Method, device and system for secure transmission of OTN fine-grained services

By employing fine-grained flexible optical data units (fgODUflex) or optical service units (OSU) in the OTN for service mapping and quantum key encryption, the bandwidth waste and flexibility limitations caused by the large granularity of the ODU pipeline are solved, enabling efficient and secure transmission of small-granular services.

CN120568235BActive Publication Date: 2026-04-14RAISECOM TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing OTN technologies, the ODU pipeline granularity is relatively large, which cannot effectively meet the bandwidth requirements of small-granularity services, resulting in bandwidth waste and flexibility limitations. In particular, small-granularity services such as government and enterprise private lines, which have low bandwidth requirements but low latency and high security, cannot be effectively supported.

Method used

Service mapping is performed using fine-grained flexible optical data units (fgODUflex) or optical service units (OSU), and secure transmission of small-granular service units is achieved through quantum key encryption. The encryption key is updated using the quantum key lifecycle to ensure data security and flexibility.

Benefits of technology

It enables efficient and secure transmission of small-granularity services, makes full use of existing network resources, increases transmission security, and ensures the flexibility of low-bandwidth services and the effective use of network resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120568235B_ABST
    Figure CN120568235B_ABST
Patent Text Reader

Abstract

The application discloses a kind of OTN fine particle service security transmission method, equipment and system, first OTN equipment is mapped to small particle service unit by service data;Quantum key encryption processing is carried out to small particle service unit, and encrypted small particle service unit is multiplexed to ODU;ODU is multiplexed to OTU and obtains optical signal, is sent to second OTN equipment by OTN transmission network;Second OTN equipment receives optical signal and converts into electrical signal, and obtains OTN frame;OTN frame is demultiplexed and obtains ODU frame;ODU frame is demultiplexed and obtains encrypted small particle service unit, and the small particle service unit includes fgODUflex or OSU;Quantum key decryption processing is carried out to small particle service unit, and obtains small particle service unit before encryption. To solve the problem that great bandwidth waste and limit the flexibility of small particle service networking can be caused by quantum key encryption to ODUk.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of optical network transmission technology, and in particular to a secure transmission method, device and system for OTN fine-grained services. Background Technology

[0002] To ensure data security across different business scenarios, existing solutions involve multiplexing and mapping multiple services into an Optical Data Unit (ODUk), then encrypting the ODUk using quantum key distribution; finally, the encrypted ODUk is multiplexed and mapped into an Optical Channel Transport Unit (OTUk) for transmission, thereby achieving unified encryption for the multiple services.

[0003] The above scheme encrypts data using the ODU pipes in OTN. However, the smallest ODU pipe, ODU0, has a relatively large granularity (1.25G), primarily used for services with speeds greater than 1Gbit / s. Currently, there are many small-granularity services, such as enterprise leased lines, that require low latency and high security but not high bandwidth. This scheme cannot adequately meet the needs of these small-granularity services. For small-granularity services, this scheme would result in significant bandwidth waste and would limit the flexibility of networking such services.

[0004] Existing solutions cannot meet the demands of numerous existing services, such as government and enterprise leased lines, which require low bandwidth, multiple entries, low latency, and high security. Therefore, there is an urgent need for a method, device, and equipment for fine-grained secure service transmission. Summary of the Invention

[0005] The purpose of this application is to provide a secure transmission method, device and system for OTN fine-grained services, which solves the problems of excessive bandwidth waste caused by quantum key encryption of ODUk and the limitation of the flexibility of small-grained service networking.

[0006] In a first aspect, embodiments of this application provide a secure transmission method for OTN fine-grained services, the method being applied to a first OTN device, the method comprising:

[0007] The service data is mapped to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU).

[0008] The small-particle service unit is encrypted using quantum key encryption, and the encrypted small-particle service unit is multiplexed into the optical path data unit (ODU).

[0009] The ODU is multiplexed into an optical path transmission unit (OTU) and sent to a second OTN device via the OTN transmission network.

[0010] In some possible embodiments, the method further includes:

[0011] Obtain the quantum key generated by the first OTN device itself; or

[0012] Receive the quantum key distributed by the quantum key distribution device through the interface of the first OTN device;

[0013] The quantum key is updated according to its lifecycle.

[0014] In some possible embodiments, the quantum key used in the encryption process is updated in any of the following ways:

[0015] Use a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for encryption processing according to the quantum key lifecycle.

[0016] The N complete complex frames of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle. The quantum key used for encryption processing is updated according to the quantum key lifecycle, where N is greater than 1.

[0017] The set period is used as the quantum key lifecycle, and the quantum key used for encryption is updated according to the quantum key lifecycle.

[0018] In some possible embodiments, the quantum key used in the encryption process is updated in the following manner:

[0019] When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed.

[0020] When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key.

[0021] When the new quantum key lifecycle is determined and the local new quantum key is successfully loaded, the quantum key used in the encryption process is updated.

[0022] In some possible embodiments, the method further includes:

[0023] When encrypting the small-granularity service unit, the reserved field of the fgODUflex multiframe or OSU frame carries the quantum key tag KTI, MFI, and verification information used for encryption, wherein:

[0024] The MFI is cleared when a new lifecycle is reached and there is no alarm, and then incremented with each fgODUflex multiframe or OSU frame.

[0025] When the MFI reaches the threshold and no new quantum key is loaded locally, the MFI is maintained and an alarm is triggered;

[0026] When the MFI reaches the threshold and a new quantum key is loaded locally, the MFI is cleared to zero;

[0027] When the MFI has not reached the threshold and a new quantum key is loaded locally, the MFI is cleared to zero.

[0028] Secondly, embodiments of this application provide a secure transmission method for OTN fine-grained services, the method being applied to a second OTN device, the method comprising:

[0029] Receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame;

[0030] The OTN frame is demultiplexed to obtain the ODU frame;

[0031] The ODU frame is demultiplexed to obtain encrypted small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU).

[0032] The small-granular service unit is decrypted using quantum key decryption to obtain the small-granular service unit before encryption.

[0033] In some possible embodiments, the method further includes:

[0034] Obtain the quantum key generated by the second OTN device itself; or

[0035] Receive the quantum key distributed by the quantum key distribution device through the interface of the second OTN device;

[0036] The quantum key is updated according to its lifecycle.

[0037] In some possible embodiments, the quantum key used in the decryption process is updated in any of the following ways:

[0038] Take a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for decryption according to the quantum key lifecycle.

