Quantum-enhanced optical transport network security system and communication method

By integrating quantum enhancement units into optical transport network equipment, a quantum-safe system integrating hardware, software, and protocol layers is realized, solving the problem of separate deployment of OTN equipment and quantum equipment, achieving efficient quantum-safe and secure transmission, and covering the complete application scenarios of optical transport networks.

CN120639388BActive Publication Date: 2025-12-09BEIJING MENGLIXING TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510792807.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-12-09
Estimated Expiration
2045-06-13

AI Technical Summary

Technical Problem

The separate deployment of OTN and quantum devices in existing optical transport networks results in low efficiency of communication information security encapsulation and high deployment complexity. QKD technology cannot fully cover optical transport network application scenarios and has limited security monitoring capabilities.

Method used

A quantum-enhanced optical transport network security system is adopted. By miniaturizing and integrating quantum enhancement units into optical transport network equipment, including quantum communication modules, secure encapsulation/restore modules, and quantum measurement sensing modules, hardware, software, and protocol layer integration is achieved. The quantum measurement sensing module is used to establish health records, match security parameter distribution modes, and combine quantum key distribution or QRNG with encryption algorithms for secure parameter distribution and data encapsulation and restoration.

Benefits of technology

It enables efficient and reliable quantum-secure and confidential transmission in traditional telecommunications optical transport networks, ensuring the confidentiality and integrity of communication information, reducing deployment complexity and maintenance costs, and covering the full range of application scenarios for optical transport networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639388B_ABST
    Figure CN120639388B_ABST
Patent Text Reader

Abstract

The application provides a quantum-enhanced optical transport network security system and a communication method, and the system is a hardware, software and protocol layer integrated structure, comprising: an optical transport network device and a quantum enhancement unit; the quantum enhancement unit comprises: a quantum measurement sensing module, which establishes a health record of the optical transport network device, matches a security parameter distribution mode based on the health record, and monitors the security state of the optical fiber transmission channel during the security parameter distribution process, and locates the security risk event; based on the security parameter distribution mode, the quantum communication module or the security packaging / restoration module generates security parameters, and distributes the security parameters to each communication node; after the security parameter distribution is completed, the security packaging / restoration module packages and restores the communication information data; and the optical transport network device transmits the packaged communication information data to the target communication node. The application can cover the traditional telecommunication optical transport network, and realizes the quantum security and privacy transmission of the telecommunication optical transport network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information and communication technology, in particular to an optical transport network security system based on quantum enhancement and a communication method. BACKGROUND

[0002] Optical transport network (OTN) is a high-speed, high-capacity, low-latency optical transmission technology, and is a key infrastructure of information and communication technology (ICT). However, with the development of science and technology, the boundaries of communication networks are opened, the exposure of key infrastructures is continuously expanded, the security risks of transparent transmission are continuously increased, and the security threats are becoming more and more serious.

[0003] Quantum technology has become one of the core driving forces of the next generation of information technology. Quantum communication can help build a new communication system that is theoretically unconditionally secure, thanks to its unique advantages in principle, and can solve the information leakage risks faced by traditional encryption systems. This technology is considered a strategic frontier technology for building future network space security infrastructure. In the scheme of combining quantum technology and optical transport network, the existing scheme has the following problems: 1. OTN equipment and quantum equipment are deployed separately. For example, by connecting quantum communication equipment and traditional OTN equipment, or using quantum communication network to distribute security parameters for communication information security encapsulation and secure transmission. The efficiency of communication information security encapsulation is not high, and the complexity and cost of deployment are high. 2. Existing QKD technology cannot completely cover the optical transport network application scenario due to the application scenarios of quantum key distribution (QKD) equipment transmission technology conditions or optical fiber resources. SUMMARY

[0004] Therefore, the purpose of the present application is to provide an optical transport network security system based on quantum enhancement and a communication method, which can cover traditional telecommunications optical transport networks and realize quantum secure transmission of telecommunications optical transport networks.

[0005] In order to achieve the above purpose, the technical scheme adopted by the present application is as follows:

[0006] In a first aspect, the present application provides a quantum-enhanced optical transport network security system, which is a hardware, software and protocol layer integrated structure, comprising: an optical transport network device and a quantum enhancement unit; wherein the quantum enhancement unit is integrated in a slot of the optical transport network device, and the quantum enhancement unit comprises: a quantum communication module, a security packaging / restoration module and a quantum measurement sensing module; the quantum measurement sensing module is used to establish a health record of the optical transport network device, and based on the health record, a data matching security parameter distribution mode is specified according to a target application scenario or a transmission channel; if the security parameter distribution mode is a quantum key distribution security parameter distribution mode, the quantum communication module is used to generate security parameters and distribute the security parameters to each communication node; if the security parameter distribution mode is a QRNG combined with an encryption algorithm security parameter distribution mode, the security packaging / restoration module is used to generate security parameters and distribute the security parameters to each communication node; during the security parameter distribution process, the quantum measurement sensing module is further used to monitor the security state of the optical fiber transmission channel and locate the security risk events of the optical fiber transmission channel; after the security parameter distribution is completed, the security packaging / restoration module is further used to package and restore the communication information data based on the security parameters and a preset encryption algorithm; and the optical transport network device is used to transmit the packaged communication information data to a target communication node.

