Distributed network security protection system integrating quantum-safe gateway VPN

The distributed network security protection system of the quantum security gateway VPN generates an unbreakable quantum key sequence, constructs a secure tunnel path, detects and dynamically generates security policies, and solves the security and efficiency problems of traditional network security protection systems under quantum computing and complex attacks, thus achieving efficient network threat management.

CN120811760BActive Publication Date: 2025-11-14HEFEI GUOXIN STAR SHIELD QUANTUM TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511254750.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-04
Publication Date
2025-11-14
Estimated Expiration
2045-09-04

AI Technical Summary

Technical Problem

Traditional network security protection systems struggle to provide effective security against quantum computing threats and complex network attacks, especially given the risk of key generation and transmission being compromised, and their inefficiency in threat detection and strategy development.

Method used

A distributed network security protection system that integrates a quantum security gateway VPN generates quantum key sequences through a quantum key distribution module, constructs a VPN tunnel path structure, analyzes node intersections and abnormal node frequencies through a threat detection module, dynamically generates security policy label groups, and establishes a network security protection structure table through a protection output module.

Benefits of technology

It achieves the unbreakability of quantum keys, improves the security of VPN tunnels and the accuracy of threat detection, dynamically generates highly targeted security policies, and improves the efficiency and convenience of security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811760B_ABST
    Figure CN120811760B_ABST
Patent Text Reader

Abstract

This invention relates to the field of network security protection technology and discloses a distributed network security protection system integrating a quantum-secure gateway VPN. The system includes a quantum key distribution module that acquires network traffic data and generates a quantum key sequence through quantum key distribution processing; a VPN tunnel construction module that sorts the quantum keys accordingly and constructs a VPN tunnel path structure; a threat detection module that extracts the tunnel path node sequence, filters threat paths by comparing node intersections and statistically analyzing the frequency of abnormal nodes, and obtains a set of potential threats; a security policy determination module that collects security tags of abnormal nodes, sorts them by frequency, matches them with path endpoint tags, and generates security policy tag groups; and a protection output module that statistically analyzes the security category nodes to which the tags belong, divides threat paths and establishes attribution relationships, and generates a network security protection structure table. This system integrates quantum security and VPN technologies to enhance network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security protection technology, specifically a distributed network security protection system that integrates a quantum security gateway VPN. Background Technology

[0002] In today's digital age, the internet has deeply integrated into all aspects of social life, from daily personal information exchange to the transmission and storage of critical business data for enterprises, and to vital communications for government agencies concerning national security and social stability. Network security is therefore paramount. Traditional network security systems primarily rely on classical encryption algorithms to ensure the confidentiality and integrity of data transmission; for example, asymmetric cryptography plays a central role in internet communication security. However, with the rapid development of technology, especially the continuous breakthroughs in quantum computing, this classical encryption method based on mathematical problems is facing unprecedented and severe challenges.

[0003] Quantum computers possess computing power far exceeding that of traditional computers. Their unique qubit characteristics enable parallel computing, theoretically allowing them to break existing classical encryption algorithms in an extremely short time. For example, Shor's algorithm and its variants can effectively attack various public-key cryptography algorithms, including ECDSA and Diffie-Hellman. Once quantum computing technology matures and is maliciously exploited, current network communications relying on these encryption algorithms will be utterly insecure. Large amounts of important information, such as bank transaction data, personal privacy data, and sensitive government communications, will be at risk of leakage. The entire network architecture will be exposed to direct attacker fire, severely undermining the security foundation of the internet ecosystem.

[0004] Meanwhile, cyberattack methods are becoming increasingly complex and diverse. Distributed Denial-of-Service (DDoS) attacks send massive amounts of requests to target servers by controlling a large number of botnets, causing slow system responses or even paralysis, severely impacting the availability of network services. Viruses and malware, like malignant tumors hidden in the shadows of the network, spread rapidly through communication networks, not only disrupting normal system operation but also silently stealing valuable data resources, posing a significant threat to the stability and reliability of network security. Under such dual pressure, traditional network security protection systems are gradually becoming inadequate, urgently requiring an innovative and more powerful security protection solution to address these challenges.

[0005] Quantum security technology, as an emerging and highly promising security measure, has emerged. Quantum key distribution (QKD) utilizes fundamental principles of quantum mechanics, such as the non-cloning and indivisibility of quantum states, to achieve absolutely secure key distribution. Unlike traditional encryption methods, in QKD, any eavesdropping by a third party during key transmission inevitably interferes with the quantum state, thus being detected by both communicating parties, fundamentally guaranteeing key security. However, quantum key distribution also has some limitations in practical applications. For example, relay nodes need to be deployed for networking or long-distance transmission, and if these relay nodes are attacked or compromised, it will seriously affect the security of the entire link. Summary of the Invention

[0006] The purpose of this invention is to provide a distributed network security protection system that integrates a quantum-secure gateway VPN to solve the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides a distributed network security protection system integrating a quantum-secure gateway VPN, the system comprising:

[0008] The quantum key distribution module acquires network traffic data, performs quantum key distribution processing, and generates a quantum key sequence.

[0009] The VPN tunnel construction module sorts the quantum keys based on the quantum key sequence and constructs the VPN tunnel path structure.

[0010] The threat detection module extracts the tunnel path node sequence based on the VPN tunnel path structure, compares the node intersection and counts the frequency of abnormal nodes, filters threat paths, and obtains a set of potential threats.

[0011] The security policy determination module collects node security tags based on abnormal nodes in the potential threat set, sorts them by frequency of occurrence, matches them with path endpoint tags, and generates a security policy tag group.

[0012] The protection output module, based on the security policy tag group, counts the security classification nodes to which each tag belongs, assigns threat paths to the corresponding nodes, establishes a node-threat path classification relationship structure, and generates a network security protection structure table.

