Processing method and device for real-time simulation software of quantum key distribution
By sending a network access request frame to the key manager device and uploading the quantum key sequence after successful authentication, the problem of the QKD simulation software being unable to interact in real time is solved, efficient interaction with the key manager device is achieved, experimental costs are reduced, and security is improved.
Patent Information
- Application Number
- CN202510958624.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-07-11
AI Technical Summary
Existing quantum key distribution (QKD) simulation software is unable to interact with the key manager (KM) device in real time.
By sending a network access request frame to the key manager device and sending a quantum key distribution strategy request frame after successful network access authentication, receiving and uploading the quantum key sequence, real-time interaction with the key manager device is achieved.
It improves the real-time interaction with the key manager device, reduces experimental costs, and ensures the standardization and security of the quantum communication process.
Smart Images

Figure CN120455009B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of quantum communication and information security technology, and specifically relates to a processing method and device for real-time simulation software of quantum key distribution. Background Art
[0002] Quantum Key Distribution (QKD) is a key distribution technology based on the principles of quantum mechanics. Its core advantage lies in its ability to utilize the characteristics of quantum states, such as the quantum no-cloning theorem and the Heisenberg uncertainty principle, to achieve unconditionally secure key distribution.
[0003] Related technologies use QKD simulation software to simulate QKD processes, such as key negotiation, error correction, enhancement, etc., to research, develop and verify QKD technology.
[0004] However, existing QKD simulation software cannot interact with the Key Manager (KM) device in real time. Summary of the Invention
[0005] The present application aims to provide a method and device for processing quantum key distribution real-time simulation software, at least to solve the problem in the prior art that the existing QKD simulation software cannot interact with the KM device in real time.
[0006] In a first aspect, embodiments of the present application disclose a method for processing quantum key distribution real-time simulation software, which is applied to a device including a quantum communication party simulated by the real-time simulation software, the method comprising:
[0007] Sending a network access request frame to the key manager device, wherein the network access request frame is used to request network access authentication with the key manager device;
[0008] When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, sending a quantum key distribution policy request frame to the key manager device; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame;
[0009] Receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
[0010] In a second aspect, an embodiment of the present application discloses a method for processing quantum key distribution real-time simulation software, which is applied to a key manager device, and the method includes:
[0011] receiving a network access request frame sent by a quantum communication party device, the network access request frame being used to request network access authentication with the key manager device; the quantum communication party device being a quantum communication party device simulated by the real-time simulation software;
[0012] In response to the network access request frame, returning a network access response frame to the quantum communication party device, and receiving a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed;
[0013] In response to the quantum key distribution strategy request frame, the quantum key distribution strategy is sent to the quantum communication party device, and the quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution strategy is received.
[0014] In a third aspect, an embodiment of the present application discloses a processing device for quantum key distribution real-time simulation software, which is applied to a device including a quantum communication party simulated by the real-time simulation software, and the device includes:
[0015] A first sending module is configured to send a network access request frame to a key manager device, wherein the network access request frame is used to request network access authentication with the key manager device;
[0016] a second sending module, configured to send a quantum key distribution policy request frame to the key manager device when the network access response frame returned by the key manager device indicates that the network access authentication has been passed; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame;
[0017] An uploading module is configured to receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
[0018] In a fourth aspect, an embodiment of the present application discloses a processing device for real-time simulation software for quantum key distribution, which is applied to a key manager device, and the device includes:
[0019] A first receiving module is configured to receive a network access request frame sent by a quantum communication party device, wherein the network access request frame is used to request network access authentication with the key manager device; the quantum communication party device is a quantum communication party device including a device simulated by the real-time simulation software;
[0020] A first processing module is configured to return a network access response frame to the quantum communication party device in response to the network access request frame, and receive a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed;
[0021] The second processing module is configured to issue a quantum key distribution policy to the quantum communication party device in response to the quantum key distribution policy request frame, and receive a quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution policy.
[0022] In a fifth aspect, an embodiment of the present application further discloses an electronic device, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect or the second aspect are implemented.
[0023] In a sixth aspect, an embodiment of the present application further discloses a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect or the second aspect are implemented.
[0024] In summary, in an embodiment of the present application, a network access request frame is sent to a key manager device. When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, a quantum key distribution policy request frame is sent to the key manager device to request the issuance of a quantum key distribution policy, and based on the quantum key distribution policy, a quantum key sequence is uploaded to the key manager device. After successful network access authentication with the key manager device, the present application generates and uploads a quantum key sequence based on the quantum key distribution policy issued by the key manager device, thereby enabling better interaction with the key manager. In addition, during the communication process, when a frame is received, the present application executes the action corresponding to the frame without waiting, thereby improving the real-time interaction with the key manager device. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In the attached figure:
[0026] Figure 1 This is a flowchart of a processing method for quantum key distribution real-time simulation software provided by an embodiment of the present application;
[0027] Figure 2 This is a flowchart of a quantum key distribution network access request provided by an embodiment of the present application;
[0028] Figure 3 This is a quantum key distribution management flow chart provided by an embodiment of the present application;
[0029] Figure 4This is a flowchart of another method for processing quantum key distribution real-time simulation software provided by an embodiment of the present application;
[0030] Figure 5 This is a flowchart of the interactive steps of another processing method of quantum key distribution real-time simulation software provided in an embodiment of the present application;
[0031] Figure 6 This is a schematic diagram of a quantum key sequence upload provided by an embodiment of the present application;
[0032] Figure 7 This is a quantum key distribution heartbeat detection flow chart provided by an embodiment of the present application;
[0033] Figure 8 This is a flowchart of a quantum key distribution operation status report provided by an embodiment of the present application;
[0034] Figure 9 This is a flowchart of reporting an abnormal state of quantum key distribution provided by an embodiment of the present application;
[0035] Figure 10 Schematic diagram of a real-time simulation software system for quantum key distribution provided in an embodiment of the present application;
[0036] Figure 11 This is a block diagram of a processing device for quantum key distribution real-time simulation software provided in an embodiment of the present application;
[0037] Figure 12 This is a block diagram of another processing device for quantum key distribution real-time simulation software provided in an embodiment of the present application;
[0038] Figure 13 is a block diagram of an electronic device according to an embodiment of the present application;
[0039] Figure 14 This is a block diagram of an electronic device according to another embodiment of the present application. DETAILED DESCRIPTION
[0040] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0041] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.
[0042] The BB84 protocol is the first key distribution protocol based on quantum mechanics, leveraging the unclonability of quantum states (such as photon polarization states) to ensure secure key transmission. Practical QKD equipment must complete complex processes such as key negotiation, error correction, and security enhancement, and must be able to interact with key management (KM) devices. However, the high cost of quantum communication equipment and limited experimental conditions pose numerous challenges to the deployment and testing of practical QKD equipment. Therefore, developing real-time QKD simulation software that can effectively simulate the BB84 protocol is of great significance for the research, education, and application promotion of quantum communication technology.
[0043] Although there are currently a variety of QKD real-time simulation software, such as QKDNetSim, SimQN, QuNetSim and NetSquid, these QKD real-time simulation software cannot interact with KM devices in real time. The solution proposed in this application is described in detail below.
[0044] Figure 1 This is a flowchart of a processing method for real-time simulation software of quantum key distribution provided by an embodiment of the present application, which is applied to a device including a quantum communication party simulated by the real-time simulation software, see Figure 1 , the method may include the following steps:
[0045] Step 101: Send a network access request frame to a key manager device, where the network access request frame is used to request network access authentication with the key manager device.
[0046] For example, a network access request frame is a data frame in a specific format, sent by a quantum communication device to a key manager device. Its core function is to request a connection with the key manager device and perform identity authentication. This data frame can carry relevant information about the key manager device, which the key manager device uses to determine whether the quantum communication device is eligible for access.
[0047] For example, a network access request frame could carry the key manager device's identifier, namely, its serial number, KM-001. The quantum communication device then sends this network access request frame to the key manager device over the network, formally initiating a network access authentication request. Because the network access request frame carries device information, it can clearly identify the communication partner, ensuring that the network access request frame is accurately sent to the designated key manager device and establishing a correct communication link.
[0048] Step 102: When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, a quantum key distribution policy request frame is sent to the key manager device; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame.
[0049] For example, the network access response frame is an information frame that the key manager device feeds back to the device after receiving the network access request frame sent by the quantum communication device, which is used to inform the quantum communication device whether it has passed the network access authentication. Figure 2 The quantum communication device sends a network access request frame to the key manager device to request network access authentication with the key manager device. After receiving the network access request frame, the key manager device returns a network access response frame to the quantum communication device.
[0050] For example, the quantum communication device calls the network access authentication module of the interface unit and uses the QKD network access request frame model in the network access authentication module to send a request to the KM device. Then, it uses the QKD network access response frame model in the network access authentication module to start the KM listening service and wait for a response. If the network access response frame returned by the key manager device carries the identifier "0x00", it indicates that the authentication is successful. If the network access response frame returned by the key manager device carries the identifier "0x01", it indicates that the authentication has failed. In this case, the device will continue to send network access request frames to the key manager device to request network access authentication.
