Quantum network security test system and method
By constructing a quantum network security testing system that integrates a management platform, a control management layer, a virtualization layer, and a physical hardware layer, full-scenario security testing of quantum information systems was achieved. This solved the problem of insufficient testing capabilities of existing platforms and improved the security assessment and attack simulation capabilities of quantum networks.
Patent Information
- Application Number
- CN202511930854.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-02-10
AI Technical Summary
Existing quantum information system security testing platforms lack full-scenario security integration testing capabilities, cannot simulate attack behavior in long-distance quantum networks, cannot comprehensively evaluate complex scenarios spanning the physical layer, link layer, network layer, and application layer, and lack the ability to simulate physical attacks on quantum hardware.
A quantum network security testing system is provided, including a management platform, a control management layer, a virtualization layer, and a physical hardware layer. It connects multiple quantum devices through a fiber optic backbone network to simulate quantum communication scenarios and quantum network attacks. Users can perform resource scheduling and parameter configuration through the management platform, and the control management layer sends control signals to execute test tasks and monitor device and network behavior in real time.
It enables joint security testing of quantum hardware, communication protocols, and quantum algorithms, verifies the security defense capabilities of quantum-classical cooperative networks, discovers potential hardware vulnerabilities, and improves the ability to assess quantum network security and simulate attacks.
Smart Images

Figure CN121509084A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of quantum communication, in particular to a quantum network security testing system and method. BACKGROUND
[0002] With the rapid development of quantum information technology, core technologies such as quantum computing, quantum communication, and quantum sensing are widely used in the field of information security. Before the actual deployment of quantum information technology, a comprehensive security evaluation of the system before the actual deployment is needed to prevent potential risks from attacking quantum information technology. However, although quantum information systems have high security at the theoretical level, they still face challenges such as side channel attacks and device vulnerabilities in actual application. In addition, there is a lack of unified testing platform tools among quantum physicists, network security experts, and engineering technicians, which will seriously hinder the efficiency of quantum security risk identification and response. Therefore, a comprehensive quantum network security testing platform is urgently needed.
[0003] Currently, there are some security testing platforms for quantum information systems in the industry. For example, some research institutions have developed simulation software specifically for quantum key distribution (QKD) protocol verification, which can simulate quantum state transmission processes and detect protocol logic vulnerabilities; some manufacturers also provide compliance detection tools for quantum random number generators or quantum key management modules.
[0004] However, existing security testing platforms only focus on single technology verification of quantum network security, lack of security integrated testing capabilities for full-scene quantum computing, network communication, quantum sensing, quantum channel, and quantum relay. In addition, the existing security testing platform lacks the ability to simulate physical attacks on quantum hardware, which makes it impossible to test the security of the hardware physical layer of quantum information systems; the existing security testing platform also cannot simulate attack behaviors in long-distance quantum networks, which makes it impossible to comprehensively evaluate complex scenarios spanning the physical layer, link layer, network layer, and application layer. SUMMARY
[0005] The purpose of the present application is to provide a quantum network security testing system and method that can achieve the effect of enriching quantum network testing environment while improving quantum network security evaluation capability and quantum network attack simulation capability.
[0006] Embodiments of the present application are implemented as follows: In a first aspect of the embodiments of the present application, a quantum network security testing system is provided, which comprises a management platform, a control management layer, a virtualization layer, and a physical hardware layer; a plurality of quantum devices and an optical fiber backbone network are deployed on the physical hardware layer, and each quantum device is connected to each other via the optical fiber backbone network to form a quantum physical communication scenario; The virtualization layer is configured to simulate a quantum simulation communication scenario and a quantum network attack in different operating states; The management platform is configured to provide a graphical interactive interface, so that a user performs resource scheduling and parameter configuration on the quantum physical communication scenario and the quantum simulation communication scenario through the graphical interactive interface, and the management platform sends a test task to the control management layer in response to an input instruction of the user; The control management layer is configured to send corresponding control signals to each quantum device in the quantum physical communication scenario and the virtualization layer based on resource scheduling instructions and parameter configuration instructions sent by the management platform, so as to adjust the quantum physical communication scenario and the quantum simulation communication scenario; meanwhile, the control management layer loads a preset test script based on the test task sent by the management platform, so as to control the quantum physical communication scenario and the quantum simulation communication scenario to execute the test task, and monitor a response behavior of the quantum physical communication scenario and the quantum simulation communication scenario in real time, the response behavior including a device operating behavior and a network behavior.
[0007] As a possible implementation manner, the plurality of quantum devices comprises at least one quantum computer, at least one quantum relay, at least one quantum sensor, and at least one optical switch, and the optical fiber backbone network comprises optical fibers and dense wavelength division multiplexing optical fibers; Each quantum computer and each quantum sensor is connected to each optical switch via the optical fibers, and each optical switch is connected to each quantum relay or optical switch via the dense wavelength division multiplexing optical fibers, so as to form a ring or mesh topology structure; Each quantum computer is configured to test the security of quantum computing power; Each quantum relay is configured to entangle distribution and signal amplification, so as to measure the security of long-distance quantum communication; Each quantum sensor is configured to obtain quantum sensing data of a measured object; Each optical switch is configured to isolate quantum channels and classical channels.
[0008] As a possible implementation manner, the physical hardware layer further comprises an attack injection module, which comprises an optical fiber splitter, a variable optical attenuator, and an electronic jammer; The attack injection module is configured to simulate quantum attack operations of eavesdropping or sub-flow signal on the physical hardware layer through the optical fiber splitter; The attack injection module is further configured to simulate quantum attack operations of signal loss or denial of service on the physical hardware layer through the variable optical attenuator. The attack injection module is also used to perform electromagnetic interference on each quantum device at the physical hardware layer through an electronic jammer to simulate a side-channel attack operation.
