A centralized quantum key relay network and key distribution method
By employing quantum security mechanisms and dynamic path selection, combined with multi-level verification, the security and efficiency issues of quantum key relay networks have been resolved, achieving efficient key transmission and automatic fault recovery.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ANHUI POLYTECHNIC UNIV
- Filing Date
- 2025-08-26
- Publication Date
- 2026-05-19
AI Technical Summary
Existing quantum key relay networks face challenges such as compromised security of traditional encryption algorithms, inflexible path selection, low efficiency in dynamic environments, and reliance on manual intervention for fault recovery.
Employing quantum security mechanisms, dynamic path selection, and multi-level verification, combined with quantum time synchronization protocols and multi-factor scoring models, dynamic path planning and automatic fault recovery are achieved.
It improves the security and timeliness of the system, ensures the integrity and reliability of key transmission, and enhances the network's self-recovery and fault tolerance capabilities.
Smart Images

Figure CN120811600B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum communication technology, and in particular to a centralized quantum key relay network and key distribution method. Background Technology
[0002] Quantum cryptography, particularly quantum key distribution networks (QKDNs) based on quantum key distribution protocols, has experienced rapid development in recent years. Compared to traditional classical cryptography, the core advantage of quantum cryptography lies in its foundation in quantum mechanics, especially the Heisenberg uncertainty principle and the no-cloning theorem. These quantum physical properties ensure unconditional security in the long-distance secure negotiation of symmetric keys. Even if the advent of quantum computers poses a potential threat to traditional encryption methods, quantum key distribution can still guarantee data security.
[0003] Multiple quantum key distribution nodes (QKD nodes) can form a quantum key distribution network (QKDN). A QKDN establishes a quantum-secure communication environment by sharing quantum keys among multiple nodes, ensuring that key exchange between different communicating parties is secure and cannot be intercepted. However, due to the finite distance between adjacent QKD nodes, the ability to directly connect and distribute keys is constrained by geographical distance. This necessitates the use of relay mechanisms to extend the network's coverage and communication capabilities in long-distance key generation and large-scale quantum communication.
[0004] To address the distance limitations in long-distance key generation, centralized quantum key relay networks (CQKRNs) have emerged. In such networks, the QKDN controller is responsible for coordinating and managing the key information reported by all relay nodes. Through the coordinated action of multiple relay nodes, quantum keys can be distributed over a wider area, enabling large-scale quantum communication. Specifically, the QKDN controller uses the key information collected by the relay nodes to generate the final shared key, thereby facilitating secure communication between the nodes.
[0005] Despite significant progress made by centralized quantum key relay networks in improving the coverage and transmission capacity of quantum communication networks, existing technologies still face several key challenges in practical applications:
[0006] (1) In the existing quantum key distribution process, the key distribution network usually relies on traditional classical encryption algorithms to further protect the key transmission process. However, with the development of quantum computing technology, the security of classical encryption algorithms has been seriously threatened. Quantum computing can effectively crack these traditional algorithms, making it impossible to ensure the long-term security of quantum key transmission.
[0007] (2) Current quantum key relay network path planning usually relies on the shortest path or fixed path selection strategy. In a dynamic environment, when the network state changes, the fixed path selection cannot flexibly adapt to the changes in network conditions, resulting in low path selection efficiency and failing to meet the requirements of high timeliness.
[0008] (3) When a network failure occurs, there is often a lack of effective automatic recovery mechanisms. Especially when encountering relay node or communication path failures, current systems often require manual intervention to repair the failure, resulting in interruption or delay in key transmission, which seriously affects the timeliness and security of key distribution. Therefore, this invention proposes a centralized quantum key relay network and key distribution method to solve the problems existing in the prior art. Summary of the Invention
[0009] To address the aforementioned problems, the present invention aims to propose a centralized quantum key relay network and key distribution method. This centralized quantum key relay network and key distribution method integrates quantum security mechanisms, dynamic path selection, and multi-level verification, and can solve the problems existing in the prior art.
