An optical fiber communication networking data security transmission method, system, device and medium

By generating an uncopyable polarization tuning quantity through the interactive modulation of pseudo-random number sequences and optical fiber channel characteristics, and establishing a nonlinear relationship between time slot allocation length and polarization tuning quantity, the problems of insufficient dynamic control of polarization state and easy cracking of protocol layer encryption in optical fiber communication networking are solved, and efficient data security transmission is achieved.

CN120880566BActive Publication Date: 2025-12-12SICHUAN TIANYI COMHEART TELECOM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511404099.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-12-12
Estimated Expiration
2045-09-29

AI Technical Summary

Technical Problem

Existing fiber optic communication networks lack the ability to dynamically adjust polarization state during secure data transmission. Attackers can reconstruct data through reverse engineering, the protocol layer encryption mechanism is easily cracked, and the fixed time slot length is easily predictable, making eavesdropping and attacks difficult to defend against.

Method used

By interactively modulating pseudo-random number sequences with the characteristics of optical fiber channels to generate non-replicable polarization tuning quantities, a nonlinear relationship between time slot allocation length and polarization tuning quantities is established. Combined with two-level threshold judgment and dynamic parameter updates, gradient identification and adaptive defense of attack behaviors are achieved.

Benefits of technology

It effectively prevents attackers from reconstructing polarization states and eavesdropping on data, reduces the possibility of reverse-engineering time slot statistical patterns, and improves transmission security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880566B_ABST
    Figure CN120880566B_ABST
Patent Text Reader

Abstract

The application discloses a kind of optical fiber communication networking data security transmission method, system, equipment and medium, it is related to data processing technical field, comprising: obtaining basic tuning amplitude and basic tuning frequency, obtaining the i th pseudo-random number, and according to basic tuning amplitude, basic tuning frequency and the i th pseudo-random number, obtain polarization tuning amount;Obtain reference time slot length and maximum time slot length, and based on time slot allocation model, reference time slot length, maximum time slot length and polarization tuning amount, obtain time slot allocation length;In the i th time period, optical signal data transmission is carried out to receiving end according to polarization tuning amount and time slot allocation length in sending end, and the time slot record length of optical signal data in the i th time period is obtained at receiving end;According to time slot record length and time slot allocation length, transmission adjustment strategy is obtained, and subsequent transmission is carried out according to transmission adjustment strategy.The application has the advantages of dynamic enhancement security, nonlinear time slot attack resistance and adaptive closed loop.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to a fiber communication networking data security transmission method, system, device and medium. BACKGROUND

[0002] In the field of optical fiber communication technology, Fiber to the Room (FTTR) as the core technology of modern broadband access, by extending the optical fiber to the user terminal, significantly improves the network bandwidth and transmission quality.

[0003] However, with the increasing demand for data security in Internet of Things, Industrial Internet and other scenarios, the existing optical fiber communication networking data gradually exposes technical bottlenecks in the field of secure transmission. First, the existing technology usually adopts static configuration of physical layer polarization state, that is, fixed polarization state (such as horizontal or vertical polarization) transmission of optical signal, however, the birefringence effect of optical fiber causes regular evolution of polarization state in the transmission process, attackers can use polarization diversity receiver to capture multiple polarization mode optical signals at the same time, and through the reverse reconstruction algorithm to completely recover the original data, more seriously, the existing technology lacks the ability of dynamic regulation of polarization state, attackers only need to implant a low-cost optical splitter in the optical fiber link to long-term eavesdrop, and legitimate users are difficult to detect such covert attacks; secondly, the static encryption mechanism of the protocol layer is difficult to cope with high-intensity attacks, attackers can perform brute force cracking through distributed computing power, or implement man-in-the-middle attacks by exploiting protocol vulnerabilities, at the same time, the existing time slicing scheme divides the data frame with fixed time slot length, attackers can accurately predict the time slot boundary through statistical analysis, so as to implement precise time slot interception or data injection attack, although part of the improved scheme attempts to introduce pseudo-random time slot adjustment, but its pseudo-random time slot lacks relevance with physical layer parameters, resulting in that the time slot length variation law is easy to be cracked by machine learning model. SUMMARY

[0004] In view of the defects in the prior art, the present application provides a fiber communication networking data security transmission method, system, device and medium.

[0005] The method comprises the following steps: obtaining a basic tuning amplitude and a basic tuning frequency according to a fiber communication networking; obtaining an i-th pseudo-random number synchronized at a sending end and a receiving end in an i-th time period; and obtaining a polarization tuning amount corresponding to the i-th time period according to the basic tuning amplitude, the basic tuning frequency and the i-th pseudo-random number; obtaining a reference time slot length and a maximum time slot length; obtaining a time slot allocation length corresponding to the i-th time period based on a time slot allocation model, the reference time slot length, the maximum time slot length and the polarization tuning amount corresponding to the i-th time period; performing optical signal data transmission from the sending end to the receiving end according to the polarization tuning amount corresponding to the i-th time period and the time slot allocation length in the i-th time period; obtaining a time slot record length of the optical signal data in the i-th time period at the receiving end; obtaining a transmission adjustment strategy according to the time slot record length and the time slot allocation length; and performing subsequent transmission according to the transmission adjustment strategy.

[0006] Optionally, obtaining the transmission adjustment strategy according to the time slot record length and the time slot allocation length comprises: when a difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, determining whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold; if yes, stopping the optical signal data transmission; and if no, skipping the i-th time period to enter an (i+1)-th time period, obtaining an (i+1)-th pseudo-random number synchronized at the sending end and the receiving end in the (i+1)-th time period, and re-obtaining the polarization tuning amount corresponding to the (i+1)-th time period and the time slot allocation length, and performing optical signal data transmission from the sending end to the receiving end according to the polarization tuning amount corresponding to the (i+1)-th time period and the time slot allocation length in the (i+1)-th time period.