[0009] As a possible implementation, the control management layer includes a quantum computing controller, a quantum communication controller, a quantum sensing controller, a software-defined network controller, an orchestration engine, and a monitoring and log collection unit. The quantum computing controller is used to run quantum compilation and error correction algorithms, and control each quantum computer through a quantum processing unit instruction set, so that each quantum computer loads and runs a corresponding quantum program, and reads the loading and running results of each quantum computer. The quantum communication controller is used to coordinate the establishment of a secure channel for each node in a quantum physical communication scenario, and control the preparation and distribution of quantum states and the transmission and measurement of quantum signals. The quantum sensing controller is used to analyze quantum sensing data uploaded by each quantum sensor in real time. The software-defined network controller is used to dynamically modify the routing, injected traffic, and redirected signals in the quantum physical communication scenario and the quantum simulation communication scenario to reconfigure the network topology in the quantum physical communication scenario and the quantum simulation communication scenario. The orchestration engine is used to automatically deploy the quantum physical communication scenario and the quantum simulation communication scenario according to a preset test script. The monitoring and log collection unit is used to monitor the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario in real time, and generate logs and alarm information according to the response behavior.
[0010] As a possible implementation, the quantum communication controller includes an entangled photon source, a single-photon detector, and a polarization analyzer. The quantum communication controller generates a specific quantum state via the entangled photon source, and controls the specific quantum state to be distributed according to a preset path. The quantum communication controller receives, analyzes, and measures quantum signals from a quantum channel through the single-photon detector and the polarization analyzer.
[0011] As a possible implementation, the virtualization layer includes a virtual quantum node, a virtual classical node, and a simulated attack unit. The virtual quantum node is used to simulate a quantum simulation communication scenario of fiber fading and environmental noise in a long-distance optical fiber transmission scenario. The virtual classical node is used to simulate a quantum simulation communication scenario of a network attack host, an eavesdropping node, and a defense node. The simulated attack unit is used to simulate quantum network attacks in the quantum simulation communication scenario provided by the virtualization layer.
[0012] As one possible implementation, the aforementioned management platform includes: a resource scheduling module and a console; The resource scheduling module is used to schedule resources for quantum physics communication scenarios and quantum simulation communication scenarios based on the configuration information entered by the user in the graphical interface. The schedulable resources include: computing power resources of quantum computers, bandwidth resources of quantum repeaters, and resolution resources of quantum sensors. The console is used to configure parameters for quantum physics communication scenarios and quantum simulation communication scenarios based on the configuration information entered by the user in the graphical interface, so as to trigger the corresponding test tasks.
[0013] As one possible implementation, the aforementioned management platform also includes: a security audit module; The security audit module is used to monitor security events and quantum channel attack events during the quantum key distribution process at the physical hardware layer and virtualization layer.
[0014] As one possible implementation, the aforementioned management platform also includes: a visual interface; The visualization interface is used to display the network topology, quantum state fidelity, quantum sensing data, and security indicators of quantum physics communication scenarios and quantum simulation communication scenarios in real time.
[0015] A second aspect of this application provides a quantum network security testing method, which is applied to the quantum network security testing system described in the first aspect above, and the method includes: The quantum devices are interconnected via a fiber optic backbone network to form a quantum physics communication scenario; a virtualization layer is used to simulate quantum communication scenarios and quantum network attacks under different operating conditions. The management platform provides a graphical user interface to obtain user requests for resource scheduling and parameter configuration for quantum physics communication scenarios and quantum simulation communication scenarios, and issues test tasks to the control management layer in response to user input commands. Based on the resource scheduling instructions and parameter configuration instructions issued by the management platform, corresponding control signals are sent to each quantum device and virtualization layer in the quantum physical communication scenario to adjust the quantum physical communication scenario and the quantum simulation communication scenario. At the same time, based on the test tasks issued by the management platform, preset test scripts are loaded to control the execution of test tasks in the quantum physical communication scenario and the quantum simulation communication scenario, and the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario is monitored in real time. The response behavior includes device operation behavior and network behavior.
[0016] The beneficial effects of the embodiments of this application include: This application provides a quantum network security testing system that constructs a practically operable quantum physics communication scenario through multiple quantum devices and a fiber optic backbone network in the physical hardware layer; it provides a quantum simulation scenario through a virtualization layer, and injects corresponding quantum network attacks into the quantum simulation scenario through the virtualization layer; users allocate hardware resources and configure test parameters for the quantum physics communication scenario and the quantum simulation communication scenario through a unified management platform, and can also issue test tasks to the control management layer; the control management layer sends corresponding control signals to the underlying physical hardware layer and virtualization layer based on the resource scheduling instructions and parameter configuration instructions issued by the management platform to adjust the quantum physics scenario and the quantum virtual scenario; the control management layer also loads corresponding preset test scripts based on the test tasks issued by the management platform to control the execution of test tasks in the quantum physics communication scenario and the quantum simulation communication scenario, and monitors the device operation behavior and network behavior of the quantum physics communication scenario and the quantum simulation communication scenario in real time. The quantum network security testing system, by combining the quantum physics communication scenario and the quantum simulation communication scenario, comprehensively supports the joint security testing of quantum hardware, communication protocols, and quantum algorithms. Furthermore, the quantum simulated communication scenario integrates classical and quantum hybrid networks, which can verify the security defense capabilities of quantum and classical collaborative networks. The management platform also provides a controllable quantum hardware attack interface, allowing users to simulate physical-level attacks on quantum devices to discover potential hardware vulnerabilities. In this way, the goal is to enrich the quantum network testing environment while simultaneously improving quantum network security assessment capabilities and quantum network attack simulation capabilities. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the structure of a first quantum network security testing system provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of a second quantum network security testing system provided in an embodiment of this application; Figure 3 A schematic diagram of the structure of the third quantum network security testing system provided in this application embodiment; Figure 4 This is a schematic diagram of the structure of the fourth quantum network security testing system provided in the embodiments of this application; Figure 5 This is a schematic diagram of the structure of the fifth quantum network security testing system provided in the embodiments of this application; Figure 6 A schematic diagram of a quantum network relay node attack test process provided in this application embodiment; Figure 7 A flowchart illustrating a quantum network security testing method provided in this application embodiment.
