A distributed system-based optical network mutual backup video data encryption method and system

By combining distributed systems and quantum channels, node trust assessments and encryption paths are dynamically adjusted, solving the problems of low encryption efficiency and poor storage reliability in optical network mutual backup video data encryption, and achieving efficient data transmission and storage in a dynamic network environment.

CN120389902BActive Publication Date: 2025-09-23BEIJING ZHAOKE HENGXING SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510700753.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-23
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Existing optical network mutual backup video data encryption methods suffer from low encryption efficiency and poor data redundancy storage reliability in environments with dynamic loads and unstable network topologies, mainly due to rigid node trust assessment and delayed encryption path adjustment.

Method used

A distributed system-based approach is adopted to generate node trust evaluation values ​​by obtaining optical network topology data and dynamic load parameters, use a distributed consensus protocol to select encryption collaboration nodes, and dynamically adjust the encryption path based on the chaotic mapping sequence. Quantum channels are used to monitor the link bit error rate in real time for key synchronization, ensuring real-time adaptation of key distribution and storage.

Benefits of technology

It improves encryption efficiency and the reliability of data redundant storage, solves the problems of decreased key distribution efficiency and insufficient redundant storage reliability caused by network fluctuations in traditional methods, and realizes efficient data transmission and storage in a dynamic network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389902B_ABST
    Figure CN120389902B_ABST
Patent Text Reader

Abstract

The present application discloses a method and system for encrypting optical network mutual backup video data based on a distributed system, which belongs to the field of data encryption. The present application generates a node trust evaluation value by obtaining optical network topology data including link state parameters and dynamic load parameters of edge nodes; and adopts a distributed consensus protocol to screen edge nodes that meet the dynamic load fluctuation range and trust evaluation value threshold as encryption collaboration nodes. Based on the node trust value, a master key splitting factor is generated, the master key is split into sub-key fragments, and the optical network mutual backup video data is divided into blocks and bound to the sub-keys for encryption to form a mutual backup encrypted data block, thereby realizing redundant storage of heterogeneous nodes across physical locations. An initial encryption path is constructed according to the link state parameters, and the transmission priority is dynamically disturbed using a chaotic mapping sequence to generate a target encryption path that adapts to the storage requirements. Finally, the encrypted data blocks are distributed to heterogeneous nodes through the path, which can improve encryption efficiency and data redundancy storage reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of data encryption, and in particular relates to a method and system for encrypting optical network mutual backup video data based on a distributed system. Background Art

[0002] With the widespread application of optical network backup technology in security surveillance, industrial IoT, and other fields, efficient encryption and reliable redundant storage of video data have become core requirements for ensuring business continuity. Optical network backup systems, through multi-path transmission and heterogeneous node collaboration, can effectively address single points of failure in the network. However, their dynamic load and complex topology characteristics place new demands on encryption methods, including real-time performance, quantum resistance, and cross-domain collaboration.

[0003] Conventional methods for encrypting video data in optical network backup are primarily based on a fixed key distribution mechanism and centralized node management. These methods encrypt video data blocks using a pre-set key, update the key through a centralized key management node, and statically divide encryption domains based on the optical network topology. The encrypted data blocks are then stored in redundant nodes.

[0004] However, existing optical network mutual backup video data encryption methods are prone to reduced key distribution efficiency and insufficient redundant storage reliability in optical network mutual backup environments with dynamic loads and unstable network topologies due to rigid node trust assessments and delayed encryption path adjustments. Therefore, existing optical network mutual backup video data encryption methods suffer from low encryption efficiency and poor data redundant storage reliability in optical network mutual backup environments with dynamic loads and unstable network topologies. Summary of the Invention

[0005] The present application provides a distributed system-based optical network mutual backup video data encryption method, system, device and computer storage medium, which can improve encryption efficiency and data redundancy storage reliability.

[0006] In a first aspect, the present application provides a method for encrypting optical network mutual backup video data based on a distributed system, the method comprising:

[0007] Obtaining optical network topology data and dynamic load parameters of edge nodes, and generating a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters;

[0008] The distributed consensus protocol determines the edge nodes that meet the mutual backup conditions as encryption collaboration nodes. The mutual backup conditions include the fluctuation range of dynamic load parameters and the node trust evaluation value meeting the preset threshold range.

[0009] A master key split factor is generated based on the node trust evaluation value of the encryption cooperation node. The master key is split into multiple sub-key fragments according to the master key split factor. The optical network mutual backup video data is divided into blocks and then bound and encrypted with the multiple sub-key fragments to form mutual backup encrypted data blocks. The mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations.

[0010] An initial encryption path is generated according to the link state parameters, and the transmission priority of the initial encryption path is dynamically perturbed based on the chaotic mapping sequence to generate a target encryption path that adapts to the mutual backup storage requirements. The mutually backup encrypted data blocks are then distributed to the corresponding heterogeneous nodes through the target encryption path.

[0011] In one possible implementation, the method further includes: obtaining a link bit error rate parameter in real time via a quantum channel during transmission of the target encrypted path;

[0012] Determine whether the link bit error rate parameter is greater than a predetermined bit rate threshold. When the link bit error rate parameter is greater than the predetermined bit rate threshold, trigger the joint decryption verification based on the encryption cooperation node to obtain the updated dynamic load parameter;

[0013] The master key splitting factor is regenerated based on the updated dynamic load parameters and optical network topology data, and the key synchronization of the mutual backup encrypted data blocks is completed through the distributed consensus protocol.

[0014] In one achievable embodiment, the master key splitting factor is regenerated based on the updated dynamic load parameter and optical network topology data, and key synchronization of the mutually encrypted data blocks is completed through a distributed consensus protocol, including:

[0015] Recalculate the target node trust evaluation value of each encryption collaboration node based on the computing resource occupancy change in the updated dynamic load parameters and the optical network topology data;

[0016] The target node trust evaluation value is superimposed and corrected with the historical master key split factor to generate the target master key split factor. The historical master key split factor is the key split factor generated last time before the joint decryption verification is triggered.

[0017] In the distributed consensus protocol, the target master key splitting factor is broadcast to all encryption collaboration nodes, and the target master key splitting factor and the historical master key splitting factor are confirmed by the majority of the encryption collaboration nodes. When more than a preset proportion of encryption collaboration nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the association constraints, the key synchronization of the mutual encryption data block is completed.

[0018] In one practicable embodiment, generating a node trust evaluation value of an edge node based on optical network topology data and dynamic load parameters includes:

[0019] Calculate the node connection weight of each edge node based on the inter-node distance and link bandwidth in the optical network topology data. The inter-node distance is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate.

[0020] Calculate the load balancing factor for each edge node based on the computing resource utilization and task queue depth in the dynamic load parameters. The task queue depth is the cumulative number of unprocessed tasks.

[0021] The node connection weight and the load balancing factor are superimposed in a preset ratio to generate a node trust evaluation value. The preset ratio is determined by the global node distribution density of the optical network topology data.

[0022] In one achievable implementation, a distributed consensus protocol is used to determine edge nodes that meet the mutual backup conditions as encryption collaboration nodes. The mutual backup conditions include the fluctuation range of dynamic load parameters and the node trust evaluation value simultaneously meeting the preset threshold range, including:

[0023] For each edge node, determine whether the fluctuation range of the dynamic load parameter is within a first preset threshold interval, and whether the node trust evaluation value is within a second preset threshold interval, where the fluctuation range is the difference between the maximum and minimum values ​​of the dynamic load parameter within a preset time window;

[0024] The edge nodes whose fluctuation range of dynamic load parameters is within a first preset threshold interval and whose node trust evaluation values ​​are within a second preset threshold interval are selected as a candidate node set;

[0025] In the distributed consensus protocol, the real-time status consistency of each candidate node in the candidate node set is confirmed through interactive voting among the edge nodes in the candidate node set, and the edge nodes with a voting pass rate exceeding a preset ratio are screened out as encryption collaborative nodes.

