SSL VPN wireless communication encryption method and system based on quantum key

By analyzing key resource balance and session priority, and dynamically adjusting key generation and distribution strategies, the problem of key mismatch in quantum key SSL VPN systems is solved, enabling refined management and efficient utilization of key resources, and ensuring the stability and security of quantum encrypted communication.

CN121485931APending Publication Date: 2026-02-06FANERJIA INTELLIGENT ELECTRIC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511860773.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-11
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

In quantum key-based SSL VPN systems, the rate at which keys are generated does not match the rate at which encryption keys for SSL VPN sessions are consumed. This results in SSL VPN sessions not receiving new keys and being unable to continue secure encryption. Furthermore, the timing of new key updates during SSL VPN session switching is out of sync, leading to issues such as insufficient key allocation, premature key expiration, or delayed key activation.

Method used

By collecting key management core status parameters, analyzing key resource balance, determining resource status, determining global key exchange interval execution strategy, and combining SSL VPN session priority for resource scheduling, the key activation window and verification frequency are dynamically adjusted, the interface error rate is monitored in real time, and a retry mechanism is triggered to ensure fine-grained and dynamic scheduling of key resources.

Benefits of technology

It enables precise management of key resources, avoids key supply shortages and encryption failures, improves the system's resilience in complex scenarios, and ensures the stability, reliability, and efficient utilization of resources in quantum encrypted communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121485931A_ABST
    Figure CN121485931A_ABST
Patent Text Reader

Abstract

The invention discloses an SSL VPN wireless communication encryption method and system based on a quantum key, and belongs to the technical field of quantum key distribution, and the method comprises the following steps: analyzing the balance degree of key resources and judging the state of the resources, thereby formulating a global key exchange interval strategy, achieving the distribution and prefetching of a key quota, and achieving the encryption of the key quota. According to the SSL VPN wireless communication encryption method based on the quantum key, a key time sequence risk index is analyzed to determine a key overlapping window adjustment strategy, the SSL VPN session distribution interface error rate and the key inventory level are monitored, whether rollback needs to be executed or not is judged, and a corresponding rollback strategy is formulated, the resource state is accurately judged, meanwhile, the SSL VPN session priority is divided, and the SSL VPN wireless communication encryption efficiency is improved. The multi-link linkage of the system effectively reduces the secret key supply interruption and encryption failure probability, enables the system to achieve self-adaptive adjustment in complex scenes such as supply and demand fluctuation and network abnormity, remarkably improves the anti-risk level, and guarantees the stability and reliability of quantum encryption communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum key distribution technology, and in particular to a quantum key-based SSL VPN wireless communication encryption method and system. Background Technology

[0002] Existing quantum key SSL VPN systems typically consist of a quantum key distribution module, a key management module, and a VPN encryption tunnel module. The quantum key distribution module primarily uses a quantum channel to randomly generate and securely transmit keys, leveraging the quantum no-cloning principle and measurement interference characteristics to ensure the key distribution process cannot be eavesdropped on. The key management module stores, schedules, and updates the distributed keys, including key pool management, key allocation strategies, and matching them with the encryption requirements of SSL VPN sessions, thus ensuring a continuous key supply capability during system operation. The VPN encryption tunnel module operates based on the SSL VPN framework, using the quantum key allocated by the key management module as the SSL VPN session encryption key to establish a secure tunnel, enabling encrypted data transmission and authentication, thereby providing a high level of security protection in wireless communication environments.

[0003] For example, Chinese invention patent CN118449691A discloses a terminal information system with quantum key encryption function, comprising: a central control center and K terminal users, where K is an integer ≥ 1; the central control center and the K terminal users are connected by optical fiber, and quantum channels and classical channels are constructed by wavelength division multiplexing to realize the transmission of quantum entangled resources and ciphertext in the same physical optical fiber; the central control center includes a business information layer for collecting sensitive information in various digital scenarios for people's livelihood; a quantum key distribution layer for generating and distributing quantum entangled resources; and a quantum parallel encryption service layer for performing parallel encryption operations on the same / different information in each optical fiber channel using different keys according to specific needs; the terminal users include quantum key distribution sub-terminals, quantum decryption sub-terminals, and information processing and display sub-terminals.

[0004] For example, Chinese invention patent CN115361125B discloses a VPN network system based on quantum key technology, comprising: when an NFVO receives a request to access a node, it obtains the network topology between the accessing node and the accessed node, and sends the network topology, node configuration information, and VPN creation command as connection information to a first virtual management configuration module and a second virtual configuration management module, so that they configure the node according to the node configuration information and establish a VPN channel according to the network topology and VPN creation command; the first virtual router and the second virtual router generate quantum keys using the first QKD module and the second QKD module respectively, and use the quantum keys to perform encrypted data communication through the VPN channel.

[0005] The above-mentioned technology has at least the following technical problems:

[0006] In quantum key-based SSL VPN systems, the generation rate of keys often does not match the consumption rate of encryption keys in SSL VPN sessions. This can lead to some SSL VPN sessions not receiving new keys and being unable to continue secure encryption. Additionally, the update sequence of new keys during SSL VPN session switching may be out of sync, causing some SSL VPN sessions to be unable to obtain keys in time when encryption is needed, or for old keys to be revoked before the new keys take effect. This results in problems such as insufficient key allocation, premature expiration, or delayed activation. Summary of the Invention

[0007] On the one hand, a quantum key-based SSL VPN wireless communication encryption method is provided, which includes:

[0008] Collect key management core status parameters, analyze key resource balance, determine key resource status, and thereby determine the global key exchange interval execution strategy.

[0009] After the global key change interval execution policy is completed, the SSL VPN session priority is obtained, resource scheduling is performed, and key quotas and prefetch resources are allocated.

[0010] Collect key timing matching parameters to obtain the key timing risk index, thereby determining the key overlap window adjustment strategy, calculating the expected effective time and determining the overlap window and distribution strategy, verifying in real time and triggering the retry mechanism, and adjusting the verification frequency according to the SSL VPN session priority.

[0011] Monitor the error rate and key inventory level of the SSL VPN session distribution interface to determine the rollback adjustment needs, and determine the rollback strategy when the rollback adjustment needs are considered rollback requirements.

[0012] On the other hand, embodiments of this application provide an SSL VPN wireless communication encryption system based on quantum keys, including: a key resource management module, used to collect key management core state parameters, analyze key resource balance, determine key resource status, and determine a global key exchange interval execution strategy.

[0013] The key change interval adjustment module is used to obtain the SSL VPN session priority, perform resource scheduling, and allocate key quotas and prefetch resources after the global key change interval execution policy is completed.

[0014] The key timing adjustment module is used to collect key timing matching parameters, obtain the key timing risk index, determine the key overlap window adjustment strategy, calculate the expected effective time and determine the overlap window and distribution strategy, verify in real time and trigger the retry mechanism, and adjust the verification frequency according to the priority of SSL VPN sessions.

[0015] The rollback adjustment module is used to monitor the error rate of the SSL VPN session distribution interface and the key inventory level, determine the rollback adjustment needs, and determine the rollback strategy when the rollback adjustment needs are rollback requirements.

[0016] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following:

[0017] 1. The quantum key-based SSL VPN wireless communication encryption method provided by this invention accurately determines the resource surplus, balance, or shortage status by analyzing the key resource balance. Simultaneously, it prioritizes SSL VPN sessions. Even when resources are scarce, high-priority services only have their key exchange intervals moderately extended, prioritizing resources for core needs. To address the risk of switching gaps, a key timing risk index is generated, extending the overlap window between old and new keys and reserving sufficient time for distribution to take effect. Shortening the window avoids resource waste. Combined with real-time verification to predict lag risks, the validity period of old keys is extended in advance and distribution is triggered, eliminating switching gaps. Faced with high interface error rates, the system's multi-stage linkage effectively reduces the probability of key supply disruptions and encryption failures, enabling the system to adaptively adjust under complex scenarios such as supply and demand fluctuations and network anomalies, significantly improving its resilience and ensuring stable and reliable quantum-encrypted communication.