[0039] The N complete complex frames of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle. The quantum key used for decryption is updated according to the quantum key lifecycle, where N is greater than 1.

[0040] The set period is used as the quantum key lifecycle, and the quantum key used for decryption is updated according to the quantum key lifecycle.

[0041] In some possible embodiments, the quantum key used in the decryption process is updated in the following manner:

[0042] When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed.

[0043] When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key.

[0044] When the new quantum key lifecycle is determined to have been reached and the new local quantum key is successfully loaded, the quantum key used in the decryption process is updated.

[0045] In some possible embodiments, the method further includes:

[0046] The MFI and KTI are maintained locally. The local MFI is cleared when it reaches a new life cycle and then incremented with each decrypted fgODUflex multiframe or OSU frame. The local KTI is the quantum key tag of the locally loaded quantum key.

[0047] When decrypting the small-granular service unit, extract the quantum key tag KTI, MFI and verification information used for encryption from the reserved fields of the fgODUflex multiframe or OSU frame;

[0048] By comparing the extracted KTI with the local KTI, when the KTI changes and the keys of the first OTN device and the second OTN device are synchronized, the quantum key used in the decryption process is updated.

[0049] By comparing the extracted MFI with the local MFI, it is determined whether the first OTN device and the second OTN device are frame synchronized. If it is determined that there is no frame synchronization, corresponding alarm processing is performed.

[0050] In some possible embodiments, it is determined whether the first OTN device and the second OTN device are frame synchronized, and when it is determined that there is no frame synchronization, corresponding alarm processing is performed, including:

[0051] If the local MFI is equal to the threshold and is inconsistent with the extracted MFI, a key expiration alarm will be triggered.

[0052] If the extracted MFI is equal to the local MFI, it is determined that the first OTN device and the second OTN device are frame synchronized.

[0053] If the extracted MFI is not equal to the threshold but is greater than the local MFI, update the local MFI to the extracted MFI and issue a jump alarm.

[0054] If the extracted MFI is less than the local MFI, keep the local MFI unchanged and issue a replay alarm.

[0055] Thirdly, embodiments of this application provide a secure transmission device for OTN fine-grained services, which serves as a first OTN device and includes:

[0056] The service mapping module is used to map service data to small-granularity service units, which include fine-grained flexible optical data unit fgODUflex or optical service unit OSU.

[0057] An encryption module is used to perform quantum key encryption processing on the small-particle service units;

[0058] The ODU module is used to multiplex encrypted small-granularity service units into optical path data units (ODUs).

[0059] The OTU module is used to multiplex the ODU into an optical path transmission unit (OTU) and transmit it to a second OTN device via the OTN transmission network.

[0060] Fourthly, embodiments of this application provide a secure transmission device for OTN fine-grained services, which serves as a second OTN device and includes:

[0061] The OTU module is used to receive optical signals sent by the first OTN device and convert them into electrical signals to obtain OTN frames, and to demultiplex the OTN frames to obtain ODU frames.

[0062] The ODU module is used to demultiplex the ODU frame to obtain encrypted small-granularity service units, the small-granularity service units including fine-grained flexible optical data unit fgODUflex or optical service unit OSU.

[0063] The decryption module is used to perform quantum key decryption on the small-granular service unit to obtain the small-granular service unit before encryption.

[0064] The business processing module is used to map the small-granular business units before encryption to obtain business data.

[0065] Fifthly, embodiments of this application provide a secure transmission system for OTN fine-grained services, comprising:

[0066] The first OTN device is used to map service data to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSUs); the small-granularity service units are subjected to quantum key encryption, and the encrypted small-granularity service units are multiplexed into optical path data units (ODUs); the ODUs are multiplexed into optical path transmission units (OTUs) to obtain optical signals, which are then transmitted to the second OTN device via the OTN transmission network.

[0067] An OTN transmission network is used to transmit optical signals sent by a first OTN device to a second OTN device.

[0068] The second OTN device is used to receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame; the OTN frame is demultiplexed to obtain an ODU frame; the ODU frame is demultiplexed to obtain an encrypted small-granularity service unit, the small-granularity service unit including a fine-grained flexible optical data unit (fgODUflex) or an optical service unit (OSU); the small-granularity service unit is subjected to quantum key decryption processing to obtain the small-granularity service unit before encryption.

[0069] The secure transmission method for OTN fine-grained services provided in this application has the advantage of encrypting based on small-grained service units. It can make full use of existing network resources. The ciphertext encrypted based on small-grained service units can still use the original network resources of the intermediate nodes, and has no impact on the original network of the intermediate nodes. It can provide a separate key for encryption, which increases the security of transmission and ensures the flexibility of low-bandwidth services.

[0070] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description

[0071] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings introduced below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0072] Figure 1 A schematic diagram of the general encryption and decryption process used for secure business transmission in related technologies;

[0073] Figure 2 A schematic diagram of a secure transmission system for OTN fine-grained services provided in an embodiment of this application;

[0074] Figure 3 This is a schematic diagram of the fgODUflex multiframe structure according to an embodiment of this application;

[0075] Figure 4 A flowchart illustrating a secure transmission method for OTN fine-grained services applied to a first OTN device, provided in an embodiment of this application.

[0076] Figure 5 A flowchart illustrating a secure transmission method for OTN fine-grained services applied to a second OTN device, provided in an embodiment of this application.

[0077] Figure 6 This is a diagram of the fgODUflex encryption overhead structure provided in an embodiment of this application;

[0078] Figure 7 A flowchart of quantum key synchronization provided for embodiments of this application;

[0079] Figure 8 A flowchart of the MFI processing of the first OTN device provided in the embodiments of this application;

[0080] Figure 9a A schematic diagram of the quantum key download process of the first OTN device provided in this application embodiment;

[0081] Figure 9b A schematic diagram illustrating the process by which the first OTN device provided in this application updates its local quantum key using a downloaded quantum key;

[0082] Figure 9c The process for updating the quantum key used in the encryption service of the first OTN device provided in the embodiments of this application;

[0083] Figure 10 This is a flowchart illustrating the MFI processing of a second OTN device provided in an embodiment of this application.

