Quantum communication method, device and system
By establishing a secure channel between the key management device and the QKD device and performing quantum key fusion processing, the problem of interoperability between QKD devices from different manufacturers and with different technical systems has been solved, enabling the low-cost, high-efficiency construction and large-scale application of quantum secure communication networks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-14
AI Technical Summary
In existing space-to-ground quantum secure communication networks, QKD devices from different manufacturers and with different technical systems cannot achieve effective and convenient interconnection, resulting in low efficiency and high cost in network construction and application, making it difficult to achieve large-scale application.
By establishing a secure channel between the key management device and the QKD device, the quantum key is obtained and fused, enabling the docking and key relay of different types of QKD devices, and ultimately achieving the unified distribution of quantum key data.
It enhances the flexibility and scalability of quantum secure communication networks, reduces the complexity and cost of network construction and maintenance, supports mixed deployment of different vendors or protocols, and optimizes network performance.
Smart Images

Figure CN121396463B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum communication technology, and in particular to a quantum communication method, device and system. Background Technology
[0002] Quantum key distribution (QKD) uses quantum systems to prepare, transmit, receive, and purify information to obtain a secure symmetric key that cannot be stolen in terms of physical principles. This process ensures that the keys obtained by the communicating parties are completely consistent, and no third party can obtain any information about the key.
[0003] In the quantum communication network architecture, the quantum layer consists of QKD devices designed and implemented according to the quantum key distribution protocol to produce quantum keys, while the key management layer consists of a key manager that interfaces with the QKD devices to obtain quantum keys and outputs quantum keys to users (cryptographic applications / cryptographic systems).
[0004] Quantum key distribution can transmit quantum optical signals using fiber optic channels and free-space (atmospheric) channels. Currently, space-to-ground quantum secure communication networks mainly rely on different ground stations interconnecting via quantum satellites, or providing key services after interoperating with key relay routing equipment offline or online. Heterogeneous interconnection with the entire fiber optic quantum secure communication network remains limited. Furthermore, the construction and application of quantum secure communication networks involve devices from different manufacturers using different technologies and employing completely different interoperability methods. For example, different manufacturers use Gaussian modulation continuous variable QKD, phase-based discrete variable QKD, and polarization-based discrete variable QKD, making effective and convenient interconnection impossible. This severely impacts the low-cost, high-efficiency construction and large-scale application of quantum secure communication networks. Summary of the Invention
[0005] The purpose of this application is to provide a quantum communication method, device and system that can facilitate the heterogeneous interconnection and hybrid networking of QKD devices with different technical systems in free space, especially in space-to-ground and fiber optic modes, so as to enable the low-cost and high-efficiency construction and large-scale application of quantum secure communication networks.
[0006] To address the aforementioned technical problems, this application provides a quantum communication method applied to a key management device. The key management device acquires the quantum key of a QKD device and outputs the quantum key to an application layer. The key management device is used to connect to at least one QKD device. The method includes: establishing a secure channel with the QKD device, wherein the secure channel is used for at least quantum key transmission between the key management device and the QKD device; when there are multiple QKD devices, and at least two of the multiple QKD devices belong to different categories, the quantum keys from the different categories of QKD devices are fused and then sent to the application layer.
[0007] This application also provides a key management device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method described above.
[0008] This application also provides a heterogeneous hybrid networking system based on quantum communication, comprising: multiple relay nodes, each relay node including a key management device as described above and at least one QKD device connected to the key management device, at least some of the relay nodes including at least two different types of QKD devices, the relay nodes being interconnected through QKD devices of the same type, and / or the relay nodes being interconnected through the key management device.
