on a remaining key state of quantum keys in a quantum key pool in response to a data transmission request of a target quantum key distribution node; wherein the data service routing is a path for encrypting and transmitting the data to be transmitted; an adjustment unit, configured to adjust an allocation of quantum channels according to the data service routing and the remaining key state.

[0026] In a third aspect, an embodiment of the present disclosure further provides an electronic device, including: a processor, a memory, and a bus, where the memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps in the first aspect, or any possible implementation manner in the first aspect, are executed.

[0027] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps in the first aspect, or any possible implementation manner in the first aspect, are executed.

[0028] In an embodiment of the present application, first, in a quantum key distribution optical network, after a data encryption service arrives, a key routing path of a global key is determined; and the global key is shared with quantum key distribution nodes in the quantum key distribution optical network through the key routing path; in response to a data transmission request of a target quantum key distribution node, a data service routing is determined based on a remaining key state of quantum keys in a quantum key pool; wherein the data transmission request carries the data to be transmitted encrypted based on the global key; the data service routing is fed back to the target quantum key distribution node to transmit the data to be transmitted through the data service routing; afterwards, the allocation of quantum channels can be adjusted according to the data service routing and the remaining key state.

[0029] In the above implementation manner, after the data encryption service arrives, by determining the data service routing according to the remaining key state of quantum keys in the quantum key pool, and adjusting the allocation of quantum channels through the data service routing and the remaining key state, it is possible to realize real-time dynamic adjustment of the routing selection of classical data services, thereby avoiding link congestion caused by key exhaustion, thus solving the problem of imbalance between key supply and demand, and reducing the impact of key imbalance on data services.

[0030] To make the above objects, features, and advantages of the present disclosure more apparent and understandable, the following presents preferred embodiments in conjunction with the accompanying drawings and provides a detailed description as follows. Description of the Drawings

[0031] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. These drawings are incorporated into the specification and constitute a part of this specification. These drawings show embodiments that conform to the present disclosure and are used together with the specification to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only show some embodiments of the present disclosure and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.

[0032] Figure 1 Shows the flowchart of a dynamic key resource scheduling method provided by an embodiment of the present disclosure;

[0033] Figure 2 Shows the network architecture diagram of a key pool-based provided by an embodiment of the present disclosure;

[0034] Figure 3 Shows the network topology diagram of a quantum key pool state provided by an embodiment of the present disclosure;

[0035] Figure 4 Shows the schematic diagram of channel allocation under three different remaining key states provided by an embodiment of the present disclosure;

[0036] Figure 5 Shows the schematic flowchart of the feedback mechanism of a key scheduling strategy provided by an embodiment of the present disclosure;

[0037] Figure 6 Shows the flowchart of another dynamic key resource scheduling method provided by an embodiment of the present disclosure;

[0038] Figure 7 Shows the schematic diagram of a dynamic key resource scheduling device provided by an embodiment of the present disclosure;

[0039] Figure 8 Shows the schematic diagram of an electronic device provided by an embodiment of the present disclosure. Detailed Embodiments

[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part rather than all of the embodiments of the present disclosure. Components of the embodiments of the present disclosure generally described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations. Therefore, the detailed description of the embodiments of the present disclosure provided in the drawings is not intended to limit the scope of the claimed present disclosure, but merely represents selected embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative efforts fall within the scope of protection of the present disclosure.

[0041] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not require further definition and explanation in subsequent drawings.

[0042] The term "and / or" in this document merely describes an association relationship and indicates that three relationships may exist. For example, A and / or B may represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "at least one" in this document means any one of multiple or any combination of at least two of multiple. For example, including at least one of A, B, and C may represent selecting any one or more elements from the set composed of A, B, and C.

[0043] Through research, it is found that in a quantum key distribution (QKD) optical network, a quantum key pool (QKP) combined with key resources has the characteristics of "gradually accumulating and instantaneously consuming", enabling efficient storage and management of key resources. When sharing a global key, each node uses the local quantum key stored on the corresponding link to perform one-time pad (OTP) encryption on the global key. Therefore, when sharing the global key, the quantum key stored on the corresponding link will be additionally consumed. If a certain link does not have enough quantum keys, the sharing of the global key cannot be completed, which will cause key link congestion and cannot meet the key requirements of upper-layer applications. Existing key scheduling strategies mainly focus on achieving a more reasonable global key relay route, selecting a link with sufficient quantum keys according to the weight factor to complete key relay, and improving the robustness of the QKD network.

[0044] Existing key scheduling algorithms for quantum key distribution services generally include the following steps: calculating the remaining effective key amounts on each link of the path; defining the costs of QKD links and relay paths according to various influencing factors such as key generation rate, consumption rate, and remaining key amounts; calculating the routing cost according to the method defined in the previous step, and selecting a suitable global key route.

[0045] Existing key scheduling strategies mostly focus on how to more reasonably select the relay route of the global key and avoid the exhaustion of quantum keys by selecting links that store sufficient quantum keys. However, in the prior art, the channel allocation of quantum signals and data signals does not change according to the remaining key state of the current link, and the encryption of services in the QKD encryption network can be achieved through steps such as data encryption, data signal and quantum signal transmission. The existing method only performs reasonable key consumption through the data encryption step. This technology can only passively alleviate the problem of key exhaustion in the link. For the more serious situation of the imbalance between key supply and demand, combining channel resource allocation can better solve this problem.