[0026] In one feasible implementation, a master key splitting factor is generated based on the node trust evaluation value of the encryption cooperation node, the master key is split into multiple sub-key fragments according to the master key splitting factor, and the optical network mutual backup video data is divided into blocks and then bound and encrypted with the multiple sub-key fragments to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including:

[0027] Sort the node trust evaluation values ​​of the encryption collaboration nodes by numerical value, and assign a corresponding split factor weight to each encryption collaboration node, where the split factor weight is inversely proportional to the ranking of the node trust evaluation value;

[0028] Calculate the target length of each sub-key fragment based on the split factor weight, and split the master key into multiple sub-key fragments according to the target length;

[0029] Divide the optical network mutual backup video data into data blocks equal in number to the subkey fragments, and perform bit-by-bit logical operations on each data block and the corresponding subkey fragment to generate mutual backup encrypted data blocks;

[0030] A redundant storage location is allocated to each mutually encrypted data block according to the split factor weight, wherein the redundant storage location is a physical storage node in the heterogeneous node that matches the split factor weight.

[0031] In one feasible implementation, an initial encryption path is generated based on link state parameters, a transmission priority of the initial encryption path is dynamically perturbed based on a chaotic mapping sequence, a target encryption path adapted to the mutual backup storage requirements is generated, and the mutually backup encrypted data blocks are distributed to corresponding heterogeneous nodes through the target encryption path, including:

[0032] Extracting the transmission delay and available bandwidth from the link state parameters, marking the links with a transmission delay less than a preset delay threshold and an available bandwidth greater than a preset bandwidth threshold as candidate transmission links;

[0033] Generate an initial encrypted path based on the physical locations of the nodes at both ends of the candidate transmission link. The initial encrypted path is composed of at least two non-overlapping candidate transmission links connected in series.

[0034] A dynamic perturbation factor is generated based on a chaotic mapping sequence, and the transmission priority of each candidate transmission link in the initial encryption path is periodically rearranged according to the dynamic perturbation factor to generate a target encryption path;

[0035] According to the real-time transmission load rate of the target encryption path, the mutually encrypted data blocks are distributed to the corresponding heterogeneous nodes in sequence, where the real-time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encryption path.

[0036] In a second aspect, the present application provides an optical network mutual backup video data encryption system based on a distributed system, the system comprising:

[0037] An acquisition module is used to acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters;

[0038] A determination module is used to determine, through a distributed consensus protocol, edge nodes that meet mutual backup conditions as encryption collaboration nodes. The mutual backup conditions include the fluctuation range of dynamic load parameters and the node trust evaluation value simultaneously meeting a preset threshold range.

[0039] A generation module is configured to generate a master key splitting factor based on a node trust evaluation value of an encryption cooperation node, split the master key into multiple sub-key fragments according to the master key splitting factor, and bind and encrypt the optical network mutual backup video data into blocks and the multiple sub-key fragments respectively to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations;

[0040] The distribution module is used to generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path that adapts to the mutual backup storage requirements, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.

[0041] In a third aspect, the present application provides an electronic device comprising: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement a distributed system-based optical network mutual backup video data encryption method as in any one of the embodiments of the first aspect.

[0042] In a fourth aspect, the present application provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, a distributed system-based optical network mutual backup video data encryption method as in any one of the embodiments of the first aspect is implemented.

[0043] The embodiment of the present application first generates a dynamic trust evaluation value based on real-time network topology and load parameters, overcoming the rigidity of the traditional fixed evaluation mechanism and ensuring that node selection adapts to network fluctuations; secondly, through a distributed consensus mechanism, it screens encryption collaboration nodes that meet the mutual backup conditions, combines master key segmentation with data block binding encryption, and realizes dynamic optimization of key distribution while ensuring anti-quantum cracking capabilities; further, through the dynamic perturbation of chaotic mapping, it generates a target encryption path that adapts to storage requirements, solves the lag problem of traditional static path adjustment, and combines with the redundant storage mechanism to significantly improve data transmission reliability, and finally achieves a coordinated improvement of encryption efficiency and storage reliability in a dynamic network environment, effectively solving the technical problems of reduced key distribution efficiency and insufficient redundant storage reliability in the existing technology.

[0044] Furthermore, by monitoring the link bit error rate in real time through the quantum channel and triggering joint decryption verification and key synchronization among encryption collaboration nodes when the bit error rate exceeds a threshold, the system addresses the risk of key leakage and data redundancy backup failure caused by sudden changes in channel quality in dynamic network environments. By dynamically updating load parameters and master key splitting factors, key distribution and node status are adapted in real time. Combined with a distributed consensus synchronization mechanism, this effectively improves the timeliness of key updates and the fault tolerance of redundant storage, ensuring encryption efficiency and data redundancy storage reliability in optical network backup environments with dynamic loads and unstable network topologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0046] Figure 1 This is a flow chart of a method for encrypting video data in an optical network based on a distributed system provided by an embodiment of the present application;

[0047] Figure 2 1 is a flow chart of a key synchronization method for mutually encrypted data blocks provided by an embodiment of the present application;

[0048] Figure 3 This is a flowchart of a method for generating a target encryption path provided by an embodiment of the present application;

[0049] Figure 4 This is a structural diagram of a distributed optical network mutual backup video data encryption system provided by an embodiment of the present application;

[0050] Figure 5 This is a schematic diagram of the hardware structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0051] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0052] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0053] Existing optical network video data encryption methods, in environments with dynamic loads and unstable network topologies, are prone to reduced key distribution efficiency and insufficient redundant storage reliability due to issues such as rigid node trust assessment and delayed encryption path adjustment. Therefore, existing optical network video data encryption methods suffer from low encryption efficiency and poor data redundant storage reliability in environments with dynamic loads and unstable network topologies.

[0054] In order to solve the problems of the prior art, the embodiments of the present application provide a method, system, device and computer storage medium for encrypting video data in an optical network based on a distributed system. The following first introduces the method for encrypting video data in an optical network based on a distributed system provided by the embodiments of the present application.

[0055] Figure 1 FIG. 1 shows a flow chart of a method for encrypting optical network video data based on a distributed system according to an embodiment of the present application. Figure 1 As shown, steps S110 to S140 are included.

[0056] S110: Acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters.

[0057] Optical network topology data refers to a set of structured parameters that describe the physical connection relationships and link status of each node in the optical network. These parameters include link status parameters such as the physical link length between nodes, available link transmission rate, transmission delay, and bit error rate. Dynamic load parameters refer to load fluctuation indicators generated by edge nodes during real-time operation. These include dynamic parameters such as computing resource utilization, task queue depth, and network throughput that reflect the node's current processing capacity. Node trust evaluation is a quantitative indicator calculated based on the comprehensive calculation of node connection stability and load balancing. It is used to characterize the trustworthiness and reliability of nodes in the encryption collaboration process.

[0058] First, the optical network management protocol periodically collects physical connection information and link status parameters from each edge node to construct a global optical network topology map. Simultaneously, resource monitoring agents deployed at edge nodes collect dynamic load parameters in real time, including CPU utilization, memory usage, and the number of pending tasks. Subsequently, a connection weight is calculated for each node based on the inter-node distance and link bandwidth in the optical network topology data. The shorter the inter-node distance and the higher the link bandwidth, the greater the connection weight. Furthermore, a load balancing factor is calculated based on the computing resource utilization and task queue depth in the dynamic load parameters. The lower the resource utilization and the smaller the task queue depth, the higher the load balancing factor. Finally, the connection weight and the load balancing factor are superimposed based on a preset ratio dynamically adjusted according to the global node density to generate a node trust evaluation value. For example, the load balancing factor is prioritized in densely populated areas, while the connection weight contribution is prioritized in sparsely populated areas, ensuring the evaluation value is scenario-appropriate.

[0059] For example, the optical network controller obtains topological data containing 10 edge nodes, including the physical link length, bandwidth and transmission delay between each node. At the same time, the monitoring agent reports that the CPU occupancy of each node is 30% to 80%, and the task queue depth is 5 to 20. For node A, the average link length between it and the adjacent node is 100 meters, the available bandwidth is 10Gbps, and the calculated connection weight is 0.8. The CPU occupancy of node A is 40%, the task queue depth is 8, and the load balancing factor is 0.7. If the global node distribution density is low, the preset ratio is 60% for the connection weight and 40% for the load balancing factor, then the node trust evaluation value is 0.8×0.6+0.7×0.4=0.76.