[0018] 2. This invention determines the resource status and, in conjunction with the SSL VPN session priority threshold, classifies SSL VPN sessions to provide a scientific basis for subsequent adjustments. This allows for a quick grasp of the true situation of abundant, balanced, or scarce key resources, avoiding blind resource management. Furthermore, it clarifies the key points of core business protection through priority differentiation, reducing encryption supply interruptions or resource waste caused by inaccurate resource perception from the source.

[0019] 3. This invention utilizes dynamic key exchange intervals and key scheduling. The global key exchange interval can be flexibly adjusted according to resource status, shortening the interval to improve security when keys are plentiful and extending the interval to save resources when keys are scarce. Differentiated adjustment at the SSL VPN session level ensures that high-priority SSL VPN sessions maintain a better key exchange frequency even when resources are tight, while low-priority SSL VPN sessions make appropriate compromises to adapt to the overall resource situation. Allocating key quotas and pre-fetching resources further optimizes resource configuration, reduces distribution delays and the risk of switching out of supply, and achieves refined and dynamic scheduling of key resources, maximizing resource utilization efficiency while ensuring the security of core businesses.

[0020] 4. This invention analyzes the key timing risk index, dynamically adapts the key activation window, and strengthens timing verification. It adjusts the basic overlap window to fundamentally avoid switching gaps. Dynamic window adjustment can balance security and resource consumption. The timing verification, combined with deviation quantification, retry mechanism, and priority verification frequency, can accurately solve the problem of key activation and SSL VPN session switching misalignment, significantly reducing the risk of switching gaps and key supply interruption. At the same time, it saves computing resources by increasing the verification frequency, taking into account both security and system operating efficiency. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart of the quantum key-based SSL VPN wireless communication encryption method provided in an embodiment of the present invention;

[0023] Figure 2 This is a diagram illustrating the key-switching interval execution strategy of the quantum key-based SSL VPN wireless communication encryption method provided in this embodiment of the invention.

[0024] Figure 3 This is a schematic diagram of the structure of the quantum key-based SSL VPN wireless communication encryption system provided in an embodiment of the present invention;

[0025] Figure 4 This is a mind map of the quantum key-based SSL VPN wireless communication encryption system provided in this embodiment of the invention. Detailed Implementation

[0026] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0027] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0028] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, their intended meanings are consistent. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, their intended meanings are consistent.

[0029] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.

[0030] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0031] like Figure 1 The flowchart shown is for a quantum key-based SSL VPN wireless communication encryption method. The processing flow of this method can include the following steps: First, analyze the key resource balance, determine the resource status, and classify the SSL VPN session priorities. Then, dynamically adjust the global key exchange interval based on the resource status, prioritize the key exchange frequency for high-priority SSL VPN sessions, and simultaneously optimize resource scheduling through priority allocation, key pre-fetching, and quota adjustment. Next, calculate the key timing risk index based on timing parameters, dynamically adjust the key activation window, and verify the switching alignment. Adapt the verification frequency according to priority. Finally, based on the SSL VPN session distribution interface error rate and key inventory, initiate a fallback strategy to ensure continuous communication.

[0032] It should be explained that the quantum key involved in this embodiment refers to a key generated and distributed based on the principles of quantum mechanics. It relies on the quantum no-cloning theorem and the principle of measurement perturbation to ensure that the key will be detected if it is eavesdropped during transmission. SSL VPN is a virtual private network implemented based on the SSL / TLS protocol. In an SSL VPN system, a secure communication connection established between the user terminal and the remote VPN gateway through the SSL / TLS protocol is called an SSL VPN session. The global key change interval refers to the key change cycle uniformly stipulated by the system.

[0033] like Figure 2 The key-switching interval execution strategy diagram of the quantum key-based SSL VPN wireless communication encryption method provided in the embodiment of the present invention is shown. First, by collecting the key management core state parameters, analyzing the key resource balance and determining the resource status, the execution strategy of the global key-switching interval is determined. Second, after the global key-switching interval strategy is completed, resource scheduling is performed according to the SSL VPN session priority, and key quota allocation and resource prefetching are carried out.

[0034] Collect key management core status parameters, analyze key resource balance, determine key resource status, and thereby determine the global key exchange interval execution strategy.

[0035] Furthermore, the key resource balance is analyzed, and the specific analysis method is as follows:

[0036] Collect key management core status parameters, including the key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate of the key interface.

[0037] A higher key supply-demand ratio indicates that the generation rate is higher than the consumption rate, which can ensure the continuous encryption needs of SSL VPN sessions and thus improve the key resource balance. When the key buffer remaining rate is high, it means that the system has enough backup key pools to maintain a stable supply when there is a short-term supply-demand imbalance, reducing the risk of supply interruption. The availability rate of the key distribution interface reflects the stability of the key transmission channel. When the interface error rate is low and the availability rate is high, the keys can be distributed and put into use in a timely manner, further enhancing the key resource balance of the system.

[0038] The key supply-demand ratio is obtained by comparing the key generation rate and the key consumption rate per unit time. The generation rate can be calculated by a quantum key distribution device or random number generator, which counts the number of keys output per second; the consumption rate is calculated by the encrypted SSL VPN session module or key distribution management unit, which counts the number of keys actually used or distributed within the same time period. The system divides the generation rate by the consumption rate to obtain the key supply-demand ratio, and this ratio can be dynamically reflected by periodic calculations to reflect the key supply-demand balance.

[0039] The key buffer remaining rate is maintained in real time by the system buffer management module. The current key buffer remaining rate can be obtained by dividing the current number of keys remaining in the buffer pool by the maximum capacity of the buffer pool, combined with the maximum number of keys that the pool can hold in the system configuration.

[0040] The availability of the key distribution interface is obtained by recording the response results of each distribution request in the system's call log, counting the number of successful interface calls and the total number of calls within a certain period of time, and dividing the number of successful distributions by the total number of requests.

[0041] The key supply-demand ratio reflects the balance between the key generation rate and the consumption rate per unit time. The larger the supply-demand ratio, the greater the generation rate is than the consumption rate. Excess keys will continuously accumulate in the buffer pool, gradually increasing the buffer surplus rate. As the buffer pool remains sufficient, most interface distribution requests can be satisfied, and the availability rate will naturally increase. The key buffer surplus rate indicates the sufficiency of available spare keys in the buffer pool. When the key buffer surplus rate is high, the interface can almost always respond instantly when it receives a distribution request, thereby ensuring that the availability rate of the key distribution interface remains at a high level.

[0042] Extract the preset key supply-demand ratio reference value, key buffer remaining rate reference value, and key distribution interface availability reference value from the database.

[0043] It should be noted that the reference values ​​for the key supply-demand ratio, buffer remaining rate, and distribution interface availability are core benchmarks for measuring system stability, used to define supply-demand balance, buffer usage, and interface capacity. When setting these reference values, data such as generation rate, consumption rate, buffer remaining capacity, and interface success rate must first be collected over multiple operating cycles. Then, statistical and trend analysis should be performed on the supply-demand ratio, buffer rate, and availability to extract the mean, range, or upper and lower limits. Finally, these values ​​are combined with average or weighted calculations and a security margin to form the preset reference values ​​in the database.

[0044] Extract the preset key supply-demand ratio feature mapping coefficient, key buffer remaining rate feature mapping coefficient, and key distribution interface availability feature mapping coefficient from the database.

[0045] It should be noted that the key supply-demand ratio feature mapping coefficient, the key buffer remaining rate feature mapping coefficient, and the key distribution interface availability rate feature mapping coefficient all range from 0 to 1, and their sum is 1. Preset values ​​can be directly extracted from the database during use. Specifically, a one-to-one mapping set is established between the key supply-demand ratio, key buffer remaining rate, and distribution interface availability rate and their corresponding feature mapping coefficients. During operation, real-time parameters are input into the set to obtain the corresponding coefficients. The aforementioned mapping set refers to establishing the correspondence between each indicator and the feature mapping coefficient through a preset interval mapping table, function model, or interpolation model. When a change in a certain indicator is detected, the system can directly look up or calculate the corresponding coefficient. Finally, after normalization processing, the sum of the three feature mapping coefficients is ensured to be 1, thereby achieving a weighted fusion evaluation of multi-source indicators and providing a basis for key management strategies.