[0046] Based on the above research, the present disclosure provides a dynamic key resource scheduling method, device, electronic device and storage medium. In the embodiments of the present application, first, after detecting a data encryption service sent by a target quantum key distribution node in a quantum key distribution optical network, determine the key routing path of the global key; and share the global key with the quantum key distribution nodes in the quantum key distribution optical network through the key routing path; in response to the data transmission request of the target quantum key distribution node, determine the data service route based on the remaining key state of the quantum keys in the quantum key pool; and transmit the data to be transmitted through the data service route; thereafter, the allocation of quantum channels can be adjusted according to the data service route and the remaining key state.

[0047] In the above embodiment, after the data encryption service arrives, by determining the data service route according to the remaining key state of the quantum keys in the quantum key pool and adjusting the allocation of quantum channels through the data service route and the remaining key state, it is possible to realize real-time dynamic adjustment of the routing selection of classical data services, thereby avoiding link blockage caused by key exhaustion, and thus solving the problem of imbalance between key supply and demand and reducing the impact of key imbalance on data services.

[0048] To facilitate the understanding of this embodiment, first, a dynamic key resource scheduling method disclosed in the embodiments of the present disclosure will be introduced in detail. The execution subject of the dynamic key resource scheduling method provided in the embodiments of the present disclosure is generally an electronic device with certain computing capabilities. In some possible implementation manners, the dynamic key resource scheduling method can be implemented by a processor calling computer-readable instructions stored in a memory.

[0049] See Figure 1 As shown, it is a flowchart of a dynamic key resource scheduling method provided by an embodiment of the present disclosure. The method includes steps S101 to S104, where:

[0050] S101: In a quantum key distribution optical network, after a data encryption service arrives, determine the key routing path of the global key.

[0051] A quantum key distribution optical network (hereinafter referred to as QKD network) consists of multiple quantum key distribution nodes (hereinafter referred to as QKD nodes), QKD links, and a quantum key pool QKP. The quantum key pool QKP is a repository for the keys generated in the QKD network maintained at each QKD node. Each QKD node has multiple QKD modules, and each QKD module can be used as a transmitter or a receiver. Each QKD link has multiple quantum channels. Among them, for each quantum channel, qubits are transmitted at different wavelengths. Each quantum channel requires a QKD module to be installed on the QKD node to transmit quantum signals.

[0052] In the embodiment of the present application, a key management device can be set for the QKD network in the control layer in advance. The QKD node can initiate a data encryption service to the key management device. After receiving the data encryption service, the key management device can determine the key routing path of the global key.

[0053] Among them, the data encryption service initiated by the QKD node to the key management device can be understood as a global key scheduling request; among them, the global key scheduling request carries the source node identifier for global key distribution, the destination node, and the key demand. The source node identifier can be understood as the QKD node that shares the global key outward, the target node can be understood as the sharing destination of the global key, and the key demand can be understood as the demand for quantum keys during the process of sharing the global key.

[0054] S102: Distribute the global key to the quantum key distribution nodes in the quantum key distribution optical network through the key routing path.

[0055] Here, the key management device can distribute the global key to the quantum key distribution nodes in the quantum key distribution optical network based on the key routing path. During the process of distributing the global key to the quantum key distribution nodes, it is necessary to encrypt the global key with the quantum keys corresponding to each link on the key routing path, so as to realize the distribution of the global key to the destination node.

[0056] S103: In response to the data transmission request of the target quantum key distribution node, determine the data service routing based on the remaining key status of the quantum keys in the quantum key pool; where the data service routing is the path for encrypting and transmitting the data to be transmitted.

[0057] In an embodiment of the present application, after the distribution of the global key is completed, the QKD node may initiate a data transmission request to the network management device in the control layer after completing data service encryption. The data transmission request carries transmission information of the data to be transmitted, specifically including the following information: the source node identifier for data transmission (i.e., the node identifier of the target quantum key distribution node), the destination node (i.e., the destination node of the data to be transmitted), and the data size of the transmitted data.

[0058] After receiving the data transmission request, the control layer may determine a data service route for the target quantum key distribution node based on the information carried in the data transmission request. Then, it may feedback the allocation result of the data service route to the target quantum key distribution node, so that the target quantum key distribution node transmits the data to be transmitted according to the data service route.

[0059] S104: Adjust the allocation of the quantum channel according to the data service route and the remaining key status.

[0060] In the above embodiment, after the data encryption service arrives, by determining the data service route according to the remaining key status of the quantum keys in the quantum key pool and adjusting the allocation of the quantum channel through the data service route and the remaining key status, it is possible to realize real-time dynamic adjustment of the routing selection of classical data services, thereby avoiding link congestion caused by key exhaustion, solving the problem of imbalance between key supply and demand, and reducing the impact of key imbalance on data services.

[0061] In an optional embodiment, the method further includes the following steps:

[0062] Step S11: Determine the average value of the key consumption rates of each link in multiple historical time windows before the current time window at a preset time interval;

[0063] Step S12: Determine the optimal key threshold of the quantum key pool corresponding to the link based on the average value of the key consumption rates; where the optimal key threshold is used to indicate the optimal number of quantum keys in the quantum key pool;

[0064] Step S13: Determine the key warning threshold, the maximum capacity of the quantum key pool, and the sufficient key threshold of the quantum key pool based on the optimal key threshold; where the maximum capacity of the quantum key pool, the sufficient key threshold, the optimal key threshold, and the key warning threshold decrease in sequence.