[0007] Optionally, obtaining the i-th pseudo-random number synchronized at the sending end and the receiving end in the i-th time period comprises: exchanging an initial seed parameter of a pseudo-random number generator through a secure channel between the sending end and the receiving end in an initial communication stage; and generating the same pseudo-random number independently based on the initial seed parameter and a predefined update rule at the sending end and the receiving end at the beginning of each subsequent time period.

[0008] Optionally, obtaining the polarization tuning amount corresponding to the i-th time period according to the basic tuning amplitude, the basic tuning frequency and the i-th pseudo-random number comprises: obtaining a wavelength disturbance amplitude of a channel between the sending end and the receiving end; and obtaining a maximum pseudo-random number; and obtaining the polarization tuning amount corresponding to the i-th time period according to the basic tuning amplitude, the basic tuning frequency, the wavelength disturbance amplitude, the maximum pseudo-random number and the i-th pseudo-random number.

[0009] Optionally, obtaining the polarization tuning amount corresponding to the i-th time period according to the basic tuning amplitude, the basic tuning frequency, the wavelength disturbance amplitude, the maximum pseudo-random number and the i-th pseudo-random number is represented as: ; wherein is the polarization tuning amount corresponding to the i th time period, is the base tuning amplitude, is the wavelength disturbance amplitude, is the base tuning frequency, is the i th pseudo-random number, is the maximum pseudo-random number.

[0010] Optionally, the time slot allocation model is represented as follows based on the time slot allocation model, the reference time slot length, the maximum time slot length, and the polarization tuning amount corresponding to the i th time period: ; wherein is the time slot allocation length corresponding to the i th time period, is the reference time slot length, is the maximum time slot length, is the polarization tuning amount corresponding to the i th time period.

[0011] Also provided is an optical fiber communication networking data security transmission system, which comprises: a polarization tuning module configured to obtain a base tuning amplitude and a base tuning frequency according to optical fiber communication networking, obtain an i th pseudo-random number synchronized at a sending end and a receiving end in an i th time period, and obtain a polarization tuning amount corresponding to the i th time period according to the base tuning amplitude, the base tuning frequency, and the i th pseudo-random number; a time slot allocation module configured to obtain a reference time slot length and a maximum time slot length, and obtain a time slot allocation length corresponding to the i th time period based on a time slot allocation model, the reference time slot length, the maximum time slot length, and the polarization tuning amount corresponding to the i th time period; a transmission execution module configured to perform optical signal data transmission from the sending end to the receiving end in the i th time period according to the polarization tuning amount corresponding to the i th time period and the time slot allocation length, and obtain a time slot record length of the optical signal data in the i th time period at the receiving end; and a feedback processing module configured to obtain a transmission adjustment strategy according to the time slot record length and the time slot allocation length, and perform subsequent transmission according to the transmission adjustment strategy.

[0012] Optionally, the feedback processing module is further configured to: when a difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, determine whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold; if yes, stop the optical signal data transmission; and if no, skip the i th time period and enter an i + 1 th time period, obtain an i + 1 th pseudo-random number synchronized at the sending end and the receiving end in the i + 1 th time period, and re-obtain a polarization tuning amount corresponding to the i + 1 th time period and a time slot allocation length, and perform optical signal data transmission from the sending end to the receiving end in the i + 1 th time period according to the polarization tuning amount corresponding to the i + 1 th time period and the time slot allocation length.

[0013] The application further provides an electronic device, comprising a memory having a computer program stored thereon, and a processor configured to execute the computer program in the memory to implement the above-mentioned optical fiber communication networking data security transmission method.

[0014] The application further provides a non-transitory computer readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the above-mentioned optical fiber communication networking data security transmission method.

[0015] The beneficial effects of the application are embodied in the following aspects:

[0016] In the whole optical fiber communication networking data security transmission method, firstly, a non-reproducible polarization tuning quantity is generated by real-time interactive modulation of a pseudo-random number sequence and a fiber channel characteristic at a physical layer, so that the polarization state evolution path not only retains the controllability of periodic modulation, but also superimposes nonlinear disturbance of channel noise. Even if an attacker intercepts a split signal, the attacker cannot reconstruct and track the polarization state through reverse engineering, and the received signal is distorted. Further, the protocol layer establishes a nonlinear relationship between the time slot allocation length and the polarization tuning quantity, converts the physical layer disturbance into irregular hopping of the time slot boundary, and greatly reduces the possibility of reverse inference of the time slot statistical law by the attacker. Further, in terms of transmission security, gradient identification and adaptive defense of attack behavior are realized through dynamic deviation analysis of the time slot record length and the allocation value. For low-intensity eavesdropping, a polarization tuning parameter rolling update strategy is adopted to force the attacker to lose the ability to continuously eavesdrop due to parameter tracking failure. For high-intensity brute force attacks, a two-level threshold determination triggers a link fusing mechanism, and the risk is quickly isolated in combination with physical layer channel self-checking. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the specific embodiments of the application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or prior art description. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual proportions.

[0018] Figure 1 A schematic diagram of the steps of the optical fiber communication networking data security transmission method of the application;

[0019] Figure 2 A schematic diagram of part of the steps of S4 in the optical fiber communication networking data security transmission method of the application;

[0020] Figure 3 A schematic diagram of part of the steps of S1 in the optical fiber communication networking data security transmission method of the application;

[0021] Figure 4Another part of steps of S1 in the optical fiber communication network data security transmission method of the application is shown in the figure;

[0022] Figure 5 A block diagram of an electronic device is shown in an embodiment of the application.

