Communication method, communication device and communication network

By dynamically generating routing information based on the key processing capabilities of quantum node devices, the problems of congestion and interruption caused by unfixed service key distribution cycles, poor noise resistance and network failure in quantum communication are solved, and efficient and secure service key transmission is achieved.

CN120389850APending Publication Date: 2025-07-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410128242.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-26
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In existing quantum communication, there are problems such as unfixed service key distribution cycle, poor noise resistance, and congestion and distribution interruption caused by network failures. In particular, when high-frequency distribution is distributed, the real-time processing and secure transmission of service keys cannot be guaranteed.

Method used

By determining the routing information of service key distribution based on the key processing capabilities of quantum node devices, generating the key distribution path and protection path, dynamically adjusting the key distribution path to avoid congestion and interruption, and using the key processing capabilities of quantum node devices to generate temporary keys for encryption, ensuring the secure transmission of service keys.

Benefits of technology

It improves the distribution efficiency and transmission quality of service keys, avoids congestion and interruption, and ensures the timely processing and security of service keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389850A_ABST
    Figure CN120389850A_ABST
Patent Text Reader

Abstract

The invention provides a communication method, a communication device and a communication network, and relates to the field of communication. According to the communication method, the routing information distributed by the service secret key can be determined based on the secret key processing capability of the quantum node equipment, so that the transmission quality of the service secret key is ensured. The communication method is applied to a control device in a communication network, the communication network comprises the control device and at least two pieces of quantum node equipment, and the at least two pieces of quantum node equipment comprise quantum source node equipment and quantum sink node equipment. The communication method comprises the following steps: receiving a service request message, wherein the service request message comprises equipment information of quantum source node equipment and equipment information of quantum sink node equipment; generating routing information based on the service request message and the key processing capability of the quantum node device; wherein the routing information comprises a key distribution path between the quantum source node device and the quantum sink node device; and configuring the routing information to the quantum source node equipment. The embodiment of the invention is applied to the field of communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and particularly to a communication method, a communication device, and a communication network. Background Art

[0002] With the development of communication technologies and the increasing emphasis on information security by people, quantum communication has increasingly appeared in the public eye, and quantum communication technology has become a strategic frontier technology for enhancing cybersecurity in cyberspace. Quantum communication is a new type of communication method that uses quantum superposition states and entanglement effects to achieve information transmission, and has higher security and efficiency.

[0003] Among them, quantum key distribution (QKD), as the most important application of quantum communication technology, is crucial for current and future global communication systems. Generally, quantum key distribution is to generate and distribute service quantum keys (also known as service keys) to achieve the purpose of quantum encryption of services. Among them, in order to prevent interception during the process of generating and distributing service keys, a temporary quantum key (also known as a temporary key) needs to be generated during distribution, and the generated temporary key can perform an exclusive OR operation with the service key. In this way, even if the XORed service key (also known as the encryption key) is intercepted during transmission, the original (before XOR) service key cannot be obtained from it, thus ensuring the security of the service key. Due to the distance limitation in the generation of temporary keys, multiple trusted relay nodes need to be selectively deployed during the transmission of service keys, so that the service keys can reach the destination node safely through multiple trusted relay nodes during the distribution process.

[0004] However, there are still many challenges in the current application of quantum communication. For example, the period of quantum key distribution is usually not fixed. According to the priority of customer services, the distribution period may be weekly (distributed at a weekly time interval), daily (distributed at a daily time interval), hourly, minute - level, or even second - level. However, the ability of trusted relay nodes to generate temporary keys (such as the number of generated keys) is limited. In this way, when the distribution period becomes short, the service keys cannot be processed in real - time, resulting in congestion. Another example is that the anti - noise ability of quantum communication is poor. Specifically, when the quality of optical fiber transmission deteriorates, it will affect the number of generated temporary keys (for example, it decreases from 400 per second to 100 per second), resulting in congestion in the processing of service keys. In addition, during the distribution process of service keys, network failures (link failures, device failures, etc.) will also cause the service keys to be unable to be distributed normally. Summary of the Invention

[0005] The present application provides a communication method, a communication device, and a communication network, which can determine the routing information for service key distribution based on the key processing capabilities of quantum node devices, thereby improving the distribution efficiency of service keys and ensuring the transmission quality of service keys.

[0006] In a first aspect, a communication method is provided. The communication method is applied to a control device in a communication network. The communication network includes a control device and at least two quantum node devices. The at least two quantum node devices include a quantum source node device and a quantum sink node device. The communication method includes: receiving a service request message, where the service request message includes device information of the quantum source node device and device information of the quantum sink node device; generating routing information based on the service request message and the key processing capabilities of the quantum node devices; where the routing information includes a key distribution path between the quantum source node device and the quantum sink node device; and configuring the routing information to the quantum source node device.

[0007] Then, through the above solution, it is possible to generate routing information based on the service request message containing the device information of the quantum source node device and the device information of the quantum destination node device, as well as the key processing capabilities of the quantum node devices in the communication network, and configure the generated routing information to the quantum source node device included in the service request message. Among them, the routing information includes the key distribution path between the quantum source node device and the quantum destination node device. For example, based on the device information of the quantum source node device and the device information of the quantum destination node device carried in the service request message, the above solution can determine the starting device (i.e., the quantum source node device) and the terminating device (i.e., the quantum destination node device) for service key distribution. At the same time, based on the key processing capabilities of the quantum node devices, it is possible to determine the key distribution path for distributing the service key between the quantum source node device and the quantum destination node device. Usually, through the starting device and the terminating device for service key distribution, multiple key distribution paths for service key distribution can be determined in the communication network. In addition, the key processing capabilities of the intermediate quantum node devices located between the starting device and the terminating device for service key distribution are usually limited. For example, when the distribution period of the service key becomes shorter, the distribution frequency of the service key will become higher (even exceeding the key processing capabilities of the quantum node devices). Limited by its own key processing capabilities, the intermediate quantum node device cannot process the received service key in real time, resulting in congestion. However, the above solution can generate routing information including the key distribution path based on the key processing capabilities of the quantum node devices, enabling the quantum node devices to process the received service key in real time, avoiding congestion, and ensuring the distribution quality of the service key. Then, through the above solution, it is possible to determine the key distribution path based on the device information of the source node device for key distribution, the device information of the quantum destination node device, and the key processing capabilities of the quantum node devices, and allocate it to the quantum source node device, thereby ensuring the transmission quality of the service key.

[0008] In a possible implementation manner, the quantum node device includes at least one port; the key processing capability includes the port identifier of the port and the key processing speed of the port.

[0009] Then, in the above solution, through the key processing capability, the port identifier of the quantum node device and the key processing speed of the port can be determined, that is, the number of service keys processed by the port of the quantum node device per unit time. Among them, the quantum node device processes the service key with a temporary key, so the number of keys processed per unit time can also be understood as the number of temporary keys generated per unit time. Usually, when distributing the service key, it is necessary to encrypt the service key with the temporary key generated by the quantum node device to ensure the security of the service key. Then, through the above solution, based on the key processing capability of the received quantum node device, the number of temporary keys generated by the quantum node device per unit time can be determined. Further, based on the key processing capability, the key distribution path can be determined, thereby ensuring the distribution efficiency of the service key.

