Multi-domain virtual network security mapping based on key balance and minimum consumption

By combining blockchain and quantum key distribution technology in a multi-domain elastic optical network, virtual node and link mapping decisions are optimized, multi-domain coordination and data transmission security problems are solved, efficient and secure cross-domain resource scheduling and virtual network mapping are achieved, and network resource utilization and data transmission security are improved.

CN120528593APending Publication Date: 2025-08-22CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510837289.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

In multi-domain elastic optical networks, there are problems with multi-domain coordination and data transmission security in the virtual network mapping process, especially the lack of trust mechanism between autonomous and independently operated physical domains, resulting in limited resource sharing and obstruction of path selection, affecting cross-domain mapping efficiency and network resource utilization. At the same time, traditional encryption algorithms face the threat of quantum computing.

Method used

Combining blockchain technology and quantum key distribution (QKD), through the methods of key equalization and minimum consumption, virtual node mapping decisions are optimized, node importance and link weight formulas are designed to achieve cross-domain resource coordination and data transmission security, and quantum key distribution path mapping based on key equalization and encrypted data transmission path mapping based on minimum spectrum consumption are adopted.

Benefits of technology

It improves the success rate of multi-domain virtual network mapping and reduces mapping costs, improves the overall utilization rate of network resources and the security of data transmission, and realizes efficient and secure cross-domain resource scheduling and virtual network mapping.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528593A_ABST
    Figure CN120528593A_ABST
Patent Text Reader

Abstract

The invention relates to multi-domain virtual network security mapping based on key balance and minimum consumption, and belongs to the technical field of optical fiber communication. According to the method, a quantum key distribution network and a block chain are integrated into a multi-domain elastic optical network, a block chain assisted multi-domain virtual network security mapping architecture is constructed, and security coordination management of multi-domain resources is realized. In the virtual node mapping process, multi-dimensional resource attributes of nodes are considered, and a node importance evaluation formula is designed to optimize virtual node mapping; the virtual link mapping process is divided into two stages: in the quantum key distribution path mapping stage, a key weight formula selection path is designed by adopting a quantum key distribution path mapping method based on key balance; in an encrypted data transmission path mapping stage, a routing spectrum allocation method for minimizing spectrum consumption is adopted, and a spectrum consumption calculation formula is designed to measure spectrum resource consumption. The method can reduce the virtual network mapping request blocking rate and improve the key utilization rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of optical fiber communication and optical signal security transmission, and relates to a multi-domain virtual network security mapping based on key balance and minimum consumption. Background Art

[0002] With the rapid development of technologies such as cloud computing, big data, and the Internet of Things, network services are becoming increasingly diverse, and application demands are becoming increasingly diversified. This places higher demands on underlying networks in terms of bandwidth, resource scheduling, and data security. Elastic Optical Networks (EONs), with their flexible spectrum allocation and efficient optical transmission capabilities, have become a key technical foundation for next-generation backbone networks. To meet the needs of large-scale resource management and on-demand services, EON network architectures are gradually evolving towards multi-domain deployments, forming Multi-Domain Elastic Optical Networks (MD-EONs).

[0003] In MD-EONs, Virtual Network Embedding (VNE) is the core technology for virtualizing and flexibly scheduling network resources. Compared to single-domain networks, the mapping process in multi-domain environments is more complex. On the one hand, each physical domain is autonomous and operates independently. For privacy and security reasons, they are often reluctant to disclose their domain topology and resource status. On the other hand, the lack of a unified trust mechanism and collaborative scheduling approach between domains limits resource sharing and hinders path selection, severely impacting the efficiency of cross-domain mapping and overall network resource utilization.

[0004] At the same time, network security issues are becoming increasingly prominent. With the development of quantum computing technology, the security of traditional encryption algorithms faces potential threats. Quantum Key Distribution (QKD), based on quantum physics principles and offering unconditional security, is widely considered a crucial tool for building next-generation secure communications systems. Integrating QKD technology into MD-EONs effectively prevents link eavesdropping attacks and provides security for multi-domain key distribution and data transmission.

[0005] To alleviate the lack of trust between domains and improve resource collaboration efficiency, blockchain technology has been gradually introduced in recent years into the mapping and management of multi-domain networks. Blockchain, with its decentralized, tamper-proof, and traceable nature, enables trusted sharing of cross-domain resource states, collaborative management of mapping requests, and transparent, controllable scheduling, all while protecting the privacy of each domain. Combined with smart contract mechanisms, blockchain can also automate the execution of mapping policies, reducing the cost of human intervention and improving overall mapping efficiency, reliability, and security.

[0006] Therefore, it is urgent to design a multi-domain virtual network mapping method that integrates the blockchain trust mechanism and QKD security capabilities to achieve future-oriented efficient, secure and reliable cross-domain resource scheduling and virtual network mapping, and improve the overall performance and security assurance capabilities of MD-EONs in complex business scenarios. Summary of the Invention

[0007] In view of this, the object of the present invention is to provide a multi-domain virtual network security mapping based on key balance and minimum consumption, which is used for efficient resource allocation of cross-domain virtual network mapping and ensures data security transmission.