[0051] For example, a quantum key distribution policy request frame is a specific data frame sent by a quantum communication device to the key manager device after passing network authentication. It is used to request quantum key distribution policies. After receiving the network access response frame and confirming authentication, the quantum communication device sends a quantum key distribution policy request frame. This frame may contain information such as a device requirement identifier and device performance parameters, indicating to the key manager that it needs to obtain a quantum key distribution policy. The device requirement identifier may be a request for a general service key policy, and the device performance parameter may be the maximum key length processing capability.
[0052] Through the quantum key distribution policy request frame and policy delivery mechanism, the key manager device can deliver customized quantum key distribution policies based on the business requirements, performance and other factors of different devices.
[0053] Step 103: Receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
[0054] See also Figure 3 Taking the quantum communication devices including client Alice and server Bob as an example, client Alice and server Bob each send a quantum key distribution policy request frame to the key manager device to apply for a quantum key distribution policy. After receiving the quantum key distribution policy request frame, the key manager device formulates a quantum key distribution policy and sends the quantum key distribution policy to client Alice and server Bob. Specifically, taking client Alice as an example, the process from sending a quantum key distribution policy request frame to receiving a quantum key distribution policy is described. Client Alice calls the quantum key distribution policy management module of the interface unit and uses the quantum key distribution policy application frame model in the quantum key distribution policy management module to send a request to the KM device. Then, the quantum key distribution policy response frame model in the module is used to start the monitoring service, wait for a response, and obtain the quantum key distribution policy after receiving the quantum key transmission response frame sent by the KM device. After both client Alice and server Bob successfully receive the quantum key distribution policy, they each start the quantum key sequence upload process according to the policy requirements. In addition, if the quantum key distribution policy is not successfully received, the quantum key distribution policy request frame will continue to be sent to the key manager device every 30 seconds until it succeeds.
[0055] For example, a quantum key distribution policy includes a key upload duration of ≤500 milliseconds. The quantum communication device generates a quantum key sequence according to the parameters in the quantum key distribution policy and uploads the quantum key sequence to the key manager device.
[0056] See also Figure 3During the quantum key sequence upload process, the key manager device sends a clear quantum key distribution policy frame to the client Alice and the server Bob to end the quantum key process. After the client Alice and the server Bob receive the clear quantum key distribution policy frame, the quantum key process is ended and a success response is sent to the KM device. Specifically, the client Alice and the server Bob call the quantum key distribution policy management module of the interface unit, use the clear quantum key distribution policy frame model in the quantum key distribution policy management module to start the monitoring service, and wait for the response. After receiving the clear quantum key distribution policy frame, the client Alice and the server Bob will clear the current quantum key distribution policy and end the process of uploading the quantum key sequence. Finally, the client Alice and the server Bob call the quantum key distribution policy management module of the interface unit, and use the clear quantum key distribution policy response frame model in the quantum key distribution policy management module to send a success response to the KM device.
[0057] Figure 4 This is a flowchart of another processing method of quantum key distribution real-time simulation software provided by this application, which is applied to the key manager device, see Figure 4 , the method may include the following steps:
[0058] Step 201: Receive a network access request frame sent by a quantum communication party device, where the network access request frame is used to request network access authentication with a key manager device; the quantum communication party device is a quantum communication party device simulated by real-time simulation software.
[0059] For example, network authentication is the process of parsing and verifying a received network access request frame to confirm whether the quantum communication device is allowed to join the key management network. Specifically, after receiving the network access request frame, the key manager device automatically forwards it to the Quantum Key Distribution Network Controller (QKDNC) for processing. Specifically, the QKDNC verifies the content of the network access request frame to determine whether the network access authentication has been passed. The QKDNC then returns a network access response frame carrying the verification result to the key manager device. The key manager then returns a network access response frame carrying the verification result to the quantum communication device. The specific details of how the QKDNC processes the network access request frame are not described here.
[0060] The quantum communication device simulated by real-time simulation software sends a network access request frame for authentication testing, eliminating the need to use expensive actual quantum communication hardware equipment and reducing experimental costs.
[0061] Step 202: In response to the network access request frame, return a network access response frame to the quantum communication party device, and receive a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed.
[0062] For example, after receiving a network access request frame, the key manager device verifies the key manager device identifier carried in the network access request frame. If the verification succeeds, the key manager generates a network access response frame with an authentication success identifier (such as "0x00"). If the verification fails, the key manager generates a network access response frame with a failure identifier (such as "0x01") and returns the network access response frame to the quantum communication device.
[0063] Step 203: In response to the quantum key distribution strategy request frame, the quantum key distribution strategy is sent to the quantum communication party device, and the quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution strategy is received.
[0064] For example, a quantum key distribution policy is a set of rules issued by a key manager to quantum communication devices, covering key generation frequency, key length, and other aspects. These rules guide the generation, distribution, and management of quantum keys on these devices. Quantum key distribution policies can be generated based on global network requirements and device performance. For example, for devices used for real-time communication services, a policy might be issued that sets a key generation frequency of once per second and a key length of 128 bits. This policy is then sent to the quantum communication devices over the network.
[0065] The quantum key distribution policy is uniformly issued by the key manager device to ensure that all devices in the network follow consistent key generation, distribution and management rules, avoid key management confusion caused by devices setting their own policies, and improve the standardization and security of the entire network key management.
[0066] Figure 5 This is a flowchart of the interactive steps of the processing method of the real-time simulation software for quantum key distribution provided by this application, see Figure 5 , the method may include the following steps:
[0067] Step 301: The quantum communication device sends a network access request frame to the key manager device. The network access request frame is used to request network access authentication with the key manager device.
[0068] This step may be specifically referred to the above step 101 and will not be described in detail here.
[0069] Step 302: When the device serial number carried in the network access request frame matches the device serial number of the key manager device, the key manager device generates a network access response frame carrying a first identifier; the first identifier is used to indicate that the network access authentication has been passed.
[0070] For example, a device serial number is a unique identifier assigned to a key manager device by the device manufacturer or system administrator. It's typically a fixed-length string of characters (e.g., letters and numbers) that uniquely identifies the device. This serial number is written into the device's hardware (e.g., chip or firmware) before it leaves the factory or connects to the network. It is tamper-proof and unique. The first identifier is a specific flag or status value returned by the key manager device to the quantum communication partner device after completing network authentication, clearly indicating that the device has passed authentication. For example, it could be defined as "0x00."
[0071] For example, taking the device serial number of the key manager device as KM-001, if the device serial number carried in the network access request frame is the same as KM-001, a network access response frame carrying 0x00 is generated to indicate to the quantum communication party device that the network access authentication has been passed.
[0072] Step 303: If the device serial number carried in the network access request frame does not match the device serial number of the key manager device, the key manager device generates a network access response frame carrying a second identifier; the second identifier is used to indicate that the network access authentication has not been passed.
[0073] For example, the second identifier is a specific flag or status value returned by the key manager device to the quantum communication partner device after completing network access authentication, which clearly indicates that the device has passed authentication. The second identifier is a specific flag or status value returned when the device serial number in the network access request frame does not match the device serial number of the key manager device, which clearly indicates that authentication failed. For example, it can be defined as "0x01".
[0074] For example, taking the device serial number of the key manager device as KM-001, if the device serial number carried in the network access request frame is different from KM-001, a network access response frame carrying 0x01 is generated to indicate that the authentication has failed to the quantum communication device.
[0075] Step 304: The key manager device sends a network access response frame to the quantum communication partner device.
[0076] This step may be specifically referred to the above step 202 and will not be described in detail here.
[0077] Optionally, the network access request frame carries a device serial number; the method further includes:
[0078] Step A1: The quantum communication device receives a network access response frame returned by the key manager device in response to the network access request frame;
[0079] Step A2: If the network access response frame carries a first identifier indicating success, it is determined that the network access authentication has passed; wherein, if the device serial number carried in the network access request frame matches the device serial number of the key manager device, the key manager device returns a network access response frame carrying the first identifier.
[0080] For steps A1 and A2, taking the device serial number KM-001 as an example, the quantum communication device sends a network access request frame carrying the KM-001 identifier to the key manager device. Since the KM-001 identifier carried in the network access request frame matches the device serial number KM-001 of the key manager device, the key manager device returns a network access response frame carrying 0x00, thereby passing the network access certification according to the quantum communication device standard.
[0081] Step 305: When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, the quantum communication device sends a quantum key distribution strategy request frame to the key manager device.
[0082] This step may be specifically referred to the above step 102 and will not be described in detail here.
[0083] Step 306: The key manager device sends the quantum key distribution policy to the quantum communication party device in response to the quantum key distribution policy request frame.
[0084] This step may be specifically referred to the above step 203 and will not be described in detail here.