[0009] The quantum communication method in this application establishes a secure channel between a key management device and a QKD device to obtain quantum keys. Furthermore, after obtaining quantum keys from different types of QKD devices through this secure channel, the quantum keys are fused to enable the interconnection of different QKD devices and complete key relay, ultimately achieving unified distribution of quantum key data. This significantly enhances the flexibility and scalability of quantum secure communication networks, allowing operators to deploy QKD devices from different vendors or using different protocols as needed to optimize cost and performance. For example, the key management device can enable heterogeneous interconnection between ground station QKDs used for connecting to quantum satellites and fiber optic QKDs used in fiber optic quantum secure communication networks. This significantly reduces the complexity and cost of network construction and subsequent maintenance, facilitating the low-cost and high-efficiency construction and large-scale application of quantum secure communication networks. Attached Figure Description
[0010] Figure 1 A flowchart illustrating a quantum communication method provided in an embodiment of this application;
[0011] Figure 2 A flowchart illustrating a quantum communication method provided in another embodiment of this application;
[0012] Figure 3 A schematic diagram illustrating the connection and data transmission between a key management device and a QKD device provided in an embodiment of this application;
[0013] Figure 4 This is a schematic diagram of the structure of a session key provided in an embodiment of this application;
[0014] Figure 5 This is a structural block diagram of a key management device provided in an embodiment of this application;
[0015] Figure 6 A schematic diagram of the network structure of a heterogeneous hybrid networking system based on quantum communication provided in an embodiment of this application;
[0016] Figure 7 A schematic diagram of the network structure of a heterogeneous hybrid networking system based on quantum communication, provided for another embodiment of this application;
[0017] Figure 8 A schematic diagram illustrating the process of quantum key transmission between two user nodes using a push mode, as provided in an embodiment of this application;
[0018] Figure 9 This is a schematic diagram illustrating the process of two user nodes transmitting quantum keys in a request mode, as provided in an embodiment of this application. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been provided in the various embodiments of this application to help readers better understand this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various changes and modifications based on the following embodiments. The division of the various embodiments below is for the convenience of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.
[0020] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more features. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0021] In related technologies, the space-to-ground quantum secure communication network mainly involves different ground stations interconnecting using quantum satellites, or providing key services to the outside world after interconnecting with key relay routing equipment through offline or online methods. However, there are still limitations in heterogeneous interconnection with the entire fiber optic quantum secure communication network. Moreover, in the construction and application of quantum secure communication networks, there are devices from different manufacturers with completely different docking methods implemented by different technical systems. For example, there are Gaussian modulation continuous variable QKD, phase-mode discrete variable QKD, and polarization-mode discrete variable QKD involved by different manufacturers. Effective and convenient interconnection cannot be achieved, which seriously affects the low-cost and high-efficiency construction and large-scale application of quantum secure communication networks.
[0022] In view of this, this application proposes a quantum communication method applied to a key management device. The key management device is used to acquire quantum keys from QKD devices and output the quantum keys to an application layer. The key management device is used to connect to at least one QKD device. The method includes: establishing a secure channel with the QKD device, wherein the secure channel is used for at least quantum key transmission between the key management device and the QKD device; when there are multiple QKD devices, and at least two of the multiple QKD devices are of different categories, the quantum keys from the different categories of QKD devices are fused and then sent to the application layer. The quantum communication method of this application establishes a secure channel between the key management device and the QKD device to acquire quantum keys. Furthermore, after acquiring quantum keys from different categories of QKD devices through the secure channel, the quantum keys are fused to achieve the connection of different QKD devices and complete key relay, ultimately realizing the unified distribution of quantum key data. This not only greatly enhances the flexibility and scalability of quantum secure communication networks, allowing operators to deploy QKD devices from different vendors or using different protocols as needed to optimize cost and performance, for example, enabling heterogeneous interconnection between ground station QKDs used for docking quantum satellites and fiber optic QKDs used for fiber optic quantum secure communication networks through key management devices. This significantly reduces the complexity and cost of network construction and subsequent maintenance, facilitating the low-cost and high-efficiency construction and large-scale application of quantum secure communication networks. The implementation details of the quantum communication method in the embodiments of this application are described below. These details are provided for ease of understanding and are not essential for implementing this solution.
[0023] Reference Figure 1 As shown, Figure 1This is a schematic flowchart illustrating a quantum communication method provided in one embodiment of this application. This application proposes a quantum communication method applied to a key management device. The key management device is used to acquire the quantum key of a QKD device and output the quantum key to the application layer. The key management device is used to connect to at least one QKD device.
[0024] The quantum communication method provided in this application embodiment is executed by a key management device, which acts as the core hub between the quantum layer and the application layer. It is responsible for obtaining quantum keys from at least one connected QKD device, processing them, and then outputting them to the application layer.