[0010] In a possible implementation manner, the service request message further includes a key distribution frequency; the above communication method further includes: determining the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path based on the key distribution frequency and the key processing capability of the quantum node device; and sending the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path to the quantum source node device.

[0011] Then, in the above solution, based on the service request message including the key distribution frequency and the key processing capabilities of the quantum node devices, the priority of the service keys transmitted through the key distribution paths processed by the ports of the quantum node devices can be determined and sent to the quantum source node device. Specifically, when the service keys are distributed, the quantum node devices passed through usually need to generate multiple temporary keys. Further, the quantum node devices can encrypt the service keys by processing the service keys with the generated temporary keys to ensure the security of the service key distribution. Generally speaking, the number of temporary keys generated by the quantum node devices per unit time is limited. Therefore, the number of service keys that the quantum node devices can process per unit time is limited, which can also be understood as the limited key processing capabilities of the quantum node devices. In this way, when the quantum node devices simultaneously process the service keys of multiple services, some services have a higher distribution frequency (at this time, the distribution frequency of the service keys is higher (reaching the second level)), and some services have a lower distribution frequency (at this time, the distribution frequency of the service keys is lower (reaching the minute level or the hour level)). If the distribution frequencies of the services are not distinguished and the quantum node devices generate temporary keys for the service keys of different services with the same mechanism, then limited by the key processing capabilities of the quantum node devices, congestion may occur when the service keys of the services with a higher distribution frequency (such as the service keys with a higher distribution frequency (reaching the second level)) are distributed, resulting in the service keys not being processed in time. Through the above solution, the priority of the service keys transmitted through the key distribution paths processed by the ports of the quantum node devices can be divided, so as to ensure that the services with a higher distribution frequency can be processed preferentially, that is, the quantum node devices can process the service keys of this service in time. In a possible implementation manner, the division of the priority can be to divide the multiple temporary keys generated by the ports of the quantum node devices into a high-priority key pool and a normal key pool, so as to ensure that the services with a high distribution frequency can be processed in time. Then, the above solution can divide the priority of the service keys transmitted through the key distribution paths based on the key distribution frequency and the key processing capabilities, so as to ensure the timeliness of the service key distribution and achieve the high availability of the service key distribution.

[0012] In a possible implementation manner, the routing information includes: the key distribution working path between the quantum source node device and the quantum destination node device, and the key distribution protection path between the quantum source node device and the quantum destination node device.

[0013] Then, in the above solution, the routing information includes the working path of key distribution between the quantum source node device and the quantum destination node device, as well as the protection path of key distribution between the quantum source node device and the quantum destination node device. That is, the generated routing information includes the working path of service key distribution (i.e., the key distribution working path) and the protection path (i.e., the key distribution protection path). Usually, the service secret key will be distributed through the key distribution working path. When a network failure or a transmission line (such as an optical fiber) failure causes the distribution to be interrupted, if there is a key distribution protection path, the service secret key will be distributed through the protection path. Then, through the above solution, the routing information generated based on the service request message and the key processing capabilities of the quantum node devices can determine the key distribution working path and the key distribution protection path, avoiding the interruption of service secret key distribution caused by problems such as network failures, and ensuring the transmission efficiency.

[0014] In a possible implementation manner, before generating the routing information based on the service request message and the key processing capabilities of the quantum node devices, it further includes: receiving the key processing capabilities sent by the quantum node devices.

[0015] Then, in the above solution, first, the key processing capabilities sent by the quantum node devices can be received, and then, based on the service request message and the received key processing capabilities of the quantum node devices, the routing information is generated. Among them, receiving the key processing capabilities sent by the quantum node devices can be receiving the key processing capabilities sent by the quantum node devices periodically, or randomly receiving the key processing capabilities sent by the quantum node devices. Also, for example, it can also be receiving the key processing capabilities actively sent by the quantum node devices in response to a change in their own key processing capabilities. Usually, the key processing capabilities of multiple quantum node devices included in the communication network are different, and a quantum node device can only determine its own key processing capabilities. Generally speaking, the service secret key is distributed through a certain key distribution path. Among them, the service secret key (the quantity of the service secret key or the distribution frequency of the service secret key) may exceed the key processing capabilities of the quantum node devices passed through, resulting in problems such as congestion. In this way, through the above solution, the key processing capabilities sent by the quantum node devices can be received first, and then the routing information is generated based on the key processing capabilities and the service request message. Then, the above solution can receive the key processing capabilities of the quantum node devices and then generate the routing information, avoiding problems such as congestion during the distribution of the service secret key, and effectively improving the distribution quality of the service secret key.

[0016] In a possible implementation manner, before receiving the key processing capabilities sent by the quantum node devices, it further includes: sending a synchronization key processing capabilities request message to the quantum node devices.

[0017] Then, in the above solution, first, a synchronization key processing capability request message can be sent to the quantum node device; then, the key processing capability sent by the quantum node device is received. Specifically, any quantum node device in the communication network can only determine its own key processing capability, and the key processing capabilities of different quantum node devices are usually different. In this way, by sending a synchronization key processing capability request message to the quantum node device, the above solution can enable the quantum node device to report its own key processing capability in response to the received synchronization key processing capability request message. Further, when the distribution of service keys is required, the above solution can determine the key distribution path based on the key processing capabilities reported by the quantum node devices, and then generate routing information. In this way, the service secret key can be distributed through the key distribution path included in the generated routing information, thereby ensuring the quality of the distribution of the service secret key. For example, it can avoid the problem of congestion caused by the service secret key exceeding the key processing capability of a certain quantum node device passed through. Then, by sending a synchronization key processing capability request message to the quantum node device, the above solution can enable the quantum node device to report its own key processing capability for further generating routing information.

[0018] In a second aspect, a communication method is provided. The communication method is applied to a quantum source node device in a communication network, the communication network includes a control device and at least two quantum node devices, and the at least two quantum node devices include a quantum source node device and a quantum destination node device; the communication method includes: receiving routing information, where the routing information includes a key distribution path between the quantum source node device and the quantum destination node device; and sending a distribution message to another quantum node device based on the routing information; where the distribution message includes the routing information and an encryption key.

[0019] Then, the above solution can send a distribution message to another quantum node device based on the received routing information. Specifically, based on the received routing information, the service key can be processed to obtain an encryption key, and then a distribution message including the routing information and the encryption key is sent to another quantum node device, so that the other quantum node device can continue to distribute the service secret key based on the received distribution message. Among them, based on the received routing information including the key distribution path between the quantum source node device and the quantum destination node device, the next quantum node device that the service secret key distribution needs to pass through can also be determined. In this way, the above solution can send the routing information and the encryption key to another quantum node device by sending a distribution message to another quantum device based on the received routing information. Then, the above solution can enable the quantum node devices passed by the service secret key distribution to obtain the routing information based on the distribution message and decrypt the (processed and encrypted) service key, ensuring the security of the service secret key distribution and facilitating the further distribution of the service key.

[0020] In a possible implementation, before sending a distribution message to another quantum node device based on routing information, it further includes: generating an encryption key based on a service secret key and a temporary key, and the distribution message further includes an identifier of the temporary key.