[0085] Optionally, step 306 may specifically include:
[0086] Sub-step 3061: When the device serial number carried in the quantum key distribution policy request frame matches the device serial number of the key manager device, the key manager device sends a distribution response frame carrying the quantum key distribution policy to the quantum communication party device.
[0087] For sub-step 3061, taking the device serial number KM-001 as an example, the quantum communication device sends a quantum key distribution policy request frame to the key manager device. This request frame carries the KM-001 identifier. After receiving the quantum key distribution policy request frame, the KM device parses the request frame and compares the device serial number KM-001 carried in the request frame with its own device serial number to see if they are consistent. If they are consistent, it issues the quantum key distribution policy and sends a distribution response frame carrying the quantum key distribution policy to the client Alice / server Bob.
[0088] Step 307: The quantum communication party device uploads the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution strategy.
[0089] This step may be specifically referred to the above step 103 and will not be described in detail here.
[0090] Optionally, the quantum key distribution strategy includes a quantum key upload duration; step 307 may specifically include:
[0091] Sub-step 3071: If a quantum key sequence has been generated, determine a parameter value corresponding to a key upload rate-related item based on the quantum key upload duration; the key upload rate-related item is a parameter item in the configuration file of the real-time simulation software that affects the quantum key upload rate;
[0092] Sub-step 3072: Modify the key upload rate related items to the corresponding parameter values, and upload the quantum key sequence to the key manager device according to the key upload rate related items.
[0093] For sub-steps 3071 and 3072, the quantum key upload duration is the time required to generate and transmit the quantum key sequence to the key manager device, and is a core indicator of key transmission efficiency. Parameters in the real-time simulation software configuration file that affect quantum key upload speed may include: network bandwidth allocation ratio, data compression ratio, and retransmission threshold. The network bandwidth allocation ratio represents the percentage of network bandwidth reserved for key transmission. The data compression ratio indicates the compression ratio applied to the key data; a higher compression ratio results in a smaller amount of transmitted data. The retransmission threshold indicates the maximum number of retransmissions allowed in the event of a transmission failure.
[0094] For example, if a quantum key sequence has been generated, the quantum key upload time is 50 milliseconds. The real-time simulation software detects that the current network bandwidth utilization is 70%. The quantum key sequence data volume is 10MB, and based on the current bandwidth, it would take 80 milliseconds to transmit the quantum key sequence within 50 milliseconds. The remaining bandwidth is insufficient to transmit the quantum key sequence within 50 milliseconds. The key upload rate-related items in the software configuration file include: the current network bandwidth allocation ratio is 30%, the current data compression ratio is 50%, and the current retransmission threshold is 3. Based on a 50 millisecond key upload time, the key upload rate-related items are calculated. Upload rate = data volume / upload time = 10MB / 50ms = 200MB / s. The bandwidth required for key transmission = 200MB / s / network efficiency (assuming 80%) = 250MB / s. If the total network bandwidth is 1000MB / s, the bandwidth allocation ratio needs to be adjusted to 25% (250 / 1000). At the same time, to reduce data volume, the data compression ratio is increased to 70% (compressed data volume: 10MB x 30% = 3MB), reducing the actual upload rate requirement to 3MB / 50ms = 60MB / s. The bandwidth allocation ratio can be further reduced to 10% (60 / 1000). To compress the upload time to 50 milliseconds, the network bandwidth allocation ratio can be adjusted to 60%, the data compression ratio increased to 70%, and the retransmission threshold maintained at 3. The real-time simulation software modifies the key upload rate-related parameters in the configuration file to the above parameter values. The quantum communication device uploads the quantum key sequence to the key manager device using a 60% network bandwidth allocation ratio, a 70% data compression ratio, and a retransmission threshold of 3.
[0095] For example, the quantum key sequence is encapsulated according to a preset transmission frame format, and the encapsulated quantum key sequence is uploaded to the key manager device according to the key upload rate related items. The preset transmission frame format is a quantum key data transmission structure predefined by the KM device, which is used to standardize the transmission format of the key in the network. The quantum communication device can encapsulate the quantum key sequence according to the preset transmission frame format, and then send the encapsulated frame to the KM device through the network according to the key upload rate related items, such as a network bandwidth allocation ratio of 10% and a data compression rate of 70%. Because the preset transmission frame format defines a unified data exchange standard, quantum key generation devices and key managers of different brands can communicate directly as long as they follow the same frame format.
[0096] Optionally, the quantum key distribution strategy includes the quantum key upload duration; step 307 may further include:
[0097] Sub-step 3073: If no quantum key sequence is generated, determine, based on the quantum key upload duration, parameter values corresponding to key generation rate-related items and parameter values corresponding to key upload rate-related items; the key generation rate-related items and the key upload rate-related items are, respectively, parameter items in the configuration file of the real-time simulation software that affect the quantum key generation rate and the quantum key upload rate.
[0098] Sub-step 3074: modify the key generation rate related item to the parameter value corresponding to the key generation rate related item, and modify the key upload rate related item to the parameter value corresponding to the key upload rate related item;
[0099] Sub-step 3075: generating a quantum key sequence according to key generation rate related items;
[0100] Sub-step 3076: Upload the quantum key sequence to the key manager device according to the key upload rate related items.
[0101] For sub-steps 3073-3076, key generation rate-related items are parameters in the real-time simulation software that affect the speed of quantum key generation, such as photon emission frequency, quantum state measurement efficiency, and error correction algorithm complexity. The photon emission frequency is the number of photons emitted per second for key generation, for example, 10^6 photons / second. The quantum state measurement efficiency is the success rate of measuring the polarization state of photons, for example, 95%. The error correction algorithm complexity is the time consumed to correct errors caused by quantum noise, for example, the number of error correction algorithm iterations.
[0102] In the absence of a quantum key sequence, taking a quantum key upload time of 200 milliseconds as an example, the quantum communication device has not yet generated a key, requiring optimization of both the key generation and key upload processes. Assume that, of the total 200 milliseconds, 150 milliseconds are reserved for key generation and 50 milliseconds for key upload. Based on a 150 millisecond key generation time, calculate the key generation rate-related terms. The required generation rate = key length (e.g., 256 bits) / generation time = 256 bits / 0.15 seconds = 1706 bits / second. The current generation rate is 1000 bits / second. The photon emission frequency needs to be increased from 5 × 10^5 photons / second to 8 × 10^5 photons / second (a 60% increase), achieving a key generation rate of 1600 bits / second. Reducing the number of error correction algorithm iterations from 5 to 3 saves 20 milliseconds, bringing the actual generation rate close to 1706 bits / second. Based on a 50 millisecond key upload time, calculate the key upload rate-related terms. The required upload rate = 256 bits ÷ 0.05 seconds = 5120 bits / second. The current upload rate is 4000 bits / second (due to insufficient bandwidth allocation). The network bandwidth allocation ratio needs to be adjusted from 8% to 10% (total bandwidth 100,000 bits / second x 10% = 10,000 bits / second, meeting the requirement). The data compression ratio remains at the default 50% (compressed data volume is 128 bits, and upload time = 128 ÷ 10,000 ≈ 12.8 milliseconds, far less than 50 milliseconds). The real-time simulation software modifies the parameters in the configuration file to: photon emission frequency: 8 × 10^5 photons / second, error correction iterations: 3, network bandwidth allocation ratio: 10%, data compression ratio: 50%. The quantum communication device generates the quantum key sequence according to the new parameters.
[0103] For example, a quantum key sequence is encapsulated according to a preset transmission frame format and uploaded to a key manager device according to key upload rate specifications. The preset transmission frame format is a quantum key data transmission structure predefined by the KM device and used to standardize the format for key transmission across the network. Quantum communication devices can encapsulate the quantum key sequence according to the preset transmission frame format. Then, according to key generation rate specifications (photon emission frequency: 8×10^5 photons / second, number of error correction iterations: 3), they generate the quantum key sequence. According to key upload rate specifications (network bandwidth allocation ratio: 10%, data compression ratio: 50%), the encapsulated frames are sent to the KM device over the network. Because the preset transmission frame format defines a unified data exchange standard, quantum key generation devices and key managers of different brands can communicate directly as long as they adhere to the same frame format.
[0104] For example, see Figure 6The entire process of uploading the quantum key sequence is divided into three coroutines, and the three coroutines are carried out simultaneously. Coroutine 1 is mainly responsible for the quantum state information exchange process between the two parties in the quantum key distribution protocol, coroutine 2 is mainly responsible for the traditional information exchange process between the two parties in the quantum key distribution protocol, and coroutine 3 is responsible for the process of Alice and Bob uploading the quantum key sequence to the key manager device. This process can be set by Alice and Bob through the interface display unit. The following is a detailed description of the process:
[0105] Quantum state preparation and measurement (corresponding to step 1)
[0106] Coroutine 1 input: None
[0107] Output of Coroutine 1: Alice / Bob's basis selection and initial key
[0108] (1) Alice: The process is initiated by Alice. First, Alice calls the quantum state preparation module of the quantum state unit and uses the pseudo-random number model of the quantum state preparation module to generate the Alice basis sequence and Alice key sequence. Then, she uses the photon polarization state preparation model of the quantum state preparation to generate a specified number of photon polarization state density matrices (2×1 matrices). For example, Alice first uses the pseudo-random number generation model GenerateRandomBinary(..) to generate the Alice key sequence Alice.Qubit and the Alice basis sequence Alice.Base_choice. Then, Alice calls the photon polarization state preparation model GeneratePolarizationState(Alice.Qubit, Alice.Base_choice,..) to generate the photon polarization state polState based on these parameters.
