Communication processing method and device based on quantum key distribution, equipment and medium
By monitoring the network bandwidth in real time and dynamically adjusting the quantum key distribution rate and shard size, combining differential processing and entropy parameter adjustment, the applicability of quantum key distribution technology in low bandwidth and bandwidth unstable scenarios is solved, and the secure communication needs of low bandwidth devices are achieved.
Patent Information
- Application Number
- CN202510578401.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-08-12
AI Technical Summary
Quantum key distribution technology has high requirements for transmission environments and is difficult to be applied to low-bandwidth devices and unstable bandwidth scenarios, and cannot meet the needs of low-bandwidth devices such as the Internet of Things and RedCap devices.
Through the bandwidth adaptation module, the network bandwidth is monitored in real time, the quantum key distribution rate and shard size are dynamically adjusted, and the compression algorithm is combined with differential processing and entropy parameter adjustment, and only the key change part is transmitted to realize differential update of the quantum key, adapting to low bandwidth and bandwidth fluctuations scenarios.
It realizes the applicability of quantum key distribution technology in low bandwidth and bandwidth unstable scenarios, reduces bandwidth usage and resource consumption, and meets application scenarios such as the Internet of Things, smart cities, and telemedicine.
Smart Images

Figure CN120474696A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication processing method, apparatus, device, and medium based on quantum key distribution. Background Art
[0002] Quantum Key Distribution (QKD) is a cryptographic technology based on the principles of quantum mechanics, used to securely distribute a shared secret key between two legitimate communicating parties. Its core features leverage the non-cloning properties of quantum states and the measurement collapse effect to ensure unconditional security of key distribution. Any third-party eavesdropping will introduce detectable perturbations, enabling both communicating parties to detect and mitigate potential security threats.
[0003] However, quantum key distribution technology takes up a large amount of payload and has frequent communication interactions, which places high demands on the transmission environment. It is suitable for high-bandwidth device scenarios, but it is difficult to meet the demand for quantum key distribution technology in low-bandwidth device scenarios such as IoT nodes and RedCap devices, or scenarios with unstable bandwidth. Summary of the Invention
[0004] The embodiments of the present application provide a communication processing method, apparatus, device, and medium based on quantum key distribution, which can meet the needs of quantum key distribution technology in low-bandwidth device scenarios and scenarios with unstable bandwidth.
[0005] In a first aspect, an embodiment of the present application provides a communication processing method based on quantum key distribution, including: obtaining a bandwidth state value at a current moment based on a bandwidth measurement value obtained at the current moment and a bandwidth measurement value before the current moment through a bandwidth adaptation module; obtaining a quantum key distribution rate at a current moment based on the bandwidth state value at the current moment, an existing quantum key compression fragment size, and a maximum quantum key distribution rate through the bandwidth adaptation module, wherein the quantum key distribution rate at a current moment matches the bandwidth state value at a current moment; and distributing quantum key compression fragments of a quantum key to a target device according to the quantum key distribution rate at a current moment through the quantum key distribution module.
[0006] In some possible implementations, obtaining a bandwidth status value at the current moment based on the bandwidth measurement value obtained at the current moment and the bandwidth measurement values within a time period before the current moment includes: sliding a preset time window within the obtained bandwidth measurement value according to a preset sliding step size, where the sliding time window includes the bandwidth measurement value at the current moment and the previous bandwidth measurement values; and obtaining the bandwidth status value at the current moment using a weighted algorithm based on the bandwidth status value at the previous moment and the bandwidth measurement value at the current moment, where the bandwidth status value at the previous moment is obtained based on the bandwidth measurement value within the time window after the previous sliding.
[0007] In some possible implementations, the method further includes: obtaining, by a bandwidth adaptation module, a bandwidth fluctuation value based on a bandwidth state value at a current moment and a bandwidth state value at a previous moment;
[0008] The method comprises: obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression shard size, and the maximum quantum key distribution rate, including: in response to the bandwidth fluctuation value exceeding the fluctuation threshold range, obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression shard size, and the maximum quantum key distribution rate.
[0009] In some possible implementations, obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression shard size, and the maximum quantum key distribution rate includes: obtaining a candidate quantum key distribution rate according to the bandwidth state value at the current moment and the existing quantum key compression shard size; and obtaining the smaller of the candidate quantum key distribution rate and the maximum quantum key distribution rate as the quantum key distribution rate at the current moment.
[0010] In some possible implementations, after obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate through the bandwidth adaptation module, the method further includes: determining the quantum key compression fragment size at the current moment based on the quantum key distribution rate at the current moment and the bandwidth state value at the current moment, so that the quantum key compression fragment size at the current moment matches the quantum key distribution rate at the current moment; or, determining the existing quantum key compression fragment size as the quantum key compression fragment size at the current moment.
[0011] In some possible implementations, the method further includes: in the case of a quantum key update, performing a differential operation on the original quantum key and the updated quantum key through a differential processing module to obtain differential data; obtaining an entropy parameter of the differential data through the differential processing module, and compressing the differential data according to the entropy parameter to obtain compressed differential data; and distributing the compressed differential data to a target device through a quantum key distribution module.
[0012] In some possible implementations, the differential data is compressed according to an entropy parameter to obtain compressed differential data, including: if the entropy parameter is greater than or equal to a preset entropy threshold, the differential data is compressed using a lossless compression algorithm to obtain compressed differential data; if the entropy parameter is less than the preset entropy threshold, the differential data is compressed using a lossy compression algorithm to obtain compressed differential data.
[0013] In some possible implementations, the method further includes: dividing the business plaintext data into multiple plaintext data segments through a communication encryption module, and encrypting each plaintext data segment using a quantum key to obtain an encrypted data segment; transmitting the encrypted data segment and the integrity check value corresponding to the encrypted data segment through a secure encrypted channel through the communication encryption module, and the integrity check value is used to perform integrity verification on the encrypted data segment.
[0014] In some possible implementations, the method further includes at least one of the following: detecting, through a security verification module, whether an update interval of the quantum key is greater than an allowed update interval threshold; in response to the update interval of the quantum key being greater than the allowed update interval threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting, through the security verification module, whether an entropy parameter of the differential data is less than a minimum entropy threshold; in response to the entropy parameter of the differential data being less than the minimum entropy threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting, through the security verification module, whether the size of the differential data is greater than a maximum value allowed for the data; in response to the size of the differential data being greater than the maximum value allowed for the data, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key.
[0015] In a second aspect, an embodiment of the present application provides a communication processing device based on quantum key distribution, including: a bandwidth adaptation module, used to obtain a bandwidth state value at the current moment based on the acquired bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment, and to obtain a quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, an existing quantum key compression fragment size and a maximum quantum key distribution rate, wherein the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment; a quantum key distribution module, used to distribute quantum key compression fragments of the quantum key to the target device according to the quantum key distribution rate at the current moment.
[0016] In a third aspect, an embodiment of the present application provides a communication processing device based on quantum key distribution, comprising: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the communication processing method based on quantum key distribution of the first aspect.
[0017] In a fourth aspect, an embodiment of the present application provides a communication processing system based on quantum key distribution, including: a bandwidth adaptation device, used to obtain a bandwidth state value at the current moment based on the acquired bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment, and to obtain a quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, an existing quantum key compression fragment size and a maximum quantum key distribution rate, wherein the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment; a quantum key distribution device, used to distribute quantum key compression fragments of the quantum key to a target device through a quantum key distribution module according to the quantum key distribution rate at the current moment; a target device, used to receive the quantum key compression fragments, restore the quantum key according to the quantum key compression fragments, and use the quantum key to encrypt business plaintext data to transmit the encrypted data.
[0018] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the communication processing method based on quantum key distribution of the first aspect is implemented.