[0021] Then, in the above solution, an encryption key can be generated based on the service secret key and the temporary key, so as to obtain the encryption key, and then a distribution message including the identifier of the temporary key is sent to another quantum node device based on the routing information. Further, based on the identifier of the temporary key in the received distribution message, another quantum node device can decrypt the received encryption key to obtain the service key; at the same time, it can also determine another quantum node device through which the service secret key needs to be distributed according to the routing information included in the distribution message. Of course, another quantum node device may also be a quantum sink node device. Generally, the quantum sink node device can obtain the service key through the identifier of the temporary key in the received distribution message and notify the control device that the distribution of the service secret key has been completed. Then, the above solution can encrypt the service secret key through the temporary key and send a distribution message including the identifier indicating the temporary key to another quantum node device, so that another quantum node device can realize the further distribution of the service key based on the received distribution message.

[0022] In a possible implementation, before sending a distribution message to another quantum node device based on routing information, it further includes: receiving the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path; the distribution message further includes the priority.

[0023] Then, the above solution can first receive the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path, and then send a distribution message including the priority to another quantum node device based on the routing information. Further, the quantum node device can generate temporary keys for services with different distribution frequencies through different mechanisms based on the priority. For example, the quantum node device divides services with a higher distribution frequency (such as the distribution frequency of the service secret key is relatively high (reaching the second level)) into a higher priority, so as to ensure that services with a higher distribution frequency can be processed preferentially. In a possible implementation, for the division of this priority, it can be to divide multiple temporary keys generated by the port of the quantum node device into a high-priority key pool and a normal key pool. Then, the above solution can receive the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path and send a distribution message including the priority to another quantum node device, so that the quantum node device can distribute the service secret key according to the priority, thereby effectively improving the distribution efficiency of the service key.

[0024] In a possible implementation, before generating an encryption key based on a service key and a temporary key, it further includes: determining the temporary key based on the priority of the service key transmitted through the key distribution path processed by the port of the quantum node device.

[0025] Then, in the above solution, the temporary key can be determined based on the priority of the service key transmitted through the key distribution path processed by the port of the received quantum node device. Specifically, based on the priority of the service key transmitted through the key distribution path processed by the port of the received quantum node device, the temporary key used to encrypt the service key can be determined, and then the encryption key is generated based on the service key and the temporary key. Usually, any quantum node device can generate multiple temporary keys for encrypting the service key within a unit time, but the distribution frequency of the service key is not fixed. Among them, for the service key with a higher distribution frequency, the priority of this service key transmitted through the key distribution path processed by the port of the quantum node device needs to be assigned a higher priority to ensure that this service key can be processed in a timely manner. Then, the above solution can determine the temporary key used to encrypt the service key among multiple temporary keys based on the priority, so that the distribution of the service key can be carried out according to the corresponding priority, improving the distribution efficiency.

[0026] In a possible implementation, before receiving the routing information, it further includes: sending the key processing capability to the control device.

[0027] Then, in the above solution, the quantum node device can actively send its own key processing capability to the control device. Specifically, the key processing capabilities of different quantum node devices are often different, and a quantum node device can only determine its own key processing capability. Through the above solution, the quantum node device can actively report its own key processing capability to the control device, so that the control device can determine the key processing capabilities of the quantum node devices in the communication network, and then determine the key distribution path of the service key based on the key processing capabilities of different quantum node devices to generate the routing information. Then, through the above solution, the quantum node device can actively send its own key processing capability to the control device, so that the control device can determine the key distribution path included in the routing information based on the key processing capability, effectively improving the accuracy of the routing information.

[0028] In a possible implementation, sending the key processing capability to the control device includes: receiving a synchronization key processing capability request message; in response to the synchronization key processing capability request message, sending the key processing capability to the control device.

[0029] In a possible implementation, sending the key processing capability to the control device includes: periodically sending the key processing capability to the control device at a predetermined period.

[0030] Then, in the above solution, the quantum node device can periodically send its key processing capability to the control device at a predetermined period. Specifically, the key processing capabilities of the quantum node device may be different at different times, or alternatively, in the event of a network failure or a transmission line failure, the key processing capability of the quantum node device may change. Through the above solution, the quantum node device can periodically report its key processing capability to the control device, enabling the control device to obtain the key processing capabilities of the quantum node devices in the communication network in real time. Based on this key processing capability, the key distribution path can be determined in real time (or the already determined key distribution path can be refreshed), thereby generating routing information. Then, through the above solution, the quantum node device can periodically send its key processing capability to the control device, enabling the control device to determine the key distribution path in real time and ensuring the timeliness of the routing information.

[0031] In a possible implementation manner, sending the key processing capability to the control device includes: in response to a change in the key processing speed of its own port, sending the key processing capability to the control device.

[0032] In a third aspect, a communication device is provided. The communication device includes: a transceiver unit, which is used to receive a service request message, and the service request message includes the device information of the quantum source node device and the device information of the quantum destination node device; a processing unit, which is used to generate routing information based on the service request message received by the transceiver unit and the key processing capability of the quantum node device; wherein the routing information includes the key distribution path between the quantum node device and the quantum destination node device; the transceiver unit is further used to configure the routing information generated by the processing unit into the quantum source node device included in the service request message.

[0033] In a fourth aspect, a communication device is provided. The communication device includes: a transceiver unit, which is used to receive routing information; a processing unit, which determines a distribution message based on the routing information received by the transceiver unit; wherein the distribution message includes the routing information; the transceiver unit is further used to send the distribution message to another quantum node device.

[0034] In a fifth aspect, a communication device is provided. The communication device includes: a processor and a transceiver module coupled to the processor; wherein the processor is used to execute computer instructions to control the transceiver module to execute the communication method described in any possible implementation manner of the first aspect and the second aspect.

[0035] In a sixth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instructions. When the computer reads and executes the computer program or instructions, the computer is caused to execute the communication method described in any possible implementation manner of the first aspect and the second aspect.

[0036] In a seventh aspect, a computer program product including instructions is provided. The computer program product includes computer program code which, when run on a computer, enables the computer to execute the communication method described in any possible implementation manner of the first aspect and the second aspect.

[0037] In an eighth aspect, a chip or a chip system is provided. The chip or the chip system includes a processing circuit and an input / output interface. Among them, the processing circuit is used to execute the communication method described in any possible implementation manner of the first aspect and the second aspect.

[0038] In a ninth aspect, a communication network is provided. The communication network includes at least one control device and at least two quantum node devices. Among them, the control device includes the communication device described in any possible implementation manner of the third aspect. At least one of the two quantum node devices includes the communication device described in any possible implementation manner of the fourth aspect.

[0039] Among them, for the technical effects brought by the above-mentioned third aspect to the ninth aspect and any of their design manners, reference can be made to the technical effects brought by different design manners in the above-mentioned first aspect and second aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 A schematic diagram of a quantum communication provided for an embodiment of the present application;

[0041] Figure 2 A schematic diagram of a quantum key distribution process provided for an embodiment of the present application;

[0042] Figure 3 A schematic diagram of a communication network provided for an embodiment of the present application;

[0043] Figure 4 A schematic diagram of a communication method provided for an embodiment of the present application;

[0044] Figure 5 A schematic diagram of a communication network provided for another embodiment of the present application;

[0045] Figure 6 A schematic diagram of a communication device provided for an embodiment of the present application;

[0046] Figure 7 A schematic diagram of a communication device provided for an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] This application will present various aspects, embodiments, or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these solutions may also be used. It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0048] Next, the technical solutions in the embodiments of this application will be described in conjunction with the accompanying drawings.