[0060] S120: Determine, through a distributed consensus protocol, edge nodes that meet the mutual backup conditions as encryption collaboration nodes. The mutual backup conditions include that the fluctuation range of dynamic load parameters and the node trust evaluation value both meet the preset threshold range.

[0061] A distributed consensus protocol refers to a collaborative decision-making mechanism that achieves state consistency through interactive communication and rule verification among multiple nodes in a network environment without a central control node. Mutual backup conditions refer to the dual constraints of dynamic load stability and trustworthiness that edge nodes must meet to participate in collaborative cryptographic tasks. These constraints include limiting the fluctuation range of dynamic load parameters within a preset time window and ensuring the lower limit of the trustworthiness of node trust assessment values.

[0062] First, the fluctuation range of the dynamic load parameters of each edge node is calculated. Specifically, by counting the difference between the maximum and minimum values ​​of the load parameters within the preset time window, it is determined whether the difference is within the first preset threshold range. For example, if the load parameter is CPU occupancy, the fluctuation range is the difference between the highest occupancy and the lowest occupancy in the past 5 minutes. At the same time, verify whether the trust evaluation value of the node meets the minimum credibility requirement of the second preset threshold range. The edge nodes that meet both conditions are selected to form a candidate node set. Subsequently, a distributed consensus protocol is implemented in the candidate node set. Each candidate node broadcasts its own real-time status information to other nodes, and the receiving node cross-checks the broadcast information according to the preset verification rules. After the verification is passed, each node votes on the availability of the candidate node and counts the voting pass rate of each candidate node. If the pass rate of a node exceeds the preset ratio, it will be included in the encryption collaborative node set.

[0063] S130: Generate a master key splitting factor based on the node trust evaluation value of the encryption collaboration node, split the master key into multiple sub-key fragments according to the master key splitting factor, and divide the optical network mutual backup video data into blocks and bind and encrypt them with the multiple sub-key fragments respectively to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations.

[0064] The master key splitting factor is a weight coefficient generated based on the trust evaluation value of the encryption collaboration node, and is used to determine the length distribution ratio of each sub-key fragment when the master key is split. The sub-key fragment is the encrypted fragment divided by the splitting factor weight, and each fragment is bound to a specific data block. Binding encryption refers to the process of performing logical operations on sub-key fragments and video data blocks to generate encrypted data blocks. Mutually redundant encrypted data blocks are encryption units with redundant storage properties after binding encryption processing, and need to be stored in heterogeneous nodes with different physical locations, such as storage servers in different computer rooms and geographical regions. Heterogeneous nodes refer to storage nodes with different physical locations and hardware configurations, which are used to achieve cross-domain redundant storage of data blocks.

[0065] First, the encryption collaboration nodes are sorted in descending order by their node trust evaluation value. Nodes with higher rankings are assigned larger splitting factor weights. For example, the top 20% of nodes with the highest trust evaluation value are assigned a weight of 0.3, the middle 60% are assigned a weight of 0.5, and the bottom 20% are assigned a weight of 0.2. The sum of these weights is normalized to 1. Next, the target length of each subkey fragment is calculated based on the splitting factor weights. Assuming the master key length is 1024 bits, with weights of 0.3, 0.5, and 0.2, the subkey fragment lengths are 307 bits, 512 bits, and 205 bits, respectively. The key fragmentation algorithm is used to split the fragments by length. Next, the video data is divided into blocks based on the number of subkey fragments, with each block size matching the corresponding subkey fragment. Data blocks are bound to subkey fragments using a bitwise XOR operation to generate encrypted data blocks. For example, data block D1 is XORed with subkey K1 to generate encrypted block E1. Finally, storage locations are allocated based on the splitting factor weights. Data blocks corresponding to subkeys with higher weights are stored on nodes with higher reliability, such as nodes with dual power supplies and multiple links. For example, the encrypted block corresponding to the fragment with weight 0.3 is stored in node A, the one with weight 0.5 is stored in node B, and the one with weight 0.2 is stored in node C.

[0066] S140: Generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path that adapts to the mutual backup storage requirements, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.

[0067] Link state parameters (LSPs) are a set of metrics that characterize the real-time performance of communication links in optical networks. These metrics include key parameters such as transmission delay, available bandwidth, and packet loss rate. Chaotic map sequences are pseudo-random number sequences generated by chaotic systems. These sequences exhibit initial value sensitivity and ergodic properties, and are used to dynamically perturb transmission priorities. Dynamic perturbations involve periodically adjusting the priority ranking of links within a path through an algorithm to address fluctuations in the network environment.

[0068] First, transmission delay and available bandwidth data are extracted from link status parameters to screen out candidate transmission links with delays below a preset threshold and bandwidths above the minimum requirement. For example, if the preset delay threshold is 50 milliseconds and the bandwidth threshold is 5 Gbps, the links that meet the conditions are marked as a candidate set. Then, an initial encrypted path is constructed based on the physical location of the candidate links, ensuring that the path consists of at least two non-overlapping links in series to avoid the risk of single points of failure. For example, a path from node A to node B and then to node C is selected, and this path is used as a backup for the path from node A to node D and then to node C.

[0069] Next, a dynamic perturbation factor sequence is generated based on the Logistic Chaotic Map, with each perturbation factor corresponding to a priority adjustment coefficient. The perturbation factor is applied to the priority values ​​of each link in the initial path according to a preset period, and the link priorities are reordered through weighted calculation. For example, if the initial priority of a link is 0.8 and the perturbation factor is -0.1, the updated priority is 0.72. This process is continuously iterated to form a dynamically changing target encryption path. Finally, based on the real-time transmission load rate of the target encryption path, the mutually encrypted data blocks are distributed in descending order of priority. For example, when the load rate of path 1 is 70% and that of path 2 is 40%, path 2 is preferentially selected to transmit new data blocks to ensure load balancing.

[0070] This embodiment overcomes the rigidity of the traditional fixed evaluation mechanism by first generating a dynamic trust evaluation value based on real-time network topology and load parameters, ensuring that node selection adapts to network fluctuations; secondly, it screens encryption collaboration nodes that meet the mutual backup conditions through a distributed consensus mechanism, and combines master key splitting with data block binding encryption to achieve dynamic optimization of key distribution while ensuring anti-quantum cracking capabilities; further, it generates a target encryption path that adapts to storage requirements through dynamic perturbation of chaotic mapping, solving the lag problem of traditional static path adjustment, and significantly improves data transmission reliability in combination with a redundant storage mechanism, ultimately achieving a coordinated improvement in encryption efficiency and storage reliability in a dynamic network environment, effectively solving the technical problems of reduced key distribution efficiency and insufficient redundant storage reliability in the existing technology.

[0071] Since existing technologies cannot respond to link quality fluctuations and node load changes in real time in a dynamic network environment, this application uses quantum channels to monitor the link bit error rate and trigger a dynamic key update mechanism to solve the problems of encryption path failure and key synchronization delay caused by network status perception lag, thereby improving the system's real-time anti-interference capability and data storage reliability.

[0072] In one feasible embodiment, the method further includes: obtaining link bit error rate parameters in real time through a quantum channel during transmission of the target encrypted path.

[0073] A quantum channel is a communication channel based on the principles of quantum mechanics. It utilizes quantum states to transmit information, making it both eavesdropper-proof and interference-resistant. The link bit error rate (BER) parameter measures the proportion of bit errors during data transmission and reflects the quality of the link. Obtaining the BER parameter through a quantum channel ensures the security of parameter transmission, preventing tampering or theft.

[0074] During data transmission along the target encrypted path, a quantum channel is established using quantum key distribution techniques, such as the BB84 protocol. The transmitter embeds a checksum in each transmission cycle, and the receiver compares the checksum through quantum measurement to calculate the link's bit error rate (BER). In practice, the transmitter encodes the checksum into quantum states, such as photon polarization states. The receiver measures and counts the number of bit errors to calculate the BER. For example, if 1000 qubits are transmitted and the receiver detects 10 errors, the BER is 1%. The real-time BER parameters are transmitted back to the control node via the quantum channel to ensure data integrity.