[0007] Optionally, the quantum measurement sensing module is specifically used to: analyze the optical fiber channel quality characteristic index and identify the characteristic information, security status information and device identity information of the optical fiber transmission channel by using intelligent identification technology, time-of-flight testing, quantum measurement sensing, registration verification and identity authentication, and establish the health record of the optical transport network device.

[0008] Optionally, the quantum measurement sensing module is further used to: inject a monitoring optical pulse signal into the channel, and use single-photon detection technology and high-precision time resolution technology to dynamically collect physical quantities in backscattered or reflected signals; after preprocessing the collected physical quantities, the optical fiber channel quality characteristic index is obtained by extracting features of different dimensions.

[0009] Optionally, the quantum measurement sensing module is further used to: monitor the security state of the optical fiber transmission channel based on the optical fiber channel quality characteristic index, and locate the security risk events of the optical fiber transmission channel.

[0010] Optionally, if the security parameter distribution mode is a quantum key distribution security parameter distribution mode, the quantum communication module is specifically configured to: for an optical transmission channel that meets quantum key distribution technical conditions, generate security parameters using a quantum key distribution technology, and distribute the security parameters to each communication node; wherein the quantum key distribution technical conditions at least include: quantum key distribution transmission distance, quantum channel, quantum key distribution protocol, and encoding mode, the quantum key distribution protocol at least includes: entanglement BB84 protocol, Gaussian modulation coherent state protocol; the encoding mode at least includes: polarization, phase, time phase.

[0011] Optionally, if the security parameter distribution mode is a QRNG combined with an encryption algorithm security parameter distribution mode, the security packaging / restoration module is specifically configured to: for an optical transmission channel that does not meet the quantum key distribution technical conditions, generate security parameters using a quantum random number generator; based on a preset encryption algorithm protocol, perform identity authentication and security parameter distribution between each communication node; wherein the preset encryption algorithm protocol at least includes: post-quantum cryptography algorithm, SM2 algorithm, SM3 algorithm, SM4 algorithm.

[0012] Optionally, the security packaging / restoration module is further configured to: transmit uplink data of the communication information to the optical path payload unit, and package the communication information data in the optical path payload unit based on the security parameters, update the OPUk payload before packaging with the OPUk payload after packaging; combine the OPUk payload after packaging and the ODU overhead to form an ODU, and map the ODU to a QOTN frame through multiplexing mapping; after the QOTN frame is transmitted to the target communication node through the optical transmission network device, separate the ODU from the QOTN frame, and extract the OPUk payload from the ODU; restore the OPUk payload based on the security parameters, and update the OPUk payload before restoration with the OPUk payload after restoration; extract the communication information data based on the OPUk payload after restoration, and transmit the communication information data to the downlink service side.

[0013] In a second aspect, the present application provides a communication method applied to the quantum-enhanced optical transport network security system of any one of the first aspect, the quantum-enhanced optical transport network security system being a hardware, software, and protocol layer integrated structure, comprising: an optical transport network device and a quantum enhancement unit; wherein the quantum enhancement unit is miniaturized and integrated into a slot of the optical transport network device, the quantum enhancement unit comprising: a quantum communication module, a security packaging / restoration module, and a quantum measurement sensing module; the method comprising: establishing a secure channel between communication nodes through a transmission channel, and establishing a health record of the optical transport network device through the quantum measurement sensing module, and based on the health record, specifying a data matching security parameter distribution mode according to a target application scenario or a transmission channel; if the security parameter distribution mode is a quantum key distribution security parameter distribution mode, generating a security parameter through the quantum communication module and distributing the security parameter to each communication node; if the security parameter distribution mode is a security parameter distribution mode combining QRNG and an encryption algorithm, generating a security parameter through the security packaging / restoration module and distributing the security parameter to each communication node; in the security parameter distribution process, the quantum measurement sensing module is further used for monitoring the security state of the optical fiber transmission channel and locating a security risk event of the optical fiber transmission channel; after the security parameter distribution is completed, the security packaging / restoration module is used for packaging and restoring communication information data based on the security parameter and a preset encryption algorithm; and the optical transport network device is used for transmitting the packaged communication information data to a target communication node.

[0014] Optionally, the health record of the optical transport network device is established through the quantum measurement sensing module, comprising: using intelligent identification technology to identify characteristic information, security state information, and device identity information of the optical fiber transmission channel through time-of-flight testing, quantum measurement sensing, registration verification, and identity authentication, and establishing the health record of the optical transport network device.

[0015] Optionally, the security parameter is generated through the quantum communication module and distributed to each communication node, comprising: for the optical transport channel meeting the quantum key distribution technical conditions, generating the security parameter using the quantum key distribution technology and distributing the security parameter to each communication node; wherein the quantum key distribution technical conditions comprise: quantum key distribution transmission distance, quantum channel, quantum key distribution protocol, and encoding mode, the quantum key distribution protocol comprises: entanglement BB84 protocol and Gaussian modulation coherent state protocol; and the encoding mode comprises: polarization, phase, and time phase.