[0008] In order to achieve the above object, the present invention provides the following technical solutions:

[0009] In response to the multi-domain coordination and data transmission security issues faced by virtual network mapping in multi-domain elastic optical networks, a multi-domain virtual network security mapping based on key balance and minimum consumption is proposed. In this method, the quantum key distribution network is integrated into the multi-domain elastic optical network as the underlying physical network for virtual network mapping and combined with blockchain distributed management of inter-domain resource coordination and scheduling; in the virtual node mapping process, the correlation between virtual nodes and virtual link mappings and the multi-dimensional resource attributes of nodes are considered, and a node importance formula is designed to optimize virtual node mapping decisions; after completing the virtual node mapping, a virtual link weight formula is designed to determine the mapping order of virtual links; a quantum key distribution path mapping method based on key balance is used to map the key requirements of virtual links to physical paths with short hops and rich key resources; an encrypted data transmission path mapping method based on minimum consumption is used to select the path with the least spectrum consumption for encrypted data transmission and complete spectrum allocation. The method specifically includes the following steps:

[0010] S1: Input the underlying physical network topology of the elastic optical network and the available computing resources of the physical nodes in the underlying physical network, the available bandwidth resources of the physical links, and the available key resources. The virtual network request and key requirement parameters are set as α = 0.4, β = γ = 0.3, ρ = 0.5, GB = 1 frequency slot, G FS =12.5GHz, collection According to the virtual network request, it is broadcast to each domain controller through the blockchain network for verification; the importance value of all virtual nodes is calculated based on the computing resource requirements of the virtual node, the virtual node degree, the bandwidth of the adjacent virtual link and the key resource requirements; all virtual nodes are sorted in non-ascending order according to the importance value and stored in the set N v middle;

[0011] The importance value of the virtual node is calculated as follows:

[0012]

[0013] In the above formula, Represents a virtual node The computing resource requirements, Represents a virtual node The node degree, Represents the computing resource requirements of all virtual nodes in the virtual network, Representation and virtual nodes The set of adjacent virtual links, Represents a virtual node Adjacent virtual links bandwidth resource requirements, Indicates the bandwidth resource requirements of all virtual links in the virtual network, Represents a virtual node Adjacent virtual links Key resource requirements, The key resource requirements of all virtual links in the virtual network, α, β and γ are the weight coefficients for weighing the resource attributes of each dimension, The larger the value, the more virtual nodes The higher the mapping priority,

[0014] S2: Each domain controller counts the available computing resources, physical node degrees, bandwidth of adjacent physical links, and key resource values ​​of the physical nodes in the domain, and calculates the importance values ​​of all physical nodes in its domain; each domain controller sorts all physical nodes in the domain in non-ascending order according to the importance values ​​and saves them in the collection middle;

[0015] The importance value of the physical node is calculated as follows:

[0016]

[0017] in, Represents a physical node The amount of available computing resources, Represents a physical node Node degree, CPU max Indicates the maximum computing resource capacity of the physical node, Representation and physical nodes The set of adjacent physical links, Represents a physical node Adjacent physical links The amount of available bandwidth resources, B max Indicates the maximum bandwidth resource capacity of the physical link, Represents a physical node Adjacent physical links The amount of available key resources, K max Indicates the maximum key resource capacity of the physical link;

[0018] S3: According to the candidate mapping domain restrictions of the virtual node in the virtual network request, if the set If there is a physical node that meets the virtual node mapping domain restrictions, the mapping scheme of the virtual node to the physical node is saved in the set VNM, and the process goes to step S4. Otherwise, the virtual network mapping fails and the algorithm ends.

[0019] The specific process of S3 is as follows: let the virtual node to be mapped be Virtual Node The candidate mapping domain is expressed as: In-order traversal The candidate physical nodes in the physical domain z are stored in the set In the check collection Is there a candidate mapping domain restriction physical node that meets the computing resource requirements of the virtual node? Right now If it exists, the virtual node Mapping to physical nodes Get the virtual node Mapping scheme, saved in the set VNM; otherwise, the virtual node If the mapping fails, the algorithm ends;

[0020] S4: Repeat steps S2 and S3 to traverse the set N v All unmapped virtual nodes in the virtual network are obtained to obtain the feasible solution set VNM for mapping all virtual nodes in the virtual network;

[0021] S5: Calculate the weight values ​​of all virtual links in the virtual network, sort them in non-ascending order according to the weight values, and put them into the set L v ;

[0022] The virtual link weight is calculated as follows:

[0023]

[0024] In the above formula, ρ is the weight coefficient that weighs the virtual link bandwidth and key resource requirements, and its value is ρ = 0.5; if The larger the value of The higher the mapping priority,

[0025] S6: From the set L vThe virtual links to be mapped are selected in sequence, and according to the mapping schemes of all virtual nodes in the set VNM, the quantum key distribution path mapping method based on key balancing according to claim 2 is adopted to map the key resource requirements of the virtual links to the underlying physical network;

[0026] S7: Using the encrypted data transmission routing spectrum allocation method based on minimum spectrum consumption as described in claim 3, sequentially mapping the bandwidth resource requirements of each virtual link requested by the virtual network to the underlying physical network;

[0027] S8: Calculate the mapping costs of all feasible mapping schemes for the virtual network, and select the mapping scheme with the lowest mapping cost as the final virtual network mapping scheme;

[0028] Among them, the calculation formula of the mapping cost of the feasible mapping scheme is:

[0029]

[0030] In the above formula, Indicates a virtual link The physical path mapped by the bandwidth resource requirements, Indicates a virtual link The physical path mapped to the bandwidth resource requirements The number of physical link hops on Indicates a virtual link The physical path mapped to the key resource requirements, Indicates a virtual link The physical path mapped to the bandwidth resource requirements The number of physical link hops on the VLAN.