[0023] Reference signs:

[0024] 700-electronic device, 701-processor, 702-memory, 703-multimedia component, 704-I / O interface, 705-communication component. DETAILED DESCRIPTION

[0025] To make the objectives, technical solutions and advantages of the embodiments of the application clearer, the technical solutions in the embodiments of the application will be described below in connection with the drawings in the embodiments of the application. Obviously, the described embodiments are only some of the embodiments of the application, rather than all the embodiments. The components of the embodiments of the application described and shown in the drawings can be arranged and designed in various different configurations.

[0026] Therefore, the following detailed description of the embodiments of the application provided in the drawings is not intended to limit the scope of the claimed application, but only represents selected embodiments of the application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the application without creative labor are within the scope of protection of the application.

[0027] It should be noted that: similar reference signs and letters represent similar items in the following drawings, therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", etc. are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0028] As Figure 1 shown, an optical fiber communication network data security transmission method is provided, comprising:

[0029] S1, acquiring a basic tuning amplitude and a basic tuning frequency according to the optical fiber communication network, and acquiring an ith pseudo-random number synchronized at a sending end and a receiving end in an ith time period, and acquiring a polarization tuning amount corresponding to the ith time period according to the basic tuning amplitude, the basic tuning frequency and the ith pseudo-random number;

[0030] S2, acquiring a reference time slot length and a maximum time slot length, and acquiring a time slot allocation length corresponding to the ith time period based on a time slot allocation model, the reference time slot length, the maximum time slot length and the polarization tuning amount corresponding to the ith time period;

[0031] S3, transmitting the optical signal data to the receiving end in the i th time period according to the polarization tuning amount corresponding to the i th time period and the time slot allocation length, and obtaining the time slot record length of the optical signal data in the i th time period at the receiving end;

[0032] S4, obtaining a transmission adjustment strategy according to the time slot record length and the time slot allocation length, and performing subsequent transmission according to the transmission adjustment strategy.

[0033] In the embodiment, it should be noted that in S1, the polarization tuning amount deeply coupled with the fiber channel characteristics is dynamically generated to realize real-time regulation of the polarization state that cannot be predicted by the attacker. First, the sending end and the receiving end generate a pseudo-random number sequence synchronously through a pre-shared initial seed parameter, which is strictly bound to the time period, and then modulate it in combination with physical layer characteristics such as channel wavelength disturbance amplitude to obtain the final polarization tuning amount. For example, when the fiber channel produces a slight wavelength shift due to temperature change, the pseudo-random number is weighted according to the real-time monitored disturbance amplitude, so that the calculation of the polarization tuning amount not only contains the preset basic tuning rule, but also integrates the nonlinear influence of the channel state. This double modulation mechanism ensures that the polarization state change in each time period not only has the technical controllability of periodic modulation, but also superimposes the non-reproducibility brought by the physical layer environmental noise.

[0034] Further, the dynamic generation process of the polarization tuning amount realizes the anti-reverse attack capability. For example, when the birefringence effect occurs in the optical fiber link, the basic tuning amplitude and frequency are dynamically scaled based on the pseudo-random number sequence, so that the polarization state evolution path cannot be reversely modeled by a single parameter in the mathematical level. At the same time, the synchronous update period of the pseudo-random number and the inherent resonance period of the fiber channel form a non-integer multiple relationship, which further destroys the periodic capture ability of the attacker on the polarization state evolution law. This method of deeply embedding the channel physical characteristics into the tuning amount generation algorithm makes it impossible for the attacker to decouple the effective polarization state control parameter set even if the split optical signal is obtained.

[0035] In S2, the dynamic association between the time slot length and the physical layer polarization tuning amount is established to realize the secure fragmentation of the data frame time boundary that cannot be predicted. Specifically, based on the constraint range of the reference time slot length and the maximum time slot length, in combination with the polarization tuning amount of the current time period, the actual time slot allocation length is dynamically calculated through a composite function. For example, when the polarization tuning amount is significantly enhanced due to channel disturbance, the model will increase the adjustment amplitude of the time slot length through a nonlinear scaling mechanism, so that the change of the time slot boundary offset is not only related to the pseudo-random sequence, but also coupled with the interference of the fiber channel. This mapping relationship makes it impossible for the attacker to predict the time slot boundary by independently analyzing the time slicing law or the polarization state change characteristics, and the attacker must crack the cross-coupling relationship between the physical layer dynamic parameters and the protocol layer fragmentation mechanism, which greatly improves the attack cost.

[0036] Further, the time slot allocation model has adaptive adjustment capability through real-time feedback of polarization tuning amount. For example, when the polarization tuning amount of the fiber channel fluctuates dramatically, the model generates a logarithmic scaling factor based on the reference time slot length, which converts the dynamic disturbance of the polarization state into non-uniform stretching of the time slot length while ensuring the basic transmission efficiency. This design not only avoids the exposure of statistical rules caused by fixed time slot length, but also makes it difficult for attackers to establish a linear regression model of time slot length change and physical layer parameters even if they intercept part of the time slot data, due to the strong correlation between polarization tuning amount and time slicing. At the same time, the hard constraint of the maximum time slot length prevents the transmission efficiency from declining due to excessively long time slots in extreme cases, forming a dynamic balance between security and transmission performance.

[0037] In S3, the dual security mechanism of dynamic polarization control and non-linear time slot slicing forms a data transmission process that is difficult for attackers to crack. At the sending end, the polarization state of the optical signal is adjusted in real time based on the polarization tuning amount generated in S1, and at the same time, the data frame is sliced according to the time slot allocation length calculated in S2. When the polarization tuning amount suddenly increases due to changes in fiber stress, the time slot length will be adaptively shortened through a non-linear scaling mechanism, causing the time slot boundaries of adjacent data frames to exhibit irregular jumps. This dual dynamic change of polarization state and time slot length makes it difficult for attackers to restore the complete transmission timing and polarization state control logic even if they intercept the split optical signal through conventional polarization diversity reception or time slot statistical analysis methods.