[0025] The key management device has the capability to connect multiple QKD devices. Depending on actual needs, it connects a specific number and type of QKD devices to form user nodes. For example, for some ground station nodes, the key management device connects to a ground station QKD; for others, it connects to both a ground station QKD and a type of fiber optic QKD; and for still others, it may connect only to fiber optic QKDs, such as connecting one or more fiber optic QKDs of different types. These QKD devices of the same and different types form the quantum layer. The key management device also connects to the application layer, for example, connecting to the application layer composed of cryptographic applications / cryptographic systems.
[0026] The method includes:
[0027] Step 100: Establish a secure channel with the QKD device, wherein the secure channel is used for at least quantum key transfer between the key management device and the QKD device.
[0028] The key management device establishes an independent secure channel with each connected QKD device. This secure channel is the foundation for all subsequent key operations and is constructed using two-way authentication and data encryption technologies (e.g., using a pre-shared seed key or encryption using an initial quantum key). This ensures the integrity and confidentiality of the quantum key transmission from the QKD device to the key management device, preventing the key from being stolen or tampered with during transmission.
[0029] Step 200: When there are multiple QKD devices, and at least two of the multiple QKD devices are of different categories, the quantum keys from the different categories of QKD devices are fused and then sent to the application layer.
[0030] When a key management device connects to multiple QKD devices, and at least two of them are of different types—for example, connecting a ground station QKD and a fiber optic QKD, or connecting two different types of fiber optic QKD (such as a Gaussian-modulated continuous-variable QKD device and a polarization-mode discrete-variable QKD device)—the key management device can fuse the keys transmitted from these different types of QKD devices. For instance, the key management device first normalizes the original quantum keys, which have varying formats and characteristics, received from each type of QKD device, such as unifying them into a standard bit string format. Then, through cryptographic algorithms such as key linking, XOR operations, or hash-based key derivation, these key materials from different sources are fused to generate a new and unified final key. This final key is then sent to the application layer for direct use by upper-layer cryptographic applications.
[0031] Therefore, the quantum communication method in this application establishes a secure channel between a key management device and a QKD device to obtain quantum keys. Furthermore, after obtaining quantum keys from different types of QKD devices through this secure channel, the quantum keys are fused to enable the docking of different QKD devices and complete key relay, ultimately achieving unified distribution of quantum key data. This significantly enhances the flexibility and scalability of the quantum secure communication network, allowing operators to deploy QKD devices from different vendors or using different protocols as needed to optimize cost and performance. For example, the key management device can enable heterogeneous interconnection between ground station QKDs used for docking with quantum satellites and fiber optic QKDs used in fiber optic quantum secure communication networks. This significantly reduces the complexity and cost of network construction and subsequent maintenance, facilitating the low-cost and high-efficiency construction and large-scale application of quantum secure communication networks.
[0032] In an optional embodiment of this application, the step of fusing quantum keys from different types of QKD devices and sending them to the application layer includes:
[0033] The quantum keys from the different types of QKD devices are fused by byte-by-byte XOR and then sent to the application layer.
[0034] In this embodiment, the fusion processing of quantum keys transmitted by different types of QKD devices is specifically implemented through a byte-by-byte XOR operation.
[0035] The key management device can first set up corresponding key buffers to temporarily store the original quantum key streams from different types of QKD devices to ensure that the operation is feasible. The system performs preprocessing, and through padding or truncation, it processes the multiple key streams to be merged into strictly equal-length byte sequences.
[0036] During the fusion process, the bytes read from the buffer are strictly matched in position, and then a bit-by-bit XOR operation is performed on each aligned byte pair. For example, the XOR operation on byte 0xA3 (binary 10100011) from the ground station QKD and byte 0xC6 (binary 11000110) from the fiber optic QKD yields 0x65 (binary 01100101). This process iterates through all byte pairs, ultimately generating a completely new fused quantum key with the same length as the single source key. Finally, the fused quantum key is transmitted to cryptographic applications or cryptographic management systems to realize quantum key applications.
[0037] In this embodiment, quantum keys from QKD devices based on different physical principles and protocols are deeply fused. This process is simple and efficient, with low computational complexity and low processing latency due to the XOR operation, thus ensuring real-time key service. Furthermore, the security of the fused key is built upon all the original quantum keys involved in the XOR operation. As long as any one of these keys is secure, the final key is secure, effectively preventing the risk of a single QKD device or channel being compromised. Ultimately, this unified fusion method logically and completely shields the heterogeneity of the underlying devices, providing a standardized key interface for upper-layer applications, thereby facilitating low-cost and high-efficiency interconnection of heterogeneous quantum networks.
