Quantum key synchronization storage method for QKD
Through dynamic topology perception and edge collaborative pre-verification mechanism, combined with state-adaptive storage optimization, the problems of inconsistent key pool status and central node verification bottleneck in quantum key distribution technology are solved, and efficient and secure key synchronization and storage are achieved.
Patent Information
- Application Number
- CN202511087783.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-05
AI Technical Summary
Existing quantum key distribution technologies in dynamic network topologies can easily lead to inconsistent key pool status, low retrieval efficiency, performance bottlenecks caused by the central node verification mechanism, and difficulty in balancing synchronization real-time performance and resource utilization with a fixed synchronization cycle.
It adopts a linkage mechanism of dynamic topology awareness triggering, edge collaborative pre-verification and state adaptive storage. By monitoring the connection status of network nodes and the key generation rate, it generates intelligent synchronization trigger rules, combines edge node pre-verification and physical storage optimization, and realizes efficient synchronization and secure storage of keys.
The real-time and reliability of key synchronization in dynamic networks are improved, redundant synchronization operations are reduced, storage resource utilization is optimized, and key retrieval speed and system anti-attack capabilities are increased.
Smart Images

Figure CN120582785B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital information transmission, and in particular to a quantum key synchronization storage method for QKD. Background Art
[0002] Quantum key distribution (QKD) technology uses the principles of quantum mechanics to achieve unconditionally secure key transmission. The generated keys must be synchronized and stored between communication nodes to support subsequent encryption applications. Existing technologies typically rely on timestamp synchronization protocols, hierarchical storage architectures, and centralized verification mechanisms.
[0003] Existing solutions often employ a fixed-cycle synchronization strategy, with a central node centrally managing key pool status and performing full verification. In storage layer design, keys are stored sequentially in chronological order, with a hash tree structure ensuring data integrity. Some improved solutions incorporate edge node caching mechanisms to reduce the load on central nodes.
[0004] However, a fixed synchronization cycle can easily lead to inconsistent key pool status in a dynamic network topology. Edge nodes only serve as cache carriers and do not participate in verification decisions. Hierarchical storage does not consider the differences in key lifecycle status, resulting in low retrieval efficiency. The full verification mechanism of the central node causes performance bottlenecks in large-scale networks. Summary of the Invention
[0005] To solve the above problems, the present invention provides a quantum key synchronization storage method for QKD, which adopts a linkage mechanism of dynamic topology perception triggering, edge collaborative pre-verification and state adaptive storage, and can achieve efficient key synchronization in dynamic networks, while improving storage resource utilization and system anti-attack capabilities.
[0006] The above objectives can be achieved through the following solutions:
[0007] A quantum key synchronization storage method for QKD includes monitoring the node connection status of a quantum key distribution network to generate a dynamic topology map; obtaining the key generation rate of the nodes in the dynamic topology map, and generating a synchronization trigger rule in combination with a preset synchronization period reference value; triggering a key synchronization instruction according to the synchronization trigger rule, and sending the key synchronization instruction to a target node; receiving a key data packet returned by the target node, extracting a key hash value summary in the key data packet; performing edge collaborative pre-verification on the key hash value summary to generate a pre-verification result; executing a key storage operation based on the pre-verification result; obtaining a key status label in the key data packet, writing the synchronized key into a corresponding physical storage area according to the key status label, and updating the priority mapping relationship of the logical index layer.
[0008] Optionally, the generation of synchronization trigger rules includes: adjusting the preset synchronization period reference value based on the node access or disconnection events monitored by the dynamic topology map to generate a first trigger period; generating a second trigger period through an incremental synchronization period calculation process according to the change value of the key generation rate in adjacent time windows; when the node connection state is stable and the key generation rate fluctuation is within a preset range, using a weighted fusion algorithm to combine the first trigger period and the second trigger period to generate a mixed trigger period, and using the first trigger period, the second trigger period or the mixed trigger period as the synchronization trigger rule.
[0009] Optionally, the edge collaborative pre-verification of the key hash value summary and the generation of the pre-verification result include: selecting the adjacent node set of the target node from the dynamic topology map; sending a comparison request of the key hash value summary to the adjacent node set; counting the number of consistent summaries returned by the adjacent node set, and when the number of consistent summaries exceeds a preset ratio threshold, generating a fast synchronization instruction; when the number of consistent summaries does not reach the ratio threshold, generating a full verification instruction; wherein, the pre-verification result includes a fast synchronization instruction and a full verification instruction.
[0010] Optionally, performing the key storage operation based on the pre-verification result includes: when the quick synchronization instruction is received, extracting the difference bitmap from the key data packet, locating and transmitting only the key fragment to be synchronized according to the difference bitmap to complete the key storage operation; when the full verification instruction is received, loading the preset hash tree construction rules to perform a hierarchical hash operation on the key data packet to generate a root hash value, and after comparing the root hash value with the preset baseline root hash value to ensure consistency, writing all the key data to complete the key storage operation.
[0011] Optionally, the priority mapping relationship of updating the logical index layer includes: identifying the hot zone identifier, warm zone identifier and cold zone identifier in the key status label; promoting the key index address corresponding to the hot zone identifier to the top storage bit of the logical index layer; when it is detected that the proportion of the number of keys of the cold zone identifier exceeds a preset threshold, triggering the merging and reorganization operation of the physical storage block.
[0012] Optionally, the merging and reorganization operation of the physical storage blocks includes: scanning the physical storage area to generate a fragmentation distribution map containing storage block location information and free area size; based on the fragmentation distribution map, calculating and generating the optimal merging path of the cold area storage blocks through a migration cost model; performing data migration according to the optimal merging path, and updating the corresponding physical address in the priority mapping relationship of the logical index layer after the migration is completed.