[0046] Analyze the key resource balance based on the core status parameters of key management.

[0047] Key resource balance is a quantitative indicator of the combined impact of the key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate on SSL VPN key management resources. The specific analysis process is as follows: The key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate are compared with their corresponding reference values. The results of each comparison are coupled with their corresponding feature mapping coefficients to obtain the key resource balance.

[0048]

[0049] Where F represents the key resource balance, Q represents the key supply-demand ratio, Q0 represents the key supply-demand ratio reference value, t represents the key supply-demand ratio feature mapping coefficient, W represents the key buffer remaining rate, W0 represents the key buffer remaining rate reference value, y represents the key buffer remaining rate feature mapping coefficient, R represents the key distribution interface availability rate, R0 represents the key distribution interface availability rate reference value, and u represents the key distribution interface availability rate feature mapping coefficient.

[0050] Furthermore, the key resource status is determined to establish a global key exchange interval execution strategy. The specific analysis method is as follows:

[0051] Extract the preset key resource balance range from the database.

[0052] If the key resource balance is greater than or equal to the upper limit of the key resource balance interval, the key resource status is determined to be key surplus, and the global key exchange interval execution strategy is recorded as shortening adjustment.

[0053] It should be noted that if the key resource balance is greater than or equal to the upper limit of the key resource balance range, it means that the current key resources are sufficient or even idle. There is no need to worry about key shortages caused by sudden business needs, and there is also a resource foundation to support more frequent security operations. In this case, in order to make full use of the surplus key resources to improve the system security level, a shorter key replacement cycle is used to significantly reduce the risk of old keys being cracked. At the same time, the maintenance costs and security risks caused by long-term storage of idle keys are avoided. Therefore, the global key replacement interval execution strategy is recorded as shortening adjustment.

[0054] If the key resource balance is within the key resource balance range, the key resource status is determined to be key balanced, and the global key exchange interval execution strategy is recorded as no adjustment is needed.

[0055] It should be noted that if the key resource balance is within the key resource balance range, it means that the current number and status of keys will not be too few, resulting in no keys available when there is a sudden business demand for encryption and decryption, nor will they be too many, causing idle waste. Therefore, the key resource status is judged as key balance, which is the ideal state of key management. This indicates that the resource configuration is highly adapted to the business needs, so the global key change interval execution strategy is recorded as no adjustment is required.

[0056] If the key resource balance is less than or equal to the lower limit of the key resource balance interval, the key resource status is determined to be key shortage, and the global key exchange interval execution strategy is recorded as extension adjustment.

[0057] It should be noted that if the key resource balance is less than or equal to the lower limit of the key resource balance range, it means that the number of currently available keys is insufficient to fully cover the normal encryption and decryption needs of the business, and may even be unable to cope with sudden operations. Therefore, the resource status is judged as key shortage. In order to avoid problems such as data not being able to be decrypted or transactions not being able to be completed due to the lack of available keys, the global key exchange interval execution strategy is recorded as extended adjustment.

[0058] Furthermore, the global key-swapping interval execution strategy is analyzed in detail as follows:

[0059] Obtain the current global key change interval from the system log, and extract the preset minimum and maximum key change interval thresholds from the database.

[0060] If there is a key surplus, the global key exchange interval execution strategy is recorded as shortening adjustment. The global key exchange interval shortening value is extracted based on the deviation between the key resource balance degree and the upper limit of the key resource balance interval. The global key exchange interval update value is obtained based on the current global key exchange interval and the global key exchange interval shortening value.

[0061] It should be noted that the key resource balance deviation value is obtained by subtracting the upper limit of the key resource balance interval from the key resource balance degree. The global key change interval shortening value is determined based on the key resource balance deviation value. The global key change interval update value is obtained by subtracting the global key change interval shortening value from the current global key change interval.

[0062] In this embodiment, the system pre-defines the correspondence between the key resource balance deviation value and the global key exchange interval reduction value, and stores these rules in a configuration file or parameter table for unified invocation. During operation, the system first calculates the key resource balance deviation value to reflect the urgency of key allocation, and then searches for or calculates the matching key exchange interval adjustment range according to the preset rules. The rules can establish the correlation between the key resource balance deviation value and the key exchange interval adjustment range through interval mapping tables, function fitting, or interpolation methods. When the key resource balance deviation value is high, it indicates insufficient key supply or uneven distribution. In this case, the system needs to increase the key exchange interval to alleviate resource tension and ensure the continuity of SSL VPN session encryption; therefore, the higher the deviation value, the greater the corresponding key exchange interval adjustment range.

[0063] If there is a shortage of keys, the global key exchange interval is adjusted by a strategy called "extension adjustment". The global key exchange interval extension value is extracted based on the deviation between the key resource balance and the lower limit of the key resource balance interval. This extension is then used for differentiated adjustment at the SSL VPN session level. The specific process is as follows:

[0064] It should be noted that the absolute value of subtracting the lower limit of the key resource balance interval from the key resource balance degree is recorded as the lower limit deviation value of the key resource balance degree, and the global key exchange interval extension value is determined based on the lower limit deviation value of the key resource balance degree.

[0065] In this embodiment, the system pre-defines the correspondence between the lower limit deviation of key resource balance and the global key exchange interval extension value, and stores these rules in a configuration file or parameter table for unified invocation. During operation, the system first calculates the lower limit deviation of key resource balance to reflect the tension of key resource allocation in the system, and then searches for or calculates the matching global key exchange interval extension value according to the preset rules. This rule can establish the correlation between the lower limit deviation of key resource balance and the extension of the key exchange interval through interval mapping tables, function fitting, or interpolation methods. When the lower limit deviation of key resource balance is large, it indicates that the key supply is insufficient or unevenly distributed. At this time, the system needs to increase the global key exchange interval to alleviate resource tension and ensure the continuity of SSL VPN session encryption; therefore, the higher the deviation value, the greater the corresponding extension of the key exchange interval should be.

[0066] Extract the preset SSL VPN session priority sequence from the database, extract the extension ratio of each SSL VPN session according to the priority of each SSL VPN session, and obtain the key change interval extension update value of each SSL VPN session based on the extension ratio of each SSL VPN session and the global key change interval extension value.

[0067] In this embodiment, the system pre-defines the corresponding rules between SSL VPN session hierarchy parameters and key update interval extension ranges, and stores these rules in a configuration file or parameter table for unified invocation. The system first prioritizes each SSL VPN session based on its importance, real-time performance, and security requirements, obtaining parameters reflecting the SSL VPN session hierarchy. Then, it uses these parameters to find or calculate the matching update interval extension ratio. This rule establishes a mapping relationship between SSL VPN session priority and update interval adjustment through interval tables, function models, or interpolation models. Lower-priority SSL VPN sessions can tolerate longer update cycles, corresponding to larger extension ratios; higher-priority SSL VPN sessions have higher security and real-time requirements, allowing for smaller extension ratios, thereby ensuring the encrypted continuity and stability of core communication.

[0068] It should be added that the key change interval extension value for each SSL VPN session is obtained by multiplying the extension ratio of each SSL VPN session and the global key change interval extension value.

[0069] The minimum and maximum threshold values ​​for key exchange intervals limit the global key exchange interval shortening value and the key exchange interval extension update value for each SSL VPN session.

[0070] It's important to note that limiting the global key exchange interval shortening value and the key exchange interval extension update value for each SSL VPN session based on the minimum and maximum thresholds of the key exchange interval is essentially to define rigid boundaries for the strategy of dynamically adjusting the key exchange interval according to the key resource balance. This avoids security risks or business failures caused by excessive strategy adjustments. The minimum threshold of the key exchange interval is the bottom line for shortening the global key exchange interval. Even if a shortening adjustment is necessary due to a surplus of keys, the final shortened global key exchange interval must never be lower than the minimum threshold. This is because unlimited compression of the key exchange cycle will significantly increase system resource consumption and may also increase the security risk of short-term key inconsistency due to key synchronization time differences, thus ensuring that the global key exchange frequency is always within the system's bearable and secure range. On the other hand, the maximum threshold of the key exchange interval is the upper limit for extending the key exchange interval for each SSL VPN session. Even if an extension adjustment is necessary due to a key shortage, the final extended key exchange interval for a single SSL VPN session cannot exceed the maximum threshold. Since the SSL VPN session is directly related to the encryption security of the data stream accessed by the user remotely, if the key exchange interval is extended without limit, the risk of old keys being cracked and stolen will increase exponentially due to long-term use, and may also cause SSL key aging issues. VPN session interruption can be mitigated by using the maximum threshold to maintain the basic security baseline of SSL VPN sessions.