[0019] In a sixth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the communication processing method based on quantum key distribution in the first aspect.
[0020] The embodiments of the present application provide a communication processing method, apparatus, device, and medium based on quantum key distribution. These methods can obtain a current bandwidth status value that more accurately reflects the current network bandwidth status trend based on the current bandwidth measurement value and bandwidth measurement values obtained by real-time monitoring. Based on the current bandwidth status value, the existing quantum key compression fragment size, and the maximum quantum key distribution rate, a current quantum key distribution rate that is less than or equal to the maximum quantum key distribution rate and matches the current network status trend can be obtained. The current quantum key distribution speed matches the current bandwidth status value that characterizes the current network bandwidth status trend. That is, the quantum key distribution speed can be adjusted based on the current network bandwidth status, making the quantum key distribution technology applicable to various network bandwidth conditions. In addition to high-bandwidth device scenarios, it can also be applied to low-bandwidth device scenarios and scenarios with unstable bandwidth, thereby meeting the demand for quantum key distribution technology in low-bandwidth device scenarios and scenarios with unstable bandwidth. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0022] Figure 1 A schematic diagram of an example of an application architecture of a communication processing method for quantum key distribution provided in an embodiment of the present application;
[0023] Figure 2 A flowchart of a communication processing method for quantum key distribution provided in one embodiment of the present application;
[0024] Figure 3 A schematic diagram of an example of a bandwidth status value evaluation process provided in an embodiment of the present application;
[0025] Figure 4 A schematic diagram of an example of a process for adjusting the quantum key distribution rate provided in an embodiment of the present application;
[0026] Figure 5 A schematic diagram of an example of a quantum key update process provided in an embodiment of the present application;
[0027] Figure 6 A schematic diagram of an example of an end-to-end data transmission process provided in an embodiment of the present application;
[0028] Figure 7 A schematic diagram of an example of a security verification process provided in an embodiment of the present application;
[0029] Figure 8 A schematic diagram of the structure of a communication processing device for quantum key distribution provided in one embodiment of the present application;
[0030] Figure 9 A schematic structural diagram of a communication processing device for quantum key distribution provided in another embodiment of the present application;
[0031] Figure 10 A schematic diagram of the structure of a communication processing device based on quantum key distribution provided in one embodiment of the present application;
[0032] Figure 11 A schematic diagram of the structure of a communication processing system based on quantum key distribution provided in one embodiment of the present application;
[0033] Figure 12 A schematic structural diagram of a communication processing system based on quantum key distribution provided in another embodiment of the present application. DETAILED DESCRIPTION
[0034] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.
[0035] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.
[0036] Quantum key distribution (QKD) is a cryptographic technology based on the principles of quantum mechanics, used to securely distribute a shared secret key between two legitimate communicating parties. Its core feature is the unconditional security of key distribution, leveraging the non-cloning properties of quantum states and the measurement collapse effect. Any eavesdropping by a third party introduces detectable perturbations, enabling both communicating parties to detect and mitigate potential security threats. However, QKD technology consumes a large payload and involves frequent communication interactions, placing high demands on the transmission environment and relying on complex processing algorithms. It is suitable for high-bandwidth and high-power devices, but is not user-friendly for low-bandwidth, unstable bandwidth, or low-power scenarios in areas such as the Internet of Things, smart cities, and telemedicine, making it difficult to meet the needs of low-bandwidth, low-power device scenarios.
[0037] The present application provides a communication processing method, apparatus, device, system, medium, and program product based on quantum key distribution, which can monitor network status in real time and dynamically adjust the quantum key distribution rate, adapting to low-bandwidth device scenarios and bandwidth fluctuation scenarios, and meeting the needs of low-bandwidth device scenarios and bandwidth fluctuation scenarios for quantum key distribution technology. It can also refer to the differential update mechanism of quantum keys, only transmitting the changing part of the key to reduce bandwidth usage during the update process, further reducing the bandwidth required for quantum key distribution, and meeting the needs of low-bandwidth device scenarios and bandwidth fluctuation scenarios. After the quantum key is distributed, the quantum key can be used to achieve full-link encryption of the data, ensuring the integrity and security of the transmitted data. It is suitable for low-bandwidth, high-privacy application scenarios such as the Internet of Things, smart cities, and telemedicine.
[0038] To facilitate understanding, the system architecture involved in the communication processing method for quantum key distribution provided in this application is briefly described here. Figure 1 A schematic diagram of an example of an application architecture of a communication processing method for quantum key distribution provided in an embodiment of the present application is shown as follows: Figure 1 As shown, the application architecture may include a quantum key distribution module 11, a bandwidth adaptation module 12, a differential processing module 13, a communication encryption module 14, a security verification module 15 and a data transmission and verification module 16.
[0039] The quantum key distribution module 11 is used to generate random quantum keys through a quantum channel and distribute them to target devices, which may include data transmitters and receivers for communication. The bandwidth adaptation module 12 can monitor network bandwidth in real time and dynamically adjust the quantum key distribution rate and update interval, as well as the size of the quantum key fragments used for distribution. The differential processing module 13 can perform differential processing on the updated quantum key, reducing bandwidth requirements by transmitting only the changed portion of the quantum key. The communication encryption module 14 can perform segmented encryption and add integrity check values to the data to be encrypted, ensuring the security of the entire transmission link. The security verification module 15 can ensure the security of the entire system through one or more verifications, including update interval verification, entropy value verification, and differential data size verification. The data transmission and verification module 16 can verify the encrypted data. Verification may include whether the encrypted data has been received by the data receiver, integrity verification, etc., but this is not limited here. The data transmission and verification module 16 can feedback the verification results to the quantum key distribution module 11, allowing the quantum key distribution module 11 to adjust the quantum key distribution rate and / or retransmit the quantum key.
[0040] The quantum key distribution module 11, bandwidth adaptation module 12, differential processing module 13, communication encryption module 14, security verification module 15 and data transmission and verification module 16 can be integrated in the same device to perform the communication processing method of quantum key distribution, or they can be distributed in multiple devices to perform the communication processing method of quantum key distribution in a systematic manner and are mutually related. This is not limited here. For example, the quantum key distribution module 11 and the bandwidth adaptation module 12 can be integrated into one device, or the two can be independently set in different devices; the differential processing module 13 can be integrated with the quantum key distribution module 11 in one device, or integrated with the communication encryption module 14 in one device, or can be independently set in one device; the communication encryption module 14 can be set in a target device that receives the quantum key distributed by the quantum key distribution module 11. Specifically, the target device where the communication encryption module 14 is located can be a data sending end; the security verification module 15 can be integrated with the quantum key distribution module 11 in the same device, or can be integrated with the differential processing module 13 in the same device, or can be independently set in one device; the data transmission and verification module 16 can be set in the target device that receives the quantum key distributed by the quantum key distribution module 11. Specifically, the target device where the data transmission and verification module 16 is located can be a data receiving end.
[0041] The communication processing method, device, equipment, system, medium and program product for quantum key distribution provided in this application are described below.
[0042] The present application provides a communication processing method for quantum key distribution, which can be applied to the application architecture in the above embodiments. For specific content, please refer to the relevant description in the above embodiments and will not be repeated here. Figure 2 This is a flow chart of a communication processing method for quantum key distribution provided in one embodiment of the present application, as shown in FIG. Figure 2 As shown, the communication processing method of quantum key distribution may include steps S201 to S203.
[0043] In step S201, the bandwidth state value at the current moment is obtained by the bandwidth adaptation module according to the obtained bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment.
[0044] Bandwidth measurements are collected periodically in real time. These values are the actual measured bandwidth values. Bandwidth measurements are stored for each preset period up to the current time. As time passes, these values change. Each time a new bandwidth value is recorded, the oldest value in the stored bandwidth values is deleted.