[0013] Preferably, the quantum key distribution module includes:

[0014] The traffic analysis submodule acquires network traffic data, performs quantum property extraction on the traffic data, extracts the quantum attribute set of each traffic group, records the index position of each quantum attribute in the traffic, compares the relationship between the first occurrence position of the key attribute in the attribute ranking list and the number of attributes, classifies them according to traffic groups, and obtains the key attribute index distribution results.

[0015] The key sequence generation submodule extracts the quantum fragments corresponding to the key attributes in the traffic data based on the key attribute index distribution results, truncates the quantum attributes based on the index interval of the key attributes in the traffic, constructs an attribute fragment set based on the position of the truncated attribute for each key attribute, and reassembles them in combination with the traffic group to which the attribute belongs to obtain a key attribute sequence set.

[0016] The key sequence construction submodule calculates the frequency of occurrence of all key attributes based on the set of key attribute sequences, performs position rearrangement processing on the set of attribute fragments based on the original order of key attributes in the traffic data, concatenates the sequences of multiple key attributes in the same traffic group according to the first occurrence position, integrates the key weight results corresponding to each traffic group, and generates a quantum key sequence.

[0017] Preferably, the VPN tunnel building module includes:

[0018] The hierarchical sorting submodule, based on the quantum key sequence and combined with the hierarchical labels of each quantum attribute node of the flow, compares and sorts all quantum attribute nodes according to their hierarchical label priority values, rearranges the quantum attributes in order from the top layer to the bottom layer, establishes a rearranged sequence index table, and obtains the attribute sorting index value.

[0019] The tunnel generation submodule sorts the index value according to the attribute, obtains the set of adjacent nodes in the quantum attribute rearrangement sequence, numbers and records the connection direction of each pair of adjacent nodes, combines the connection relationship of all nodes in the path, integrates the structural edge information, and generates VPN tunnel path map data.

[0020] The node structure extraction submodule collects the node numbers and adjacent node pairs in all connected edges based on the VPN tunnel path graph data, constructs a node mapping table based on the adjacent structure relationship, stores the upstream and downstream relationship types and connection directions between each attribute, and obtains the VPN tunnel path structure.

[0021] Preferably, the threat detection module includes:

[0022] Based on the VPN tunnel path structure, the path extraction submodule collects the node sequence in any two tunnel paths, extracts the node number information under each path in turn, establishes a tunnel node mapping set, marks the tunnel identifier and path length parameter of each path, and obtains the tunnel path node number value.

[0023] The intersection comparison submodule calls the node number sequence of any two tunnel paths based on the tunnel path node number value, performs an intersection comparison operation on the node sets of the two paths, extracts all endpoint node numbers in the intersection, counts the number of times each type of node appears in different paths, compares it with the path intersection judgment benchmark value one by one, filters path pairs with deviation values ​​less than or equal to the benchmark value, and establishes a set of path intersection numbers that meet the conditions.

[0024] The path filtering submodule, based on the set of path intersection numbers that meet the conditions, queries the original tunnel path identifier according to the path combination corresponding to the number, integrates the tunnel identifier and the path intersection node information, establishes a tunnel path relationship chain, and generates a potential threat set.

[0025] Preferably, the security policy determination module includes:

[0026] The security tag collection submodule collects the security tag set to which each abnormal node belongs based on the abnormal nodes in the potential threat set, performs index mapping between the tunnel path and its destination tag, and generates a path destination security tag group.

[0027] The tag frequency statistics submodule performs a repetition count operation on all safety tags based on the path endpoint safety tag group, records the number of times each safety tag appears in the tunnel path set, and sorts them from high to low according to the number of occurrences to obtain a sorted safety tag sequence.

[0028] The category label determination submodule performs a matching judgment on the label set corresponding to the end node in the tunnel path according to the sorted security label sequence, selects the label item with the highest position in the sorted sequence in each path as the security category to which the path belongs, integrates the belonging labels of all tunnel paths, and generates a security policy label group.

[0029] Preferably, the protection output module includes:

[0030] The node extraction submodule collects the security category nodes corresponding to each tag according to the security policy tag group, records the path numbers associated with each category node and the number of their corresponding tunnel path sets, determines the matching index between security tags and security nodes, and obtains the tag-assigned node number value.

[0031] The path classification submodule, based on the node number value to which the tag belongs, divides the corresponding tunnel paths into various safety classification nodes according to the safety tag as the classification basis, establishes a two-way correspondence structure between tunnel path numbers and node numbers, extracts the path number list to which each node belongs, and obtains the number of paths to which each node belongs.

[0032] The structure generation submodule integrates the security classification nodes with their subordinate tunnel path numbers based on the node path affiliation quantity value, outputs the classification node index, corresponding security label and total number of paths, determines the affiliation of nodes and tunnel paths, and generates a network security protection structure table.

[0033] Preferably, the system further includes a data preprocessing module:

[0034] The data preprocessing module receives initial network traffic data, performs a cleaning operation to remove invalid data packets, classifies the data into valid datasets and invalid datasets, and discards invalid datasets.

[0035] The data preprocessing module sorts the subsets in the effective dataset in descending order according to the number of subsets in the effective dataset, selects the top few subsets as the preferred dataset, calculates the proportion of the preferred dataset in the effective dataset and compares it with the preset screening ratio threshold.

[0036] The data preprocessing module generates preliminary flow analysis results based on the proportion results, which are then input into the quantum key distribution module.

[0037] Preferably, the system further includes an environmental compensation module:

[0038] The environmental compensation module acquires the noise fluctuation sequence in the network environment parameters, extracts the extreme noise values ​​and noise change frequencies in the sequence, and calculates the dynamic adjustment amount of quantum key stability as noise changes.

[0039] The environmental compensation module performs noise interference compensation calculations on the quantum key sequence based on the dynamic adjustment amount, and generates a corrected quantum key sequence.