[0031] 1. The multi-domain virtual network security mapping based on key balance and minimum consumption according to claim 1 is characterized in that: the quantum key distribution path mapping method based on key balance in S6 specifically includes the following steps:

[0032] S601: The virtual link to be mapped The virtual nodes at both ends correspond to the physical nodes in the feasible solution set VNM, which are marked as and judge and Are they in the same physical domain? If so, the virtual link mapping is intra-domain mapping, and the process goes to step S602; otherwise, the virtual link mapping is inter-domain mapping, and the process goes to step S604;

[0033] S602: For intra-domain mapping, under the management of the domain controller, first calculate K candidate quantum key distribution paths according to the K shortest path algorithm, assuming K = 3; calculate the key weight values ​​of these K candidate quantum key distribution paths respectively, and sort them in non-ascending order according to the key weight values, and put them into the set P key , go to step S603;

[0034] Among them, the key weight calculation formula of the quantum key distribution candidate path is:

[0035]

[0036] In the above formula, Indicates a virtual link The jth path among the K candidate quantum key distribution paths mapped by the key resource requirements, K min Indicates the physical path The minimum available key amount among all physical links, Indicates the physical path The number of hops on the physical link, The larger the value of , the more keys are available on the path and the fewer hops.

[0037] 603: Traverse set P key Among all candidate quantum key distribution paths in , check whether there is a path that meets the key requirements, i.e. If it exists, the path is selected as the quantum key distribution mapping path, and the process goes to step S7; otherwise, the quantum key distribution path mapping fails, and the algorithm ends.

[0038] S604: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain are used as the source and destination nodes of the virtual link mapping. According to the inter-domain topology, a shortest path that meets the key requirements of the virtual network request is calculated, and the shortest path is determined to be between the two domain boundary nodes. and If the path exists, the path is recorded and saved as the inter-domain path of the virtual link mapping, and the process goes to step S605; otherwise, the quantum key distribution path mapping fails;

[0039] S605: From the physical node arrive From the physical node arrive The paths are managed by their respective domain controllers. First, K shortest paths are calculated as candidate sub-paths for quantum key distribution. The key weight value of each candidate sub-path for quantum key distribution is calculated and sorted in non-ascending order according to the key weight value. The paths are placed in the set and , go to step S606;

[0040] S606: Traverse the collection separately and All quantum key distribution candidate subpaths in the virtual link are checked to see if there is a quantum key distribution candidate subpath that meets the key requirements. If all exist, the path is selected as the subpath for quantum key distribution path mapping, and the process goes to step S607. Otherwise, the quantum key distribution path mapping of the virtual link fails, and the algorithm ends.

[0041] S607: Combine the inter-domain path of the virtual link mapping obtained in step S604 and the quantum key distribution sub-path obtained in step S606 to obtain the complete inter-domain and intra-domain quantum key distribution mapping paths of the virtual link mapping.

[0042] 2. The multi-domain virtual network security mapping based on key balancing and minimum consumption according to claim 1, wherein the spectrum allocation method for encrypted data transmission routing based on minimum spectrum consumption in S7 specifically comprises the following steps:

[0043] S701: The virtual link to be mapped The physical nodes mapped to the virtual nodes at both ends are marked as and Determine the physical node and Are they in the same physical domain? If so, the virtual link is an intra-domain mapping, and the process goes to step S702; otherwise, the virtual link is an inter-domain mapping, and the process goes to step S704;

[0044] S702: For intra-domain mapping, under the management of the domain controller, first calculate K candidate transmission paths for encrypted data according to the K shortest path algorithm, assuming K = 3; calculate the frequency slot consumption required for the encrypted data to be transmitted on these K candidate transmission paths, and sort them in non-ascending order according to the frequency slot consumption, and save them in the set P data , go to step S703;

[0045] The calculation formula for the frequency slot consumption required for encrypted data transmission on the candidate transmission path is:

[0046]

[0047] In the above formula, Indicates a virtual link The jth of the K candidate transmission paths mapped by the bandwidth resource demand, Represents candidate paths The number of hops on the physical link, m kIndicates the highest modulation level that can be used for the candidate path, G FS Indicates the bandwidth of the unit frequency slot, GB indicates the size of the protection frequency slot, The larger the value is, the more frequency slots the candidate path needs to consume when used as an encrypted data transmission path.

[0048] The relationship between modulation level, modulation format and transmission distance is as follows:

[0049]

[0050] In the table, BPSK (Binary Phase Shift Keying), QPSK (Quadrature Phase Shift Keying), 8QAM (8-Quadrature Amplitude Modulation), and 16QAM (16-Quadrature Amplitude Modulation) are binary phase shift keying, quadrature phase shift keying, 8th-order quadrature amplitude modulation, and 16th-order quadrature amplitude modulation, respectively.

[0051] S703: Traverse the set P data Among all candidate transmission paths, the number of frequency slots contained in the maximum available continuous spectrum block on the candidate path is represented by MFS, and it is determined whether there is a candidate transmission path whose number of frequency slots in the maximum available continuous spectrum block meets the virtual link bandwidth requirement, that is, whether there is a path with If so, the candidate transmission path is selected as the transmission path for virtual link mapping, and the process goes to step S708; otherwise, the virtual link mapping fails, and the algorithm ends.