[0019] Figure reference numerals: 10: Quantum network security testing system; 101: Management platform; 1011: Resource scheduling module; 1012: Console; 1013: Security audit module; 1014: Visual interface; 102: Control management layer; 1021: Quantum computing controller; 1022: Quantum communication controller; 221: Entangled photon source; 222: Single photon detector; 223: Polarization analyzer; 1023: Quantum sensing controller; 1024: Software-defined network controller; 1025: Orchestration engine; 1026: Monitoring 103: Log collection unit; 103: Virtualization layer; 1031: Virtual quantum node; 1032: Virtual classical node; 1033: Simulated attack unit; 104: Physical hardware layer; 1041: Quantum device; 411: Quantum computer; 412: Quantum repeater; 413: Quantum sensor; 414: Optical switch; 1042: Fiber optic backbone network; 421: Fiber optic; 422: Dense wavelength division multiplexing fiber optic; 1043: Attack injection module; 431: Fiber optic splitter; 432: Variable optical attenuator; 433: Electronic jammer. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0021] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0022] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0023] Currently, any network system is vulnerable to attack and compromised through unexpected means, even information or network systems containing quantum components are not immune to this reality. Until quantum information systems are deployed and applied, the inherent risks remain, placing quantum network security at the forefront of system testing research. Furthermore, network security begins with vulnerability risk; therefore, building a comprehensive quantum network security testing environment is crucial before quantum computers can exploit vulnerabilities to break asymmetric keys.
[0024] The security testing platform aims to achieve joint security testing and experimental evaluation of quantum hardware (such as quantum computers, quantum sensors, and quantum repeaters), communication protocols (such as quantum key distribution protocols and quantum entanglement distribution protocols), and algorithms in quantum information systems, thereby ensuring the secure deployment of quantum information systems.
[0025] However, existing security testing platforms for quantum information systems in the industry only focus on single technology verification and generally lack the ability to conduct integrated security testing across all scenarios, including quantum computing, network communication, quantum sensing, and quantum channels.
[0026] To address this, this application provides a quantum network security testing system. It implements a quantum physical communication scenario through multiple quantum devices and a fiber optic backbone network in the physical hardware layer, and a quantum simulated communication scenario and a quantum network attack scenario through a virtualization layer. Users can schedule resources and configure parameters for the quantum simulated communication scenario and the quantum physical communication scenario through a graphical user interface provided by the management platform, and issue test tasks to the control management layer through the management platform. The control management layer sends corresponding control signals to the quantum physical communication scenario and the quantum simulated communication scenario based on the resource scheduling and parameter configuration instructions issued by the management platform to adjust the quantum physical communication scenario and the quantum simulated communication scenario. Simultaneously, the control management layer can also load preset test scripts based on the test tasks issued by the management platform to control the execution of test tasks in the quantum physical communication scenario and the quantum simulated communication scenario, and monitor the device operation behavior and network behavior of the quantum physical communication scenario and the quantum simulated communication scenario in real time. In this way, it can enrich the quantum network testing environment while improving the quantum network security assessment capability and the quantum network attack simulation capability.
[0027] The quantum network security testing system provided in the embodiments of this application will be explained in detail below with reference to the accompanying drawings.
[0028] Figure 1 A quantum network security testing system provided for this application, see [link to relevant documentation]. Figure 1This application provides a quantum network security testing system 10, comprising: a management platform 101, a control management layer 102, a virtualization layer 103, and a physical hardware layer 104. The physical hardware layer 104 is equipped with multiple quantum devices 1041 and an optical fiber backbone network 1042. The quantum devices 1041 are interconnected via the optical fiber backbone network 1042 to form a quantum physics communication scenario.
[0029] The management platform 101 is used to provide a unified user testing platform for quantum physicists, cybersecurity experts, and engineers. Quantum physicists, cybersecurity experts, and engineers can issue test tasks to the control management layer 102 through the management platform 101. Quantum physicists, cybersecurity experts, and engineers can also change the resources and configurations of the physical hardware layer 104 and the virtualization layer 103 through the management platform 101, thereby changing the security test scenario. This application does not make specific limitations in this regard.
[0030] Specifically, multiple quantum devices 1041 and an optical fiber backbone network 1042 are deployed on the physical hardware layer 104. The physical hardware layer 104 builds a physical quantum network test scenario through multiple quantum devices 1041 and optical fiber backbone network 1042, which is the physical test foundation for building the quantum network security test system 10.
[0031] Furthermore, the quantum devices 1041 in the physical hardware layer 104 are interconnected via an optical fiber backbone network 1042 to form a practically operational quantum physics communication scenario. Specifically, the quantum devices 1041 can be quantum computers requiring ultra-low temperature operation, quantum repeaters for long-distance entanglement distribution and signal amplification, quantum sensors for high-precision measurement, optical switches, etc. The optical fiber backbone network 1042 can be optical fibers, dense wavelength division multiplexing fibers, etc., and this application does not impose specific limitations on these.
[0032] In addition, the physical hardware layer 104 allows testers to directly inject quantum network attacks such as eavesdropping, signal attenuation, and electronic interference into the physical link to verify the security protection capabilities of the quantum information system at the hardware level.