[0038] Further, at the receiving end, the clear optical signal data is parsed through synchronized pseudo-random numbers and channel parameters, and this process forms a security closed loop in S4: if an attacker attempts to inject fake data or brute-force intercept time slots, the time slot length recorded at the receiving end will deviate significantly from the allocated value at the sending end (e.g., due to time slot fragmentation caused by response delay of the attack device). For example, when an attacker tries to insert malicious data packets at the time slot boundary, his operation will disrupt the dynamic correlation between polarization tuning amount and data slicing, resulting in abnormal time slot length fluctuations recorded at the receiving end, thereby triggering a rapid response of the subsequent security strategy. This cross-validation mechanism of transmission layer and physical layer parameters fundamentally blocks the possibility of man-in-the-middle attacks and time slot injection.

[0039] In S4, a transmission security closed loop is achieved through a time slot length dynamic verification mechanism, forming a real-time detection and adaptive defense system for attack behavior. Specifically, by comparing the actual recorded time slot length at the receiving end with the time slot length pre-allocated by the sending end, a security situation assessment is achieved; for example, when an attacker attempts to steal data through a splitter, the signal processing delay of his eavesdropping device will cause a slight deviation in the time slot record length; and a brute force interception attack will cause a dramatic jump in the time slot length difference. Among them, a two-level threshold judgment mechanism is used to distinguish the type of interference: when the difference exceeds the first threshold but does not reach the second threshold, it is determined to be channel environmental noise or low-intensity attack, triggering a time slot parameter dynamic reset strategy, which forces the attacker to be unable to continuously track parameter changes by jumping to the next time period and updating the polarization tuning amount; if the difference breaks through the second threshold, it is determined to be a high-intensity brute force attack, immediately cutting off the transmission link and starting a physical layer channel self-check to avoid key parameter leakage.

[0040] Further, the security verification mechanism forms a deep coupling defense network with the physical layer parameters. For example, in a man-in-the-middle attack scenario, the attacker's fake time slot injection will destroy the dynamic association between the polarization tuning amount and the data fragment, causing the time slot length recorded by the receiving end to present a nonlinear deviation from the expected value. By analyzing the statistical characteristics of the deviation (such as mutation frequency and deviation direction), the type of attack can be accurately identified and the corresponding defense strategy can be triggered. At the same time, the parameter reset process uses the previous polarization tuning amount as an entropy source to generate a new pseudo-random number sequence, so that the security parameters of each jump period inherit the historical tuning characteristics and superimpose new channel noise disturbances, forming a rolling security barrier that cannot be reproduced by the attacker. This mechanism that binds transmission verification with physical layer state effectively blocks the possibility of the attacker predicting the defense strategy through historical data analysis.

[0041] In summary, in the whole optical fiber communication networking data security transmission method, first, through the real-time interaction modulation of the pseudo-random number sequence and the optical channel characteristics in the physical layer, the polarization tuning quantity which cannot be copied is generated, so that the polarization state evolution path not only retains the controllability of periodic modulation technology, but also superimposes the nonlinear disturbance of channel noise. Even if the attacker intercepts the light splitting signal, he cannot reconstruct and track the polarization state through reverse engineering, and the received signal is distorted. Further, the protocol layer establishes a nonlinear relationship between the time slot allocation length and the polarization tuning quantity, converts the physical layer disturbance into irregular jumping of the time slot boundary, and greatly reduces the possibility of reverse prediction of the time slot statistical law by the attacker. Further, in terms of transmission security, through dynamic deviation analysis of the time slot record length and the allocation value, gradient identification and adaptive defense of attack behavior are realized: for low-intensity eavesdropping, the polarization tuning parameter rolling update strategy is adopted, forcing the attacker to lose the ability to continuously eavesdrop due to parameter tracking failure, and for high-intensity brute force attack, the two-level threshold determination triggers the link fuse mechanism, combined with the physical layer channel self-checking to quickly isolate the risk. In summary, through the secure presetting of the initial seed parameter of the pseudo-random number generator, the cross-entropy binding of the polarization tuning quantity and the time slicing parameter, and the real-time linkage of the defense strategy and the channel physical state, a trinity defense architecture of key update, parameter evolution and attack response is formed, so that the attacker cannot obtain effective polarization state control parameters through light splitting eavesdropping, cannot rely on protocol vulnerabilities to implement man-in-the-middle attacks, and cannot break the time slot slicing law through distributed computing power brute force, so as to realize the transmission security and communication reliability as much as possible.

[0042] As shown in Figure 2 In one embodiment, acquiring a transmission adjustment strategy according to the time slot record length and the time slot allocation length in S4 includes:

[0043] S41, when the difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, determining whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold;

[0044] S42, if it exceeds, stopping the optical signal data transmission;

[0045] S43, if it does not exceed, skipping the i-th time period to enter the i+1-th time period, acquiring the i+1-th pseudo-random number synchronized at the sending end and the receiving end in the i+1-th time period, reacquiring the polarization tuning quantity and the time slot allocation length corresponding to the i+1-th time period, and performing optical signal data transmission from the sending end to the receiving end in the i+1-th time period according to the polarization tuning quantity and the time slot allocation length corresponding to the i+1-th time period.