[0065] In order to reduce the impact of the imbalance between the supply and demand of keys on data services, the technical solution of the present disclosure needs to evaluate the current network status in real time by combining the remaining key information in the QKD network, so as to perform reasonable global key scheduling according to the network status, and at the same time update and allocate the quantum channel and the classical channel in real time, so that the network resources are reasonably allocated. Among them, the quantum channel is used to indicate the channel for distributing new quantum keys to the quantum key pool of the corresponding link, and the classical channel is used to indicate the channel for data transmission.

[0066] Here, the remaining key information needs to be combined with the QKP management technology to improve the perception of the overall QKD network by setting threshold parameters for the QKPs in the QKD network. Among them, the threshold parameters can be understood as the key pool capacity and the threshold, and the setting of the key pool capacity and the threshold is very critical. If the key pool capacity is set too small, it will cause key overflow and waste; and the setting of the key pool threshold can also better detect the situation where the key amount in the network is too low or sufficient, so as to adjust the global key scheduling route and channel allocation in time to avoid problems such as service waiting or failure due to insufficient key amount.

[0067] For example, as Figure 2 shown is the network architecture diagram based on the key pool. From Figure 2 it can be seen that the QKD network includes multiple QKD nodes, and QKP quantum key pools are set between adjacent QKD nodes. A key management device is set in the control layer. Among them, the key management device can manage the remaining key status of each QKP quantum key pool in the QKD network.

[0068] In the embodiment of the present application, as Figure 2 shown, each quantum key pool in the QKD network has set the following threshold parameters: the maximum capacity MAX and three thresholds SUF (sufficient key threshold), EXP (optimal key threshold), WARN (key warning threshold).

[0069] Here, each preset time interval can be set to determine the traffic of each link in the QKD network in multiple historical time windows before the current time window, so as to determine the key consumption rate according to the traffic Among them, represents the key consumption rate (KCR) of the link at time T n . After obtaining the key consumption rate, the optimal key threshold V EXP of the quantum key pool can be determined according to the key consumption rate, and then according to the optimal key threshold V EXP the key warning threshold V WARN , the maximum capacity V MAX of the quantum key pool and the sufficient key threshold V SUF can be determined respectively.

[0070] Among them, V SUF indicates that the current key amount is sufficient, and V EXP represents the optimal value of the key amount set through load awareness, and V WARN indicates that the key amount is too low and the key needs to be replenished in time. The maximum capacity of the key pool and multiple thresholds are set based on a time window. Among them, the preset time interval can be the duration of a single time window. That is to say, at the moment when each time window arrives, based on the key consumption rate of the previous n historical time windows, the maximum capacity and multiple thresholds of the quantum key pool under the current time window can be determined.

[0071] In the embodiment of the present application, the optimal key threshold of the quantum key pool under the current time window can be calculated through the average value of the key consumption amounts of the previous n historical time windows:

[0072]

[0073] Among them, represents the moment corresponding to the historical time window T N-1 n represents the number of historical time windows, and the key consumption rate (KCR) of the link. The threshold in the QKP can be calculated through the following formula: V WARN = 0.4V EXP 、V SUF = 1.6V EXP 、V MAX = 1.6V EXP .

[0074] In the above implementation manner, by determining the average value of the key consumption rates of multiple historical time windows before the current time window for each link, and determining the maximum capacity and multiple thresholds according to this average value, it is possible to determine different maximum capacities and multiple thresholds for different quantum key pools to meet the requirements of each link for quantum keys, thereby further ensuring key balance and further reducing the impact of key imbalance on data services.

[0075] In an alternative implementation manner, the above step S101 of determining the key routing path of the global key specifically includes the following steps:

[0076] Step S21: Determine at least one candidate routing path in the quantum key distribution optical network;

[0077] Step S22: Determine the remaining key amount of the quantum key in each quantum key pool;

[0078] Step S23: Determine the routing cost information of each candidate routing path based on the remaining key amount;

[0079] Step S24: Determine the key routing path among the at least one candidate routing path according to the routing cost information.

[0080] In the embodiment of the present application, during the selection process of global key routing, first, k shortest paths are calculated according to the k - shortest path algorithm, and the k shortest paths are determined as at least one candidate routing path.

[0081] After determining at least one candidate routing path, the remaining key amount of the quantum keys in each quantum key pool can be determined, denoted as V; then, based on the remaining key amount, the routing cost information K of each candidate routing path is calculated in sequence. Finally, the key routing path is determined among the at least one candidate routing path according to the routing cost information K. Among them, the key routing path can be determined based on the candidate routing path corresponding to the minimum routing cost information in the routing cost information.

[0082] Here, the routing cost information K of at least one candidate routing path can be sorted. For example, it can be sorted in ascending order or in descending order. After obtaining the sorting result, the candidate routing path corresponding to the minimum routing cost information in the sorting result can be determined as the key routing path. For example, after sorting in descending order, the candidate routing path corresponding to the routing cost information at the end of the sorting result can be determined as the key routing path.

