A laser seed attack defense method, system, device and medium
By acquiring optical power and temperature data in real time, the CV-QKD system is attacked and defended using the Classification and Regression Tree (CART) algorithm. This solves the shortcomings of traditional hardware defense methods when facing complex attacks and achieves efficient laser seed attack defense.
Patent Information
- Application Number
- CN202511084480.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2045-08-04
AI Technical Summary
When facing laser seed attacks, existing CV-QKD systems are hampered by traditional hardware defenses that struggle to effectively identify and respond to complex and ever-changing attack patterns, resulting in limited system security and issues with false alarms or missed alarms.
By collecting optical power and temperature data in real time, the Classification and Regression Tree (CART) algorithm is used to segment and classify key features, identify potential attacks, determine the attack strength based on the confidence level, issue alarm signals, and take defensive actions.
It improves the system's attack detection capabilities in dynamic environments, reduces false alarms and false negatives, and can promptly identify highly concealed laser seed attacks, maintaining efficient security protection performance.
Smart Images

Figure CN120785534B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of quantum key distribution technology, specifically relating to a laser seed attack defense method, system, device, and medium. Background Technology
[0002] Quantum key distribution (QKD) technology utilizes the principles of quantum mechanics to achieve secure key distribution, and is one of the important technologies for ensuring the security of future information and communication. Among the many QKD implementation schemes, continuous variable quantum key distribution (CV-QKD) has attracted widespread attention due to its significant advantages. Compared with discrete variable quantum key distribution (DV-QKD), CV-QKD's high compatibility with standard communication optical fibers and existing detector infrastructure allows it to be integrated into existing communication networks at a lower cost. At the same time, CV-QKD has a higher key generation rate, especially performing well in short-distance communication, thus showing great potential in practical applications.
[0003] However, CV-QKD systems may face various security threats during actual deployment, particularly laser-seeding attacks. A laser-seeding attack is an attack method that injects a high-power optical signal into the system to interfere with the system's light source output and steal key information. This attack can not only lead to the manipulation of the light source and leakage of key-related information, but also cause abnormal temperature fluctuations in the system hardware, further weakening the security of the CV-QKD system. With the gradual commercialization of quantum communication technology, the stealth and destructiveness of laser-seeding attacks pose a serious threat to CV-QKD systems; therefore, defense against this type of attack has become a key issue in the field of quantum communication security.
[0004] Existing defense technologies largely rely on hardware methods, such as using optical power limiters (OPLs) to restrict the range of optical power entering the system, preventing high-power optical signals from damaging equipment. However, these traditional methods are insufficient when facing complex and ever-changing attack patterns, making it difficult to identify and respond to attacks in a timely and effective manner. In particular, when attack patterns trigger complex effects such as optical power fluctuations and system temperature changes, hardware protection methods that rely solely on fixed threshold judgments may not meet practical needs, easily leading to false alarms or missed alarms, thus limiting system security. Summary of the Invention
[0005] To overcome the shortcomings of the existing technology, the present invention provides a laser seed attack defense method, comprising the following steps:
[0006] Real-time acquisition of optical power and temperature data of the optical power limiter of the continuous variable quantum key distribution system under attack light; the temperature data is used to reflect whether there is abnormal light input or laser seed attack on the optical power limiter.
[0007] Key features of optical power and temperature data are acquired, and these key features are input into a decision tree model. A classification and regression tree algorithm is used to segment the key features into different regions. The optimal segmentation point of the key features is determined based on the features of each region. Based on the optimal segmentation point, the key features are segmented into different categories, and potential attack data in different categories is identified.
[0008] The system obtains the credibility of potential attack data, determines the attack strength of the potential attack data based on the credibility, identifies whether there is a laser seed attack signal based on the attack strength, and if so, issues an alarm signal and takes defensive action.
[0009] Preferably, before acquiring the key features of the optical power data and temperature data, the process further includes cleaning and noise reduction of the optical power data and temperature data.
[0010] Preferably, the key features include the amplitude of optical power fluctuations, the rate of temperature change, and the correlation coefficient between temperature and optical power.
[0011] Preferably, the rate of temperature change is obtained by the following formula:
[0012] ;
[0013] in, and Temperature data at adjacent time points, For time intervals.