[0075] Determine whether the link bit error rate parameter is greater than a predetermined bit rate threshold. When the link bit error rate parameter is greater than the predetermined bit rate threshold, trigger the joint decryption verification based on the encryption cooperation node to obtain the updated dynamic load parameter.

[0076] The predetermined bitrate threshold is an upper limit on the bit error rate (BER) set based on service reliability requirements. For example, the maximum permissible BER for video transmission is 0.1%. Joint decryption verification involves multiple encryption collaboration nodes participating in the decryption process, verifying the integrity of encrypted data through distributed collaboration. The updated dynamic load parameter is the real-time load metric re-collected by the encryption collaboration nodes during the verification process.

[0077] The control node compares the real-time bit error rate with a predetermined bit rate threshold. If the bit error rate exceeds the threshold, a verification instruction is sent to the encryption collaboration node. The encryption collaboration node initiates joint decryption verification based on a distributed consensus protocol. Each node retrieves the corresponding mutually encrypted data block from redundant storage locations, decrypts a portion of the data block using a local subkey fragment, and verifies the correctness of the decryption result through a majority voting mechanism. For example, three nodes each decrypt a data block fragment. If the decryption results of two nodes are consistent, the data is deemed complete. During the verification process, each node synchronously reports dynamic load parameters such as current computing resource utilization and task queue depth to form an updated dynamic load dataset.

[0078] The master key splitting factor is regenerated based on the updated dynamic load parameters and optical network topology data, and the key synchronization of the mutual backup encrypted data blocks is completed through the distributed consensus protocol.

[0079] Key synchronization refers to ensuring through a distributed protocol that the sub-key fragments held by all encryption collaboration nodes are consistent with the updated master key splitting factors.

[0080] Based on the updated dynamic load parameters and combined with the optical network topology data, the node trust evaluation value of each encryption collaboration node is recalculated. In the distributed consensus protocol, the newly generated master key split factor is broadcast to all encryption collaboration nodes, and each node verifies its association with the historical split factor, such as whether it meets the threshold constraint. If more than a preset proportion of nodes confirm that the new split factor is legal, the master key is re-split using a secret sharing algorithm, and the new sub-key fragments are distributed to the corresponding nodes, completing key synchronization. For example, using the Shamir threshold scheme, any two of the three nodes can collaboratively recover the master key.

[0081] Figure 2 FIG2 shows a flow chart of a key synchronization method for mutually encrypted data blocks provided by an embodiment of the present application. Figure 2 As shown, steps S210 to S230 are included.

[0082] In one achievable embodiment, the master key splitting factor is regenerated based on the updated dynamic load parameter and optical network topology data, and key synchronization of the mutually encrypted data blocks is completed through a distributed consensus protocol, including:

[0083] S210: Recalculate the target node trust evaluation value of each encryption cooperation node based on the computing resource occupancy change in the updated dynamic load parameter and the optical network topology data.

[0084] The real-time computing resource utilization of the encryption collaboration nodes during the joint decryption verification process is obtained. For example, if the CPU utilization increases from 40% to 55%, the change relative to the historical value is calculated. The node connection weights in the optical network topology data and the updated load balancing factor are combined according to a preset ratio to generate a new trust evaluation value. For example, if the load balancing factor of node A decreases due to the increase in CPU utilization, its trust evaluation value will drop from 0.7 to 0.65.

[0085] S220: The target node trust evaluation value is superimposed and corrected with the historical master key splitting factor to generate a target master key splitting factor. The historical master key splitting factor is the key splitting factor generated last time before the joint decryption verification is triggered.

[0086] The historical master key split factor is the key split weight coefficient generated last time before triggering joint decryption verification. Using a weighted average method, the target node's trust assessment value and the historical split factor are dynamically superimposed. For example, if node A's historical split factor weight is 0.5 and the corresponding weight of the new trust assessment value is 0.4, and the superposition ratio is 60% for the new weight and 40% for the historical weight, the revised target split factor weight is 0.4 × 0.6 + 0.5 × 0.4 = 0.44. This process ensures a smooth transition of the key split factor and avoids key distribution fluctuations caused by sudden load changes.

[0087] S230: In the distributed consensus protocol, the target master key splitting factor is broadcast to all encryption collaboration nodes, and the target master key splitting factor and the historical master key splitting factor are confirmed by the majority of the encryption collaboration nodes. When more than a preset proportion of encryption collaboration nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the association constraint, the key synchronization of the mutual backup encrypted data block is completed.

[0088] Association constraints limit the logical relationship between the old and new split factors, such as ensuring that the weight change does not exceed a preset threshold or that the sum of the split factors remains normalized. The control node broadcasts the target split factor to all encryption collaboration nodes, and each node verifies the association between the old and new split factors. For example, node A checks whether the change in the target split factor weight is within ±20% and whether the sum is normalized to 1. If verification passes, the node sends a confirmation signal; if more than two-thirds of the nodes confirm, key synchronization is triggered. During synchronization, the master key is re-split using the Shamir threshold algorithm, and the new subkey fragments are distributed to the corresponding storage nodes via redundant paths.

[0089] For example, assume that the historical split factor weights of encryption collaboration nodes N1, N2, and N3 in an optical network mutual backup system are 0.5, 0.3, and 0.2, respectively. After a joint decryption verification is triggered due to an excessive link bit error rate, node N1's CPU utilization increases from 40% to 55%, and its trust evaluation value decreases from 0.7 to 0.65. When recalculating the target split factor, N1's new weight is adjusted to 0.44 according to the superposition correction rule, N2 remains at 0.3, and N3 is adjusted to 0.26. In the distributed consensus protocol, node N1 broadcasts the target split factor weight of 0.44. N2 and N3 verify that the change is within the allowable range and that the sum is 1. After confirmation, a threshold algorithm is used to split the master key into new subkey fragments with lengths corresponding to weights of 0.44, 0.3, and 0.26. The new subkeys are distributed to the remote disaster recovery node, local cluster, and edge nodes via the target encryption path, completing key synchronization.

[0090] This embodiment monitors the link bit error rate (BER) in real time through a quantum channel and triggers joint decryption verification and key synchronization among encryption collaboration nodes when the BER exceeds a threshold. This addresses the risks of key leakage and data redundancy backup failure caused by sudden changes in channel quality in dynamic network environments. Dynamic updates of load parameters and master key split factors ensure real-time adaptation of key distribution to node status. Combined with a distributed consensus synchronization mechanism, this effectively improves the timeliness of key updates and the fault tolerance of redundant storage, ensuring encryption efficiency and data redundancy storage reliability in optical network backup environments with dynamic loads and unstable network topologies.

[0091] In one feasible implementation, generating a node trust evaluation value of an edge node based on the optical network topology data and the dynamic load parameter in step S110 includes:

[0092] The node connection weight of each edge node is calculated based on the inter-node distance and link bandwidth in the optical network topology data. The inter-node distance is the physical link length between adjacent nodes, and the link bandwidth is the available transmission rate.

[0093] First, the physical link lengths between the target edge node and all its neighboring nodes are extracted from the optical network topology data to calculate the average inter-node distance. For example, if the link lengths between node A and its neighboring nodes B and C are 100 meters and 200 meters, respectively, the average distance is 150 meters. Simultaneously, the available bandwidth data for node A and its neighboring links is obtained, such as bandwidths of 10 Gbps and 8 Gbps, respectively. The inter-node distances are then normalized using an inverse proportional function, with shorter distances receiving higher scores. For example, the normalization formula is: distance score = 1 / (average distance + 1). Simultaneously, the link bandwidth is linearly normalized, with higher scores receiving higher bandwidths. For example, bandwidth score = bandwidth value / maximum bandwidth threshold. Finally, the distance score and bandwidth score are weighted and summed according to preset weights (e.g., distance accounts for 40% and bandwidth accounts for 60%) to generate the node connection weight. For example, if node A has a distance score of 0.6 and a bandwidth score of 0.9, the connection weight is 0.6 × 0.4 + 0.9 × 0.6 = 0.78. The load balancing factor of each edge node is calculated based on the computing resource occupancy and task queue depth in the dynamic load parameters. The task queue depth is the cumulative number of unprocessed tasks.