[0084] Figure 11a A schematic diagram of the quantum key download process for the second OTN device provided in this application embodiment;

[0085] Figure 11b A schematic diagram illustrating the process by which the second OTN device provided in this application updates its local quantum key using a downloaded quantum key;

[0086] Figure 11c The process for updating the quantum key used in the encryption service of the second OTN device provided in this application embodiment;

[0087] Figure 12 This is a schematic diagram of the OSU frame structure provided in an embodiment of this application. Detailed Implementation

[0088] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on conventional or non-inventive effort. For steps that do not logically have a necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the control device executes the method, it may be executed sequentially or in parallel according to the method shown in the embodiments or drawings.

[0089] Basic telecommunications networks provide crucial support for important systems closely related to the national economy and people's livelihood, such as finance, energy, transportation, water supply, healthcare, and emergency services, as well as government affairs management. They are also related to national security, and ensuring the security of basic telecommunications networks has become a rigid requirement for the development of informatization.

[0090] Quantum Key Distribution (QKD) generates and distributes quantum keys based on quantum information theory. It has the theoretical advantage of "unconditional security". QKD can be used to distribute quantum keys for various services in fine-grained flexible optical data units (fgODUflex) or optical service units (OSU) to encrypt services and achieve secure transmission of multiple services.

[0091] To ensure data security in different business scenarios, such as Figure 1 As shown, the QKD terminal is responsible for distributing quantum keys. The existing solution involves multiplexing and mapping multiple services into an optical path data unit (ODUk), then using an encryption module to encrypt the ODUk with a quantum key. The encrypted ODUk is then multiplexed and mapped into an optical path transmission unit (OTUk) for transmission, thus achieving unified encryption for the multiple services. The 'k' above represents the level; the lower the level, the lower the corresponding ODU bandwidth.

[0092] Traditional OTN (Optical Transport Network) technology has a large service granularity, primarily used for services with speeds greater than 1 Gbit / s. To address the flexible bandwidth requirements of carrier and enterprise private lines and the small-granularity hard-pipe technology requirements of industry production networks, fine-grained OTN (fgOTN) technology and optical service units (OSUs) meet the technical needs of optical communication network development in different scenarios. The fine-grained flexible optical data unit (fgODUflex) employs 10M time slot hard isolation, providing p... The 10M flexible container supports service carrying capacity from 10Mbit / s to 1Gbit / s. OSU introduces the OSUflex container with granular speeds of 2.6 Mbit / s, supporting efficient carrying of customer services at rates from 2Mbit / s to 100Gbit / s.

[0093] Current solutions encrypt the ODU pipes in the OTN, but even the smallest ODU pipe, ODU0, has a relatively large granularity (1.25G), primarily used for services with speeds greater than 1Gbit / s. However, many small-granularity services, such as enterprise leased lines, have low bandwidth requirements but demand low latency and high security. This solution cannot adequately meet the needs of these small-granularity services. For such services, this approach results in significant bandwidth waste and limits the flexibility of network deployment.

[0094] In view of the above-mentioned problems existing in the related technologies, the embodiments of this application provide a secure transmission method, device and system for carrying small-granularity service units such as fine-grained flexible optical data unit (fgODUflex) or optical service unit (OSU). The small-granularity service units include circuit services and packet services such as government and enterprise leased line services, interactive network television IPTV (Internet Protocol TV) services, and Internet video services.

[0095] like Figure 2 As shown in the figure, this application provides a secure transmission system for OTN fine-grained services, including:

[0096] The first OTN device is used to map service data to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSUs); the small-granularity service units are subjected to quantum key encryption, and the encrypted small-granularity service units are multiplexed into optical path data units (ODUs); the ODUs are multiplexed into optical path transmission units (OTUs) and transmitted to the second OTN device via the OTN transmission network.

[0097] An OTN transmission network is used to transmit optical signals sent by a first OTN device to a second OTN device.

[0098] The second OTN device is used to receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame; the OTN frame is demultiplexed to obtain an ODU frame; the ODU frame is demultiplexed to obtain an encrypted small-granularity service unit, the small-granularity service unit including a fine-grained flexible optical data unit (fgODUflex) or an optical service unit (OSU); the small-granularity service unit is subjected to quantum key decryption processing to obtain the small-granularity service unit before encryption.

[0099] The secure transmission system for fine-grained OTN services provided in this application embodiment can securely transmit small-granularity service units, such as fine-grained flexible optical data units (fgODUflex) or optical service units (OSU). Specifically, these can be circuit-based services and packet services such as enterprise leased lines, IPTV, and internet video. By mapping the small-granularity service units to fgODUflex containers or OSU containers, quantum key encryption is applied to the fgODUflex or OSU. The encryption method in this application embodiment does not need to be adapted separately for different service types, but is uniformly encrypted, reducing the complexity of access encryption. The advantage of encryption based on fgODUflex or OSU granularity is that it can fully utilize existing network resources. Based on the ciphertext encrypted by one or more fgODUflex or OSU, the original network resources of the intermediate nodes can still be used, and there is no impact on the original network of the intermediate nodes. This application embodiment can support encryption based on one or more fgODUflex or OSU simultaneously or separately, and can provide individual quantum keys for encryption, increasing transmission security while ensuring the flexibility of low-bandwidth services.

[0100] This application provides a secure transmission device for OTN fine-grained services, which serves as a first OTN device, such as... Figure 2 As shown, it includes:

[0101] The service mapping module is used to map service data to small-granularity service units, which include fine-grained flexible optical data unit fgODUflex or optical service unit OSU.

[0102] An encryption module is used to perform quantum key encryption processing on the small-particle service units;

[0103] The ODU module is used to multiplex encrypted small-granularity service units into optical path data units (ODUs).

[0104] The OTU module is used to multiplex the ODU into an optical path transmission unit (OTU) and transmit it to a second OTN device via the OTN transmission network.

[0105] This application provides a secure transmission device for OTN fine-grained services, which serves as a second OTN device, such as... Figure 2 As shown, it includes:

[0106] The OTU module is used to receive optical signals sent by the first OTN device and convert them into electrical signals to obtain OTN frames, and to demultiplex the OTN frames to obtain ODU frames.

[0107] The ODU module is used to demultiplex the ODU frame to obtain encrypted small-granularity service units, the small-granularity service units including fine-grained flexible optical data unit fgODUflex or optical service unit OSU.

[0108] The decryption module is used to perform quantum key decryption on the small-granular service unit to obtain the small-granular service unit before encryption.

[0109] The business processing module is used to map the small-granular business units before encryption to obtain business data.