[0014] Preferably, the correlation coefficient between temperature and optical power is determined by the following formula:
[0015] ;
[0016] in, and These are data points for temperature and optical power, respectively. and This represents the average of temperature and optical power. n It represents the number of data points.
[0017] This invention also provides a laser seed attack defense system, comprising:
[0018] The data acquisition module is used to acquire in real time the optical power data and temperature data of the optical power limiter of the continuous variable quantum key distribution system under attack light; the temperature data is used to reflect whether there is abnormal light input or laser seed attack on the optical power limiter.
[0019] The data analysis module is used to acquire key features of optical power data and temperature data, input the key features into the decision tree model, use the classification regression tree algorithm to segment the key features into different regions, determine the optimal segmentation point of the key features based on the features of each region, segment the key features into different categories based on the optimal segmentation point, and judge the potential attack data in different categories.
[0020] The defense module is used to obtain the credibility of potential attack data, determine the attack strength of the potential attack data based on the credibility, identify whether there is a laser seed attack signal based on the attack strength, and if so, issue an alarm signal and take defensive action.
[0021] The present invention also provides a computer device, characterized in that it includes a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute a laser seed attack defense method.
[0022] The present invention also provides a computer-readable storage medium storing a computer program adapted for loading by a processor to execute the laser seed attack defense method.
[0023] The laser seed attack defense method provided by this invention has the following beneficial effects:
[0024] This invention enables the system to comprehensively monitor potential attack signs by acquiring real-time optical power and temperature data. By using optical power and temperature data as input to a decision tree model, a classification regression tree algorithm is employed to segment key features into different regions. Based on the characteristics of each region, the optimal segmentation point for the key features is determined, and the input data is then segmented into different categories based on these optimal points. This process accurately distinguishes between "normal operation" and "potential attack," effectively reducing false positives and false negatives and improving the reliability and accuracy of the classification results. Furthermore, by obtaining the credibility of potential attack data and determining the attack intensity based on this credibility, the system can identify laser seed attack signals and respond defensively, thus optimizing its attack detection capabilities.
[0025] This invention overcomes the shortcomings of traditional optical power limiters in accurately detecting and responding to complex attacks. Through the efficient classification of the classification regression tree algorithm, this invention can not only identify conventional attack patterns, but also capture highly concealed laser seed attacks in a timely manner, improving the system's adaptability in dynamic environments and effectively responding to various complex attack behaviors. At the same time, it avoids the limitations of relying on fixed rules or hardware adjustments, enabling the system to maintain high-efficiency security protection performance in different application scenarios. Attached Figure Description
[0026] To more clearly illustrate the embodiments and design schemes of the present invention, the accompanying drawings required for this embodiment will be briefly described below. The drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a flowchart of a laser seed attack defense method according to an embodiment of the present invention;
[0028] Figure 2 This is a diagram showing the composition of the OPL in this invention. Detailed Implementation
[0029] To enable those skilled in the art to better understand and implement the technical solutions of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and should not be construed as limiting the scope of protection of the present invention.
[0030] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the technical solution of this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.
[0031] Furthermore, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this invention, it should be noted that, unless otherwise explicitly specified or limited, the terms "connected" or "linked" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances. In the description of this invention, unless otherwise stated, "a plurality of" means two or more, which will not be elaborated further here.
[0032] Example
[0033] This invention provides a method for defending against laser seed attacks, specifically as follows: Figure 1 As shown, the present invention also provides a method for defending against laser seed attacks, comprising the following steps:
[0034] Step 1: Real-time acquisition of optical power data and temperature data of the optical power limiter of the continuous variable quantum key distribution system under attack light; the temperature data is used to reflect whether there is abnormal light input or laser seed attack on the optical power limiter.
[0035] The optical power limiter (OPL), as a core hardware component for data acquisition, primarily limits the power of the optical signal entering the system, thereby preventing excessive optical power from damaging the optical system. In continuous-variable quantum key distribution systems, the OPL achieves dynamic power limiting through nonlinear optical effects (such as multiphoton absorption or the optical Kerr effect). The OPL not only protects the system's optical components but also provides a stable operating environment for subsequent optical power and temperature monitoring.