[0038] Reference Figure 2 As shown, in an optional embodiment of this application, the key management device has a first data interface and a second data interface; establishing a secure channel with the QKD device includes:
[0039] Step 101: Transmit a session key to the QKD device through the first data interface, so that the QKD device can authenticate the key management device based on the session key;
[0040] Step 102: Complete the identity authentication based on the QKD device and establish the secure channel with the QKD device based on the second data interface.
[0041] In this embodiment, the key management device can be configured with two physically isolated data interfaces: a first data interface and a second data interface. Correspondingly, the QKD device also has a first data interface and a second data interface (or has a connecting cable connecting the first data interface and the second data interface). The first data interface and the second data interface can be data interfaces commonly found in electronic devices. In a specific implementation, the first data interface can be a USB interface based on a smart cryptographic key, which is used to transmit a preset session key and is dedicated to the transmission of highly secure initial authentication information. The second data interface can be a standard network interface, which can at least undertake the subsequent large-scale quantum key transmission tasks.
[0042] Reference Figure 3 As shown, both the key management device and the QKD device include a USB interface and an Ethernet port. The USB interface is based on the smart cryptographic key Ukey and serves as the primary data interface, allowing the key management device to transmit preset keys (session keys) to the QKD device. For example, it can be used to import preset session key files offline from the key management device to the QKD device. The Ethernet port is used for the exchange of quantum keys and message data between the QKD device and the key management device, as well as for reporting QKD device status information.
[0043] In an optional embodiment, the process of establishing a secure channel specifically includes the following steps: In the first stage, the key management device actively transmits a preset session key to the connected QKD device through its USB interface. After receiving this key, both parties authenticate and negotiate to establish a high-bandwidth secure channel based on the network interface (which can be divided into different network interfaces for service / management as needed). This channel typically uses the session key transmitted in this transmission or a key derived from it for encryption and integrity protection. All subsequent transmissions of quantum keys are carried out through this channel.
[0044] Therefore, in this embodiment, QKD devices from different manufacturers and with different technical systems can access the key management device through a unified interface. The data interface used is a highly universal interface, which facilitates unified adaptation of external keys and management interfaces for various QKD devices. Specifically, the scheme of physically separating the authentication channel and the data channel uses the session key transmitted through the first data interface for initial authentication and subsequent encryption, preventing unauthorized devices from accessing the system. The second data interface is used for efficient quantum key and other data transmission. This improves the overall security of the system and allows standardized network interfaces to be fully utilized in a secure environment, simplifying system cabling and configuration.
[0045] In an optional embodiment of this application, the session key includes a data encryption key, a transmission encryption key, and a message authentication key, wherein the data encryption key, the transmission encryption key, and the message authentication key sequentially constitute the front byte, the middle byte, and the back byte of the data transmission session key.
[0046] Reference Figure 4As shown, in this embodiment, the key management device and the QKD device share a 48-byte data transmission session key via a USB interface. The first 16 bytes are the data encryption key (DEK), the middle 16 bytes are the transmission encryption key (TEK), and the last 16 bytes are the message authentication key (MAK). The data encryption key is used to protect the confidentiality of quantum key data transmitted between the key management device and the QKD device via the network port; the message authentication key is used to protect the integrity of quantum key data transmitted between the key management device and the QKD device via the network port; and the transmission encryption key is used to encrypt and protect the session key transmitted between the key management device and the QKD device via the USB interface, such as protecting the next session key update.
[0047] Therefore, in this embodiment of the application, a method of segmenting by fixed order and function is adopted to provide independent and conflict-free key materials for different security requirements (encryption and integrity) during the establishment of a secure channel and the subsequent data transmission of quantum keys, thereby avoiding potential security risks that may be caused by the multiple uses of a single key.
[0048] In an optional embodiment of this application, the quantum communication method further includes:
[0049] A new session key is generated and sent to the QKD device to complete the update of the session key in the QKD device, wherein the transmission encryption key of the new session key is the same as the transmission encryption key of the original session key.