[0049] With the development of communication technologies and the increasing emphasis on information security by people, quantum communication has increasingly appeared in the public eye, and quantum communication technology has become a strategic frontier technology for enhancing cybersecurity in cyberspace. Quantum communication is a new type of communication method that uses quantum superposition states and entanglement effects to achieve information transmission, and has higher security and efficiency.

[0050] Among them, quantum key distribution, as the most important application of quantum communication technology, is crucial for current and future global communication systems. Generally, quantum key distribution realizes the purpose of quantum encryption of services by generating and distributing service quantum keys (also known as service keys). Among them, in order to prevent the interception during the generation and distribution of service keys, a temporary quantum key (also known as a temporary key) needs to be generated during distribution, and the generated temporary key can perform an exclusive OR operation with the service key. In this way, even if the XORed service key is intercepted during transmission, the original (before XOR) service key cannot be obtained from it, thus ensuring the security of the service key. Due to the distance limitation in the generation of temporary keys, multiple quantum trusted relay nodes also need to be selectively deployed during the transmission of service keys, so that the service key can reach the destination node safely through multiple quantum trusted relay nodes during the distribution process.

[0051] [[ID= (12)]]Exemplarily, referring to Figure 1 As shown, the embodiments of this application provide a schematic diagram of quantum communication, showing the process of distributing service keys between user nodes. Among them, in combination with Figure 1 As shown, it includes user node A, quantum trusted relay node (abbreviated as relay node) B, quantum trusted relay node C, and user node D.

[0052] It should be noted that only Figure 1Taking the architecture shown as an example, the process of distributing business keys is described, and the embodiments of this application should not be limited thereby. In a possible implementation, the above-mentioned quantum trusted relay nodes (such as relay node B and relay node C) can be implemented by quantum devices (such as quantum node devices) in a quantum communication network, and the above-mentioned user nodes (such as user node A and user node D) can be implemented by communication devices (such as node devices) in a communication network. It can be understood that the embodiments of this application do not limit Figure 1 the device types, the number of devices, etc. in the architecture shown.

[0053] Specifically, referring to Figure 1 shown, the process of business key distribution is described as follows:

[0054] (1) Between user node A and relay node B, a temporary key and the corresponding identity document (ID) of the temporary key are generated in real time through quantum negotiation. Among them, the speed of relay node B generating temporary keys is hundreds per second. For example, referring to Figure 2 shown, if the temporary key is K AB1 , then the ID of this temporary key is AB1, denoted as ID AB1 .

[0055] (2) User node A generates business key K1 and temporary key K AB1 , and by performing exclusive OR on K1 and K AB1 , an encrypted business key (also called an encrypted key) is obtained. Usually, in order to ensure that the encrypted key cannot be cracked during the distribution process, after performing the exclusive OR, the temporary key (such as K AB1 ) used to encrypt the business key will no longer be available, for example, it cannot be used again to perform exclusive OR on another business key.

[0056] (3) User node A forwards the encrypted key and the identity ID of the temporary key AB1 to relay node B. Relay node B re-obtains business key K1 by performing exclusive OR on the received encrypted key and the temporary key K AB1 corresponding to ID AB1 .

[0057] (4) Similarly, relay node B performs exclusive OR on temporary key K BC1 and business key K1 to obtain a new encrypted key.

[0058] It is not difficult to understand that the process of generating a temporary secret key and the identifier of the corresponding temporary secret key in real time through quantum negotiation between relay node B and relay node C, and between relay node C and user node D can refer to the above step (1). Among them, the embodiments of the present application do not limit the specific steps of how the quantum node device specifically generates the temporary secret key and the identifier of the corresponding temporary secret key.

[0059] In this way, by repeating the above process (steps (1) to (4)), user node A encrypts the service secret key K1, and user node D decrypts it to obtain the service secret key K1, thereby realizing the distribution of the service key from user node A to user node D.

[0060] However, there are still many challenges in the current application of quantum communication. For example, the period of quantum secret key distribution is usually not fixed. According to the priority of customer services, the distribution period may be weekly (distributed at a weekly time interval), daily (distributed at a daily time interval), hourly, minute-level, or even second-level. However, the ability of a trusted relay node (such as the quantum trusted relay node B in Figure 2 to generate temporary secret keys (such as the quantity generated) is limited. In this way, when the distribution period becomes short, the service secret key cannot be processed in real time, resulting in congestion. Another example is that the anti-noise ability of quantum communication is poor. Specifically, when the transmission quality of the optical fiber deteriorates, it will affect the number of generated temporary secret keys (for example, decreasing from 400 per second to 100 per second), resulting in congestion in the processing of the service secret key. In addition, during the distribution of the service secret key, network failures (link failures, quantum node device failures, etc.) will also cause the service secret key to not be distributed normally.

[0061] Based on the above problems, quantum secret key distribution is usually achieved through manual static configuration. Exemplarily, referring to Figure 2 as shown, the embodiments of the present application provide a schematic diagram of the process of quantum key distribution, showing the process of realizing service key distribution through static configuration. Specifically, as shown in combination with Figure 2 there is a quantum communication network 10 and a service network 20. Among them, the quantum communication network 10 includes: a management system 101, and multiple quantum node devices ( Figure 2 the quantum node devices 102-1 to 102-N in Figure 2 ). The service network 20 includes: an operator network 21 and an enterprise network 22; among them, the operator network 21 includes multiple node devices ( Figure 2 the node devices 201-1 to 201-N in

[0062] Specifically, the service network can be a network for service transmission, such as an optical transport network, or it can also be other possible service networks. The quantum communication network is used to generate service keys and distribute service keys to enable the service transmission required by the service network. Among them, between the above-mentioned service networks (including operator networks, enterprise networks, etc.) and multiple devices included in the quantum communication network (such as between quantum node devices, between node devices), transmissions are all realized through corresponding transmission lines. Optionally, the transmission line can be realized through transmission media such as optical fibers and optical cables, or it can also be realized through other possible structures. It should be noted that only the Figure 2 shown architecture is used as an example to illustrate the process of quantum key distribution, and the embodiments of this application should not be limited thereby. For example, the above-mentioned node devices (such as node devices 202-1 to node devices 202-N) can be realized by communication devices in the communication network. It can be understood that the embodiments of this application do not limit Figure 2 the device types, the number of devices, etc. in the

[0063] shown architecture. Figure 2 Specifically, with reference to

[0064] (1) Through the management system 101, perform manual static configuration to specify that the quantum node device 102-1 (in the quantum communication network 10) connected to the node device 201-1 (in the operator network 21) generates service keys.

[0065] (2) Through the management system 101, configure the key distribution path of the service key. This key distribution path includes the key distribution working path of the service key (refer to Figure 2 shown) and the key distribution protection path of the service key (refer to Figure 2 shown). Among them, this key distribution path needs to specify the quantum source node device (such as quantum node device 102-1), the quantum destination node device (such as quantum node device 102-N) for service key distribution, and the passed quantum trusted relay nodes (corresponding quantum node devices). Usually, the service key will be distributed through the key distribution working path.

[0066] (3) After completing the manual configuration described in the above steps, the quantum source node device generates service keys and starts to distribute them. The specific process of the distribution can refer to the Figure 1 shown process, which will not be elaborated here.

