Quantum key distribution method and device, electronic equipment and computer storage medium
By acquiring network status information in real time through the quantum key distribution network control center, dynamically evaluating path weights, and optimizing paths and allocation methods, the problems of high resource consumption and insufficient anti-attack capability of quantum key distribution networks are solved, thereby improving the network's robustness and resource utilization and reducing the risk of attacks.
Patent Information
- Application Number
- CN202511104047.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-07
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2045-08-07
AI Technical Summary
Existing quantum key distribution networks suffer from high resource consumption, low utilization, and insufficient resistance to attacks in complex network environments. In particular, in static single-path transmission mode, key information can be easily leaked when relay nodes are compromised.
By acquiring network status information in real time through the quantum key distribution network control center, dynamically evaluating path weights, and simultaneously solving for the optimal path and allocation method using a bivariate optimization algorithm, quantum key splitting and recombination are achieved, reducing redundant hops and node key pool load pressure, and improving resource utilization and anti-attack capabilities.
This study improved the robustness and flexibility of quantum key distribution networks, reduced the risk of single-point failures and relay node breaches, optimized resource consumption, and improved the overall resource utilization and anti-attack capabilities of the network.
Smart Images

Figure CN120602091B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum key distribution, and particularly to a quantum key distribution method, a quantum key distribution device, an electronic device, and a computer-readable storage medium. Background Art
[0002] Quantum key distribution (QKD) is based on the principles of quantum no-cloning and uncertainty, and can achieve information-theoretic secure key negotiation. It is one of the core technologies for next-generation network security. As quantum communication develops from point-to-point transmission to multi-node networking, how to achieve efficient, reliable, and secure key distribution in a complex network environment has become a key issue to be urgently solved.
[0003] Most current quantum networks adopt a static single-path transmission mode. This mode relies on fixed links or simple load balancing algorithms, and there are significant hidden dangers. In the trusted relay mode, an attacker only needs to break through any relay node to easily steal the complete key information, and the risk of single-point failure is extremely high. To address the security risks of relay nodes, segmented routing technology has been proposed as a defense measure. Its core idea is to divide the complete key into multiple segments and independently transmit them through different paths. An attacker needs to intercept all sub-segments of all paths simultaneously to recover the key. For example, the secret sharing scheme based on Shamir threshold can divide the key into n segments, and only any t segments (t < n) are required to reconstruct the original key, thus significantly reducing the risk of single-path leakage.
[0004] This technology theoretically improves the ability to resist relay attacks. However, since the key segmentation and different paths need to be determined manually respectively, the resource consumption of the quantum key distribution network is relatively high and the utilization rate is relatively low. Summary of the Invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a quantum key distribution method, a quantum key distribution device, an electronic device, and a computer-readable storage medium that overcome the above problems or at least partially solve the above problems.
[0006] To solve the above problems, an embodiment of the present invention discloses a quantum key distribution method, which is applied to a quantum key distribution network control center. The method includes:
[0007] Responding to a quantum key distribution request, obtaining network status information of the quantum key distribution network, and determining a path set for distributing the quantum key based on the network status information; the path set includes at least one reachable path;
[0008] Determining the path weight of each reachable path based on the network status information;
[0009] The method for allocating the quantum key is determined based on the path weights, and a target path is determined from the path set.
[0010] The allocation method and the target path are sent to the source node, so that the source node can segment the quantum key based on the allocation method to obtain multiple quantum key segments, and send each quantum key segment to the destination node based on the target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
[0011] In one or more embodiments, determining the set of paths for distributing quantum keys based on the network state information includes:
[0012] The network topology of the quantum distribution network is constructed using the network state information.
[0013] A preset algorithm is used to calculate at least one reachable path between the source node and the destination node in the network topology;
[0014] The reachable paths are combined to obtain a path set.
[0015] In one or more embodiments, prior to obtaining the network state information of the quantum key distribution network, the method further includes:
[0016] The validity of the quantum key distribution request is verified;
[0017] If the verification is successful, the total number of quantum keys and the destination node are obtained from the quantum key distribution request.
[0018] In one or more embodiments, determining the path weight of each reachable path based on the network state information includes:
[0019] The network status information of each node in each reachable path is determined from the network status information;
[0020] The security score and resource consumption of each reachable path are calculated based on the network status information of each node;
[0021] The path weight of each reachable path is calculated based on its security score and resource consumption.
[0022] In one or more embodiments, the network state information includes quantum error rate, key generation rate, number of path nodes, and remaining key quantity in the key pool;
[0023] The calculation of the security score and resource consumption of each reachable path based on the network state information of each node includes:
[0024] The security score of each node is calculated using the quantum error rate and the key generation rate of each node;
[0025] The resource consumption of each node is calculated using the number of path nodes for each node and the remaining key amount in the key pool.
[0026] In one or more embodiments, determining the allocation method of the quantum key based on the path weights, and determining the target path from the path set, includes:
[0027] Construct an optimization model; the optimization model includes key allocation variables and path selection variables;
[0028] Input the path weight of each reachable path into the optimization model;
[0029] The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result.
[0030] The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key.
[0031] Accordingly, this invention discloses a quantum key distribution method applied to a source node, the method comprising:
[0032] In response to a quantum key distribution instruction, a quantum key distribution request is generated;
[0033] The quantum key distribution request is sent to the quantum key distribution network control center, so that the quantum key distribution network control center responds to the quantum key distribution request, determines the quantum key allocation method and target path, and sends the allocation method and target path to the source node;
[0034] Obtain the allocation method and the target path;
[0035] The quantum key is divided based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths;
[0036] Each quantum key segment is sent to the destination node through the corresponding target path, so that the destination node can reassemble each quantum key segment when it obtains the quantum key segment to obtain the quantum key.
[0037] In one or more embodiments, generating a quantum key distribution request includes:
[0038] Obtain the total number of keys and the destination node from the quantum key distribution instruction;
[0039] A quantum key distribution request is generated using the total amount of key and the destination node.
[0040] Accordingly, embodiments of the present invention disclose a quantum key distribution method applied to a destination node, the method comprising:
[0041] Obtain at least one quantum key segment ciphertext;
[0042] Decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment;
[0043] The individual quantum key segments are recombined to obtain the quantum key.
[0044] In one or more embodiments, the step of decrypting the ciphertext of each quantum key segment to obtain at least one quantum key segment includes:
[0045] Determine the previous hop node corresponding to each quantum key segment ciphertext;
[0046] Determine the shared key for each upstream node;
[0047] Each quantum key segment is obtained by decrypting the corresponding quantum key segment ciphertext using the shared key.