[0033] Therefore, the quantum physics communication scenario refers to the physical quantum network test scenario built by the physical hardware layer 104 through multiple quantum devices 1041 and the optical fiber backbone network 1042.
[0034] The virtualization layer 103 is used to simulate quantum communication scenarios and quantum network attacks under different operating conditions.
[0035] Optionally, the virtualization layer 103 constructs a virtual quantum network environment through software simulation technology. Specifically, the virtualization layer 103 can rapidly create a large number of virtual quantum nodes and virtual classical networks to simulate different network topologies, channel conditions, and attack nodes. In this way, large-scale, remote, and repeatable security testing of quantum network scenarios can be conducted without consuming physical resources.
[0036] Among them, the quantum simulation communication scenario is the virtual quantum network environment constructed by the virtualization layer 103 through software simulation technology, and the quantum network attack is the channel attenuation, noise, denial-of-service, and other attacks injected into the virtual quantum network environment by the virtualization layer 103 through software simulation technology. This application does not make specific limitations here.
[0037] The management platform 101 provides a graphical user interface so that users can schedule resources and configure parameters for quantum physics communication scenarios and quantum simulation communication scenarios through the graphical user interface. The management platform 101 responds to the user's input commands and issues test tasks to the control management layer 102.
[0038] Optionally, the graphical user interface is a window provided by the management platform 101 for users to interact with the quantum network security testing system 10. The graphical user interface can display real-time network topology, quantum device status, and security indicators for quantum physics communication scenarios and quantum simulation communication scenarios. Specifically, security indicators may include information such as qubit error rate and key generation efficiency; this application does not impose specific limitations on these.
[0039] Furthermore, users can flexibly allocate resources for quantum physics communication scenarios and quantum simulation communication scenarios through the graphical interface provided by the management platform 101. They can also customize test parameters for these scenarios through the same interface, and upload and select preset attack test scripts to trigger corresponding test tasks. The resources that users can schedule through the management platform 101 can include quantum computing power, repeater parameters, etc., and this application does not specifically limit their allocation.
[0040] In addition, after the quantum network security tests are completed in the quantum physics communication scenario and the quantum simulation communication scenario, the management platform 101 can automatically generate a detailed evaluation report containing data curves and analysis conclusions, and display it to the user through a graphical interactive interface.
[0041] Optionally, resource scheduling refers to reallocating hardware resources to quantum devices or nodes in quantum physics communication scenarios and quantum simulation communication scenarios; parameter configuration refers to the configuration parameters that quantum physicists, cybersecurity experts, and engineers input for each quantum device or node in the quantum physics communication scenario and quantum simulation communication scenario through the graphical interface of management platform 101; input instructions are test tasks input by quantum physicists, cybersecurity experts, and engineers through the graphical interface provided by management platform 101, such as testing the communication protocol and hardware protection capabilities of the quantum communication scenario, etc., and this application does not specifically limit them.
[0042] The control management layer 102 sends corresponding control signals to each quantum device and virtualization layer 103 in the quantum physical communication scenario based on the resource scheduling instructions and parameter configuration instructions issued by the management platform 101, so as to adjust the quantum physical communication scenario and the quantum simulation communication scenario. At the same time, the control management layer 102 loads preset test scripts based on the test tasks issued by the management platform 101 to control the execution of test tasks in the quantum physical communication scenario and the quantum simulation communication scenario, and monitors the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario in real time. The response behavior includes device operation behavior and network behavior.
[0043] Optionally, the control management layer 102 is the core of coordinating the secure operation of the quantum network security testing system 10. The control management layer 102 receives instructions from users via the management platform 101 and converts these instructions into specific control signals for the underlying physical hardware layer 104 and the virtualization layer 103. For example, the quantum computing controller is responsible for compiling and distributing quantum programs to the quantum computer, the quantum communication controller manages entangled photon sources, the single-photon detector establishes quantum channels, the software-defined network controller dynamically configures network routing, and the orchestration engine automatically executes preset test scripts, etc. This application does not specifically limit these aspects.
[0044] Meanwhile, the control management layer 102 also collects operational data, network traffic, and security events from the physical hardware layer 104, virtualization layer 103, and management platform 101 in real time, providing raw data for subsequent data analysis.
[0045] Optionally, the resource scheduling command refers to the command issued by the user to the control management layer 102 through the graphical interface of the management platform 101 to regulate the hardware resources of each quantum device and node in the quantum physical communication scenario and the quantum simulation communication scenario; the parameter configuration command refers to the command issued by the user to the control management layer 102 through the graphical interface provided by the management platform 101 to adjust the test configuration parameters of each quantum device and node in the quantum physical communication scenario and the quantum simulation communication scenario; the preset test script is a standard test script pre-written by developers according to the quantum network security test scenario. When the user issues a test task to the control management layer 102 through the management platform 101, the control management layer 102 parses the received test task and loads the matching test script based on the test task to realize the test task.
[0046] The response behaviors monitored in real time by the control management layer 102 include device operation behavior and network behavior. Device operation behavior refers to the internal state, performance indicators, and physical responses exhibited by various physical or virtual quantum devices and key components in quantum physics communication scenarios and quantum simulation communication scenarios when performing test tasks. Device operation behavior directly reflects the health status, functional integrity, and physical layer response to external interference or attacks of the device itself. Network behavior refers to the communication performance, protocol interaction, topology dynamics, and security-related event sequences exhibited by quantum and classical networks as a whole in the test scenario. Network behavior directly reflects the flow of data and control information in the network, the effectiveness of protocol execution, and the overall response of the network to threats.