[0046] In this embodiment, it should be noted that in S41, the fine grading determination of attack strength is realized through a two-stage threshold mechanism. When the difference between the time slot length recorded by the receiving end and the allocation value of the sending end exceeds the first preset threshold, it is determined that there is abnormal disturbance in the channel. At this time, the key to distinguishing between low-intensity attacks and high-intensity attacks lies in the second threshold determination. For example, when an attacker uses a low-power optical splitter to eavesdrop, the time delay deviation introduced by it is usually small, and the difference may only slightly exceed the first threshold but not reach the second threshold, and it is identified as environmental noise or covert eavesdropping. When the attacker implements a full-fiber link brute-force interception, the redirection operation of its device will cause the optical signal transmission path to mutate, causing the time slot difference to grow exponentially and quickly break through the second threshold. This gradient determination mechanism effectively avoids the misjudgment caused by the natural disturbance of the channel in the traditional single threshold scheme, while ensuring the early warning ability to covert attacks.

[0047] wherein the acquisition of the first preset threshold and the second preset threshold needs to be based on the comprehensive calibration of channel characteristic modeling, historical transmission data statistics and attack mode analysis. Specifically: the first preset threshold (low-risk determination threshold): by long-term monitoring of the natural deviation of the time slot record length and the allocation value in the normal transmission state (such as time delay jitter caused by fiber microbending, environmental temperature and humidity changes), the probability distribution (such as Gaussian distribution or Poisson distribution) is calculated by statistical method, and the upper limit of the confidence interval (such as 3δ principle) is selected as the threshold boundary; for example, in the non-attack scene, the time slot difference samples are continuously collected, the mean and standard deviation are calculated, the first threshold is set as the mean plus 3 times the standard deviation, covering 99.7% of the normal fluctuation range, and exceeding it is determined to exist potential interference. And the second preset threshold (high-risk determination threshold): simulate attack experiments and physical layer damage, quantify the time slot difference mutation amplitude caused by high-intensity attacks (such as brute-force interception, full-link signal hijacking); for example, by injecting controllable power interference signals or simulating optical splitter eavesdropping device delay, the extreme deviation value of the time slot difference is measured, and the maximum tolerance of the channel (such as the limit of the fiber nonlinear effect) is superimposed, and finally the second threshold is determined as the critical collapse point of safe transmission, which is usually two to three times of the first threshold. It should be noted that a dynamic adaptive mechanism can be used, and in actual operation, based on the latest channel state data (such as polarization tuning amount fluctuation range, time slot allocation length change rate) and attack log, the threshold parameters are refitted periodically (such as every 24 hours); for example, when it is detected that the baseline deviation of the fiber link is expanded due to aging, the threshold is automatically increased in proportion; if low-intensity attacks occur frequently in recent period, the gradient between the first and second thresholds is compressed to enhance the sensitivity; this process realizes closed-loop optimization through sliding window statistics and reinforcement learning strategy.

[0048] In S42, a circuit breaker defense strategy is designed to counter high-intensity brute-force attacks, interrupting the persistence of the attack by immediately cutting off the optical signal transmission link. For example, in a distributed denial-of-service (DDoS) attack scenario, an attacker attempts to overwhelm legitimate signals by injecting high-power signals. In this case, the receiver's time slot difference will fluctuate drastically due to large-scale packet loss, triggering a second threshold and immediately severing the physical layer optical channel. The physical layer channel self-test module is then activated to scan for abnormal states such as fiber optic micro-bending and loose connectors. This mechanism differs from traditional protocol-layer disconnection and reconnection; instead, it interrupts the attack path at the physical medium level while preserving the security state of key parameters and the pseudo-random number generator, preventing attackers from reverse-engineering the security parameters required for polarization tuning through continuous signal injection.

[0049] In S43, a defense system against persistent tracking is constructed through dynamic parameter rolling updates to counter low-intensity covert attacks. When the difference is between the first and second thresholds, it is determined that the attacker is attempting long-term parameter sniffing. At this point, the current time period is skipped, and a new pseudo-random number sequence is generated based on the preceding polarization tuning. For example, when an attacker learns historical time slot allocation patterns through a machine learning model, parameter resetting will disrupt the temporal continuity of its training data. The polarization tuning of the new period will undergo non-stationary jumps due to superimposed real-time channel disturbances, causing the attack model's predictions to fail. Simultaneously, the time slot allocation length is reconstructed through a nonlinear function, resulting in uncorrelated jumps in the time slot boundaries between adjacent periods. This completely destroys the attacker's ability to progressively learn the sharding patterns, forming a dynamically evolving security barrier.

[0050] like Figure 3 As shown, in one embodiment, obtaining the i-th pseudo-random number synchronized at the sending and receiving ends within the i-th time period in S1 includes:

[0051] S11. During the initial communication phase, the sending end and the receiving end exchange the initial seed parameters of the pseudo-random number generator through a secure channel.

[0052] S12. At the beginning of each subsequent time period, the sending end and the receiving end independently generate the same pseudo-random number based on the initial seed parameter and the predefined update rule.

[0053] In this embodiment, it should be noted that in S11, an initial synchronization basis is established through a secure channel to ensure that the initial seed parameters of the pseudo-random number generator are exchanged simultaneously between the sending end and the receiving end.

[0054] In S12, the seamless synchronization of the pseudo-random sequence is achieved by the deterministic update rule, ensuring the parameter consistency strictly bound to the time period. After the seed parameter presetting is completed, the sending end and the receiving end independently generate the same pseudo-random number at the beginning of each time period. For example, a forward security chain structure is adopted, the pseudo-random number of the last period is taken as the input, and the timestamp and the channel noise characteristics are combined for multi-round regular operation to generate the new pseudo-random number of the current period. This design not only ensures that the attacker cannot predict the subsequent sequence through historical data, but also eliminates the generation deviation of the two ends caused by clock drift through the strict synchronization mechanism of the timestamp. Even if the attacker tampers with part of the transmission data, the pseudo-random number generation process can still maintain self-consistency, forming a rolling security barrier against man-in-the-middle attacks.