[0048] In one or more embodiments, it further includes:
[0049] The quantum key is verified;
[0050] If the verification fails, an alarm message will be generated.
[0051] Accordingly, this invention discloses a quantum key distribution device applied in a quantum key distribution network control center, the device comprising:
[0052] The first acquisition module is used to acquire network status information of the quantum key distribution network in response to a quantum key distribution request;
[0053] The first computing module is used to determine a set of paths for distributing quantum keys based on the network state information; the set of paths includes at least one reachable path.
[0054] The second calculation module is used to determine the path weight of each reachable path based on the network state information;
[0055] The third calculation module is used to determine the distribution method of the quantum key based on the path weight, and to determine the target path from the path set;
[0056] The first sending module is used to send the allocation method and the target path to the source node, so that the source node can segment the quantum key based on the allocation method to obtain multiple quantum key segments, and send each of the quantum key segments to the destination node based on the target path, so that the destination node can reassemble each of the quantum key segments when it obtains each of the quantum key segments to obtain the quantum key.
[0057] In one or more embodiments, the first computing module is specifically used for:
[0058] The network topology of the quantum distribution network is constructed using the network state information.
[0059] A preset algorithm is used to calculate at least one reachable path between the source node and the destination node in the network topology;
[0060] The reachable paths are combined to obtain a path set.
[0061] In one or more embodiments, it further includes:
[0062] The first verification module is used to verify the legitimacy of the quantum key distribution request before obtaining the network state information of the quantum key distribution network;
[0063] An extraction module is used to obtain the total number of quantum keys and the destination node from the quantum key distribution request if the verification is successful.
[0064] In one or more embodiments, the second computing module includes:
[0065] The determination submodule is used to determine the network status information of each node in each reachable path from the network status information;
[0066] The first calculation submodule is used to calculate the security score and resource consumption of each reachable path based on the network status information of each node;
[0067] The second calculation submodule is used to calculate the path weight of each reachable path based on the security score and resource consumption of each reachable path.
[0068] In one or more embodiments, the network state information includes quantum error rate, key generation rate, number of path nodes, and remaining key quantity in the key pool;
[0069] The first calculation submodule is specifically used for:
[0070] The security score of each node is calculated using the quantum error rate and the key generation rate of each node;
[0071] The resource consumption of each node is calculated using the number of path nodes for each node and the remaining key amount in the key pool.
[0072] In one or more embodiments, the third computing module is specifically used for:
[0073] Construct an optimization model; the optimization model includes key allocation variables and path selection variables;
[0074] Input the path weight of each reachable path into the optimization model;
[0075] The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result.
[0076] The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key.
[0077] Accordingly, embodiments of the present invention disclose a quantum key distribution device applied to a source node, the device comprising:
[0078] The first generation module is used to generate a quantum key distribution request in response to a quantum key distribution instruction;
[0079] The second sending module is used to send the quantum key distribution request to the quantum key distribution network control center, so that the quantum key distribution network control center responds to the quantum key distribution request, determines the quantum key allocation method and target path, and sends the allocation method and target path to the source node;
[0080] The second acquisition module is used to acquire the allocation method and the target path;
[0081] A segmentation module is used to segment the quantum key based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths;
[0082] The third sending module is used to send each quantum key segment to the destination node through the corresponding target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
[0083] In one or more embodiments, the generation module is specifically used for:
[0084] Obtain the total number of keys and the destination node from the quantum key distribution instruction;
[0085] A quantum key distribution request is generated using the total amount of key and the destination node.
[0086] Accordingly, embodiments of the present invention disclose a quantum key distribution device applied to a destination node, the device comprising:
[0087] The third acquisition module is used to acquire at least one quantum key segment ciphertext.
[0088] The decryption module is used to decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment;
[0089] The recombination module is used to recombine the various quantum key segments to obtain the quantum key.
[0090] In one or more embodiments, the decryption module is specifically used for:
[0091] Determine the previous hop node corresponding to each quantum key segment ciphertext;
[0092] Determine the shared key for each upstream node;
[0093] Each quantum key segment is obtained by decrypting the corresponding quantum key segment ciphertext using the shared key.
[0094] In one or more embodiments, it further includes:
[0095] The second verification module is used to verify the quantum key;
[0096] The second generation module is used to generate an alarm message if the verification fails.
[0097] Accordingly, this invention discloses an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various steps of the above-described quantum key distribution method embodiments.
[0098] Accordingly, embodiments of the present invention disclose a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the various steps of the above-described quantum key distribution method embodiments.
[0099] The embodiments of the present invention have the following advantages:
[0100] In response to a quantum key distribution network (QKD) request, the control center of the QKD acquires the network state information of the QKD and determines a set of paths for distributing quantum keys based on the network state information. Then, based on the network state information, it determines the path weight of each reachable path and the allocation method of the quantum key based on the path weight. Finally, it determines the target path from the set of paths. The allocation method and the target path are sent to the source node, allowing the source node to segment the quantum key according to the allocation method, obtaining multiple quantum key segments. Each quantum key segment is then sent to the destination node based on the target path, enabling the destination node to reassemble the quantum key segments to obtain the final quantum key. This approach, by dynamically evaluating the path weights based on the real-time network state information acquired by the QKD, allows for real-time awareness of the network state and adjustment of routing strategies. It effectively addresses quantum link quality fluctuations or node resource constraints, achieving quantitative analysis of path security performance and resource efficiency, and improving the system's robustness and flexibility.
[0101] Moreover, a bivariate optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve for the optimal path and optimal distribution method. This not only solves the problem of decision fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relay and the load pressure on node key pools, improves the overall resource utilization of the network, and minimizes global resource consumption.
[0102] Furthermore, by adjusting the routing strategy in real time, the risk of single point of failure or relay node breach can be significantly reduced, thus improving the anti-attack capability of quantum key distribution. Attached Figure Description
[0103] Figure 1 This is a flowchart illustrating the steps of a first embodiment of the quantum key distribution method of the present invention;
[0104] Figure 2 This is a flowchart illustrating the steps of a second embodiment of the quantum key distribution method of the present invention;
[0105] Figure 3 This is a flowchart of the steps in a third embodiment of the quantum key distribution method of the present invention;
[0106] Figure 4 This is a schematic diagram of quantum key distribution according to the present invention;
[0107] Figure 5 This is a structural block diagram of a first embodiment of a quantum key distribution device according to the present invention;
[0108] Figure 6This is a structural block diagram of a second embodiment of the quantum key distribution device of the present invention;
[0109] Figure 7 This is a structural block diagram of a third embodiment of the quantum key distribution device of the present invention. Detailed Implementation
[0110] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0111] One of the core concepts of this invention is that by dynamically evaluating the path weights through real-time acquisition of network state information from the quantum key distribution network, the network state can be perceived in real time and the routing strategy can be adjusted. This effectively addresses issues such as fluctuations in quantum link quality or shortage of node resources, enabling quantitative analysis of path security performance and resource efficiency, and improving the robustness and flexibility of the system.