[0071] After the global key change interval execution policy is completed, the SSL VPN session priority is obtained, resource scheduling is performed, and key quotas and prefetch resources are allocated.

[0072] Furthermore, key quotas and prefetch resources are allocated, and the specific analysis method is as follows:

[0073] Extract the SSL VPN session priority threshold. SSL VPN sessions with a priority greater than or equal to the SSL VPN session priority threshold are recorded as high-priority SSL VPN sessions, and SSL VPN sessions with a priority less than the SSL VPN session priority threshold are recorded as low-priority SSL VPN sessions.

[0074] It should be noted that SSL VPN sessions with a priority sequence greater than or equal to the SSL VPN session priority threshold are SSL VPN sessions that the system has determined to have a core impact on business continuity and data security and that require priority protection. These SSL VPN sessions typically correspond to critical scenarios, and classifying them as high priority essentially grants them priority access to resources. SSL VPN sessions with a priority sequence less than the SSL VPN session priority threshold represent SSL VPN sessions that are less critical and urgent to the business and can be given priority when resources are scarce. These SSL VPN sessions are common in non-critical scenarios, and classifying them as low priority does not negate their necessity, but rather, when system resources are limited, resources are freed up for high-priority SSL VPN sessions through non-priority allocation.

[0075] Based on the SSL VPN session priority sequence, high-priority SSL VPN sessions are given priority in obtaining key quotas, while low-priority SSL VPN sessions only receive quotas when keys are abundant and allocation can be delayed when keys are scarce. For each SSL VPN session about to start, the time length for pre-allocating new keys is determined based on the key resource balance to avoid key supply interruption during switching. Based on the time length, the keys normally consumed by the SSL VPN session are pre-fetched from the key pool. The initial pre-fetch quantity is extracted based on the SSL VPN session, and the pre-fetch quantity is determined in combination with the key resource balance and stored in the dedicated cache area of ​​the SSL VPN session.

[0076] It should be noted that in this embodiment, the system pre-sets the corresponding rules for key resource balance and the pre-allocation time of new keys, and stores them in a configuration file or parameter table for unified invocation. The system first calculates a value reflecting the resource scarcity level based on the current key resource balance, and then searches for or calculates the matching pre-allocation time according to the preset rules. These rules establish the correlation between key resource balance and pre-allocation time through interval mapping tables, function fitting, or interpolation methods. When the key resource balance is low, the system needs to pre-allocate new keys to ensure the continuity of session encryption; the longer the pre-allocation time, the better.

[0077] It should be noted that if keys are not prepared in advance when starting or switching SSL VPN sessions, key shortages or supply interruptions may occur, causing SSL VPN session encryption to fail. This step calculates the duration of the pre-allocated new keys based on key resource balance and prefetches the normal consumption amount to ensure that each SSL VPN session obtains sufficient keys at the beginning of startup and operation. The initial prefetch quantity is extracted based on SSL VPN session priority and dynamically adjusted according to key resource balance. This can avoid excessive occupation or waste of the key pool while ensuring the security of SSL VPN sessions. In this way, the system can achieve balanced and efficient key distribution when multiple SSL VPN sessions are running simultaneously, improving the overall resource utilization. The prefetched keys are stored in a dedicated cache area for each SSL VPN session, allowing the SSL VPN session to directly access the required keys during operation, reducing frequent access to the global key pool, reducing latency and interface pressure, and enhancing the system's ability to handle high-concurrency SSL VPN sessions.

[0078] In this embodiment, the system pre-sets initial key prefetching rules for SSL VPN sessions of different priorities and stores them in a configuration file or parameter table for unified invocation. During operation, the system first obtains the SSL VPN session priority, reflecting the importance and urgency of the SSL VPN session, and then searches for or calculates the matching initial key prefetching quantity according to the preset rules. The rules can establish the correlation between SSL VPN session priority and prefetching quantity through interval mapping tables, function fitting, or interpolation methods. When the SSL VPN session priority is high, it means that the SSL VPN session has higher requirements for key continuity and encryption stability. At this time, the system increases the initial key prefetching quantity to ensure that the SSL VPN session can obtain the key in a timely manner during startup or switching phases.

[0079] It should be noted that the prefetch correction coefficient is determined based on the key resource balance, and the initial prefetch quantity is multiplied by the prefetch correction coefficient to obtain the prefetch quantity.

[0080] In this embodiment, the system pre-defines the correspondence rules between key resource balance and key prefetch correction coefficients, and stores them in a configuration file or parameter table for unified invocation. During operation, the system first calculates the key resource balance, reflecting the current balance between key allocation and usage, and then searches for or calculates the matching prefetch correction coefficient according to the preset rules. The rules can establish the correlation between key resource balance and prefetch correction coefficients through interval mapping tables, function fitting, or interpolation methods. When the key resource balance is high, it indicates a good supply-demand balance, and the prefetch correction coefficient can be reduced to decrease redundancy consumption.

[0081] Extract the communication traffic growth value of the SSL VPN session from the system log.

[0082] If the communication traffic growth value of a high-priority SSL VPN session exceeds the communication traffic growth threshold, its key quota will be temporarily increased and adjusted from the idle quota of other low-priority SSL VPN sessions. If the communication traffic growth value of all high-priority SSL VPN sessions is less than or equal to the communication traffic growth threshold, a key change interval adjustment completion signal will be generated.

[0083] It should be noted that if the communication traffic growth value of a high-priority SSL VPN session exceeds the communication traffic growth threshold, it means that the service load of that SSL VPN session has increased significantly, requiring more key resources to support it. If the key quota is insufficient, it may lead to communication delays, interruptions, or even data security risks. Therefore, the system will trigger a temporary increase in its key quota, adjusting it from the idle quotas of other low-priority SSL VPN sessions. This design avoids resource waste caused by adding quotas and ensures that the core communication needs of high-priority SSL VPN sessions are not affected through priority-oriented resource allocation. When the communication traffic growth value of all high-priority SSL VPN sessions does not exceed the threshold, it indicates that the current load of high-priority SSL VPN sessions is within a stable and controllable range, the supply and demand of key resources has adapted to the business needs, and the series of operations to adjust the key exchange interval based on key balance have achieved the expected results, generating a key exchange interval adjustment completion signal.

[0084] It should be added that the specific process of adjusting idle quotas from other low-priority SSL VPN sessions is as follows: All low-priority SSL VPN sessions are traversed, and the number of idle quotas for each SSL VPN session is queried and counted according to the quota utilization rate. This is then aggregated to form an adjustable idle quota pool. Next, the idle quotas of the target low-priority SSL VPN session are locked and their usage rights are frozen to prevent resource conflicts caused by multiple systems competing for quotas simultaneously. Then, based on the demand gap of high-priority SSL VPN sessions, sufficient idle quotas are selected from the quota pool, and the ownership of the quotas is transferred through the system's internal key management module. Simultaneously, the adjusted quota information is pushed to the key management unit of the high-priority SSL VPN session to ensure it can be accessed immediately.

[0085] Collect key timing matching parameters to obtain the key timing risk index, thereby determining the key overlap window adjustment strategy, calculating the expected effective time and determining the overlap window and distribution strategy, verifying in real time and triggering the retry mechanism, and adjusting the verification frequency according to the SSL VPN session priority.

[0086] Furthermore, the key timing risk index is obtained, and the specific analysis method is as follows:

[0087] Collect key timing matching parameters, including key activation delay, SSL VPN session switching interval, and key pre-generation lead time.