[0050] In this embodiment, the key management device can generate a new session key according to a predetermined security management strategy (e.g., periodic updates or updates based on usage frequency), protect it with the existing transmission encryption key, and then distribute it online to the QKD device for key updates. The key management device can initiate key updates when no other services are in operation.
[0051] When generating a new session key, the new transport encryption key remains consistent with the original (i.e., the one currently in use) transport encryption key. This balances security and business continuity. By updating the data encryption key and message authentication key, the security of quantum key encryption is improved, meeting the need for periodic updates to enhance security. Simultaneously, keeping the transport encryption key unchanged ensures that large-scale quantum key transfer processes conducted through secure channels will not be interrupted or require channel renegotiation due to key updates, thus guaranteeing the continuity and stability of the key supply service.
[0052] In an optional embodiment of this application, the key management device is associated with at least one other key management device; the method further includes:
[0053] When there is a demand for quantum keys, the QKD device connected to the key management device pushes the quantum key, and other QKD devices connected to the key management device push the quantum key synchronously until the number of quantum keys in the key management device meets the demand.
[0054] It is understandable that in a quantum communication network, each key management device can establish a logical association with at least one other key management device in the network. This association forms a collaborative key management cluster, designed to address scenarios where the key production capacity of a single node is insufficient or where cross-domain key supply is required. For example, in a scenario requiring cross-domain quantum key supply, the two associated key management devices send quantum keys to the application layer for encryption and decryption.
[0055] In this embodiment, when a key management device has a quantum key requirement, for example, when the local key management device detects that the key quantity of its own key pool is lower than a preset low threshold, it initiates a distributed key supply process. First, it causes the QKD devices connected to it to start or prepare to push quantum keys. Second, through the coordination channel between key management devices, it causes the QKD devices connected to other associated key management devices to synchronously start the same key push process.
[0056] In this context, "push" can refer to actively generating and pushing, or extracting and sending keys from the QKD device's key pool.
[0057] The keys generated by all participating QKD devices are ultimately aggregated at the key management device that initiated the request. The quantum keys from different QKD devices are then fused through a byte-by-byte XOR process by the key management device. When the accumulated number of keys in the current key management device reaches a threshold sufficient to meet the demand, a stop command is sent to the other participating devices. This achieves mutual coordination among the key management devices, significantly improving the reliability and supply capacity of the key service in the entire quantum secure communication network, and providing a foundation for building a large-scale and highly available quantum network.
[0058] In an optional embodiment of this application, the step of having the QKD device connected to the key management device push the quantum key when there is a quantum key requirement, and having other QKD devices connected to the key management device simultaneously push the quantum key, includes:
[0059] Send first key production information to the QKD device connected to the key management device, so that the QKD device responds to the first key production information and begins the production of the quantum key;
[0060] Send the second key production information to the other key management devices so that the other key management devices can forward the second key production information to the QKD device connected to them, so that the QKD device responds to the second key production information and starts the production of the quantum key;
[0061] The device receives a quantum key pushed by a QKD device connected to the key management device, wherein the QKD device connected to the key management device is used to cooperate with other QKD devices connected to the key management device to perform a quantum key consistency check, and after the quantum key consistency check is completed, pushes the quantum key to the key management device.
[0062] For QKD devices that have no key pool or only a small amount of key data cache, after the key management device notifies the QKD device to start production, the QKD device pushes a consistent quantum key to the two associated key management devices.
[0063] Specifically, the current key management device sends the first key production information to the local QKD device directly connected to it. The local QKD device responds to this information and immediately initiates the quantum key preparation process. Simultaneously, the current key management device sends the second key production information to other associated key management devices via the network. Upon receiving this information, the other key management devices forward it to their connected peer QKD devices, triggering the peer QKD devices to synchronously initiate quantum key production.
[0064] Subsequently, the local QKD device and the peer QKD device will perform quantum negotiation and processing according to the QKD protocol to jointly generate a batch of consistent quantum keys. During this process, quantum key consistency checks (such as parameter estimation, error correction, and privacy amplification) will be performed to ensure that the quantum keys obtained by both parties are completely identical and secure. After the consistency check is completed, the local QKD device and the peer QKD device will proactively push this batch of newly generated consistent quantum keys to their respective key management devices to meet their own needs.