[0094] First, the CPU and memory usage of edge nodes are collected in real time, and their average is calculated as the computing resource usage. For example, if the CPU usage is 50% and the memory usage is 40%, the average usage is 45%.

[0095] At the same time, monitor the depth of the node's task queue and count the number of unprocessed tasks. For example, there are 12 pending tasks in the current queue. Subsequently, the computing resource occupancy rate is reverse normalized, and the lower the occupancy rate, the higher the score. For example, occupancy score = 1-(occupancy rate / 100). The task queue depth is scored using an exponential decay function, and the smaller the queue depth, the higher the score. For example, depth score = 1 / (1+queue depth×0.1). Finally, the occupancy score and the depth score are superimposed according to a preset ratio (such as occupancy rate accounts for 70% and depth accounts for 30%) to generate a load balancing factor. For example, if the occupancy score is 0.55 and the depth score is 0.7, the load balancing factor is 0.55×0.7+0.7×0.3=0.595.

[0096] The node connection weight and the load balancing factor are superimposed in a preset ratio to generate a node trust evaluation value. The preset ratio is determined by the global node distribution density of the optical network topology data.

[0097] First, the global distribution density of nodes in the optical network is counted, and the average number of nodes per unit area is calculated. For example, if there are 50 nodes within 10 square kilometers, the density is 5 nodes / square kilometer. The preset ratio is dynamically adjusted according to the density value: if the density is higher than the threshold, the weight of the load balancing factor is increased (such as 60%); if the density is lower than the threshold, the weight of the connection weight is increased (such as 60%). Finally, the node connection weight and the load balancing factor are weighted and summed according to the adjusted ratio to generate the node trust evaluation value. For example, the connection weight of node A is 0.78, the load balancing factor is 0.595, and the preset ratio is 40% connection weight and 60% load balancing factor. The trust evaluation value is 0.78×0.4+0.595×0.6=0.669.

[0098] In one possible implementation, step S120: determining, through a distributed consensus protocol, an edge node that meets the mutual backup condition as an encryption collaboration node, the mutual backup condition including the fluctuation range of the dynamic load parameter and the node trust evaluation value simultaneously meeting a preset threshold range, including:

[0099] For each edge node, determine whether the fluctuation range of the dynamic load parameter is within the first preset threshold interval and whether the node trust evaluation value is within the second preset threshold interval, where the fluctuation range is the difference between the maximum and minimum values ​​of the dynamic load parameter within the preset time window.

[0100] The dynamic load parameter fluctuation range refers to the difference between the maximum and minimum values ​​of the dynamic load parameter of the edge node within a preset time window, which is used to quantify the stability of the node load. For example, the difference between the highest and lowest CPU usage within 5 minutes. The first preset threshold interval refers to the pre-set allowable range of load fluctuation. Exceeding this range indicates that the node load fluctuation is too large and is not suitable for participating in encryption collaboration tasks. The second preset threshold interval refers to the pre-defined valid range of node trust assessment values. Nodes below the lower limit are considered untrustworthy, and nodes above the upper limit may be overloaded.

[0101] First, for each edge node, a dynamic load parameter sequence within a preset time window is collected, such as continuously collecting CPU occupancy data at 10 time points. The maximum and minimum values ​​are calculated using a sliding window algorithm to obtain the fluctuation range. For example, if the maximum occupancy in the window is 80% and the minimum is 30%, the fluctuation range is 50%. At the same time, the node trust evaluation value generated in step S110 is obtained. The fluctuation range is compared with the first preset threshold interval, which can allow fluctuations of no more than 40%. The node trust evaluation value is compared with the second preset threshold interval, which can be 0.6 to 0.9. If the fluctuation range is within the first threshold interval and the trust evaluation value is within the second threshold interval, the node passes the preliminary screening.

[0102] The edge nodes that meet the requirements of the fluctuation range of the dynamic load parameter being within the first preset threshold interval and the node trust evaluation value being within the second preset threshold interval are selected as the candidate node set.

[0103] After traversing the screening results of all edge nodes, nodes that meet both the fluctuation range and the trust evaluation threshold are added to the candidate node set. For example, if there are 20 edge nodes, and 15 of them have a fluctuation range of less than 40% and a trust evaluation value between 0.6 and 0.9, these 15 nodes constitute the candidate set. The candidate node set will serve as the participants in the subsequent distributed consensus protocol.

[0104] In the distributed consensus protocol, the real-time status consistency of each candidate node in the candidate node set is confirmed through interactive voting among the edge nodes in the candidate node set, and the edge nodes with a voting pass rate exceeding a preset ratio are screened out as encryption collaborative nodes.

[0105] Real-time state consistency refers to the consistency between the candidate node's actual load and reported data at the current moment, ensuring the authenticity of the node's state. Interactive voting is a collaborative decision-making mechanism in which candidate nodes reach consensus on each other's states through multiple rounds of information exchange and verification.

[0106] First, status information is broadcast. Each candidate node broadcasts its real-time load data and trustworthiness assessment to other nodes in the set, including current CPU utilization and task queue depth. Cross-validation then occurs, with the receiving nodes verifying the broadcasted data, for example by verifying its timeliness through timestamps or analyzing historical data trends for unusual fluctuations. Each node then votes on the other nodes based on the verification results. If the data is authentic and meets the threshold, it votes yes; otherwise, it votes no. Finally, the results are tallied, calculating the percentage of yes votes for each node. If it exceeds a preset percentage, such as 70%, the node is added to the set of encrypted collaborative nodes.

[0107] In the optical network, the dynamic load parameter fluctuation ranges of nodes X, Y, and Z are 35%, 45%, and 25%, respectively, and the node trust values ​​are 0.75, 0.65, and 0.85, respectively. The first threshold interval is preset as a fluctuation range ≤ 40%, and the second threshold interval is a trust value ≥ 0.6. In the preliminary screening, nodes X (fluctuation 35%, trust value 0.75) and Z (fluctuation 25%, trust value 0.85) meet the requirements. Node Y (fluctuation 45%) is excluded because it exceeds the load threshold, resulting in the candidate node set {X, Z}. In the interactive voting phase, node X broadcasts a real-time CPU utilization of 50% and a task queue depth of 10, while node Z broadcasts a CPU utilization of 40% and a task queue depth of 5. Node X verifies node Z's data (historical CPU utilization is usually below 45%, indicating that the current data is reasonable) and votes in favor. Node Z verifies node X's data (the task queue depth has increased by 8 compared to the previous period, but the fluctuation is within the allowable range) and votes in favor. Ultimately, nodes X and Z both receive 100% of the votes in favor and are included in the encrypted collaborative node set.

[0108] For example, the dynamic load parameter fluctuation ranges for nodes X, Y, and Z in an optical network are 35%, 45%, and 25%, respectively, and their trust assessment values ​​are 0.75, 0.65, and 0.85, respectively. According to pre-set rules, nodes must have a dynamic load less than or equal to 40% and a trust value greater than or equal to 0.6 to be eligible for screening. Node X passes because it meets both the 35% fluctuation and the 0.75 trust value. Node Y is eliminated because its 45% fluctuation exceeds the threshold. Node Z is selected because it meets both the 25% fluctuation and the 0.85 trust value, forming the candidate set {X, Z}. During the interactive voting phase, node X reports a CPU utilization of 50% and a task queue depth of 10 in real time, while node Z reports a CPU utilization of 40% and a task queue depth of 5. Based on historical data analysis, node X determines that node Z's CPU utilization is consistent with its regular trend of less than 45%, and the data is reasonably reliable. Node Z confirms that the task queue depth of node X has only increased by 8 compared to the previous period, which is within the acceptable range of load fluctuation. In the end, both parties voted in favor of each other, and nodes X and Z were both included in the encryption collaborative node set with 100% support.

[0109] In one feasible embodiment, step S130: generating a master key splitting factor based on the node trust evaluation value of the encryption cooperation node, splitting the master key into multiple sub-key fragments according to the master key splitting factor, and dividing the optical network mutual backup video data into blocks and binding and encrypting them with the multiple sub-key fragments respectively to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including:

[0110] The node trust evaluation values ​​of the encrypted collaborative nodes are sorted by numerical value, and a corresponding split factor weight is assigned to each encrypted collaborative node, where the split factor weight is inversely proportional to the ranking of the node trust evaluation value.