[0016] The present application has the following beneficial effects:

[0017] The application provides the above-mentioned quantum-enhanced optical transport network security system and communication method, which is a hardware, software and protocol layer integrated structure, and comprises optical transport network equipment and a quantum enhancement unit; the quantum enhancement unit is integrated in a slot of the optical transport network equipment in a miniaturized manner, and comprises a quantum communication module, a security packaging / restoration module and a quantum measurement sensing module; the quantum measurement sensing module is used for establishing a health record of the optical transport network equipment, and based on the health record, a data matching security parameter distribution mode is specified according to a target application scenario or a transmission channel; if the security parameter distribution mode is a quantum key distribution security parameter distribution mode, the quantum communication module is used for generating security parameters and distributing the security parameters to each communication node; if the security parameter distribution mode is a QRNG combined with an encryption algorithm security parameter distribution mode, the security packaging / restoration module is used for generating security parameters and distributing the security parameters to each communication node; in the security parameter distribution process, the quantum measurement sensing module is further used for monitoring the security state of the optical fiber transmission channel and locating a security risk event of the optical fiber transmission channel; after the security parameter distribution is completed, the security packaging / restoration module is further used for packaging and restoring communication information data based on the security parameters and a preset encryption algorithm; and the optical transport network equipment is used for transmitting the packaged communication information data to a target communication node.

[0018] The above-mentioned quantum-enhanced optical transport network security system adopts an optical transmission equipment "all-in-one" design, integrates the quantum enhancement unit in a miniaturized manner in a slot of the optical transport network equipment, and is a hardware, software and protocol layer integrated design. The health record of the optical transport network equipment is established by the quantum measurement sensing module, and based on the health record, a security parameter distribution mode is matched according to a target application scenario and an optical fiber transmission channel, so that the security parameters are distributed between communication nodes in a trusted security domain; in the security parameter distribution process, the quantum measurement sensing module can monitor the security state of the optical fiber transmission channel and locate a security risk event of the optical fiber transmission channel as needed; after the security parameter distribution is completed, the communication information data can be packaged and restored in combination with the security parameters and a preset encryption algorithm, the confidentiality and integrity of the transmission information are ensured, and thus the quantum security and privacy transmission of the telecommunication optical transport network is realized.

[0019] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application will be realized and achieved by the structure particularly pointed out in the description, claims and drawings.

[0020] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the following preferred embodiments are specifically described below, and the accompanying drawings are referred to for detailed description. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the specific embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0022] Figure 1 A quantum-enhanced optical transport network security architecture diagram is provided for the embodiments of the present application.

[0023] Figure 2 A quantum measurement sensing module principle schematic diagram is provided for the embodiments of the present application.

[0024] Figure 3 A QKD working principle schematic diagram is provided for the embodiments of the present application.

[0025] Figure 4 A secure packaging / reduction module schematic diagram is provided for the embodiments of the present application.

[0026] Figure 5 A communication information data packaging and reduction schematic diagram is provided for the embodiments of the present application.

[0027] Figure 6 A quantum-enhanced OTN equipment block diagram is provided for the embodiments of the present application.

[0028] Figure 7 A communication flowchart of a quantum-enhanced optical transport network security system is provided for the embodiments of the present application.

[0029] Figure 8 A flowchart of a communication method is provided for the embodiments of the present application.

[0030] Figure 9 A structural schematic diagram of an electronic device is provided for the embodiments of the present application. DETAILED DESCRIPTION

[0031] In order to make the purposes, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions of the present application will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.

[0032] Currently, the application scenarios of quantum key distribution are limited by transmission line conditions, OTN equipment and separate deployment of quantum equipment, and there are problems of low performance efficiency, high cost, complex maintenance, limited security monitoring and protection ability of existing fiber channel, and insufficient active defense means.

[0033] Based on this, the embodiment of the present application provides an optical transport network security system and a communication method based on quantum enhancement, which can cover the traditional telecommunications optical transport network and realize quantum security transmission of the telecommunications optical transport network.

[0034] In order to facilitate the understanding of the present embodiment, first of all, a kind of quantum enhancement-based optical transport network security system disclosed by the embodiment of the present application is introduced in detail. Referring to Figure 1 As shown, according to the structure of traditional telecommunications network, based on the form of OTN equipment, referring to the relevant standards of ITU-T, quantum technology is integrated in the form of equipment module in OTN equipment, which is a high-integration, high-security and high-reliability design from hardware, software and protocol layer, thereby forming an optical transport equipment with integrated security. The quantum enhancement-based optical transport network security architecture includes an optical transport network device and a quantum enhancement unit, which is integrated in the slot of the optical transport network device. The optical transport network device includes a user side processing module, a cross module, a line side processing module and a multiplexing / demultiplexing module; the quantum enhancement unit (i.e. QuA quantum enhancement unit) includes but is not limited to: a quantum communication module, a security packaging / restoration module and a quantum measurement sensing module.

[0035] The quantum measurement sensing module is used to establish a health record of the optical transport network device, and based on the health record, a data matching security parameter distribution mode is specified according to the target application scenario or transmission channel.

[0036] If the security parameter distribution mode is a quantum key distribution security parameter distribution mode, the quantum communication module is used to generate security parameters and distribute them to each communication node; if the security parameter distribution mode is a security parameter distribution mode combining QRNG (Quantum Random Number Generator) and encryption algorithm, the security packaging / restoration module is used to generate security parameters and distribute them to each communication node.