[0010] To achieve the objectives of this invention, the invention is implemented through the following technical solution: a centralized quantum key relay network and key distribution method, comprising the following steps:
[0011] Step 1: Relay Request Initiation and Requirements Analysis
[0012] The request-initiating node sends a relay request based on the timeliness level and selects the signature method. The relay request includes the destination node ID, key quantity, and quantization delay index. After the controller verifies the signature, it parses and binds the level label to generate a unique request ID. This unique request ID includes the controller number, quantum timestamp, and request feature hash value.
[0013] Step 2: Path Constraints and Decisions
[0014] The controller loads request details based on the unique request ID and collects the node trust authentication level, quantum link bit error rate and throughput data of each candidate path in real time. After calibrating the entire network clock through the quantum time synchronization protocol, the paths are ranked according to the multi-factor dynamic model score. The path with the highest score and meeting the time window is selected as the optimal relay path, and an elastic target time window is generated. Finally, the unique request ID, the optimal relay path and the elastic target time window are input into the quantum-resistant hash function, and the spatiotemporal constraint path unique ID with the controller's digital signature is output and returned to the request initiating node.
[0015] Step 3: Collaborative Key Generation and Verification
[0016] The controller sends key generation instructions to all relay nodes involved in the spatiotemporal constraint path. The relay nodes generate keys in real time, obtaining multiple key segments. Each key segment is appended with a quantum-safe MAC checksum, and then encapsulated to obtain a key packet, which is returned to the controller. After the controller receives the key packets from all relay nodes in the path, it performs three-level verification. After the verification is successful, the unique ID of the spatiotemporal constraint path is concatenated with all key segments in sequence to form the final relay key. This key is then encrypted using a quantum key encapsulation protocol and distributed to the request initiating node and the destination node. The two nodes then begin subsequent communication.
[0017] Step 4: Monitoring and Processing During Transmission
[0018] The controller tracks each active path based on the unique ID of the spatiotemporal constraint path and collects relevant indicator data in real time. This relevant indicator data includes the quantum bit error rate, key stream throughput fluctuation value, and node response latency jitter. A dynamic circuit breaker threshold is set in advance according to the request timeliness level. When any indicator data exceeds the threshold, the current key stream transmission is immediately frozen and the backup path is used for transmission.
[0019] A further improvement is made in the following: In step one, the timeliness level is divided into low level, medium level and high level, where the low level and medium level adopt the quantum-safe HMAC signature mechanism, and the high level adopts the post-quantum digital signature mechanism.
[0020] A further improvement is that, in step one, the quantification latency indicators include the maximum allowed latency, the minimum key quantity guarantee, and the node hop limit.
[0021] A further improvement is that, in step one, high-level time-sensitive requests are scheduled first, while when requests of the same level are encountered, they are sorted according to the time order of the quantum timestamp.
[0022] A further improvement lies in the following: In step two, the multi-factor dynamic scoring model is as follows:
[0023] Path score = Trustworthy authentication level × Link quality coefficient + Timeliness level weight × (1 - Real-time quantum error rate).
[0024] A further improvement is made in step two, where the two highest-rated paths from the remaining paths are selected as backup paths of the same level.
[0025] A further improvement is that in step three, the real-time key generation is achieved by generating the original key through a quantum random number generator and dividing it into multiple key segments according to the required path length.
[0026] The further improvement lies in the fact that, in step three, the three-level verification includes single-packet verification, cross-pool consistency verification, and path integrity verification.
[0027] A further improvement is made in step four, where if the backup path fails twice in a row, the quantum-safe backtracking protocol is triggered to send a quantum erasure command to all nodes on the path, physically destroy the untransmitted key segments, release the relevant key pool marker resources, and then record the topological black spots.
[0028] The beneficial effects of this invention are as follows:
[0029] (1) This invention significantly improves the security of the system in the face of quantum computing threats by using quantum digital signature, quantum secure MAC check code and post-quantum cryptographic signature mechanism. At the same time, it adopts dynamic path selection that combines timeliness level, multi-factor dynamic scoring model and flexible target time window. It can dynamically adjust the optimal path and target time according to the timeliness requirements of the request, path conditions and network status, making path selection more flexible and meeting different timeliness requirements.