[0111] The splitting factor weight is a weight coefficient assigned based on the node trust evaluation value ranking results, which is used to quantify the node's contribution to the key splitting process. The ranking rank refers to the order of the node trust evaluation values ​​from high to low, and the higher the rank, the higher the node's trustworthiness. First, the trust evaluation values ​​of the encryption collaboration nodes are sorted in descending order, for example, nodes N1 (0.9), N2 (0.8), and N3 (0.7). A reverse weight distribution strategy is used based on the ranking rank, for example, assigning a weight of 0.2 to the first rank, 0.3 to the second rank, and 0.5 to the third rank, ensuring that nodes with lower rankings receive higher weights. The sum of the weights needs to be normalized to 1, for example, by adjusting the weight distribution through linear interpolation. The resulting splitting factor weight will be used for subsequent key splitting and storage allocation.

[0112] The target length of each sub-key fragment is calculated based on the splitting factor weight, and the master key is split into multiple sub-key fragments according to the target length.

[0113] Assuming the master key length is 1024 bits and the splitting factor weights are 0.2, 0.3, and 0.5, the target lengths are 205 bits, 307 bits, and 512 bits, respectively. The Shamir secret sharing algorithm or threshold splitting technique is used to split the master key into subkey fragments according to the target lengths. The splitting process must ensure that the master key cannot be recovered if the number of fragments in any subset does not reach a preset threshold, such as using a 2-out-of-3 threshold mechanism.

[0114] The optical network mutual backup video data is divided into data blocks with the same number as the subkey fragments, and each data block is subjected to a bit-by-bit logical operation with the corresponding subkey fragment to generate a mutual backup encrypted data block.

[0115] Bit-by-bit logical operations involve performing an exclusive-or (XOR), permutation, or modular addition on each bit of the data block and the subkey to generate an encrypted data block. The video data is divided into blocks corresponding to the number of subkey fragments (for example, three subkeys correspond to three data blocks). Bit-by-bit encryption is performed using an exclusive-or (XOR) operation: data block D1 is XORed with subkey K1 to generate E1, D2 with K2 to generate E2, and so on. The encrypted data block must be irreversible, meaning that the original data or subkey cannot be derived from the encrypted block.

[0116] A redundant storage location is allocated to each mutually encrypted data block according to the split factor weight, wherein the redundant storage location is a physical storage node in the heterogeneous node that matches the split factor weight.

[0117] Redundant storage locations are pre-configured heterogeneous storage nodes whose reliability levels are positively correlated with the partitioning factor weights. Encrypted data blocks corresponding to higher-weighted subkeys are stored on more reliable nodes, such as those with multi-link backup or geographically dispersed nodes. Data blocks corresponding to the highest-weighted subkeys are assigned to the most reliable nodes, sorted by partitioning factor weights. For example, a subkey with a weight of 0.5 is stored in a remote active-active data center, a subkey with a weight of 0.3 is stored in a local high-availability cluster, and a subkey with a weight of 0.2 is stored on an edge node. A storage location mapping table is maintained by the distributed configuration management module to ensure that data blocks are matched to nodes.

[0118] For example, assume that the optical network mutual backup system includes three encryption collaboration nodes N1, N2, and N3, and their node trust evaluation values ​​are 0.9, 0.8, and 0.7, respectively. The split factor weights are assigned in reverse order, with N3 weight 0.5, N2 weight 0.3, and N1 weight 0.2. The master key length is 1024 bits, which is split into three sub-key fragments with lengths of 512 bits, 307 bits, and 205 bits, respectively. The video data is divided into three data blocks D1, D2, and D3, which are XOR-encrypted with sub-keys K3, K2, and K1, respectively, to generate encryption blocks E1, E2, and E3. The storage location is allocated according to the weight: E1 (weight 0.5) is stored in an off-site disaster recovery node, E2 (weight 0.3) is stored in a local high-availability cluster, and E3 (weight 0.2) is stored in an edge node. This design ensures that high-weight encryption blocks are stored in more reliable nodes, improves the reliability of the overall redundant storage, and adapts to the key distribution requirements in a dynamic network environment.

[0119] Figure 3 FIG. 1 shows a flow chart of a method for generating a target encryption path provided by an embodiment of the present application. Figure 3 As shown, it includes steps S310 to S340.

[0120] In one feasible embodiment, step S140: generating an initial encryption path based on link state parameters, dynamically perturbing the transmission priority of the initial encryption path based on a chaotic mapping sequence, generating a target encryption path adapted to the mutual backup storage requirements, and distributing the mutual backup encrypted data blocks to corresponding heterogeneous nodes through the target encryption path, includes:

[0121] S310: Extracting transmission delay and available bandwidth from link state parameters, and marking links with transmission delay less than a preset delay threshold and available bandwidth greater than a preset bandwidth threshold as candidate transmission links.

[0122] First, the transmission delay threshold and bandwidth threshold are set. The delay threshold is determined based on business continuity requirements, such as the maximum tolerable delay for video data transmission; the bandwidth threshold is calculated based on the data block size and transmission period. The real-time transmission delay and available bandwidth parameters of each link are extracted from the optical network topology data. Each link is then determined to determine whether the delay is less than the threshold and the bandwidth is greater than the threshold. Links that meet the requirements are marked as candidate transmission links, and the information of the nodes at both ends is recorded. For example, if the delay of link L1 is 30 milliseconds and the bandwidth is 8 Gbps, and the preset delay threshold is 50 milliseconds and the bandwidth threshold is 5 Gbps, then L1 is marked as a candidate link.

[0123] S320: Generate an initial encrypted path according to the physical locations of the nodes at both ends of the candidate transmission link. The initial encrypted path is formed by serially connecting at least two non-overlapping candidate transmission links.

[0124] Based on the physical locations of the nodes at both ends of the candidate transmission links, a graph theory shortest path algorithm, such as the Dijkstra algorithm, or a redundant path generation algorithm, is used to construct multiple transmission paths from the source node to the destination node. Each path must meet the following conditions: the path length does not exceed the maximum hop limit; and there are no shared links or nodes between paths. For example, there are two candidate paths from source node S to destination node T: path P1 consists of links L1-L2-L3, and path P2 consists of links L4-L5-L6, with no overlapping links. The initial encrypted path set is {P1, P2}.

[0125] S330: Generate a dynamic perturbation factor based on the chaotic mapping sequence, periodically rearrange the transmission priority of each candidate transmission link in the initial encryption path according to the dynamic perturbation factor, and generate a target encryption path.

[0126] A dynamic perturbation factor sequence is generated using a logistic chaos mapping model. Its iterative formula is: x_{n+1} = μ*x_n(1-x_n), where μ is the control parameter and x_n∈(0,1). The perturbation factor sequence is generated by setting the initial value x_0 and the control parameter μ. Within each perturbation cycle, the current perturbation factor is multiplied by the initial priority of the link (calculated based on latency and bandwidth) to obtain the updated priority. For example, if the perturbation factor of a link with an initial priority of 0.8 is 0.9, the updated priority is 0.72. The priorities of all links are sorted to generate the target encrypted path.

[0127] S340: Distribute the mutually encrypted data blocks to the corresponding heterogeneous nodes in sequence according to the real-time transmission load rate of the target encryption path, where the real-time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encryption path.

[0128] Monitor the occupied bandwidth of each link in the target encryption path in real time and calculate the real-time load ratio of each path. Paths are sorted in descending order of priority, with paths with higher priorities and lower load ratios being prioritized for transmitting mutually encrypted data blocks. For example, if path P1 has a priority of 0.8 and a load ratio of 60%, and path P2 has a priority of 0.7 and a load ratio of 40%, P2 will be prioritized for data block transmission. If the path load ratio exceeds a preset threshold, perhaps 80%, the path is suspended and path reconstruction is triggered.