[0088] When the key activation delay is too long, the old key may become invalid before the new key is put into use, increasing the risk of a switchover gap. The shorter the SSL VPN session switchover interval, the easier it is to misalign with the key distribution and activation process, thus amplifying the impact of the delay on security and increasing the key timing risk index. If the key pre-generation lead time is insufficient, it cannot be guaranteed that the new key will be ready when the switchover occurs, leading to an increased risk of key supply disruption.

[0089] Key activation delay can be obtained by recording the time interval from key generation to its actual use for SSL VPN session encryption in system logs or monitoring modules. Specifically, the time difference between the key generation event and the first use event is statistically analyzed, combined with interface response time, distribution strategy, and network latency, to obtain the average activation delay, which is recorded as the key activation delay.

[0090] The SSL VPN session switching interval can be obtained through the SSL VPN session management module or system log statistics, that is, by calculating the time difference between adjacent SSL VPN session startup or switching events.

[0091] The key pre-generation advance is calculated by first collecting historical data on the delay from key generation to availability, as well as data on the time interval of SSL VPN session switching. The average value and fluctuation range are calculated, and preset weights are extracted from the database. The average availability delay and delay fluctuation are weighted to obtain the initial advance. This is then adjusted in conjunction with the SSL VPN session switching interval: the security buffer time is subtracted from the SSL VPN session switching interval to obtain the security window. The initial advance is then compared with this security window, and the smaller value is taken as the final key pre-generation advance.

[0092] When the key activation delay increases, the time required for a key to become available from generation to use increases. Therefore, the system needs to prepare more keys in advance to ensure that new SSL VPN sessions can obtain available keys in time when they start up, thereby ensuring encryption continuity. At the same time, when the SSL VPN session switching interval is shortened, that is, when SSL VPN session switching is more frequent, the demand for new keys for each SSL VPN session will also increase. In order to avoid key supply interruption during the switching process, the key pre-generation advance also needs to be increased accordingly.

[0093] Extract the preset key activation delay reference value, SSL VPN session switching interval reference value, and key pre-generation lead time reference value from the database.

[0094] To evaluate key scheduling and SSL VPN session security, the system presets reference values ​​for key activation delay, SSL VPN session switching interval, and key pre-generation lead time in the database. These values ​​define the normal range and serve as a basis for adjustment. The reference values ​​are set based on a large amount of historical SSL VPN session data, including key generation and usage times, SSL VPN session startup and switching events, to calculate the distribution of activation delay, switching interval, and lead time. The final reference values ​​are determined through statistical analysis of the data's mean, variance, maximum, and minimum values, combined with actual needs and security redundancy strategies.

[0095] Extract the preset key activation delay feature mapping coefficient, SSL VPN session switching interval feature mapping coefficient, and key pre-generation advance feature mapping coefficient from the database.

[0096] The key activation delay feature mapping coefficient, SSL VPN session switching interval feature mapping coefficient, and key pre-generation advance feature mapping coefficient all range from 0 to 1, and their sum is 1. Preset values ​​can be directly extracted from the database. Specifically, a one-to-one mapping set is established between the key activation delay, SSL VPN session switching interval, and pre-generation advance and their corresponding feature mapping coefficients. During system operation, real-time parameters are input into the set to obtain the corresponding coefficients. The mapping set refers to establishing the correspondence between each indicator and the feature mapping coefficient through a preset interval mapping table, function model, or interpolation model. During system operation, when a change in a certain indicator is detected, the system can directly look up or calculate its corresponding coefficient. Finally, normalization processing is performed to ensure that the sum of the three is 1, thereby achieving a weighted fusion evaluation of multi-source indicators and providing a basis for key scheduling and SSL VPN session security strategies.

[0097] Analysis of key timing risk index based on key timing matching degree parameter.

[0098] The Key Timing Risk Index is a quantitative indicator of the combined impact of key activation delay, SSL VPN session switching interval, and key pre-generation advance on the timing matching of key activation and SSL VPN session switching. The specific analysis process is as follows: The key activation delay is compared with the corresponding reference value. The reference values ​​corresponding to the SSL VPN session switching interval and key pre-generation advance are compared with the collected SSL VPN session switching interval and key pre-generation advance. The results of each comparison are coupled with the corresponding feature mapping coefficients to obtain the Key Timing Risk Index.

[0099]

[0100] Wherein, G represents the key timing risk index, O represents the key activation delay, O0 represents the key activation delay reference value, s represents the key activation delay feature mapping coefficient, P represents the SSL VPN session switching interval, P0 represents the SSL VPN session switching interval reference value, d represents the SSL VPN session switching interval feature mapping coefficient, A represents the key pre-generation advance, A0 represents the key pre-generation advance reference value, and h represents the key pre-generation advance feature mapping coefficient.

[0101] Furthermore, the key overlap window adjustment strategy is determined, and the specific analysis method is as follows:

[0102] Extract the pre-defined overlapping window of old and new keys from the database.

[0103] If the key timing risk index is greater than or equal to the key timing risk index threshold, the key overlap window adjustment strategy is recorded as key overlap window extension. Based on the overlap window, the key distribution interface extension value is extracted according to the key timing risk index deviation value. Based on the key distribution interface extension value and the new and old key overlap windows, the key distribution interface update value is obtained.

[0104] It should be added that the absolute value of subtracting the key timing risk index threshold from the key timing risk index is recorded as the key timing risk index deviation value.

[0105] It should be noted that if the key timing risk index is greater than or equal to the key timing risk index threshold, it indicates that the timing risk of the current key switching has exceeded the security controllable range, which means that the probability of causing communication interruption or security vulnerability is high. In order to avoid the vacuum period where no valid key is available, and to alleviate the timing pressure of the system in processing key switching requests, and reduce key switching failures caused by intensive operations and time constraints, the key overlap window adjustment strategy is denoted as key overlap window extension. The specific analysis process is as follows: extract the key distribution interface extension value according to the key timing risk index deviation value, and add the key distribution interface extension value and the new and old key overlap windows to obtain the key distribution interface update value.

[0106] It should be noted that in this embodiment, the system pre-defines the correspondence between the key timing risk index deviation value and the key distribution interface extension range, and stores these rules in a configuration file or parameter table for unified invocation. During operation, the system first calculates the key timing risk index deviation value, reflecting the timing risk status of key distribution, and then searches for or calculates the matching interface extension value according to the preset rules. The rules can establish the correlation between the key timing risk index deviation value and the interface extension range through interval mapping tables, function fitting, or interpolation methods. When the key timing risk index deviation value is high, it means that there is a high risk in distribution. In this case, the interface extension range needs to be increased to ensure the continuity of key distribution and the stability of SSLVPN session encryption; therefore, the higher the risk deviation, the larger the corresponding interface extension range.

[0107] If the key timing risk index is less than the key timing risk index threshold, the key overlap window adjustment strategy is recorded as key overlap window shrinking. The key distribution interface shortening value is extracted from the overlap window based on the key timing risk index deviation value. The key distribution interface update value is obtained based on the key distribution interface shortening value and the new and old key overlap windows.

[0108] It should be noted that if the key timing risk index is less than the key timing risk index threshold, it means that the time dimension risk of the current key switching is within a safe and controllable range. The original key overlap window has time redundancy. An excessively long window will increase the management cost and security risks of the long-term coexistence of old keys. Therefore, the key overlap window adjustment strategy is called key overlap window shrinking. The specific analysis process is as follows: extract the key distribution interface shortening value based on the key timing risk index deviation value, and subtract the new and old key overlap window and the key distribution interface shortening value to obtain the key distribution interface update value.

[0109] In this embodiment, the system pre-defines the correspondence between the key timing risk index deviation value and the key distribution interface shortening range, and stores these rules in a configuration file or parameter table for unified invocation. During operation, the system first calculates the key timing risk index deviation value, reflecting the timing risk status of key distribution, and then searches for or calculates the matching interface shortening value according to the preset rules. The rules can establish the correlation between the key timing risk index deviation value and the interface shortening range through interval mapping tables, function fitting, or interpolation methods. When the key timing risk index deviation value is low, it means that the distribution risk is low, and the interface latency can be appropriately shortened to improve key distribution efficiency and SSL VPN session encryption response speed; therefore, the lower the risk deviation, the greater the corresponding interface shortening range.