[0037] During the security parameter distribution process, the quantum measurement sensing module can monitor the security state of the fiber transmission channel and locate the security risk events of the fiber transmission channel as needed.

[0038] After the security parameter distribution is completed, the security packaging / restoration module is also used to package and restore the communication information data based on the security parameters and the preset encryption algorithm.

[0039] The optical transport network device is used for transmitting encapsulated communication information data to a target communication node.

[0040] The optical transport network security system based on quantum enhancement provided by the embodiment of the application adopts the "all-in-one" design of the optical transmission device, miniaturizes the quantum enhancement unit and fuses it in the optical transport network device slot, establishes a health record of the optical transport network device through the quantum measurement and sensing module, and distributes security parameters according to a target application scenario and a fiber transmission channel matching security parameter distribution mode based on the health record, so that the security parameters realize secure distribution between communication nodes in a trusted security domain; after the security parameter distribution is completed, the communication information data can be encapsulated and restored in combination with the security parameters and a preset encryption algorithm, the confidentiality and integrity of the transmission information are ensured, and thus the quantum secure and confidential transmission of the telecommunication optical transport network is realized.

[0041] In an embodiment, the quantum measurement and sensing module is specifically configured to: adopt intelligent identification technology, identify characteristic information, security status information and device identity information of the fiber transmission channel through time-of-flight testing, quantum measurement and sensing, registration verification and identity authentication, and establish a health record of the optical transport network device.

[0042] In specific implementation, the quantum measurement and sensing module is used for online measurement of the physical security of the OTN fiber transmission route. Specifically, technologies such as time-of-flight testing and quantum measurement and sensing (QMS) can be adopted to monitor the physical characteristics of the fiber in real time and dynamically, identify event, loss, distance and other operating environment physical conditions, as well as security status information, device identity information and other information in the transmission route, establish a health record of the optical transport network device through data preprocessing, feature data extraction and artificial intelligence technology.

[0043] Further, the security parameter distribution mode can be automatically matched according to the health record, and the security parameter distribution mode includes: (1) a quantum key distribution (QKD) security parameter distribution mode, which adopts a quantum communication module to distribute security parameters; and (2) a security parameter distribution mode combining QRNG with national encryption, PQC and other algorithms, which adopts a security encapsulation / restoration module to distribute security parameters.

[0044] The quantum measurement and sensing module can also analyze and evaluate the fiber transmission quality and identify possible security parameter or communication information eavesdropping risks in the whole life cycle of the security parameters on demand, and provide security operation and maintenance guidance for fiber line maintenance. Specifically, the quantum measurement and sensing module can monitor the security status of the fiber transmission channel based on the fiber channel quality characteristic index, and locate the security risk events of the fiber transmission channel.

[0045] In an embodiment, the quantum measurement sensing module is further configured to: inject a monitoring optical pulse signal into the channel, and dynamically collect physical quantities in the backscattered or reflected signal by using single-photon detection technology and high-precision time resolution technology; and after preprocessing the collected physical quantities, extract features of different dimensions to obtain the optical fiber channel quality feature index.

[0046] In specific implementation, referring to FIG. 1, Figure 2 As shown in FIG. 1, the quantum measurement sensing module injects a monitoring optical pulse into the channel, and dynamically collects physical quantities in the backscattered or reflected signal by using single-photon detection technology and high-precision time resolution technology. After sending the data to the processing unit, and preprocessing the data (cleaning, denoising, normalization, etc.), features of different dimensions (such as time domain, frequency domain, time-frequency, intensity, etc.) are extracted, and then the optical fiber channel quality feature index and abnormal events such as clamping, bending, fiber breakage, strong light injection, V-shaped groove cut, scattering, beam separation, asymptotic coupling, etc. in the channel are identified, analyzed, located and evaluated by combining intelligent algorithms. At the same time, through the quantum enhancement cooperation mechanism, the QuA is provided with real-time and reliable security analysis and evaluation, to ensure the confidentiality, integrity and credibility of the security parameter distribution.

[0047] In an embodiment, the quantum communication module is specifically configured to: for an optical transmission channel meeting the quantum key distribution technology conditions, generate security parameters by using quantum key distribution technology, and distribute the security parameters to each communication node; wherein the quantum key distribution technology conditions at least include: quantum key distribution transmission distance, quantum channel, quantum key distribution protocol and encoding mode, the quantum key distribution protocol at least includes: entangled state BB84 protocol, Gaussian modulation coherent state protocol; and the encoding mode at least includes: polarization, phase, time phase.

[0048] In specific implementation, the quantum communication module is mainly composed of QKD and other functional modules. For an optical transmission channel meeting the QKD technology conditions in a traditional telecommunications network, the two parties of communication can generate and share random security parameters, which are used for subsequent packaging and restoring of communication information.