[0045] The bandwidth measurement value within the preset time period includes the bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment. The bandwidth measurement value before the current moment can reflect the most recent historical trend of the bandwidth. The most recent historical trend of the bandwidth can be obtained through the bandwidth measurement value before the current moment, and then the bandwidth status at the current moment is evaluated based on the most recent historical trend of the bandwidth and the bandwidth measurement value at the current moment to obtain the bandwidth status value at the current moment. The bandwidth status value at the current moment is the result of a smoothing process, which can reduce the instantaneous fluctuation and noise influence of the bandwidth measurement. Compared with the instantaneous value of the bandwidth measurement value at the current moment, the bandwidth status value at the current moment can more accurately reflect the network bandwidth status trend at the current moment. In some examples, the bandwidth status value at the current moment can be obtained by a weighted average algorithm based on the bandwidth measurement value within the preset time period up to the current moment (including the bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment).
[0046] In step S202, the bandwidth adaptation module obtains the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size and the maximum quantum key distribution rate.
[0047] After generating a quantum key, the quantum key can be fragmented and compressed to obtain compressed quantum key fragments. Distributing the quantum key to a target device is specifically implemented by distributing the compressed quantum key fragments to the target device. The quantum key compression fragment size is the size of the compressed quantum key fragment, which can be measured in bits. The quantum key distribution rate is the rate at which the quantum key is distributed to the target device, which can be measured in fragments per second. The maximum quantum key distribution rate is the maximum quantum key distribution rate supported by the system. The bandwidth state value, quantum key compression fragment size, and quantum key distribution rate are associated with each other; knowing any two of them can determine the remaining one. The quantum key compression fragment size can be adjusted or maintained unchanged. The existing quantum key compression fragment size can be the initially set quantum key compression fragment size or the quantum key compression fragment size obtained after the last adjustment. If the quantum key distribution rate is less than or equal to the maximum quantum key distribution rate, the current quantum key distribution rate, which is less than or equal to the maximum quantum key distribution rate, can be determined based on the relationship between the current bandwidth state value, the existing quantum key compression fragment size, and the quantum key distribution rate.
[0048] In some embodiments, the quantum key compression shard size at the current moment may be the same as or different from the existing quantum key compression shard size. In some examples, the quantum key compression shard size at the current moment matches the quantum key distribution rate at the current moment, and the quantum key compression shard size at the current moment can be determined based on the quantum key distribution rate at the current moment. Specifically, the quantum key compression shard size at the current moment can be determined based on the quantum key distribution rate at the current moment and the bandwidth state value at the current moment. For example, the quantum key compression shard size at the current moment can be determined as the ratio of the bandwidth state value at the current moment to the quantum key distribution rate at the current moment. Matching the quantum key compression shard size at the current moment with the quantum key distribution rate at the current moment can further improve the flexibility of quantum key distribution and its adaptability to various network bandwidths. In other examples, the existing quantum key compression shard size is determined as the quantum key compression shard size at the current moment, that is, the quantum key compression shard size remains unchanged.
[0049] In step S203, the quantum key compression fragments of the quantum key are distributed to the target device through the quantum key distribution module according to the quantum key distribution rate at the current moment.
[0050] The generated quantum key is split and compressed to obtain quantum key compression fragments that match the size of the quantum key compression fragments. These quantum key compression fragments are then distributed to the target device at the current quantum key distribution rate. The target device is a device that needs to use the quantum key to encrypt or decrypt business data. The target device can restore the quantum key from the received quantum key compression fragments and use the quantum key to encrypt or decrypt business data. For example, the target device may include a data transmitter and a data receiver. The data transmitter can encrypt business data using the quantum key to obtain encrypted data, and then send the encrypted data to the data receiver. The data receiver then decrypts the received encrypted data using the quantum key to obtain the business data.
[0051] In an embodiment of the present application, a bandwidth state value at the current moment that more accurately reflects the current network bandwidth status trend can be obtained based on the bandwidth measurement value at the current moment obtained by real-time monitoring and the bandwidth measurement value before the current moment. Based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate, a quantum key distribution rate at the current moment that is less than or equal to the maximum quantum key distribution rate and matches the current network status trend can be obtained. The quantum key distribution speed at the current moment matches the bandwidth state value at the current moment that can represent the current network bandwidth status trend. That is, the quantum key distribution speed can be adjusted according to the current network bandwidth status, making the quantum key distribution technology applicable to various network bandwidth conditions. In addition to high-bandwidth device scenarios, it can also be applied to low-bandwidth device scenarios and scenarios with unstable bandwidth, thereby meeting the needs of low-bandwidth device scenarios and scenarios with unstable bandwidth for quantum key distribution technology. The quantum key distribution rate is adjusted based on the bandwidth state value, and the matching of the quantum key distribution rate and the bandwidth state value is adjusted more simply, realizing a lightweight authentication process and protocol design, which can reduce resource overhead in the authentication and communication process, and make quantum key distribution technology applicable to low-power devices, meeting the demand for quantum key distribution technology in low-power device scenarios.
[0052] In some embodiments, the current bandwidth status value can be obtained by combining a time window with an exponentially weighted moving average (EWMA) algorithm. Specifically, the bandwidth adaptation module can slide a preset time window within the acquired bandwidth measurement value according to a preset sliding step size; and use a weighted algorithm based on the bandwidth status value at the previous moment and the bandwidth measurement value at the current moment to obtain the current bandwidth status value.
[0053] The duration of the time window can be the preset duration described in the above embodiment. The sliding step size can be one bandwidth measurement value. The time window can be slid once according to the sliding step size each time the bandwidth measurement value at the current moment is obtained. Each time the time window is slid, the first bandwidth measurement value in the time window before the sliding is removed and the bandwidth measurement value at the current moment is moved in. The time window after the sliding includes the bandwidth measurement value at the current moment and the previous bandwidth measurement value. The number of bandwidth measurement values in the time window should be greater than or equal to 2. The specific number can be set based on the scenario, requirements, experience, etc. and is not limited here. The bandwidth status value at each moment can be derived based on the bandwidth measurement value at the current moment and the bandwidth measurement value before the current moment. The bandwidth measurement value before the current moment here can include the bandwidth measurement value before the current moment within the time window and the bandwidth measurement value before the current moment outside the time window. The bandwidth status value at the previous moment is derived based on the bandwidth measurement value within the time window after the previous sliding. The bandwidth measurement value at the current moment and the bandwidth status value at the previous moment each have corresponding weighting factors, and the sum of the weighting factors of the bandwidth measurement value at the current moment and the bandwidth status value at the previous moment is 1. For example, the bandwidth status value at the current moment can be calculated according to the following formula (1):
[0054] BW t =α·BW current +(1-α)BW previous (1)
[0055] Among them, BW t BW is the bandwidth status value at the current moment; current BW is the bandwidth measurement value at the current moment; previous is the bandwidth status value at the previous moment; α is the weight factor of the bandwidth measurement value at the current moment, and the value of α can be in the range of 0.2 to 0.5; 1-α is the weight factor of the bandwidth status value at the previous moment.
[0056] The bandwidth status value at the current moment obtained by combining the time window with the exponentially weighted moving average algorithm can more accurately reflect the network bandwidth status trend at the current moment relative to the instantaneous value of the bandwidth measurement value at the current moment. The quantum key distribution rate at the current moment and the quantum key compression fragment size at the current moment obtained based on the bandwidth status value at the current moment match the network bandwidth status trend at the current moment and can adapt to more variable bandwidth scenarios.