[0110] Furthermore, the overlapping window and distribution strategy are determined, and a retry mechanism is triggered in real time. The specific analysis method is as follows:

[0111] After determining the key overlap window adjustment strategy, execute the key overlap window adjustment strategy. After execution, determine the verification frequency based on the SSL VPN session priority.

[0112] In this embodiment, the system establishes a correspondence between SSL VPN session priority and session verification frequency according to preset rules and stores this information in a configuration file or parameter table. During runtime, the system extracts the priority value of each session and then searches for or calculates the matching verification frequency. Sessions with higher priority have stricter security and real-time requirements, therefore their verification frequency is higher to ensure the security and reliability of critical sessions.

[0113] Based on the verification frequency, the SSL VPN session switching time is monitored in real time, and the expected effective time of the new key is calculated. If the expected effective time is greater than the SSL VPN session switching time, the timing deviation index is obtained through the expected effective time and the SSL VPN session switching time. The validity period of the old key is adjusted according to the timing deviation index, and the distribution or effective time of the new key is triggered in advance. If the expected effective time is less than or equal to the SSL VPN session switching time, an adjustment completion signal is generated.

[0114] It should be noted that the system monitors the SSL VPN session switching time, key distribution time, and terminal synchronization delay in real time, and adds these three factors together to obtain the estimated effective time of the new key. If the calculated estimated effective time of the new key is greater than the SSL VPN session switching time, it means that the new key cannot be activated on time during the SSL VPN session switching, which may result in a key vacuum period where the old key has expired and the new key has not yet taken effect. In this case, the timing deviation index is first obtained by subtracting the SSL VPN session switching time from the estimated effective time to quantify the lag. Then, based on this index, the old key expiration time is extended, the validity period of the old key is adjusted, and the new key distribution or activation process is triggered in advance to ensure that the new key can seamlessly connect with the old key at the adjusted time. If the estimated effective time of the new key is less than or equal to the SSL VPN session switching time, it means that the new key can be prepared on time or even in advance, and a smooth switch can be achieved without additional intervention. At this time, an adjustment completion signal is generated.

[0115] In this embodiment, the system pre-defines the correspondence between the timing deviation index and the old key expiration time extension value, and stores these rules in a configuration file or parameter table for unified invocation. During runtime, the system first calculates the timing deviation index to reflect the timing stability of key distribution and activation, and then searches for or calculates the matching old key expiration time extension value according to the preset rules. These rules establish the correlation between the timing deviation index and the extension value through interval mapping tables, function fitting, or interpolation methods; the larger the timing deviation index, the larger the old key expiration time extension value.

[0116] Based on the verification frequency, the actual effective time of the new key in actual operation is monitored in real time. If the monitoring finds that the actual effective time of the new key is still greater than the SSL VPN session switching time, a retry mechanism is triggered to re-push the new key and extend the validity period of the old key. If the monitoring finds that the actual effective time of the new key is less than or equal to the SSL VPN session switching time, an adjustment completion signal is generated.

[0117] It should be noted that the system tracks the actual effective time of the new key for each SSL VPN terminal in real time based on a preset verification frequency. That is, the time when the new key is deployed on the terminal and begins encryption / decryption. This step is the final verification of whether the new key can adapt to the SSL VPN session switching on time. If the monitoring finds that the actual effective time of the new key is still greater than the SSL VPN session switching time, it means that the previous adjustment has not solved the problem and there is still a risk of "key vacuum period". In this case, the retry mechanism is immediately triggered. On the one hand, the key is pushed back to the terminal that has not successfully enabled the new key. On the other hand, the validity period of the old key is extended at the same time. The dual actions of retrying the push and extending the old key are used to cover the risk. If the monitoring finds that the actual effective time of the new key is less than or equal to the SSL VPN session switching time, it means that the new key is ready in advance or on time and can seamlessly connect to the SSL VPN session switching. Then, an adjustment completion signal is generated.

[0118] It should be noted that, in this embodiment, extending the validity period of the old key refers to extending the expiration time of the old key by a certain amount.

[0119] Monitor the error rate and key inventory level of the SSL VPN session distribution interface to determine the rollback adjustment needs, and determine the rollback strategy when the rollback adjustment needs are considered rollback requirements.

[0120] Furthermore, the rollback adjustment demand is determined, and when the rollback adjustment demand is a rollback demand, the rollback strategy is determined. The specific analysis method is as follows:

[0121] After the signal generation is completed, the error rate threshold of the quantum key distribution interface is determined based on the key timing risk index deviation value, and the preset key storage security threshold is extracted from the database.

[0122] In this embodiment, the system pre-defines the correspondence rules between the key timing risk index deviation value and the quantum key distribution interface error rate threshold, and stores them in a configuration file or parameter table for unified invocation. The system first calculates the key timing risk index deviation value, reflecting the timing risk status of quantum key distribution, and then searches for or calculates the matching interface error rate threshold according to the preset rules. These rules establish the correlation between the key timing risk index deviation value and the interface error rate threshold through interval mapping tables, function fitting, or interpolation methods. A high key timing risk index deviation value indicates significant uncertainty or potential error risk in the distribution; in this case, the interface error rate threshold needs to be adjusted to ensure distribution stability and SSL VPN session encryption security. Therefore, the higher the risk deviation, the smaller the corresponding threshold adjustment range.

[0123] If the error rate of the quantum key distribution interface increases to above the interface error rate threshold but the key inventory is higher than or equal to the key inventory security threshold, the rollback adjustment requirement is recorded as a demand rollback, and the rollback strategy is recorded as old key rollback extension: rollback to key overlap window adjustment, determine the old key usage time extension value for all SSL VPN sessions based on the deviation between the quantum key distribution interface error rate and the interface error rate threshold, generate new key instructions to restrict low-priority SSL VPN sessions and generate early warning information simultaneously.

[0124] It should be noted that when the error rate of the quantum key distribution interface increases to above the error rate threshold, it means that there is an anomaly in the generation or transmission of new keys. Continuing to rely on this interface to distribute new keys may lead to invalid keys or transmission failures. However, if the key inventory is higher than or equal to the key inventory security threshold, it means that there are still enough old keys available. There is no need to worry about a shortage of key resources. Therefore, the rollback adjustment requirement is recorded as a demand rollback. The specific analysis process is as follows: Roll back to the previous key overlap window adjustment. First, subtract the error rate threshold from the quantum key distribution interface error rate to obtain the error rate deviation value. Then, determine the old key usage time extension value for all SSL VPN sessions based on the error rate deviation value. At the same time, generate a new key instruction to restrict low-priority SSL VPN sessions to avoid low-priority SSL VPN sessions preempting limited old key resources, prioritize the key supply for high-priority SSL VPN sessions, and generate early warning information simultaneously.

[0125] In this embodiment, the warning message could be: "Attention! The error rate of the quantum key interface exceeds the standard, and the old key extension strategy has been enabled."

[0126] In this embodiment, the system pre-defines the correspondence between error rate deviation values ​​and the extension values ​​of old key usage time for all SSL VPN sessions, and stores these rules in a configuration file or parameter table. During runtime, the system first calculates the error rate deviation value to reflect the stability risks of key distribution and session encryption, and then searches for or calculates the matching extension value according to the preset rules. These rules establish the correlation between error rate deviation and extension magnitude through interval mapping tables, function fitting, or interpolation methods. When the error rate deviation value is high, to ensure timely new key integration and session encryption continuity, the old key usage time extension value for all SSL VPN sessions is increased accordingly.

[0127] If the key inventory is below the key inventory security threshold but the error rate of the quantum key distribution interface is below the error rate threshold, the rollback adjustment requirement is recorded as a demand rollback, and the rollback strategy is recorded as a hybrid encryption rollback: high-priority SSL VPN sessions continue to use the remaining quantum keys, and low-priority SSL VPN sessions automatically switch to traditional encryption algorithms, and switch back after the quantum keys are recovered, to ensure uninterrupted communication.