[0109] (2) Alice → Bob: Alice calls the quantum channel module of the transmission unit and uses the photon polarization state transmission model in the quantum channel module to send the generated photon polarization state density matrix to Bob. At the same time, the quantum channel physical model of the module is used to reduce the number of photon polarization state density matrices sent by Alice to simulate the attenuation in the actual environment, and a polarization angle offset of a specified value is applied to the photon polarization state density matrix to simulate bit errors. The photon polarization state polState is sent to Bob through the quantum channel qchannel.send(polState,..). Bob monitors Alice's port and uses qchannel.read(..) to read the polarization state polState_error, which may contain errors.
[0110] (3) Bob: Bob first calls the quantum state preparation module of the quantum state unit and uses the pseudo-random number model of the quantum state preparation module to generate the Bob basis sequence. Then, he calls the quantum channel module of the transmission unit and the quantum state measurement module of the quantum state unit, and uses the photon polarization state receiving model in the quantum state measurement module to measure the reduced photon polarization state density matrix. Then, he uses the quantum channel physical model of the quantum channel module to perform bit flipping on the measured partial random key to simulate the generation of bit errors. For example, Bob also generates the Bob basis sequence Bob.Base_choice through the pseudo-random number generation model GenerateRandomBinary(..), and uses the photon polarization state measurement model MeasurePolarizationState(Bob.Base_choice,polState_error,..) to complete the measurement of the photon polarization state, and finally obtains the Bob key sequence Bob.Qubit.
[0111] Base (coroutine 2)
[0112] Coroutine 2 input: Alice / Bob's basis selection and initial key
[0113] Coroutine 2 output: Alice / Bob's final security key
[0114] (4) Bob → Alice: Bob calls the classical channel module of the transmission unit and uses the data transmission model in the classical channel module to send Bob's basis sequence to Alice. At the same time, the classical channel physical model in the module is used to increase the delay. For example, Bob first sends Bob's basis sequence Bob.Base_choice to Alice through the classical channel cchannel.send(Bob.Base_choice,..).
[0115] (5) Alice: Alice calls the classical channel module of the transmission unit and uses the data receiving model in the classical channel module to receive Bob's basis sequence. Alice then calls the base matching module of the post-processing unit and uses the base matching module's bit comparison model 1 to filter out the base choices that are the same for Alice and Bob, obtaining the screening result (bit sequence). Then, based on the screening result, bit comparison model 2 is used to retain the keys under the same base choices for Alice and Bob, obtaining Alice's key sequence after base matching. Alice monitors Bob's port and reads Bob.Base_choice via cchannel.read(..) . Then, using bit comparison model 1 (bitcompare1(Alice.Base_choice, Bob.Base_choice,..)) , Alice compares it with her own base choice, Alice.Base_choice, to obtain the comparison result compareresult and the corresponding Alice.Qubit.
[0116] (6) Alice → Bob: Alice calls the classical channel module of the transmission unit and uses the data transmission model in the classical channel module to send the screening result to Bob. At the same time, the classical channel physical model in the module is used to increase the latency. Alice sends the compare result to Bob via cchannel.send(compareresult,..).
[0117] (7) Bob: Bob calls the classical channel module of the transmission unit and uses the data receiving model in the classical channel module to receive the screening results. Then, Bob calls the basis matching module of the post-processing unit and uses the bit comparison model 2 of the basis matching module to retain the key under the same basis selection of Alice and Bob, obtaining Bob's key (bit sequence) after basis matching. Bob monitors Alice's port, reads compareresult through cchannel.read(..), and uses bit comparison model 2 (bitcompare2(compareresult, Bob.Qubit..)) to obtain Bob.Qubit2.
[0118] Key verification (coroutine 2)
[0119] (8) Bob: Bob calls the key verification module of the post-processing unit and uses the bit extraction model in the key module to extract the 10%-based Bob key bit sequence, obtaining Bob's check key sequence and Bob's key sequence after key verification. Bob uses the bit extraction model (bitextract(Bob.Qubit2,..)) to extract Bob.checkQubit and Bob.Qubit3 from Bob.Qubit2.
[0120] (9) Bob → Alice: Bob calls the classical channel module of the transmission unit and uses the data transmission model in the classical channel module to send Bob's check key sequence to Alice. At the same time, the classical channel physics model in the module is used to increase the latency. Bob.checkQubit is sent to Alice via cchannel.send(Bob.checkQubit,..).
[0121] (10) Alice: Alice calls the key verification module of the post-processing unit and uses the bit extraction model in the key module to extract Alice's key sequence after 10% basis correction, obtaining Alice's verification key sequence and Alice's key sequence after key verification. Then, Alice uses the bit error rate calculation model in the module to calculate the bit error rate of the two parts of the verification key. If the bit error rate exceeds 11%, Alice terminates the protocol (shuts down the server). If the bit error rate is less than 11%, execute (11). Alice listens to Bob's port and reads Bob.checkQubit through cchannel.read(..). Similarly, she uses the bit extraction model (bitextract(Alice.Qubit2,..)) to obtain Alice.checkQubit and Alice.Qubit3. Afterwards, Alice uses the bit error rate calculation model (calculateerror(Alice.checkQubit, Bob.checkQubit)) to estimate the bit error rate. If the bit error rate exceeds 11%, Alice will shut down the program and the entire process will terminate; if the bit error rate is less than 11%, the program will continue.
[0122] Error Correction (Coroutine 2)
[0123] Note: The Cascade error correction algorithm requires Alice and Bob to perform multiple rounds of interaction. Here we take the Ldpc error correction algorithm model as an example.
[0124] (11) Alice: Alice calls the error correction module of the post-processing unit, and uses the Ldpc error correction algorithm model in the error correction module to generate the Ldpc check code based on the Alice key sequence after key verification.
[0125] (12) Alice → Bob: Alice calls the classical channel module of the transmission unit and uses the data transmission model in the classical channel module to send the Ldpc check code to Bob. At the same time, the classical channel physical model in the module is used to increase the delay.
[0126] (13) Bob: Bob calls the classical channel module of the transmission unit and uses the data receiving model in the classical channel module to receive the Ldpc checksum. Then, Bob calls the error correction module of the post-processing unit and uses the Ldpc checksum and the Ldpc error correction algorithm model in the error correction module to correct the key sequence after key verification, obtaining the corrected key sequence. Alice and Bob use the error correction algorithm to complete the error correction. After the error correction is completed, Alice obtains Alice.Qubit4 and Bob obtains Bob.Qubit4.
[0127] Security Enhancement (Coroutine 2)
[0128] Note: The system supports multiple hash algorithm models. The following takes the modular arithmetic pan-binary hash algorithm as an example.
[0129] (14) Bob: Bob calls the security enhancement module of the post-processing unit and uses the security enhancement module's modular arithmetic-based universal binary hashing algorithm model to perform fixed-length data compression on the error-corrected Bob key. Bob obtains the final key and two sets of Bob's random bit sequences. Alice generates random bit sequences a and b of the same length as Alice.Qubit4 using GenerateRandomBinary(..) and uses the hash function model (hashfunction(a,b,Alice.Qubit4)) to generate the final key Alice.key.
[0130] (15) Bob → Alice: Bob calls the classical channel module of the transmission unit and uses the data transmission model in the classical channel module to send Bob's two sets of random bit sequences to Alice. At the same time, the classical channel physical model in the module is used to increase the delay. a and b are sent to Bob via cchannel.send(a,b,..).
[0131] (16) Alice: Alice calls the classical channel module of the transmission unit and uses the data receiving model in the classical channel module to receive Bob's two sets of random bit sequences. Then, Alice calls the security enhancement module of the post-processing unit and uses the modular arithmetic of the security enhancement module's universal binary hash algorithm to perform fixed-length data compression on Alice's key sequence after key verification. Alice obtains the final key. Bob monitors Alice's port and reads a and b through cchannel.read(..). He also uses the hash function model (hashfunction(a,b,Bob.Qubit4)) to generate the final key Bob.key.
[0132] Key upload (coroutine 3)
[0133] Coroutine 3 input: Alice / Bob's final security key
[0134] Coroutine 3 output: None
[0135] (17) Alice / Bob: Alice / Bob calls the key transmission module of the interface unit and uses the key transmission frame model in the key transmission module to encapsulate Alice / Bob's final key in the transmission frame format and upload it to the KM device. Then, Alice / Bob calls the key transmission response frame model of the module to start the KM listening port and wait for the response. If the response is received, the QKD key upload process is successful. Alice\Bob uses the interface model kqframe(Alice.key\Bob.key,..) to encapsulate the key into kkey, and then uses the sending model kqsend(kkqy,..) to upload the key to the specified KM device.