[0040] The environmental compensation module performs path offset correction processing on the VPN tunnel path structure based on the correlation between noise change frequency and tunnel stability, generating a corrected VPN tunnel path structure for input to the threat detection module.

[0041] Preferably, the system further includes a model optimization module:

[0042] The model optimization module obtains the number of path intersection nodes and the number of abnormal node conversions during the threat detection process, and calculates the average conversion ratio.

[0043] The model optimization module schedules the number of paths and nodes in the potential threat set and analyzes and calculates the estimated risk index.

[0044] The model optimization module generates optimized security policy instructions based on the comparison results between the estimated risk index and the preset risk threshold, which are used to adjust the judgment process of the security policy judgment module.

[0045] Preferably, the system further includes a verification feedback module:

[0046] The verification feedback module collects actual network security event data within a preset period;

[0047] The verification feedback module performs deviation analysis on the actual event data and the set of potential threats to generate error correction coefficients.

[0048] The verification feedback module adjusts the detection parameters of the threat detection module based on the error correction coefficient to generate an optimized threat detection model, which is used to iteratively update the system protection process.

[0049] Compared with the prior art, the beneficial effects of the present invention are:

[0050] In terms of key generation and management, the quantum key distribution module acquires network traffic data, performs quantum key distribution processing, and generates a quantum key sequence. Based on the principles of quantum mechanics, quantum keys are non-clonal and indivisible. This means that any attempt to steal or tamper with the key during key generation and transmission will be immediately detected, thus laying a solid key security foundation for the entire network security protection system. Compared with traditional encryption keys, this significantly reduces the risk of key cracking and safeguards the core security elements of data encryption.

[0051] In the VPN tunnel construction phase, quantum keys are sorted based on quantum key sequences to construct the VPN tunnel path structure. Due to the high security of quantum keys, the constructed VPN tunnel path is more secure and reliable. Traditional VPN tunnel paths are vulnerable to various network attacks, while the tunnel path built based on quantum keys in this system can effectively resist common attack methods such as man-in-the-middle attacks. Because attackers cannot obtain the correct quantum key, they cannot decrypt or tamper with the data transmitted within the tunnel, ensuring the integrity and confidentiality of the data during transmission.

[0052] The threat detection module extracts the node sequence of the VPN tunnel path based on its structure. By comparing node intersections and counting the frequency of abnormal nodes, it filters threat paths and obtains a set of potential threats. This threat detection method based on node sequence analysis offers higher accuracy and comprehensiveness compared to traditional single-rule matching or simple traffic monitoring. It can deeply uncover abnormal network traffic behavior at the node level and promptly discover potential threat paths. Even if attackers employ complex multi-step attack strategies, the module can accurately identify abnormal nodes and their hidden threat paths through correlation analysis of multiple nodes, providing precise target localization for subsequent security measures.

[0053] The security policy determination module collects security tags from abnormal nodes in the potential threat set, sorts them by frequency of occurrence, and matches them with path endpoint tags to generate security policy tag groups. This module can dynamically generate highly targeted security policies based on the actual threat situation. Compared to traditional fixed security policies, it can more flexibly respond to different types and levels of network threats. When a new threat pattern emerges, the system can quickly generate a corresponding security policy based on the tag information of abnormal nodes, without requiring manual adjustments to numerous complex configuration parameters, greatly improving the efficiency and adaptability of security policy formulation.

[0054] The protection output module, based on security policy tag groups, statistically analyzes the security classification nodes to which each tag belongs, assigns threat paths to corresponding nodes, establishes a node-threat path classification structure, and generates a network security protection structure table. This clear classification structure and the generated protection structure table enable network security administrators to intuitively and quickly understand the distribution of threats in the network and the corresponding security measures. In traditional network security protection systems, security administrators often need to spend a significant amount of time sifting through massive amounts of logs and complex alerts to sift through threat information. This system, however, greatly improves the efficiency and convenience of security management through its intuitive structure table display. Furthermore, this structured protection output approach facilitates subsequent data analysis and optimization, providing strong support for further enhancing network security protection capabilities. Attached Figure Description

[0055] Figure 1 This is a timing diagram of the distributed network security protection system integrating a quantum-secure gateway VPN as described in this invention;

[0056] Figure 2 A flowchart illustrating the operation of the quantum key distribution module;

[0057] Figure 3 A flowchart illustrating how the threat detection module works;

[0058] Figure 4 A flowchart illustrating the operation of the security policy determination module;

[0059] Figure 5 A flowchart illustrating the operation of the data preprocessing module. Detailed Implementation

[0060] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0061] Please see Figure 1 This invention provides a distributed network security protection system that integrates a quantum security gateway VPN. The system includes modules such as quantum key distribution, VPN tunnel construction, threat detection, security policy determination, and protection output, which work together to achieve dynamic network security protection.

[0062] The quantum key distribution module acquires network traffic data and performs quantum key distribution processing to generate a quantum key sequence. The VPN tunnel construction module constructs the VPN tunnel path structure based on the quantum key sequence. The threat detection module extracts the node sequence of the tunnel path, compares node intersections, counts the frequency of abnormal nodes, and filters threat paths to obtain a set of potential threats. The security policy determination module generates security policy label groups based on the abnormal nodes in the set of potential threats. The protection output module establishes a node-threat path classification relationship structure based on the security policy label groups, generating a network security protection structure table.