[0030] (2) By adopting a three-level verification method, the present invention ensures the integrity and legality of the key, greatly reduces the risk of key tampering or damage during transmission, improves the reliability of key generation and transmission, and can respond quickly when network failure occurs, automatically switch to backup paths and effectively isolate problem nodes, thereby improving the fault tolerance and self-recovery capability of the system. Attached Figure Description
[0031] Figure 1 This is a schematic diagram of the method flow of the present invention. Detailed Implementation
[0032] To enhance understanding of the present invention, the present invention will be further described in detail below with reference to embodiments. These embodiments are only used to explain the present invention and do not constitute a limitation on the scope of protection of the present invention.
[0033] according to Figure 1 As shown, this embodiment proposes a centralized quantum key relay network and key distribution method, including the following steps:
[0034] Step 1: Relay Request Initiation and Requirements Analysis
[0035] The request initiating node generates a relay request based on specific communication needs and timeliness requirements. The request includes the destination node ID, key quantity, and quantized latency metrics. The destination node ID represents the target communication node, the key quantity defines the number of quantum keys required for the relay request, and the quantized latency metrics include the maximum allowed latency (representing the maximum time delay during key transmission), the minimum key quantity guarantee (defining the minimum key quantity that must be guaranteed to ensure key security and sufficiency), and the node hop limit (limiting the maximum number of relay nodes allowed on the request path to avoid latency and complexity caused by excessive hops). Timeliness levels are categorized as low, medium, and high. Low and medium levels use a quantum-safe HMAC (Hash Message Authentication Code) signature mechanism, while the high level uses a post-quantum digital signature mechanism (based on the Lattice signature scheme) to provide higher security.
[0036] The controller verifies the request signature using the corresponding public key to ensure the authenticity of the request source and the integrity of the data. Then, it parses and binds the level label, as shown in Table 1 below:
[0037] Table 1 Quantitative Indicator Binding
[0038] Timeliness level Maximum allowable delay Minimum key size guarantee Node hop limit high ≤50ms ≥1Mbps ≤3 middle ≤200ms ≥100kbps ≤5 Low ≤1s ≥10kbps No limit
[0039] This generates a unique ID, which includes a controller number (identifying the controller currently processing the request), a quantum timestamp (ensuring that the timestamp of each request is unique and can be synchronized with the network clock to guarantee the time order of requests), and a request feature hash value (a hash operation is performed on the request content to ensure that the characteristics of the request can be uniquely identified and tracked), thus effectively avoiding ID conflicts.
[0040] Furthermore, based on the timeliness level in the relay request, the controller prioritizes the requests. For high-level timeliness requests, the controller will process them first to ensure that key distribution can be completed within the required time. When encountering requests of the same level, the controller sorts them according to the quantum timestamp in the request, and the earlier the timestamp, the higher the priority is given to avoid fairness issues in request processing.
[0041] Step 2: Path Constraints and Decisions
[0042] The controller loads request details based on the unique request ID and collects node trust authentication level, quantum link bit error rate and throughput data for each candidate path in real time. The node trust authentication level refers to the security and trustworthiness of each node, the quantum link bit error rate refers to the bit error rate in the quantum communication link, which affects the reliability of the key, and the throughput data refers to the transmission rate of the path, which affects the timeliness.
[0043] Then, the entire network clock is calibrated using a quantum time synchronization protocol to ensure that the time synchronization error between nodes is less than 1μs, ensuring that key loss or delay will not occur due to time asynchrony in requests with high timeliness requirements.
[0044] Then, sort the results according to the multi-factor dynamic model scoring path, where the multi-factor dynamic scoring model is as follows:
[0045] Path score = Trustworthy authentication level × Link quality coefficient + Timeliness level weight × (1 - Real-time quantum error rate)
[0046] In the formula, the trusted authentication level is the security authentication level of the node, and a higher authentication level will receive a higher score; the link quality coefficient is the quality of the quantum link, which is usually inversely proportional to the throughput and bit error rate. The higher the link quality, the higher the score; the timeliness level weight is a weighted average based on the timeliness level of the request, and requests with a high timeliness level will be given a higher weight; the real-time quantum bit error rate is the real-time bit error rate of the quantum link. The lower the bit error rate, the higher the score.
[0047] Therefore, based on the path score, the candidate paths are sorted, and the path with the highest score that can meet the timeliness requirements of the request is selected as the optimal relay path. From the remaining paths, the two paths with the highest scores are selected as backup paths of the same level.