[0013] Optionally, before sending the key synchronization instruction, it also includes: executing a two-way authentication protocol with the target node, verifying the legitimacy of the identity by exchanging random challenge codes; after the legitimacy of the identity is verified, obtaining the current network timestamp and the target node identifier to generate a watermark seed, using the watermark seed to generate a dynamic encrypted watermark, and embedding the dynamic encrypted watermark into the key synchronization instruction or key data packet.
[0014] Optionally, the use of the watermark seed to generate a dynamic encrypted watermark and embedding the dynamic encrypted watermark into the key synchronization instruction or key data packet includes: using the hardware fingerprint of the target node as a chaotic parameter and the watermark seed parameter as an initial value to generate a chaotic sequence; using the chaotic sequence to generate a dynamic watermark matrix to obtain a dynamic encrypted watermark; performing an XOR operation on the dynamic encrypted watermark and the header information of the key data packet to generate an encrypted data packet header.
[0015] Optionally, the method further comprises: capturing illegal read requests in real time in the physical storage area; when the illegal read request is detected, redirecting the logical address of the attacked storage block to a backup storage area, and triggering a key regeneration process.
[0016] Based on the same inventive concept, the present invention also provides a quantum key synchronization storage system for QKD, which includes: a dynamic topology perception module, which is used to monitor the node connection status of the quantum key distribution network and generate a dynamic topology map; a synchronization rule generation module, which is used to obtain the key generation rate of the nodes in the dynamic topology map, and generate a synchronization trigger rule in combination with a preset synchronization period reference value; an instruction distribution module, which is used to trigger the key synchronization instruction according to the synchronization trigger rule and send the key synchronization instruction to the target node; a data extraction module, which is used to receive the key data packet returned by the target node and extract the key hash value summary in the key data packet; an edge pre-verification module, which is used to perform edge collaborative pre-verification on the key hash value summary and generate a pre-verification result; a storage execution module, which is used to perform a key storage operation based on the pre-verification result; a storage optimization module, which is used to obtain the key status label in the key data packet, write the synchronized key into the corresponding physical storage area according to the key status label, and update the priority mapping relationship of the logical index layer.
[0017] Compared with the prior art, the present invention has the following advantages:
[0018] 1. By combining dynamic network topology perception with a flexible synchronization trigger mechanism, the present invention can adapt to dynamic network environments where nodes frequently connect or disconnect, while ensuring the consistency of the key pool and reducing redundant synchronization operations, significantly improving the real-time performance and reliability of key synchronization.
[0019] 2. The present invention adopts a two-layer verification architecture of collaborative pre-verification by edge nodes and deep verification by central nodes, which effectively disperses the computational pressure of traditional centralized verification, ensures accurate identification of abnormal data while reducing synchronization delay, and achieves balanced optimization of efficiency and security.
[0020] 3. The present invention adopts the physical storage partitioning and logical index dynamic mapping technology based on key status labels. By separating the storage of hot and cold data and intelligently reorganizing the fragments, it optimizes the storage space utilization and improves the retrieval response speed of high-frequency keys, forming a dynamic adaptation mechanism for storage resources and access requirements.
[0021] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] Figure 1 It is a flowchart of a quantum key synchronous storage method for QKD according to an embodiment of the present invention.
[0024] Figure 2 This is a schematic diagram of storage distribution before merging and reorganization according to an embodiment of the present invention.
[0025] Figure 3 This is a schematic diagram of storage distribution after merging and reorganization according to an embodiment of the present invention.
[0026] Figure 4 1 is a schematic diagram of priority mapping of hot / warm / cold zone keys for logical index layer optimization according to an embodiment of the present invention.
[0027] Figure 5 It is a structural diagram of a quantum key synchronization storage system for QKD according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0029] Reference Figure 1 An embodiment of the present invention proposes a quantum key synchronization storage method for QKD, which adopts a linkage mechanism of dynamic topology perception triggering, edge collaborative pre-verification and state adaptive storage, and can achieve efficient key synchronization in dynamic networks while improving storage resource utilization and system anti-attack capabilities.
[0030] The method of this embodiment specifically includes:
[0031] Monitor the node connection status of the quantum key distribution network and generate a dynamic topology map;
[0032] Obtaining the key generation rate of the nodes in the dynamic topology map, and generating a synchronization trigger rule in combination with a preset synchronization period reference value;
[0033] Triggering a key synchronization instruction according to the synchronization triggering rule, and sending the key synchronization instruction to the target node;
[0034] Receive the key data packet returned by the target node, and extract the key hash value digest in the key data packet;
[0035] Performing edge collaborative pre-verification on the key hash value summary to generate a pre-verification result;
[0036] Based on the pre-verification result, performing a key storage operation;
[0037] The key status tag in the key data packet is obtained, the synchronized key is written into the corresponding physical storage area according to the key status tag, and the priority mapping relationship of the logical index layer is updated.
[0038] By dynamically sensing the node connection status of the quantum key distribution network, a real-time topology map is generated. Intelligent triggering rules are constructed based on the key generation rate and a preset synchronization benchmark period, enabling the adaptive generation and issuance of synchronization instructions. During key packet transmission, a collaborative pre-verification mechanism at the edge nodes performs distributed verification of the key hash value digest. Full or incremental synchronization is selected based on the verification results. Finally, the synchronized keys are written to the physical storage area according to priority based on the key status tag, and the logical index mapping is updated. This method, through a three-level linkage mechanism of dynamic topology awareness, edge collaborative verification, and state-driven storage, forms a closed-loop control system for network state awareness, data verification decision-making, and storage optimization. Dynamically adjusting the synchronization trigger mechanism effectively adapts to network topology changes, reducing the risk of synchronization failures caused by frequent node connections or disconnections. The collaborative pre-verification mechanism at the edge distributes pressure on central nodes, improving verification efficiency while ensuring data consistency. A storage optimization strategy based on key status tags enables coordinated management of physical storage and logical indexes, significantly improving key retrieval speed and storage resource utilization. The deep coupling of various technical links results in an overall performance improvement, solves the common problems of synchronization delay, storage fragmentation and central node overload in traditional solutions, and enhances the robustness and security of the quantum key synchronization storage system.