[0057] In some embodiments, bandwidth stability can be determined based on bandwidth status values at different times. If the bandwidth is unstable, adjustments to the quantum key distribution rate and quantum key compression fragment size are triggered. Specifically, the bandwidth adaptation module can determine a bandwidth fluctuation value based on the current bandwidth status value and the bandwidth status value at the previous moment. In response to the bandwidth fluctuation value exceeding a fluctuation threshold, the module can determine the current quantum key distribution rate based on the current bandwidth status value, the existing quantum key compression fragment size, and the maximum quantum key distribution rate.
[0058] The bandwidth fluctuation value can be the difference between the bandwidth status value at the previous moment and the bandwidth status value at the current moment. The fluctuation threshold range can be a stable fluctuation range. The specific value of the fluctuation threshold range can be determined based on the scenario, requirements, experience, etc. If the bandwidth fluctuation value is within the fluctuation threshold range, the bandwidth is stable and there is no need to adjust the quantum key distribution rate or quantum key compression fragment size. If the bandwidth fluctuation value exceeds the fluctuation threshold range, it indicates that the bandwidth is unstable. To make quantum key distribution technology suitable for unstable bandwidth, the quantum key distribution rate needs to be adjusted to minimize resource consumption while matching the quantum key distribution rate with the bandwidth status.
[0059] In other embodiments, there is no need to trigger the adjustment of the quantum key distribution rate based on the bandwidth fluctuation value. The quantum key distribution rate can be adjusted in real time based on the current bandwidth state value, the existing quantum key compression fragment size and the maximum quantum key distribution rate.
[0060] For example, Figure 3 A schematic diagram of an example of a bandwidth status value evaluation process provided in an embodiment of the present application is shown as follows: Figure 3 As shown, the evaluation process of the bandwidth status value may include steps a1 to a10.
[0061] In step a1, the bandwidth history record is initialized. When the system starts, a time window can be initialized to record the collected bandwidth measurement values for subsequent estimation calculations.
[0062] In step a2, the bandwidth measurement value at the current moment is collected in real time. Specifically, the bandwidth measurement value at the current moment can be collected regularly from the network monitoring module.
[0063] In step a3, the time window is slid to update the data within the time window. Based on the fixed-size time window, the bandwidth measurement value within the time window is updated, the earliest bandwidth measurement value within the time window is removed, and the most recently collected bandwidth measurement value is added.
[0064] In step a4, the bandwidth status value at the current moment is calculated. The specific calculation process can be found in the relevant description of the above embodiment and will not be repeated here.
[0065] In step a5, bandwidth stability is determined. The bandwidth status value at the current moment can be compared with the bandwidth status value at the previous moment (which can represent a historical trend) to obtain a bandwidth fluctuation value, thereby determining whether the bandwidth is stable. If the bandwidth fluctuation value exceeds the fluctuation threshold, the bandwidth is determined to be unstable and step a6 is executed. If the bandwidth fluctuation value is within the fluctuation threshold, the bandwidth is determined to be stable and step a7 is executed.
[0066] In step a6, the bandwidth fluctuation event is recorded, and then step a7 is performed.
[0067] In step a7, the bandwidth status value at the current moment is updated.
[0068] In step a8, determine whether triggering adjustment is required. This adjustment refers to the adjustment of the quantum key distribution rate and the quantum key compression fragment size. If triggering is required, proceed to step a9; if not, proceed to step a10.
[0069] In step a9, the quantum key distribution rate is adjusted. While adjusting the quantum key distribution rate, the quantum key compression fragment size can also be adjusted, and then step a10 is executed.
[0070] In step a10 , the evaluation of the bandwidth status value is completed.
[0071] The specific contents of the above steps a1 to a10 can be found in the relevant descriptions in the embodiments of the present application and will not be repeated here.
[0072] In some embodiments, the bandwidth adaptation module can obtain a candidate quantum key distribution rate based on the bandwidth state value at the current moment and the existing quantum key compression fragment size; and obtain the smaller of the candidate quantum key distribution rate and the maximum quantum key distribution rate as the quantum key distribution rate at the current moment.
[0073] The ratio of the bandwidth state value at the current moment to the size of the existing quantum key compression fragment can be calculated first, and this ratio can be used as the candidate quantum key distribution rate. Since the maximum quantum key distribution rate is the maximum rate that the performance of the entire system can support, the quantum key distribution rate at the current moment should be less than or equal to the maximum quantum key distribution rate. For example, the quantum key distribution rate at the current moment can be calculated according to the following formula (2):
[0074]
[0075] Among them, R k is the quantum key distribution rate at the current moment; BW t is the bandwidth status value at the current moment; S k Compress the shard size of the existing quantum key; R max is the maximum rate of quantum key distribution; min is the minimum value algorithm.
[0076] If the candidate quantum key distribution rate is less than or equal to the maximum quantum key distribution rate, it means that the candidate quantum key distribution rate meets the system requirements and matches the current network bandwidth status trend. The candidate quantum key distribution rate is determined as the bandwidth status value at the current moment to match the current network bandwidth status trend. If the candidate quantum key distribution rate is greater than the maximum quantum key distribution rate, it means that the candidate quantum key distribution rate does not meet the system requirements. The maximum quantum key distribution rate is determined as the bandwidth status value at the current moment to match the current network bandwidth status trend as much as possible while ensuring feasibility.
[0077] For example, Figure 4 A schematic diagram of an example of a process for adjusting the quantum key distribution rate provided in an embodiment of the present application is shown as follows: Figure 4 As shown, the process of adjusting the quantum key distribution rate may include steps b1 to b12.
[0078] In step b1, the bandwidth is monitored in real time to obtain the bandwidth status value at the current moment.
[0079] In step b2, the candidate quantum key distribution rate is calculated.
[0080] In step b3, determine whether the candidate quantum key distribution rate is greater than the maximum quantum key distribution rate. If so, proceed to step b4; if not, proceed to step b5.
[0081] In step b4, the maximum quantum key distribution rate is determined as the quantum key distribution rate at the current moment.
[0082] In step b5, the candidate quantum key distribution rate is determined as the quantum key distribution rate at the current moment.
[0083] In step b6, the quantum key compression fragment size is dynamically adjusted. Specifically, the quantum key compression fragment size at the current moment can be determined based on the quantum key distribution rate and the bandwidth state value at the current moment.
[0084] In step b7, quantum key compression fragments are distributed according to the quantum key distribution rate and the quantum key compression fragment size at the current moment.
[0085] In step b8, a feedback check is performed to determine whether feedback verification is required. If so, proceed to step b9; if not, proceed to step b12. Feedback verification can be performed by the target device receiving the quantum key compression fragment. The feedback verification may include whether the target device has received the quantum key compression fragment and whether the received quantum key compression fragment is correct and complete. Verification algorithms may include cyclic redundancy checks (CRCs) and hash checks, among other methods, which are not limited here.
[0086] In step b9, the feedback verification result from the target device is received. The feedback verification result may include ACK (Acknowledgement) information, NACK (Negative Acknowledgement) information, sequence number, checksum, etc., but is not limited here. The feedback verification result can be used to determine whether the feedback verification has passed. Errors during transmission that result in data corruption, fragment loss, fragment reordering, etc. may all cause the feedback verification to fail.
[0087] In step b10, determine whether the feedback verification has passed. If so, proceed to step b12. If not, proceed to step b11.
[0088] In step b11, the distribution parameters are adjusted and the quantum key compression fragments are retransmitted. The distribution parameters may include, but are not limited to, the quantum key distribution rate, quantum key compression fragment size, retransmission strategy, channel coding, and other parameters. Retransmitting the quantum key compression fragments may include retransmitting quantum key compression fragments that failed feedback verification.
[0089] In step b12, the distribution of quantum key compression fragments is completed.
[0090] The specific contents of the above steps b1 to b12 can be found in the relevant descriptions in the above embodiments and will not be repeated here.