[0128] It should be noted that if the key inventory is below the key inventory security threshold, it means that the number of available quantum keys is insufficient to meet the needs of all SSL VPN sessions, posing a risk of resource shortage. However, if the error rate of the quantum key distribution interface is below the error rate threshold, it indicates that the interface itself is functioning normally, and quantum key generation and replenishment can be resumed later. Therefore, the rollback adjustment requirement is recorded as a demand rollback, and the corresponding rollback strategy is a hybrid encryption rollback, which allocates encryption resources differently according to the priority of SSL VPN sessions: for high-priority SSL VPN sessions, the remaining quantum keys continue to be used; for low-priority SSL VPN sessions, the traditional encryption algorithm is automatically switched. After the quantum key distribution interface replenishes sufficient keys and the inventory is restored to above the key inventory security threshold, the encryption method of the low-priority SSL VPN sessions is switched back to quantum encryption. The entire process, through priority-oriented resource allocation and temporary encryption methods as a backup, not only safeguards the security bottom line of high-priority services but also ensures that communication of all SSL VPN sessions is not interrupted, achieving a balance between security and continuity when resources are scarce.

[0129] If the key inventory is higher than or equal to the key inventory security threshold and the error rate of the quantum key distribution interface is below the error rate threshold, the rollback adjustment requirement will be recorded as no rollback is required.

[0130] It should be noted that if the key inventory is higher than or equal to the key inventory security threshold, and the error rate of the quantum key distribution interface is below the error rate threshold, this means that the current quantum key management system is in an ideal operating state with sufficient resources and a stable interface. No emergency rollback strategy needs to be initiated, and the rollback adjustment requirement is recorded as no rollback is required. A sufficient key inventory indicates that the existing number of subkeys is sufficient to cover the encryption needs of all SSL VPN sessions, and there is no risk of service interruption due to key shortages. A compliant quantum key distribution interface error rate indicates that the generation and transmission process of new keys is stable and reliable, and key resources can be replenished normally in the future. There is no need to worry about interface failures affecting key supply. In this case, the system can continue to use the original conventional strategies such as key allocation, key exchange intervals, and encryption algorithms, without needing to adjust through emergency methods such as extending the rollback of old keys or hybrid encryption rollback.

[0131] If the key inventory is below the key inventory security threshold and the error rate of the quantum key distribution interface increases to above the error rate threshold, the rollback adjustment requirement is recorded as a demand rollback, the rollback strategy is recorded as a joint rollback, and the rollback is adjusted to the key overlap window. The high-priority SSL VPN session determines the old key usage time extension value based on the deviation between the quantum key distribution interface error rate and the error rate threshold, and continues to use the remaining quantum keys. The low-priority SSL VPN session automatically switches to the traditional encryption algorithm.

[0132] It should be noted that when the key bank is below the security threshold and the error rate of the quantum key distribution interface is above the threshold, the system faces the dual risks of resource shortage and interface failure. In this situation, a rollback adjustment is triggered, and a joint rollback strategy is executed. Specifically, the strategy first rolls back to the key overlap window adjustment to reserve buffer time for key switching. For high-priority SSL VPN sessions, the validity period of the old key is extended based on the interface error rate deviation, while the remaining quantum key is used to ensure the security of the core session. For low-priority sessions, a temporary fallback using traditional encryption algorithms is implemented to avoid communication interruption. Through this differentiated design of prioritizing high-priority sessions and flexibly handling low-priority sessions, the system ensures both the security of core business operations and uninterrupted sessions under the dual risks of resource shortages and interface failures, buying time for subsequent interface troubleshooting and key replenishment.

[0133] The embodiments of the present invention provide, as follows Figure 3 The diagram shows the structure of a quantum key-based SSL VPN wireless communication encryption system. The system's processing flow can include the following steps: key resource management module, key exchange interval adjustment module, key timing adjustment module, and backoff adjustment module.

[0134] The key resource management module is used to collect core status parameters of key management, analyze the key resource balance, determine the key resource status, and determine the global key exchange interval execution strategy.

[0135] The key change interval adjustment module is used to obtain the SSL VPN session priority, perform resource scheduling, and allocate key quotas and prefetch resources after the global key change interval execution policy is completed.

[0136] The key timing adjustment module is used to collect key timing matching parameters, obtain the key timing risk index, determine the key overlap window adjustment strategy, calculate the expected effective time and determine the overlap window and distribution strategy, verify in real time and trigger the retry mechanism, and adjust the verification frequency according to the priority of SSL VPN sessions.

[0137] The rollback adjustment module is used to monitor the error rate of the SSL VPN session distribution interface and the key inventory level, determine the rollback adjustment needs, and determine the rollback strategy when the rollback adjustment needs are rollback requirements.

[0138] See Figure 4 The diagram shown is a mind map of the quantum key-based SSL VPN wireless communication encryption system provided in this embodiment of the invention. The system first determines the key resource status and SSL VPN session priority, then dynamically adjusts the key switching interval and optimizes key scheduling to prioritize high-priority SSL VPN sessions. Next, it manages timing risks and ensures seamless key switching. Finally, it handles abnormal situations by using fallback or hybrid encryption to maintain continuous communication.

[0139] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.

[0140] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0141] In this invention, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0142] It should be understood that, in various embodiments of the present invention, the order of the above-mentioned process numbers does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0143] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0144] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0145] In the embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0146] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0147] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0148] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0149] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A quantum key-based SSL VPN wireless communication encryption method, characterized in that, The method includes: Collect key management core status parameters, analyze key resource balance, determine key resource status, and thereby determine the global key exchange interval execution strategy. After the global key change interval execution policy is completed, the SSL VPN session priority is obtained, resource scheduling is performed, and key quotas are allocated and resources are prefetched. Collect key timing matching parameters to obtain the key timing risk index, thereby determining the key overlap window adjustment strategy, calculating the expected effective time and thereby determining the overlap window and distribution strategy, verifying in real time and triggering the retry mechanism, and adjusting the verification frequency according to the SSL VPN session priority; Monitor the error rate and key inventory level of the SSL VPN session distribution interface to determine the rollback adjustment needs, and determine the rollback strategy when the rollback adjustment needs are considered rollback requirements.

2. The quantum key-based SSL VPN wireless communication encryption method according to claim 1, characterized in that, The specific analysis method for determining the key resource balance is as follows: Collect key management core status parameters, including the key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate of the key interface; Analyze the key resource balance based on the core status parameters of key management; The key resource balance is a quantitative indicator of the combined impact of the key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate on SSL VPN key management resources. The specific analysis process is as follows: the key supply-demand ratio, key buffer remaining rate, and key distribution interface availability rate are compared with their corresponding reference values, and the results of each comparison are coupled with their corresponding feature mapping coefficients to obtain the key resource balance.

3. The quantum key-based SSL VPN wireless communication encryption method according to claim 2, characterized in that, The determination of the key resource status, thereby determining the global key exchange interval execution strategy, is analyzed using the following method: Extract the key resource balance interval; If the key resource balance is greater than or equal to the upper limit of the key resource balance interval, the key resource status is determined to be key surplus, and the global key exchange interval execution strategy is recorded as shortening adjustment. If the key resource balance is within the key resource balance range, the key resource status is determined to be key balanced, and the global key change interval execution strategy is recorded as no adjustment is needed. If the key resource balance is less than or equal to the lower limit of the key resource balance interval, the key resource status is determined to be key shortage, and the global key exchange interval execution strategy is recorded as extension adjustment.

4. The quantum key-based SSL VPN wireless communication encryption method according to claim 3, characterized in that, The specific analysis method for the global key-swapping interval execution strategy is as follows: Get the current global key exchange interval, and extract the minimum and maximum threshold values ​​for the key exchange interval. If there is a key surplus, the global key exchange interval execution strategy is recorded as shortening adjustment. The global key exchange interval shortening value is extracted based on the deviation between the key resource balance degree and the upper limit of the key resource balance interval. The global key exchange interval update value is obtained based on the current global key exchange interval and the global key exchange interval shortening value. If there is a shortage of keys, the global key exchange interval is adjusted by a strategy called "extension adjustment". The global key exchange interval extension value is extracted based on the deviation between the key resource balance and the lower limit of the key resource balance interval. This extension is then used for differentiated adjustment at the SSL VPN session level. The specific process is as follows: Extract the SSL VPN session priority sequence, extract the extension ratio of each SSL VPN session according to the priority of each SSL VPN session, and obtain the key exchange interval extension update value of each SSL VPN session based on the extension ratio of each SSL VPN session and the global key exchange interval extension value. The minimum and maximum threshold values ​​for key exchange intervals limit the global key exchange interval shortening value and the key exchange interval extension update value for each SSLVPN session.