[0129] Exemplarily, the optical network mutual backup system includes a source node S, a target node T, and intermediate nodes A, B, C, and D. Among the link state parameters, the link SA delay is 20ms and the bandwidth is 10Gbps, the AT delay is 35ms and the bandwidth is 8Gbps, the SB delay is 25ms and the bandwidth is 9Gbps, and the BT delay is 40ms and the bandwidth is 7Gbps. The preset delay threshold is 50ms and the bandwidth threshold is 5Gbps, and SA, AT, SB, and BT are selected as candidate transmission links. The initial encrypted paths P1 (SAT) and P2 (SBT) are constructed, and there are no overlapping links between the two. The perturbation factor sequence is generated using the Logistic chaotic map, with the initial value x_0 = 0.3, μ = 3.9, and the perturbation factors 0.6 and 0.8 are generated. The initial priority of path P1 is 0.85 (low delay and high bandwidth), and the priority of P2 is 0.75. After applying the perturbation factor, P1's priority is updated to 0.85 × 0.6 = 0.51, and P2's priority is updated to 0.75 × 0.8 = 0.6. After the reordering, P2 has a higher priority than P1. Real-time load rates are monitored. If P1's load rate is 70% and P2's is 45%, P2 is prioritized for distributing encrypted data blocks to heterogeneous nodes. When P2's load rate rises to 75%, the chaotic map is triggered to regenerate the perturbation factor and dynamically adjust path priorities.

[0130] Based on the same concept, the embodiment of the present application provides an optical network mutual backup video data encryption system based on a distributed system. Figure 4 The optical network mutual backup video data encryption system based on a distributed system provided in an embodiment of the present application is described in detail.

[0131] Figure 4 This is a structural block diagram of an optical network mutual backup video data encryption system based on a distributed system shown in an embodiment of the present application.

[0132] like Figure 4 As shown, the optical network mutual backup video data encryption system based on a distributed system may include:

[0133] An acquisition module 410 is configured to acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters;

[0134] A determination module 420 is configured to determine, through a distributed consensus protocol, edge nodes that meet a mutual backup condition as encryption collaboration nodes, where the mutual backup condition includes a fluctuation range of a dynamic load parameter and a node trust evaluation value that simultaneously meet a preset threshold range;

[0135] A generation module 430 is configured to generate a master key splitting factor based on the node trust evaluation value of the encryption cooperation node, split the master key into multiple subkey segments according to the master key splitting factor, and bind and encrypt the optical network mutual backup video data into blocks and the multiple subkey segments to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations;

[0136] The distribution module 440 is used to generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on the chaotic mapping sequence, generate a target encryption path that adapts to the mutual backup storage requirements, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.

[0137] In one embodiment, the distribution module 440 is also used to obtain the link bit error rate parameter in real time through the quantum channel during the transmission of the target encryption path; determine whether the link bit error rate parameter is greater than a predetermined code rate threshold, and when the link bit error rate parameter is greater than the predetermined code rate threshold, trigger the joint decryption verification based on the encryption collaboration node to obtain the updated dynamic load parameter; regenerate the master key splitting factor based on the updated dynamic load parameter and the optical network topology data, and complete the key synchronization of the mutual backup encrypted data block through a distributed consensus protocol.

[0138] In one embodiment, the distribution module 440 is specifically used to recalculate the target node trust evaluation value of each encryption collaboration node based on the change in computing resource occupancy in the updated dynamic load parameters and the optical network topology data; superimpose and correct the target node trust evaluation value with the historical master key splitting factor to generate a target master key splitting factor, where the historical master key splitting factor is the key splitting factor generated for the last time before triggering the joint decryption verification; in the distributed consensus protocol, the target master key splitting factor is broadcast to all encryption collaboration nodes, and the target master key splitting factor and the historical master key splitting factor are majority confirmed by the encryption collaboration nodes. When more than a preset proportion of encryption collaboration nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the associated constraints, the key synchronization of the mutual backup encrypted data blocks is completed.

[0139] In one embodiment, the acquisition module 410 is specifically used to calculate the node connection weight of each edge node based on the node distance and link bandwidth in the optical network topology data, where the node distance is the physical link length between adjacent nodes and the link bandwidth is the available transmission rate; based on the computing resource occupancy and task queue depth in the dynamic load parameters, the load balancing factor of each edge node is calculated, where the task queue depth is the cumulative number of unprocessed tasks; the node connection weight and the load balancing factor are superimposed in a preset ratio to generate a node trust evaluation value, where the preset ratio is determined by the global node distribution density of the optical network topology data.

[0140] In one embodiment, the determination module 420 is specifically used to determine, for each edge node, whether the fluctuation range of the dynamic load parameter is within a first preset threshold interval and whether the node trust evaluation value is within a second preset threshold interval, where the fluctuation range is the difference between the maximum and minimum values ​​of the dynamic load parameter within a preset time window; the edge nodes that meet the requirements of the fluctuation range of the dynamic load parameter being within the first preset threshold interval and the node trust evaluation value being within the second preset threshold interval are taken as a candidate node set; in a distributed consensus protocol, the real-time status consistency of each candidate node in the candidate node set is confirmed through interactive voting between the edge nodes in the candidate node set, and the edge nodes whose voting pass rate exceeds a preset ratio are screened out as encryption collaborative nodes.

[0141] In one embodiment, the generation module 430 is specifically used to sort the node trust evaluation values ​​of the encryption collaboration nodes according to numerical size, and assign a corresponding splitting factor weight to each encryption collaboration node, wherein the splitting factor weight is inversely proportional to the ranking position of the node trust evaluation value; calculate the target length of each sub-key fragment according to the splitting factor weight, and split the master key into multiple sub-key fragments according to the target length; divide the optical network mutual backup video data into data blocks with the same number of sub-key fragments, and perform a bit-by-bit logical operation on each data block and the corresponding sub-key fragment to generate a mutual backup encrypted data block; allocate a redundant storage location for each mutual backup encrypted data block according to the splitting factor weight, wherein the redundant storage location is a physical storage node in the heterogeneous node that matches the splitting factor weight.

[0142] In one embodiment, the distribution module 440 is specifically used to extract the transmission delay and available bandwidth from the link status parameters, and mark the links with transmission delay less than a preset delay threshold and available bandwidth greater than a preset bandwidth threshold as candidate transmission links; generate an initial encryption path based on the physical positions of the nodes at both ends of the candidate transmission link, and the initial encryption path is composed of at least two non-overlapping candidate transmission links connected in series; generate a dynamic perturbation factor based on a chaotic mapping sequence, and periodically rearrange the transmission priority of each candidate transmission link in the initial encryption path according to the dynamic perturbation factor to generate a target encryption path; according to the real-time transmission load rate of the target encryption path, distribute the mutually encrypted data blocks to the corresponding heterogeneous nodes in sequence, where the real-time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encryption path.

[0143] Figure 4 Each module in the system shown has the function of implementing Figures 1 to 3 The functions of each step in the embodiment can achieve the corresponding technical effects, which will not be described in detail here for the sake of brevity.

[0144] Figure 5 A schematic diagram of the hardware structure of an electronic device provided in one embodiment of the present application is shown.

[0145] The electronic device may include a processor 510 and a memory 520 storing computer program instructions.

[0146] Specifically, the processor 510 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0147] The memory 520 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 520 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 520 may include removable or non-removable (or fixed) media. Where appropriate, the memory 520 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 520 is a non-volatile solid-state memory.

[0148] The memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to the first aspect of the present disclosure.

[0149] The processor 510 reads and executes computer program instructions stored in the memory 520 to implement any one of the optical network mutual backup video data encryption methods based on a distributed system in the above embodiments.

[0150] In one example, the electronic device may further include a communication interface 530 and a bus 540. Figure 5 As shown, the processor 510 , the memory 520 , and the communication interface 530 are connected via a bus 540 and communicate with each other.

[0151] The communication interface 530 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0152] Bus 540 includes hardware, software or both, and the parts of online data flow metering equipment are coupled to each other. For example, but not limitation, bus can include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 540 can include one or more buses. Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.

[0153] The electronic device can execute the optical network mutual backup video data encryption method based on the distributed system in the embodiment of the present application, thereby realizing the combination Figures 1 to 3 The invention describes an optical network mutual backup video data encryption method based on a distributed system.