[0091] In some embodiments, when a quantum key needs to be updated, only the changed portion of the quantum key can be transmitted, reducing communication resource consumption during the quantum key update process and adapting it to the needs of various bandwidth devices. Specifically, during the quantum key update, a differential processing module performs a differential operation on the original quantum key and the updated quantum key to obtain differential data. The differential processing module obtains an entropy parameter for the differential data and compresses the differential data based on the entropy parameter to obtain compressed differential data. The compressed differential data is then distributed to the target device via the quantum key distribution module.
[0092] The update of the quantum key can be based on a preset security policy, such as being triggered by a fixed time interval or when the amount of data used reaches a threshold. The update of the quantum key can also be triggered by a specific security event, which is not limited here. The original quantum key and the updated quantum key can be obtained from the quantum key distribution module that generates the quantum key, and an exclusive OR operation (i.e., XOR operation) is performed on the original quantum key and the updated quantum key to generate differential data. The differential data D = K new ⊕K current , D is differential data, K new is the updated quantum key, K current is the original quantum key, and ⊕ is the XOR operator. Based on the differential data, the entropy parameter of the differential data is calculated. The entropy parameter can be specifically an entropy value. The entropy value can be calculated according to the following formula (3):
[0093]
[0094] Among them, H(D) is the entropy value of differential data; D is differential data; p i is the probability of the i-th data block of the differential data. The data block is the basic unit or symbol for dividing the differential data for entropy statistical analysis. The probability of occurrence of the data block can be calculated in bytes, or in blocks of fixed size.
[0095] The entropy parameter can reflect the information content of the differential data. A compression method can be selected based on the information content of the differential data, and the compressed differential data, or compressed differential data, can be distributed to the target device. In some examples, if the entropy parameter is greater than or equal to a preset entropy threshold, the differential data is compressed by the differential processing module using a lossless compression algorithm to obtain compressed differential data. If the entropy parameter is less than the preset entropy threshold, the differential data is compressed by the differential processing module using a lossy compression algorithm to obtain compressed differential data. The preset entropy threshold can be used to determine whether the information content of the differential data meets the lossless compression requirements. If the entropy parameter is greater than or equal to the preset entropy threshold, the differential data contains a large amount of information and can be compressed using a lossless compression method, which may include but is not limited to entropy coding. If the entropy parameter is less than the preset entropy threshold, the differential data contains a small amount of information and has high information redundancy, and can be compressed using a lossy compression method to reduce the amount of data transmitted. The compressed differential data can be stored in a transmission queue. When the quantum key distribution module needs to distribute the compressed differential data, it can call the transmission queue and distribute the data to the target device according to the order of the data in the transmission queue. Choosing the compression method for differential data based on the entropy parameter can balance bandwidth savings with differential data transmission accuracy. When the entropy parameter is greater than or equal to the preset entropy threshold, lossless compression is used to ensure the accuracy of the compressed differential data. When the entropy parameter is less than the preset entropy threshold, lossy compression is used to reduce the amount of data transmitted, thereby saving bandwidth.
[0096] For example, Figure 5 A schematic diagram of an example of a quantum key update process provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the quantum key update process may include steps c1 to c8.
[0097] In step c1, the original quantum key and the updated quantum key are loaded.
[0098] In step c2, differential data is generated.
[0099] In step c3, the entropy parameter of the differential data is calculated.
[0100] In step c4, it is determined whether the entropy parameter is greater than or equal to a preset entropy threshold. If it is greater than or equal to the preset entropy threshold, step c5 is executed; if it is less than the preset entropy threshold, step c6 is executed.
[0101] In step c5, a lossless compression method is selected.
[0102] In step c6, a lossy compression method is selected.
[0103] In step c7, compressed differential data is generated.
[0104] In step c8, the compressed differential data is stored in a transmission queue.
[0105] The specific contents of the above steps c1 to c8 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.
[0106] In some embodiments, the target device can use quantum keys to encrypt the plaintext business data that needs to be encrypted, achieving end-to-end encryption protection based on quantum key distribution, ensuring the security of the entire link from business data generation to final reception of the business data, preventing data leakage or tampering, and thus ensuring the security of business data. Specifically, the business plaintext data is divided into multiple plaintext data segments through the communication encryption module, and each plaintext data segment is encrypted using a quantum key to obtain an encrypted data segment; the encrypted data segment and the corresponding integrity check value of the encrypted data segment are transmitted through the communication encryption module using a secure encrypted channel.
[0107] The communication encryption module can be located in the target device. Furthermore, the communication encryption module can be located at the data sending end of the target device. After the target device receives the quantum key compression fragments, it can decompress the quantum key compression fragments and combine them to obtain the quantum key. The business plaintext data M can be divided into multiple plaintext data segments M i , multiple plaintext data segments M i The business plaintext data M can be combined, such as business plaintext data M = {M1, M2, ..., M nEach plaintext data segment can be encrypted using a quantum key, and the encrypted data segment can be expressed as E i =Enc(K,M i ),E i is the i-th plaintext data segment M i The i-th encrypted data segment is obtained by encrypting with the quantum key K, where Enc() is the encryption algorithm. An integrity check value can also be obtained based on the plaintext data segment and the verification algorithm. The integrity check value is used to perform integrity verification on the encrypted data segment to ensure that the encrypted business data plaintext is not tampered with during transmission. In some examples, the verification algorithm can use a hash function, and the integrity check value H(M i )=Hash(M i ), H(M i ) is the integrity check value corresponding to the i-th plaintext data segment, and Hash() is the hash algorithm. When sending an encrypted data segment, the encrypted data segment and the integrity check value can be placed in a message and transmitted through a secure encrypted channel to prevent the encrypted data segment from being intercepted or tampered with at the intermediate node of data transmission. Correspondingly, the target device that receives the encrypted data segment and the integrity check value, i.e., the data receiving end, can use the quantum key to decrypt the encrypted data segment to obtain the plaintext data segment, and merge the multiple plaintext data segments obtained by decryption to obtain the business plaintext data. Plaintext data segment M i =Dec(K,E i ), M i For the i-th encrypted data segment E i The i-th plaintext data segment is decrypted using the quantum key K, where Dec() is the decryption algorithm. The target device, i.e., the data receiving end, can obtain an integrity check value based on the verification algorithm and the decrypted plaintext data segment. This integrity check value can be compared with the integrity check value transmitted along with the encrypted data segment. If the two match, the transmitted encrypted data segment is considered to be complete and correct. If the two do not match, the data sending end needs to retransmit the data segment to the data receiving end. For example, the plaintext data segment M obtained after decryption can be calculated as i The integrity check value H'(M i ), the integrity check value sent along with the encrypted data segment is H(M i ); if H'(M i )=H(M i ), then the two match; if H'(M i )≠H(M i ), the two do not match.
[0108] For example, Figure 6 A schematic diagram of an example of an end-to-end data transmission process provided in an embodiment of the present application is shown as follows: Figure 6 As shown, the end-to-end data transmission process may include steps d1 to d8.
[0109] In step d1, the data sending end segments the service plaintext data.
[0110] In step d2, the plaintext data segments obtained by segmentation are encrypted to obtain encrypted data segments.
[0111] In step d3, an integrity check value of the corresponding plaintext data segment is attached to each encrypted data segment.
[0112] In step d4, the encrypted data segment and the integrity check value are transmitted through a secure encryption channel to achieve end-to-end encrypted transmission.
[0113] In step d5, the data receiving end decrypts the encrypted data segment and restores the service plaintext data.
[0114] In step d6, it is determined whether the integrity check passes. If so, step d8 is performed; if not, step d7 is performed.
[0115] In step d7, the encrypted data segment is retransmitted.
[0116] In step d8, the data transmission is completed.