[0055] As shown in Figure 4 In one embodiment, the polarization tuning amount corresponding to the i-th time period is obtained according to the basic tuning amplitude, the basic tuning frequency, and the i-th pseudo-random number in S1, which includes:

[0056] S13, the wavelength disturbance amplitude of the channel between the sending end and the receiving end is obtained, and the maximum pseudo-random number is obtained;

[0057] S14, the polarization tuning amount corresponding to the i-th time period is obtained according to the basic tuning amplitude, the basic tuning frequency, the wavelength disturbance amplitude, the maximum pseudo-random number, and the i-th pseudo-random number.

[0058] In this embodiment, it should be noted that in S13, the physical state disturbance characteristics of the optical fiber channel are captured in real time, and environmental noise entropy sources are injected into the polarization tuning amount. By monitoring the wavelength shift between the sending end and the receiving end (such as the optical fiber stretching effect caused by temperature fluctuations or the refractive index change caused by mechanical vibration), the wavelength disturbance amplitude is dynamically quantified. For example, when the optical fiber link is periodically deformed under external pressure, the photodetector will measure the wavelength shift of the optical signal in real time and convert it into the disturbance amplitude. At the same time, the upper limit of the pseudo-random number generator value range is preset to ensure that the pseudo-random numbers of different time periods fluctuate within a controllable range, forming a modulation basis that is affected by environmental disturbances and has mathematical constraints.

[0059] In S14, the polarization tuning amount is generated by multi-parameter fusion, and the static tuning rule is associated with the dynamic channel noise. Specifically, the periodic function corresponding to the basic tuning amplitude is nonlinearly superimposed with the linear term guided by the wavelength disturbance amplitude. For example, when the optical fiber channel suddenly experiences strong birefringence effect, the wavelength disturbance amplitude increases significantly, so that the weight of the pseudo-random number in the calculation of the polarization tuning amount is also increased, resulting in a polarization state evolution path that exhibits inseparable chaotic characteristics in the mathematical model. This design makes it impossible for the attacker to decouple the independent influence relationship between the basic tuning parameters and the channel disturbance factors through Fourier transform or regression analysis even if the polarization tuning amount data of multiple time periods is intercepted.

[0060] In one embodiment, the polarization tuning amount corresponding to the i-th time period is obtained according to the base tuning amplitude, the base tuning frequency, the wavelength perturbation amplitude, the maximum pseudo-random number, and the i-th pseudo-random number in S14, and is expressed as:

[0061] ; wherein,

[0062] is the polarization tuning amount corresponding to the i-th time period, is the base tuning amplitude, is the wavelength perturbation amplitude, is the base tuning frequency, is the i-th pseudo-random number, is the maximum pseudo-random number.

[0063] In the present embodiment, it is necessary to note that, is the periodic modulation term; the base tuning amplitude controls the amplitude range of the periodic change of the polarization state, and determines the baseline strength of the polarization state modulation; the base tuning frequency sets the periodic frequency of the polarization state change, for example, 10 Hz means that the polarization state completes a complete cycle evolution every 0.1 second; is the pseudo-random number normalization, compresses the pseudo-random number to the interval [-1, 1], so that the phase of the sine wave of each period is determined by the pseudo-random number, which destroys the ability of the attacker to capture the periodicity, for example, when the phase of the sine function jumps discontinuously in the range when randomly changing, the polarization state evolution path cannot be extracted by Fourier analysis. Fixed frequency characteristics.

[0064] Further, is the dynamic perturbation term; the wavelength perturbation amplitude monitors the physical disturbance of the fiber channel in real time (such as the wavelength shift amount caused by temperature and stress), and quantifies the environmental noise intensity; the normalized pseudo-random number represents the weight, which dynamically binds the pseudo-random number with the channel noise, so that the contribution of the perturbation term changes randomly, enhancing the unpredictability of the tuning amount.

[0065] In summary, the anti-reverse attack ability is guaranteed, and even if the attacker discovers the base tuning frequency by spectrum analysis, due to the pseudo-random distribution, the phase of the actual input sine function presents non-uniform jumps on the time axis; for example, if =1000, = 300, 720, 150, the phase is 0.8, -0.88, 1.4, respectively , resulting in a sinusoidal output that cannot form a continuous periodic signal. Further, the inseparability of noise and pseudo-random numbers is also achieved, and the wavelength disturbance and pseudo-random numbers are coupled through linear terms, and attackers cannot separate the effects of pure environmental noise or pure pseudo-random sequences through Fourier transform or independent component analysis (ICA). When the disturbance term weight is amplified synchronously due to sudden fiber vibration, but the specific value still depends on randomness, forming double confusion.

[0066] For example, = 1, = 5, = 100, when = 30, ; if the next period = 15, while increases to 6 due to temperature changes, .

[0067] Analysis: the sign of the tuning amount of the adjacent period is reversed and the amplitude jumps, completely destroying the regularity; if the attacker tries to fit the relationship between and through a neural network, since changes in real time (such as from 5 to 6), the same corresponding will change from to , resulting in a failure of the model prediction.

[0068] In one embodiment, the time slot allocation model in S2 is represented as:

[0069] ; wherein,

[0070] is the time slot allocation length corresponding to the i-th time period, is the reference time slot length, is the maximum time slot length, is the polarization tuning amount corresponding to the i-th time period.

[0071] In this embodiment, it should be noted that the expression realizes a nonlinear scaling mechanism, which maps the polarization tuning amount to the time slot length adjustment range[ , ], while introduces nonlinear compression to avoid the time slot length from changing with​​ Linear growth, prevent attackers through linear regression modeling. Among them, is the adjustment term of the entire expression, the normalization factor Compress the time slot length adjustment range, Realize the polarization tuning quantity normalization, and Angular dimension mapping to a certain interval, and the phase range of the fiber birefringence effect is 0 to Alignment, realize the nonlinear growth of the entire adjustment term, ensure that the time slot allocation length increases with Increase, the time slot allocation length change rate decreases with Increase, avoid extreme fluctuations.