[0154] In addition, in conjunction with the distributed system-based optical network mutual backup video data encryption method in the above embodiments, the present application embodiments may provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the distributed system-based optical network mutual backup video data encryption methods in the above embodiments is implemented.

[0155] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0156] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0157] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0158] Aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. This processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be implemented by the dedicated hardware that performs the specified function or action, or can be implemented by the combination of dedicated hardware and computer instructions.

[0159] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A method for encrypting video data in an optical network based on a distributed system, characterized in that: include: Acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters; Determine, through a distributed consensus protocol, an edge node that meets the mutual backup condition as an encryption collaboration node, wherein the mutual backup condition includes that the fluctuation range of the dynamic load parameter and the node trust evaluation value both meet a preset threshold range; Generating a master key splitting factor based on the node trust evaluation value of the encryption cooperation node, splitting the master key into multiple sub-key fragments according to the master key splitting factor, and binding and encrypting the optical network mutual backup video data with the multiple sub-key fragments respectively to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations; An initial encryption path is generated according to the link state parameters, the transmission priority of the initial encryption path is dynamically perturbed based on a chaotic mapping sequence, a target encryption path adapted to the mutual backup storage requirements is generated, and the mutual backup encrypted data blocks are distributed to the corresponding heterogeneous nodes through the target encryption path.

2. The method according to claim 1, characterized in that The method further comprises: During the transmission of the target encrypted path, a link bit error rate parameter is obtained in real time through a quantum channel; Determining whether the link bit error rate parameter is greater than a predetermined bit rate threshold, and when the link bit error rate parameter is greater than the predetermined bit rate threshold, triggering joint decryption verification based on the encryption collaboration node to obtain the updated dynamic load parameter; The master key splitting factor is regenerated according to the updated dynamic load parameter and the optical network topology data, and the key synchronization of the mutually encrypted data block is completed through the distributed consensus protocol.

3. The method according to claim 2, characterized in that The method of regenerating the master key splitting factor according to the updated dynamic load parameter and the optical network topology data, and completing key synchronization of the mutually encrypted data block through the distributed consensus protocol, includes: Recalculating the target node trust evaluation value of each of the encryption collaboration nodes based on the updated computing resource occupancy change in the dynamic load parameter and the optical network topology data; The target node trust evaluation value is superimposed and corrected with the historical master key split factor to generate a target master key split factor, where the historical master key split factor is the key split factor generated last time before triggering the joint decryption verification; In the distributed consensus protocol, the target master key splitting factor is broadcast to all the encryption collaboration nodes, and the target master key splitting factor and the historical master key splitting factor are majority confirmed by the encryption collaboration nodes. When more than a preset proportion of the encryption collaboration nodes confirm that the target master key splitting factor and the historical master key splitting factor meet the associated constraints, the key synchronization of the mutually encrypted data blocks is completed.

4. The method according to claim 1, wherein The generating a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameter includes: Calculating a node connection weight for each edge node based on an inter-node distance and a link bandwidth in the optical network topology data, wherein the inter-node distance is a physical link length between adjacent nodes and the link bandwidth is an available transmission rate; Calculating a load balancing factor for each edge node based on the computing resource occupancy and task queue depth in the dynamic load parameters, where the task queue depth is the cumulative number of unprocessed tasks; The node connection weight and the load balancing factor are superimposed in a preset ratio to generate the node trust evaluation value, and the preset ratio is determined by the global node distribution density of the optical network topology data.

5. The method according to claim 1, wherein The step of determining, through a distributed consensus protocol, an edge node that meets a mutual backup condition as an encryption collaboration node, wherein the mutual backup condition includes that the fluctuation range of the dynamic load parameter and the node trust evaluation value both meet a preset threshold range, includes: For each edge node, determining whether the fluctuation range of the dynamic load parameter is within a first preset threshold interval and whether the node trust evaluation value is within a second preset threshold interval, where the fluctuation range is the difference between the maximum and minimum values ​​of the dynamic load parameter within a preset time window; Select edge nodes that satisfy the fluctuation range of the dynamic load parameter within a first preset threshold interval and the node trust evaluation value within a second preset threshold interval as a candidate node set; In the distributed consensus protocol, the real-time status consistency of each candidate node in the candidate node set is confirmed through interactive voting among the edge nodes in the candidate node set, and the edge nodes with a voting pass rate exceeding a preset ratio are screened out as the encryption collaborative nodes.

6. The method according to claim 1, characterized in that The method includes generating a master key splitting factor based on the node trust evaluation value of the encryption cooperation node, splitting the master key into multiple sub-key fragments according to the master key splitting factor, and binding and encrypting the optical network mutual backup video data with the multiple sub-key fragments after the blocks are divided to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations, including: Sort the node trust evaluation values ​​of the encryption cooperative nodes by numerical value, and assign a corresponding splitting factor weight to each encryption cooperative node, wherein the splitting factor weight is inversely proportional to the ranking of the node trust evaluation value; Calculating a target length of each subkey fragment according to the splitting factor weight, and splitting the master key into multiple subkey fragments according to the target length; Dividing the optical network mutual backup video data into data blocks equal in number to the subkey fragments, performing a bit-by-bit logical operation on each data block and the corresponding subkey fragment to generate the mutual backup encrypted data block; A redundant storage location is allocated to each of the mutually redundant encrypted data blocks according to the split factor weight, wherein the redundant storage location is a physical storage node in the heterogeneous nodes that matches the split factor weight.

7. The method according to claim 1, characterized in that The method includes generating an initial encryption path according to the link state parameters, dynamically perturbing the transmission priority of the initial encryption path based on a chaotic mapping sequence, generating a target encryption path adapted to the mutual backup storage requirement, and distributing the mutual backup encrypted data block to the corresponding heterogeneous node through the target encryption path, including: Extracting the transmission delay and available bandwidth from the link state parameters, and marking the links whose transmission delay is less than a preset delay threshold and whose available bandwidth is greater than a preset bandwidth threshold as candidate transmission links; Generate an initial encrypted path based on the physical locations of the nodes at both ends of the candidate transmission link, wherein the initial encrypted path is formed by connecting at least two non-overlapping candidate transmission links in series; generating a dynamic perturbation factor based on the chaotic mapping sequence, and periodically rearranging the transmission priority of each candidate transmission link in the initial encryption path according to the dynamic perturbation factor to generate the target encryption path; The mutually encrypted data blocks are distributed in sequence to corresponding heterogeneous nodes according to the real-time transmission load rate of the target encryption path, wherein the real-time transmission load rate is the ratio of the occupied bandwidth to the total bandwidth in the target encryption path.

8. An optical network mutual backup video data encryption system based on a distributed system, characterized in that: The system comprises: An acquisition module, configured to acquire optical network topology data and dynamic load parameters of edge nodes, and generate a node trust evaluation value of the edge node based on the optical network topology data and the dynamic load parameters, wherein the optical network topology data includes link state parameters; A determination module is used to determine, through a distributed consensus protocol, an edge node that meets a mutual backup condition as an encryption collaboration node, wherein the mutual backup condition includes that the fluctuation range of the dynamic load parameter and the node trust evaluation value simultaneously meet a preset threshold range; a generation module, configured to generate a master key splitting factor based on the node trust evaluation value of the encryption cooperation node, split the master key into multiple subkey fragments according to the master key splitting factor, and bind and encrypt the optical network mutual backup video data into blocks and the multiple subkey fragments respectively to form mutual backup encrypted data blocks, wherein the mutual backup encrypted data blocks are configured to be redundantly stored in heterogeneous nodes at different physical locations; A distribution module is used to generate an initial encryption path according to the link state parameters, dynamically perturb the transmission priority of the initial encryption path based on a chaotic mapping sequence, generate a target encryption path that adapts to the mutual backup storage requirements, and distribute the mutual backup encrypted data blocks to the corresponding heterogeneous nodes through the target encryption path.

9. An electronic device, characterized in that: The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the optical network mutual backup video data encryption method based on a distributed system as described in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the optical network mutual backup video data encryption method based on a distributed system as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network edge calculation method and communication device

    CN119520156A

  • Communication transmission control cabinet based on big data

    CN119603301A