[0117] The specific contents of the above steps d1 to d8 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.
[0118] In some embodiments, one or more security verifications, such as update interval verification, entropy parameter verification, and differential data verification, may also be performed to improve the security of quantum key transmission. Specifically, the security verification module detects whether the update interval of the quantum key is greater than the update interval allowable threshold. In response to the quantum key update interval being greater than the update interval allowable threshold, an alarm message is triggered and the quantum key distribution module is triggered to regenerate the quantum key. The security verification module detects whether the entropy parameter of the differential data is less than the minimum entropy threshold. In response to the entropy parameter of the differential data being less than the minimum entropy threshold, an alarm message is triggered and the quantum key distribution module is triggered to regenerate the quantum key. The security verification module detects whether the size of the differential data is greater than the maximum value allowed for the data. In response to the size of the differential data being greater than the maximum value allowed for the data, an alarm message is triggered and the quantum key distribution module is triggered to regenerate the quantum key.
[0119] The quantum key update interval can be verified by comparing it with the update interval threshold. This verification can be performed during the quantum key update process. The update interval threshold is a safety threshold for the quantum key update interval and can be set based on the scenario, requirements, and experience, and is not limited here. If the quantum key update interval is less than or equal to the update interval threshold, the quantum key update interval is safe and the next step can be performed. If the quantum key update interval is greater than the update interval threshold, the quantum key update interval is unsafe and requires an alarm message to alert the relevant administrator and regenerate the quantum key to ensure safety.
[0120] Entropy parameter verification can be achieved by comparing the entropy parameter with the minimum entropy threshold. Entropy parameter verification can be performed after obtaining the entropy parameter. The minimum entropy threshold is the threshold for the amount of information in the differential data between the updated quantum key and the original quantum key. It can be set according to the scenario, requirements, experience, etc., and is not limited here. If the entropy parameter of the differential data is greater than or equal to the minimum entropy threshold, it means that the amount of information in the differential data is sufficient and the next step can be carried out; if the entropy parameter of the differential data is less than the minimum entropy threshold, it means that the amount of information in the differential data is insufficient and it is necessary to alert the relevant manager through an alarm message and regenerate the quantum key to ensure safety.
[0121] Differential data verification can be achieved by comparing the size of the differential data with the maximum value allowed by the data. Differential data verification can be performed after the differential data is obtained. The maximum value allowed by the data is the maximum value allowed for the size of the differential data, which can be set according to the scenario, requirements, experience, etc., and is not limited here. The larger the size of the differential data, the greater the difference between the updated quantum key and the original quantum key. If the size of the differential data is less than or equal to the maximum value allowed by the data, it means that the difference between the new quantum key and the original quantum key meets the requirements and the next step can be carried out; if the size of the differential data is greater than the maximum value allowed by the data, it means that the difference between the new quantum key and the original quantum key is too large. Transmitting this differential data may require bandwidth similar to or even more than transmitting a complete quantum key. There may be problems with certain statistical characteristics in the quantum key update process. If transmitting this differential data does not save bandwidth, it is necessary to remind the relevant administrator through an alarm message and regenerate the quantum key to ensure security.
[0122] When security verification involves multiple methods, it is considered to have passed only if all methods pass. If at least one verification method fails, it is considered to have failed security verification. Security verification methods such as update interval verification, entropy parameter verification, and differential data verification can achieve security protection and improve the security and reliability of quantum key systems.
[0123] For example, Figure 7A schematic diagram of an example of a security verification process provided in an embodiment of the present application is shown as follows: Figure 7 As shown, the security verification process may include steps e1 to e5.
[0124] In step e1, verify whether the quantum key update interval is reasonable. If reasonable, proceed to step e2; if not, proceed to step e5;
[0125] In step e2, verify whether the entropy parameter meets the requirements. If so, proceed to step e3; if not, proceed to step e5;
[0126] In step e3, it is verified whether the size of the differential data is reasonable. If it is reasonable, step e4 is executed; if not, step e5 is executed.
[0127] In step e4, the security verification is passed.
[0128] In step e5, an alarm message is triggered and the quantum key is regenerated.
[0129] The specific contents of the above steps e1 to e5 can be found in the relevant descriptions in the above embodiments, which will not be repeated here.
[0130] This application also provides a communication processing device based on quantum key distribution. Figure 8 This is a schematic diagram of the structure of a communication processing device for quantum key distribution provided in one embodiment of the present application, as shown in FIG. Figure 8 As shown, the communication processing device 10 for quantum key distribution may include a bandwidth adaptation module 12 and a quantum key distribution module 11.
[0131] The bandwidth adaptation module 12 can be used to obtain the bandwidth state value at the current moment based on the bandwidth measurement value obtained at the current moment and the bandwidth measurement value before the current moment, and to obtain the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size and the maximum quantum key distribution rate, so that the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment.
[0132] The quantum key distribution module 11 can be used to distribute quantum key compression fragments of the quantum key to the target device according to the quantum key distribution rate at the current moment.
[0133] In some embodiments, the bandwidth adaptation module 12 can be specifically used to: slide a preset time window in the acquired bandwidth measurement value according to a preset sliding step size, where the sliding time window includes the bandwidth measurement value at the current moment and the previous bandwidth measurement value; and obtain the bandwidth status value at the current moment using a weighted algorithm based on the bandwidth status value at the previous moment and the bandwidth measurement value at the current moment, where the bandwidth status value at the previous moment is obtained based on the bandwidth measurement value in the time window after the previous sliding.
[0134] In some embodiments, the bandwidth adaptation module 12 may be further configured to obtain a bandwidth fluctuation value according to a bandwidth status value at a current moment and a bandwidth status value at a previous moment through the bandwidth adaptation module.
[0135] The bandwidth adaptation module 12 can be specifically used to: in response to the bandwidth fluctuation value exceeding the fluctuation threshold range, obtain the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size and the maximum quantum key distribution rate.
[0136] In some embodiments, the quantum key distribution module 11 can be specifically used to obtain a candidate quantum key distribution rate based on the bandwidth state value at the current moment and the existing quantum key compression fragment size; and obtain the smaller of the candidate quantum key distribution rate and the maximum quantum key distribution rate as the quantum key distribution rate at the current moment.
[0137] In some examples, the bandwidth adaptation module 12 may also be used to: after obtaining the quantum key distribution rate at the current moment through the bandwidth adaptation module based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate, determine the quantum key compression fragment size at the current moment according to the quantum key distribution rate at the current moment and the bandwidth state value at the current moment, so that the quantum key compression fragment size at the current moment matches the quantum key distribution rate at the current moment; or, after obtaining the quantum key distribution rate at the current moment through the bandwidth adaptation module based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate, determine the existing quantum key compression fragment size as the quantum key compression fragment size at the current moment.
[0138] In some embodiments, the communication processing device 10 based on quantum key distribution may further include a differential processing module. Figure 9 This is a schematic diagram of the structure of a communication processing device for quantum key distribution provided by another embodiment of the present application. Figure 9 and Figure 8 The difference is that Figure 9 The communication processing device 10 for quantum key distribution shown may further include a differential processing module 13, a communication encryption module 14 and a security verification module 15. It should be noted that, Figure 9 Only one example of a communication processing device 10 for quantum key distribution is shown. In actual operation, the communication processing device 10 for quantum key distribution may include one or more of a differential processing module 13, a communication encryption module 14 and a security verification module 15, which is not limited here.
[0139] In some examples, the differential processing module 13 can be used to: when the quantum key is updated, perform a differential operation on the original quantum key and the updated quantum key to obtain differential data; obtain an entropy parameter of the differential data, and compress the differential data according to the entropy parameter to obtain compressed differential data.