[0136] Optionally, the method further includes:
[0137] Step 308: Periodically send a heartbeat detection request frame to the key manager device;
[0138] Step 309: If the heartbeat detection response frame returned by the key manager device in response to the heartbeat detection request frame is not received within the preset time period, the step of sending the network access request frame to the key manager device is executed again.
[0139] For steps 308 and 309, take the period as 30s and the preset duration as 90s as an example, see Figure 7After passing QKD network authentication, the quantum communication device sends a heartbeat request frame to the key manager device every 30 seconds. If it does not receive a heartbeat response frame within 90 seconds, it disconnects from the key manager device and attempts to re-authenticate. If it receives a heartbeat response frame within 90 seconds, it continues to send heartbeat request frames to the key manager device every 30 seconds. Specifically, the quantum communication device (client Alice / server Bob) invokes the heartbeat detection module of the interface unit and uses the heartbeat detection request frame model in the network authentication module to send a heartbeat detection request to the KM device. It then uses the heartbeat detection request response frame model in the heartbeat detection module to start the monitoring service and wait for a response. After receiving the heartbeat detection request from client Alice / server Bob, the KM device will automatically forward it to other units in the KM device for processing and feedback. For example, the QKDNC unit will return a heartbeat detection response frame to the QKD device after the QKDNC unit completes the processing. After receiving the heartbeat detection response frame, the QKD device returns a heartbeat detection response frame to client Alice / server Bob. If client Alice / server Bob does not receive the heartbeat detection response frame within 90 seconds, it will disconnect from the KM device and attempt to re-authenticate to the network. If it receives the heartbeat detection response frame within 90 seconds, it will continue to send heartbeat detection request frames to the key manager device every 30 seconds.
[0140] For example, see Figure 8 After completing the QKD network access authentication, the quantum communication device regularly reports its operating status to the KM device and listens for the operating status report response returned by the KM device. Specifically, every 30 seconds, Alice / Bob calls the status reporting module of the interface unit and uses the QKD operating status reporting frame model in the status reporting module to send an operating status report frame to the KM device. Then, the QKD operating status reporting response frame model in the module is used to start the monitoring service and wait for the response. After receiving the operating status report from Alice / Bob, the KM device will automatically forward it to the QKDNC for processing and feedback. After receiving the operating status report response frame returned by the QKDNC, the KM device returns the operating status report response frame to Alice / Bob.
[0141] For example, see Figure 9After completing the QKD network access authentication, when an abnormality occurs during the execution of quantum key sequence upload, the quantum communication party device reports the abnormal status to the KM device, listens for the abnormal status report response returned by the KM device, and executes the quantum key policy clearing process. Specifically, Alice / Bob calls the status reporting module of the interface unit and uses the QKD abnormal status reporting frame model in the status reporting module to send a request to the KM device. Then, the QKD abnormal status reporting response frame model in the module is used to start the monitoring service and wait for the response. After receiving the operating status report from Alice / Bob, the KM device will automatically forward it to the QKDNC for processing feedback, and the QKDNC will start the "QKD quantum key distribution policy clearing" process. After receiving the abnormal status reporting response frame returned by the QKDNC, the KM device returns the abnormal status reporting response frame to Alice / Bob. If Alice / Bob receives the QKD abnormal status reporting response frame model, it executes the "QKD quantum key distribution policy clearing" process. If it does not receive it, it uses the QKD abnormal status reporting frame model in the status reporting module to send a request to the KM device every 30 seconds.
[0142] In an embodiment of the present application, a network access request frame is sent to a key manager device. When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, a quantum key distribution policy request frame is sent to the key manager device to request the issuance of a quantum key distribution policy. Based on the quantum key distribution policy, a quantum key sequence is uploaded to the key manager device. After successful network access authentication with the key manager device, the present application generates and uploads a quantum key sequence based on the quantum key distribution policy issued by the key manager device, thereby enabling better interaction with the key manager. In addition, during the communication process, when a frame is received, the present application executes the action corresponding to the frame without waiting, thereby improving the real-time interaction with the key manager device.
[0143] join Figure 10 , which shows a real-time simulation software system for quantum key distribution provided in an embodiment of the present application, which includes: an interface display unit, an interface unit, a post-processing unit, a transmission unit, a quantum state unit, and a storage and management unit.
[0144] The interface display unit includes a system status monitoring module, a parameter configuration module, a key display and management module, a connection management module, and a visualization interface module. The system status monitoring module obtains qubit transmission rate, bit error rate, and key generation rate. The parameter configuration module configures optical system parameters, quantum parameters, and protocol parameters. Optical system parameters include free-space optical parameters such as telescope receiving aperture, transmission distance, atmospheric transmittance, detector efficiency, and background light parameters, as well as fiber optical parameters such as light distance, attenuation coefficient, internal transmittance, and normal-state photon signal ratio. Users can adjust these parameters to simulate optical signal reception, system performance calibration, and background light interference in different application scenarios. Quantum parameters include qubit length and polarization angle offset. Users can flexibly configure these parameters to meet data processing requirements and simulate quantum signal transmission and reception. Protocol parameters include error correction algorithms and security enhancement algorithms. These parameters are flexibly configured and scalable. The key display and management module provides key storage and export functions, displaying authentic keys to meet key storage and usage requirements. The connection management module features a dedicated start / stop quantum transmission button. Simply pressing this button allows you to start and stop the QKD quantum transmission simulation process. The page also provides options for selecting the Alice / Bob identity, allowing users to define their communication roles based on their needs. It also includes a target information configuration area for the connection, where users can accurately enter relevant information about the target communication node, such as the IP address and port number, to establish an accurate connection target, such as the KM device and the peer simulated QKD device. A dedicated connection information configuration interface is also provided. The visual interface module accurately displays the quantum bit transmission rate, bit error rate, and key generation rate, providing visual data feedback to help users understand system performance and efficiency.
[0145] The interface unit manages communication between the QKD system and the operator's KM equipment, ensuring that the simulated QKD can access the operator's quantum key distribution network. It includes a network authentication module, a heartbeat detection module, a quantum key distribution policy management module, a key transmission module, and a status reporting module. The network authentication module is responsible for the identity verification process when the QKD system joins the operator's quantum key distribution network, ensuring that only authorized devices can access the network. This module includes the QKD network access request frame model and the QKD network access response frame model. The heartbeat detection module periodically sends heartbeat detection messages to confirm the connection between the QKD device and the KM system is functioning properly. If no heartbeat response is received, a reconnection mechanism is triggered to ensure system stability. This module includes the heartbeat detection request frame model and the heartbeat detection response frame model. The quantum key distribution policy management module manages quantum key generation and distribution policies, including application, issuance, execution, and clearing of policies. This module includes the quantum key distribution policy application frame model, the quantum key distribution policy response frame model, the quantum key distribution policy clearing frame model, and the quantum key distribution policy clearing frame model. The transmission module is responsible for securely transmitting the quantum key generated by the QKD to the KM system, including the key encapsulation, transmission, and confirmation processes, including the key transmission frame model and the key transmission response frame model. The status reporting module reports the status information of the QKD device regularly or under abnormal circumstances, including the operating status and abnormal status, including the QKD operating status reporting frame model, the QKD operating status reporting response frame model, the QKD abnormal status reporting frame, and the QKD abnormal status reporting response frame.
[0146] The post-processing unit includes a basis alignment module, a key verification module, an error correction module, and a security enhancement module. The basis alignment module uses a classical channel to allow Alice and Bob to compare their chosen bases, retaining the measurement results for the same basis vectors to generate a shared key. This module includes: Bit Comparison Model 1: This module compares two binary bit sequences, assigning 1s to identical bits and 0s to different bits, and returns the comparison result. Bit Comparison Model 2: Based on the output of Bit Comparison Model 1, this module performs bit filtering on the key: bits corresponding to bits where the output of Bit Comparison Model 1 is 1 are retained, and bits corresponding to bits where the output of Bit Comparison Model 1 is 0 are deleted. The key verification module selects a portion of Bob's basis-aligned key and compares it with Alice's corresponding key to estimate the bit error rate. If the bit error rate exceeds 11%, the process is terminated; otherwise, error correction is performed. This module includes: A Bit Truncation Model: This module takes a bit sequence as input, extracts the last 10% as one segment, and the remaining first 90% as another segment, returning both segments. A Bit Error Rate Calculation Model: This module calculates the ratio of the number of different bits in two equal-length binary bit sequences to the total number of bits. In the error correction module, Alice and Bob use an error correction algorithm to correct key errors, reducing Bob's key error rate. Correction stops only when the error correction stop condition is reached. This module includes both the Cascade error correction algorithm model and the LDPC error correction algorithm model, and is scalable. The security enhancement module uses a hash function to compress the original key into a shorter key. Even if an eavesdropper obtains partial information, it is difficult to infer the final key content, thereby improving security. This module includes both the Pan-Hash algorithm model based on modular arithmetic and the Pan-Hash algorithm model based on binary matrix multiplication, and is scalable.