[0112] Moreover, a bivariate optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve for the optimal path and optimal distribution method. This not only solves the problem of decision fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relay and the load pressure on node key pools, improves the overall resource utilization of the network, and minimizes global resource consumption.
[0113] Furthermore, by adjusting the routing strategy in real time, the risk of single point of failure or relay node breach can be significantly reduced, thus improving the anti-attack capability of quantum key distribution.
[0114] Reference Figure 1 This diagram illustrates a flowchart of a first embodiment of the quantum key distribution method of the present invention, applied to the quantum key distribution network control center (QKDNC). The QKDNC is a key functional module in the quantum key distribution network (QKDN), located in the QKDN control layer. It is responsible for managing and controlling the operation of the quantum key distribution network, including functions such as routing control, configuration management, policy control, and access control. Through collaborative work with other functional modules (such as the QKD module in the quantum layer and the key management module in the key layer), the QKDNC ensures the secure generation, distribution, and management of quantum keys to support efficient and stable quantum-secure communication services.
[0115] This method may specifically include the following steps:
[0116] Step 101: In response to a quantum key distribution request, obtain network state information of the quantum key distribution network, and determine a set of paths for distributing quantum keys based on the network state information; the set of paths includes at least one reachable path.
[0117] After receiving the quantum key distribution request sent by the source node, the control center of the quantum key distribution network can obtain the network state information of the quantum key distribution network at the current moment. Based on the network state information, it can determine the set of paths (referred to as "reachable paths") between the source node and the destination node that can be used to distribute quantum keys (referred to as "path set" for ease of description). In other words, the path set includes at least one reachable path.
[0118] In this embodiment of the invention, determining the set of paths for distributing quantum keys based on the network state information includes:
[0119] The network topology of the quantum distribution network is constructed using the network state information.
[0120] A preset algorithm is used to calculate at least one reachable path between the source node and the destination node in the network topology;
[0121] The reachable paths are combined to obtain a path set.
[0122] Specifically, after obtaining the network state information at the current moment, the quantum key distribution network control center can use the network state information to construct the network topology of the quantum key distribution network at the current moment. This network topology can clearly show the connection relationship between each node in the quantum key distribution network.
[0123] Then, a preset algorithm is used to calculate all reachable paths between the source node and the destination node, and all reachable paths are combined to obtain a path set.
[0124] It should be noted that when calculating reachable paths, path search algorithms, such as Dijkstra's algorithm, or other algorithms can be used. In practical applications, the specific algorithm used to calculate reachable paths can be set according to actual needs, and this embodiment of the invention does not impose any restrictions on this.
[0125] In this embodiment of the invention, before obtaining the network state information of the quantum key distribution network, the method further includes:
[0126] The validity of the quantum key distribution request is verified;
[0127] If the verification is successful, the total number of quantum keys and the destination node are obtained from the quantum key distribution request.
[0128] Specifically, after receiving a quantum key distribution request, the control center of the quantum key distribution network can verify the validity of the request. If the verification is successful, it can obtain the total number of quantum keys and the destination node from the request to facilitate subsequent transmission. If the verification fails, the process can be terminated.
[0129] Furthermore, during the legitimacy verification, user identity, permissions, and the reachability of the destination node can be verified, as well as other information. In practical applications, the specific verification information can be set according to actual needs, and this embodiment of the invention does not impose any restrictions on this.
[0130] Step 102: Determine the path weight of each reachable path based on the network state information.
[0131] After determining the network state information, the weight of each path in the path set can be calculated using the information in the network state information (denoted as "path weight"), so that the required path can be determined from the path set according to the path weight.
[0132] In this embodiment of the invention, determining the path weight of each reachable path based on the network state information includes:
[0133] The network status information of each node in each reachable path is determined from the network status information;
[0134] The security score and resource consumption of each reachable path are calculated based on the network status information of each node;
[0135] The path weight of each reachable path is calculated based on its security score and resource consumption.
[0136] Specifically, the network state information of each node in each reachable path can be determined first. Then, based on the network state information of each node, the security score and resource consumption of each reachable path can be calculated. The security score reflects the security of each reachable path, and the resource consumption reflects the amount of key consumed by each reachable path.
[0137] The network status information includes quantum error rate, key generation rate, number of path nodes, and remaining key quantity in the key pool;
[0138] The calculation of the security score and resource consumption of each reachable path based on the network state information of each node includes:
[0139] The security score of each node is calculated using the quantum error rate and the key generation rate of each node;
[0140] The resource consumption of each node is calculated using the number of path nodes for each node and the remaining key amount in the key pool.
[0141] Specifically, network state information may include quantum bit error rate (QBER), key generation rate (R), number of path nodes (N), and remaining key amount in the key pool (S).
[0142] In quantum key distribution (QKD), QBER reflects the error rate of qubits during transmission. The higher the error rate, the greater the possibility that the link is subject to noise or potential eavesdropping attacks. When the QBER exceeds a certain threshold, the communicating parties can determine that there is a security risk in the link and take measures accordingly.
[0143] The key generation rate R reflects the number of secure keys that a node can generate per unit of time. A higher key generation rate usually means better link quality and higher security.
[0144] Therefore, when using a reachable path with N path nodes for key relay, the security of the reachable path can be considered to be determined by the path node with the worst security. The security score of the reachable path can then be calculated using the following formula:
[0145]
[0146] in, i Indicates the first path in the reachable path i 1 node and These are weighting coefficients, which can be adjusted according to actual needs.
[0147] When QKD links perform key relay, key resources are consumed for relaying keys at any node in the link. The longer the selected path, i.e., the more nodes N in the path, the more key resources will be consumed, further reducing the resource utilization of the entire network.
[0148] QKD link nodes generally have a low key generation rate, and the remaining key quantity S in the link node key pool and the key quantity requirements of each node are also different. Therefore, in order to alleviate the key resource shortage of nodes, this embodiment of the invention introduces a key quantity penalty factor to alleviate the resource shortage of nodes.
[0149] Based on this, a suitable option is selected. N When using reachable paths with a number of nodes for key relay, assume the total number of quantum keys is... L Therefore, the resource consumption of a reachable path can be calculated using the following formula:
[0150]
[0151] in, This is the key amount penalty factor for path nodes, which can be adjusted according to the resource scarcity of the nodes.