[0039] Optionally, generating a synchronization trigger rule includes:
[0040] Based on the node access or disconnection events monitored by the dynamic topology map, a preset synchronization period reference value is adjusted to generate a first trigger period;
[0041] Generating a second trigger period through an incremental synchronization period calculation process according to a change value of the key generation rate in adjacent time windows;
[0042] When the node connection status is stable and the key generation rate fluctuation is within a preset range, a weighted fusion algorithm is used to combine the first trigger period and the second trigger period to generate a mixed trigger period, and the first trigger period, the second trigger period or the mixed trigger period is used as a synchronization trigger rule.
[0043] Specifically, when generating synchronization trigger rules, the state monitoring agent deployed on the network node first captures the node access or disconnection events in real time. When a new node is detected to join the network or an existing node is disconnected, the system automatically calls the cycle adjustment algorithm and multiplies the preset synchronization cycle reference value by the adjustment coefficient to obtain the first trigger cycle. For the first trigger cycle ,have:
[0044] ,
[0045] in is the synchronization period reference value, The adjustment coefficient is calculated in real time according to the node change frequency. ,have:
[0046] ,
[0047] in is the maximum adjustment factor, usually 1.0 (no adjustment), is the minimum adjustment coefficient, for example 0.5, which represents the most unstable state of the network. is the total number of node access or disconnection events that occurred within the window, is a preset event number threshold, indicating the number of events (e.g., 10) at which the network is considered to have reached the maximum dynamic level within the time window. Exceed ,but according to The system continuously monitors the key generation rate of each target node. In two adjacent time windows, the rate of change of the key generation rate is calculated. :
[0048] ,
[0049] in, is the key generation rate in the previous time window, is the key generation rate of the next time window, when When the fluctuation threshold (e.g., 20%) is exceeded, the calculation of the second trigger cycle is started. This calculation uses a nonlinear exponential decay function to make a more sensitive response to the sharp change of the rate. ,have:
[0050] ,
[0051] in, is the natural exponential function, is a positive sensitivity coefficient (e.g. ), which is used to adjust the degree to which the synchronization period is shortened as the rate changes. The larger the value, the more sensitive the response to rate changes. This formula ensures that the larger the fluctuation in the key generation rate, The shorter the cycle, the more timely the key pool synchronization can be achieved to prevent key exhaustion due to rapid consumption. is 0) and the key generation rate fluctuates within the preset range, the system uses a weighted fusion algorithm to generate a hybrid trigger cycle to balance efficiency and resource consumption. First, a network stability weight is calculated, which is related to the historical average stable connection time of the node. ,have:
[0052] ,
[0053] in is the historical average stable connection time between the weight and the node, is a reference maximum stable duration (for example, 24 hours). When the average stable connection duration of a node exceeds this value, the stability weight is 1. Then, the hybrid trigger period is calculated by weighted fusion. :
[0054] ,
[0055] The first and second trigger periods are potential values calculated based on the current (albeit stable) network state. The algorithm's logic is that the more stable the network (the stability weight approaches 1), the closer the hybrid trigger period is to the baseline period to conserve resources. If network stability decreases slightly but the independent first or second periods are not triggered (the stability weight is less than 1), the effects of the first and second trigger periods are appropriately integrated to perform preventative fine-tuning of the period.
[0056] By dynamically sensing changes in network topology and fluctuations in key generation, the synchronization cycle is intelligently adjusted. When the network is experiencing high-frequency fluctuations, the shortened first trigger cycle is prioritized to ensure timely synchronization. When key generation experiences abnormal fluctuations, the second trigger cycle is activated to maintain data consistency. In a stable state, a hybrid mode is used to balance resource consumption and synchronization efficiency. This mechanism enables the system to adapt to different network states, reducing the synchronization failure rate while avoiding excessive synchronization operations. This effectively resolves the dual contradictions of resource waste and state inconsistency in traditional fixed-cycle mechanisms in dynamic networks. The synchronization triggering rules are deeply coupled with the actual network state, and through the synergy of multiple judgment conditions, resource utilization efficiency and system reliability are simultaneously improved.
[0057] Optionally, performing edge collaborative pre-verification on the key hash value digest to generate a pre-verification result includes:
[0058] Selecting a set of adjacent nodes of the target node from the dynamic topology map;
[0059] Sending a comparison request of the key hash value digest to the set of neighboring nodes;
[0060] Counting the number of consistent summaries returned by the set of adjacent nodes, and generating a fast synchronization instruction when the number of consistent summaries exceeds a preset ratio threshold;
[0061] When the number of digest consistency does not reach the ratio threshold, a full verification instruction is generated;
[0062] The pre-verification result includes a fast synchronization instruction and a full verification instruction.