[0067] (4) After the service key is distributed to the node device 202-N in the enterprise network 22 connected to the quantum node device 102-N (in the quantum communication network 10), it is manually configured through the management system 101 to specify that the node device 201-1 and the node device 202-N use the new service key for service key distribution (including encrypting and decrypting the service key).

[0068] (5) During the distribution process of the service key, if a network failure occurs, the service key will switch to be distributed through the key distribution protection path to ensure that the service key can continue to be normally distributed.

[0069] In this way, based on the above, through the method of manual static configuration, the key distribution path of the service key can be specified to ensure the normal distribution of the service key. For example, by manually statically configuring the key distribution protection path of the service key in advance, when a network failure occurs, the service key can be timely switched to the configured key distribution protection path for distribution and will not be directly interrupted due to the network failure.

[0070] However, there are still many problems in implementing the distribution of service keys through the method of manual static configuration. For example, the method of manual static configuration can only support scenarios with a small network scale, that is, this method can only configure the routing of service key distribution involving a small number of network elements (such as quantum node devices), for example, dozens. It will be difficult to implement the configuration of the routing of service key distribution involving a large number of network elements (such as reaching the thousands level) through the method of manual static configuration. Usually, to implement the corresponding configuration for the routing of service key distribution involving hundreds of thousands of network elements, it is necessary to maintain a static routing table of millions. In addition, there is a risk of loss of service keys when using the method of manual static configuration for service key distribution. For example, if a transmission line failure occurs (such as the deterioration of the transmission quality of optical fibers and optical cables), the processing speed of the quantum node device for service keys will decrease (such as from 400 per second to 100 per second), which causes some service keys to be lost because they cannot be processed in real time. In addition, there is also a risk of distribution interruption when using the method of manual static configuration. For example, when transmission line interruptions occur in both the key distribution working path and the key distribution protection path (also known as double fiber break), the service key cannot be normally distributed. Another example is that in other similar scenarios with multiple failures, the service key cannot be normally distributed.

[0071] Based on the above problems, exemplarily, referring to Figure 3 as shown, the embodiments of the present application provide a schematic diagram of a communication network. Specifically, in combination with Figure 3As shown, the communication network includes a quantum communication network, which includes: a control device 301 and multiple quantum node devices ( Figure 3 the quantum node devices 302-1 to 302-N in

[0072] Optionally, the above communication network further includes a service network. Among them, the service network can refer to the service network 20 Figure 2 shown. Specifically, the service network can be a network for service transmission, such as an OTN network, or it can also be other possible service networks. When the service network is deployed in different application scenarios, different types of service transmissions will be carried out. For example, when the service network is deployed in an enterprise scenario (i.e., an enterprise network), the service transmission within the enterprise can be realized. Of course, the service network can also be different types of communication networks corresponding to other application scenarios. Further, the quantum communication network can realize the service transmission required by the service network by generating service keys and distributing the generated service keys. In this way, the quantum communication network can be used for service transmission for the corresponding service network.

[0073] Specifically, as shown in Figure 3 multiple quantum node devices in the quantum communication network can report the temporary key processing ability to the quantum network control device (abbreviated as the control device, i.e., the control device 301) in real time. Optionally, the control device 301 stores the key processing abilities of all quantum node devices in the quantum communication network. In a possible implementation manner, the quantum node device includes at least one port; the key processing ability includes the port identifier of the port and the key processing speed of the port.

[0074] In a possible implementation manner, the control device 301 receives a service request message, which includes the device information of the quantum source node device and the device information of the quantum destination node device; the control device 301 generates routing information based on the service request message and the key processing ability of the quantum node device; among them, the routing information includes the key distribution path between the quantum source node device and the quantum destination node device. Further, the control device 301 configures the routing information into the quantum source node device (such as the quantum node device 302-1) included in the service request message.

[0075] Optionally, the routing information includes the key distribution working path passing between the quantum source node device and the quantum destination node device, and the key distribution protection path passing between the quantum source node device and the quantum destination node device.

[0076] Optionally, the service request message may be sent to the control device 301 manually or by a certain node device in the service network (such as node device 303-1).

[0077] In a possible implementation, the service request message further includes a key distribution frequency. Then, the control device 301 generates routing information based on the service request message and the key processing capabilities of the quantum node devices, including: determining the priority of the service key for the port of the quantum node device to process the key distribution path transmission based on the key distribution frequency; and sending the priority of the service key for the port of the quantum node device to process the key distribution path transmission to the quantum source node device.

[0078] In this way, the quantum source node device (quantum node device 302-1) can select a temporary secret key to perform exclusive OR on the service secret key based on the above priority to obtain an encrypted secret key, and then determine a distribution message based on the temporary key, the encrypted secret key, and the routing information. Further, based on the key distribution working path included in the routing information, the determined distribution message is sent to another quantum node device (such as quantum node device 302-2). After receiving the message, the other quantum node device performs exclusive OR on the encrypted secret key based on the distribution message to obtain the service secret key, and then repeats the processing flow of the quantum source node device. When the service secret key is distributed to the quantum destination node device (such as quantum node device 302-N), the quantum destination node device notifies the control device 301 that the service secret key distribution is completed.

[0079] In this way, the above solution can determine the key distribution path based on the device information of the quantum source node device for service key distribution, the device information of the quantum destination node device, and the key processing capabilities of the quantum node devices, so that the service secret key can be distributed through the determined key distribution path, thereby improving the distribution efficiency of the service secret key and ensuring the transmission quality of the service secret key.

[0080] Based on Figure 3 the architecture shown, exemplarily, as shown in Figure 4 shown, an embodiment of the present application provides a schematic diagram of a communication method, wherein the communication method can be used to implement service key distribution. Next, the communication method provided by the embodiment of the present application will be described in detail in conjunction with Figure 4 . It should be noted that, taking the architecture shown in Figure 3 as an example, the communication method provided by the embodiment of the present application is described by taking the control device (control device 301) and the quantum source node device (such as quantum node device 302-1) as examples, and this should not limit the communication method provided by the embodiment of the present application. The communication method includes steps 401-step 405, which are specifically described as follows:

[0081] Step 401: Receive a service request message.

[0082] Combine Figure 4 As shown, the control device receives a service request message, where the service request message includes the device information of the quantum source node device and the device information of the quantum destination node device. Specifically, combine Figure 3 As shown, the control device 301 receives a service request message.

[0083] In a possible implementation, the service request message further includes the key distribution frequency.

[0084] Optionally, the quantum node device includes at least one port; the key processing capability includes the port identifier of the port and the key processing speed of the port. For example, referring to Figure 5 As shown, the quantum node device 302-1 includes at least one port E, and the key processing capability of the quantum node device 302-1 includes: the port identifier of the port (i.e., port E) and the key processing speed of port E (i.e., 400 per second).

[0085] It should be noted that the above service request message can be sent by a human or a certain node device in the service network (such as node device 303-1) to the control device 301 for requesting the generation and distribution of service secrets.

[0086] Step 402, generate routing information.

[0087] Combine Figure 4 As shown, the control device generates routing information based on the service request message and the key processing capabilities of the quantum node devices; where the routing information includes the key distribution path between the quantum source node device and the quantum destination node device. Specifically, combine Figure 3 As shown, the control device 301 generates routing information based on the service request message and the key processing capabilities of the quantum node devices.