[0072] In summary, it is realized to break the time slot statistical law, and the linear change of the fixed time slot or pseudo-random time slot in the prior art is easy to be statistically analyzed and predicted. The model realizes the chaotic characteristics of the time slot length change through the nonlinear logarithmic function and the dynamic input of the polarization tuning quantity. For example, if an attacker intercepts the time slot length sequence , tries to extract the periodic characteristics through Fourier transform, it will not be able to obtain effective spectral components due to the nonlinear distortion and Randomness. Further, an irreversible one-way function is formed, and the generation of the polarization tuning quantity Depend on channel noise and pseudo-random number, even if the attacker obtains part Data, it is also impossible to reversely deduce the security parameters such as , , , And Etc.

[0073] For example, =100, =200, = (Medium polarization tuning quantity); substitute into the expression to calculate . If =3 (High polarization tuning quantity); substitute into the expression to calculate . If =0 (low polarization tuning quantity); substitute into the expression to calculate .

[0074] Also provided is a fiber communication networking data security transmission system, the system comprising:

[0075] a polarization tuning module configured to obtain a basic tuning amplitude and a basic tuning frequency according to the fiber communication networking, obtain an ith pseudo-random number synchronized at the sending end and the receiving end in an ith time period, and obtain a polarization tuning amount corresponding to the ith time period according to the basic tuning amplitude, the basic tuning frequency, and the ith pseudo-random number;

[0076] a time slot allocation module configured to obtain a reference time slot length and a maximum time slot length, and obtain a time slot allocation length corresponding to the ith time period based on a time slot allocation model, the reference time slot length, the maximum time slot length, and the polarization tuning amount corresponding to the ith time period;

[0077] a transmission execution module configured to perform optical signal data transmission from the sending end to the receiving end by the polarization tuning amount corresponding to the ith time period and the time slot allocation length in the ith time period, and obtain a time slot record length of the optical signal data in the ith time period at the receiving end;

[0078] a feedback processing module configured to obtain a transmission adjustment strategy according to the time slot record length and the time slot allocation length, and perform subsequent transmission according to the transmission adjustment strategy.

[0079] In an embodiment, the feedback processing module is further configured to: when a difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, determine whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold; if yes, stop the optical signal data transmission; and if no, skip the ith time period and enter an (i+1)th time period, obtain an (i+1)th pseudo-random number synchronized at the sending end and the receiving end in the (i+1)th time period, and re-obtain the polarization tuning amount corresponding to the (i+1)th time period and the time slot allocation length corresponding to the (i+1)th time period, and perform optical signal data transmission from the sending end to the receiving end by the polarization tuning amount corresponding to the (i+1)th time period and the time slot allocation length corresponding to the (i+1)th time period in the (i+1)th time period.

[0080] In the embodiment, it should be noted that, as to the above-mentioned fiber communication networking data security transmission system, the specific manner of performing operations has been described in detail in the embodiments of the fiber communication networking data security transmission method, which will not be described in detail here.

[0081] Figure 5 is a block diagram of an electronic device for a fiber communication networking data security transmission method according to an example embodiment. As shown in Figure 5 the electronic device 700 can include a processor 701 and a memory 702. The electronic device 700 can also include one or more of a multimedia component 703, an I / O interface 704 (input / output interface), and a communication component 705.

[0082] The processor 701 is configured to control overall operations of the electronic device 700 to complete all or part of the steps of the above-described optical fiber communication networking data security transmission method. The memory 702 is configured to store various types of data to support operations of the electronic device 700, which can include, for example, instructions for operating any application or method on the electronic device 700, and application-related data, such as contact data, sent and received messages, pictures, audio, video, and the like. The memory 702 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk. The multimedia component 703 can include a screen and an audio component. The screen can be, for example, a touch screen, and the audio component is configured to output and / or input audio signals. For example, the audio component can include a microphone configured to receive external audio signals. The received audio signals can be further stored in the memory 702 or transmitted through the communication component 705. The audio component also includes at least one speaker configured to output audio signals. The I / O interface 704 provides an interface between the processor 701 and other interface modules, which can be a keyboard, a mouse, a button, and the like. The buttons can be virtual buttons or physical buttons. The communication component 705 is configured to perform wired or wireless communication between the electronic device 700 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, near field communication (NFC), 2G, 3G, 4G, NB-IOT, eMTC, or other 5G, and the like, or a combination of one or more of them, is not limited herein. Therefore, the corresponding communication component 705 can include a Wi-Fi module, a Bluetooth module, an NFC module, and the like.

[0083] In an exemplary embodiment, the electronic device 700 can be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, micro-controllers, microprocessors, or other electronic elements for performing the above-mentioned optical fiber communication networking data security transmission method.

[0084] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the above-mentioned optical fiber communication networking data security transmission method. For example, the computer-readable storage medium can be the above-mentioned memory 702 including program instructions, and the above-mentioned program instructions can be executed by the processor 701 of the electronic device 700 to complete the above-mentioned optical fiber communication networking data security transmission method.

[0085] In another exemplary embodiment, a computer program product is also provided, which contains a computer program capable of being executed by a programmable device, and the computer program has code portions for executing the above-mentioned optical fiber communication networking data security transmission method when executed by the programmable device.

[0086] The preferred embodiments of the present disclosure are described in detail above with reference to the accompanying drawings, but the present disclosure is not limited to the specific details in the above-described embodiments. Within the technical concept scope of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all belong to the protection scope of the present disclosure.

[0087] In addition, it should be noted that each specific technical feature described in the above-described specific embodiments can be combined in any appropriate manner without contradiction. In order to avoid unnecessary repetition, various possible combinations are not described again in the present disclosure.