[0083] In an alternative embodiment, the above - mentioned step S23 determines the routing cost information of each candidate routing path based on the remaining key amount, and specifically includes the following steps:

[0084] Step S231: Based on the remaining key amount, determine the link weight of each link in each candidate routing path; wherein, the link weight is determined based on the ratio between the maximum capacity and the remaining key amount of the quantum key pool corresponding to the link;

[0085] Step S232: Perform a summation operation on the link weights of each link to obtain the routing cost information of the candidate routing path.

[0086] As can be seen from the above description, the technical solution of the present disclosure is based on a QKD network composed of trusted QKD nodes, and realizes global key sharing between non - adjacent QKD nodes through relay. Reasonably selecting the key routing path among candidate routing paths can avoid the exhaustion of quantum keys. Based on this, the exhaustion of quantum keys can be avoided by selecting links that store sufficient quantum keys.

[0087] By adopting this processing method, the consumption of keys by links with insufficient remaining quantum keys can be reduced, and the consumption of keys by links with sufficient remaining quantum keys can also be increased, so as to realize the reasonable scheduling of keys and ensure the preliminary solution to the problem of imbalance between key supply and demand.

[0088] Based on this, in the embodiment of the present application, the ratio between the maximum capacity of the quantum key pool and the remaining key amount of the quantum key pool can be calculated, and then this ratio is used as the link weight of the link corresponding to the quantum key pool; afterwards, the link weights of each link on the candidate routing path can be summed up to obtain the routing cost information of the candidate routing path.

[0089] Specifically, the technical solution of the present disclosure takes into account the number of remaining quantum keys of the link and the number of path hops, and defines the routing cost information K:

[0090] Among them, n represents the total number of links in the path, represents the synthesis of the link weights of each link of the candidate routing path, represents the remaining link weight per average link, and considering the influence of the number of hops, it is multiplied by n times to obtain the routing cost information of the candidate routing path.

[0091] In an optional implementation manner, step S103 determines the data service routing based on the remaining key state of the quantum keys in the quantum key pool, specifically including the following steps:

[0092] Step S31: Determine a first quantum key pool in which the remaining key amount of the quantum key is less than the key warning threshold based on the remaining key state; wherein, the key warning threshold is used to indicate that quantum keys need to be replenished to the corresponding quantum key pool;

[0093] Step S32: Determine the first link corresponding to the first quantum key pool, and determine the data service routing among the links other than the first link in the quantum key distribution optical network.

[0094] Here, if it is determined based on the remaining key state that the remaining key amount V of the quantum key belongs to [0, WARN], it means that the remaining key rate in the current quantum key pool is not sufficient. This situation indicates that in the previous moment, the key consumption rate was mostly greater than the key generation rate.

[0095] Therefore, when it is determined that the remaining key amount V belongs to [0, WARN], this link in the key state topology graph is automatically set to be disconnected, that is, the classical data service will not select this link as the transmission path; wherein, the key state topology graph is the network topology graph reflecting the state of the quantum key pool at the current moment.

[0096] For example, as Figure 3As shown, it can be seen that the remaining key amount V of the quantum keys in the quantum key pools corresponding to the two links between node 3 and node 4 and between node 4 and node 5 in the figure (i.e., the first link) belongs to [0, WARN]. At this time, when updating the topology graph, these two links are disconnected. When the classical service selects a route, it can temporarily avoid these two links, thereby reducing the noise interference generated by the classical data signal. There is also sufficient time to continue generating keys, and the situation where the key amount in the link becomes 0 will not occur. Furthermore, the blocking and waiting problems in data service transmission are avoided.

[0097] In an alternative embodiment, adjusting the allocation of the quantum channels according to the data service route and the remaining key state includes the following steps:

[0098] Step S41: Determine a second quantum key pool in which the remaining key amount of the quantum keys is less than the sufficient key threshold based on the remaining key state; wherein, the sufficient key threshold is used to indicate the threshold corresponding to the case where the key quantity in the corresponding quantum key pool is sufficient;

[0099] Step S42: Determine the quantum demand degree of the second quantum key pool;

[0100] Step S43: Determine the channel noise based on the transmission scheme of the data service route;

[0101] Step S44: Determine the target quantum channel added to the second quantum key pool based on the quantum demand degree and the channel noise; wherein, the target quantum channel is used to transmit new quantum keys to the second quantum key pool.

[0102] In the embodiment of the present application, after determining the data service route, the number and position of the quantum channels allocated to each link can also be adjusted based on the remaining key amount of the quantum keys. For example, when it is determined based on the remaining key amount that the quantum key quantity is not sufficient to support classical data transmission, a new quantum channel can be added to the corresponding link, thereby increasing the number of quantum keys in the quantum key pool corresponding to the link.

[0103] Based on this, the interaction between the quantum channel and the classical channel can be improved. By adopting this processing method, a matching state can be achieved between the generation and consumption of quantum keys, and thus supply-demand balance can be realized.

[0104] Therefore, in the embodiments of the present application, not only can the routing selection scheme of classical signals be updated according to the remaining quantity of quantum keys in the QKD network, but also the allocation of quantum channels can be updated according to the remaining quantity of quantum keys. The main idea of the quantum channel allocation scheme proposed by the technical solution of the present application is to control the transmission of quantum signals to make the remaining quantity of quantum keys in the quantum key pool reach a balanced state, thereby maintaining the stability of the encrypted services in the QKD network.