[0140] The quantum key distribution module 11 can also be used to distribute compressed differential data to a target device.
[0141] In some examples, the differential processing module 13 can be specifically used to: if the entropy parameter is greater than or equal to a preset entropy threshold, compress the differential data using a lossless compression algorithm to obtain compressed differential data; if the entropy parameter is less than the preset entropy threshold, compress the differential data using a lossy compression algorithm to obtain compressed differential data.
[0142] In some examples, the communication encryption module 14 can be used to: divide business plaintext data into multiple plaintext data segments, and use quantum keys to encrypt each plaintext data segment to obtain encrypted data segments; use a secure encrypted channel to transmit the encrypted data segments and the integrity check values corresponding to the encrypted data segments, and the integrity check values are used to perform integrity verification on the encrypted data segments.
[0143] In some examples, the security verification module 15 can be used to implement at least one of the following: detecting whether the update interval of the quantum key is greater than the update interval allowable threshold, and in response to the update interval of the quantum key being greater than the update interval allowable threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting whether the entropy parameter of the differential data is less than the minimum entropy threshold, and in response to the entropy parameter of the differential data being less than the minimum entropy threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting whether the size of the differential data is greater than the maximum value allowed for the data, and in response to the size of the differential data being greater than the maximum value allowed for the data, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key.
[0144] It should be noted that the communication processing device 10 based on quantum key distribution is a device corresponding to the above-mentioned communication processing method based on quantum key distribution. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of the device and can achieve the same technical effects.
[0145] This application also provides a communication processing device based on quantum key distribution. Figure 10This is a schematic diagram of the structure of a communication processing device based on quantum key distribution provided in one embodiment of the present application. Figure 10 As shown, the communication processing device 300 based on quantum key distribution includes a memory 301, a processor 302, and a computer program stored in the memory 301 and executable on the processor 302.
[0146] In some examples, the processor 302 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0147] The memory 301 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical or other physical / tangible memory storage device. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., a memory device) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the communication processing method based on quantum key distribution in the embodiment of the present application.
[0148] The processor 302 runs a computer program corresponding to the executable program code by reading the executable program code stored in the memory 301, so as to implement the communication processing method based on quantum key distribution in the above embodiment.
[0149] In some examples, the communication processing device 300 based on quantum key distribution may further include a communication interface 303 and a bus 304. Figure 10 As shown, the memory 301 , the processor 302 , and the communication interface 303 are connected via a bus 304 and communicate with each other.
[0150] The communication interface 303 is mainly used to implement communication between the modules, devices, units and / or equipment in the embodiment of the present application. Input devices and / or output devices can also be connected through the communication interface 303.
[0151] The bus 304 includes hardware, software, or both, and couples the components of the communication processing device 300 based on quantum key distribution to each other. By way of example and not limitation, the bus 304 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-E) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 304 may include one or more buses. Although embodiments herein describe and illustrate a particular bus, this application contemplates any suitable bus or interconnect.
[0152] This application also provides a communication processing system based on quantum key distribution. Figure 11 This is a schematic diagram of the structure of a communication processing system based on quantum key distribution provided in one embodiment of the present application, as shown in FIG. Figure 11 As shown, the communication processing system 400 based on quantum key distribution includes a bandwidth adaptation device 401, a quantum key distribution device 402 and a target device 403.
[0153] The bandwidth adaptation device 401 can be used to obtain the bandwidth state value at the current moment based on the bandwidth measurement value obtained at the current moment and the bandwidth measurement value before the current moment, and to obtain the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size and the maximum quantum key distribution rate, so that the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment.
[0154] The quantum key distribution device 402 may be configured to distribute quantum key compression fragments of the quantum key to the target device according to the quantum key distribution rate at the current moment through the quantum key distribution module.
[0155] The target device 403 can be used to receive quantum key compression fragments, restore the quantum key according to the quantum key compression fragments, and use the quantum key to encrypt business plaintext data to transmit the encrypted data.
[0156] In some embodiments, the bandwidth adaptation device 401 can be specifically used to: slide a preset time window in the acquired bandwidth measurement value according to a preset sliding step size, and the sliding time window includes the bandwidth measurement value at the current moment and the previous bandwidth measurement value; according to the bandwidth status value at the previous moment and the bandwidth measurement value at the current moment, use a weighted algorithm to obtain the bandwidth status value at the current moment, and the bandwidth status value at the previous moment is obtained based on the bandwidth measurement value in the time window after the last sliding.
[0157] In some embodiments, the bandwidth adaptation device 401 may also be configured to obtain a bandwidth fluctuation value according to a bandwidth status value at a current moment and a bandwidth status value at a previous moment.
[0158] The bandwidth adaptation device 401 can be specifically used to: in response to the bandwidth fluctuation value exceeding the fluctuation threshold range, obtain the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size and the maximum quantum key distribution rate.
[0159] In some embodiments, the bandwidth adaptation device 401 can be specifically used to: obtain a candidate quantum key distribution rate based on the bandwidth state value at the current moment and the existing quantum key compression fragment size; obtain the smaller of the candidate quantum key distribution rate and the maximum quantum key distribution rate as the quantum key distribution rate at the current moment.
[0160] In some embodiments, the bandwidth adaptation device 401 can also be used to: determine the quantum key compression fragment size at the current moment based on the quantum key distribution rate at the current moment and the bandwidth state value at the current moment, so that the quantum key compression fragment size at the current moment matches the quantum key distribution rate at the current moment; or, determine the existing quantum key compression fragment size as the quantum key compression fragment size at the current moment.
[0161] In some embodiments, the communication processing system 400 based on quantum key distribution may further include a differential processing device and a security verification device. Figure 12 This is a schematic diagram of the structure of a communication processing system based on quantum key distribution provided by another embodiment of the present application. Figure 12 and Figure 11 The difference is that Figure 12The communication processing system 400 based on quantum key distribution shown may also include a differential processing device 404 and a security verification device 405. It should be noted that, Figure 12 Only one example of the communication processing system 400 for quantum key distribution is shown. In actual operation, the communication processing system 400 for quantum key distribution may include a differential processing device 404 and / or a security verification device 405, which is not limited here.
[0162] In some examples, the differential processing device 404 can be used to: when the quantum key is updated, perform a differential operation on the original quantum key and the updated quantum key to obtain differential data; obtain an entropy parameter of the differential data, and compress the differential data according to the entropy parameter to obtain compressed differential data.
[0163] Correspondingly, the quantum key distribution device 402 can be used to distribute compressed differential data to the target device.
[0164] In some examples, the differential processing device 404 can be specifically used to: if the entropy parameter is greater than or equal to a preset entropy threshold, compress the differential data using a lossless compression algorithm to obtain compressed differential data; if the entropy parameter is less than the preset entropy threshold, compress the differential data using a lossy compression algorithm to obtain compressed differential data.
[0165] In some examples, the target device 403 can also be used to: divide business plaintext data into multiple plaintext data segments, and use quantum keys to encrypt each plaintext data segment to obtain encrypted data segments; use a secure encrypted channel to transmit the encrypted data segments and the integrity check values corresponding to the encrypted data segments, and the integrity check values are used to perform integrity verification on the encrypted data segments.
[0166] In some examples, the security verification device 405 can be used to implement at least one of the following: detecting whether the update interval of the quantum key is greater than the update interval allowable threshold, and in response to the update interval of the quantum key being greater than the update interval allowable threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting whether the entropy parameter of the differential data is less than the minimum entropy threshold, and in response to the entropy parameter of the differential data being less than the minimum entropy threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key; detecting whether the size of the differential data is greater than the maximum value allowed for the data, and in response to the size of the differential data being greater than the maximum value allowed for the data, triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key.