[0052] S704: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain of the elastic optical network are used as the source and destination nodes respectively. According to the inter-domain topology results, a shortest path that meets the bandwidth requirements of the virtual link is calculated as the inter-domain path of the virtual link mapping. The source and destination nodes of the inter-domain path are determined as the boundary nodes of the domain respectively. and If the inter-domain path exists, the inter-domain path is recorded and saved, and the process goes to step S705; otherwise, the virtual link mapping fails, and the algorithm ends.

[0053] S705: When the domain controller is turned off, the K shortest path method is used to calculate the path from the physical node To the physical domain boundary node The K shortest paths are calculated, and the frequency slot consumption of each shortest path is calculated respectively. Then, the frequency slot consumption is sorted in non-descending order and stored in the set In; Using the K shortest path method, from the physical node To the physical domain boundary node The K shortest paths are calculated, the frequency slot consumption required for the encrypted data to be transmitted on each shortest candidate path is calculated, and the frequency slot consumption is sorted in non-descending order and stored in the set , go to step S706;

[0054] S706: Traverse the collection separately and Among all the candidate subpaths for encrypted data transmission, check whether there is a candidate subpath for virtual link mapping whose maximum available spectrum block size on the path meets the virtual link bandwidth requirement. If both exist, select the path as the subpath for virtual link mapping and go to step S707. Otherwise, the mapping of the virtual link mapping fails and the algorithm ends.

[0055] S707: Combine the inter-domain path of the virtual link mapping obtained in step S704 and the sub-path of the virtual link mapping obtained in step S706 to obtain the complete inter-domain and intra-domain encrypted data mapping paths of the virtual link mapping;

[0056] S708: For the path or path combination mapped by the virtual link, allocate spectrum to the mapped path in a first matching manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to make the purpose, technical solutions and beneficial effects of the present invention more clear, the present invention provides the following drawings for illustration:

[0058] Figure 1 An example diagram of the virtual node domain restriction mapping process;

[0059] Figure 2 This is an example diagram of the virtual link mapping process;

[0060] Figure 3 A multi-domain virtual network security mapping flow chart based on key balance and minimum consumption;

[0061] Figure 4 This is a flow chart of the quantum key distribution path mapping method based on key equalization;

[0062] Figure 5 Flowchart of a spectrum allocation method for routing encrypted data transmission based on minimum spectrum consumption. DETAILED DESCRIPTION

[0063] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0064] The present invention provides a multi-domain virtual network security mapping based on key balance and minimum consumption, the purpose of which is to better improve the success rate of virtual network mapping and reduce mapping costs in a multi-domain elastic optical network. The present invention can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. The following embodiments and the features in the embodiments can be combined with each other without conflict.

[0065] Among them, the figures are used for illustrative purposes only and represent only schematic diagrams rather than actual pictures, and should not be understood as limiting the present invention. In order to better illustrate the embodiments of the present invention, some parts in the figures may be omitted, enlarged or reduced, and do not represent the dimensions of actual products. For those skilled in the art, it is understandable that some well-known structures and their descriptions may be omitted in the figures.

[0066] Attachment Figure 1 This diagram illustrates the virtual node domain constraint mapping process. It includes a virtual network request and the underlying physical network of the elastic optical network. The virtual network request is a virtual network with three virtual nodes and three virtual links. The numbers in the boxes above the virtual nodes represent the compute resource requirements of the virtual nodes, i.e., the compute resource requirements for virtual nodes a, b, and c are 3, 4, and 5, respectively. The set next to the virtual nodes represents the candidate mapping domain constraints for the virtual nodes, i.e., the candidate mapping domain constraints for virtual nodes a, b, and c are {physical domain 1, physical domain 2}, {physical domain 2}, and {physical domain 3}, respectively. The numbers in parentheses above the virtual links represent the bandwidth resource requirements and key resource requirements, respectively. For virtual links ab, bc, and ac, the bandwidth resource requirements are 3, 6, and 4 units, respectively, and the key resource requirements are 2, 3, and 2 units, respectively. The underlying physical network is a network topology with three domains, 11 physical nodes, and 16 physical links. The numbers in the boxes above the physical nodes represent the available compute resources for the physical nodes. The numbers in parentheses above the physical links represent the available bandwidth resources and key resources, respectively. The numbers outside the parentheses represent the physical distance of the link. The importance value of each virtual node can be calculated as follows: and Therefore, the mapping order of virtual nodes a, b and c is c, b, a. According to the candidate mapping domain restrictions of each virtual node, the possible mapping domain selection schemes {physical domain 1, physical domain 2, physical domain 3} and {physical domain 2, physical domain 2, physical domain 3} can be obtained by combining them. Assume that the computing resource capacity of the physical nodes in the underlying physical network is 30 units, and the bandwidth and key resource capacity of the physical link are 30 units and 20 units respectively. The importance values ​​of the physical nodes in each domain can be obtained by calculation, where the importance values ​​of all physical nodes in physical domain 1 are

[0067] Therefore, the carrying capacities of the physical nodes in physical domain 1 are 1, 4, 3, and 2, from largest to smallest. The importance values ​​for physical domains 2 and 3 are calculated similarly, resulting in the carrying capacities of the physical nodes in physical domain 2 being 7, 6, 5, and 8, and those in physical domain 3 being 9, 11, and 10, from largest to smallest. Specific mapping of the mapping domain selection scheme yields the virtual node mapping schemes {a→3, b→7, c→9} and {a→6, b→7, c→9}.