[0105] In the embodiments of the present application, first, determine the quantum key pool that needs to allocate new quantum channels, denoted as the second quantum key pool. For example, the second quantum key pool with the remaining key quantity of quantum keys less than the sufficient key threshold SUF can be determined based on the remaining key state; then, determine the quantum demand degree of the second quantum key pool, and determine the channel noise based on the transmission scheme of the data service routing, and then determine the number and location of the target quantum channels to be added to the second quantum key pool according to the quantum demand degree and the channel noise.

[0106] In an alternative embodiment, determining the quantum demand degree of the second quantum key pool specifically includes the following steps:

[0107] First, calculate the target ratio between the remaining key quantity of quantum keys in the second quantum key pool and the sufficient key threshold of the first quantum key pool; wherein, the sufficient key threshold of the second quantum key pool is greater than the key warning threshold of the second quantum key pool and less than the maximum capacity of the second quantum key pool;

[0108] Secondly, determine the quantum demand degree based on the target difference between the target value and the target ratio.

[0109] Due to the cost of QKD devices and the limitations of actual deployment, the number of QKD receivers and QKD transmitters deployed in each link or each pair of communicating QKD nodes is limited. The current demand degree of quantum keys can be known according to the remaining key quantity of quantum keys in the quantum key pool. In specific implementation, the target ratio between the remaining key quantity of quantum keys in the second quantum key pool and the sufficient key threshold of the first quantum key pool can be calculated. Furthermore, calculate the target difference between the target value and the target ratio. Assume that the target value can be 1. At this time, the target difference between 1 and can be calculated. Furthermore, determine this target difference as the quantum demand degree of the second quantum key pool.

[0110] Among them, the key demand degree R can be expressed by the following formula:

[0111]

[0112] Among them, V represents the remaining number of keys in the key pool at the current moment, that is, the remaining key amount. It can be easily seen from the formula that R represents the difference degree between the remaining key amount V and V SUF at the current moment.

[0113] It can be seen from the above formula that when the remaining key amount V ∈ [0, SUF], the quantum demand degree of the corresponding quantum key pool is When the remaining key amount V ∈ [SUF, MAX] V ∈ [0, SUF], the quantum demand degree of the corresponding quantum key pool is 0.

[0114] After determining the quantum demand degree, the number of target quantum channels can be increased for the second quantum key pool according to this quantum demand degree. Through this processing method, the number and position of the quantum channels can be controlled, so as to control the key generation rate and ensure the balance of keys.

[0115] Such as Figure 4 shown is the channel allocation situation under three different remaining key states. Such as Figure 4 shown, the three different remaining key states are respectively the remaining key number V ∈ [0, WARN], the remaining key number V ∈ [0, SUF], and the remaining key number V ∈ [0, MAX]. Such as Figure 4 shown, when the remaining key number V ∈ [0, SUF], it means that the quantum key pool has not reached the sufficient level. Therefore, the link needs to continue generating keys. At this time, the number of target quantum channels needs to be increased for this quantum key pool. When the remaining key number V ∈ [0, WARN], it means that the quantum key pool has not reached the sufficient level. Therefore, the link needs to continue generating keys. At this time, the number of target quantum channels needs to be increased for this quantum key pool, and this link is cut off. When the remaining key number V ∈ [0, MAX], it means that the quantum key pool has reached the sufficient level. Therefore, the link does not need to continue generating keys.

[0116] In an optional implementation manner, the above steps of determining the target quantum channels added for the second quantum key pool based on the quantum demand degree and the channel noise specifically include the following steps:

[0117] First, determine the number of quantum key distribution devices on the link corresponding to the second quantum key pool;

[0118] Then, based on the product of the number of quantum key distribution devices and the quantum demand degree, determine the number of target quantum channels added for the second quantum key pool;

[0119] Finally, determine the position of the target quantum channel based on the channel noise.

[0120] In the embodiments of the present application, assuming that the number of QKD devices on each link is N, when V ∈ [0, SUF], the number of target quantum channels can be expressed by the following formula:

[0121] Channel Q = R·N.

[0122] Therefore, in the embodiments of the present application, the product of the number N of key distribution devices and the quantum demand degree R can be calculated, so as to determine the number of target quantum channels added to the second quantum key pool according to this product.

[0123] After determining the number of target quantum channels, the position of the target quantum channels can also be determined based on channel noise. For example, the target quantum channels can be selected from channels that are not easily interfered by classical channels.

[0124] In an alternative embodiment, after determining the data service route based on the remaining key state of the quantum keys in the quantum key pool, the method further includes the following steps:

[0125] First, determine a third quantum key pool based on the remaining key state, where the remaining key amount of the quantum keys is greater than the sufficient key threshold and less than the maximum capacity;

[0126] Second, determine the number of target service channels added to the third quantum key pool based on the data service route; where the target service channel is a channel used to transmit the data to be transmitted.

[0127] In the embodiments of the present application, if it is determined based on the remaining key state that the remaining key amount of the quantum keys is greater than the sufficient key threshold SUF and less than the maximum capacity MAX. At this time, it can be determined that this quantum key pool is the third quantum key pool, and the number of quantum keys in the third quantum key pool is sufficient. At this time, in order to increase the consumption of the quantum keys in the third quantum key pool, the number of target service channels of the third quantum key pool can be increased. By increasing the number of target service channels, the consumption of quantum keys can be increased to ensure that the keys are in a balanced state.