[0063] Example 1: See Figure 2 The quantum key distribution module, through the collaborative operation of the traffic analysis submodule, key sequence generation submodule, and key sequence construction submodule, completes the process of generating quantum key sequences from raw network traffic data. The traffic analysis submodule acquires real-time network traffic data streams, which contain multiple continuously transmitted data packets. For each data packet, a quantum property extraction operation is performed to analyze and identify the quantum property features contained within. These quantum property features specifically include physical properties such as quantum state polarization direction parameters, quantum phase shifts, and quantum entanglement state correlation parameters exhibited by the data packet during transmission. The extraction operation is performed independently for each traffic packet, identifying and recording all observable quantum properties within that packet, forming a set of quantum properties specific to that packet. Simultaneously, the specific index position of each identified quantum property in the traffic packet data stream is recorded; this index position is determined by the attribute's timestamp sequence number in the data stream and its spatial coordinate offset within the packet. Subsequently, the analysis process focuses on a preset set of key quantum properties. For each key attribute, the system analyzes its first occurrence coordinate in the attribute ranking list and compares this coordinate with the total number of times the key attribute appears in the current traffic packet. By calculating the relative relationship between the first occurrence position and the attribute frequency, the current traffic packet is classified into a predefined category interval based on the range of this relationship value. This classification operation iterates through all received traffic packets and finally outputs the key attribute index distribution result, which reflects the distribution pattern of key quantum attributes in different categories of traffic packets.

[0064] The key sequence generation submodule receives the key attribute index distribution results from the traffic analysis submodule. Based on these results, the module locates and extracts the original quantum data fragment corresponding to each key attribute in the entire network traffic data stream. The extraction process relies on the index interval information of the key attribute in the traffic data, which is defined by the start and end timestamps of the key attribute, as well as its start and end spatial coordinates in the data packet. Based on the index interval, the system precisely truncates the original quantum data carrying the key attribute to obtain quantum attribute fragments containing complete key attribute information. Each truncated quantum attribute fragment carries the identification information of its original traffic packet. The module collects all quantum attribute fragments corresponding to all key attributes to form an initial set of attribute fragments. Subsequently, based on the traffic packet identifier to which the attribute fragment belongs, the set of attribute fragments is reassembled. The reassembly rule is to aggregate all key attribute fragments belonging to the same traffic packet to form a key attribute sequence corresponding to that packet. After traversing all traffic packets, a set of key attribute sequences is obtained, which organizes the key quantum attribute fragments by packet.

[0065] The key sequence construction submodule processes the key attribute sequence set. First, the module statistically calculates the frequency of occurrence of all key attributes in the entire traffic data. Frequency statistics not only calculate the absolute number of occurrences of each key attribute but also combine the temporal density (number of occurrences per unit time) and spatial density (number of occurrences per unit data length) of the attribute occurrences for weighted calculation, resulting in a comprehensive frequency value. Next, the module strictly follows the order in which the key attributes appear in the original network traffic data, performing position rearrangement processing on the attribute fragments in the key attribute sequence set. The core principle of rearrangement is time priority; that is, if multiple key attributes exist within the same traffic group, their corresponding attribute fragments are linearly concatenated according to the order in which they are first detected in the data stream of that group, forming an ordered key attribute sequence fragment within that group. During the concatenation process, the system calculates and assigns a key weight value to each key attribute sequence fragment. The calculation of this key weight value comprehensively considers the quantum entanglement strength coefficient (reflecting the tightness of quantum state correlation) and the quantum polarization direction stability parameter (reflecting the degree of fluctuation in the quantum state polarization direction over time) of the key attributes in the sequence fragment. Finally, the module integrates the key attribute sequence fragments from all traffic packets after rearrangement and weighting, and arranges them according to the order of the packets in the original data stream to output the final quantum key sequence. This sequence contains both the ordered arrangement of the key quantum attributes and the key weight information corresponding to each attribute fragment.

[0066] Example 2: See Figure 3The VPN tunnel construction module transforms quantum key sequences into operable VPN tunnel path structures through the collaborative processing of a hierarchical sorting submodule, a tunnel generation submodule, and a node structure extraction submodule. The hierarchical sorting submodule receives the quantum key sequence as input, which contains key quantum property fragments arranged in chronological order and their corresponding key weight information. Simultaneously, the module acquires the hierarchical label information of each quantum property node in the traffic data. The hierarchical label is determined by preset security level parameters and real-time transmission path length. The security level parameters are divided into multiple discrete levels based on the entanglement strength threshold and polarization stability range of the quantum property, while the transmission path length is dynamically calculated based on the spatial span of the property node in the data stream. For each quantum property node, the system calculates its hierarchical label priority value, which is generated by weighted fusion of the security level coefficient and the path length attenuation factor. Subsequently, the module performs a total order comparison of all quantum property nodes based on their priority values. The comparison process employs a quantum parallel comparison algorithm, while simultaneously performing phase interference determination on the priority differences of all node pairs. Based on the comparison results, all quantum property nodes are rearranged in order of priority value from high to low (i.e., from the top layer to the bottom layer). The rearrangement operation must satisfy the quantum superposition constraint: when the priority difference between two nodes is less than the quantum coherence tolerance, they are allowed to occupy the same sorting position interval in a superposition state; when the priority difference exceeds the tolerance, they are strictly separated and sorted according to their numerical values. After the rearrangement is completed, the system establishes a rearrangement sequence index table, records the new position coordinates of each quantum attribute node in the rearrangement sequence and its original position mapping relationship, and outputs the attribute sorting index value.

[0067] The tunnel generation submodule operates based on attribute sorting index values. The module reads the rearranged quantum attribute sequence and identifies the relationships between adjacent nodes. Adjacent node determination requires simultaneous satisfaction of spatial and temporal continuity conditions: spatial continuity requires that the difference in spatial coordinates between two nodes in the original data stream does not exceed the quantum state correlation radius; temporal continuity requires that the timestamp interval between nodes is less than the quantum state coherence time window. For each pair of adjacent nodes meeting the conditions, the system assigns a unique connection number and records its connection direction attribute. The connection direction is determined by the propagation polarization angle of the quantum states between nodes: a polarization angle between 0° and 90° is marked as a forward connection, between 90° and 180° as a reverse connection, and between 180° and 270° as a bidirectional connection. The module traverses the entire rearranged sequence, collecting all valid adjacent node pairs and their connection direction information. During integration, the system constructs a path structure edge dataset, where each edge data includes the starting node number, ending node number, connection direction identifier, and connection strength value (calculated from the quantum entanglement correlation degree between nodes). Based on the complete edge dataset, the module generates VPN tunnel path graph data, which uses a weighted directed graph structure to represent the connection topology between quantum attribute nodes.