[0110] When the small-granularity service unit is fgODUflex, a complete service frame consists of multiple fgODUflex multiframes. Encryption specifically involves encrypting the payload within the fgODUflex multiframes to obtain the encrypted fgODUflex multiframe. Figure 3 The diagram shows the frame structure of an fgODUflex multiframe. The encrypted data range is the fgOPUflex payload area, which comprises columns 17 to 1904 and columns 1921 to 3824 of rows 1-4 of the fgODUflex multiframe. The encrypted data is encrypted using 128 bits. The encryption and processing procedure for the fgODUflex multiframe in this embodiment is as follows: the payload OPU of the fgODUflex multiframe is encrypted. Figure 3 In this context, fgOPUflexOH represents the overhead of the payload, and then the corresponding overhead is added to form an encrypted fgODUflex multiframe; one or more encrypted fgODUflex multiframes are multiplexed into an ODU; one or more ODUs are multiplexed into an OTU. To further improve the rate, multiple ODUs can be multiplexed into a higher-rate ODU to obtain a higher-level ODUk, and then one or more ODUs can be multiplexed into an OTU to obtain a higher-level OTUk, where the larger k is, the higher the bandwidth.

[0111] The secure transmission process for OTN fine-grained services applied to a first OTN device provided in this application embodiment is as follows: Figure 4 As shown, it mainly includes:

[0112] Step 401: Map the service data to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU), specifically fgODUflex multiframes and OSU frames.

[0113] Step 402: Perform quantum key encryption on the small-granular service unit, and reuse the encrypted small-granular service unit in the optical path data unit (ODU). Specifically, use quantum key to encrypt the payload of the fgODUflex multiframe or OSU frame to be encrypted to obtain the encrypted fgODUflex multiframe or OSU frame, and reuse it in the ODU.

[0114] Step 403: The ODU is multiplexed into an optical path transmission unit (OTU) and sent to the second OTN device via the OTN transmission network. Specifically, the OTN signal is converted from an electrical signal to an optical signal and then transmitted to the second OTN device.

[0115] In this embodiment, the first OTN device may acquire the quantum key in any of the following ways, but is not limited to: acquiring the quantum key generated by the first OTN device itself; or receiving the quantum key distributed by the quantum key distribution device through the interface of the first OTN device. The aforementioned quantum key distribution device may be, but is not limited to, a QKD terminal communicating with the first OTN device.

[0116] In this embodiment, the quantum key is updated according to the quantum key lifecycle, thereby ensuring data security.

[0117] The aforementioned quantum key cycle can be, but is not limited to, a set period of time for one complete multiframe of fgODUflex or one complete frame of OSU, N complete multiframes of fgODUflex or N complete frames of OSU.

[0118] In some possible embodiments, the first OTN device described above updates the quantum key used in the encryption process in any of the following ways:

[0119] 1) Take a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for encryption processing according to the quantum key lifecycle; the above complete multiframe or complete frame can be understood as a service frame. A complete multiframe of fgODUflex includes multiple fgODUflex multiframes, and a complete frame of OSU includes n OSU frames, where n is a positive integer greater than 1. In this embodiment of the application, a complete multiframe of fgODUflex or a complete frame of OSU is taken as the quantum key lifecycle. After encrypting n consecutive fgODUflex multiframes or OSU frames, the quantum key used for encryption is updated.

[0120] 2) Using N complete multiframes of fgODUflex or N complete frames of OSU as the quantum key lifecycle, the quantum key used for encryption processing is updated according to the quantum key lifecycle, where N is greater than 1; In this embodiment of the application, N complete multiframes of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle, then in continuous encryption n After N fgODUflex multiframes or OSU frames, the quantum key used for encryption is updated.

[0121] 3) Use the set period as the quantum key lifecycle and update the quantum key used for encryption processing according to the quantum key lifecycle.

[0122] The above-mentioned periodicity can be flexibly set as needed, and the quantum key used for encryption is updated at each set periodicity.

[0123] The decryption process of the second OTN device in this embodiment is as follows: Figure 5 As shown, it mainly includes:

[0124] Step 501: Receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame, which includes an encrypted fgODUflex multiframe or an OSU frame.

[0125] Step 502: Demultiplex the OTN frame to obtain the ODU frame;

[0126] Step 503: Demultiplex the ODU frame to obtain encrypted small-granularity service units. The small-granularity service units include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU), specifically encrypted fgODUflex multiframes or OSU frames.

[0127] Step 504: Perform quantum key decryption on the small-granular service unit to obtain the small-granular service unit before encryption. The quantum key used in the decryption process is the same as the quantum key used in the encryption process, thereby obtaining the fgODUflex multiframe or OSU frame before encryption.

[0128] In this embodiment of the application, the second OTN device may acquire the quantum key in any of the following ways, but not limited to: acquiring the quantum key generated by the second OTN device itself; or receiving the quantum key distributed by the quantum key distribution device through the interface of the second OTN device.

[0129] In this embodiment, the quantum key is updated according to the quantum key lifecycle, thereby ensuring data security.

[0130] The aforementioned quantum key lifetime can be, but is not limited to, one complete multiframe of fgODUflex or one complete frame of OSU, or N complete multiframes of fgODUflex or N complete frames of OSU, or a set period of time.

[0131] In some possible embodiments, the second OTN device described above updates the quantum key used for decryption processing in any of the following ways:

[0132] 1) Take a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for decryption according to the quantum key lifecycle; the above-mentioned complete multiframe of fgODUflex or a complete frame of OSU can be understood as a service frame. A complete multiframe of fgODUflex includes multiple fgODUflex multiframes, and a complete frame of OSU includes n OSU frames, where n is a positive integer greater than 1. In this embodiment of the application, a complete multiframe of fgODUflex or a complete frame of OSU is taken as the quantum key lifecycle. After encrypting n consecutive fgODUflex multiframes or OSU frames, the quantum key used for decryption is updated.

[0133] 2) Using N complete multiframes of fgODUflex or N complete frames of OSU as the quantum key lifecycle, the quantum key used for decryption is updated according to the quantum key lifecycle, where N is greater than 1; In this embodiment of the application, N complete multiframes of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle, then in continuous encryption n After N fgODUflex multiframes or OSU frames, update the quantum key used for decryption.

[0134] 3) Use the set period as the quantum key lifecycle, and update the quantum key used for decryption according to the quantum key lifecycle.