[0128] The feedback mechanism of the key scheduling strategy will be introduced below with reference to the figure.

[0129] As Figure 5As shown, the remaining key status of the quantum key pool can be monitored. When it is monitored based on the remaining key status that there is insufficient remaining key in a link in the QKD network, the consumption of the key in this link will be reduced successively through the quantum key scheduling strategy, the transmission of data signals in this link will be reduced to reduce noise interference through the data service routing and allocation scheme, and the number of quantum channels will be increased through the quantum channel allocation scheme, thereby increasing the remaining key in the link and avoiding insufficient final key. However, when it is monitored based on the remaining key status that there is too much remaining key in a link in the QKD network, the consumption of the key in this link will be increased successively through the quantum key scheduling strategy, the transmission channels of data signals in this link will be increased through the data service routing and allocation scheme, and the number of quantum channels will be reduced through the quantum channel allocation scheme, finally keeping the key in a sufficient but non-overflowing state.

[0130] The following combines Figure 6 to introduce the above dynamic key resource scheduling method. As Figure 6 shown, this method includes the following steps:

[0131] S601: The QKD node sends a key scheduling request to the key management device; among them, the global key scheduling request carries the source node identifier for global key distribution, the destination node, and the key demand. The source node identifier can be understood as the QKD node that shares the global key outward, the target node can be understood as the sharing destination of the global key, and the key demand can be understood as the demand for quantum keys during the process of sharing the global key.

[0132] S602: The key management device determines the key routing path of the global key by calculating the routing cost information; among them, the way for the key management device to calculate the routing cost information is as described in the above embodiment, and will not be described in detail here.

[0133] S603: Realize the sharing of the global key.

[0134] S604: The key management device sends a key scheduling response to the QKD node.

[0135] S605: The QKD node completes the encryption of the data to be transmitted.

[0136] S606: The QKD node sends a data transmission request to the network management device; among them, the data transmission request carries the transmission information of the data to be transmitted, specifically including the following information: the source node identifier for data transmission (i.e., the node identifier of the target quantum key distribution node), the destination node (i.e., the destination node of the data to be transmitted), and the data size of the transmitted data.

[0137] S607: The network management device sends a resource allocation request to the key management device.

[0138] S608: The key management device sends a resource allocation response to the network management device; wherein, the resource allocation response is used to indicate the remaining key status of the quantum key in the QKD network.

[0139] S609: The network management device determines the data service route according to the remaining key status and calculates the number of target quantum channels.

[0140] S610: The network management device performs resource allocation between the classical channel and the quantum channel.

[0141] S611: The network management device feeds back the channel allocation result to the QKD node.

[0142] Those skilled in the art can understand that in the above method of the specific embodiment, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.

[0143] Based on the same inventive concept, an embodiment of the present disclosure also provides a dynamic key resource scheduling device corresponding to the dynamic key resource scheduling method. Since the principle of solving problems by the device in the embodiment of the present disclosure is similar to the above dynamic key resource scheduling method in the embodiment of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0144] Refer to Figure 7 As shown in the figure, it is a schematic diagram of a dynamic key resource scheduling device provided by an embodiment of the present disclosure. The device includes: a first determination unit 10, a distribution unit 20, a second determination unit 30, and a transmission unit 40; wherein,

[0145] The first determination unit is configured to determine the key routing path of the global key after the data encryption service arrives in the quantum key distribution optical network.

[0146] The distribution unit is configured to share the global key with the quantum key distribution nodes in the quantum key distribution optical network through the key routing path.

[0147] The second determination unit is configured to determine the data service route based on the remaining key status of the quantum key in the quantum key pool in response to the data transmission request of the target quantum key distribution node; wherein, the data service route is the path for encrypting and transmitting the data to be transmitted.

[0148] The adjustment unit is configured to adjust the allocation of the quantum channel according to the data service route and the remaining key status.

[0149] In the above embodiments, after the data encryption service arrives, by determining the data service route according to the remaining key status of the quantum keys in the quantum key pool, and adjusting the allocation of the quantum channels through the data service route and the remaining key status, it is possible to dynamically adjust the route selection of the classical data service in real time, thereby avoiding link blockage caused by key exhaustion, solving the problem of imbalance between key supply and demand, and reducing the impact of key imbalance on the data service.

[0150] In a possible embodiment, the first determining unit is further configured to: determine at least one candidate routing path in the quantum key distribution optical network; determine the remaining key amount of the quantum keys in each of the quantum key pools; determine the routing cost information of each of the candidate routing paths based on the remaining key amount; and determine the key routing path from the at least one candidate routing path according to the routing cost information.

[0151] In a possible embodiment, the first determining unit is further configured to: determine the link weight of each link in each of the candidate routing paths based on the remaining key amount; wherein the link weight is determined based on the ratio between the maximum capacity of the quantum key pool corresponding to the link and the remaining key amount; and perform a summation operation on the link weights of each of the links to obtain the routing cost information of the candidate routing path.

[0152] In a possible embodiment, the first determining unit is further configured to: determine the key routing path based on the candidate routing path corresponding to the minimum routing cost information in the routing cost information.