[0049] Specifically, for an optical transmission channel meeting the technology conditions in a traditional telecommunications network, the security of the security parameter distribution is ensured by using the principle of quantum mechanics. Referring to FIG. 2, Figure 3A QKD working principle diagram is shown. Quantum key distribution is a secure communication method involving quantum technology components and protocols, which enables both parties to generate and share a random security parameter to encapsulate and restore communication information. The technical conditions of QKD generally include QKD transmission distance, quantum channel, QKD protocol and encoding method. QKD protocols include but are not limited to decoy state BB84 protocol, Gaussian modulation coherent state protocol, etc. The encoding method can be polarization, phase, time phase, etc. Through time division multiplexing, a secure parameter distribution link from the central room to the node room n is constructed. The control unit is used to process the relevant control information between nodes, such as synchronization information and classical communication information during the security parameter distribution process; the analysis unit is used to receive and analyze the information uploaded between nodes for subsequent optimization of on-demand allocation of security parameter resources.

[0050] In an embodiment, the security encapsulation / restoration module is specifically used for: for optical transmission channels that do not meet the technical conditions of quantum key distribution, using a quantum random number generator to generate security parameters; based on a preset encryption algorithm protocol, identity authentication and security parameter distribution between communication nodes are performed; wherein the preset encryption algorithm protocol at least includes: a post-quantum cryptography algorithm, an SM2 algorithm, an SM3 algorithm, and an SM4 algorithm.

[0051] In specific implementation, the security encapsulation / restoration module mainly consists of a quantum random number generator (QRNG), a post-quantum cryptography (PQC), a security module, and a QMS cooperative mechanism and intelligent matching algorithm, which are used for security parameter generation and synchronization, security encapsulation and restoration, and security parameter life cycle management. For optical transmission channels that do not meet the technical conditions of QKD, QRNG is combined with national encryption and PQC algorithms, and is configured to run according to the strategy, to realize identity authentication and security parameter sharing between communication nodes, and to complete communication information security encapsulation or security restoration.

[0052] Specifically, the security encapsulation / restoration module carries SM2, SM3, SM4, etc. national encryption algorithms, covers Kyber, Dilithium, and SPHINCS+ post-quantum cryptography algorithms, and is composed of an integrated intellectual property core, an efficient core operator, a dynamic reconfigurable, a side channel attack defense, a security SoC integrated technology special integrated circuit, and a security hardware composed of QRNG, FPGA, etc. and a QMS security cooperative strategy platform. See Figure 4As shown, the security module mainly includes an embedded system, a hardware cryptographic coprocessor, and a quantum random number entropy source. The embedded system realizes the rapid response and processing of control commands and data, and the hardware cryptographic coprocessor realizes cryptographic operations such as encryption and decryption, key exchange, and digital signature verification. The quantum random number entropy source can extract random information from the true physical state based on quantum principles such as quantum tunneling effect, ensuring the compliance and security of the source of the cryptographic system. Among them, the security encapsulation / restore module includes the following functions: (1) providing high-speed, multi-task parallel processing security operation functions; (2) providing functions such as application system digital signature, identity authentication, security parameter exchange, communication service data protection, and security parameter lifecycle management; (3) used to establish a secure communication channel for security parameter exchange, protect the unforgeability of digital signatures and the security of data during transmission and storage, and ensure the confidentiality, integrity, and trustworthiness of transmitted information.

[0053] Furthermore, the aforementioned secure encapsulation / restore module is also used for: transmitting uplink data of communication information to the optical path payload unit, and performing secure encapsulation of the communication information data in the optical path payload unit based on security parameters, and updating the unencapsulated OPUk payload using the encapsulated OPUk payload; combining the encapsulated OPUk payload and ODU overhead into an ODU, and mapping the ODU to a QOTN frame through multiplexing mapping; after the QOTN frame is transmitted to the target communication node via the optical transport network equipment, separating the ODU from the QOTN frame, and extracting the OPUk payload from the ODU; performing secure restoration of the OPUk payload based on security parameters, and updating the unrestored OPUk payload using the restored OPUk payload; extracting communication information data based on the restored OPUk payload, and transmitting the communication information data to the downlink service side.

[0054] For details, see Figure 5 The diagram illustrates a communication information data encapsulation and restoration process. Uplink data from the communication information is sent to the Optical Path Payload Unit (OPUk). Security parameters are used to securely encapsulate the communication information data in the OPUk, and the OPUk payload is updated. Then, the OPUk payload and ODU overhead are combined to form an ODU, which is then multiplexed and mapped to a QOTN frame. After being transmitted to the target communication node via the optical transport network, the ODU is separated from the QOTN device frame, and the OPUk payload is extracted. Security parameters are used to securely restore the OPUk payload area, and the restored OPUk payload is used to update the original OPUk payload. Thus, the communication information data can be extracted from the OPUk and transmitted to the downlink side.

[0055] The embodiment of the present application can enable quantum security parameters to be securely distributed between communication nodes in a trusted security domain, and be used for on-demand deployment of quantum-enhanced security technology at the OTN physical layer, data link layer or network layer, and completely cover traditional telecommunications optical transport networks, thereby realizing quantum security and privacy transmission of the telecommunications optical transport network, without affecting normal communication, without leaving security risks due to relays, and without affecting quantum security performance due to optical amplification.