[0135] The above-mentioned periodicity can be flexibly set as needed, and the quantum key used for decryption is updated at each set periodicity interval.

[0136] In this embodiment of the application, the quantum key used in the encryption process for the first OTN device is updated in the following manner:

[0137] When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed.

[0138] When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key.

[0139] When the new quantum key lifecycle is determined and the local new quantum key is successfully loaded, the quantum key used in the encryption process is updated.

[0140] The process involves first downloading the quantum key from QKD, then updating the local quantum key, and finally updating the quantum key used for encryption, thus achieving quantum key updates. Each of these steps is triggered by different and independent conditions.

[0141] In this embodiment of the application, for the second OTN device, the quantum key used in the decryption process is updated in the following manner:

[0142] When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed.

[0143] When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key.

[0144] When the new quantum key lifecycle is determined to have been reached and the new local quantum key is successfully loaded, the quantum key used in the decryption process is updated.

[0145] The process involves first downloading the quantum key from QKD, then updating the local quantum key, and finally updating the quantum key used for decryption, thus achieving quantum key updates. Each of these steps is triggered by different and independent conditions.

[0146] In some possible embodiments, the first OTN device is also used for:

[0147] When encrypting the small-granularity service unit, the reserved field of the fgODUflex multiframe or OSU frame carries the quantum key tag KTI, MFI, and verification information used for encryption, wherein:

[0148] The MFI is cleared when it reaches a new lifecycle and there is no alarm. Then, as the fgODUflex multiframe or OSU frame increases, if there is an alarm, the MFI is not cleared. This allows the second OTN device to detect the abnormality of the MFI, thereby determining that there is a desynchronization problem.

[0149] When the MFI reaches the threshold and no new quantum key is loaded locally, the MFI is maintained and an alarm is triggered. If the MFI reaches the threshold and no new quantum key is loaded locally, it indicates that the quantum key has not been updated in a timely manner, and a corresponding alarm is triggered. Maintaining the MFI value unchanged can enable the second OTN device to detect the anomaly.

[0150] When the MFI reaches the threshold and a new quantum key is loaded locally, the MFI is cleared to zero. When the MFI reaches the threshold and a new quantum key is loaded locally, it indicates that the quantum key has been delivered in a timely manner, so that the quantum key is updated when a new quantum key cycle is reached.

[0151] If the MFI has not reached the threshold and a new quantum key is loaded locally, the MFI is cleared to zero. If the MFI has not reached the threshold and a new quantum key is loaded locally, it means that the quantum key has been issued in advance, and the MFI is cleared to zero. The second OTN device will also clear its local MFI when it loads the new quantum key synchronously, so as to ensure that the MFI of the first OTN device and the second OTN device are synchronized.

[0152] The first OTN device carries a quantum key tag (KTI) for encryption in the reserved field of the fgODUflex multiframe or OSU frame. This allows the second OTN device to compare the KTI with the local KTI to determine whether the quantum key is synchronized. The aforementioned verification information can be used by the second OTN device to verify the fgODUflex multiframe or OSU frame.

[0153] In some possible embodiments, the second OTN device described above is further used for:

[0154] The MFI and KTI are maintained locally. The local MFI is cleared when a new quantum key cycle is reached, and then incremented with each decrypted fgODUflex multiframe or OSU frame. The local KTI is the quantum key tag of the locally loaded quantum key. The KTI maintained locally by the second OTN device is the quantum key tag of the locally loaded quantum key. The quantum key tag is updated in the same way as the quantum key. When the locally loaded quantum key is updated, the above-mentioned quantum key tag is updated.

[0155] When decrypting the small-granular service unit, extract the quantum key tag KTI, MFI and verification information used for encryption from the reserved fields of the fgODUflex multiframe or OSU frame;

[0156] By comparing the extracted KTI with the local KTI, when the KTI changes and the keys of the first OTN device and the second OTN device are synchronized, the quantum key used in the decryption process is updated. The situations for updating the quantum key used in the decryption process include updating when the quantum key cycle has been reached or forcibly updating before the quantum key cycle has been reached.

[0157] By comparing the extracted MFI with the local MFI, it is determined whether the first OTN device and the second OTN device are frame synchronized. If it is determined that there is no frame synchronization, corresponding alarm processing is performed.

[0158] In this embodiment, the second OTN device extracts the KTI, MFI, and verification information. By comparing the extracted KTI with the local KTI, it can determine whether the quantum key is synchronized. By comparing the extracted MFI with the local MFI, it can determine whether the frame is synchronized. Appropriate alarm processing is performed when the quantum key or frame is determined to be out of sync. This embodiment can also use the extracted verification information to verify the fine-grained flexible optical data unit (fgODUflex) or optical service unit (OSU), thereby verifying whether the received fgODUflex or OSU is correct.

[0159] In some possible embodiments, it is determined whether the first OTN device and the second OTN device are frame synchronized, and when it is determined that there is no frame synchronization, corresponding alarm processing is performed, including:

[0160] The MFI thresholds of the first OTN device and the second OTN device may be different. If the local MFI is equal to the threshold and is inconsistent with the extracted MFI, the corresponding device will issue a key expiration alarm.

[0161] If the extracted MFI is equal to the local MFI, it is determined that the first OTN device and the second OTN device are synchronized. In the case of synchronization, the quantum keys of the two OTN devices are equal, so the synchronization of the two OTN devices can be determined by the equality of the two MFIs.

[0162] If the extracted MFI is not equal to the threshold but is greater than the local MFI, the local MFI will be updated to the extracted MFI and a jump alarm will be issued. In the event of local frame loss, the extracted MFI may be greater than the local MFI, thus triggering a corresponding alarm.

[0163] If the extracted MFI is less than the local MFI, keep the local MFI unchanged and issue a replay alarm. In the case of duplicate frames occurring in the first OTN device, the extracted MFI may be less than the local MFI.

[0164] The following provides a detailed embodiment of the secure transmission method for OTN fine-grained services according to this application.

[0165] This application takes the small-granularity service unit as the fine-granularity flexible optical data unit fgODUflex as an example to give a specific implementation method for secure transmission of OTN fine-granularity services.

[0166] like Figure 6 As shown, in the embodiment of this application, the reserved bytes of PSI (Private Set Intersection) in the fgODUflex multiframe are used for key synchronization and switching between the encrypted first OTN device and the decrypted second OTN device.