[0153] In a possible embodiment, the second determining unit is further configured to: determine a first quantum key pool in which the remaining key amount of the quantum keys is less than a key warning threshold based on the remaining key status; wherein the key warning threshold is used to indicate that quantum keys need to be replenished to the corresponding quantum key pool; determine the first link corresponding to the first quantum key pool, and determine the data service route in the links of the quantum key distribution optical network other than the first link.

[0154] In a possible embodiment, the adjusting unit is further configured to: determine a second quantum key pool in which the remaining key amount of the quantum keys is less than a sufficient key threshold based on the remaining key status; wherein the sufficient key threshold is used to indicate the threshold corresponding to the case where the number of keys in the corresponding quantum key pool is sufficient; determine the quantum demand degree of the second quantum key pool; determine the channel noise based on the transmission scheme of the data service route; and determine the target quantum channel to be added to the second quantum key pool based on the quantum demand degree and the channel noise; wherein the target quantum channel is used to transmit new quantum keys to the second quantum key pool.

[0155] In a possible implementation, the adjustment unit is further configured to: calculate a target ratio between the remaining key amount of the quantum keys in the second quantum key pool and the sufficient key threshold of the second quantum key pool; wherein, the sufficient key threshold of the second quantum key pool is greater than the key warning threshold of the second quantum key pool and less than the maximum capacity of the second quantum key pool; determine the quantum demand degree based on a target difference between a target value and the target ratio.

[0156] In a possible implementation, the adjustment unit is further configured to: determine the number of quantum key distribution devices on the link corresponding to the second quantum key pool; determine the number of target quantum channels to be added to the second quantum key pool based on a product of the number of the quantum key distribution devices and the quantum demand degree; determine the positions of the target quantum channels based on the channel noise.

[0157] In a possible implementation, the adjustment unit is further configured to: based on the remaining key state, determine a third quantum key pool in which the remaining key amount of the quantum keys is greater than the sufficient key threshold and less than the maximum capacity; determine the number and positions of the target service channels of the third quantum key pool to be added based on the data service routing; wherein, the target service channel is a channel for transmitting the data to be transmitted.

[0158] In a possible implementation, the apparatus is further configured to: at preset time intervals, determine an average value of the key consumption rates of each link in a plurality of historical time windows before the current time window; determine an optimal key threshold of the quantum key pool corresponding to the link based on the average value of the key consumption rates; wherein, the optimal key threshold is used to indicate the optimal number of quantum keys in the quantum key pool; determine the key warning threshold, the maximum capacity of the quantum key pool, and the sufficient key threshold of the quantum key pool based on the optimal key threshold; wherein, the maximum capacity, the sufficient key threshold, the optimal key threshold, and the key warning threshold of the quantum key pool decrease in sequence.

[0159] Descriptions of the processing procedures of the various modules in the apparatus and the interaction procedures between the various modules may refer to the relevant descriptions in the above method embodiments and will not be elaborated here.

[0160] Corresponding to Figure 1 the dynamic key resource scheduling method in, the embodiments of the present disclosure further provide an electronic device 800, as Figure 8 shown, which is a schematic structural diagram of the electronic device 800 provided by the embodiments of the present disclosure, and includes:

[0161] A processor 81, a memory 82, and a bus 83; the memory 82 is used to store execution instructions, including an internal memory 821 and an external memory 822; here, the internal memory 821 is also called the main memory, which is used to temporarily store the operation data in the processor 81 and the data exchanged with the external memory 822 such as a hard disk. The processor 81 exchanges data with the external memory 822 through the internal memory 821. When the electronic device 800 runs, the processor 81 communicates with the memory 82 through the bus 83, so that the processor 81 executes the following instructions:

[0162] In a quantum key distribution optical network, after a data encryption service arrives, determine the key routing path of the global key;

[0163] Share the global key to the quantum key distribution nodes in the quantum key distribution optical network through the key routing path;

[0164] In response to a data transmission request of a target quantum key distribution node, determine a data service route based on the remaining key status of the quantum keys in the quantum key pool; wherein, the data service route is a path for encrypting and transmitting the data to be transmitted;

[0165] Adjust the allocation of quantum channels according to the data service route and the remaining key status.

[0166] The embodiments of the present disclosure further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the dynamic key resource scheduling method described in the above method embodiments. Wherein, the storage medium may be a volatile or non-volatile computer-readable storage medium.

[0167] The embodiments of the present disclosure further provide a computer program product, which carries program codes. The instructions included in the program codes can be used to execute the steps of the dynamic key resource scheduling method described in the above method embodiments. For details, please refer to the above method embodiments and will not be elaborated here.

[0168] Wherein, the above computer program product can be specifically implemented in a manner of hardware, software, or a combination thereof. In an optional embodiment, the computer program product is specifically embodied as a computer storage medium. In another optional embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.

[0169] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein. In the several embodiments provided in the present disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other can be through some communication interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0170] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0171] In addition, in each embodiment of the present disclosure, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0172] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present disclosure. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0173] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than limiting them. The protection scope of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that any person skilled in the art within the technical scope disclosed by the present disclosure can still modify the technical solutions described in the foregoing embodiments or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A dynamic key resource scheduling method, characterized in that Including: In a quantum key distribution optical network, after a data encryption service arrives, determining a key routing path for a global key; Sharing the global key with quantum key distribution nodes in the quantum key distribution optical network through the key routing path; In response to a data transmission request from a target quantum key distribution node, determining a data service routing based on the remaining key state of quantum keys in a quantum key pool; wherein, the data service routing is a path for encrypting and transmitting data to be transmitted; Adjusting the allocation of quantum channels according to the data service routing and the remaining key state.