[0147] Cascade error correction algorithm model:
[0148] 1. Initialization
[0149] Input: Alice and Bob's respective key sequences K_A and K_B, both of length n;
[0150] Parameter setting: determine the number of error correction rounds N and group size m.
[0151] 2. First round of error correction
[0152] 2.1. Grouping and check code generation:
[0153] Alice divides her key sequence K_A into several groups according to group size m, generates a parity code for each group (i.e., the XOR result of all bits in the group), and sends the grouping scheme and parity code to Bob.
[0154] Bob groups his key sequence K_B into groups in the same way according to Alice's grouping scheme and calculates the parity code for each group.
[0155] 2.2. Comparison and error correction:
[0156] Bob compares the parity check code he calculated with the check code sent by Alice group by group.
[0157] If the checksums of a group are inconsistent, it means that there is an error in the group. Bob uses the binary search method to gradually narrow down the range of the error bit until the error bit is found and corrected.
[0158] Record the grouping plan and the corrected error locations.
[0159] 2.3. Binary Error Correction
[0160] Bob further divides the group with errors into two subgroups, each containing half the bits (padded with 0s for odd numbers). Bob calculates the parity codes for these two subgroups separately and sends the location of the error group and the parity code to Alice.
[0161] Alice locates the wrong group and divides the located group into two subgroups in the same way. She calculates the parity codes of the two subgroups and compares the parity codes she calculated with the parity codes sent by Bob. If the parity codes of a subgroup are inconsistent, it means that there is an error in the subgroup.
[0162] Alice continues to use the binary search method on the subgroup to gradually narrow the range of the error bit and repeats process 2.3 until the group size is 1 and the error bit is found.
[0163] 3. Subsequent rounds of error correction (round i, i=1, 2, ..., N)
[0164] 3.1. Grouping and check code generation:
[0165] Alice divides her key sequence K_A into several groups according to the group size m+i (if the group size is less than 0, it will be filled in). Other operations are the same as those in process 2.1.
[0166] 3.2. Associated historical groups:
[0167] Find all historical packets containing the current error bit, recorded as set M.
[0168] Select a group with the shortest length from the set M and use binary error correction on this group.
[0169] Record the corrected error bit position and update the set M.
[0170] 3.3, Iterative Error Correction:
[0171] If the set M is not empty, skip to step 3.1 until M is empty.
[0172] Ensure that each group's checksum eventually matches Alice's checksum.
[0173] 4. End Condition
[0174] The algorithm ends when there are no errors in this round or the set number of error correction rounds N is completed.
[0175] LDPC error correction algorithm model:
[0176] 1. Initialization
[0177] Input: Alice and Bob's respective key sequences K_A and K_B, both of length n.
[0178] Parameter setting: Determine the check matrix H (code rate and sparsity) and set the maximum number of iterations N.
[0179] 2. Verification code generation, transmission and comparison
[0180] Alice: Based on the preset sparse check matrix H, she calculates the check code S_A = H * (K_A)T of the key sequence K_A, and then sends the check matrix H and the check code S_A to Bob.
[0181] Bob receives the check matrix H and check code S_A from Alice. Based on the same check matrix H, he calculates the check code S_B = H*(K_A)T for his own key sequence K_B. He then compares the check code S_B with the check digit S_A bit by bit. If they are inconsistent, it means that there is an error in Bob's key sequence K_B.
[0182] 3. Iterative error correction
[0183] initialization:
[0184] Bob initializes the “soft information” (such as log-likelihood ratio, LLR) for each bit.
[0185] Iterative error correction update:
[0186] (1) For each inconsistent check bit, Bob determines the bit set involved in the check bit based on the structure of the check matrix H.
[0187] (2) In these sets of bits, Bob calculates the "soft information" of each bit and updates the bit value based on this information.
[0188] (3) The error correction process ends until the check codes S_A and S_B are consistent, or the preset maximum number of iterations N is reached.
[0189] Pan-binary hashing algorithm model based on modular arithmetic:
[0190] 1. Initialization
[0191] Input: A bit sequence x of length n.
[0192] Parameter setting: the length m of the compressed bit sequence.
[0193] 2. Random sequence generation
[0194] Generate two random bit sequences a and b of length n.
[0195] 3. Linear transformation calculation
[0196] Treating a, b, and x as binary integers, calculate a*x+b.
[0197] 4. Hash value extraction
[0198] Extract the subsequence from the nth to n-m+1th bits of the binary sequence a*x+b, and output a total of m bits as the result.
[0199] Pan-binary hashing algorithm model based on binary matrix multiplication:
[0200] 1. Initialization
[0201] Input: A bit sequence x of length n.
[0202] Parameter setting: the length m of the compressed bit sequence.
[0203] 2. Random sequence generation
[0204] Generates random bits s of length n-m+1.
[0205] 3. Constructing the Toeplitz Matrix
[0206] Construct the Toeplitz matrix T(s). For the sake of brevity, the matrix will not be described in detail here.
[0207] 4. Hash value extraction
[0208] Calculate T(s)*x, which is the m-bit output result.
[0209] The transmission unit includes: a classical channel module and a quantum channel module. The quantum channel module simulates quantum channel communication, and can select quantum channel physics models (free space / fiber / error simulation) to simulate real-world quantum channels. This module contains the following models: Quantum Channel Physics Model (Fiber): A fiber channel photon reception rate model. Quantum Channel Physics Model (Free Space): A free space channel photon reception rate model. Quantum Channel Physics Model (Error Simulation): Includes simulation of photon polarization state evolution modeling and bit error rate modeling. Photon Polarization State Transmission Model: A matrix data transmission program that uses classical TCP communication to simulate the four photon polarization state matrices prepared by the transmission photon polarization state preparation model. Photon Polarization State Reception Model: A matrix data reception program that uses classical TCP communication to simulate the four photon polarization state matrices prepared by the reception photon polarization state preparation model. The classical channel module simulates classical channel communication, simulating real-world classical communication channels through classical channel physics models. This module includes the following models: Classic channel physics model: adds latency, where latency = transmission latency (data size / channel bandwidth) + propagation latency (distance / propagation speed). Data transmission model: a classic TCP data transmission program. Data reception model: a classic TCP data reception program.
[0210] The quantum state unit includes: a quantum state preparation module and a quantum state detection module. The quantum state preparation module simulates the preparation and encoding of photon polarization states and includes the following models:
[0211] 1) Pseudo-random number model: Call the random number seed to generate a random bit sequence.
[0212] 2) Photon polarization state preparation model: Using the original key and a basis (such as the polarization basis {|0>, |1>} or the diagonal basis {|+>, |->}), the four (corresponding) polarization states of photons are prepared.
[0213] Right angle base:
[0214]
[0215] Diagonal basis:
[0216]
[0217]
[0218] The quantum state measurement module simulates the measurement and decoding of photon polarization states. This module includes the following models:
[0219] 1> Pseudo-random number model: call the random number seed to generate a random bit sequence.
[0220] 2> Photon polarization state measurement model: By measuring the measurement operator corresponding to the measurement basis, the transmitted skew-normal state is measured, and then the measured key is obtained.
[0221] The measuring operator of the rectangular basis is:
[0222]
[0223]
[0224] The measurement operator of the diagonal basis is:
[0225]
[0226]
[0227] For example, the quantum state is transmitted for:
[0228]
[0229] Among them, α, β are complex numbers and satisfy:
[0230]
[0231] If the chosen basis is a rectangular basis, measure the collapse The probability of being |0> is:
[0232]
[0233] Measuring collapse The probability of being |1> is:
[0234]
[0235] The storage and management unit includes a key storage and management module, a log storage and management module, and a configuration and management module. The configuration and management module includes a configuration file and a program for parsing the configuration. The QKD simulation system first reads the configuration file, which includes log configuration, quantum preparation configuration, free-space model parameter configuration, fiber channel model parameter configuration, error correction model parameters, and security enhancement model parameters. By modifying the configuration file, QKD simulations can be performed in various scenarios. The log storage and management module records communication logs, key generation logs, and error logs, and saves them locally as files. The key storage and management module stores and secures the keys generated by the QKD simulation system. The key is securely transmitted to the application layer via the interface unit.
[0236] See also Figure 11, which shows a processing device 40 for quantum key distribution real-time simulation software provided in an embodiment of the present application, applied to a device including a quantum communication party simulated by the real-time simulation software, the device 40 comprising:
[0237] A first sending module 401 is configured to send a network access request frame to a key manager device, wherein the network access request frame is used to request network access authentication with the key manager device;
[0238] The second sending module 402 is configured to send a quantum key distribution policy request frame to the key manager device when the network access response frame returned by the key manager device indicates that the network access authentication has been passed; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame;
[0239] The uploading module 403 is configured to receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
[0240] Optionally, the quantum key distribution strategy includes a quantum key upload duration; the upload module is specifically configured to:
[0241] When the quantum key sequence has been generated, determining a parameter value corresponding to a key upload rate-related item based on the quantum key upload duration; the key upload rate-related item is a parameter item in a configuration file of the real-time simulation software that affects the quantum key upload rate;
[0242] The key upload rate related item is modified to the corresponding parameter value, and the quantum key sequence is uploaded to the key manager device according to the key upload rate related item.