[0088] In addition, any combination of various different embodiments of the present disclosure can also be made, as long as it does not deviate from the idea of the present disclosure, and it should also be considered as the disclosed content of the present disclosure.

[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can still be modified, or some or all of the technical features can be replaced by equivalent replacements; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application, and they should be covered in the scope of the claims and the description of the present application.

Claims

1. A method for secure transmission of data in fiber optic communication networking, comprising: The method comprises the following steps: acquiring a basic tuning amplitude and a basic tuning frequency according to fiber communication networking, and acquiring an ith pseudo-random number synchronized at the sending end and the receiving end in an ith time period; acquiring a wavelength disturbance amplitude of a channel between the sending end and the receiving end, and acquiring a maximum pseudo-random number; acquiring a polarization tuning amount corresponding to the ith time period according to the basic tuning amplitude, the basic tuning frequency, the wavelength disturbance amplitude, the maximum pseudo-random number, and the ith pseudo-random number; wherein the polarization tuning amount corresponding to the ith time period is represented as: ; wherein, is the polarization tuning amount corresponding to the ith time period, is a base tuning amplitude, is a wavelength perturbation amplitude, is a base tuning frequency, is the ith pseudo-random number, is the maximum pseudo-random number; acquiring a reference time slot length and a maximum time slot length, and acquiring a time slot allocation length corresponding to the ith time period based on a time slot allocation model, the reference time slot length, the maximum time slot length, and the polarization tuning amount corresponding to the ith time period; The time slot allocation model is represented as: ; wherein, is the time slot allocation length corresponding to the i-th time period, is the reference time slot length, is the maximum time slot length, is the polarization tuning amount corresponding to the i-th time period; performing optical signal data transmission from the sending end to the receiving end in the ith time period according to the polarization tuning amount corresponding to the ith time period and the time slot allocation length, and acquiring a time slot record length of the optical signal data in the ith time period at the receiving end; acquiring a transmission adjustment strategy according to the time slot record length and the time slot allocation length, and performing subsequent transmission according to the transmission adjustment strategy.

2. The method of claim 1, wherein, The acquiring of the transmission adjustment strategy according to the time slot record length and the time slot allocation length comprises the following steps: when the difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, judging whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold; if yes, stopping the optical signal data transmission; if no, skipping the ith time period to enter an (i+1)th time period, acquiring an (i+1)th pseudo-random number synchronized at the sending end and the receiving end in the (i+1)th time period, re-acquiring the polarization tuning amount corresponding to the (i+1)th time period and the time slot allocation length, and performing optical signal data transmission from the sending end to the receiving end in the (i+1)th time period according to the polarization tuning amount corresponding to the (i+1)th time period and the time slot allocation length.

3. The method of claim 1, wherein the method further comprises: The acquiring of the ith pseudo-random number synchronized at the sending end and the receiving end in the ith time period comprises the following steps: the sending end and the receiving end exchange an initial seed parameter of a pseudo-random number generator through a secure channel in an initial communication stage; at the beginning of each subsequent time period, the sending end and the receiving end independently generate the same pseudo-random number based on the initial seed parameter and a predefined update rule.

4. An optical fiber communication networking data security transmission system, characterized by, The system is used to implement the optical fiber communication networking data secure transmission method according to any one of claims 1 to 3, and the system comprises: a polarization tuning module, configured to acquire a basic tuning amplitude and a basic tuning frequency according to fiber communication networking, acquire an ith pseudo-random number synchronized at the sending end and the receiving end in an ith time period, and acquire a polarization tuning amount corresponding to the ith time period according to the basic tuning amplitude, the basic tuning frequency, and the ith pseudo-random number; a time slot allocation module, configured to acquire a reference time slot length and a maximum time slot length, and acquire a time slot allocation length corresponding to the ith time period based on a time slot allocation model, the reference time slot length, the maximum time slot length, and the polarization tuning amount corresponding to the ith time period. The transmission execution module is configured to perform optical signal data transmission from the sending end to the receiving end in the i th time period according to the polarization tuning amount corresponding to the i th time period and the time slot allocation length in the i th time period, and obtain the time slot record length of the optical signal data in the i th time period at the receiving end. The feedback processing module is configured to obtain a transmission adjustment strategy according to the time slot record length and the time slot allocation length, and perform subsequent transmission according to the transmission adjustment strategy.

5. The fiber optic communication networking data security transmission system of claim 4, wherein, The feedback processing module is further configured to: when the difference between the time slot record length and the time slot allocation length exceeds a first preset threshold, determine whether the difference between the time slot record length and the time slot allocation length exceeds a second preset threshold; if yes, stop the optical signal data transmission; if no, skip the i th time period and enter an i + 1 th time period, obtain an i + 1 th pseudo-random number synchronized at the sending end and the receiving end in the i + 1 th time period, re-obtain the polarization tuning amount corresponding to the i + 1 th time period and the time slot allocation length, and perform optical signal data transmission from the sending end to the receiving end in the i + 1 th time period according to the polarization tuning amount corresponding to the i + 1 th time period and the time slot allocation length in the i + 1 th time period.

6. An electronic device, comprising: The memory has a computer program stored thereon; The processor is configured to execute the computer program in the memory to implement the optical fiber communication networking data security transmission method in any one of claims 1 to 3. The program is executed by the processor to implement the optical fiber communication networking data security transmission method in any one of claims 1 to 3.

7. A non-transitory computer-readable storage medium having stored thereon a computer program, characterized in that, ​

Citation Information

Patent Citations

  • Continuous variable quantum key distribution method capable of resisting actual attack

    CN106788706A

  • Information security transmission method based on photon noise aliasing multi-system transformation

    CN112468236A