[0056] For ease of understanding, the present application also provides a quantum-enhanced OTN equipment block diagram, as shown in Figure 6 The control and exchange platform CXP (Control and Exchange Platform) integrates cross, master control, and clock, supports communication control, service scheduling, clock processing, etc., the hardware architecture adopts a single board design, the quantum enhancement unit provides two types of interfaces for customer side and line side, and includes a quantum communication module, a security packaging / restoration module, a quantum measurement sensing module, etc. The quantum-enhanced OTN simultaneously supports packet switching, time division multiplexing (TDM), VC cross of SDH, and OTN service adaptation packaging and mapping functions, and has various communication service interfaces such as E1, FE, GE, 10GE LAN, STM-1 / 4 / 16, STM-64, ODU1, ODU2, etc.

[0057] The quantum enhancement unit includes but is not limited to a quantum communication module, a security packaging / restoration module, a quantum measurement sensing module, and a security policy, adopts SM2, SM3, SM4, and PQC algorithms, and through quantum enhancement and collaborative mechanisms such as identity authentication and security monitoring and evaluation, a distributed telecommunications network single-to-multipoint security parameter distribution network is constructed, communication information is packaged and restored for security, and OTN security and privacy is realized.

[0058] The quantum enhancement unit is a quantum-enhanced optical transport network security architecture, which is applied to the above-mentioned quantum-enhanced optical transport network security system, as shown in Figure 7 The communication process of the quantum-enhanced optical transport network security system includes the following steps:

[0059] S1: Establish and analyze the channel. Specifically, first, a secure channel is established between the communication nodes through the transmission channel, the quantum measurement sensing module is used, intelligent identification technology is adopted, and through node identity authentication, time-of-flight testing, quantum measurement sensing, and other security mechanisms and strategies, the characteristics of the optical fiber transmission channel are analyzed, the characteristics of the optical fiber channel, the security status, the device identity, and other performances are identified, and a basic infrastructure health record is established.

[0060] S2: Security parameter distribution. Specifically, according to the health record, one of the following two security parameter distribution mechanisms is selected according to the application scenario and the transmission channel to complete the security parameter distribution: (1) Technical route one: using a quantum communication module, a QKD security parameter distribution mode; (2) Technical route two: using a secure packaging / reduction module, adopting a QRNG combined with a national secret, a PQC and other algorithm security parameter distribution mode. At the same time, a network management system is deployed to centrally monitor, diagnose and implement performance, configuration and security management.

[0061] S3: Security state monitoring and risk event positioning. Specifically, in the security parameter distribution process, the quantum measurement sensing module can monitor the security state of the optical fiber transmission channel as needed, and locate the security risk events of the optical fiber transmission channel.

[0062] S4: Communication information data packaging and reduction. Specifically, after the security parameter distribution is completed, the data of the communication information is packaged and reduced by using the security parameter combined with the national secret, the PQC and other algorithms. The whole process adopts the security parameter full life cycle management, and the network management system is deployed to centrally monitor, diagnose, analyze exceptions, manage performance, configure and manage security, so as to centrally manage the OTN equipment, the communication route, the transmission medium, the communication information and the security parameter, and alarm the abnormal phenomena and positioning, so as to guarantee the security, stability and efficient operation of the communication network, and reduce the maintenance cost.

[0063] The above-mentioned optical transport network security system based on quantum enhancement provided by the embodiment of the application adopts a QuA technology and an OTN transmission equipment integrated technical route including but not limited to quantum key distribution, quantum random number generator, post-quantum cryptography and quantum measurement sensing, realizes the quantum security and quantum enhancement protection functions such as security packaging and security reduction on the OTN physical layer, the data link layer or the network layer according to the application demand on the basis of the traditional telecommunication network, and fully adapts to the traditional telecommunication network structure and the flexibility networking requirement.

[0064] The embodiment of the application is based on the international telecommunication union (ITU-T) OTN technical standard, and through the QuA miniaturization design technology, the QKD, the QRNG, the PQC and the QMS and other equipment and component boards are integrated in the OTN equipment slot, which is a hardware, software and protocol layer integrated telecommunication level solution with high integration, high security and high reliability.

[0065] The embodiment of the application adopts a high-sensitivity large-dynamic-range QMS technology, dynamically monitors the physical properties of the optical fiber through an online measurement strategy and a security cooperation mechanism, captures the security hidden danger of the optical fiber channel in real time, provides physical security data and analysis and evaluation conclusions for the online distribution of the security parameter channel, monitors the safety of the optical transport network infrastructure, and guarantees the confidentiality, integrity and credibility of the optical fiber transmission.

[0066] For the quantum-enhanced optical transport network security system provided in the foregoing embodiments, an embodiment of the present application further provides a communication method applied to the quantum-enhanced optical transport network security system in the foregoing embodiments, referring to Figure 8 A flowchart of a communication method is shown in FIG. 8, which shows that the method mainly includes the following steps S801 to S805:

[0067] Step S801: a secure channel between communication nodes is established through a transmission channel, and a health record of an optical transport network device is established through a quantum measurement sensing module, and based on the health record, a data matching security parameter distribution mode is specified according to a target application scenario or a transmission channel.