[0088] For example, referring to Figure 5 As shown, the control device 301 can specifically implement the key topology management and distribution routing management functions. Among them, through the key topology management function, the control device can determine the topology formed by multiple quantum node devices in the network based on the key processing capabilities reported by the quantum node devices; at the same time, through the distribution routing management function, it can perform distribution routing management based on the formed topology. Specifically, it can calculate and manage the key distribution paths of service secrets (including the key distribution working path and the key distribution protection path of service secrets). And when the network changes, it can adjust and refresh the key distribution path in real time.

[0089] In a possible implementation, the routing information includes the working path of key distribution between the quantum source node device and the quantum destination node device, as well as the protection path of key distribution between the quantum source node device and the quantum destination node device. In this way, when problems such as network failures or transmission line failures cause the port of the quantum node device to process service keys at a reduced speed, resulting in the inability to normally distribute service keys, the quantum source node device can automatically switch to the key distribution protection path for key distribution to ensure that service keys can be normally distributed.

[0090] In a possible implementation, as described in step 401, the service request message further includes the key distribution frequency. Then step 402 further includes: determining the priority of the service key transmitted by the port of the quantum node device for the key distribution path based on the key distribution frequency and the key processing ability of the quantum node device.

[0091] Specifically: In a possible implementation, the routing information includes the port information of the ports of the quantum node devices through which the key distribution path passes. Refer to Figure 5 As shown, for a certain path (such as path 1E-2F) between the quantum node device 302-1 and the quantum node device 302-2, where path 1E-2F represents the transmission line (such as an optical fiber link) connecting port E of the quantum node device 302-1 and port F of the quantum node device 302-2, the key processing ability on path 1E-2F represents the speed at which the port E of the quantum node device 302-1 and the port F of the quantum node device 302-2 can generate temporary keys in real time through quantum negotiation (such as 500 per second).

[0092] Combined with Figure 5 As shown, based on the received key processing ability, the control device can determine the priority of the service key transmitted by path 1E-2F. For example, 50 of the 500 temporary keys generated per second by path 1E-2F are determined to be of high priority, and the remaining 450 temporary keys out of the 500 generated per second by path 1E-2F are determined to be of normal priority. That is, the division of priorities can be to divide the multiple temporary keys generated by the ports of the quantum node devices, and divide out a high-priority key pool (such as corresponding to the above 50 high-priority temporary keys) and a normal key pool (such as corresponding to the above 450 normal-priority temporary keys), so as to ensure that services with a high distribution frequency can be processed in a timely manner.

[0093] Step 403: Configure the routing information into the quantum source node device.

[0094] Combined with Figure 4 As shown, the control device configures the routing information into the quantum source node device included in the service request message. Specifically, combined with Figure 3As shown, the control device 301 configures the routing information into the quantum source node device 302-1 included in the service request message.

[0095] Combined with step 402, if the service request message further includes the key distribution frequency. Then step 403 further includes: sending the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path to the quantum source node device.

[0096] In this way, based on the above steps 401 to 403, it is possible to determine the key distribution path based on the service request message and the key processing capabilities of the quantum node devices, and allocate it to the quantum source node device, thereby realizing the configuration of the path for service key distribution.

[0097] Optionally, before the above step 402, it further includes: receiving the key processing capabilities sent by the quantum node device. In this way, the control device can obtain the key processing capabilities of any quantum node device and generate routing information including the key distribution path. Among them, referring to Figure 5 As shown, through the key topology management function, the control device can store the key processing capabilities sent by the received quantum node device in the local data and automatically generate the quantum network key topology.

[0098] In a possible implementation manner, when problems such as network failures or fiber optic cable cracking occur, resulting in a change (usually a decrease) in the key processing speed of the quantum node device and the inability to normally distribute service keys, the quantum source node device will automatically switch to the key distribution protection path for quantum key distribution. Among them, referring to Figure 5 As shown, through the key management function, the quantum node device can report the changed key processing capabilities to the control device. Further, the quantum source node device will notify the control device of the switch of the distribution path. Based on the above step 602, the control device will automatically re-determine the routing information and send the refreshed routing information to the quantum source node device. Among them, referring to Figure 5 As shown, through the key topology management function, the control device can refresh the generated quantum network key topology.

[0099] Further, combined with Figure 4 As shown, the above communication method further includes:

[0100] 404. Receive routing information.

[0101] Combined with Figure 4 As shown, the quantum source node device receives the routing information. Specifically, combined with Figure 3 As shown, the quantum source node device 302-1 receives the routing information.

[0102] For example, referring to Figure 5As shown, the quantum source node device 302-1 can specifically implement the key management function. Through the key management function, it can generate keys, manage the priorities of service keys transmitted along the key distribution path for the ports of the quantum node device, and perform encryption (XOR) processing on the service keys. In addition, when the network changes (such as a fault occurs) resulting in a change in the key processing ability of the quantum node device, through the key management function, it can report the key processing ability to the control device in real time, so that the control device can refresh the quantum network key topology (i.e., the stored key processing abilities of the quantum node devices) and adjust and refresh the key distribution path in real time.

[0103] 405. Send a distribution message.

[0104] Combined with Figure 4 As shown, the quantum source node device sends a distribution message to another quantum node device based on the routing information; among them, the distribution message includes the routing information and the encryption key. Specifically, combined with Figure 3 As shown, the quantum source node device 302-1 sends a distribution message to another quantum node device (the quantum intermediate node device 302-2) based on the routing information.

[0105] For example, referring to Figure 5 As shown, the quantum source node device 302-1 can specifically also implement the signaling protocol function. Through the signaling protocol function, it can implement the protocol processing and forwarding of key distribution, that is, perform protocol processing and forwarding on the information related to the service key, routing information, priority, etc. included in the distribution message. In a possible implementation manner, the format of the above distribution message can refer to Figure 5 As shown.

[0106] It should be noted that when the key distribution path changes, it is usually necessary to reconfigure the quantum node devices through which the key distribution path of the service key passes. However, since the moment when the key distribution path changes is not fixed and it is difficult to determine the degree of the change, it is difficult to achieve the reconfiguration of the key distribution path through manual static configuration. In one possible implementation, the automatic reconfiguration (also known as dynamic configuration) of the key distribution path can be achieved by introducing a dynamic protocol (such as multiprotocol label switching (MPLS)). However, if the resource reservation protocol (RSVP) in MPLS is used for dynamic configuration, the configuration data (such as ports, priorities, etc.) of a large number of intermediate nodes (i.e., quantum intermediate node devices) need to be maintained. For example, if a certain quantum node device through which the key distribution path passes fails, resulting in a change in the key distribution path, it is necessary to re-determine each quantum node device (such as priorities, etc.) through which the service key is distributed to achieve the reconfiguration of the key distribution path, resulting in relatively complex maintenance.

[0107] However, referring to Figure 5 As shown, based on step 405 of the present application, through the signaling protocol function of the quantum node device, the key distribution path and the service key can be integrated into a data packet (i.e., the distribution message, referring to Figure 5 the format of the distribution message shown). In this way, when the key distribution path changes, only the distribution message distributed to the quantum source node device needs to be modified. Further, the distribution message can be distributed and encrypted along the key distribution path of the service key in the distribution message, thereby improving the scalability of the service key distribution.