[0047] Optionally, the device operation behavior includes: quantum computing device behavior, quantum communication device behavior, quantum sensing device behavior, and attack injection module behavior. Quantum computing device behavior includes: qubit states, quantum gate operations, processor environment parameters, and error rate. Qubit states include: coherence time, decoherence rate, quantum state fidelity, etc. Quantum gate operations include: gate operation accuracy (fidelity), execution time, calibration status, etc. Processor environment parameters include: ultra-low temperature cooling system temperature (e.g., 10mK level stability), microwave control signal power and phase stability, etc. Error rates include: qubit readout error rate, quantum gate error rate. Quantum communication device behavior includes: single-photon detector behavior, entangled photon source behavior, polarization analyzer and optical modulator behavior, and quantum repeater behavior, etc. Single-photon detector behavior includes: detection efficiency, dark count rate, dead time, afterpulse probability, etc. Entangled photon source behavior includes... The behaviors of quantum repeaters include: entanglement generation rate, entanglement fidelity, and photon polarization / time mode stability; polarization analyzer and optical modulator behavior includes: modulation accuracy, switching speed, and polarization extinction ratio; quantum repeater behavior includes: entanglement swapping success rate, storage time, signal amplification gain, and noise figure; quantum sensing device behavior includes: sensor output and calibration status, with sensor output including: magnetic field sensitivity of atomic magnetometers, angular velocity measurement accuracy of quantum gyroscopes, and signal stability; calibration status including: drift of sensor calibration parameters and environmental noise suppression capability; and attack injection module behavior includes: variable attenuator behavior, electronic jammer behavior, and fiber optic splitter behavior. Variable optical attenuator behavior includes: attenuation accuracy and response speed; electronic jammer behavior includes: frequency, amplitude, and modulation mode of the interference signal; and fiber optic splitter behavior includes: splitting ratio stability and insertion loss.
[0048] Therefore, by analyzing the device's operating behavior, the control management layer can determine whether the quantum device is working normally within the expected parameters, identify performance degradation or abnormal responses caused by hardware failure, aging, or physical layer / side channel attacks, and thus assess the physical security and reliability of the quantum device.
[0049] Furthermore, network behavior includes: quantum channel behavior, classical channel and hybrid network behavior, topology and routing behavior, and system-level cooperative behavior. Quantum channel behavior includes: traditional performance, protocol interaction, and security events. Transmission performance includes: quantum bit error rate, channel loss, key generation rate, and effective entanglement distribution rate; protocol interaction includes: quantum key distribution protocol handshake success rate, synchronization signal timing, and anomalies in the basis vector comparison process; security events include: number of eavesdropping detection triggers, key negotiation failure events, and authentication failure logs. Classical channel and hybrid network behavior includes: network performance, control signaling, and traffic patterns. Network performance includes: round-trip time, throughput, packet loss rate, and bandwidth utilization of classical data packets; control signaling includes: delivery rate and latency of software-defined network control commands, device configuration update status, and routing table change records; traffic patterns include: normal... Distribution, identification, and isolation effectiveness of business traffic and simulated attack traffic; topology and routing behavior including: topology status and routing status, topology status including: online / offline status of network nodes (physical and simulated), link connection status (connected / disconnected / degraded), etc., routing dynamics including: path switching events triggered by software-defined network controllers, execution results of traffic redirection, path recovery time under ring / mesh topology, etc.; system-level collaborative behavior including: task coordination and defense linkage, task coordination including: synchronous execution progress of test scripts among various devices and controllers, step triggering sequence, etc., defense linkage including: when an attack is detected, the coordinated response and timeliness of cross-layer defense measures such as quantum channel shutdown, classical channel switching, and firewall rule updates, etc.
[0050] In summary, by capturing and analyzing network behavior, the control management layer can assess the actual security of quantum communication protocols, the network's resilience to attacks at the protocol and network layers, and the collaborative management and defense capabilities of quantum-classical hybrid networks. This provides crucial data for discovering protocol vulnerabilities, evaluating network architecture security, and verifying the effectiveness of defense strategies.
[0051] In this embodiment, a practically operable quantum physics communication scenario is constructed using multiple quantum devices and a fiber optic backbone network in the physical hardware layer. A quantum simulation scenario is provided through a virtualization layer, which also injects corresponding quantum network attacks into the quantum simulation scenario. Users allocate hardware resources and configure test parameters for the quantum physics communication scenario and the quantum simulation communication scenario through a unified management platform, and can also issue test tasks to the control management layer. Based on the resource scheduling instructions and parameter configuration instructions issued by the management platform, the control management layer sends corresponding control signals to the underlying physical hardware layer and the virtualization layer to adjust the quantum physics scenario and the quantum virtual scenario. The control management layer also loads corresponding preset test scripts based on the test tasks issued by the management platform to control the execution of test tasks in the quantum physics communication scenario and the quantum simulation communication scenario, and monitors the device operation behavior and network behavior of the quantum physics communication scenario and the quantum simulation communication scenario in real time. The quantum network security testing system, by combining the quantum physics communication scenario and the quantum simulation communication scenario, comprehensively supports the joint security testing of quantum hardware, communication protocols, and quantum algorithms. Furthermore, the quantum simulated communication scenario integrates classical and quantum hybrid networks, which can verify the security defense capabilities of quantum and classical collaborative networks. The management platform also provides a controllable quantum hardware attack interface, allowing users to simulate physical-level attacks on quantum devices to discover potential hardware vulnerabilities. In this way, the goal is to enrich the quantum network testing environment while simultaneously improving quantum network security assessment capabilities and quantum network attack simulation capabilities.
[0052] In one alternative implementation, see [link to implementation details]. Figure 2 The quantum network security testing system 10 provided in this application embodiment includes multiple quantum devices 1041 in the physical hardware layer 104, including at least one quantum computer 411, at least one quantum repeater 412, at least one quantum sensor 413, and at least one optical switch 414. The optical fiber backbone network 1042 includes optical fiber 421 and dense wavelength division multiplexing optical fiber 422.