[0068] The node structure extraction submodule processes VPN tunnel path graph data. This module parses all connection edges in the graph, extracting the node ID pairs and connection direction attributes for each edge. Based on this data, the system constructs a node mapping table using a quantum hash storage structure. The table stores all downstream node IDs and their corresponding connection direction types, with the starting node ID as the index key. The storage process strictly adheres to the quantum no-cloning principle: only a single copy of each node mapping relationship is stored, and quantum entanglement check codes prevent data duplication. Simultaneously, the module constructs an upstream node mapping table indexed by the terminating node, forming a complete bidirectional relationship mapping. During the mapping table construction process, the system verifies the quantum state compatibility of connections between nodes in real time: when a new connection conflicts with an existing connection in terms of quantum state (e.g., orthogonal polarization directions or phase repulsion), the system automatically inserts a quantum state transition node for coordination. The final output VPN tunnel path structure includes the node mapping table, edge attribute table, and quantum state compatibility check records.

[0069] The path extraction submodule of the threat detection module operates based on the aforementioned VPN tunnel path structure. The module first collects all possible tunnel paths, each defined as a continuous sequence of nodes from the entry node to the exit node. Path collection must satisfy the quantum state decoherence time constraint: the total transmission delay of the path must not exceed the maximum time threshold for maintaining a coherent quantum state. For each valid path, the system extracts the sequence of node numbers it contains, establishing a path node list. Simultaneously, it records the tunnel identifier (generated from the quantum fingerprint of the entry node) and the path length (measured in terms of the number of quantum state transitions). All path information is integrated to form a tunnel node mapping set, which is stored using quantum compression encoding to reduce storage space requirements.

[0070] The intersection comparison submodule processes the set of tunnel node maps. The module selects any two different tunnel paths and calls their node number sequences. It performs a quantum interference intersection operation on the node sets of the two paths: treating the node sequences of the two paths as quantum state wave functions, it constructs a quantum interferometer to simulate their superposition state, and extracts the node numbers corresponding to the wave crest positions in the interference fringes as the intersection result. This process can simultaneously obtain the phase difference of all nodes in the intersection in the two paths. The system pays special attention to the presence state of the endpoint node (i.e., the path exit node) in the intersection result. For each endpoint node present in the intersection, it counts the number of times it appears in the two paths (achieved through quantum state projection measurement) and calculates the difference in the number of occurrences. This difference is compared with a preset path intersection judgment benchmark (a dynamic threshold determined by the network topology complexity). All path pairs with differences not exceeding the benchmark are selected, and their endpoint node numbers, path pair identifiers, and difference information are integrated into a set of path intersection numbers that meet the conditions.

[0071] The path filtering submodule performs deep processing based on the intersection number set. The module uses the path pair identifiers recorded in the set to reverse-look up the complete path information in the original tunnel path structure. For each matching path pair, it extracts its common endpoint node and path intersection points (i.e., non-endpoint nodes in the intersection nodes). Quantum entanglement must be maintained during the integration process: when multiple paths share a common intersection point, the state information of all associated paths is synchronously updated through a quantum entanglement channel. The system constructs a tunnel path relationship linked list, where each node contains a path identifier, a set of intersection nodes, a common endpoint node, and pointers to associated paths. This linked list uses a quantum teleportation protocol to connect nodes, ensuring the security of information transmission. The final output set of potential threats consists of this relationship linked list and the associated quantum state verification signatures.

[0072] Example 3: See Figure 4 The security policy determination module, through the collaborative processing of the security tag acquisition submodule, tag frequency statistics submodule, and category tag determination submodule, transforms a set of potential threats into an executable set of security policy tags. The security tag acquisition submodule receives a set of potential threats from the threat detection module, which contains information on multiple anomalous nodes and their associated tunnel paths. Each anomalous node carries a set of security tags, generated jointly by the node's quantum state characteristics and network behavior patterns. The tag acquisition process employs quantum selective measurement technology to perform non-destructive projection measurements on the node's quantum state to obtain its security attribute characteristics. During the measurement process, the system establishes a measurement basis set for each anomalous node. ,in Let represent the i-th measurement basis vector, determined by the Hilbert space dimension of the node's quantum state. The set of node security tags is obtained through measurement. ,in This represents the j-th security label of node n, where k is the upper limit for the number of labels. Simultaneously, the module establishes an index mapping relationship between the tunnel path endpoint and the security labels. , indicating path The set of security tags corresponding to the endpoint node n. This mapping relationship is transmitted using a quantum teleportation protocol to ensure that the tag information is not stolen.

[0073] The tag frequency statistics submodule processes the path endpoint security tag group. The module performs repetition counts on all security tags, taking into account the statistical properties of quantum states during the statistical process. For each tag... Calculate its weighted frequency of occurrence in all tunnel path endpoints. :

[0074] ,

[0075] in: Represents the set of all tunnel paths. When the label The set of endpoint labels existing in path p The value is 1 if it is true and 0 otherwise. The weighting factor for path p is determined by both path length and node credibility. Frequency statistics employ a quantum parallel computing architecture, simultaneously performing interferometry on all tag path combinations. After obtaining the raw frequency data, the system performs quantum annealing sorting, arranging the security tags in descending order of frequency value to form a sorted security tag sequence. , where m is the total number of distinct labels, and satisfies During the sorting process, the quantum entanglement between tags is maintained, ensuring that tags of the same frequency remain in a coherent superposition state.