[0243] Optionally, the quantum key distribution strategy includes a quantum key upload duration; the upload module is specifically configured to:
[0244] In a case where the quantum key sequence is not generated, determining a parameter value corresponding to a key generation rate-related item and a parameter value corresponding to a key upload rate-related item based on the quantum key upload duration; the key generation rate-related item and the key upload rate-related item are, respectively, a parameter item affecting the quantum key generation rate and a parameter item affecting the quantum key upload rate in a configuration file of the real-time simulation software;
[0245] Modify the key generation rate related item to the parameter value corresponding to the key generation rate related item, and modify the key upload rate related item to the parameter value corresponding to the key upload rate related item;
[0246] generating the quantum key sequence according to the key generation rate-related term;
[0247] Upload the quantum key sequence to the key manager device according to the key upload rate related item.
[0248] Optionally, the upload module is specifically used to:
[0249] Encapsulating the quantum key sequence according to a preset transmission frame format;
[0250] Upload the encapsulated quantum key sequence to the key manager device according to the key upload rate related item.
[0251] Optionally, the network access request frame carries a device serial number; and the apparatus further includes:
[0252] a receiving module, configured to receive a network access response frame returned by the key manager device in response to the network access request frame;
[0253] A determination module is used to determine that the network access authentication is passed if the network access response frame carries a first identifier indicating success; wherein, if the device serial number carried in the network access request frame matches the device serial number of the key manager device, the key manager device returns a network access response frame carrying the first identifier.
[0254] Optionally, the second sending module is specifically configured to:
[0255] Sending a quantum key distribution policy request frame carrying a device serial number to the key manager device;
[0256] The upload module is specifically used to:
[0257] Receive a distribution response frame carrying the quantum key distribution policy sent by the key manager device; when the device serial number carried in the quantum key distribution policy request frame matches the device serial number of the key manager device, the key manager device returns a distribution response frame carrying the quantum key distribution policy.
[0258] Optionally, the device further includes:
[0259] A third sending module is configured to periodically send a heartbeat detection request frame to the key manager device;
[0260] The execution module is configured to re-execute the step of sending the network access request frame to the key manager device if no heartbeat detection response frame is received from the key manager device in response to the heartbeat detection request frame within a preset time period.
[0261] See also Figure 12 , which shows a processing device 50 of a quantum key distribution real-time simulation software provided by an embodiment of the present application, applied to a key manager device, the device 50 comprising:
[0262] A first receiving module 501 is configured to receive a network access request frame sent by a quantum communication party device, wherein the network access request frame is used to request network access authentication with the key manager device; the quantum communication party device is a quantum communication party device including a device simulated by the real-time simulation software;
[0263] A first processing module 502 is configured to return a network access response frame to the quantum communication party device in response to the network access request frame, and receive a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed;
[0264] The second processing module 503 is configured to issue a quantum key distribution policy to the quantum communication party device in response to the quantum key distribution policy request frame, and receive a quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution policy.
[0265] Optionally, the network access request frame carries a device serial number; and the first processing module is specifically configured to:
[0266] generating a network access response frame carrying a first identifier when the device serial number carried in the network access request frame matches the device serial number of the key manager device; the first identifier is used to indicate that the network access authentication has been passed;
[0267] generating a network access response frame carrying a second identifier when the device serial number carried in the network access request frame does not match the device serial number of the key manager device; the second identifier is used to indicate that the network access authentication has not been passed;
[0268] Send the network access response frame to the quantum communication party device.
[0269] Optionally, the quantum key distribution strategy request frame carries a device serial number; and the second processing module is specifically configured to:
[0270] When the device serial number carried in the quantum key distribution strategy request frame matches the device serial number of the key manager device, a distribution response frame carrying the quantum key distribution strategy is sent to the quantum communication party device.
[0271] Figure 13 This is a block diagram of an electronic device 600 according to an embodiment of the present application. Figure 13, electronic device 600 may include one or more of the following components: a processing component 602 , a memory 604 , a power component 606 , a multimedia component 608 , an audio component 610 , an input / output (I / O) interface 612 , a sensor component 614 , and a communication component 616 .
[0272] The processing component 602 generally controls the overall operation of the electronic device 600, such as operations associated with display, phone calls, data communications, camera operation, and recording operations. The processing component 602 may include one or more processors 620 to execute instructions to perform all or part of the steps of the above-described method. In addition, the processing component 602 may include one or more modules to facilitate interaction between the processing component 602 and other components. For example, the processing component 602 may include a multimedia module to facilitate interaction between the multimedia component 608 and the processing component 602.
[0273] The memory 604 is used to store various types of data to support operations on the electronic device 600. Examples of such data include instructions for any application or method operating on the electronic device 600, contact data, phone book data, messages, pictures, multimedia, etc. The memory 604 can be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0274] The power supply assembly 606 provides power to the various components of the electronic device 600. The power supply assembly 606 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 600.
[0275] The multimedia component 608 includes an interface that provides an output interface between the electronic device 600 and the user. In some embodiments, the interface may include a liquid crystal display (LCD) and a touch panel (TP). If the interface includes a touch panel, the interface may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensors can not only sense the demarcation of a touch or slide action, but also detect the duration and pressure associated with the touch or slide action. In some embodiments, the multimedia component 608 includes a front-facing camera and / or a rear-facing camera. When the electronic device 600 is in an operating mode, such as a capture mode or a multimedia mode, the front-facing camera and / or the rear-facing camera can receive external multimedia data. Each front-facing camera and the rear-facing camera can have a fixed optical lens system or have focal length and optical zoom capabilities.
[0276] The audio component 610 is used to output and / or input audio signals. For example, the audio component 610 includes a microphone (MIC) that is used to receive external audio signals when the electronic device 600 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals can be further stored in the memory 604 or transmitted via the communication component 616. In some embodiments, the audio component 610 also includes a speaker for outputting audio signals.
[0277] The input / output I / O interface 612 provides an interface between the processing component 602 and peripheral interface modules, such as a keyboard, a click wheel, buttons, etc. These buttons may include but are not limited to: a home button, a volume button, a start button, and a lock button.
[0278] The sensor assembly 614 includes one or more sensors for providing various aspects of status assessment for the electronic device 600. For example, the sensor assembly 614 can detect the open / closed state of the electronic device 600, the relative positioning of components, such as the display and keypad of the electronic device 600. The sensor assembly 614 can also detect changes in the position of the electronic device 600 or a component of the electronic device 600, the presence or absence of user contact with the electronic device 600, the orientation or acceleration / deceleration of the electronic device 600, and temperature changes of the electronic device 600. The sensor assembly 614 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 614 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 614 may also include an accelerometer, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0279] The communication component 616 is used to facilitate wired or wireless communication between the electronic device 600 and other devices. The electronic device 600 can access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G, or 5G), or a combination thereof. In an exemplary embodiment, the communication component 616 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 616 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0280] In an exemplary embodiment, the electronic device 600 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to implement a communication method for quantum key distribution real-time simulation software provided in an embodiment of the present application.
[0281] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 404 including instructions, which can be executed by a processor 420 of an electronic device 400 to perform the above method. For example, the non-transitory storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0282] Figure 14 is a block diagram of an electronic device 700 according to another embodiment of the present application. For example, the electronic device 700 may be provided as a server. Figure 14 The electronic device 700 includes a processing component 722, which further includes one or more processors, and a memory resource represented by a memory 732 for storing instructions executable by the processing component 722, such as an application. The application stored in the memory 732 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 722 is configured to execute instructions to perform a communication method for quantum key distribution real-time simulation software provided in an embodiment of the present application.
[0283] The electronic device 700 may further include a power supply component 726 configured to perform power management of the electronic device 700, a wired or wireless network interface 750 configured to connect the electronic device 700 to a network, and an input / output (I / O) interface 758. The electronic device 700 may operate based on an operating system stored in the memory 732, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or the like.
[0284] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the application disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0285] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for processing quantum key distribution real-time simulation software, characterized in that: Applied to a device including a quantum communication party simulated by the real-time simulation software, the method comprises: Sending a network access request frame to the key manager device, wherein the network access request frame is used to request network access authentication with the key manager device; When the network access response frame returned by the key manager device indicates that the network access authentication has been passed, sending a quantum key distribution policy request frame to the key manager device; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame; Receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
2. The method according to claim 1, characterized in that The quantum key distribution strategy includes the quantum key upload duration; In a case where the quantum key sequence has been generated, uploading the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution strategy includes: Determining a parameter value corresponding to a key upload rate-related item based on the quantum key upload duration; the key upload rate-related item is a parameter item in a configuration file of the real-time simulation software that affects the quantum key upload rate; The key upload rate related item is modified to the corresponding parameter value, and the quantum key sequence is uploaded to the key manager device according to the key upload rate related item.