[0036] The optical power limiter (OPL) operates based on nonlinear optical effects. When the optical power is below a certain threshold, the optical transmittance of the OPL approaches 1, having almost no impact on the signal. When the optical power exceeds this threshold, the nonlinear properties of the material cause its absorptivity to increase significantly, limiting the power of the transmitted optical signal. This process can be expressed by the following formula:
[0037] ;
[0038] In the formula, To output optical power, For input optical power, and denoted by the nonlinear coefficient of the material. This formula describes the effect of input optical power on output optical power and limits the increase of output power through nonlinear response.
[0039] Specifically, this invention uses an optical power sensor to monitor the optical power value passing through an optical power limiter in real time, capturing instantaneous fluctuations in optical power and converting the optical signal into a digital signal for subsequent processing. The optical power sensor measures the light intensity passing through the optical power limiter using a photodetector (such as a photodiode) and converts it into a processable electrical signal. The optical power sensor uses the photoelectric effect to convert the optical signal into an electrical signal. The photodetector receives the optical signal and generates a current, the magnitude of which is proportional to the optical power. The voltage signal output by the photodetector... This can be represented by the following relationship:
[0040] ;
[0041] in, The sensitivity of the photodetector. This represents the incident light power.
[0042] The OPL of the present invention is as follows Figure 2 As shown (only the main components are shown), the OPL consists of two collimators, a temperature monitor, an optical power detector, a small aperture, and an acrylic prism.
[0043] A collimator is an optical device used to transform a beam of light or a stream of particles from a scattered state to a parallel state. Its function in optical systems, especially in laser and fiber optic communication, is to ensure the directionality and focusing quality of light. An aperture is generally a component in an optical system used to limit the passage of light. A small aperture, as one type, typically refers to a small aperture and can be used to control light intensity by limiting the amount of light entering the system. Acrylic prisms have a structure similar to traditional glass prisms, typically being a transparent triangular or polygonal optical element. In laser applications, acrylic prisms can be used to adjust the propagation path of a laser beam or change its direction.
[0044] An attacker's beam enters the acrylic prism through the left collimator. The light diffuses and propagates within the prism. A small aperture is placed on the right side of the prism to ensure that only a small portion of the light can pass through and is ultimately collected by the right collimator and received by the receiver. The acrylic prism acts as an active medium, playing a crucial role in power limiting. When the prism absorbs energy and generates an internal temperature gradient, the incident beam diverges due to thermal defocusing. Therefore, if an attacker launches a high-power laser injection attack, the temperature of the acrylic prism will rise sharply. To detect such attacks, a temperature sensor is placed around the acrylic prism to record real-time temperature changes. Once the temperature exceeds room temperature, a signal is triggered to stop the CV-QKD laser to prevent information leakage. Furthermore, when the injected light power exceeds 4W, the acrylic prism will dissolve, reaching a maximum temperature of approximately 50 degrees Celsius. After dissolution, the acrylic prism blocks light transmission. Therefore, other devices in the CV-QKD system can be protected by sacrificing one acrylic prism.
[0045] The temperature monitor of this invention can detect the surface temperature and internal thermal effects of an optical power limiter, capture temperature changes caused by optical power fluctuations, and record temperature fluctuation curves. Temperature changes can reflect the presence of abnormal optical power input or laser seed attacks within the system. The temperature monitor can monitor temperature changes in real time and provide auxiliary information for attack detection. The temperature monitor of this invention typically uses thermocouples or temperature sensors (such as RTD sensors) to measure temperature changes. The temperature sensor converts temperature changes into electrical signals, which are linearly related to the temperature change. The output signal of the temperature sensor... This can be represented by the following relationship:
[0046] ;
[0047] in, For output voltage, For the sensitivity of the temperature sensor, This refers to the change in temperature. Temperature sensors can accurately monitor temperature changes caused by fluctuations in optical power, providing necessary thermal effect data for subsequent analysis.
[0048] Step 2: Data preprocessing.
[0049] (1) Data cleaning.
[0050] The collected data is processed to remove invalid data, outliers, and sensor errors, ensuring that subsequent processing is based on accurate data. Data cleaning effectively removes abnormal data caused by environmental interference, sensor malfunctions, or other abnormal reasons, thus guaranteeing data quality. If the deviation of a data point exceeds a preset threshold (e.g., twice the standard deviation), the data is considered an outlier and needs to be removed.
[0051] (2) Data noise reduction.
[0052] By employing a smoothing filtering algorithm, random noise and high-frequency interference in optical power and temperature data are reduced. Data generated by many sensors is affected by environmental factors (such as temperature changes and electronic interference), resulting in unwanted noise. This section aims to retain useful information from the data while removing interfering signals that are not beneficial for classification and analysis.