[0152] After calculating the security score and resource consumption of each reachable path, the path weight of each reachable path can be calculated using these scores and resource consumption. The path weight reflects the security effectiveness and resource consumption efficiency of the reachable path.
[0153] It should be noted that, in practical applications, the specific method of using security scoring and resource consumption to calculate path weights can be set according to actual needs, and this embodiment of the invention does not impose any restrictions on this.
[0154] Step 103: Determine the distribution method of the quantum key based on the path weight, and determine the target path from the path set.
[0155] After calculating the path weight of each reachable path, and assuming that the security requirements are met, the method of quantum key distribution can be determined with the goal of minimizing the resources of the entire quantum key distribution network, and the path used to transmit the quantum key (denoted as the "target path") can be determined from the path set.
[0156] In this embodiment of the invention, determining the quantum key allocation method based on the path weights and determining the target path from the path set includes:
[0157] Construct an optimization model; the optimization model includes key allocation variables and path selection variables;
[0158] Input the path weight of each reachable path into the optimization model;
[0159] The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result.
[0160] The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key.
[0161] Specifically, define path selection variables and key allocation variables The path selection variable indicates whether to select the reachable path, and the key allocation variable indicates the proportion of the total key quantity allocated to the quantum key segment assigned to the reachable path. L The proportion.
[0162] Path selection variables ,in, P For a set of paths, =1 indicates that a reachable path is selected. p Otherwise, it is 0.
[0163] Key allocation variables This indicates that the path is assigned to a reachable path. p Quantum key segments account for a certain percentage of the total key volume L The proportion.
[0164] Using path selection variables and key allocation variables Define the objective function (including the resource consumption formula mentioned above):
[0165]
[0166] in, Indicates any reachable path p The number of jumps, Indicates reachable path p The set of all path nodes.
[0167] And, set constraints:
[0168] Key integrity constraints (ensuring total key quantity) L (All allocated)
[0169]
[0170] Security constraints ( (This represents the lowest overall safety score, which includes the safety scores mentioned above).
[0171]
[0172] Path selection and assignment of association constraints (when reachable paths) p (Only when selected will the key be allowed to be assigned to the reachable path)
[0173]
[0174] Multi-path constraints (at least one path must be selected) (A reachable path to mitigate risks)
[0175]
[0176] At this point, the optimization model has been completed.
[0177] Then, the path weight of each reachable path, the number of hops of the reachable path, and the set of all path nodes on the reachable path are input into the optimization model. The optimization model is solved using the MILP (Mixed Integer Linear Programming) algorithm to obtain the optimal path selection result and the optimal key distribution result. The optimal path selection result is used as the target path, and the optimal key distribution result is used as the quantum key distribution method to obtain the final distribution scheme.
[0178] It should be noted that the optimization model can be solved using not only the MILP algorithm, but also other algorithms. In practical applications, the specific algorithm can be set according to actual needs, and this embodiment of the invention does not impose any restrictions on this.
[0179] Step 104: Send the allocation method and the target path to the source node, so that the source node can segment the quantum key based on the allocation method to obtain multiple quantum key segments, and send each quantum key segment to the destination node based on the target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
[0180] Specifically, after obtaining the final allocation scheme, it can be sent to the source node. Upon receiving the allocation scheme, the source node divides the quantum key into multiple quantum key segments using the allocation method specified in the scheme. Since the number of quantum key segments is the same as the target path and they correspond one-to-one, each quantum key segment can be sent to the destination node through its corresponding target path.
[0181] In this process, each node along the target path can encrypt the quantum key segment using a one-time pad (OTP) method. Therefore, each quantum key segment obtained by the target node is an encrypted ciphertext. The target node then needs to decrypt each ciphertext to obtain the individual quantum key segments, and then reassemble them in the correct order to obtain the complete quantum key.
[0182] Furthermore, in any two adjacent path nodes of any target path, the next-hop path node shares the key of the current path node; however, the current path node does not share the key of the next-hop path node. For example, if the target path includes four path nodes A, B, C, and D, B shares A's key with A, C shares B's key with B, and D shares C's key with C. In this way, A encrypts the quantum key segment and sends it to B. B decrypts the quantum key segment using A's key, then encrypts it again using B's key and sends it to C. C decrypts the quantum key segment using B's key, then encrypts it again using C's key and sends it to D. D then decrypts the quantum key segment using C's key.
[0183] In this embodiment of the invention, the quantum key distribution network control center responds to a quantum key distribution request by acquiring network state information of the quantum key distribution network, determining a set of paths for distributing quantum keys based on the network state information, determining the path weight of each reachable path based on the network state information, determining the allocation method of the quantum key based on the path weight, and determining a target path from the set of paths. The allocation method and the target path are then sent to the source node, allowing the source node to segment the quantum key based on the allocation method, obtaining multiple quantum key segments. Each quantum key segment is then sent to the destination node based on the target path, allowing the destination node to reassemble the quantum key segments upon acquisition to obtain the quantum key. Thus, by dynamically evaluating the path weights based on the real-time network state information acquired by the quantum key distribution network, the system can perceive the network state in real time and adjust routing strategies, effectively addressing issues such as quantum link quality fluctuations or node resource constraints. This achieves quantitative analysis of path security performance and resource efficiency, improving the robustness and flexibility of the system.
[0184] Moreover, a bivariate optimization algorithm for quantum key distribution and path selection is adopted to simultaneously solve for the optimal path and optimal distribution method. This not only solves the problem of decision fragmentation caused by the independent optimization of the two in traditional algorithms, but also reduces the redundant hops of key relay and the load pressure on node key pools, improves the overall resource utilization of the network, and minimizes global resource consumption.
[0185] Furthermore, by adjusting the routing strategy in real time, the risk of single point of failure or relay node breach can be significantly reduced, thus improving the anti-attack capability of quantum key distribution.
[0186] Reference Figure 2 The diagram illustrates a flowchart of a second embodiment of the quantum key distribution method of the present invention, applied to a source node, and specifically includes the following steps:
[0187] Step 201: In response to the quantum key distribution instruction, generate a quantum key distribution request.
[0188] A client can be installed on the source node, allowing users to trigger quantum key distribution commands. Once the source node receives the quantum key distribution command, it can generate a quantum key distribution request.
[0189] Furthermore, in addition to users triggering quantum key distribution commands, other tasks or third-party clients can also trigger quantum key distribution commands. In practical applications, the specific method of triggering quantum key distribution requests can be set according to actual needs, and this embodiment of the invention does not limit this.