[0167] In this embodiment, the quantum key tag (KTI) used for quantum key synchronization switching, the quantum key period (MFI) used for key period calculation, and the CRC-8 verification information appear as a group and are uniformly distributed by the QKD quantum terminal. The CRC-8 is a 32-bit verification data with the polynomial x^8 + x^7 + x^4 + x^2 + 1. The CRC-8 verification range is PSI[252:255], used to protect the MFI and KTI from being overwritten.

[0168] like Figure 7 The diagram illustrates the quantum key synchronization process. After successfully downloading the quantum key (KEY LOAD) from the connected QKD terminal, the first OTN device uses the quantum key and CRC to encrypt the fgOPUflex payload. Simultaneously, it inserts the KTI into the PSI field and sends it. The sending process includes multiplexing the encrypted fgOPUflex multiframe as described above and sending it to the second OTN device. The second OTN device receives the optical signal and demultiplexes it to obtain the fgOPUflex multiframe. After successfully downloading the quantum key (KEY LOAD) from the connected QKD terminal, the second OTN device extracts the KTI from the PSI field of the received fgOPUflex multiframe. If the quantum key used is correct, it uses the corresponding quantum key and CRC to decrypt and verify the ciphertext. The decrypted data is the fgOPUflex payload.

[0169] like Figure 8 The specific processing flow of the first OTN device in the embodiment of this application is shown, wherein the MFI adopts a one-way synchronization process, specifically including:

[0170] Check if an fgOPUflex multiframe has been received. A complete fgOPUflex multiframe consists of 256 fgOPUflex multiframes. If not received, enter the idle state and continue the detection.

[0171] If a gOPUflex multiframe is received, increment the local MFI by 1;

[0172] The MFI is detected and compared with the software-configured MFI threshold MAX_MFI to determine the relationship between MFI and the threshold. The threshold determines the quantum key lifecycle. In this embodiment, the threshold MAX_MFI can be configured to 256.

[0173] When the MFI reaches the threshold and no new quantum key is loaded locally, the MFI is maintained and an alarm is issued. That is, if no new quantum key is received at the end of the quantum key cycle, the current quantum key cycle is considered and an alarm is issued.

[0174] When the MFI reaches the threshold and a new quantum key is loaded locally, the MFI is cleared to zero without alarm. That is, if a new quantum key is received at the end of the quantum key cycle, it means that the new quantum key can be used in the next quantum key cycle. The current quantum key cycle ends, and the MFI is cleared to zero and the new quantum key is used in the next quantum key cycle.

[0175] When the MFI has not reached the threshold and a new quantum key is loaded locally, there is no alarm and the MFI is cleared to zero, so that the new quantum key corresponds to a new quantum key cycle.

[0176] In this embodiment, the first OTN device updates the quantum key used for encryption according to the quantum key cycle. This mainly includes downloading the quantum key, updating the local quantum key using the downloaded quantum key, and updating the quantum key used for encryption services. The specific process is as follows:

[0177] like Figure 9a As shown, the quantum key download process mainly includes: detecting whether a key download judgment has been triggered; if not, entering an idle state to continue the judgment; if so, continuously sending quantum key loading requests to request the software to load the quantum key from the QKD; determining whether a new quantum key download instruction has been received from the key distribution device QKD; if a new quantum key download instruction has been received, executing the new quantum key download and closing the quantum key loading request, continuously sending key switching requests; otherwise, continuing to request the software to load the quantum key from the QKD; determining whether the switching of the quantum key used for encryption has been completed; if it is determined that the quantum key used for encryption has not been switched, returning to continue executing the quantum key download; if the currently used quantum key for encryption has been switched, closing the key switching request. In this embodiment, the above-mentioned triggering of the quantum key download judgment can be in automatic mode, that is, triggering the key download judgment when the quantum key's life cycle is halfway through, or it can be in manual mode triggered by software.

[0178] like Figure 9b As shown, the process of updating the local quantum key using the downloaded quantum key mainly includes: detecting whether the local key loading judgment is triggered. If not, it enters an idle state to continue the judgment. If the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. Specifically, it can be determined whether the KTI of the downloaded new quantum key is different from the KTI of the locally loaded quantum key, that is, whether the KTI has changed. If it is determined that they are different, the KTI of the locally loaded quantum key is updated using the KTI of the downloaded new quantum key. If the KTI has not changed, the local KTI, quantum key and CRC are kept unchanged. Furthermore, a duplicate alarm can be set for the downloaded KTI and the local KTI. The above-mentioned triggering of the local key loading judgment can be carried out in automatic mode when the quantum key cycle is reached, or it can be triggered by software in manual mode.

[0179] like Figure 9c As shown, the process of updating the quantum key used in the encryption service mainly includes: detecting whether the service KTI update judgment is triggered. If not, it enters the idle state to continue detecting. If the service KTI update judgment is triggered and the local new quantum key is successfully loaded, the quantum key and CRC used for encryption processing are updated using the locally loaded new quantum key, and the quantum key update success indication of the encryption service is output.

[0180] In this embodiment, the KTI change ensures that the software issues a new quantum key, which can switch to the local new KTI 5 frames in advance to perform CRC calculation and overhead filling. Therefore, when switching the quantum key used for encryption services at the quantum key cycle of 256 complex frames, sufficient timing is guaranteed. This embodiment adopts single-module processing and supports multi-channel multiplexing.

[0181] In this embodiment, the quantum key and CRC are loaded in units of 256 multiframes. The quantum key and CRC are switched after the lifecycle ends or the software is triggered.

[0182] like Figure 10 The specific processing flow of the second OTN device in the embodiment of this application shown includes:

[0183] Check if MFI extraction in the receiving direction is triggered; if not, enter the idle state and continue checking.

[0184] If MFI extraction in the receiving direction is triggered, check whether an fgOPUflex multiframe has been received. A complete fgOPUflex multiframe consists of 256 fgOPUflex multiframes. If not received, enter the idle state and continue the detection.

[0185] If a gOPUflex multiframe is received, increment the local MFI by 1 and extract the MFI from the gOPUflex multiframe;

[0186] Check if the locally loaded quantum key has been updated. If the locally loaded quantum key has been updated, clear the MFI and clear the alarm information.

[0187] If the locally loaded quantum key has not been updated, check whether the CRC check passes. If the CRC check fails, indicate the CRC error count.

[0188] When the CRC check passes, the extracted MFI is compared with the local MFI.