[0053] Moving Average Filter: This filter smooths data by taking the average of a sliding window of data points, thus eliminating noise from sudden changes.
[0054] ;
[0055] in, These are the smoothed data points. These are the original data points. It refers to the window size.
[0056] (3) Feature extraction.
[0057] The most critical features for subsequent classification analysis are extracted from the cleaned and denoised data. These features include, but are not limited to, the amplitude of optical power fluctuations, the rate of temperature change, and the correlation between temperature and optical power. The quality of feature extraction directly affects the effectiveness of subsequent attack detection and defense strategies.
[0058] The rate of temperature change is obtained by calculating the amount of temperature change between adjacent time points. A common calculation method is as follows:
[0059] ;
[0060] in, and Temperature data at adjacent time points, For time intervals.
[0061] The correlation coefficient between temperature data and optical power data is calculated to analyze their mutual influence. (Correlation coefficient) It can be calculated using Pearson's relevant formula:
[0062] ;
[0063] in, and These are data points for temperature and optical power, respectively. and This represents the average of temperature and optical power. n
[0064] This represents the number of data points.
[0065] (4) Data formatting.
[0066] The extracted feature data is standardized to ensure that it meets the input requirements of the subsequent decision tree model. Through data normalization and other methods, feature data of different scales and dimensions are converted into a standard format suitable for machine learning models to ensure data compatibility and efficient analysis.
[0067] Normalization: Transforms data linearly into a uniform range (usually between 0 and 1), specifically achieved by the following formula:
[0068] ;
[0069] in, It is the raw data. and These are the minimum and maximum values of the data, respectively.
[0070] Step 3: Obtain key features of optical power data and temperature data, input the key features into the decision tree model, use the classification regression tree algorithm to segment the key features into different regions, determine the optimal segmentation point of the key features based on the features of each region, segment the key features into different categories based on the optimal segmentation point, and judge the potential attack data in different categories.
[0071] (1) Data input.
[0072] By performing necessary standardization on the cleaned and denoised data, the data is limited to a specific range (such as between 0 and 1), thereby avoiding model bias caused by differences in the dimensions of certain features.
[0073] (2) Classification and processing.
[0074] Classification is the core of this invention. Its main task is to analyze the provided feature data using the Classification and Regression Trees (CART) algorithm and classify the data as either "normal operation" or "potential attack." By using the hierarchical decision rules of the CART algorithm, the feature data is matched with the classification model, outputting the classification result. Its working principle is based on the construction of a decision tree model, determining the category of the data layer by layer, and finally outputting the decision result.
[0075] The CART algorithm is a tree-structured machine learning method widely used in classification and regression problems. In classification, the CART algorithm divides the data into different regions and outputs a corresponding class label based on the features of each region. The main goal of the CART algorithm is to find the optimal split point using feature data and determine the class of the data based on the feature values.
[0076] The CART algorithm constructs a binary tree structure recursively. Each node partitions the dataset based on the value of a certain feature until a leaf node is reached, which represents the final class of the data. Each decision node at each level selects an optimal feature for data partitioning, ensuring that the resulting dataset is as class-pure as possible.
[0077] In CART, each node splits based on a specific feature's split point, with the goal of maximizing purity after each split. Commonly used metrics for purity are Gini impurity and information gain.
[0078] Gini impurity is a commonly used metric for measuring the purity of a dataset. Its formula is:
[0079] ;
[0080] in, It is the first The proportion of samples of each class It is the total number of categories. It is a dataset. If the dataset is pure (i.e., all samples belong to the same class), the Gini impurity is 0; if the classes in the dataset are uniformly distributed, the Gini impurity is maximum.
[0081] At each split point, CART selects a feature and a split point that minimizes the Gini impurity of the dataset for data partitioning. Specifically, at each node, the algorithm chooses a feature and a threshold that minimizes the weighted sum of the Gini impurities of the resulting subsets.
[0082] Information gain measures how a feature's split improves the classification purity of a dataset. A higher information gain indicates that the feature is more helpful for classification. The formula for information gain is as follows:
[0083] ;
[0084] in, Represents the dataset Information entropy It is a feature The set of possible values, It is a feature A subset of data when a specific value is taken. and They are subsets and dataset The size of the feature. By selecting the feature with the maximum information gain, the CART algorithm can effectively reduce uncertainty, thereby improving classification accuracy.