[0065] Therefore, the quantum communication method in this application embodiment can realize the synchronous on-demand production of keys across regions. It ensures that when demand is triggered, multiple geographically isolated QKD devices can work together to produce completely consistent keys and distribute them in real time, avoiding a large amount of key pre-storage at the QKD device end. It is suitable for providing instant and synchronous quantum keys for temporary secure communication sessions.
[0066] In an optional embodiment of this application, the step of having the QKD device connected to the key management device push the quantum key when there is a quantum key requirement, and having other QKD devices connected to the key management device simultaneously push the quantum key, includes:
[0067] A first key request message is sent to a QKD device connected to the key management device, so that the QKD device responds to the first key request message and pushes the stored quantum key to the key management device. The other QKD devices connected to the key management device are used to push the same quantum key to the other key management devices according to the notification from the QKD devices connected to the key management device.
[0068] If the QKD device has a key pool, the key management device can query the QKD device to see if the required number of keys has been pre-stored. If so, it can request to obtain quantum keys until the key management device meets the key quantity requirements and then stops obtaining keys.
[0069] Specifically, the current key management device sends a first key request message to its local QKD device. This request process can be step-by-step: first, a query message is sent to inquire about the key pool status; after receiving a positive response, a formal request message is sent; the local QKD device responds to this request by pushing the available quantum keys pre-stored in its own key pool to the current key management device.
[0070] To ensure that the key management devices at the communication peers obtain the same key, this embodiment utilizes a collaborative mechanism of QKD devices. When the local QKD device responds to a request from the current key management device, it notifies its paired peer QKD devices connected to by other key management devices. Upon receiving the notification from its peer node, the peer QKD device finds a key segment from its own key pool that is identical to the key provided by the local QKD device and actively pushes it to its connected key management device. In this way, the current key management device and its associated other key management devices obtain the same quantum key.
[0071] The key management device in this application embodiment can utilize the QKD device's fast response based on pre-stored keys and the existing key pool of the QKD device, eliminating the waiting time for real-time production. It can meet the key requirements of the key management device with extremely low latency. Combined with the active notification mechanism between QKD devices, it solves the problem of key synchronization and consistency acquisition in a distributed environment, making it suitable for providing fast key supply services for services with high real-time requirements.
[0072] Figure 5 A key management device provided in one embodiment of this application includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method described above.
[0073] The memory and processor can be connected via a bus, which can include any number or type of interconnecting buses and bridges, connecting various circuits of one or more processors and memories. The bus can also connect various other circuits, such as peripheral devices, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by the processor is transmitted over the wireless medium via an antenna, which further receives data and transmits it to the processor.
[0074] The processor manages the bus and general processing, and also provides various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory can also be used to store data used by the processor during operation.
[0075] Reference Figure 6 and Figure 7 As shown in the embodiments of this application, a heterogeneous hybrid networking system based on quantum communication is also provided, including:
[0076] Multiple relay nodes, each of the relay nodes including the key management device as described above and at least one QKD device connected to the key management device, at least some of the relay nodes including at least two different categories of the QKD devices, the relay nodes being interconnected through the same category of QKD devices, and / or the relay nodes being interconnected through the key management device.
[0077] The key management device in this application plays a relay switching role in quantum communication networks, and therefore can also be called a key router device. Figure 6 In the diagram, relay nodes are specifically user nodes A-D. These user nodes can include ground station nodes (whose key management equipment includes ground station QKD) and fiber optic nodes (whose key management equipment includes fiber optic QKD). Each node is connected through a backbone network and a metropolitan area network. The ground station QKD of the ground station node is connected through a quantum satellite. Figure 7 In this quantum communication network, key management devices constitute the key management layer, ground station QKDs connected to each key management device and different types of fiber QKDs (fiber QKD type 1, fiber QKD type 2, fiber QKD type 3, etc.) constitute the quantum layer, and cryptographic applications / cryptographic systems connected to each key management device constitute the application layer.
[0078] The processor of the key management device has a heterogeneous-hybrid networking plug-in module to execute the quantum communication method described above. Through the key management device, a unified physical interface with the QKD device is achieved. The heterogeneous-hybrid networking plug-in module in the key management device implements the corresponding unified interface protocol, thereby enabling heterogeneous-hybrid networking with ground station QKD devices and different types of fiber optic QKD devices.