[0053] Each quantum computer 411 and each quantum sensor 413 is connected to each optical switch 414 via optical fiber 421. Each optical switch 414 is connected to each quantum repeater 412 or optical switch 414 via dense wavelength division multiplexing optical fiber 422 to form a ring or mesh topology.
[0054] Optionally, the optical fiber backbone network 1042 specifically includes two core components: standard optical fiber 421 and dense wavelength division multiplexing (DWDM) optical fiber 422. The standard optical fiber 421 is primarily used for short-distance, high-fidelity connections between the quantum devices 1041 and the core switching nodes. Each quantum computer 411 and each quantum sensor 413 is connected to the nearest or designated optical switch 414 via the standard optical fiber 421 to ensure that control signals and quantum / sensor data can be efficiently and with low loss access to the core network.
[0055] Optionally, the optical switch 414 is the core node of the network topology. The optical switches 414 are connected to each other, and to the long-distance quantum repeater 412, via dense wavelength division multiplexing (DWDM) optical fiber 422. DWDM technology enables the simultaneous transmission of multiple wavelengths of optical signals in a single optical fiber, significantly improving the capacity and flexibility of the backbone link. Furthermore, this connection method allows the system to construct ring or mesh topologies.
[0056] Furthermore, ring topology provides path redundancy, enhancing network reliability; mesh topology offers greater connectivity flexibility and routing options, facilitating the simulation of complex multi-node quantum network scenarios and supporting dynamic reconfiguration to adapt to different testing needs.
[0057] Each quantum computer 411 is used to test the security of quantum computing power.
[0058] Optionally, each quantum computer 411 is primarily used to test the security of quantum computing power. This includes evaluating the physical stability of the quantum processor when executing specific quantum algorithms (such as Shor's algorithm and quantum machine learning algorithms), the fidelity of quantum gate operations, and the correctness and reliability of its output results when subjected to computational task loads or side-channel interference. It is worth noting that quantum computer 411 provides a direct hardware experimental platform for identifying security vulnerabilities in core quantum computing components.
[0059] Each quantum repeater 412 is used for entanglement distribution and signal amplification to measure the security of long-distance quantum communication.
[0060] Optionally, each quantum repeater 412 is key to realizing long-distance quantum communication. The quantum repeaters 412 are deployed at key nodes in the optical fiber path (e.g., at certain intervals) and are mainly used for entanglement distribution and signal amplification.
[0061] Optionally, by testing the performance of quantum repeaters in the link under different distances, different channel losses, and under attack conditions (such as signal interception and tampering), the actual security of long-distance quantum communication links can be systematically measured and evaluated, and it can be verified whether they can still maintain the theoretically expected security characteristics.
[0062] Each quantum sensor 413 is used to acquire quantum sensing data of the object being measured.
[0063] Optionally, each quantum sensor 413 (such as an atomic magnetometer or a quantum gyroscope) is used to acquire quantum sensing data of the object under test with high precision.
[0064] Specifically, in security testing, these quantum sensing data can reflect changes in the physical environment (such as electromagnetic disturbances and temperature fluctuations), which may be caused by attacks or by physical defects in the system itself.
[0065] Furthermore, analyzing quantum sensing data can help discover potential side-channel information leakage or environmental interference vulnerabilities at the physical level.
[0066] Each optical switch 414 is used to isolate the quantum channel and the classical channel.
[0067] Optionally, each optical switch 414 plays a key role in signal routing and isolation. The optical switch 414 is responsible for isolating the transmission of quantum channels and classical channels. This isolation can effectively prevent classical control signals and data traffic from causing crosstalk or interference to extremely fragile quantum states (such as single photons), thereby ensuring the purity and security of quantum state transmission and laying the foundation for building a trustworthy quantum physics testing environment.
[0068] In the embodiments of this application, the hardware structure of the physical hardware layer clearly defines the physical infrastructure that supports the operation of the entire quantum network security testing system. This provides material support for conducting in-depth testing on real hardware in dimensions such as quantum computing security, long-distance communication security, and physical layer perception security. It is an important foundation for realizing the integrated testing capability of this invention.
[0069] In one alternative implementation, see [link to implementation details]. Figure 2 The physical hardware layer 104 of the quantum network security testing system 10 provided in this application embodiment further includes an attack injection module 1043, which includes an optical fiber splitter 431, a variable optical attenuator 432, and an electronic jammer 433.
[0070] Optionally, the attack injection module 1043 is a key component for realizing proactive, controllable, and diversified physical layer security testing capabilities, enabling the quantum network security testing system to simulate and reproduce a series of typical quantum network physical layer attacks from the attacker's perspective in a real hardware environment.
[0071] Specifically, the attack injection module 1043 is integrated into the physical hardware layer 104 as a controllable and programmable test intervention unit. The fiber optic splitter 431, variable optical attenuator 432, and electronic jammer 433 in the attack injection module 1043 can be strategically connected to the fiber optic backbone network 1042 or located near the target quantum device, and execute preset attack operations under the instructions of the control management layer 102.
[0072] The attack injection module 1043 is used to simulate quantum attack operations of eavesdropping or splitting quantum signals on the physical hardware layer 104 via the fiber optic splitter 431.
[0073] Optionally, the fiber optic splitter 431, as a passive optical device, is connected to the target quantum communication link (e.g., between the endpoint and the relay) and can distribute the transmitted optical signal (including single photons carrying quantum information) to two or more output ports in a specific ratio.
[0074] Specifically, one port connects to the legitimate receiver, while the other port connects to a simulated "eavesdropper" measuring device. In this way, the attack injection module 1043 can non-intrusively divert a portion of the optical signal, thereby simulating an attacker's eavesdropping or traffic analysis behavior on the physical link. This provides a direct and realistic test scenario for evaluating the quantum key distribution system's ability to detect and resist eavesdropping techniques such as photon number splitting attacks.