[0085] In building a decision tree model, the CART algorithm starts from the root node and gradually forms a tree structure by splitting the dataset at each level. Each split is based on the features of the current dataset, until a stopping condition is met. The stopping condition can be reaching a preset maximum tree depth, the data at the current node being completely pure, or the purity of the dataset splitting cannot be further improved. After the decision tree model is built, it traverses down the tree path according to the feature values of the new data until a leaf node is reached. The class label of the leaf node is the classification result of that data. The final classification result will output "normal operation" or "potential attack" based on the model's prediction.
[0086] Step 4: Obtain the credibility of potential attack data, determine the attack strength of potential attack data based on the credibility, identify whether there is a laser seed attack signal based on the attack strength, and if so, issue an alarm signal and take defensive action.
[0087] (1) Credibility calculation.
[0088] Credibility calculations are typically based on the model's output probabilities. Each leaf node of the CART algorithm not only provides a class but also a probability for that class. Credibility calculations use these probabilities to evaluate the reliability of the classification. For example, when the probability of the classification result is close to 1, the credibility is high; when the probability is close to 0.5, the credibility is low, and further verification or manual intervention may be needed.
[0089] (2) Analysis of classification results.
[0090] The analysis is based on the classification results (such as "normal operation" or "potential attack") and confidence scores output by the CART algorithm. In the CART algorithm, the prediction for each data point includes not only the classification result but also a confidence index, representing the confidence level of that result. This confidence index is used to evaluate the reliability of the classification result, thereby determining whether further processing is needed. For example, assuming the classification result is "potential attack" with a confidence level of 0.85 (meaning the confidence level of the classification result is 85%), a threshold is used to determine whether the result is strong enough to confirm a potential attack.
[0091] (3) Attack pattern identification.
[0092] Based on historical attack data and characteristic patterns, combined with current data, specific algorithms (such as cluster analysis and association rule mining) are used for comparative analysis. By identifying patterns in features such as optical power fluctuation amplitude, temperature change rate, and the correlation between optical power and temperature, different attack patterns can be identified. For example, when optical power and temperature characteristics show abrupt changes and continuous fluctuations, this can be identified as a sign of a "laser seed attack," and the attack type can be verified by combining confidence indicators.
[0093] (4) Attack confirmed.
[0094] The final judgment is made based on the output of the attack pattern recognition module to confirm whether an attack has occurred and to determine whether a response mechanism needs to be triggered.
[0095] (5) Dynamic adjustment.
[0096] By acquiring attack signals and their intensity in real time, the sensitivity of temperature monitoring is adjusted based on the rate of change of optical power and temperature, as well as the credibility of the attack signals. For example, when abnormal fluctuations in optical power or temperature change rate are detected, and the credibility of the attack signal is high, the sensitivity of the temperature sensor can be increased to more acutely respond to potential attacks. Specific adjustment methods may include:
[0097] Increase sensitivity by dynamically adjusting the temperature sensor's sensitivity when the attack signal strength is high, thus enabling more sensitive detection of minute temperature changes. Reduce sensitivity when the system returns to normal to avoid over-responding to environmental changes. Temperature sensor sensitivity adjustment is typically based on the following feedback mechanism:
[0098] ;
[0099] in, and These are the adjusted and current sensitivity values, respectively. It is an adjustment factor. It represents the strength of the attack signal, indicating the severity of the attack.
[0100] (5) Alarm response.
[0101] When a high-intensity or high-confidence attack signal is detected, an alarm signal is issued to remind operators to intervene in a timely manner. Multiple methods, including sound, light, and remote notification, are used to ensure a rapid response to attack signals and to provide clear warnings when the system faces a major security threat.
[0102] (6) Parameter recovery.
[0103] After the attack disappears, based on the attack disappearance signal provided by the attack detection module, the temperature monitoring sensitivity is gradually restored to a preset normal range. This restoration is usually based on time series or feedback mechanisms to ensure that the temperature sensor sensitivity is not over-adjusted and affects system performance. The mathematical model of the restoration process can be expressed as:
[0104] ;
[0105] in, For the restored sensitivity, For the current sensitivity, For recovery rate, This indicates the attack duration. As the attack duration decreases, the sensitivity gradually returns to its original state.