[0079] In an optional embodiment, the process of hybrid networking and interaction between the key management device and the QKD device is divided into the following stages:
[0080] Initial setup: The key management device exports the pre-set session key to the QKD device to be connected via the USB interface.
[0081] Chain establishment phase: The network ports of the key management device and the QKD device are used for identity authentication to establish a secure channel.
[0082] Operational phase: When it is necessary to obtain quantum keys, the key management device obtains quantum keys from the QKD device in two modes: push (QKD device has no key pool or only a small amount of key data cache) and request (QKD device has key pool). Each mode corresponds to a different interface process and is carried out after the QKD device is authenticated by the key management device.
[0083] In push mode, when the number of keys in the key management device falls below the minimum threshold, a message is sent to the QKD device to notify it to start key production. The key management device then continuously pushes keys to the key management device until its quantum key pool reaches the maximum threshold. Only then does the key management device send a message to the QKD device to stop key production. (See reference...) Figure 8 The diagram shown illustrates a process in which two user nodes transmit quantum keys using a push mode in one embodiment.
[0084] like Figure 8 middle:
[0085] 1) When the key pool of node A's key management device falls below the minimum threshold, key production begins;
[0086] 2) A sends a KeyOn message to the key management device of node B;
[0087] 3) The B-node key management device forwards the KeyOn message to the local QKD device;
[0088] 4) The B-node QKD device responds to the KeyOn message from the local key management device;
[0089] 5) Node B sends a KeyOn response message to notify Node A's key management device;
[0090] 6) The A node key management device sends a KeyOn message to the local QKD device;
[0091] 7) The QKD device responds to the KeyOn message from the local key management device;
[0092] 8) After key negotiation, both QKD devices actively push a consistent key to the key management device and send a KeySend message;
[0093] 9) The key management device stores the key in the key pool and responds with a KeySend message to the QKD device;
[0094] 10) When the number of keys in the key pool of the key management device of node A reaches the maximum threshold, key production is stopped;
[0095] 11) Send a KeyOff message to the key management device of node B;
[0096] 12) The B-node key management device sends a KeyOff message to the local QKD device;
[0097] 13) The B node QKD device responds with a KeyOff message to the local key management device;
[0098] 14) Node B's key management device sends a KeyOff response message to Node A's key management device;
[0099] 15) The A node key management device sends a KeyOff message to the local QKD device;
[0100] 16) The QKD device responds with a KeyOff message to the local key management device.
[0101] In request mode, when the number of keys in the key management device falls below the minimum threshold, the key management device actively requests keys from the QKD device. The key management device continuously sends key request requests to the QKD device until the quantum key pool in the key management device reaches the maximum threshold, at which point the key management device stops requesting keys from the QKD device. (Refer to...) Figure 9 The diagram shown illustrates a process in which two user nodes transmit quantum keys using a request mode in one embodiment.
[0102] like Figure 9 middle:
[0103] When node A's key management device actively initiates a key request:
[0104] 1) When the key of the key management device of node A is lower than the minimum threshold, a KeyPrepare key query message is sent;
[0105] 2) If node A's QKD device has the key, it will respond with a KeyReady message;
[0106] 3) Node A's key pool sends a key application message, KeyApply;
[0107] 4) Node A's QKD device responds to the KeyRelay message, returning the key;
[0108] 5) At the same time, the QKD device of node A notifies the QKD device of node B to push the same key;
[0109] 6) The QKD device of node B actively pushes the KeyRelay message to the key management device of node B, and then performs subsequent quantum key transmission.
[0110] When the B node's key management device actively initiates a key request:
[0111] 1) When the key pool of the B node key management device is below the minimum threshold, a KeyPrepare key query message is sent;
[0112] 2) If the QKD device at node B has the key, it will respond with a KeyReady message;
[0113] 3) The B-node key management device sends a key application message KeyApply;
[0114] 4) The B-node QKD device responds to the KeyRelay message and returns the key;
[0115] 5) At the same time, the QKD device of node B notifies the QKD device of node A to push the same key;
[0116] 6) The QKD device of node A actively pushes the KeyRelay message to the key management device of node A, and then performs subsequent quantum key transmission.
[0117] During operation, QKD devices can also report heartbeat monitoring and abnormal device status to the key management device.