[0076] The category label determination submodule classifies paths based on a sorted sequence of security labels. For each tunnel path... Extract the tag set corresponding to its endpoint node. Compare this set with the sorted sequence. Perform matching, search In China The first label to appear in the text The matching process employs a quantum search algorithm, accelerating the search by constructing the Grover iterative operator. The system then uses this label as a path. The classification of security categories. The determination process needs to resolve tag conflicts: when multiple tags are in the sequence... When paths have the same sorting position, a quantum random number generator is used for nondeterministic selection. After all paths are classified, the module integrates the attribution label information to construct a security policy label group. ,in Representing a path Assigned security label The tag set uses quantum error-correcting encoding for storage to prevent information corruption.

[0077] The node extraction submodule of the protection output module processes security policy tag groups. The module parses tag groups. Each tag in Query the predefined security category node mapping table to obtain the security category node corresponding to the label. The mapping table is encrypted using quantum key distribution, and each tag-to-node mapping relationship... Dynamically generated from quantum state measurement results. Records each security classification node. List of currently associated path numbers And calculate the list length. This serves as the number of paths associated with the node. The node extraction process must adhere to the quantum no-cloning theorem, retaining only a single quantum copy of the path association information for each node.

[0078] The path classification submodule performs path allocation based on the label-node mapping relationship. This applies to security policy label groups. Each entry in According to the mapping relationship path Assigned to security classification node The partitioning operation is implemented using a quantum state exchange protocol, and path information is transmitted to the target node via a quantum channel. The module establishes node numbers. With path number bidirectional correspondence structure This structure uses quantum entangled pairs for association, ensuring that the connection between nodes and paths is indivisible. Simultaneously, the system maintains a list of path numbers for each security classification node. And update the list length count in real time. .

[0079] The structure generation submodule integrates all categorized data. This module iterates through all safe category nodes, collecting data from each node. Path list and its corresponding security label set Build the node index table. Each record in the table contains a node number. Related tag set Number of paths And path list pointers. Pointer information is accessed across space via quantum tunneling, unrestricted by traditional storage media. The final generated network security protection structure table. From the node index table and path-node association matrix Composition, in which matrix elements Representing a path With nodes The attribution relationship is represented by qubits. Indicates ownership. (Indicates non-belonging). This structure table achieves distributed storage through a quantum entanglement network, maintaining quantum coherence between components.

[0080] Example 4: See Figure 5The data preprocessing module works in conjunction with the environmental compensation module to complete the processing flow from raw network traffic to optimized network structure. The network traffic data received by the data preprocessing module is input in the form of data packet sequences, each containing header information and a payload. The module first performs data cleaning operations to identify and filter invalid data packets. The criteria for determining invalid data packets include: header checksum errors, abnormal payload lengths, and broken timestamps. The system maintains a real-time updated invalid feature library, marking data packets matching any feature in the library as invalid. Valid data packets are classified according to their protocol type and quality of service parameters, forming multiple data subsets. Typical data subset classifications are shown in Table 1.

[0081] Table 1: Examples of Network Traffic Data Subset Classification

[0082]

[0083] The module sorts the subsets in descending order based on their data volume and selects the top-ranked subsets as the preferred dataset. The selection process considers the quantum characteristic strength and temporal density parameters of the subsets to ensure that the selected data possesses sufficient quantum expressiveness and temporal continuity. When calculating the proportion of the preferred dataset in the total valid data, the system dynamically adjusts the screening ratio threshold, which is negatively correlated with the current network load. When the network load is high, the threshold is appropriately lowered to control the data processing volume; when the load is low, the threshold is raised to obtain more refined data features. The preliminary traffic analysis results include a feature summary and distribution statistics of the preferred dataset, providing input for subsequent quantum key distribution.

[0084] The environmental compensation module monitors network environment parameters in real time, focusing on collecting noise fluctuation data. Noise sources include electromagnetic interference, equipment thermal noise, and channel crosstalk. The module acquires the time and frequency domain characteristics of the noise through a quantum sensor array. The noise fluctuation sequence is organized in time windows, with each window recording the noise peak, valley, and average energy value within that time period. Extreme noise values ​​are identified using an adaptive thresholding method, with the threshold dynamically fluctuating according to the noise baseline level. Noise variation frequency analysis employs quantum Fourier transform technology to extract the periodic characteristics of the main noise components. The module establishes a correlation model between noise characteristics and quantum key stability, mapping noise parameters to key stability adjustment coefficients. The coefficient calculation considers the degree of matching between the noise spectrum distribution and the quantum carrier frequency, as well as the relative relationship between the instantaneous noise amplitude and the quantum state tolerance threshold.

[0085] The compensation process for the quantum key sequence employs a segment-by-segment correction strategy. The module divides the key sequence into several logical segments, each corresponding to a specific noise environment state. Based on the noise characteristics of each time segment, the compensation amount is calculated, and the key bits are phase-adjusted or amplitude-calibrated. The compensated key sequence must pass a quantum state verification test to ensure it still meets the requirements of non-cloning and entanglement properties. The correction process for the VPN tunnel path structure focuses on path offset issues. The module analyzes the correlation between noise variation frequency and path stability, identifying vulnerable path segments susceptible to noise. Quantum repeater nodes are inserted into these path segments, and quantum state purification technology is used to improve path noise resistance. The corrected VPN structure recalculates the transmission delay and reliability indicators of each path to ensure it meets the basic requirements of quantum communication.

[0086] In a specific implementation case, this system was deployed in a financial data center to process real-time transaction data. The data preprocessing module received transaction traffic containing multiple protocol types, among which a subset of TCP / SSL and HTTP / 2 was selected as the preferred dataset due to their high quantum characteristic strength. The environmental compensation module detected periodic noise interference introduced by the UPS equipment in the data center and avoided peak noise periods by adjusting the key generation clock phase. When constructing the VPN tunnel, the system automatically bypassed physical links subject to strong electromagnetic interference, selecting a direct fiber optic connection path as the primary transmission channel. The entire processing flow maintained quantum security characteristics while adapting to the complexity of the actual network environment.