[0189] If the extracted MFI is equal to the threshold and inconsistent with the local MFI, the quantum key cycle ends and an expired alarm is triggered.

[0190] If the extracted MFI is equal to the local MFI, it is determined that the first OTN device and the second OTN device are frame synchronized, the local MFI remains unchanged and there is no alarm.

[0191] If the extracted MFI is not equal to the threshold but is greater than the local MFI, update the local MFI to the extracted MFI and issue a jump alarm.

[0192] If the extracted MFI is less than the local MFI, keep the local MFI unchanged and issue a replay alarm.

[0193] In this embodiment, the second OTN device updates the quantum key used for decryption according to the quantum key cycle. This mainly includes downloading the quantum key, updating the local quantum key using the downloaded quantum key, and updating the quantum key used for decryption services. Specifically, it includes:

[0194] like Figure 11a The quantum key download process mainly includes: detecting whether a key download judgment has been triggered; if not, entering an idle state to continue the judgment; if so, requesting the software to load the quantum key from the QKD; determining whether a new quantum key download instruction has been received from the key distribution device (QKD); if a new quantum key download instruction has been received, executing the new quantum key download, closing the quantum key download request, and continuously sending key switching requests; otherwise, continuing to request the software to load the quantum key from the QKD; after the quantum key is downloaded, determining whether the quantum key used for encryption has been switched; if not switched, keeping the quantum key download request closed and continuously sending key switching requests; otherwise, closing the key switching request. In this embodiment, the above-mentioned triggering of quantum key download can be in automatic mode, that is, triggering the key download judgment when the quantum key's life cycle is halfway through, or it can be in manual mode triggered by software.

[0195] like Figure 11b The process of updating the local quantum key using the downloaded quantum key mainly includes: checking whether the local KTI update time has been reached; if so, entering an idle state to continue checking; otherwise, judging whether the local KTI and the extracted KTI have changed based on the key switching request; if they have changed, updating the locally loaded quantum key's KTI with the KTI of the downloaded new quantum key; if the KTI has not changed, keeping the local KTI, quantum key, and CRC unchanged. Furthermore, a duplicate alarm for the configured KTI and the local KTI can also be performed.

[0196] like Figure 11cThe process of updating the quantum key used for decryption mainly includes: extracting the KTI from the fgOPUflex multiframe in the idle state; determining whether to update the KTI used for decryption; if the local KTI is equal to the extracted KTI, updating the quantum key and CRC used for decryption and outputting a quantum key update success indication for the decryption service; otherwise, issuing an asynchronous alarm when the local KTI is not equal to the extracted KTI.

[0197] The above embodiments are illustrated using the fgOPUflex multiframe as an example of a small-granularity service unit. When the small-granularity service unit is an OSU frame, such as Figure 12 As shown, the SQ field in the OSU frame is a reserved field, so the KTI, MFI and CRC can be carried in the SQ part. For the specific implementation process, please refer to the above implementation method, which will not be described in detail here.

[0198] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0199] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A secure transmission method for OTN fine-grained services, the method being applied to a first OTN device, characterized in that, The method includes: The service data is mapped to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU). The small-granular service unit is encrypted using quantum key encryption. The encrypted small-granular service unit is then multiplexed into the optical path data unit (ODU). The quantum key is updated according to the quantum key lifecycle. When encrypting the small-granular service unit, the quantum key tag KTI used for encryption, the quantum key period MFI used for key period calculation, and verification information are carried in the reserved field of the fgODUflex multiframe or OSU frame. The second OTN device maintains the MFI locally. The MFI adopts a one-way synchronization process so that the second OTN device can determine whether the first OTN device and the second OTN device are frame synchronized by comparing the extracted MFI with the local MFI. The ODU is multiplexed into an optical path transmission unit (OTU) and sent to a second OTN device via the OTN transmission network.

2. The method according to claim 1, characterized in that, Also includes: Obtain the quantum key generated by the first OTN device itself; or The quantum key distributed by the quantum key distribution device is received through the interface of the first OTN device.

3. The method according to claim 1, characterized in that, Update the quantum key used in the encryption process using any of the following methods: Use a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for encryption processing according to the quantum key lifecycle. The N complete complex frames of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle. The quantum key used for encryption processing is updated according to the quantum key lifecycle, where N is greater than 1. The set period is used as the quantum key lifecycle, and the quantum key used for encryption is updated according to the quantum key lifecycle.

4. The method according to claim 2, characterized in that, The quantum key used in the encryption process is updated in the following manner: When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed. When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key. When the new quantum key lifecycle is determined and the local new quantum key is successfully loaded, the quantum key used in the encryption process is updated.

5. The method according to any one of claims 2 to 4, characterized in that, Also includes: The MFI is cleared when a new lifecycle is reached and there is no alarm, and then incremented with each fgODUflex multiframe or OSU frame. When the MFI reaches the threshold and no new quantum key is loaded locally, the MFI is maintained and an alarm is triggered; When the MFI reaches the threshold and a new quantum key is loaded locally, the MFI is cleared to zero; When the MFI has not reached the threshold and a new quantum key is loaded locally, the MFI is cleared to zero.

6. A secure transmission method for OTN fine-grained services, wherein the method... The method is applied to a second OTN device, characterized in that, The method includes: Receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame; The OTN frame is demultiplexed to obtain the ODU frame; The ODU frame is demultiplexed to obtain encrypted small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSU). The small-particle service unit is decrypted using quantum key decryption to obtain the small-particle service unit before encryption. The quantum key is updated according to its lifecycle; The MFI is maintained locally, where the local MFI is cleared when it reaches a new lifecycle and then incremented with each decrypted fgODUflex multiframe or OSU frame. When decrypting the small-granular service unit, extract the quantum key tag KTI used for encryption, the quantum key period MFI used for key period calculation, and the verification information from the reserved fields of the fgODUflex multiframe or OSU frame; By comparing the extracted MFI with the local MFI, it is determined whether the first OTN device and the second OTN device are frame synchronized. If it is determined that there is no frame synchronization, corresponding alarm processing is performed.

7. The method according to claim 6, characterized in that, Also includes: Obtain the quantum key generated by the second OTN device itself; or The quantum key distributed by the quantum key distribution device is received through the interface of the second OTN device.