[0108] It should be noted that only Figure 5 the format of the distribution message shown is used as an example to illustrate the functions of protocol processing and forwarding of the signaling protocol function, and the embodiments of the present application should not be limited thereby.

[0109] Optionally, before step 404, the above steps further include: the quantum node device sends the key processing capability to the control device. In one possible implementation, the quantum node device sends the key processing capability to the control device in response to a change in the key processing speed of its own port.

[0110] Optionally, before step 405, the above steps further include: receiving the priority of the service key transmitted by the port processing key distribution path of the quantum node device; determining a temporary key based on the priority. Further, the above steps further include: generating an encryption key based on the service key and the temporary key, and the distributed message further includes an identifier of the temporary key.

[0111] Based on the above steps 404 to 405, the quantum node device can actively report the quantum key processing capability to the control device, including the changed quantum key processing capability, and at the same time can store the priority of the service key transmitted by the port processing key distribution path of the quantum node device. In this way, the above steps can, based on the received routing information, and then send the routing information and the encryption key to another quantum node device by sending a distribution message to another quantum device, so that all quantum node devices through which the service key is distributed can obtain the routing information and decrypt the service key based on this distribution message, ensuring the security of the service key distribution and facilitating the further distribution of the service key.

[0112] Then, the communication method described in the above steps 401 to 405 can be applied to a quantum communication network including a large number of network elements. Through the above steps, a key distribution path can be automatically generated without manual maintenance (such as manual static configuration), and the key distribution path can be adjusted (refreshed) in real time when the key processing capability of the quantum node device changes, so as to ensure the normal transmission of the service key. In addition, based on the above communication method for transmitting the service key, the security of the service key distribution can be improved, and it is ensured that the service key will not be lost during the distribution process. In addition, the above communication method can improve the reliability of the service key distribution. In the face of problems such as network failures and transmission line failures, it can achieve a quick switch of the service key distribution service (for example, within 50 milliseconds (ms)).

[0113] Exemplarily, referring to Figure 6 as shown, an embodiment of the present application provides a schematic diagram of a communication device, which can be applied to a control device. Combining Figure 6 as shown, the communication device 6 includes: a transceiver unit 601 and a processing unit 602; the transceiver unit 601 is used for the transceiver unit to receive a service request message, and the service request message includes device information of the quantum source node device and device information of the quantum destination node device; the processing unit 602 is used to generate routing information based on the service request message received by the transceiver unit 601 and the key processing capability of the quantum node device; wherein, the routing information includes a key distribution path between the quantum source node device and the quantum destination node device. The transceiver unit 601 is further used to configure the routing information generated by the processing unit to the quantum source node device included in the service request message.

[0114] In a possible implementation, the quantum node device includes at least one port; the key processing capability includes the port identifier of the port and the key processing speed of the port.

[0115] In a possible implementation, the service request message further includes the key distribution frequency; the processing unit 602 is further configured to determine the priority of the service key for the port of the quantum node device to process the key distribution path transmission based on the key distribution frequency and the key processing capability of the quantum node device. The transceiver unit 601 is further configured to send the priority of the service key for the port of the quantum node device to process the key distribution path transmission determined by the processing unit 602 to the quantum source node device.

[0116] In a possible implementation, the routing information includes: the key distribution working path between the quantum source node device and the quantum destination node device, and the key distribution protection path between the quantum source node device and the quantum destination node device.

[0117] In a possible implementation, before the processing unit 602 generates the routing information based on the service request message and the key processing capability of the quantum node device, the transceiver unit 601 is further configured to receive the key processing capability sent by the quantum node device.

[0118] In a possible implementation, before the transceiver unit 601 receives the key processing capability sent by the quantum node device, the transceiver unit 601 is further configured to send a synchronization key processing capability request message to the quantum node device.

[0119] Wherein, the transceiver unit 601 is further configured to execute the communication methods described in steps 401 and 403; the processing unit 602 is further configured to execute the communication method described in step 402. It can be understood that this communication device can directly quote the Figure 4 descriptions of the various functions and effects in the shown communication method, which will not be elaborated here.

[0120] In a possible implementation, an embodiment of the present application further provides a communication device applied to a quantum source node device. Combining Figure 7 As shown, the communication device 20 includes: a transceiver unit 701 and a processing unit 702; the transceiver unit 701 is configured to receive routing information; the processing unit 702 is configured to determine a distribution message based on the routing information received by the transceiver unit 701; wherein, the distribution message includes the routing information; the transceiver unit 701 is further configured to send the distribution message to another quantum node device.

[0121] In a possible implementation, before the processing unit 702 determines the distribution message based on the routing information; the processing unit 702 is further configured to generate an encryption key based on the service secret key and the temporary key, and the distribution message further includes the identifier of the temporary key.

[0122] In a possible implementation, before the processing unit 702 determines the distribution message based on the routing information; the transceiver unit 701 is further configured to receive the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path; the distribution message further includes the priority.

[0123] In a possible implementation, before the processing unit 702 generates the encryption key based on the service secret key and the temporary key; the processing unit 702 is further configured to determine the temporary key based on the priority of the service key transmitted by the port of the quantum node device for processing the key distribution path.

[0124] In a possible implementation, before the transceiver unit 701 receives the routing information; the transceiver unit 701 is further configured to send the key processing capability to the control device.

[0125] In a possible implementation, before the transceiver unit 701 sends the key processing capability to the control device; the transceiver unit 701 is further configured to receive the synchronization key processing capability request message sent by the control device; the transceiver unit 701 is further configured to, in response to the synchronization key processing capability request message, send the key processing capability to the control device.

[0126] In a possible implementation, the transceiver unit 701 sending the key processing capability to the control device includes: the transceiver unit 701 is further configured to, in response to a change in the key processing speed of its own port, send the key processing capability to the control device.

[0127] Wherein, the transceiver unit 701 is further configured to execute the communication method described in step 404; the processing unit 702 is further configured to execute the communication method described in step 405. It can be understood that this communication device can directly cite the descriptions of the various functions and effects in the above Figure 4 illustrated communication method, which will not be elaborated here.

[0128] In a possible implementation, an embodiment of the present application further provides a communication device. The communication device includes: a processor and a transceiver module coupled to the processor; wherein, the processor is configured to execute computer instructions to control the transceiver module to execute the communication method described in the above method embodiment of the present application. It should be noted that when this communication device is applied to the control device, the functions of the above transceiver module can be implemented by Figure 6 the transceiver unit 601 therein, and the functions of the above processor can be implemented by Figure 6 the processing unit 602 therein. In other examples, when this communication device is applied to the quantum source node device, the functions of the above transceiver module can be implemented by Figure 7 the transceiver unit 701 therein, and the functions of the above processor can be implemented by Figure 7 the processing unit 702 therein.

[0129] In a possible implementation, an embodiment of the present application further provides a computer-readable storage medium. A computer program or instructions are stored in the computer-readable storage medium. When the computer reads and executes the computer program or instructions, the computer is caused to execute the communication method as described in the above method embodiment of the present application.

[0130] In a possible implementation, an embodiment of the present application further provides a computer program product containing instructions. The computer program product includes: computer program code. When the computer program code runs on a computer, the computer can execute the communication method as described in the above method embodiment of the present application.