5. The quantum key-based SSL VPN wireless communication encryption method according to claim 1, characterized in that, The specific analysis method for allocating key quotas and prefetching resources is as follows: Extract the SSL VPN session priority threshold, and record the SSL VPN sessions in the SSL VPN session priority sequence that are greater than or equal to the SSL VPN session priority threshold as high-priority SSL VPN sessions, and record the SSL VPN sessions in the SSL VPN session priority sequence that are less than the SSL VPN session priority threshold as low-priority SSL VPN sessions. Based on the SSL VPN session priority sequence, high-priority SSL VPN sessions are given priority in obtaining key quotas, while low-priority SSL VPN sessions only receive quotas when keys are abundant and allocation can be delayed when keys are scarce. For each SSL VPN session about to start, the time length for pre-allocating new keys is determined based on the key resource balance to avoid key supply interruption during switching. Based on the time length, the keys that the SSL VPN session usually consumes are pre-fetched from the key pool. The initial pre-fetch quantity is extracted based on the SSL VPN session, and the pre-fetch quantity is determined in combination with the key resource balance and stored in the dedicated cache area of ​​the SSL VPN session. If the communication traffic growth value of a high-priority SSL VPN session exceeds the communication traffic growth threshold, its key quota will be temporarily increased and adjusted from the idle quota of other low-priority SSL VPN sessions. If the communication traffic growth value of all high-priority SSL VPN sessions is less than or equal to the communication traffic growth threshold, a key change interval adjustment completion signal will be generated.

6. The quantum key-based SSL VPN wireless communication encryption method according to claim 1, characterized in that, The specific analysis method for obtaining the key timing risk index is as follows: Collect key timing matching parameters, including key activation delay, SSL VPN session switching interval, and key pre-generation lead time. Analysis of key timing risk index based on key timing matching degree parameter; The key timing risk index is a quantitative indicator of the combined impact of key activation delay, SSL VPN session switching interval, and key pre-generation advance on the timing matching of key activation and SSL VPN session switching. The specific analysis process is as follows: the key activation delay is compared with the corresponding reference value; the reference values ​​corresponding to the SSL VPN session switching interval and key pre-generation advance are compared with the collected SSL VPN session switching interval and key pre-generation advance; and the results of each comparison are coupled with the corresponding feature mapping coefficients to obtain the key timing risk index.

7. The quantum key-based SSL VPN wireless communication encryption method according to claim 6, characterized in that, The specific analysis method for determining the key overlap window adjustment strategy is as follows: Extract the preset window that overlaps the old and new keys; If the key timing risk index is greater than or equal to the key timing risk index threshold, the key overlap window adjustment strategy is recorded as key overlap window extension. Based on the overlap window, the key distribution interface extension value is extracted according to the key timing risk index deviation value. Based on the key distribution interface extension value and the new and old key overlap windows, the key distribution interface update value is obtained. If the key timing risk index is less than the key timing risk index threshold, the key overlap window adjustment strategy is recorded as key overlap window shrinking. The key distribution interface shortening value is extracted from the overlap window based on the key timing risk index deviation value. The key distribution interface update value is obtained based on the key distribution interface shortening value and the new and old key overlap windows.

8. The quantum key-based SSL VPN wireless communication encryption method according to claim 1, characterized in that, The specific analysis method for determining the overlapping window and distribution strategy, and for real-time verification and triggering the retry mechanism is as follows: After determining the key overlap window adjustment strategy, execute the key overlap window adjustment strategy. After execution, determine the verification frequency based on the SSLVPN session priority. Based on the verification frequency, the SSL VPN session switching time is monitored in real time, and the expected effective time of the new key is calculated. If the expected effective time is greater than the SSL VPN session switching time, the timing deviation index is obtained through the expected effective time and the SSL VPN session switching time. The validity period of the old key is adjusted according to the timing deviation index, and the distribution or effective time of the new key is triggered in advance. If the expected effective time is less than or equal to the SSL VPN session switching time, an adjustment completion signal is generated. Based on the verification frequency, the actual effective time of the new key in actual operation is monitored in real time. If the monitoring finds that the actual effective time of the new key is still greater than the SSL VPN session switching time, a retry mechanism is triggered to re-push the new key and extend the validity period of the old key. If the monitoring finds that the actual effective time of the new key is less than or equal to the SSL VPN session switching time, an adjustment completion signal is generated.

9. The quantum key-based SSL VPN wireless communication encryption method according to claim 1, characterized in that, The specific analysis method for determining the rollback adjustment requirement and, when the rollback adjustment requirement is a rollback requirement, determining the rollback strategy is as follows: After the signal generation is completed, the error rate threshold of the quantum key distribution interface is determined based on the key timing risk index deviation value, and the key inventory security threshold is extracted. If the error rate of the quantum key distribution interface increases to above the interface error rate threshold, but the key inventory is higher than or equal to the key inventory security threshold, the rollback adjustment requirement is recorded as a requirement rollback, and the rollback strategy is recorded as old key rollback extension: rollback to key overlap window adjustment, determine the old key usage time extension value for all SSLVPN sessions based on the deviation between the quantum key distribution interface error rate and the interface error rate threshold, generate new key instructions to restrict low-priority SSLVPN sessions and generate early warning information simultaneously; If the key bank is below the key bank security threshold but the error rate of the quantum key distribution interface is below the error rate threshold, the rollback adjustment requirement is recorded as a requirement rollback and the rollback strategy is recorded as a hybrid encryption rollback: high-priority SSL VPN sessions continue to use the remaining quantum keys, and low-priority SSL VPN sessions automatically switch to traditional encryption algorithms and switch back after the quantum keys are recovered to ensure uninterrupted communication. If the key bank is higher than or equal to the key bank security threshold and the error rate of the quantum key distribution interface is below the error rate threshold, the rollback adjustment requirement will be recorded as no rollback required. If the key inventory is below the key inventory security threshold and the error rate of the quantum key distribution interface increases to above the error rate threshold, the rollback adjustment requirement is recorded as a demand rollback, the rollback strategy is recorded as a joint rollback, and the rollback is adjusted to the key overlap window. The high-priority SSL VPN session determines the old key usage time extension value of the high-priority SSL VPN session based on the deviation value between the quantum key distribution interface error rate and the error rate threshold, and continues to use the remaining quantum keys. The low-priority SSL VPN session automatically switches to the traditional encryption algorithm.

10. A quantum-key-based SSL VPN wireless communication encryption system, employing the quantum-key-based SSL VPN wireless communication encryption method as described in any one of claims 1-9, characterized in that, The system includes: a key resource management module, a key exchange interval adjustment module, a key timing adjustment module, and a rollback adjustment module; The key resource management module is used to collect key management core status parameters, analyze key resource balance, determine key resource status, and thereby determine the global key exchange interval execution strategy. The key change interval adjustment module is used to obtain the SSL VPN session priority, perform resource scheduling, and allocate key quotas and prefetch resources after the global key change interval execution policy is completed. The key timing adjustment module is used to collect key timing matching parameters, obtain key timing risk index, determine key overlap window adjustment strategy, calculate expected effective time and determine overlap window and distribution strategy, verify and trigger retry mechanism in real time, and adjust verification frequency according to SSL VPN session priority. The rollback adjustment module is used to monitor the error rate of the SSL VPN session distribution interface and the key inventory level, determine the rollback adjustment requirement, and determine the rollback strategy when the rollback adjustment requirement is a rollback requirement.

Citation Information

Patent Citations

  • A VPN network system based on quantum key technology

    CN115361125B

  • Terminal information system with quantum key encryption function

    CN118449691A