8. The method according to claim 6, characterized in that, Update the quantum key used for decryption in any of the following ways: Take a complete multiframe of fgODUflex or a complete frame of OSU as the quantum key lifecycle, and update the quantum key used for decryption according to the quantum key lifecycle. The N complete complex frames of fgODUflex or N complete frames of OSU are used as the quantum key lifecycle. The quantum key used for decryption is updated according to the quantum key lifecycle, where N is greater than 1. The set period is used as the quantum key lifecycle, and the quantum key used for decryption is updated according to the quantum key lifecycle.

9. The method according to claim 7, characterized in that, The quantum key used in the decryption process is updated in the following manner, including: When triggering the key download judgment, it is determined whether a new quantum key download instruction has been received from the key distribution device QKD. If it is determined that a new quantum key download instruction has been received, the new quantum key download is performed. When the local key loading judgment is triggered, it is determined whether the downloaded new quantum key is different from the locally loaded quantum key. If they are different, the locally loaded quantum key is updated using the downloaded new quantum key. When the new quantum key lifecycle is determined to have been reached and the new local quantum key is successfully loaded, the quantum key used in the decryption process is updated.

10. The method according to any one of claims 7 to 9, characterized in that, Also includes: KTI is maintained locally; local KTI is the quantum key tag of the locally loaded quantum key. By comparing the extracted KTI with the local KTI, when the KTI changes and the keys of the first OTN device and the second OTN device are synchronized, the quantum key used in the decryption process is updated.

11. The method according to claim 10, characterized in that, Determine whether the first OTN device and the second OTN device are frame synchronized, and perform corresponding alarm processing when it is determined that there is no frame synchronization, including: If the local MFI is equal to the threshold and is inconsistent with the extracted MFI, a key expiration alarm will be triggered. If the extracted MFI is equal to the local MFI, it is determined that the first OTN device and the second OTN device are frame synchronized. If the extracted MFI is not equal to the threshold but is greater than the local MFI, update the local MFI to the extracted MFI and issue a jump alarm. If the extracted MFI is less than the local MFI, keep the local MFI unchanged and issue a replay alarm.

12. A secure transmission device for OTN fine-grained services, characterized in that, This device, as the first OTN device, includes: The service mapping module is used to map service data to small-granularity service units, which include fine-grained flexible optical data unit fgODUflex or optical service unit OSU. An encryption module is used to perform quantum key encryption processing on the small-particle service units; The ODU module is used to multiplex encrypted small-granularity service units into optical path data units (ODUs). The quantum key is updated according to the quantum key lifecycle. When encrypting the small-granularity service unit, the reserved field of the fgODUflex multiframe or OSU frame carries the quantum key tag KTI used for encryption, the quantum key period MFI used for key period calculation, and verification information. The second OTN device maintains the MFI locally. The MFI adopts a one-way synchronization process so that the second OTN device can determine whether the first OTN device and the second OTN device are frame synchronized by comparing the extracted MFI with the local MFI. The OTU module is used to multiplex the ODU into an optical path transmission unit (OTU) and transmit it to a second OTN device via the OTN transmission network.

13. A secure transmission device for OTN fine-grained services, characterized in that, This device, as a second OTN device, includes: The OTU module is used to receive optical signals sent by the first OTN device and convert them into electrical signals to obtain OTN frames, and to demultiplex the OTN frames to obtain ODU frames. The ODU module is used to demultiplex the ODU frame to obtain encrypted small-granularity service units, the small-granularity service units including fine-grained flexible optical data unit fgODUflex or optical service unit OSU. The decryption module is used to perform quantum key decryption on the small-granular service unit to obtain the small-granular service unit before encryption. The business processing module is used to map the small-granular business units before encryption to obtain business data; The quantum key is updated according to its lifecycle; The MFI is maintained locally, where the local MFI is cleared when it reaches a new lifecycle and then incremented with each decrypted fgODUflex multiframe or OSU frame. When decrypting the small-granular service unit, extract the quantum key tag KTI used for encryption, the quantum key period MFI used for key period calculation, and the verification information from the reserved fields of the fgODUflex multiframe or OSU frame; By comparing the extracted MFI with the local MFI, it is determined whether the first OTN device and the second OTN device are frame synchronized. If it is determined that there is no frame synchronization, corresponding alarm processing is performed.

14. A secure transmission system for OTN fine-grained services, characterized in that, include: A first OTN device maps service data to small-granularity service units, which include fine-grained flexible optical data units (fgODUflex) or optical service units (OSUs). The small-granularity service units are subjected to quantum key encryption, and the encrypted small-granularity service units are multiplexed into optical path data units (ODUs). The quantum key is updated according to its lifecycle. When encrypting the small-granularity service units, the reserved field of the fgODUflex multiframe or OSU frame carries the quantum key tag (KTI) used for encryption, the quantum key period (MFI) used for key period calculation, and verification information. A second OTN device locally maintains the MFI, which employs a one-way synchronization process to ensure that the second OTN device determines whether the first and second OTN devices are frame-synchronized by comparing the extracted MFI with the local MFI. The ODU is multiplexed into an optical path transmission unit (OTU) to obtain an optical signal, which is then transmitted to the second OTN device via the OTN transmission network. An OTN transmission network is used to transmit optical signals sent by a first OTN device to a second OTN device. The second OTN device is used to receive the optical signal sent by the first OTN device and convert it into an electrical signal to obtain an OTN frame; demultiplex the OTN frame to obtain an ODU frame; demultiplex the ODU frame to obtain an encrypted small-granularity service unit, the small-granularity service unit including a fine-grained flexible optical data unit fgODUflex or an optical service unit OSU; and perform quantum key decryption processing on the small-granularity service unit to obtain the small-granularity service unit before encryption. The quantum key is updated according to its lifecycle; The MFI is maintained locally, where the local MFI is cleared when it reaches a new lifecycle and then incremented with each decrypted fgODUflex multiframe or OSU frame. When decrypting the small-granular service unit, extract the quantum key tag KTI used for encryption, the quantum key period MFI used for key period calculation, and the verification information from the reserved fields of the fgODUflex multiframe or OSU frame; By comparing the extracted MFI with the local MFI, it is determined whether the first OTN device and the second OTN device are frame synchronized. If it is determined that there is no frame synchronization, corresponding alarm processing is performed.

Citation Information

Patent Citations

  • Method, device and equipment for safely transporting multiple services in optical transport network

    CN108667526A

  • Encryption transmission method and device

    CN115549895A