[0068] Attachment Figure 2 This is an example diagram of the virtual link mapping process. The underlying physical network in the figure is divided into three physical domains, with a total of 11 physical nodes and 16 physical links. The number outside the brackets on the physical link represents the link length, the first number in the brackets represents the number of frequency slots currently available for the physical link, and the second number represents the current amount of available keys in the VKP on the physical link; the virtual network request is a virtual network consisting of 3 nodes and 3 links, where virtual nodes A, B, and C are mapped to physical nodes 2, 6, and 9 respectively. The bandwidth rate requirement of virtual link BC is 50Gbps, and the quantum key requirement is 3 units. For virtual link BC, the virtual nodes at both ends are mapped in different domains. Therefore, it is necessary to find a shortest path between domains. According to the inter-domain topology, the shortest path between domains can be obtained as p inter Then, the K shortest path algorithm can be used to calculate the three shortest paths from physical node 6 to boundary node 8, which are p intra,1 :6-5-8、p intra,2 : 6-8 and p intra,3 :6-7-8, and finally we can combine three inter-domain mapping paths p1:6-5-8-9, p2:6-8-9 and p3:6-7-8-9. In quantum key distribution path mapping, the quantum key requirements must be met first. The quantum key of path p1 is not enough to meet the quantum key requirements of virtual link BC. The key weight values ​​of paths p2 and p3 are calculated respectively. and Therefore, path p3:6-7-8-9 is selected as the quantum key distribution path in the quantum key distribution path mapping. In the encrypted data transmission path mapping, paths with low bandwidth consumption are preferred. The modulation format in EONs is related to the transmission distance. Generally, the highest modulation format that does not exceed the maximum transmission distance is used based on the physical path length. The transmission distances of paths p1, p2, and p3 are 2200km, 2500km, and 2600km respectively. Therefore, the highest modulation level m that can be used is 2200km, 2500km, and 2600km respectively. k They are 3, 2 and 2 respectively. The protection spectrum GB is 1 frequency slot, and the calculation results show that the frequency slot consumption on paths p1, p2 and p3 is and Therefore, the path p2:6-8-9 is selected as the encrypted data transmission path.

[0069] The following will be combined with the Figure 3 、 4 5. A more detailed introduction to a multi-domain virtual network security mapping based on key balance and minimum consumption of the present invention is given, wherein Figure 3 The following is a general flow chart of a multi-domain virtual network security mapping based on key balance and minimum consumption. Figure 3 The specific overall process can be divided into the following steps:

[0070] Input: Update the underlying elastic optical network physical topology and the available computing resources of the physical nodes, available bandwidth resources of the physical links and available key resources in the underlying physical network; input the virtual network request and key requirements; set parameters α=0.4,β=γ=0.3,ρ=0.5,GB=1,G FS =12.5GHz, collection

[0071] Output: virtual node mapping results, virtual link mapping results, specifically including: quantum key distribution path and key consumption, encrypted data transmission route spectrum allocation results.

[0072] S1: After the virtual network request arrives, it is broadcast to each domain controller through the blockchain network for verification, and the importance values ​​of all virtual nodes are calculated; all virtual nodes are sorted in non-ascending order according to the importance values ​​and put into the set N v , go to step S2;

[0073] S2: Calculate the importance values ​​of all nodes in each domain; each domain controller sorts all physical nodes in the domain in non-ascending order according to the importance values ​​and puts them into the collection Go to step S3;

[0074] S3: Traverse all virtual nodes and limit the candidate mapping domain of the virtual nodes Arrange and combine all possible virtual node mapping domains and mark the determined candidate mapping domains as And put it into the set VNM, and go to step S4;

[0075] S4: Take out a mapping solution from the set VNM in turn, and go to step S5;

[0076] S5: From set N v Take out a virtual node in order Go to step S6;

[0077] S6: According to the virtual node in the mapping scheme Determined mapping candidate domains Traverse the physical node set of physical domain z in order Check whether there is a virtual node that meets the computing resource requirements. If it exists, the virtual node Mapping to physical nodes On and from the collection Delete the physical node and go to step S7; otherwise, the virtual node mapping scheme fails;

[0078] S7: Determine virtual network set N v Whether all virtual nodes have completed mapping, if so, put the solution into set M and go to step S8; otherwise, go to step S5;

[0079] S8: Determine whether there is an untraversed mapping solution in the set VNM. If so, go to step S4; otherwise, the virtual node mapping is completed.

[0080] S9: Calculate the weight values ​​of all virtual links in the virtual network, sort them in non-ascending order according to the weight values ​​of the virtual links, and put them into the set L v , go to step S10;

[0081] S10: Traverse each virtual link of the virtual network in order and call Figure 4 The quantum key distribution path mapping method based on key equalization shown in the figure maps the key requirements of the virtual link to the physical path. If the key requirement mapping of the virtual link fails, the virtual network request mapping fails; otherwise, the key requirement mapping of the virtual link is successful, and the process goes to step S11.

[0082] S11: Traverse each virtual link of the virtual network in order and call Figure 5The spectrum allocation method for encrypted data transmission routing based on minimum spectrum consumption shown in the figure maps the bandwidth requirements of the virtual link to the physical path. If the bandwidth requirement mapping of the virtual link fails, the virtual network request mapping fails. Otherwise, the bandwidth requirement mapping of the virtual link succeeds, and the process goes to step S12.

[0083] S12: Calculate the mapping costs of all feasible mapping solutions, select the mapping solution with the lowest mapping cost as the final virtual network mapping solution, and return the mapping result.