[0048] The elastic target time window is then regenerated. The center point of the elastic target time window is determined by the theoretical transmission time, which is calculated based on the network latency and throughput of the selected path. The window width is equal to the timeliness level × the dynamic network jitter coefficient. The timeliness level is the timeliness level of the request, and the timeliness window is narrower for higher-level requests. The dynamic network jitter coefficient is a coefficient that is dynamically adjusted based on the current network load and uncertainty to ensure the flexibility of the target time under network fluctuations.
[0049] Therefore, the calculation of the elastic target time window ensures that key transmission can still be completed within a reasonable time range even under fluctuating network conditions.
[0050] The request unique ID, optimal relay path, and flexible target time window are then input into the quantum-resistant hash function (SHA-3), which outputs the spatiotemporal constraint path unique ID with the controller's digital signature and returns it to the request initiating node.
[0051] Step 3: Collaborative Key Generation and Verification
[0052] The controller sends a key generation command to all relay nodes involved in the spatiotemporal constraint path. This command includes the unique ID of the spatiotemporal constraint path and its bound sequence of path nodes (the order of each node in the relay path to ensure path consistency during relaying), and a target time window (the time range set for the generated key to ensure that key generation meets timeliness requirements). The relay nodes perform real-time key generation within the target time window. Specifically, they use a quantum random number generator to generate the original key and divide it into multiple key segments according to the required path length. Furthermore, a quantum-safe MAC checksum is appended to each key segment to ensure the integrity and legitimacy of the key. These segments are then encapsulated to obtain a key packet with the following format: key segment + quantum-safe MAC + generation timestamp + real-time error rate.
[0053] The key packet is returned to the controller. After the controller receives the key packets from all relay nodes along the path, it performs three levels of verification: single packet verification, cross-pool consistency verification, and path integrity verification. Single packet verification uses a pre-shared quantum key to check the MAC validity of each key segment, ensuring that the key segments generated by each relay node have not been tampered with. Cross-pool consistency verification verifies whether the generation timestamp deviation of all key segments within the same time window is within 1μs, ensuring the time synchronization of each node. Path integrity verification checks whether the number of key segments in each key packet is consistent with the number of hops in the path nodes.
[0054] Once the Level 3 verification is successful, the controller will concatenate the unique ID of the spatiotemporal constraint path with all key segments in sequence to form the final relay key, and then encrypt it using the quantum key encapsulation protocol. After encryption, the key is distributed to the request initiating node and the destination node, and the two nodes will then conduct subsequent communication interactions.
[0055] Step 4: Monitoring and Processing During Transmission
[0056] The controller tracks each active path based on the unique ID of the spatiotemporal constraint path and collects relevant indicator data in real time. This relevant indicator data includes the qubit error rate, key stream throughput fluctuation value, and node response delay jitter. Among them, the qubit error rate is the bit error rate in the quantum link, which directly affects the correctness and reliability of the key; the key stream throughput fluctuation value is the change in the throughput of the quantum key stream. Excessive fluctuation may indicate link instability or network congestion; the node response delay jitter is the fluctuation in the response time of each node. Excessive jitter will affect the timeliness and lead to an increase in the delay of key transmission.
[0057] The dynamic circuit breaker threshold is pre-set based on the request timeliness level, as shown in Table 2 below:
[0058] Table 2
[0059] Timeliness level Error rate threshold Fluctuation threshold jitter threshold high ≤0.5% ≤3% ≤5μs middle ≤1.2% ≤8% ≤20μs Low ≤2.5% ≤15% ≤100μs
[0060] When any indicator data exceeds the threshold, the current key stream transmission is immediately frozen, and backup paths (two have been selected in step two) are activated for transmission. When a backup path fails twice consecutively (i.e., both backup paths fail consecutively), the quantum-secure backtracking protocol is triggered, sending a quantum erasure command to all nodes on the path to physically destroy untransmitted key segments, ensuring system security, preventing the further propagation of erroneous or invalid keys, and releasing relevant key pool marking resources to ensure that these resources are not mistakenly marked as used or valid. Then, topological black spots are recorded, i.e., the path nodes that have failed are marked. Furthermore, nodes that fail three times will be suspended from scheduling to prevent these nodes from being used as relay paths again, reducing potential risks in the system.