[0063] Specifically, when performing edge collaborative pre-verification, a preset number of adjacent nodes are first selected from the target node's direct communication node list based on the node connectivity relationships recorded in the dynamic topology map to form a neighboring node set. During this screening process, the three nodes with the highest scores are selected as neighboring nodes based on a comprehensive score of inter-node communication latency and historical connection stability. A comparison request message is then constructed containing a digest of the target node's key hash value. This digest is generated using a truncated hash algorithm, specifically by performing a SHA-256 hash operation on the original key data and taking the first 16 bits as the digest value. This comparison request message is simultaneously sent to all nodes in the neighboring node set via an encrypted channel. Each adjacent node retrieves the currently stored key associated with the target node's identifier from its local key repository, generates a local digest value using the same truncated hash algorithm, and compares the local digest value with the received digest value of the target node bit by bit. Each node encapsulates the comparison results in a response message and returns it to the target node. The target node counts the number of nodes with matching digests in all response messages. When this number reaches or exceeds a preset majority threshold, the pre-verification is determined to have passed and a fast synchronization instruction is generated. If the threshold is not reached, a full verification instruction is generated to trigger the deep verification process of the central node. Pre-verification is achieved through lightweight summary comparison between distributed nodes, and local data copies of adjacent nodes are used for fast consistency verification. The technical effect is reflected in the distribution of the pressure of traditional centralized verification to edge nodes, filtering most invalid requests before data synchronization through a local consensus mechanism, while retaining the central node's final decision-making ability on abnormal situations. This method significantly reduces network bandwidth and computing resource consumption while maintaining data consistency, forming a two-layer verification system with rapid edge response and precise center control, solving the technical contradiction of synchronization efficiency and verification accuracy in large-scale dynamic networks.
[0064] Optionally, performing a key storage operation based on the pre-verification result includes:
[0065] When the fast synchronization instruction is received, extracting a difference bitmap from the key data packet, locating and transmitting only the key fragment to be synchronized according to the difference bitmap to complete the key storage operation;
[0066] When the full verification instruction is received, the preset hash tree construction rules are loaded to perform a hierarchical hash operation on the key data packet to generate a root hash value. After the root hash value is compared with the preset reference root hash value and found to be consistent, all key data is written to complete the key storage operation.
[0067] Specifically, when a quick synchronization instruction is received, the system starts the difference identification bit parsing engine and extracts the pre-generated difference bitmap from the metadata area of the key data packet. The difference bitmap is generated by comparing the key version numbers of the target node and the set of adjacent nodes. Specifically, the current key sequence of the target node is divided into multiple data blocks according to the preset block size, and the version identifier of each data block is calculated and XORed with the version identifier set reported by the adjacent nodes to generate the difference bitmap. :
[0068] ,
[0069] in Represents the version identifier of the i-th data block of the target node, Represents the version identifier of the jth data block of the adjacent node. The key fragment to be synchronized is located according to the bit number marked as 1 in the difference bitmap, and only the key fragment is transmitted to the central node through the encrypted channel for storage. When the full verification instruction is triggered, the integrity verification module of the central node loads the preset hash tree construction rules, divides the key data packet into leaf node data blocks according to the hierarchical structure, performs two hash operations on each leaf node data block to generate the intermediate node hash value, and merges the layers upward until the root hash value is generated. :
[0070] ,
[0071] Among them, L1 to L4 represent leaf node data blocks, and H is the SHA-256 hash function. The calculated root hash value is compared with the benchmark root hash value stored in the central node. If they are completely consistent, the full key data is allowed to be written to the storage area, otherwise the data rollback mechanism is triggered. The difference bitmap is used to accurately locate the data fragments that need to be synchronized, and the data transmission volume is greatly reduced in fast synchronization mode. At the same time, the hierarchical hash tree is constructed to ensure that the data integrity during full verification is verifiable. The synchronization granularity is intelligently selected according to the pre-verification results, which can not only achieve efficient incremental synchronization in most consistent scenarios, but also ensure data reliability through strict tree verification in abnormal situations. It solves the problem that efficiency and security cannot be achieved at the same time in traditional solutions, and forms a dynamically adjustable elastic synchronization mechanism.
[0072] Optionally, the priority mapping relationship of updating the logical index layer includes:
[0073] Identify the hot zone identifier, warm zone identifier, and cold zone identifier in the key status label;
[0074] Promoting the key index address corresponding to the hot zone identifier to the top storage bit of the logical index layer;
[0075] When it is detected that the proportion of the number of keys identified by the cold zone exceeds a preset threshold, a merging and reorganization operation of the physical storage blocks is triggered.
[0076] Specifically, when updating the priority mapping relationship at the logical index layer, the key status parser first reads the key status tag carried in the key data packet. The key status tag contains a three-bit binary-coded status identifier, where the highest bit is 1, indicating a hot zone identifier; the middle bit is 1, indicating a warm zone identifier; and the last bit is 1, indicating a cold zone identifier. For keys carrying hot zone identifiers, the index manager inserts their logical addresses at the head of the logical index linked list, simultaneously moving the logical addresses of warm zone identifier keys to the middle of the linked list and the logical addresses of cold zone identifier keys to the end of the linked list. When the cold zone monitoring module detects that the proportion of cold zone identifier keys exceeds a preset threshold, the storage optimization engine is activated to perform physical storage block consolidation and reorganization. The preset threshold is dynamically adjusted by a storage space utilization calculation model. Specifically, a consolidation operation is triggered when the proportion of cold zone keys is greater than or equal to a threshold Q for three consecutive monitoring cycles. Threshold Q is the product of an adjustment coefficient set based on storage device performance and the current physical storage fragmentation rate. The adjustment coefficient set based on storage device performance is obtained by querying the performance parameter table built into the storage controller. During the merging process, the storage block locator scans all storage blocks marked as cold areas in the physical storage area, migrates their contents to the newly allocated continuous storage space, and releases the original discrete storage block addresses after the migration is completed. Through state-aware dynamic index adjustment and intelligent reorganization of storage space, continuous optimization of key storage efficiency is achieved. The technical effect is reflected in the real-time adjustment of access priority according to the key usage status, so that frequently used hot area keys are always in a fast and retrievable position, and at the same time, the space fragmentation problem is reduced through cold area storage merging. This method forms a collaborative optimization mechanism for physical storage and logical indexing, which improves the life of the storage medium while ensuring the key access speed, and solves the performance bottleneck problem caused by the mutual interference between high-frequency access areas and low-frequency areas in traditional fixed storage structures.