[0075] The attack injection module 1043 is also used to simulate signal loss or perform denial-of-service quantum attack operations on the physical hardware layer 104 via the variable optical attenuator 432.
[0076] Optionally, signal loss can be simulated or denial-of-service attacks can be performed using the variable optical attenuator 432. The variable optical attenuator 432 is an active device capable of precisely adjusting the attenuation of the optical signal, and is connected in series with a quantum channel or a classical control channel.
[0077] Specifically, the variable optical attenuator 432 can simulate additional channel loss caused by long-distance transmission or harsh environments by dynamically increasing the attenuation amount, and test the performance limits and stability of the system when channel conditions deteriorate.
[0078] Optionally, a denial-of-service attack against a quantum link can be simulated by adjusting the attenuation value to an extreme value, or even completely blocking the transmission of optical signals. It should be noted that a denial-of-service attack aims to disrupt the establishment of quantum entanglement, key distribution, or sensor data transmission to assess the availability and resilience of network services.
[0079] The attack injection module 1043 is also used to perform electromagnetic interference on each quantum device on the physical hardware layer 104 via the electronic jammer 433 to simulate side-channel attack operations.
[0080] Optionally, the electronic jammer 433 is placed near the target quantum device (such as a single-photon detector, quantum computer control cable, or sensing circuit) to generate electromagnetic signals of a specific frequency, amplitude, and modulation mode.
[0081] Optionally, the electronic jammer 433 simulates the physical environment of a side-channel attack by emitting controlled electromagnetic interference toward the target device. For example, it may attempt to influence the operating point of an avalanche diode in a single-photon detector or interfere with the precision control electronics of a quantum computer, aiming to induce abnormal operating timing, power consumption patterns, or erroneous outputs that could potentially leak sensitive information or disrupt system functionality. This provides a crucial experimental means for studying and verifying the vulnerability of quantum devices to physical attacks such as electromagnetic interference and for developing protective measures (such as shielding and filtering algorithms).
[0082] In the embodiments of this application, an attack injection module integrated into the physical hardware layer enables a leap from passive monitoring to active attack simulation. This allows testers to systematically introduce, control, and quantify various attack vectors at a real physical layer, thereby comprehensively verifying the actual protective capabilities of quantum hardware and underlying links against known physical attacks, proactively discovering novel vulnerabilities that quantum devices may expose under non-ideal operating conditions, and evaluating the effectiveness of different defense schemes in real adversarial environments.
[0083] In one alternative implementation, see [link to implementation details]. Figure 3 The control management layer 102 of the quantum network security testing system 10 provided in this application embodiment includes: a quantum computing controller 1021, a quantum communication controller 1022, a quantum sensing controller 1023, a software-defined network controller 1024, an orchestration engine 1025, and a monitoring and log acquisition unit 1026.
[0084] Optionally, the control management layer 102, as the intelligent hub and coordination engine connecting the management platform 101 with the underlying physical hardware layer 104 and the virtualization layer 103, is the key to realizing test automation, precise control and panoramic monitoring.
[0085] The quantum computing controller 1021 is used to run quantum compilation and error correction algorithms, and controls each quantum computer 411 through the instruction set of the quantum processing unit, so that each quantum computer 411 loads and runs the corresponding quantum program, and reads the loading and running results of each quantum computer 411.
[0086] Optionally, the quantum computing controller 1021 is deployed on a dedicated server and is the core of managing quantum computing resources. The main functions of the quantum computing controller 1021 include: running quantum compilation, running error correction algorithms, and controlling the quantum computer 411.
[0087] Specifically, running quantum compilation refers to compiling user-defined high-level quantum algorithms into a sequence of microinstructions that can be recognized by the underlying quantum computer 411; running error correction algorithms refers to integrating the encoding and decoding logic of quantum error correction codes during compilation or execution to evaluate the effectiveness of error correction capability in ensuring computational reliability in noisy environments or under attack interference.
[0088] Optionally, the quantum computing controller 1021 sends a precise sequence of control pulses to the quantum computer 411 via a dedicated quantum processing unit instruction set, instructing it to load, initialize, and execute quantum programs, and ultimately read the measurement results of the quantum state, in order to complete a security test of the quantum computer's computing power.
[0089] The quantum communication controller 1022 is used to coordinate the establishment of secure channels among nodes in a quantum physics communication scenario, and to control the preparation and distribution of quantum states as well as the transmission and measurement of quantum signals.
[0090] Optionally, the quantum communication controller 1022 serves as the command center for quantum network communication, typically integrating drivers and interfaces for hardware such as entangled photon sources, single-photon detectors, and polarization controllers. The quantum communication controller 1022 is primarily used to coordinate the establishment of secure channels and control quantum state operations.
[0091] Specifically, the quantum communication controller 1022 is used in quantum physics communication scenarios to coordinate communication endpoints and relay nodes, execute the handshake, negotiation and synchronization process of the QKD protocol or entanglement distribution protocol, and establish a usable quantum secure channel.
[0092] Furthermore, the quantum communication controller 1022 is also used to prepare specifically encoded quantum states (such as polarization states and phase states), distribute entangled photon pairs or key particles, and control the receiver to measure quantum signals.
[0093] In summary, the quantum communication controller 1022 can achieve precise control over the entire quantum communication process, providing a direct control interface for simulating protocol layer attacks and assessing protocol security.
[0094] The quantum sensing controller 1023 is used to analyze the quantum sensing data uploaded by each quantum sensor in real time.
[0095] Optionally, the quantum sensing controller 1023 is responsible for interacting with the quantum sensors to parse the raw quantum sensing data (such as atomic spin readings and interference phase differences) uploaded by each quantum sensor.