[0190] In this embodiment of the invention, generating a quantum key distribution request includes:
[0191] Obtain the total number of keys and the destination node from the quantum key distribution instruction;
[0192] A quantum key distribution request is generated using the total amount of key and the destination node.
[0193] Specifically, when triggering a quantum key distribution instruction, it is necessary to specify the total amount of quantum key to be transmitted and the destination node. Therefore, the total amount of key and the destination node can be obtained from the quantum key distribution instruction, and a quantum key distribution request can be generated using the total amount of key and the destination node.
[0194] Step 202: Send the quantum key distribution request to the quantum key distribution network control center, so that the quantum key distribution network control center responds to the quantum key distribution request, determines the quantum key allocation method and target path, and sends the allocation method and target path to the source node.
[0195] After generating a quantum key distribution request, the source node sends the request to the quantum key distribution network control center. The quantum key distribution network control center responds to the request, determines the allocation method and target path for the quantum key, and returns these to the source node. The specific determination method is detailed in steps 101-104 and will not be elaborated upon here.
[0196] Step 203: Obtain the allocation method and the target path.
[0197] Step 204: The quantum key is divided based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths.
[0198] Step 205: Send each quantum key segment to the destination node through the corresponding target path, so that when the destination node obtains each quantum key segment, it can reassemble each quantum key segment to obtain the quantum key.
[0199] Specifically, after obtaining the allocation scheme, the source node divides the quantum key into multiple quantum key segments using the allocation method in the scheme. Since the number of quantum key segments is the same as that of the target path and they correspond one-to-one, each quantum key segment can be sent to the destination node through the corresponding target path.
[0200] In this process, each node along the target path can encrypt the quantum key segment using a one-time pad (OTP) method. Therefore, each quantum key segment obtained by the target node is an encrypted ciphertext. The target node then needs to decrypt each ciphertext to obtain the individual quantum key segments, and then reassemble them in the correct order to obtain the complete quantum key.
[0201] Furthermore, in any two adjacent path nodes of any target path, the next-hop path node shares the key of the current path node; however, the current path node does not share the key of the next-hop path node.
[0202] In this embodiment of the invention, the source node responds to a quantum key distribution instruction by generating a quantum key distribution request and sending the request to the quantum key distribution network control center. The control center then responds to the request by determining the quantum key allocation method and target path, and sends these to the source node. The control center acquires the allocation method and target path, and segments the quantum key based on the allocation method to obtain multiple quantum key segments. The number of quantum key segments is the same as the number of target paths. Each quantum key segment is sent to the destination node via its corresponding target path. The destination node, upon acquiring each quantum key segment, reassembles them to obtain the final quantum key. This approach employs a bivariate optimization algorithm for both quantum key allocation and path selection, simultaneously solving for the optimal path and optimal allocation method. This not only solves the problem of decision fragmentation caused by independent optimization in traditional algorithms, but also reduces redundant hops in key relays and the load on node key pools, improving overall network resource utilization and minimizing global resource consumption.
[0203] Furthermore, by adjusting the routing strategy in real time, the risk of single point of failure or relay node breach can be significantly reduced, thus improving the anti-attack capability of quantum key distribution.
[0204] Reference Figure 3 The diagram illustrates a flowchart of a third embodiment of the quantum key distribution method of the present invention, applied to a destination node, and specifically includes the following steps:
[0205] Step 301: Obtain at least one quantum key segment ciphertext.
[0206] Step 302: Decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment.
[0207] After the destination node obtains the ciphertext of each quantum key segment through each target path, it can decrypt it using the key corresponding to each quantum key segment ciphertext to obtain each quantum key segment.
[0208] In this embodiment of the invention, the step of decrypting the ciphertext of each quantum key segment to obtain at least one quantum key segment includes:
[0209] Determine the previous hop node corresponding to each quantum key segment ciphertext;
[0210] Determine the shared key for each upstream node;
[0211] Each shared key is used to decrypt the corresponding quantum key segment ciphertext.
[0212] Specifically, each node in each target path can encrypt the quantum key segment using a one-time pad (OTP) method. Therefore, each quantum key segment obtained by the destination node is an encrypted ciphertext. The destination node then needs to decrypt each ciphertext to obtain the individual quantum key segments, and then reassemble them in the correct order to obtain the complete quantum key.
[0213] Furthermore, in any two adjacent path nodes of any target path, the next-hop path node shares the key of the current path node; however, the current path node does not share the key of the next-hop path node. Based on this, the target node can determine the previous-hop node corresponding to each quantum key segment ciphertext, thereby determining the key of each previous-hop node (denoted as the "shared key"). Then, by using each shared key to decrypt each quantum key segment ciphertext, the respective quantum key segments can be obtained.
[0214] It should be noted that the specific methods for determining the target path and allocation method are detailed in steps 101 to 104, and will not be repeated here.
[0215] Step 303: Reassemble the various quantum key segments to obtain the quantum key.
[0216] After obtaining each quantum key segment, the destination node can reassemble the quantum key segments in the correct order to obtain the complete quantum key.
[0217] In this embodiment of the invention, it further includes:
[0218] The quantum key is verified;
[0219] If the verification fails, an alarm message will be generated.
[0220] Specifically, after obtaining the complete quantum key, the destination node can perform integrity verification and security verification on the quantum key to ensure that the quantum key has not been tampered with or leaked during transmission.
[0221] If the verification passes, the quantum key distribution can be used to execute subsequent processes; if the verification fails, an alarm message can be generated.
[0222] It should be noted that when performing integrity and security verification on quantum keys, the specific verification methods can be set according to actual needs, and the embodiments of the present invention do not impose any restrictions on this.
[0223] In this embodiment of the invention, the destination node obtains at least one quantum key segment ciphertext through each target path, decrypts each quantum key segment ciphertext to obtain at least one quantum key segment, and reassembles the quantum key segments to obtain the quantum key. Each target path is determined in real time by the quantum key distribution network control center based on the network state information of the quantum key distribution network. Thus, by dynamically evaluating the path weights using the real-time network state information obtained by the quantum key distribution network, the system can perceive the network state in real time and adjust routing strategies accordingly. This effectively addresses issues such as quantum link quality fluctuations or node resource constraints, enabling quantitative analysis of path security performance and resource efficiency, and improving the robustness and flexibility of the system.
[0224] Furthermore, by adjusting the routing strategy in real time, the risk of single point of failure or relay node breach can be significantly reduced, thus improving the anti-attack capability of quantum key distribution.
[0225] For ease of understanding, the complete process of the embodiments of the present invention will be illustrated below.