[0084] Attachment Figure 4 It is a quantum key distribution path mapping method based on key balance. The specific process is shown in the following steps:

[0085] Input: Virtual link to be mapped

[0086] Output: Quantum key distribution path mapping result.

[0087] S1: The virtual link to be mapped The physical nodes mapped to the virtual nodes at both ends are marked as and Determine whether the two physical nodes are in the same physical domain. If so, it is intra-domain mapping, and go to step S2; otherwise, it is inter-domain mapping, and go to step S4;

[0088] S2: For intra-domain mapping, under the management of the domain controller, first calculate K candidate quantum key distribution paths according to the K shortest path algorithm, set K = 3; calculate the key weight values ​​of these K candidate quantum key distribution paths respectively, and sort them in non-ascending order according to the key weight values, and put them into the set P key , go to step S3;

[0089] S3: traverse the set P key Among all candidate quantum key distribution paths in , check whether there is a path that meets the key requirements, that is, If it exists, the path is selected as the quantum key distribution mapping path, and the process goes to step S7; otherwise, the quantum key distribution path mapping fails;

[0090] S4: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain are used as source and destination nodes. A shortest path that meets the key requirements is calculated based on the inter-domain topology, and the boundary nodes are determined. and If the path exists, record the path and go to step S5; otherwise, the quantum key distribution path mapping fails;

[0091] S5: From physical node To the physical domain boundary node and from physical nodes To the physical domain boundary node The path is completed by the corresponding domain controller. First, the K shortest paths are calculated, the key weight value of each quantum key distribution candidate path is calculated, and the key weight value is sorted in non-ascending order and placed in the set and , go to step S6;

[0092] S6: Traverse the collection separately and All quantum key distribution candidate subpaths in are checked to see if there is a quantum key distribution candidate subpath that meets the key requirements. If so, the path is selected as the subpath for quantum key distribution path mapping, and the process goes to step S7. Otherwise, the quantum key distribution path mapping fails, and the algorithm ends.

[0093] S7: Combine all subpaths obtained in steps S4 and S6 to obtain a complete inter-domain quantum key distribution mapping path, and go to step S8;

[0094] S8: Record and return the quantum key distribution mapping path.

[0095] Attachment Figure 5 This is a spectrum allocation method for encrypted data transmission routing based on minimum spectrum consumption. The specific process is shown in the following steps:

[0096] Input: Virtual link to be mapped

[0097] Output: Encrypted data transmission routing spectrum allocation results.

[0098] S1: The virtual link to be mapped The physical nodes mapped to the virtual nodes at both ends are marked as and Determine whether the two physical nodes are in the same physical domain. If so, it is intra-domain mapping, and go to step S2; otherwise, it is inter-domain mapping, and go to step S4;

[0099] S2: For intra-domain mapping, under the management of the domain controller, first calculate K candidate paths for encrypted data transmission according to the K shortest path algorithm, where K = 3; calculate the frequency slot consumption of these K candidate paths for encrypted data transmission respectively, and sort them in non-ascending order according to the frequency slot consumption, and put them into the set P data , go to step S3;

[0100] S3: traverse the set P dataFor all the candidate paths for encrypted data transmission in , check whether there is a path whose maximum available continuous spectrum block size MFS on the candidate path meets the virtual link bandwidth requirement, that is, If it exists, the path is selected as the encrypted data transmission mapping path, and the process goes to step S24; otherwise, the encrypted data transmission path mapping fails, and the algorithm ends;

[0101] S4: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain are used as source and destination nodes. A shortest path that meets bandwidth requirements is calculated based on the inter-domain topology, and the boundary nodes are determined. and If the path exists, the path is recorded and the process goes to step S5; otherwise, the encrypted data transmission path mapping fails and the algorithm ends;

[0102] S5: From physical node To the physical domain boundary node and from physical nodes To the physical domain boundary node The path is completed by the corresponding domain controller. First, K shortest paths are calculated, the frequency slot consumption of each candidate path for encrypted data transmission is calculated, and the frequency slot consumption is sorted in non-descending order and placed in the set and , go to step S6;

[0103] S6: Traverse the collection separately and Among all the candidate sub-paths for encrypted data transmission, check whether there is a candidate sub-path for encrypted data transmission whose maximum available spectrum block size MFS on the path meets the bandwidth requirement. If so, select the path as the sub-path for encrypted data transmission path mapping, and go to step S7; otherwise, the encrypted data transmission path mapping fails, and the algorithm ends.

[0104] S7: Combine all sub-paths of steps S4 and S6 to obtain a complete inter-domain encrypted data transmission mapping path, and go to step S8;

[0105] S8: Calculate the number of frequency slots required based on the highest modulation level that can be used for the selected path, allocate spectrum based on the first matching method, and proceed to step S9;

[0106] S9: Record and return the encrypted data transmission route spectrum allocation result.

[0107] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made in form and details without departing from the scope defined by the claims of the present invention.