[0131] In a possible implementation, an embodiment of the present application further provides a chip or a chip system. The chip or the chip system includes: a processing circuit and an input / output interface; wherein, the processing circuit is configured to execute the communication method as described in the above method embodiment of the present application.

[0132] In a possible implementation, an embodiment of the present application further provides a communication network. The communication network includes: at least one control device and at least one quantum node device; wherein, the control device includes the communication device as described in the embodiment of the present application (refer to Figure 6 shown), and the quantum node device includes the communication device as described in the embodiment of the present application (refer to Figure 7 shown).

[0133] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more media integrated therein. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc. In the embodiments of the present application, the computer can include the device described above.

[0134] Although the present application has been described in connection with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the accompanying drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0135] Although the present application has been described in connection with specific features and their embodiments, it will be apparent that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A communication method, characterized in that, A control device applied to a communication network, the communication network including the control device and at least two quantum node devices, the at least two quantum node devices including a quantum source node device and a quantum sink node device; the communication method includes: Receiving a service request message, the service request message including device information of the quantum source node device and device information of the quantum sink node device; Generating routing information based on the service request message and the key processing capabilities of the quantum node devices; wherein, the routing information includes a key distribution path between the quantum source node device and the quantum sink node device; Configuring the routing information to the quantum source node device.

2. The communication method according to claim 1, characterized in that, The quantum node device includes at least one port; the key processing capabilities include the port identifier of the port and the key processing speed of the port.

3. The communication method according to claim 2, characterized in that, The service request message further includes a key distribution frequency; the communication method further includes: determining, based on the key distribution frequency and the key processing capabilities of the quantum node devices, the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path; Sending the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path to the quantum source node device.

4. The communication method according to any one of claims 1-3, characterized in that, The routing information includes: a key distribution working path between the quantum source node device and the quantum sink node device, and a key distribution protection path between the quantum source node device and the quantum sink node device.

5. The communication method according to any one of claims 1-3, characterized in that, Before generating the routing information based on the service request message and the key processing capabilities of the quantum node devices, it further includes: Receiving the key processing capabilities sent by the quantum node device.

6. The communication method according to claim 5, wherein Before receiving the key processing capabilities sent by the quantum node device, it further includes: Sending a synchronization key processing capability request message to the quantum node device.

7. A communication method, characterized in that, A quantum source node device applied to a communication network, the communication network including a control device and at least two quantum node devices, the at least two quantum node devices including a quantum source node device and a quantum sink node device; The communication method includes: Receiving routing information, the routing information including a key distribution path between the quantum source node device and the quantum sink node device; Sending a distribution message to another quantum node device based on the routing information; wherein, the distribution message includes the routing information and an encryption key.

8. The communication method according to claim 7, characterized in that, Before sending the distribution message to another quantum node device based on the routing information, it further includes: Generating an encryption key based on a service secret key and a temporary key, and the distribution message further includes an identifier of the temporary key.

9. The communication method according to claim 7, characterized in that Before sending the distribution message to another quantum node device based on the routing information, it further includes: Receiving the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path; the distribution message further includes the priority.

10. The communication method according to claim 8 or 9, characterized in that, Before generating the encryption key based on the service secret key and the temporary key, it further includes: Determining a temporary key based on the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path.

11. The communication method according to claim 7, characterized in that, Before receiving the routing information, it further includes: Sending the key processing capability to the control device.

12. The communication method according to claim 11, wherein Before sending the key processing capability to the control device, it includes: Receiving a synchronization key processing capability request message sent by the control device; In response to the synchronization key processing capability request message, sending the key processing capability to the control device.

13. The communication method according to claim 11, wherein Sending the key processing capability to the control device includes: In response to a change in the key processing speed of its own port, sending the key processing capability to the control device.

14. A communication device, characterized in that, The communication device includes: A transceiver unit for receiving a service request message, where the service request message includes quantum source node device information and quantum destination node device information; A processing unit for generating routing information based on the service request message received by the transceiver unit and the key processing capabilities of the quantum node devices; wherein, the routing information includes the key distribution path between the quantum source node device and the quantum destination node device; The transceiver unit is further configured to configure the routing information generated by the processing unit to the quantum source node device included in the service request message.

15. The communication device according to claim 14, wherein The quantum node device includes at least one port; the key processing capability includes the port identifier of the port and the key processing speed of the port.

16. The communication device according to claim 15, characterized in that, The service request message received by the transceiver unit further includes a key distribution frequency; The processing unit is further configured to determine the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path based on the key distribution frequency and the key processing capabilities of the quantum node devices; The transceiver unit is further configured to send the priority of the port of the quantum node device for processing the service key transmitted along the key distribution path determined by the processing unit to the quantum source node device.

17. The communication device according to any one of claims 14 to 16, characterized in that, The routing information includes: the key distribution working path between the quantum source node device and the quantum destination node device, and the key distribution protection path between the quantum source node device and the quantum destination node device.

18. The communication device according to any one of claims 14 to 16, characterized in that Before the processing unit generates routing information based on the service request message and the key processing capabilities of the quantum node devices; The transceiver unit is further configured to receive the key processing capabilities sent by the quantum node device.

19. The communication device according to claim 18, wherein Before the transceiver unit receives the key processing capabilities sent by the quantum node device; The transceiver unit is further configured to send a synchronization key processing capability request message to the quantum node device.

20. A communication device, characterized in that, The communication device includes: A transceiver unit for receiving routing information, where the routing information includes the key distribution path between the quantum source node device and the quantum destination node device; A processing unit for determining a distribution message based on the routing information received by the transceiver unit; wherein, the distribution message includes the routing information; The transceiver unit is further configured to send the distribution message to another quantum node device.

21. The communication device according to claim 20, characterized in that, Before the processing unit determines the distribution message based on the routing information; The processing unit is further configured to generate an encryption key based on the service secret key and the temporary key, and the distribution message further includes the identifier of the temporary key.

22. The communication device according to claim 20, characterized in that, Before the processing unit determines to distribute the message based on the routing information; The transceiver unit is further configured to receive the priority of the service key transmitted by the port of the quantum node device for the key distribution path; the distribution message further includes the priority.

23. The communication device according to claim 21 or 22, characterized in that, Before the processing unit generates an encryption key based on the service secret key and the temporary key; The processing unit is further configured to determine a temporary key based on the priority of the service key transmitted by the port of the quantum node device for the key distribution path.

24. The communication device according to claim 20, wherein Before the transceiver unit receives the routing information; The transceiver unit is further configured to send key processing capabilities to the control device.

25. The communication device according to claim 24, wherein Before the transceiver unit sends key processing capabilities to the control device; The transceiver unit is further configured to receive a synchronization key processing capability request message sent by the control device; The transceiver unit is further configured to, in response to the synchronization key processing capability request message, send key processing capabilities to the control device.

26. The communication device according to claim 24, characterized in that, The transceiver unit sending key processing capabilities to the control device includes: The transceiver unit is further configured to, in response to a change in the key processing speed of its own port, send key processing capabilities to the control device.

27. A communication network, characterized in that, The communication network includes: at least one control device and at least two quantum node devices; wherein, the control device includes the communication device as claimed in claim 14; the quantum source node device among the at least two quantum node devices includes the communication device as claimed in claim 20.