[0226] (1) User initiates request: The user sends a key transmission request to the Quantum Key Distribution Network Control Center (QKDNC) through the client in the source node, specifying the total amount of key L to be transmitted and the destination node.
[0227] (2) System verification request: After receiving the request, QKDNC verifies the legality of the request, including verifying the user's identity, permissions and the reachability of the destination node.
[0228] (3) Determine key requirements: After verification, QKDNC determines the total number of quantum keys to be transmitted as L and prepares to start the subsequent transmission process.
[0229] (4) Obtaining network status information: QKDNC sends status query commands to each node in the quantum key distribution network to collect network status information including parameters such as quantum bit error rate (QBER), key generation rate R, number of path nodes N, and remaining key amount S in the key pool.
[0230] (5) Constructing a network topology diagram: Based on the collected network state information, construct a topology diagram of the current quantum key distribution network to clearly show the relationship between the connections of each node.
[0231] (6) Calculate the set of reachable paths: Based on the constructed network topology graph, use path search algorithms (such as Dijkstra's algorithm) to calculate all reachable paths from the source node to the destination node, and form the path set P of these reachable paths.
[0232] (7) Collect and analyze secure node information: For each reachable path in the path set P, collect the QBER and key generation rate R of each node on the reachable path; according to the quantum link security calculation model, calculate the security score of each reachable path, where QBER reflects the possibility of the link being attacked by noise or potential eavesdropping, and key generation rate R reflects the quality and security of the link.
[0233] (8) Collect and analyze node resource information: Collect the link hop count N and the remaining key amount S of the key pool of each node on each reachable path; calculate the resource consumption of each reachable path based on the quantum link resource calculation model, and consider the impact of the link hop count N on the key relay resource consumption and the mitigation effect of the node key amount penalty factor on resource-scarce nodes.
[0234] (9) Comprehensive calculation path weight: Combining the quantum link security calculation model and the quantum link resource calculation model, a comprehensive weight is calculated for each reachable path. This weight reflects the security performance and resource consumption efficiency of the reachable path.
[0235] (10) Constructing an optimization model: Define path selection variables and key allocation variables, where the path selection variable indicates whether to select a certain reachable path, and the key allocation variable indicates the proportion of keys allocated to that reachable path relative to the total number of keys L. Set the objective function, which is to minimize the resource consumption of the entire quantum distribution network under the premise of satisfying security constraints and key integrity constraints. Determine the constraints, including key integrity constraints, security constraints, path selection and allocation association constraints, and multi-path constraints.
[0236] (11) Input parameters into the model: Input parameters such as the weight of each reachable path, the number of hops, and the set of nodes into the constructed optimization model.
[0237] (12) Solve the optimization model: Use the mixed integer linear programming (MILP) algorithm to solve the optimization model and obtain the optimal path selection result and key distribution result.
[0238] (13) Generate optimization results: Based on the optimal solution obtained, generate a specific scheme containing the selected target reachable path and the corresponding key allocation ratio, and send the scheme to the source node.
[0239] (14) Source node prepares to distribute key: After receiving the path selection result and key distribution result, the source node divides the total quantum key Q of L into multiple sub-key segments according to the distribution ratio. The length of each sub-key segment is determined according to the distribution ratio of the corresponding path.
[0240] (15) The source node distributes the key through the optimization result: The source node distributes each sub-key segment according to the path selection result (i.e. the target path).
[0241] (16) Relay node encryption and forwarding: After receiving the subkey segment, the relay nodes on each path encrypt the quantum key segment using the locally generated quantum key and the one-time pad (OTP) encryption method. The relay nodes forward the encrypted quantum key segment to the next node until the quantum key segment safely reaches the destination node.
[0242] (17) Destination node receives key: The destination node receives quantum key segments from different target paths through the quantum key network.
[0243] (18) Decrypting the quantum key segment ciphertext: The destination node uses the quantum key shared with the relay node to decrypt the received quantum key segment ciphertext and recover the original quantum key segment.
[0244] (19) Reassemble the key: The destination node reassembles all the decrypted quantum key segments in the correct order to obtain the complete quantum key Q.
[0245] (20) Verify the integrity and security of the key: Perform integrity verification and security verification on the recombined quantum key Q to ensure that the key has not been tampered with or leaked during transmission.
[0246] further, Figure 4The diagram illustrates quantum key distribution. The source node sends a quantum key distribution request to the quantum key distribution network control center (QKDC). The QKDC control center determines the target path and distribution method and sends this information back to the source node. The source node divides the quantum key Q into K1, K2, ..., Kn quantum key segments according to the distribution method. Then, it sends these n quantum key segments to the destination node through various target paths. Ki, Kj, ..., Km are the shared keys used for encryption and decryption of the quantum key segments in each target path. The destination node obtains the ciphertext of each quantum key segment through its respective target path, decrypts it using the shared key from the previous node, and obtains K1, K2, ..., Kn. Then, K1, K2, ..., Kn are reassembled in sequence to obtain the quantum key Q.
[0247] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0248] Reference Figure 5 The diagram shows a structural block diagram of a quantum key distribution device according to a first embodiment of the present invention, which is applied to a quantum key distribution network control center and may specifically include the following modules:
[0249] The first acquisition module 501 is used to acquire network status information of the quantum key distribution network in response to a quantum key distribution request;
[0250] The first computing module 502 is used to determine a set of paths for distributing quantum keys based on the network state information; the set of paths includes at least one reachable path.
[0251] The second calculation module 503 is used to determine the path weight of each reachable path based on the network state information;
[0252] The third calculation module 504 is used to determine the distribution method of the quantum key based on the path weight, and to determine the target path from the path set;
[0253] The first sending module 505 is used to send the allocation method and the target path to the source node, so that the source node divides the quantum key based on the allocation method to obtain multiple quantum key segments, and sends each of the quantum key segments to the destination node based on the target path, so that the destination node reassembles each of the quantum key segments when it obtains each of the quantum key segments to obtain the quantum key.
[0254] In this embodiment of the invention, the first calculation module is specifically used for:
[0255] The network topology of the quantum distribution network is constructed using the network state information.
[0256] A preset algorithm is used to calculate at least one reachable path between the source node and the destination node in the network topology;
[0257] The reachable paths are combined to obtain a path set.
[0258] In this embodiment of the invention, it further includes:
[0259] The first verification module is used to verify the legitimacy of the quantum key distribution request before obtaining the network state information of the quantum key distribution network;
[0260] An extraction module is used to obtain the total number of quantum keys and the destination node from the quantum key distribution request if the verification is successful.