Claims

1. A multi-domain virtual network security mapping method based on key balance and minimum consumption, characterized by: In this method, the quantum key distribution network is integrated into the multi-domain elastic optical network as the underlying physical network for virtual network mapping and combined with blockchain distributed management to coordinate and schedule inter-domain resources; In the virtual node mapping process, the correlation between virtual nodes and virtual link mappings and the multi-dimensional resource attributes of nodes are considered, and a node importance formula is designed to optimize virtual node mapping decisions. After completing the virtual node mapping, a virtual link weight formula is designed to determine the mapping order of virtual links; A quantum key distribution path mapping method based on key balancing is used to map the key requirements of the virtual link to a physical path with fewer hops and richer key resources. A minimum-cost encrypted data transmission path mapping method is used to select the path with the lowest spectrum consumption for encrypted data transmission and complete spectrum allocation. The method specifically includes the following steps: S1: Input the elastic optical network topology and resource usage status, virtual network request and key requirement. According to the virtual network request, broadcast it to each domain controller through the blockchain network for verification. And calculate the importance value of all virtual nodes according to the computing resource requirement of virtual nodes, virtual node degree, bandwidth of adjacent virtual links and key resource requirement. Sort all virtual nodes in non-ascending order according to importance value and save them in set N. v middle; Wherein, the virtual node The importance value of is calculated as follows: In the above formula, Represents a virtual node The computing resource requirements, Represents a virtual node The node degree, Represents the computing resource requirements of all virtual nodes in the virtual network, Representation and virtual nodes The set of adjacent virtual links, Represents a virtual node Adjacent virtual links bandwidth resource requirements, Indicates the bandwidth resource requirements of all virtual links in the virtual network, Represents a virtual node Adjacent virtual links Key resource requirements, The key resource requirements of all virtual links in the virtual network, α, β and γ are weight coefficients for weighing the resource attributes of each dimension, assuming α = 0.4, β = γ = 0.3; S2: Each domain controller counts the available computing resources, physical node degrees, bandwidth of adjacent physical links, and key resource values ​​of the physical nodes in the domain, and calculates the importance values ​​of all physical nodes in its domain; each domain controller sorts all physical nodes in the domain in non-ascending order according to their importance values ​​and stores them in the collection middle; The importance value of the physical node is calculated as follows: in, Represents a physical node The amount of available computing resources, Represents a physical node Node degree, CPU max Indicates the maximum computing resource capacity of the physical node, Representation and physical nodes The set of adjacent physical links, Represents a physical node Adjacent physical links The amount of available bandwidth resources, B max Indicates the maximum bandwidth resource capacity of the physical link, Represents a physical node Adjacent physical links The amount of available key resources, K max Indicates the maximum key resource capacity of the physical link; S3: According to the candidate mapping domain restrictions of the virtual node in the virtual network request, if the set If there is a physical node that meets the virtual node mapping domain restriction, the mapping scheme of the virtual node to the physical node is saved in the set VNM and the process goes to step S4. Otherwise, the virtual network mapping fails and the algorithm ends. The specific process of S3 is as follows: let the virtual node to be mapped be Virtual Node The candidate mapping domain is expressed as: In-order traversal The candidate physical nodes in the physical domain z are stored in the set In the check collection Is there a candidate mapping domain restriction physical node that meets the computing resource requirements of the virtual node? Right now If it exists, the virtual node Mapping to physical nodes Get the virtual node Mapping scheme, saved in the set VNM; otherwise, the virtual node If the mapping fails, the algorithm ends; S4: Repeat steps S2 and S3 to traverse the set N v All unmapped virtual nodes in the virtual network are obtained to obtain the feasible solution set VNM for mapping all virtual nodes in the virtual network; S5: Calculate the weight values ​​of all virtual links in the virtual network, sort them in non-ascending order according to the weight values, and put them into the set L v ; The virtual link weight is calculated as follows: In the above formula, ρ is the weight coefficient that weighs the virtual link bandwidth and key resource requirements, and its value is ρ = 0.5; if The larger the value of The higher the mapping priority, S6: From the set L v The virtual links to be mapped are selected in sequence, and according to the mapping schemes of all virtual nodes in the set VNM, the quantum key distribution path mapping method based on key balancing according to claim 2 is adopted to map the key resource requirements of the virtual links to the underlying physical network; S7: Using the encrypted data transmission routing spectrum allocation method based on minimum spectrum consumption according to claim 3, sequentially mapping the bandwidth resource requirements of each virtual link requested by the virtual network to the underlying physical network; S8: Calculate the mapping costs of all feasible mapping schemes for the virtual network, and select the mapping scheme with the lowest mapping cost as the final virtual network mapping scheme; Among them, the calculation formula of the mapping cost of the feasible mapping scheme is: In the above formula, Indicates a virtual link The physical path mapped by the bandwidth resource requirements, Indicates a virtual link The physical path mapped to the bandwidth resource requirements The number of physical link hops on Indicates a virtual link The physical path mapped to the key resource requirements, Indicates a virtual link The physical path mapped to the bandwidth resource requirements The number of physical link hops on the VLAN.