[0106] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
[0107] This invention also provides a laser seed attack defense system, comprising:
[0108] The data acquisition module is used to acquire in real time the optical power data and temperature data of the optical power limiter of the continuous variable quantum key distribution system under attack light; the temperature data is used to reflect whether there is abnormal light input or laser seed attack on the optical power limiter.
[0109] The data analysis module is used to acquire key features of optical power data and temperature data, input the key features into the decision tree model, use the classification regression tree algorithm to segment the key features into different regions, determine the optimal segmentation point of the key features based on the features of each region, segment the key features into different categories based on the optimal segmentation point, and judge the potential attack data in different categories.
[0110] The defense module is used to obtain the credibility of potential attack data, determine the attack strength of the potential attack data based on the credibility, identify whether there is a laser seed attack signal based on the attack strength, and if so, issue an alarm signal and take defensive action.
[0111] The present invention also provides a computer device, characterized in that it includes a memory and a processor; the memory stores a computer program, and the processor is used to run the computer program in the memory to execute a laser seed attack defense method.
[0112] The present invention also provides a computer-readable storage medium storing a computer program adapted for loading by a processor to execute the laser seed attack defense method.
[0113] The above-described embodiments are merely preferred embodiments of the present invention, and the scope of protection of the present invention is not limited thereto. Any simple changes or equivalent substitutions of the technical solutions that can be obviously obtained by those skilled in the art within the scope of the technology disclosed in the present invention shall fall within the scope of protection of the present invention.
Claims
1. A laser seed attack defense method, characterized by, The method comprises the following steps: Real-time acquisition of optical power data and temperature data of an optical power limiter of a continuous variable quantum key distribution system under attack light; the temperature data is used to reflect whether the optical power limiter is subjected to abnormal light input or laser seed attack; Obtaining key features of the optical power data and the temperature data, inputting the key features into a decision tree model, segmenting the key features into different regions by using a classification and regression tree algorithm, determining the best segmentation point of the key features according to the features of each region, segmenting the key features into different categories according to the best segmentation point, and judging potential attack data in different categories; Obtaining the credibility of the potential attack data, determining the attack strength of the potential attack data according to the credibility, identifying whether there is a laser seed attack signal according to the attack strength, and if there is, issuing an alarm signal and making a defense response.
2. The laser seed attack defense method of claim 1, wherein, Before the key features of the optical power data and the temperature data are obtained, the optical power data and the temperature data are subjected to cleaning and noise reduction processing.
3. The laser seed attack defense method of claim 2, wherein, The key features include the amplitude of optical power fluctuation, the rate of temperature change, and the correlation coefficient between temperature and optical power.
4. The laser seed attack defense method of claim 3, wherein, The rate of temperature change is obtained by the following formula: ; wherein and is temperature data of adjacent time points, is a time interval.
5. The laser seed attack defense method of claim 3, wherein, The correlation coefficient between temperature and optical power is determined by the following formula: ; wherein, and are the temperature and optical power data points, respectively, and are the mean values of temperature and optical power, respectively, n is the number of data points.
6. A laser seed attack defense system characterized by, It comprises: A data acquisition module is configured to acquire optical power data and temperature data of an optical power limiter of a continuous variable quantum key distribution system under attack light in real time; the temperature data is used to reflect whether the optical power limiter is subjected to abnormal light input or laser seed attack; A data analysis module is configured to obtain key features of the optical power data and the temperature data, input the key features into a decision tree model, segment the key features into different regions by using a classification and regression tree algorithm, determine the best segmentation point of the key features according to the features of each region, segment the key features into different categories according to the best segmentation point, and judge potential attack data in different categories; A defense module is configured to obtain the credibility of the potential attack data, determine the attack strength of the potential attack data according to the credibility, identify whether there is a laser seed attack signal according to the attack strength, and if there is, issue an alarm signal and make a defense response.
7. A computer device, comprising: It comprises a memory and a processor; the memory stores a computer program, and the processor is configured to run the computer program in the memory to execute the laser seed attack defense method of any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is adapted to be loaded by the processor to execute the laser seed attack defense method of any one of claims 1-5.
Citation Information
Patent Citations
Continuous variable quantum key distribution method and system based on free space channel
CN120223308A
Hardening of direct anonymous attestation from side-channel attack
US20140095883A1