[0261] In this embodiment of the invention, the second computing module includes:
[0262] The determination submodule is used to determine the network status information of each node in each reachable path from the network status information;
[0263] The first calculation submodule is used to calculate the security score and resource consumption of each reachable path based on the network status information of each node;
[0264] The second calculation submodule is used to calculate the path weight of each reachable path based on the security score and resource consumption of each reachable path.
[0265] In this embodiment of the invention, the network state information includes quantum error rate, key generation rate, number of path nodes, and remaining key quantity in the key pool;
[0266] The first calculation submodule is specifically used for:
[0267] The security score of each node is calculated using the quantum error rate and the key generation rate of each node;
[0268] The resource consumption of each node is calculated using the number of path nodes for each node and the remaining key amount in the key pool.
[0269] In this embodiment of the invention, the third calculation module is specifically used for:
[0270] Construct an optimization model; the optimization model includes key allocation variables and path selection variables;
[0271] Input the path weight of each reachable path into the optimization model;
[0272] The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result.
[0273] The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key.
[0274] Reference Figure 6 The diagram shows a structural block diagram of a second embodiment of the quantum key distribution device of the present invention, applied to a source node, and specifically may include the following modules:
[0275] The first generation module 601 is used to generate a quantum key distribution request in response to a quantum key distribution instruction;
[0276] The second sending module 602 is used to send the quantum key distribution request to the quantum key distribution network control center, so that the quantum key distribution network control center responds to the quantum key distribution request, determines the quantum key allocation method and target path, and sends the allocation method and target path to the source node;
[0277] The second acquisition module 603 is used to acquire the allocation method and the target path;
[0278] The segmentation module 604 is used to segment the quantum key based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths;
[0279] The third sending module 605 is used to send each quantum key segment to the destination node through the corresponding target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
[0280] In this embodiment of the invention, the generation module is specifically used for:
[0281] Obtain the total number of keys and the destination node from the quantum key distribution instruction;
[0282] A quantum key distribution request is generated using the total amount of key and the destination node.
[0283] Reference Figure 7 The diagram shows a structural block diagram of a quantum key distribution device according to a third embodiment of the present invention, applied to a destination node, and specifically may include the following modules:
[0284] The third acquisition module 701 is used to acquire at least one quantum key segment ciphertext;
[0285] The decryption module 702 is used to decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment;
[0286] The recombination module 703 is used to recombine the various quantum key segments to obtain a quantum key.
[0287] In this embodiment of the invention, the decryption module is specifically used for:
[0288] Determine the previous hop node corresponding to each quantum key segment ciphertext;
[0289] Determine the shared key for each upstream node;
[0290] Each quantum key segment is obtained by decrypting the corresponding quantum key segment ciphertext using the shared key.
[0291] In this embodiment of the invention, it further includes:
[0292] The second verification module is used to verify the quantum key;
[0293] The second generation module is used to generate an alarm message if the verification fails.
[0294] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0295] This invention also provides an electronic device, comprising:
[0296] It includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described quantum key distribution method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0297] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described quantum key distribution method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0298] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0299] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0300] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0301] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0302] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0303] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0304] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0305] The present invention has provided a detailed description of a quantum key distribution method and a quantum key distribution device. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A quantum key distribution method, characterized in that, The method, applied to the control center of a quantum key distribution network, includes: Verify the legitimacy of quantum key distribution requests; If the verification is successful, the total number of quantum keys and the destination node are obtained from the quantum key distribution request. In response to a quantum key distribution request, network state information of the quantum key distribution network is obtained, and a set of paths for distributing quantum keys is determined based on the network state information; the set of paths includes at least one reachable path. The path weight of each reachable path is determined based on the network state information; Construct an optimization model; the optimization model includes key allocation variables and path selection variables, the path selection variables indicate whether to select a certain reachable path, and the key allocation variables indicate the proportion of quantum key segments allocated to the reachable path to the total number of keys; Input the path weight of each reachable path into the optimization model; The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result. The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key; The allocation method and the target path are sent to the source node, so that the source node can segment the quantum key based on the allocation method to obtain multiple quantum key segments, and send each quantum key segment to the destination node based on the target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
2. The quantum key distribution method according to claim 1, characterized in that, The step of determining the set of paths for distributing quantum keys based on the network state information includes: The network topology of the quantum key distribution network is constructed using the network state information; A preset algorithm is used to calculate at least one reachable path between the source node and the destination node in the network topology; The reachable paths are combined to obtain a path set.
3. The quantum key distribution method according to claim 1, characterized in that, Determining the path weight of each reachable path based on the network state information includes: The network status information of each node in each reachable path is determined from the network status information; The security score and resource consumption of each reachable path are calculated based on the network status information of each node; The path weight of each reachable path is calculated based on its security score and resource consumption.
4. The quantum key distribution method according to claim 3, characterized in that, The network state information includes quantum error rate, key generation rate, number of path nodes, and remaining key quantity in the key pool; The calculation of the security score and resource consumption of each reachable path based on the network state information of each node includes: The security score of each node is calculated using the quantum error rate and the key generation rate of each node; The resource consumption of each node is calculated using the number of path nodes for each node and the remaining key amount in the key pool.
5. A quantum key distribution method, characterized in that, Applied to the source node, the method includes: In response to a quantum key distribution instruction, a quantum key distribution request is generated; The quantum key distribution request is sent to the quantum key distribution network control center, which then responds to the request by verifying its legitimacy. If the verification is successful, the total number of quantum keys and the destination node are obtained from the request. In response to the request, the network state information of the quantum key distribution network is obtained, and a set of paths for distributing quantum keys is determined based on this information. The path set includes at least one reachable path. The path weight of each reachable path is determined based on the network state information. An optimization model is constructed, including key allocation variables and path selection variables. The path selection variable indicates whether to select a reachable path, and the key allocation variable indicates the proportion of quantum key segments allocated to that reachable path relative to the total number of keys. The path weight of each reachable path is input into the optimization model. A preset algorithm is used to solve the optimization model to obtain the optimal path selection result and the optimal key allocation result. The optimal path selection result is used as the target path, and the optimal key allocation result is used as the quantum key allocation method. The allocation method and the target path are then sent to the source node. Obtain the allocation method and the target path; The quantum key is divided based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths; Each quantum key segment is sent to the destination node through the corresponding target path, so that when the destination node obtains each quantum key segment, it can reassemble the quantum key segments to obtain the quantum key.
6. The quantum key distribution method according to claim 5, characterized in that, The generation of the quantum key distribution request includes: Obtain the total number of keys and the destination node from the quantum key distribution instruction; A quantum key distribution request is generated using the total amount of key and the destination node.