[0087] Example 5: The model optimization module and the verification feedback module form a closed-loop optimization mechanism to continuously improve the system's protection effectiveness. The model optimization module periodically collects intermediate data during the threat detection process, including the number of intersection nodes and the number of abnormal nodes converted. The number of intersection nodes is counted using quantum parallel counting technology, simultaneously acquiring the number of shared nodes for all path pairs in a single measurement. The number of abnormal nodes converted refers to the proportion of nodes marked as threats out of the initial abnormal nodes. This proportion is calculated considering the probability amplitude evolution characteristics of quantum states, and the statistical distribution of the conversion trajectory is obtained through quantum interference measurement. When calculating the average conversion proportion, the conversion events within each detection cycle are quantum coherently superimposed to eliminate random biases caused by measurement disturbances. When scheduling the total number of paths and nodes in the potential threat set, a quantum entanglement channel is used to achieve cross-module data synchronization, ensuring the spatiotemporal consistency of statistical data.

[0088] Based on the ratio of the number of paths to the number of nodes, the module performs a risk index prediction. The calculation process incorporates a quantum annealing optimization algorithm, mapping the path node network to a spin system of the Ising model, and finding the optimal risk estimate by adjusting the quantum tunneling intensity. The risk index reflects the overall danger level of the current threat set, and its numerical range is compared with a preset risk threshold. The preset threshold dynamically fluctuates according to the network environment's security level, automatically lowering the threshold to improve detection sensitivity in high-security scenarios. The comparison results trigger different optimization strategy instructions: when the risk index is consistently higher than the threshold, an enhanced detection instruction is generated; when the risk index is consistently lower than the threshold, an efficiency optimization instruction is generated. The instruction generation mechanism uses a quantum decision tree model, where each decision node corresponds to a set of quantum state measurement bases, and the optimal instruction type is determined through quantum state projection.

[0089] The verification feedback module collects data on actual network security incidents within fixed time periods. Incident collection covers various types of security threats, including unauthorized access attempts, abnormal data transmissions, and protocol violations. The collection process employs quantum non-destructive measurement techniques to maintain the quantum coherence of the network state while acquiring incident information. After quantum encoding, the incident data is matched and analyzed against the system's predicted set of potential threats. Deviation analysis includes two dimensions: event type matching degree and time window overlap degree. Type matching degree analysis uses a quantum pattern recognition algorithm to calculate the Hilbert spatial distance between the actual event feature vector and the predicted threat features. Time window overlap degree analysis is achieved through quantum correlation measurement, detecting the phase correlation between the event occurrence time and the predicted time point.

[0090] Based on the matching analysis results, the module calculates the error correction coefficient. This coefficient is generated by fusing a type bias factor and a time bias factor through quantum entanglement weights. The type bias factor reflects the weighted combination of the false negative rate and the false positive rate, while the time bias factor represents the mean squared error between the predicted time and the actual time. The error correction coefficient applies to key parameters of the threat detection module, including the path intersection judgment benchmark and the abnormal node judgment threshold. The parameter adjustment process follows the principle of quantum adiabatic evolution, progressively changing parameter values ​​while maintaining the quantum properties of the system. The adjusted detection parameters are used to retrain the threat detection model, with training data injected into the model parameter space using quantum teleportation technology. The optimized threat detection model achieves real-time inference through quantum gate circuits, and its output serves as the input for the next round of protection procedures.

[0091] During continuous operation, the system establishes a dual-cycle iterative mechanism. Short-cycle (minute-level) fine-tuning of model parameters dynamically optimizes detection sensitivity based on real-time risk indices. Long-cycle (day-level) model structure updates reconstruct the detection algorithm's quantum circuit based on accumulated error correction data. Each iteration retains a snapshot of the historical model's quantum states, allowing for rapid rollback to a stable version if the new model fails to validate. The entire optimization process records operation logs using quantum blockchain technology, with each optimization step generating an immutable quantum hash value, forming a traceable chain of protective evolution.

[0092] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0093] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A distributed network security protection system integrating a quantum-secure gateway VPN, characterized in that, The system includes: The quantum key distribution module acquires network traffic data, performs quantum key distribution processing, and generates a quantum key sequence. The VPN tunnel construction module sorts the quantum keys based on the quantum key sequence and constructs the VPN tunnel path structure. The threat detection module extracts the tunnel path node sequence based on the VPN tunnel path structure, compares the node intersection and counts the frequency of abnormal nodes, filters threat paths, and obtains a set of potential threats. The security policy determination module collects node security tags based on abnormal nodes in the potential threat set, sorts them by frequency of occurrence, matches them with path endpoint tags, and generates a security policy tag group. The protection output module, based on the security policy tag group, counts the security classification nodes to which each tag belongs, assigns threat paths to the corresponding nodes, establishes a node-threat path classification relationship structure, and generates a network security protection structure table.

2. The distributed network security protection system integrating a quantum-secure gateway VPN as described in claim 1, characterized in that, The quantum key distribution module includes: The traffic analysis submodule acquires network traffic data, performs quantum property extraction on the traffic data, extracts the quantum attribute set of each traffic group, records the index position of each quantum attribute in the traffic, compares the relationship between the first occurrence position of the key attribute in the attribute ranking list and the number of attributes, classifies them according to traffic groups, and obtains the key attribute index distribution results. The key sequence generation submodule extracts the quantum fragments corresponding to the key attributes in the traffic data based on the key attribute index distribution results, truncates the quantum attributes based on the index interval of the key attributes in the traffic, constructs an attribute fragment set based on the position of the truncated attribute for each key attribute, and reassembles them in combination with the traffic group to which the attribute belongs to obtain a key attribute sequence set. The key sequence construction submodule calculates the frequency of occurrence of all key attributes based on the set of key attribute sequences, performs position rearrangement processing on the set of attribute fragments based on the original order of key attributes in the traffic data, concatenates the sequences of multiple key attributes in the same traffic group according to the first occurrence position, integrates the key weight results corresponding to each traffic group, and generates a quantum key sequence.

3. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The VPN tunnel construction module includes: The hierarchical sorting submodule, based on the quantum key sequence and combined with the hierarchical labels of each quantum attribute node of the flow, compares and sorts all quantum attribute nodes according to their hierarchical label priority values, rearranges the quantum attributes in order from the top layer to the bottom layer, establishes a rearranged sequence index table, and obtains the attribute sorting index value. The tunnel generation submodule sorts the index value according to the attribute, obtains the set of adjacent nodes in the quantum attribute rearrangement sequence, numbers and records the connection direction of each pair of adjacent nodes, combines the connection relationship of all nodes in the path, integrates the structural edge information, and generates VPN tunnel path map data. The node structure extraction submodule collects the node numbers and adjacent node pairs in all connected edges based on the VPN tunnel path graph data, constructs a node mapping table based on the adjacent structure relationship, stores the upstream and downstream relationship types and connection directions between each attribute, and obtains the VPN tunnel path structure.

4. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The threat detection module includes: Based on the VPN tunnel path structure, the path extraction submodule collects the node sequence in any two tunnel paths, extracts the node number information under each path in turn, establishes a tunnel node mapping set, marks the tunnel identifier and path length parameter of each path, and obtains the tunnel path node number value. The intersection comparison submodule calls the node number sequence of any two tunnel paths based on the tunnel path node number value, performs an intersection comparison operation on the node sets of the two paths, extracts all endpoint node numbers in the intersection, counts the number of times each type of node appears in different paths, compares it with the path intersection judgment benchmark value one by one, filters path pairs with deviation values ​​less than or equal to the benchmark value, and establishes a set of path intersection numbers that meet the conditions. The path filtering submodule, based on the set of path intersection numbers that meet the conditions, queries the original tunnel path identifier according to the path combination corresponding to the number, integrates the tunnel identifier and the path intersection node information, establishes a tunnel path relationship chain, and generates a potential threat set.

5. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The security policy determination module includes: The security tag collection submodule collects the security tag set to which each abnormal node belongs based on the abnormal nodes in the potential threat set, performs index mapping between the tunnel path and its destination tag, and generates a path destination security tag group. The tag frequency statistics submodule performs a repetition count operation on all safety tags based on the path endpoint safety tag group, records the number of times each safety tag appears in the tunnel path set, and sorts them from high to low according to the number of occurrences to obtain a sorted safety tag sequence. The category label determination submodule performs a matching judgment on the label set corresponding to the end node in the tunnel path according to the sorted security label sequence, selects the label item with the highest position in the sorted sequence in each path as the security category to which the path belongs, integrates the belonging labels of all tunnel paths, and generates a security policy label group.

6. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The protection output module includes: The node extraction submodule collects the security category nodes corresponding to each tag according to the security policy tag group, records the path numbers associated with each category node and the number of their corresponding tunnel path sets, determines the matching index between security tags and security nodes, and obtains the tag-assigned node number value. The path classification submodule, based on the node number value to which the tag belongs, divides the corresponding tunnel paths into various safety classification nodes according to the safety tag as the classification basis, establishes a two-way correspondence structure between tunnel path numbers and node numbers, extracts the path number list to which each node belongs, and obtains the number of paths to which each node belongs. The structure generation submodule integrates the security classification nodes with their subordinate tunnel path numbers based on the node path affiliation quantity value, outputs the classification node index, corresponding security label and total number of paths, determines the affiliation of nodes and tunnel paths, and generates a network security protection structure table.

7. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The system also includes a data preprocessing module: The data preprocessing module receives initial network traffic data, performs a cleaning operation to remove invalid data packets, classifies the data into valid datasets and invalid datasets, and discards invalid datasets. The data preprocessing module sorts the subsets in the effective dataset in descending order according to the number of subsets in the effective dataset, selects the top few subsets as the preferred dataset, calculates the proportion of the preferred dataset in the effective dataset and compares it with the preset screening ratio threshold. The data preprocessing module generates preliminary flow analysis results based on the proportion results, which are then input into the quantum key distribution module.

8. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 7, characterized in that, The system also includes an environmental compensation module: The environmental compensation module acquires the noise fluctuation sequence in the network environment parameters, extracts the extreme noise values ​​and noise change frequencies in the sequence, and calculates the dynamic adjustment amount of quantum key stability as noise changes. The environmental compensation module performs noise interference compensation calculations on the quantum key sequence based on the dynamic adjustment amount, and generates a corrected quantum key sequence. The environmental compensation module performs path offset correction processing on the VPN tunnel path structure based on the correlation between noise change frequency and tunnel stability, generating a corrected VPN tunnel path structure for input to the threat detection module.

9. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The system also includes a model optimization module: The model optimization module obtains the number of path intersection nodes and the number of abnormal node conversions during the threat detection process, and calculates the average conversion ratio. The model optimization module schedules the number of paths and nodes in the potential threat set and analyzes and calculates the estimated risk index. The model optimization module generates optimized security policy instructions based on the comparison results between the estimated risk index and the preset risk threshold, which are used to adjust the judgment process of the security policy judgment module.

10. The distributed network security protection system integrating a quantum-secure gateway VPN according to claim 1, characterized in that, The system also includes a verification feedback module: The verification feedback module collects actual network security event data within a preset period; The verification feedback module performs deviation analysis on the actual event data and the set of potential threats to generate error correction coefficients. The verification feedback module adjusts the detection parameters of the threat detection module based on the error correction coefficient to generate an optimized threat detection model, which is used to iteratively update the system protection process.

Citation Information

Patent Citations

  • Method and equipment for realizing IPSec VPN (Internet Protocol Security Virtual Private Network) by adopting software definition and quantum key distribution

    CN116055091A

  • IPSec VPN security gateway system fusing quantum key distribution network technology

    CN117640087A