[0077] Optionally, the merging and reorganizing operation of the physical storage blocks includes:
[0078] Scan the physical storage area to generate a fragmentation distribution map containing storage block location information and free area size;
[0079] Based on the fragment distribution map, an optimal merging path of cold zone storage blocks is calculated and generated through a migration cost model;
[0080] Data migration is performed according to the optimal merge path, and after the migration is completed, the corresponding physical address in the priority mapping relationship of the logical index layer is updated.
[0081] Specifically, when performing the merging and reorganization operation of physical storage blocks, the fragment analyzer is first started to perform a full disk scan of the physical storage area, recording the starting address, ending address and storage status mark of each storage block. The storage status mark includes three types: occupied, cold area migration, and free. The storage distribution before merging and reorganization is as follows: Figure 2 The scan results are input into the spatial reconstruction algorithm to generate a fragment distribution map. , where the vertex set V represents the location information of the storage block, and the weight of the edge set E have:
[0082] ,
[0083] in and Represent the starting addresses of the i-th and j-th storage blocks respectively, Indicates the size of the free area between two storage blocks, The adjustment factor is set according to the read and write speed of the storage medium. The adjustment factor value is obtained by querying the performance parameter table of the storage controller. Based on the fragmentation distribution map, the path planning module uses an improved nearest neighbor algorithm to calculate the optimal merge path. Specifically, starting from the position of the largest continuous free block, the cold zone storage block with the lowest migration cost is selected in turn for filling. ,have:
[0084] ,
[0085] in Indicates the offset distance of the target storage block k to be migrated to. is the data size of storage block k, is the transfer rate of the storage medium, which is obtained through real-time monitoring of the storage controller. A migration queue is generated in ascending order of migration cost, and the data mover is controlled to migrate the cold zone key blocks one by one to the target continuous area in the queue order. After the migration is completed, the address recycler marks the original discrete storage block as idle and triggers the index updater to traverse the cold zone index pointer of the logical index layer. The storage distribution after merging and reorganization is as follows: Figure 3 For each storage block that has completed migration, the mapping relationship between its logical address and the new physical address is written into the index table, and the index item of the old address is cleared at the same time. The logical index layer is optimized as follows: Figure 4As shown in the figure. By combining a spatial reorganization algorithm with a migration cost model, optimal storage space organization is achieved while ensuring data integrity. Discrete cold zone key blocks are intelligently aggregated to reduce mechanical loss during storage addressing or the write amplification effect of solid-state storage. At the same time, real-time updates of logical indexes ensure that key retrieval efficiency is not affected by changes in physical location. This method forms a synergistic mechanism between physical storage optimization and logical access control, solving the problem of service interruptions or index failure caused by data migration in traditional storage organization solutions, and achieving a dual improvement in storage space utilization and system reliability.
[0086] It should be further clarified that the "optimal merging path" described in this invention is a "practical optimal solution" defined after comprehensively considering real-time system performance and storage organization efficiency. Theoretically, finding the absolute globally optimal path for data migration across massive storage blocks and fragments is an NP-hard (non-deterministic polynomial time) problem similar to the Traveling Salesman Problem (TSP). Performing an exhaustive computation to find the global optimal solution in a large-scale QKD network would result in unacceptable computational overhead and time delay, making it impractical for engineering applications.
[0087] Therefore, the "improved nearest neighbor algorithm" combined with the "migration cost model" employed in this invention is a highly efficient heuristic strategy. By prioritizing filling the largest free blocks and iteratively selecting the migration step with the lowest current cost, it can generate a very low-cost merge path that closely approaches the global optimum within limited computing resources and time. In the application scenarios of this invention, the results of this path (such as reduced fragmentation and subsequent access latency) are negligible compared to the theoretical global optimum, while achieving several orders of magnitude improvement in computational efficiency.
[0088] Therefore, the "optimal" in the "optimal merging path" in the present invention refers to the best feasible path under the migration cost model that can be found by the efficient heuristic algorithm disclosed in the present invention. It successfully achieves the best balance between computational complexity and storage organization effect, and meets the requirements of the QKD system for high efficiency and high reliability.
[0089] Optionally, before sending the key synchronization instruction, the method further includes:
[0090] Execute a two-way authentication protocol with the target node to verify the legitimacy of the identity by exchanging random challenge codes;
[0091] After the identity legitimacy is verified, the current network timestamp and the target node identifier are obtained to generate a watermark seed, the watermark seed is used to generate a dynamic encrypted watermark, and the dynamic encrypted watermark is embedded in the key synchronization instruction or key data packet.
[0092] Optionally, the generating a dynamic encrypted watermark by using the watermark seed and embedding the dynamic encrypted watermark into the key synchronization instruction or key data packet includes:
[0093] Using the hardware fingerprint of the target node as a chaotic parameter and the watermark seed parameter as an initial value to generate a chaotic sequence;
[0094] Generating a dynamic watermark matrix using the chaotic sequence to obtain a dynamic encrypted watermark;
[0095] An XOR operation is performed on the dynamic encryption watermark and the header information of the key data packet to generate an encrypted data packet header.