7. A quantum key distribution method, characterized in that, Applied to the destination node, the method includes: Obtain at least one quantum key segment ciphertext; Decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment; The individual quantum key segments are reassembled to obtain the quantum key; The quantum key segment ciphertext is generated in the following manner: The source node responds to the quantum key distribution instruction by generating a quantum key distribution request; The quantum key distribution request is sent to the quantum key distribution network control center, which then responds to the request by verifying its legitimacy. If the verification is successful, the total number of quantum keys and the destination node are obtained from the request. In response to the request, the network state information of the quantum key distribution network is obtained, and a set of paths for distributing quantum keys is determined based on this information. The path set includes at least one reachable path. The path weight of each reachable path is determined based on the network state information. An optimization model is constructed, including key allocation variables and path selection variables. The path selection variable indicates whether to select a reachable path, and the key allocation variable indicates the proportion of quantum key segments allocated to that reachable path relative to the total number of keys. The path weight of each reachable path is input into the optimization model. A preset algorithm is used to solve the optimization model to obtain the optimal path selection result and the optimal key allocation result. The optimal path selection result is used as the target path, and the optimal key allocation result is used as the quantum key allocation method. The allocation method and the target path are then sent to the source node. Obtain the allocation method and the target path; The quantum key is divided and encrypted based on the allocation method to obtain multiple quantum key segment ciphertexts.
8. The quantum key distribution method according to claim 7, characterized in that, The process of decrypting the ciphertext of each quantum key segment to obtain at least one quantum key segment includes: Determine the previous hop node corresponding to each quantum key segment ciphertext; Determine the shared key for each upstream node; Each quantum key segment is obtained by decrypting the corresponding quantum key segment ciphertext using the shared key.
9. The quantum key distribution method according to claim 7, characterized in that, Also includes: The quantum key is verified; If the verification fails, an alarm message will be generated.
10. A quantum key distribution device, characterized in that, The device, used in the control center of a quantum key distribution network, includes: The first verification module is used to verify the legitimacy of the quantum key distribution request; An extraction module is used to obtain the total number of quantum keys and the destination node from the quantum key distribution request if the verification is successful. The first acquisition module is used to acquire network status information of the quantum key distribution network in response to a quantum key distribution request; The first computing module is used to determine a set of paths for distributing quantum keys based on the network state information; the set of paths includes at least one reachable path. The second calculation module is used to determine the path weight of each reachable path based on the network state information; The third calculation module is used to determine the distribution method of the quantum key based on the path weight, and to determine the target path from the path set; The first sending module is used to send the allocation method and the target path to the source node, so that the source node can divide the quantum key based on the allocation method to obtain multiple quantum key segments, and send each of the quantum key segments to the destination node based on the target path, so that the destination node can reassemble each of the quantum key segments when it obtains each of the quantum key segments to obtain the quantum key. The third calculation module is specifically used for: Construct an optimization model; the optimization model includes key allocation variables and path selection variables; Input the path weight of each reachable path into the optimization model; The optimization model is solved using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result. The optimal path selection result is taken as the target path, and the optimal key allocation result is taken as the allocation method of the quantum key.
11. A quantum key distribution device, characterized in that, Applied to the source node, the device includes: The first generation module is used to generate a quantum key distribution request in response to a quantum key distribution instruction; The second sending module is configured to send the quantum key distribution request to the quantum key distribution network control center, so that the quantum key distribution network control center, in response to the quantum key distribution request, verifies the legitimacy of the quantum key distribution request; if the verification is successful, it obtains the total number of quantum keys and the destination node from the quantum key distribution request; in response to the quantum key distribution request, it obtains the network state information of the quantum key distribution network, and determines a set of paths for distributing quantum keys based on the network state information; the set of paths includes at least one reachable path; and determines the [specific parameters] of each reachable path based on the network state information. Path weights; constructing an optimization model; the optimization model includes key allocation variables and path selection variables, the path selection variable indicating whether to select a reachable path, and the key allocation variable indicating the proportion of quantum key segments allocated to the reachable path relative to the total number of keys; inputting the path weights of each reachable path into the optimization model; solving the optimization model using a preset algorithm to obtain the optimal path selection result and the optimal key allocation result; using the optimal path selection result as the target path, and the optimal key allocation result as the quantum key allocation method, and sending the allocation method and the target path to the source node; The second acquisition module is used to acquire the allocation method and the target path; A segmentation module is used to segment the quantum key based on the allocation method to obtain multiple quantum key segments; the number of quantum key segments is the same as the number of target paths; The third sending module is used to send each quantum key segment to the destination node through the corresponding target path, so that the destination node can reassemble each quantum key segment when it obtains each quantum key segment to obtain the quantum key.
12. A quantum key distribution device, characterized in that, Applied to the destination node, the device includes: The third acquisition module is used to acquire at least one quantum key segment ciphertext. The decryption module is used to decrypt the ciphertext of each quantum key segment to obtain at least one quantum key segment; The recombination module is used to recombine the various quantum key segments to obtain the quantum key; The quantum key segment ciphertext is generated in the following manner: The source node responds to the quantum key distribution instruction by generating a quantum key distribution request; The quantum key distribution request is sent to the quantum key distribution network control center, which then responds to the request by verifying its legitimacy. If the verification is successful, the total number of quantum keys and the destination node are obtained from the request. In response to the request, the network state information of the quantum key distribution network is obtained, and a set of paths for distributing quantum keys is determined based on this information. The path set includes at least one reachable path. The path weight of each reachable path is determined based on the network state information. An optimization model is constructed, including key allocation variables and path selection variables. The path selection variable indicates whether to select a reachable path, and the key allocation variable indicates the proportion of quantum key segments allocated to that reachable path relative to the total number of keys. The path weight of each reachable path is input into the optimization model. A preset algorithm is used to solve the optimization model to obtain the optimal path selection result and the optimal key allocation result. The optimal path selection result is used as the target path, and the optimal key allocation result is used as the quantum key allocation method. The allocation method and the target path are then sent to the source node. Obtain the allocation method and the target path; The quantum key is divided and encrypted based on the allocation method to obtain multiple quantum key segment ciphertexts.
13. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the quantum key distribution method as described in any one of claims 1 to 4, 5 to 6, or 7 to 9.
14. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the steps of the quantum key distribution method as described in any one of claims 1-4, 5-6, or 7-9.
Citation Information
Patent Citations
Quantum key distribution relay path determination method, device and system and medium
CN119341739A
Routing method suitable for quantum key distribution network and related equipment
CN119766451A