2. The method according to claim 1, wherein The determining of the key routing path for the global key includes: Determining at least one candidate routing path in the quantum key distribution optical network; Determining the remaining key amount of quantum keys in each quantum key pool; Determining routing cost information for each candidate routing path based on the remaining key amount; Determining the key routing path from the at least one candidate routing path according to the routing cost information.

3. The method according to claim 2, characterized in that, The determining of the routing cost information for each candidate routing path based on the remaining key amount includes: Based on the remaining key amount, determining the link weight of each link in each candidate routing path; wherein, the link weight is determined based on the ratio between the maximum capacity of the quantum key pool corresponding to the link and the remaining key amount; Performing a summation operation on the link weights of each link to obtain the routing cost information of the candidate routing path.

4. The method according to claim 2, wherein The determining of the key routing path from the at least one candidate routing path according to the routing cost information includes: Determining the key routing path based on the candidate routing path corresponding to the minimum routing cost information in the routing cost information.

5. The method according to claim 1, characterized in that The determining of the data service routing based on the remaining key state of quantum keys in a quantum key pool includes: Determining a first quantum key pool in which the remaining key amount of quantum keys is less than a key warning threshold based on the remaining key state; wherein, the key warning threshold is used to indicate that quantum keys need to be replenished to the corresponding quantum key pool; Determining a first link corresponding to the first quantum key pool, and determining the data service routing in the links of the quantum key distribution optical network other than the first link.

6. The method according to claim 1, wherein The adjusting of the allocation of quantum channels according to the data service routing and the remaining key state includes: Determining a second quantum key pool in which the remaining key amount of quantum keys is less than a sufficient key threshold based on the remaining key state; wherein, the sufficient key threshold is used to indicate the threshold corresponding to the case where the number of keys in the corresponding quantum key pool is sufficient; Determining the quantum demand degree of the second quantum key pool; Determining channel noise based on the transmission scheme of the data service routing; Determining a target quantum channel to be added to the second quantum key pool based on the quantum demand degree and the channel noise; wherein, the target quantum channel is used to transmit new quantum keys to the second quantum key pool.

7. The method according to claim 6, characterized in that The determining of the quantum demand degree of the second quantum key pool includes: Calculate the target ratio between the remaining key amount of the quantum keys in the second quantum key pool and the sufficient key threshold of the second quantum key pool; wherein, the sufficient key threshold of the second quantum key pool is greater than the key warning threshold of the second quantum key pool and less than the maximum capacity of the second quantum key pool; Determine the quantum demand degree based on the target difference between the target value and the target ratio.

8. The method according to claim 6, characterized in that, The determining the target quantum channel to be added to the second quantum key pool based on the quantum demand degree and the channel noise includes: Determine the number of quantum key distribution devices on the link corresponding to the second quantum key pool; Determine the number of target quantum channels to be added to the second quantum key pool based on the product of the number of the quantum key distribution devices and the quantum demand degree; Determine the location of the target quantum channel based on the channel noise.

9. The method according to claim 6, characterized in that, The adjusting the allocation of the quantum channels according to the data service route and the remaining key state includes: Based on the remaining key state, determine a third quantum key pool in which the remaining key amount of the quantum keys is greater than the sufficient key threshold and less than the maximum capacity; Based on the data service route, determine the number and location of the target service channels of the added third quantum key pool; wherein, the target service channel is a channel for transmitting the data to be transmitted.

10. The method according to claim 1, wherein The method further includes: At preset time intervals, determine the average value of the key consumption rates of each link in multiple historical time windows before the current time window; Determine the optimal key threshold of the quantum key pool corresponding to the link based on the average value of the key consumption rates; wherein, the optimal key threshold is used to indicate the optimal number of quantum keys in the quantum key pool; Based on the optimal key threshold, determine the key warning threshold, the maximum capacity of the quantum key pool, and the sufficient key threshold of the quantum key pool; wherein, the maximum capacity, the sufficient key threshold, the optimal key threshold, and the key warning threshold of the quantum key pool decrease in sequence.

11. A dynamic key resource scheduling device, characterized in that, Includes: A first determination unit, configured to determine the key routing path of the global key after the data encryption service arrives in the quantum key distribution optical network; A distribution unit, configured to share the global key with the quantum key distribution nodes in the quantum key distribution optical network through the key routing path; A second determination unit, configured to, in response to a data transmission request of a target quantum key distribution node, determine a data service route based on the remaining key state of the quantum keys in the quantum key pool; wherein, the data service route is a path for encrypting and transmitting the data to be transmitted; An adjustment unit, configured to adjust the allocation of the quantum channels according to the data service route and the remaining key state.

12. An electronic device, characterized in that, Includes: A processor, a memory, and a bus, where the memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the dynamic key resource scheduling method according to any one of claims 1 to 10 are executed.

13. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by a processor, it executes the steps of the dynamic key resource scheduling method according to any one of claims 1 to 10.