[0096] Specifically, before sending the key synchronization instruction, when executing the target node identity verification, the two-way authentication protocol is started, and the digital certificate preset in the target node is matched with the root certificate library of the central node for verification. First, the central node generates a random challenge code ,in is the current system timestamp, is a one-time random number, The challenge code is encrypted and sent to the target node, which decrypts the challenge code using the private key and appends the node identifier. , re-encrypt to form a response message and return it to the central node. The central node verifies the public key decryption The legitimacy of the challenge code and the timeliness of the challenge code are verified when the timestamp difference is within the preset time window and the node identifier exists in the authorized list. After the verification is passed, the dynamic encrypted watermark generator obtains the current network timestamp and the target node identifier , generate watermark seeds through watermark generation function, for watermark seeds ,have:
[0097] ,
[0098] in is the dimension parameter of the watermark matrix, which is obtained through the system configuration table. The watermark seed is input into the chaotic sequence generator to iteratively generate the dynamic watermark matrix , specifically:
[0099] ,
[0100] in is the chaos parameter generated by device fingerprint, , is the binary number of the watermark seed, specifically , The disturbance factor of 0.001 is used to prevent the chaotic sequence from falling into a periodic cycle. After iteratively generating 256 chaotic values, the chaotic value sequence is binarized according to the threshold of 0.5 to generate a 256-bit dynamic watermark matrix. ,when The corresponding bit is 1 when , otherwise it is 0. The header information of the key data packet is divided into blocks and XORed. Specifically, the header data is divided into groups of 256 bits each, and each group is XORed with the dynamic watermark matrix. Bit-by-bit XOR, if the header data length is less than 256 bits, random numbers are padded to complete the block. After completing the XOR operation, the encrypted header and the original packet body data are reassembled into the final transmission data packet. When the receiving end parses the final transmission data packet, the watermark extraction module separates the encrypted watermark part from the packet header, using the same chaotic parameters and timestamp Reconstruct the dynamic watermark matrix and restore the original header information through the inverse XOR operation. Compare the restored header hash value with the actual header hash value of the data packet, and confirm the data integrity if and only if the two are completely consistent. Ensure the legitimacy of the node identity through two-way authentication, and combine dynamic watermark technology to achieve traceability and tamper-proofing of the data transmission process. The verification process is coupled with the timing of watermark embedding, so that any man-in-the-middle attack will destroy the correlation between the watermark structure and the verification logic. At the same time, the dynamically changing chaotic parameters ensure the uniqueness of each watermark transmission. This method forms a triple protection system of identity authentication, data encryption, and integrity verification, which solves the technical defects of traditional solutions that are difficult to coordinate and defend against identity forgery and data tampering, and improves the overall security of the quantum key synchronization storage system.
[0101] Optionally, the method further includes:
[0102] In the physical storage area, capturing illegal read requests in real time;
[0103] When the illegal read request is detected, the logical address of the attacked storage block is redirected to the backup storage area, and the key regeneration process is triggered.
[0104] Specifically, when deploying the abnormal access monitoring module in the physical storage area, first configure the multi-dimensional detection strategy, including access frequency threshold detection and operation mode recognition. The access frequency threshold detection counts the number of read requests to a specific storage block per unit time. When the detection value exceeds the dynamically adjusted threshold, When the primary alarm is triggered, the threshold ,have:
[0105] ,
[0106] in is the fluctuation coefficient obtained by analyzing the storage access log, This is the basic offset set according to the security level. =( ... This method forms a closed-loop security system of attack detection, isolation protection, and key regeneration, solving the technical defects of attack response lag and data recovery difficulty in traditional solutions, and improving the adaptive protection capabilities of quantum key storage systems in the face of continuous attacks.
[0107] Based on the same inventive concept, Figure 5 As shown, the present invention also provides a quantum key synchronization storage system for QKD, the system comprising:
[0108] Dynamic topology perception module, used to monitor the node connection status of the quantum key distribution network and generate a dynamic topology map;
[0109] A synchronization rule generation module is used to obtain the key generation rate of the nodes in the dynamic topology map and generate a synchronization trigger rule in combination with a preset synchronization period reference value;
[0110] An instruction distribution module is used to trigger a key synchronization instruction according to the synchronization triggering rule and send the key synchronization instruction to a target node;
[0111] A data extraction module is used to receive the key data packet returned by the target node and extract the key hash value digest in the key data packet;
[0112] An edge pre-verification module, configured to perform edge collaborative pre-verification on the key hash value summary to generate a pre-verification result;
[0113] A storage execution module, configured to execute a key storage operation based on the pre-verification result;
[0114] The storage optimization module is used to obtain the key status tag in the key data packet, write the synchronized key into the corresponding physical storage area according to the key status tag, and update the priority mapping relationship of the logical index layer.
[0115] Example 1
[0116] To verify the feasibility of this invention, it was applied to a cross-regional financial quantum communication backbone network. This backbone network connects three core nodes in Beijing, Shanghai, and Shenzhen, and provides quantum key distribution (QKD) services to hundreds of branch offices and mobile terminals, ensuring the confidentiality of core transaction data. Due to the frequent dynamic connection and disconnection of branch office nodes, and the significant fluctuations in key generation rates caused by transaction volume between nodes, traditional fixed-period key synchronization methods struggle to balance timeliness and resource consumption, often leading to inconsistent key states and verification bottlenecks at the central node.
[0117] In this embodiment, the backbone network deploys the quantum key synchronization storage system described in the present invention. The system monitors the connection status of all network nodes in real time through the dynamic topology perception module and generates a dynamic topology map. When a new self-service bank terminal in the Shenzhen area is connected to the network, the synchronization rule generation module immediately detects the new node access event and shortens the synchronization period baseline value preset to 60 seconds by 40%. The key synchronization is performed on the new node and its neighboring nodes with a first trigger period of 36 seconds to ensure that new members are quickly integrated into the key system. During the peak trading period at noon, the system detected that the key generation rate of the Shanghai core node exceeded the preset 25% threshold, and then used the incremental synchronization period superposition algorithm to generate the second trigger period, encrypting the synchronization frequency to cope with the surge in key consumption.