[0061] Accordingly, the controller will recalculate the optimal path to ensure that faults in the network do not propagate and to guarantee the stability of the system.
[0062] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the present invention without departing from its framework and scope of application, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. A centralized quantum key relay network and key distribution method, characterized in that: Includes the following steps: Step 1: Relay Request Initiation and Requirements Analysis The request-initiating node sends a relay request based on the timeliness level and selects the signature method. The relay request includes the destination node ID, key quantity, and quantization delay index. After the controller verifies the signature, it parses and binds the level label to generate a unique request ID. This unique request ID includes the controller number, quantum timestamp, and request feature hash value. Step 2: Path Constraints and Decisions The controller loads request details based on the unique request ID and collects real-time node trust authentication levels, quantum link bit error rate, and throughput data for each candidate path. After calibrating the entire network clock using a quantum time synchronization protocol, the paths are ranked according to a multi-factor dynamic scoring model. The path with the highest score and meeting the timeliness window is selected as the optimal relay path, and a flexible target time window is generated. The center point of the flexible target time window is determined by the theoretical transmission time, and the window width is determined by the product of the timeliness level and the dynamic network jitter coefficient. Finally, the unique request ID, the optimal relay path, and the flexible target time window are input into a quantum-resistant hash function, and the spatiotemporal constrained path unique ID with the controller's digital signature is output and returned to the request initiating node. In step two, the multi-factor dynamic scoring model is as follows: Path score = Trustworthy authentication level × Link quality coefficient + Timeliness level weight × (1 - Real-time quantum error rate) In the formula, the trusted authentication level is the security authentication level of the node, the link quality coefficient represents the quality of the quantum link, and its value is inversely proportional to the throughput and bit error rate. The timeliness level weight is determined according to the timeliness level of the request, and the real-time quantum bit error rate is the real-time bit error rate of the quantum link. Step 3: Collaborative Key Generation and Verification The controller sends key generation instructions to all relay nodes involved in the spatiotemporal constraint path. The relay nodes generate keys in real time, obtaining multiple key segments. Each key segment is appended with a quantum-safe MAC checksum, and then encapsulated to obtain a key packet, which is returned to the controller. After the controller receives the key packets from all relay nodes in the path, it performs three-level verification. After the verification is successful, the unique ID of the spatiotemporal constraint path is concatenated with all key segments in sequence to form the final relay key. This key is then encrypted using a quantum key encapsulation protocol and distributed to the request initiating node and the destination node. The two nodes then begin subsequent communication. Step 4: Monitoring and Processing During Transmission The controller tracks each active path based on the unique ID of the spatiotemporal constraint path and collects relevant indicator data in real time. This relevant indicator data includes the quantum bit error rate, key stream throughput fluctuation value, and node response latency jitter. A dynamic circuit breaker threshold is set in advance according to the request timeliness level. When any indicator data exceeds the threshold, the current key stream transmission is immediately frozen and the backup path is used for transmission.
2. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step one, the timeliness level is divided into low level, medium level and high level. The low level and medium level adopt the quantum-safe HMAC signature mechanism, while the high level adopts the post-quantum digital signature mechanism.
3. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step one, the quantification latency metrics include the maximum allowed latency, minimum key quantity guarantee, and node hop limit.
4. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step one, high-priority timeliness requests are scheduled first, while when requests of the same level are encountered, they are sorted according to the time order of the quantum timestamp.
5. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step two, the two highest-rated paths are selected from the remaining paths as backup paths of the same level.
6. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step three, real-time key generation involves generating the original key using a quantum random number generator and then dividing it into multiple key segments according to the required path length.
7. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step three, the three-level verification includes single-packet verification, cross-pool consistency verification, and path integrity verification.
8. The centralized quantum key relay network and key distribution method according to claim 1, characterized in that: In step four, if the backup path fails twice in a row, the quantum-safe backtracking protocol is triggered, a quantum erasure command is sent to all nodes of the path, the untransmitted key segments are physically destroyed, the relevant key pool marker resources are released, and then the topological black spots are recorded.