3. The method according to claim 1, characterized in that The quantum key distribution strategy includes the quantum key upload duration; In a case where the quantum key sequence is not generated, uploading the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution strategy includes: Determining, based on the quantum key upload duration, a parameter value corresponding to a key generation rate-related item and a parameter value corresponding to a key upload rate-related item; the key generation rate-related item and the key upload rate-related item are, respectively, a parameter item affecting the quantum key generation rate and a parameter item affecting the quantum key upload rate in a configuration file of the real-time simulation software; Modify the key generation rate related item to the parameter value corresponding to the key generation rate related item, and modify the key upload rate related item to the parameter value corresponding to the key upload rate related item; generating the quantum key sequence according to the key generation rate-related term; Upload the quantum key sequence to the key manager device according to the key upload rate related item.
4. The method according to claim 2 or 3, characterized in that The uploading of the quantum key sequence to the key manager device according to the key upload rate related item includes: Encapsulating the quantum key sequence according to a preset transmission frame format; Upload the encapsulated quantum key sequence to the key manager device according to the key upload rate related item.
5. The method according to claim 1, wherein The network access request frame carries a device serial number; after sending the network access request frame to the key manager device, the method further includes: receiving a network access response frame returned by the key manager device in response to the network access request frame; If the network access response frame carries a first identifier indicating success, it is determined that the network access authentication is passed; wherein, if the device serial number carried in the network access request frame matches the device serial number of the key manager device, the key manager device returns a network access response frame carrying the first identifier.
6. The method according to claim 1, characterized in that The sending of a quantum key distribution policy request frame to the key manager device includes: sending a quantum key distribution policy request frame carrying a device serial number to the key manager device; The receiving the quantum key distribution policy issued by the key manager device includes: Receive a distribution response frame carrying the quantum key distribution policy sent by the key manager device; when the device serial number carried in the quantum key distribution policy request frame matches the device serial number of the key manager device, the key manager device returns a distribution response frame carrying the quantum key distribution policy.
7. The method according to claim 1, characterized in that The method further comprises: Periodically sending a heartbeat detection request frame to the key manager device; If the heartbeat detection response frame returned by the key manager device in response to the heartbeat detection request frame is not received within the preset time period, the step of sending the network access request frame to the key manager device is performed again.
8. A method for processing quantum key distribution real-time simulation software, characterized in that: Applied to a key manager device, the method includes: receiving a network access request frame sent by a quantum communication party device, the network access request frame being used to request network access authentication with the key manager device; the quantum communication party device being a quantum communication party device simulated by the real-time simulation software; In response to the network access request frame, returning a network access response frame to the quantum communication party device, and receiving a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed; In response to the quantum key distribution strategy request frame, the quantum key distribution strategy is sent to the quantum communication party device, and the quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution strategy is received.
9. The method according to claim 8, characterized in that The network access request frame carries a device serial number; and in response to the network access request frame, returning a network access response frame to the quantum communication party device includes: generating a network access response frame carrying a first identifier when the device serial number carried in the network access request frame matches the device serial number of the key manager device; the first identifier is used to indicate that the network access authentication has been passed; generating a network access response frame carrying a second identifier when the device serial number carried in the network access request frame does not match the device serial number of the key manager device; the second identifier is used to indicate that the network access authentication has not been passed; Send the network access response frame to the quantum communication party device.
10. The method according to claim 8, characterized in that The quantum key distribution strategy request frame carries a device serial number; and in response to the quantum key distribution strategy request frame, issuing a quantum key distribution strategy to the quantum communication party device includes: When the device serial number carried in the quantum key distribution strategy request frame matches the device serial number of the key manager device, a distribution response frame carrying the quantum key distribution strategy is sent to the quantum communication party device.
11. A processing device for quantum key distribution real-time simulation software, characterized in that: Applicable to a device including a quantum communication party simulated by the real-time simulation software, the device comprising: A first sending module is configured to send a network access request frame to a key manager device, wherein the network access request frame is used to request network access authentication with the key manager device; a second sending module, configured to send a quantum key distribution policy request frame to the key manager device when the network access response frame returned by the key manager device indicates that the network access authentication has been passed; the key manager device is configured to issue a quantum key distribution policy in response to the quantum key distribution policy request frame; An uploading module is configured to receive the quantum key distribution policy issued by the key manager device, and upload the quantum key sequence generated by the quantum communication party to the key manager device based on the quantum key distribution policy.
12. The device according to claim 11, characterized in that The quantum key distribution strategy includes the quantum key upload duration; the upload module is specifically used to: When the quantum key sequence has been generated, determining a parameter value corresponding to a key upload rate-related item based on the quantum key upload duration; the key upload rate-related item is a parameter item in a configuration file of the real-time simulation software that affects the quantum key upload rate; The key upload rate related item is modified to the corresponding parameter value, and the quantum key sequence is uploaded to the key manager device according to the key upload rate related item.
13. The device according to claim 11, characterized in that The quantum key distribution strategy includes the quantum key upload duration; the upload module is specifically used to: If the quantum key sequence is not generated, determining, based on the quantum key upload duration, a parameter value corresponding to a key generation rate-related item and a parameter value corresponding to a key upload rate-related item; The key generation rate related item and the key upload rate related item are, respectively, parameter items affecting the quantum key generation rate and the quantum key upload rate in the configuration file of the real-time simulation software; Modify the key generation rate related item to the parameter value corresponding to the key generation rate related item, and modify the key upload rate related item to the parameter value corresponding to the key upload rate related item; generating the quantum key sequence according to the key generation rate-related term; Upload the quantum key sequence to the key manager device according to the key upload rate related item.
14. The device according to claim 12 or 13, characterized in that The upload module is specifically used to: Encapsulating the quantum key sequence according to a preset transmission frame format; Upload the encapsulated quantum key sequence to the key manager device according to the key upload rate related item.
15. The device according to claim 11, characterized in that The network access request frame carries a device serial number; the apparatus further includes: a receiving module, configured to receive a network access response frame returned by the key manager device in response to the network access request frame; A determination module is used to determine that the network access authentication is passed if the network access response frame carries a first identifier indicating success; wherein, if the device serial number carried in the network access request frame matches the device serial number of the key manager device, the key manager device returns a network access response frame carrying the first identifier.
16. The device according to claim 11, characterized in that The second sending module is specifically configured to: Sending a quantum key distribution policy request frame carrying a device serial number to the key manager device; The upload module is specifically used to: Receive a distribution response frame carrying the quantum key distribution policy sent by the key manager device; when the device serial number carried in the quantum key distribution policy request frame matches the device serial number of the key manager device, the key manager device returns a distribution response frame carrying the quantum key distribution policy.
17. The device according to claim 11, characterized in that The device further comprises: A third sending module is configured to periodically send a heartbeat detection request frame to the key manager device; The execution module is configured to re-execute the step of sending the network access request frame to the key manager device if no heartbeat detection response frame is received from the key manager device in response to the heartbeat detection request frame within a preset time period.
18. A processing device for quantum key distribution real-time simulation software, characterized in that: Applied to a key manager device, the apparatus comprises: A first receiving module is configured to receive a network access request frame sent by a quantum communication party device, wherein the network access request frame is used to request network access authentication with the key manager device; the quantum communication party device is a quantum communication party device including a device simulated by the real-time simulation software; A first processing module is configured to return a network access response frame to the quantum communication party device in response to the network access request frame, and receive a quantum key distribution strategy request frame sent by the quantum communication party device when the network access response frame indicates that the network access authentication has been passed; The second processing module is configured to issue a quantum key distribution policy to the quantum communication party device in response to the quantum key distribution policy request frame, and receive a quantum key sequence uploaded by the quantum communication party device to the key manager device based on the quantum key distribution policy.
19. The device according to claim 18, characterized in that The network access request frame carries a device serial number; the first processing module is specifically configured to: generating a network access response frame carrying a first identifier when the device serial number carried in the network access request frame matches the device serial number of the key manager device; the first identifier is used to indicate that the network access authentication has been passed; generating a network access response frame carrying a second identifier when the device serial number carried in the network access request frame does not match the device serial number of the key manager device; The second identifier is used to indicate that the network access authentication has not been passed; Send the network access response frame to the quantum communication party device.
20. The device according to claim 18, wherein The quantum key distribution strategy request frame carries a device serial number; the second processing module is specifically configured to: When the device serial number carried in the quantum key distribution strategy request frame matches the device serial number of the key manager device, a distribution response frame carrying the quantum key distribution strategy is sent to the quantum communication party device.
21. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method according to any one of claims 1 to 10 are implemented.
22. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
Quantum secret communication application security test method, system, device and medium
CN119696813A
KR20230027721A