[0118] During a routine synchronization initiated by the Beijing node, the system sent a key synchronization command to the Shanghai node according to the synchronization trigger rules. Before sending the command, the system performed a two-way authentication of the Shanghai node's identity using a pre-set digital certificate. After authentication, the system retrieved the current network timestamp and the Shanghai node's identifier, generated a dynamic encryption watermark using a chaotic sequence generator, and performed an XOR operation with the key data packet header to ensure transmission security. After receiving the key data packet returned by the Shanghai node, the Beijing node first extracted the key hash value digest within the packet (using the first 16 bits after a SHA-256 operation) and initiated the edge collaboration pre-verification process. The system selected a set of Shanghai node's neighboring nodes (such as Nanjing and Hangzhou nodes) from the dynamic topology map and sent them a digest comparison request. Both the Nanjing and Hangzhou nodes returned confirmation information that the digests were consistent. Because the number of consistent digests exceeded the preset 80% ratio threshold, the system generated a fast synchronization command.
[0119] Following the quick synchronization command, the system extracts only the difference identifiers from the key data packet, locating the key fragments that are inconsistent with the local storage for incremental synchronization, reducing the original 128MB of full key data required to be transmitted to 8MB. If the pre-verification fails (for example, only one adjacent node confirms consistency), a full verification command is generated. The central node in Beijing calls the integrity verification module to perform layer-by-layer hash tree verification on the data packet, ensuring data integrity with the highest security standards.
[0120] The synchronized keys are assigned different key status labels according to their business attributes. Keys used for high-frequency trading are marked as "hot zone identifiers", and their index addresses are promoted to the top storage bit of the logical index layer to achieve millisecond-level access. After one quarter of operation, the system detected that the proportion of archived keys marked as "cold zone identifiers" exceeded the set 20% threshold, and automatically triggered the merging and reorganization of physical storage blocks. The system scans the physical storage area to generate a fragmentation distribution map, and based on the optimal merge path algorithm, efficiently migrates the cold zone key blocks scattered in different physical locations to a continuous storage space. After completion, the original storage block address is released and the cold zone index pointer of the logical index layer is updated.
[0121] Furthermore, the system's abnormal access monitoring module successfully captured an illegal read request targeting the historical key storage area at 02:10 on August 15, 2024. This request attempted to access the same cold storage block more than five times within one second, triggering a high-frequency access alarm. The system immediately activated the isolation protection mechanism, redirecting the logical address of the attacked storage block to the backup storage area and triggering the key regeneration process, ensuring the security of key assets.
[0122] Table 1 Synchronous trigger efficiency and network status data table
[0123]
[0124] Table 2 Comparison of key synchronization modes and resource consumption data
[0125]
[0126] Table 3 Security protection and storage optimization effect data table
[0127]
[0128] As can be seen from the data in Tables 1 through 3, the present invention demonstrates excellent performance in complex financial quantum communication network environments. Table 1 shows that the present invention's dynamic synchronization trigger mechanism can adjust the synchronization period in real time based on network status. Compared to traditional fixed-period methods, its synchronization success rate is increased to over 99.5% in various scenarios, including dynamic node changes and surges in key rates. This effectively resolves the issue of synchronization failures during network instability.
[0129] Table 2 clearly demonstrates the advantages of edge collaborative pre-verification. In over 90% of synchronization scenarios, the system triggered incremental synchronization through summary consistency comparison, reducing data transmission volume and synchronization time by more than an order of magnitude. The CPU utilization of the central node plummeted from nearly 50% to around 5%, significantly alleviating performance bottlenecks at the central node and improving synchronization efficiency across the entire network.
[0130] The data in Table 3 demonstrates the significant effectiveness of this invention in storage optimization and security protection. Through regular merging and reorganization operations, storage fragmentation has been reduced from 28% to 3%. Through logical index optimization, access time for frequently used hot zone keys has been shortened by over 85%. More importantly, the automated security protection mechanism reduces the response time for unauthorized access from seconds to milliseconds. Combined with dynamic encryption watermarking technology, this system establishes a full-link, proactive security protection system from transmission to storage, providing strong security protection for financial-grade applications.
[0131] It should be noted that the formulas appearing above can translate physical quantities of different properties into unitless standard values or superimposable parameters of the same dimension through the principle of dimensional consistency and mathematical standardization means (such as normalization, dimensionless parameter conversion or unit system unification), thereby eliminating the interference of different dimensions on the operation logic, so that the formulas have mathematical operation rationality and objective law adaptability while retaining the distribution characteristics of the original data. It is a conventional technical means and will not be elaborated here. The electrical connection between the above-mentioned units does not necessarily mean a direct connection of the circuit. The indirect connection method can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above is only an exemplary embodiment of the present invention and the scope of the present invention cannot be limited thereto.
[0132] That is, any equivalent changes and modifications made according to the teachings of the present invention are still within the scope of the present invention. Those skilled in the art will readily conceive of other embodiments of the present invention after considering the disclosure of the specification and practical truths. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary technical means in the art not described herein.