[0068] Step S802: if the security parameter distribution mode is a quantum key distribution security parameter distribution mode, a security parameter is generated through a quantum communication module, and the security parameter is distributed to each communication node; if the security parameter distribution mode is a QRNG combined with an encryption algorithm security parameter distribution mode, a security parameter is generated through a security packaging / restoration module, and the security parameter is distributed to each communication node.

[0069] Step S803: in the security parameter distribution process, the security state of the optical fiber transmission channel is monitored through the quantum measurement sensing module, and a security risk event of the optical fiber transmission channel is located.

[0070] Step S804: after the security parameter distribution is completed, the communication information data is packaged and restored based on the security parameter and a preset encryption algorithm through the security packaging / restoration module.

[0071] Step S805: the packaged communication information data is transmitted to a target communication node through the optical transport network device.

[0072] The communication method provided in the embodiment of the present application establishes a health record of an optical transport network device through a quantum measurement sensing module, and according to the health record, a security parameter distribution mode is matched according to a target application scenario and an optical fiber transmission channel, so that the security parameter realizes secure distribution between communication nodes in a trusted security domain; after the security parameter distribution is completed, the communication information data can be packaged and restored in combination with the security parameter and a preset encryption algorithm, thereby ensuring the confidentiality and integrity of the transmission information, so as to realize quantum security and privacy transmission of the telecommunication optical transport network.

[0073] In an embodiment, when the health record of the optical transport network device is established through the quantum measurement sensing module, the following modes can be adopted, but are not limited to: an intelligent recognition technology is adopted to recognize characteristic information, security state information and device identity information of the optical fiber transmission channel through time-of-flight testing, quantum measurement sensing, registration verification and identity authentication, and the health record of the optical transport network device is established.

[0074] It should be noted that the method provided by the embodiments of the present application has the same implementation principle and technical effects as the foregoing system embodiments, and for brief description, the part not mentioned in the method embodiments can refer to the corresponding content in the foregoing system embodiments.

[0075] The embodiments of the present application also provide an electronic device, specifically, the electronic device includes a processor and a storage device; the storage device stores a computer program, and the computer program performs the method according to any one of the above embodiments when the computer program is run by the processor.

[0076] Figure 9 The structure schematic diagram of the electronic device provided by the embodiments of the present application is shown in the figure, and the electronic device 100 includes a processor 90, a memory 91, a bus 92 and a communication interface 93, the processor 90, the communication interface 93 and the memory 91 are connected through the bus 92; the processor 90 is used for executing the executable module stored in the memory 91, for example, a computer program.

[0077] The memory 91 can contain a high-speed random access memory (RAM), and can also include a non-volatile memory, for example, at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 93 (which can be wired or wireless), and the Internet, a wide area network, a local area network, a metropolitan area network, etc. can be used.

[0078] The bus 92 can be an ISA bus, a PCI bus or an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 9 Only one bidirectional arrow is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0079] The memory 91 is used for storing a program, and the processor 90 executes the program after receiving an execution instruction; the method executed by the device defined by the flow process disclosed in any one of the foregoing embodiments of the present application can be applied to the processor 90 or realized by the processor 90.

[0080] The processor 90 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the processor 90 or the instruction in the form of software. The processor 90 described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. Each method, step and logic block disclosed in the embodiment of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiment of the present application can be directly embodied as a hardware code processor for execution, or can be executed by a combination of hardware and software modules in the code processor. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register or other mature storage medium in the art. The storage medium is located in the memory 91, and the processor 90 reads the information in the memory 91 and combines the hardware to complete the steps of the above method.

[0081] The computer program product of the readable storage medium provided by the embodiment of the present application comprises a computer readable storage medium storing program codes, and the instructions included in the program codes can be used to execute the method described in the foregoing method embodiment. The specific implementation can be referred to the foregoing method embodiment, and will not be described here.

[0082] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of software products. The computer software product is stored in a storage medium and includes instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0083] Finally, it should be noted that: the above-described embodiments are only specific embodiments of the present application, which are used to illustrate the technical solutions of the present application, but not to limit them. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily think of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed by the present application, or make equivalent replacements to some of the technical features. The modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A quantum-enhanced optical transport network security system, comprising: The system is a hardware, software, protocol layer integrated structure, comprising: an optical transport network device and a quantum enhancement unit; wherein the quantum enhancement unit is miniaturized and integrated into a slot of the optical transport network device, the quantum enhancement unit comprises: a quantum communication module, a security packaging / restoration module and a quantum measurement sensing module; The quantum measurement sensing module is used to establish a health record of the optical transport network device, and based on the health record, a target application scenario or a transmission channel is specified to match a data security parameter distribution mode; For an optical transmission channel meeting the quantum key distribution technology condition, the security parameter distribution mode is a security parameter distribution mode of quantum key distribution, and the quantum communication module is used to generate security parameters and distribute the security parameters to each communication node; for an optical transmission channel not meeting the quantum key distribution technology condition, the security parameter distribution mode is a security parameter distribution mode of quantum random number generator QRNG combined with an encryption algorithm, and the security packaging / restoration module is used to generate security parameters and distribute the security parameters to each communication node; The quantum measurement sensing module is specifically used to: adopt intelligent identification technology, analyze fiber channel quality characteristic indexes through time-of-flight test, quantum measurement sensing, registration verification and identity authentication, identify characteristic information, security status information and device identity information of the fiber transmission channel, and establish the health record of the optical transport network device; In the security parameter distribution process, the quantum measurement sensing module is also used to monitor the security state of the fiber transmission channel and locate the security risk event of the fiber transmission channel; After the security parameter distribution is completed, the security packaging / restoration module is also used to package and restore communication information data based on the security parameters and a preset encryption algorithm; The optical transport network device is used to transmit the packaged communication information data to a target communication node.