[0167] For the specific content of the bandwidth adaptation device 401 in the above embodiment, please refer to the relevant description of the bandwidth adaptation module in the above embodiment; for the specific content of the quantum key distribution device 402, please refer to the relevant description of the quantum key distribution module in the above embodiment; for the specific content of the target device 403, please refer to the relevant description of the target device and the communication encryption module in the above embodiment; for the specific content of the differential processing device 404, please refer to the relevant description of the differential processing module in the above embodiment; for the specific content of the security verification device 405, please refer to the relevant description of the security verification module in the above embodiment, and no further details will be given here.
[0168] The present application also provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the communication processing method based on quantum key distribution in the above embodiment can be implemented, and the same technical effect can be achieved. To avoid repetition, the above-mentioned computer-readable storage medium may include a non-transitory computer-readable storage medium, such as a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc., which is not limited here.
[0169] The present application also provides a computer program product, which may include a computer program. When the computer program is executed by a processor, it implements the communication processing method based on quantum key distribution in the above embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0170] It should be understood that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. For device embodiments, equipment embodiments, system embodiments, computer-readable storage medium embodiments, and computer program product embodiments, the relevant parts can be referred to the description part of the method embodiment. This application is not limited to the specific steps and structures described above and shown in the figures. Those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of this application. In addition, for the sake of brevity, a detailed description of known method technologies is omitted here.
[0171] Aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed via the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. This processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or the flowchart and the combination of the boxes in the block diagram and / or the flowchart can also be implemented by the dedicated hardware that performs the specified function or action, or can be implemented by the combination of dedicated hardware and computer instructions.
[0172] Those skilled in the art should understand that the above embodiments are illustrative rather than restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, the specification and the claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other devices or steps; the quantifier "one" does not exclude a plurality; the terms "first" and "second" are used to identify names rather than to indicate any specific order. Any figure marks in the claims should not be understood as limiting the scope of protection. The functions of multiple parts appearing in the claims can be implemented by a separate hardware or software module. The fact that certain technical features appear in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.
Claims
1. A communication processing method based on quantum key distribution, characterized in that: include: Obtaining, by the bandwidth adaptation module, a bandwidth state value at a current moment based on the acquired bandwidth measurement value at the current moment and bandwidth measurement values before the current moment; The bandwidth adaptation module obtains the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate, so that the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment; The quantum key distribution module distributes quantum key compression fragments of the quantum key to the target device according to the quantum key distribution rate at the current moment.
2. The method according to claim 1, characterized in that The obtaining of the bandwidth status value at the current moment based on the obtained bandwidth measurement value at the current moment and the bandwidth measurement value in the time period before the current moment includes: Sliding a preset time window in the obtained bandwidth measurement value according to a preset sliding step size, wherein the sliding time window includes the bandwidth measurement value at the current moment and the previous bandwidth measurement value; The bandwidth state value at the current moment is obtained by using a weighted algorithm according to the bandwidth state value at the previous moment and the bandwidth measurement value at the current moment. The bandwidth state value at the previous moment is obtained based on the bandwidth measurement value in the time window after the last sliding.
3. The method according to claim 1, characterized in that The method further comprises: Obtaining a bandwidth fluctuation value by the bandwidth adaptation module according to the bandwidth state value at the current moment and the bandwidth state value at the previous moment; The method of obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate includes: In response to the bandwidth fluctuation value exceeding the fluctuation threshold range, a quantum key distribution rate at the current moment is obtained based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate.
4. The method according to claim 1 or 3, characterized in that The method of obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate includes: According to the current bandwidth state value and the existing quantum key compression fragment size, the candidate quantum key distribution rate is obtained; The smaller of the candidate quantum key distribution rate and the maximum quantum key distribution rate is obtained as the quantum key distribution rate at the current moment.
5. The method according to claim 1 or 3, characterized in that After obtaining the quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, the existing quantum key compression fragment size, and the maximum quantum key distribution rate by the bandwidth adaptation module, the method further includes: Determine the quantum key compression fragment size at the current moment according to the quantum key distribution rate at the current moment and the bandwidth state value at the current moment, so that the quantum key compression fragment size at the current moment matches the quantum key distribution rate at the current moment; or, The existing quantum key compression shard size is determined as the quantum key compression shard size at the current moment.
6. The method according to claim 1, characterized in that The method further comprises: In the case of quantum key update, the differential processing module performs differential operation on the original quantum key and the updated quantum key to obtain differential data; Obtaining an entropy parameter of the differential data through the differential processing module, and compressing the differential data according to the entropy parameter to obtain compressed differential data; The compressed differential data is distributed to the target device through the quantum key distribution module.
7. The method according to claim 6, characterized in that The compressing the differential data according to the entropy parameter to obtain compressed differential data includes: If the entropy parameter is greater than or equal to a preset entropy threshold, compressing the differential data using a lossless compression algorithm to obtain the compressed differential data; If the entropy parameter is less than the preset entropy threshold, the differential data is compressed using a lossy compression algorithm to obtain the compressed differential data.
8. The method according to claim 1, characterized in that The method further comprises: The communication encryption module divides the service plaintext data into multiple plaintext data segments, and encrypts each of the plaintext data segments using a quantum key to obtain an encrypted data segment; The encrypted data segment and the integrity check value corresponding to the encrypted data segment are transmitted through the communication encryption module using a secure encryption channel, and the integrity check value is used to perform integrity check on the encrypted data segment.
9. The method according to claim 1, characterized in that The method further comprises at least one of the following: detecting, by a security verification module, whether an update interval of the quantum key is greater than an update interval allowable threshold, and triggering an alarm message and triggering the quantum key distribution module to regenerate the quantum key in response to the update interval of the quantum key being greater than the update interval allowable threshold; detecting, by the security verification module, whether an entropy parameter of the differential data is less than a minimum entropy threshold, and in response to the entropy parameter of the differential data being less than the minimum entropy threshold, triggering an alarm message and triggering the quantum key distribution module to regenerate a quantum key; The security verification module detects whether the size of the differential data is greater than the maximum value allowed by the data. In response to the size of the differential data being greater than the maximum value allowed by the data, an alarm message is triggered and the quantum key distribution module is triggered to regenerate the quantum key.
10. A communication processing device based on quantum key distribution, characterized in that: include: a bandwidth adaptation module, configured to obtain a bandwidth state value at a current moment based on the obtained bandwidth measurement value at the current moment and bandwidth measurement values before the current moment, and to obtain a quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, an existing quantum key compression fragment size, and a maximum quantum key distribution rate, wherein the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment; The quantum key distribution module is used to distribute quantum key compression fragments of the quantum key to the target device according to the quantum key distribution rate at the current moment.
11. A communication processing device based on quantum key distribution, characterized in that: include: A processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the communication processing method based on quantum key distribution according to any one of claims 1 to 9.
12. A communication processing system based on quantum key distribution, characterized in that: include: a bandwidth adaptation device, configured to obtain a bandwidth state value at a current moment based on the obtained bandwidth measurement value at the current moment and a bandwidth measurement value before the current moment, and to obtain a quantum key distribution rate at the current moment based on the bandwidth state value at the current moment, an existing quantum key compression fragment size, and a maximum quantum key distribution rate, wherein the quantum key distribution rate at the current moment matches the bandwidth state value at the current moment; A quantum key distribution device, configured to distribute quantum key compression fragments of the quantum key to a target device according to a current quantum key distribution rate via a quantum key distribution module; The target device is used to receive quantum key compression fragments, restore the quantum key according to the quantum key compression fragments, and use the quantum key to encrypt the business plaintext data to transmit the encrypted data.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the communication processing method based on quantum key distribution according to any one of claims 1 to 9.
14. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, implements the communication processing method based on quantum key distribution according to any one of claims 1 to 9.