2. The multi-domain virtual network security mapping based on key balance and minimum consumption according to claim 1, characterized in that: The quantum key distribution path mapping method based on key equalization in S6 specifically includes the following steps: S601: The virtual link to be mapped The virtual nodes at both ends correspond to the physical nodes in the feasible solution set VNM, which are marked as and judge and Are they in the same physical domain? If so, the virtual link mapping is intra-domain mapping, and the process goes to step S602; otherwise, the virtual link mapping is inter-domain mapping, and the process goes to step S604; S602: For intra-domain mapping, under the management of the domain controller, first calculate K candidate quantum key distribution paths according to the K shortest path algorithm, assuming K = 3; calculate the key weight values ​​of these K candidate quantum key distribution paths respectively, and sort them in non-ascending order according to the key weight values, and put them into the set P key , go to step S603; Among them, the key weight calculation formula of the quantum key distribution candidate path is: In the above formula, Indicates a virtual link The jth path among the K candidate quantum key distribution paths mapped by the key resource requirements, K min Indicates the physical path The minimum available key amount among all physical links, Indicates the physical path The number of hops on the physical link, The larger the value of , the more keys are available on the path and the fewer hops. 603: Traverse set P key Among all candidate quantum key distribution paths in , check whether there is a path that meets the key requirements, i.e. If it exists, the path is selected as the quantum key distribution mapping path, and the process goes to step S7; otherwise, the quantum key distribution path mapping fails, and the algorithm ends. S604: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain are used as the source and destination nodes of the virtual link mapping. According to the inter-domain topology, a shortest path that meets the key requirements of the virtual network request is calculated, and the shortest path is determined to be between the two domain boundary nodes. and If the path exists, the path is recorded and saved as the inter-domain path of the virtual link mapping, and the process goes to step S605; otherwise, the quantum key distribution path mapping fails; S605: From the physical node arrive From the physical node arrive The paths are managed by their respective domain controllers. First, K shortest paths are calculated as candidate sub-paths for quantum key distribution. The key weight value of each candidate sub-path for quantum key distribution is calculated and sorted in non-ascending order according to the key weight value. The paths are placed in the set and , go to step S606; S606: Traverse the collection separately and All quantum key distribution candidate subpaths in the virtual link are checked to see if there is a quantum key distribution candidate subpath that meets the key requirements. If all exist, the path is selected as the subpath for quantum key distribution path mapping, and the process goes to step S607. Otherwise, the quantum key distribution path mapping of the virtual link fails, and the algorithm ends. S607: Combine the inter-domain path of the virtual link mapping obtained in step S604 and the quantum key distribution sub-path obtained in step S606 to obtain the complete inter-domain and intra-domain quantum key distribution mapping paths of the virtual link mapping.

3. The multi-domain virtual network security mapping based on key balance and minimum consumption according to claim 1, characterized in that: The spectrum allocation method for encrypted data transmission routing based on minimum spectrum consumption in S7 specifically includes the following steps: S701: The virtual link to be mapped The physical nodes mapped to the virtual nodes at both ends are marked as and Determine the physical node and Are they in the same physical domain? If so, the virtual link is an intra-domain mapping, and the process goes to step S702; otherwise, the virtual link is an inter-domain mapping, and the process goes to step S704; S702: For intra-domain mapping, under the management of the domain controller, first calculate K candidate transmission paths for encrypted data according to the K shortest path algorithm, assuming K = 3; calculate the frequency slot consumption required for the encrypted data to be transmitted on these K candidate transmission paths, and sort them in non-ascending order according to the frequency slot consumption, and save them in the set P data , go to step S703; The calculation formula for the frequency slot consumption required for encrypted data transmission on the candidate transmission path is: In the above formula, Indicates a virtual link The jth of the K candidate transmission paths mapped by the bandwidth resource demand, Represents candidate paths The number of hops on the physical link, m k Indicates the highest modulation level that can be used for the candidate path, G FS Indicates the bandwidth of the unit frequency slot, GB indicates the size of the protection frequency slot, The larger the value is, the more frequency slots the candidate path needs to consume when used as an encrypted data transmission path. S703: Traverse the set P data Among all candidate transmission paths, the number of frequency slots contained in the maximum available continuous spectrum block on the candidate path is represented by MFS, and it is determined whether there is a candidate transmission path whose number of frequency slots in the maximum available continuous spectrum block meets the virtual link bandwidth requirement, that is, whether there is a path with If so, the candidate transmission path is selected as the transmission path for virtual link mapping, and the process goes to step S708; otherwise, the virtual link mapping fails, and the algorithm ends. S704: For inter-domain mapping, under the management of the domain controller, you need to first and The boundary nodes of the physical domain of the elastic optical network are used as the source and destination nodes respectively. According to the inter-domain topology results, a shortest path that meets the bandwidth requirements of the virtual link is calculated as the inter-domain path of the virtual link mapping. The source and destination nodes of the inter-domain path are determined as the boundary nodes of the domain respectively. and If the inter-domain path exists, the inter-domain path is recorded and the process goes to step S705; otherwise, the virtual link mapping fails and the algorithm ends. S705: When the domain controller is turned off, the K shortest path method is used to calculate the path from the physical node To the physical domain boundary node The K shortest paths are calculated, and the frequency slot consumption of each shortest path is calculated respectively. Then, the frequency slot consumption is sorted in non-descending order and stored in the set In; Using the K shortest path method, from the physical node To the physical domain boundary node The K shortest paths are calculated, the frequency slot consumption required for the encrypted data to be transmitted on each shortest candidate path is calculated, and the frequency slot consumption is sorted in non-descending order and stored in the set , go to step S706; S706: Traverse the collection separately and Among all the candidate subpaths for encrypted data transmission, check whether there is a candidate subpath for virtual link mapping whose maximum available spectrum block size on the path meets the virtual link bandwidth requirement. If both exist, select the path as the subpath for virtual link mapping and go to step S707. Otherwise, the mapping of the virtual link mapping fails and the algorithm ends. S707: Combine the inter-domain path of the virtual link mapping obtained in step S704 and the sub-path of the virtual link mapping obtained in step S706 to obtain the complete inter-domain and intra-domain encrypted data mapping paths of the virtual link mapping; S708: For the path or path combination mapped by the virtual link, allocate spectrum to the mapped path in a first matching manner.