2. The system of claim 1, wherein, The quantum measurement sensing module is also used to: Monitor channel injection monitoring light pulse signals, and use single-photon detection technology and high-precision time resolution technology to dynamically collect physical quantities in backscattered or reflected signals; After preprocessing the collected physical quantities, extract features of different dimensions to obtain fiber channel quality characteristic indexes.

3. The system of claim 2, wherein, The quantum measurement sensing module is also used to: Monitor the security state of the fiber transmission channel based on the fiber channel quality characteristic indexes, and locate the security risk event of the fiber transmission channel.

4. The system of claim 1, wherein, When the security parameter distribution mode is a security parameter distribution mode of quantum key distribution, the quantum communication module is specifically used to: Generate security parameters using quantum key distribution technology and distribute the security parameters to each communication node; wherein the quantum key distribution technology condition at least includes: quantum key distribution transmission distance, quantum channel, quantum key distribution protocol and encoding mode, the quantum key distribution protocol at least includes: BB84 protocol of entanglement state, Gaussian modulation coherent state protocol; and the encoding mode at least includes: polarization, phase, time phase.

5. The system of claim 1, wherein, When the security parameter distribution mode is the security parameter distribution mode of QRNG combined with an encryption algorithm, the security packaging / restoration module is specifically configured to: generate the security parameter by using a quantum random number generator; perform identity authentication between the communication nodes and distribution of the security parameter based on a preset encryption algorithm protocol, wherein the preset encryption algorithm protocol at least includes a post-quantum cryptography algorithm, an SM2 algorithm, an SM3 algorithm, and an SM4 algorithm.

6. The system of claim 1, wherein, The security packaging / restoration module is further configured to: transmit uplink data of the communication information to an optical path payload unit, and perform security packaging on the communication information data in the optical path payload unit based on the security parameter, and update the OPUk payload before packaging with the OPUk payload after packaging; combine the OPUk payload after packaging and an ODU overhead to form an ODU, and map the ODU to a QOTN frame through multiplexing mapping; after the QOTN frame is transmitted to a target communication node through the optical transport network device, separate the ODU from the QOTN frame, and extract the OPUk payload from the ODU; perform security restoration on the OPUk payload based on the security parameter, and update the OPUk payload before restoration with the OPUk payload after restoration; extract the communication information data based on the OPUk payload after restoration, and transmit the communication information data to a downstream service side.

7. A communication method characterized by comprising: The quantum-enhanced optical transport network security system applied to any one of claims 1 to 6 is a hardware, software, and protocol layer integrated structure, and includes an optical transport network device and a quantum enhancement unit; the quantum enhancement unit is miniaturized and integrated into a slot of the optical transport network device, and includes a quantum communication module, a security packaging / restoration module, and a quantum measurement sensing module; and the method includes: establishing a secure channel between the communication nodes through a transmission channel, and establishing a health record of the optical transport network device through the quantum measurement sensing module, and matching a security parameter distribution mode according to a target application scenario or a transmission channel based on the health record; when the security parameter distribution mode is a quantum key distribution security parameter distribution mode, generating a security parameter through the quantum communication module and distributing the security parameter to each communication node; when the security parameter distribution mode is a QRNG combined with an encryption algorithm security parameter distribution mode, generating a security parameter through the security packaging / restoration module and distributing the security parameter to each communication node; in the security parameter distribution process, monitoring the security state of the optical fiber transmission channel through the quantum measurement sensing module, and locating a security risk event of the optical fiber transmission channel; after the security parameter distribution is completed, packaging and restoring the communication information data based on the security parameter and a preset encryption algorithm through the security packaging / restoration module; transmitting the packaged communication information data to a target communication node through the optical transport network device.

8. The communication method according to claim 7, wherein, establishing the health record of the optical transport network device through the quantum measurement sensing module, including: Adopting intelligent identification technology, the characteristic information, the security status information and the equipment identity information of the optical fiber transmission channel are identified through time-of-flight test, quantum measurement sensing, registration verification and identity authentication, and a health record of the optical transport network equipment is established.

9. The communication method according to claim 7, wherein, The security parameters are generated by the quantum communication module and distributed to each communication node, including: For the optical transmission channel meeting the quantum key distribution technology conditions, the security parameters are generated by the quantum key distribution technology and distributed to each communication node; wherein the quantum key distribution technology conditions at least include: quantum key distribution transmission distance, quantum channel, quantum key distribution protocol and encoding mode, the quantum key distribution protocol at least includes: entanglement BB84 protocol, Gaussian modulation coherent state protocol; the encoding mode at least includes: polarization, phase, time phase.

Citation Information

Patent Citations

  • Multi-node secure communication method and system based on quantum key distribution

    CN120128524A

  • Communication systems and methods

    US20210083864A1