Claims
1. A quantum key synchronization storage method for QKD, characterized in that: The method comprises: Monitor the node connection status of the quantum key distribution network and generate a dynamic topology map; Obtaining the key generation rate of the nodes in the dynamic topology map, and generating a synchronization trigger rule in combination with a preset synchronization period reference value; Triggering a key synchronization instruction according to the synchronization triggering rule, and sending the key synchronization instruction to the target node; Receive the key data packet returned by the target node, and extract the key hash value digest in the key data packet; Performing edge collaborative pre-verification on the key hash value summary to generate a pre-verification result; Based on the pre-verification result, performing a key storage operation; The key status tag in the key data packet is obtained, the synchronized key is written into the corresponding physical storage area according to the key status tag, and the priority mapping relationship of the logical index layer is updated.
2. The method for synchronous storage of quantum keys for QKD according to claim 1, characterized in that: Generating synchronization trigger rules includes: Based on the node access or disconnection events monitored by the dynamic topology map, a preset synchronization period reference value is adjusted to generate a first trigger period; Generating a second trigger period through an incremental synchronization period calculation process according to a change value of the key generation rate in adjacent time windows; When the node connection status is stable and the key generation rate fluctuation is within a preset range, a weighted fusion algorithm is used to combine the first trigger period and the second trigger period to generate a mixed trigger period, and the first trigger period, the second trigger period or the mixed trigger period is used as a synchronization trigger rule.
3. The method for synchronous storage of quantum keys for QKD according to claim 1, characterized in that: The performing edge collaborative pre-verification on the key hash value digest to generate a pre-verification result includes: Selecting a set of adjacent nodes of the target node from the dynamic topology map; Sending a comparison request of the key hash value digest to the set of neighboring nodes; Counting the number of consistent summaries returned by the set of adjacent nodes, and generating a fast synchronization instruction when the number of consistent summaries exceeds a preset ratio threshold; When the number of digest consistency does not reach the ratio threshold, a full verification instruction is generated; The pre-verification result includes a fast synchronization instruction and a full verification instruction.
4. The method for synchronous storage of quantum keys for QKD according to claim 3, characterized in that: The performing the key storage operation based on the pre-verification result includes: When the fast synchronization instruction is received, extracting a difference bitmap from the key data packet, locating and transmitting only the key fragment to be synchronized according to the difference bitmap to complete the key storage operation; When the full verification instruction is received, the preset hash tree construction rules are loaded to perform a hierarchical hash operation on the key data packet to generate a root hash value. After the root hash value is compared with the preset reference root hash value and found to be consistent, all key data is written to complete the key storage operation.
5. The method for synchronous storage of quantum keys for QKD according to claim 1, characterized in that: The priority mapping relationship of updating the logical index layer includes: Identify the hot zone identifier, warm zone identifier, and cold zone identifier in the key status label; Promoting the key index address corresponding to the hot zone identifier to the top storage bit of the logical index layer; When it is detected that the proportion of the number of keys identified by the cold zone exceeds a preset threshold, a merging and reorganization operation of the physical storage blocks is triggered.
6. The method for synchronous storage of quantum keys for QKD according to claim 5, characterized in that: The merging and reorganization operation of the physical storage blocks includes: Scan the physical storage area to generate a fragmentation distribution map containing storage block location information and free area size; Based on the fragment distribution map, an optimal merging path of cold zone storage blocks is calculated and generated through a migration cost model; Data migration is performed according to the optimal merge path, and after the migration is completed, the corresponding physical address in the priority mapping relationship of the logical index layer is updated.
7. The method for synchronous storage of quantum keys for QKD according to claim 1, characterized in that: Before sending the key synchronization instruction, the method further includes: Execute a two-way authentication protocol with the target node to verify the legitimacy of the identity by exchanging random challenge codes; After the identity legitimacy is verified, the current network timestamp and the target node identifier are obtained to generate a watermark seed, the watermark seed is used to generate a dynamic encrypted watermark, and the dynamic encrypted watermark is embedded in the key synchronization instruction or key data packet.
8. The method for synchronous storage of quantum keys for QKD according to claim 7, characterized in that: The generating a dynamic encrypted watermark by using the watermark seed and embedding the dynamic encrypted watermark into the key synchronization instruction or key data packet comprises: Using the hardware fingerprint of the target node as a chaotic parameter and the watermark seed parameter as an initial value to generate a chaotic sequence; Generating a dynamic watermark matrix using the chaotic sequence to obtain a dynamic encrypted watermark; An XOR operation is performed on the dynamic encryption watermark and the header information of the key data packet to generate an encrypted data packet header.
9. The method for synchronous storage of quantum keys for QKD according to claim 1, characterized in that: The method further comprises: In the physical storage area, capturing illegal read requests in real time; When the illegal read request is detected, the logical address of the attacked storage block is redirected to the backup storage area, and the key regeneration process is triggered.
10. A quantum key synchronous storage system for QKD, applied to the quantum key synchronous storage method for QKD according to any one of claims 1 to 9, characterized in that: The system comprises: Dynamic topology perception module, used to monitor the node connection status of the quantum key distribution network and generate a dynamic topology map; A synchronization rule generation module is used to obtain the key generation rate of the nodes in the dynamic topology map and generate a synchronization trigger rule in combination with a preset synchronization period reference value; An instruction distribution module is used to trigger a key synchronization instruction according to the synchronization triggering rule and send the key synchronization instruction to a target node; A data extraction module is used to receive the key data packet returned by the target node and extract the key hash value digest in the key data packet; An edge pre-verification module, configured to perform edge collaborative pre-verification on the key hash value summary to generate a pre-verification result; A storage execution module, configured to execute a key storage operation based on the pre-verification result; The storage optimization module is used to obtain the key status tag in the key data packet, write the synchronized key into the corresponding physical storage area according to the key status tag, and update the priority mapping relationship of the logical index layer.
Citation Information
Patent Citations
Data encryption method and device, equipment and medium
CN120263411A
Key synchronization method between quantum key distribution network nodes
CN120320946A