[0118] Key update phase: The key management device generates a new data transmission session key according to a predetermined security management policy, protects it with the original transmission encryption key, and then distributes it online to the QKD device to update the key. The key management device can initiate a key update when no other business is in progress.
[0119] The key management device and the heterogeneous hybrid networking system based on quantum communication in this application have similar technical effects to the aforementioned quantum communication methods, and will not be described in detail here.
[0120] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.
Claims
1. A quantum communication method, characterized in that, The method is applied to a key management device, which is used to acquire the quantum key of a QKD device and output the quantum key to an application layer, and the key management device is used to connect to at least one QKD device; the method includes: A secure channel is established with the QKD device, wherein the secure channel is used for at least quantum key transfer between the key management device and the QKD device; When there are multiple QKD devices, and at least two of the multiple QKD devices are of different categories, the quantum keys from the different categories of QKD devices are fused and then sent to the application layer. The key management device is associated with at least one other key management device; the method further includes: When there is a demand for quantum keys, the QKD device connected to the key management device pushes the quantum key, and other QKD devices connected to the key management device push the quantum key synchronously until the number of quantum keys in the key management device meets the demand.
2. The quantum communication method according to claim 1, characterized in that, The step of fusing quantum keys from different types of QKD devices and sending them to the application layer includes: The quantum keys from the different types of QKD devices are fused by byte-by-byte XOR and then sent to the application layer.
3. The quantum communication method according to claim 1, characterized in that, The key management device has a first data interface and a second data interface; Establishing a secure channel with the QKD device includes: The session key is transmitted to the QKD device through the first data interface so that the QKD device can authenticate the key management device based on the session key. The identity authentication is completed based on the QKD device, and a secure channel is established with the QKD device based on the second data interface.
4. The quantum communication method according to claim 3, characterized in that, The session key includes a data encryption key, a transmission encryption key, and a message authentication key, wherein the data encryption key, the transmission encryption key, and the message authentication key sequentially constitute the first, middle, and last bytes of the data transmission session key.
5. The quantum communication method according to claim 4, characterized in that, Also includes: A new session key is generated and sent to the QKD device to complete the update of the session key in the QKD device, wherein the transmission encryption key of the new session key is the same as the transmission encryption key of the original session key.
6. The quantum communication method according to claim 1, characterized in that, The step of instructing the QKD device connected to the key management device to push the quantum key when a quantum key is required, and instructing other QKD devices connected to the key management device to simultaneously push the quantum key, includes: Send first key production information to the QKD device connected to the key management device, so that the QKD device responds to the first key production information and begins the production of the quantum key; Send the second key production information to the other key management devices so that the other key management devices can forward the second key production information to the QKD device connected to them, so that the QKD device responds to the second key production information and starts the production of the quantum key; The device receives a quantum key pushed by a QKD device connected to the key management device, wherein the QKD device connected to the key management device is used to cooperate with other QKD devices connected to the key management device to perform a quantum key consistency check, and after the quantum key consistency check is completed, pushes the quantum key to the key management device.
7. The quantum communication method according to claim 1, characterized in that, The step of instructing the QKD device connected to the key management device to push the quantum key when a quantum key is required, and instructing other QKD devices connected to the key management device to simultaneously push the quantum key, includes: A first key request message is sent to a QKD device connected to the key management device, so that the QKD device responds to the first key request message and pushes the stored quantum key to the key management device. The other QKD devices connected to the key management device are used to push the same quantum key to the other key management devices according to the notification from the QKD devices connected to the key management device.
8. A key management device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method as described in any one of claims 1 to 7.
9. A heterogeneous hybrid networking system based on quantum communication, characterized in that, include: Multiple relay nodes, each of the relay nodes including the key management device as described in claim 8 and at least one QKD device connected to the key management device, at least some of the relay nodes including at least two different categories of the QKD devices, the relay nodes being interconnected through the same category of QKD devices, and / or the relay nodes being interconnected through the key management device.
Citation Information
Patent Citations
Communication encryption method, computer equipment and storage medium
CN121126333A
System, method, and apparatus for quantum key output, storage, and consistency verification
US20160359626A1
Method and system for secure distribution of symmetric encryption keys using quantum key distribution (QKD)
US20240340160A1