[0096] Specifically, the quantum sensor controller 1023 converts the original physical signal into high-precision measurement information (such as magnetic field strength and rotation rate) through built-in calibration algorithm, noise reduction algorithm and feature extraction module.
[0097] Furthermore, the quantum sensing controller 1023 provides real-time, high-sensitivity data from the physical world for security assessment, enabling the detection of environmental disturbances or abnormal changes in the physical state of devices caused by attacks. It is an important source of information for discovering side-channel leaks or physical intrusions.
[0098] The software-defined network controller 1024 is used to dynamically modify routing, injected traffic, and redirected signals in quantum physical communication scenarios and quantum simulation communication scenarios to reconstruct the network topology in quantum physical communication scenarios and quantum simulation communication scenarios.
[0099] Optionally, the software-defined network controller 1024 is used for unified and centralized control of the quantum and classical hybrid network.
[0100] The software-defined network controller 1024 is primarily used for dynamically modifying routes, injecting traffic, and redirecting signals. For example, it can change classical or quantum transmission paths in real time according to testing needs or to respond to attacks; it can also controllably inject test traffic or simulated attack traffic into quantum networks and redirect specific signals to monitoring or analysis nodes.
[0101] In addition, the software-defined network controller 1024 can dynamically and software-definedly reconstruct the network topology of quantum physics communication scenarios and quantum simulation communication scenarios, and quickly switch between different topologies such as star, ring, and mesh.
[0102] The orchestration engine 1025 is used to automatically deploy quantum physics communication scenarios and quantum simulation communication scenarios based on preset test scripts.
[0103] Optionally, the orchestration engine 1025 can automatically deploy based on preset test scripts. Specifically, the orchestration engine 1025 automatically coordinates and calls the corresponding interfaces of the aforementioned controllers, virtualization layer 103, and management platform 101 based on preset test scripts, completing a one-click deployment and execution of the entire process from resource configuration, network setup, attack injection to task startup. This greatly improves the efficiency, repeatability, and accuracy of complex cross-layer, multi-step security testing, and reduces errors caused by manual intervention.
[0104] The monitoring and log collection unit 1026 is used to monitor the response behavior in quantum physics communication scenarios and quantum simulation communication scenarios in real time, and generate logs and alarm information based on the response behavior.
[0105] Optionally, the monitoring and log collection unit 1026 can monitor the response behavior in both quantum physics communication scenarios and quantum simulation communication scenarios in real time. Specifically, it continuously collects data on device operation and network behavior from various controllers, hardware quantum devices, virtual nodes, and network links.
[0106] Optionally, the monitoring and log collection unit 1026 can also be used to generate logs and alarm information. Specifically, it standardizes the collected raw data, events, and system state changes into timestamped log records and stores them persistently. At the same time, based on preset rules or anomaly detection models, it generates alarm information in real time for security events (such as a sudden increase in QBER or key negotiation failure) or system failures, and notifies the management platform or relevant personnel.
[0107] In the embodiments of this application, this integrated control management layer provides core support for flexible, efficient, and comprehensive security assessment, which is significantly different from existing fragmented testing tools.
[0108] In one alternative implementation, see [link to implementation details]. Figure 3 The quantum communication controller 1022 in the control management layer 102 of the quantum network security testing system 10 provided in this application embodiment includes: entangled photon source 221, single photon detector 222 and polarization analyzer 223.
[0109] Optionally, the quantum communication controller 1022 makes the specific implementation and operation mechanism of the quantum communication controller 1022 clearer through the entangled photon source 221, the single photon detector 222 and the polarization analyzer 223.
[0110] The quantum communication controller 1022 generates a specific quantum state via the entangled photon source 221 and controls the distribution of the specific quantum state according to a preset path.
[0111] Optionally, the entangled photon source 221 serves as the signal generator of the quantum communication controller 1022, operating based on a nonlinear optical process to generate photons in a specific quantum state. This specific quantum state can be, for example, a pair of photons highly entangled in polarization, time, or energy; this application does not specifically limit this.
[0112] Specifically, under the control commands issued by the quantum communication controller 1022, the entangled photon source 221 is activated to generate entangled photon pairs or single-photon sequences encoded with information that meet the testing requirements. Furthermore, the quantum communication controller 1022 controls these photons to be distributed in the quantum network according to a preset path (the route set by the software-defined network controller 1024, etc.).
[0113] The quantum communication controller 1022 receives, analyzes, and measures quantum signals from the quantum channel via a single-photon detector 222 and a polarization analyzer 223.
[0114] Optionally, the single-photon detector 222 serves as a highly sensitive receiver for quantum signals, capable of detecting extremely weak single-photon level optical signals.
[0115] Specifically, at the receiving end, the single-photon detector 222 is responsible for receiving the extremely weak quantum light signal transmitted from the quantum channel and converting it into a recordable electrical pulse signal. It is worth noting that the detection efficiency, dark count rate, and timing jitter of the single-photon detector directly affect the final performance and security boundaries of quantum communication.
[0116] Optionally, the polarization analyzer 223 typically consists of a series of dynamically switchable waveplates, polarization beam splitters, and auxiliary detectors.
[0117] Among them, the polarization analyzer 223 works in conjunction with the single-photon detector 222 to analyze and measure the received optical signal. The polarization analyzer 223 can select a specific measurement basis vector to project and measure the polarization state of the photon according to the communication protocol requirements or test script.
[0118] In the embodiments of this application, this quantum communication controller clearly defines the key physical entities required to realize the quantum communication control function, avoiding ambiguity in functional description and enhancing the focus and depth of security testing. Furthermore, using real quantum optical devices to construct the communication link can more accurately reproduce all non-ideal characteristics present in actual quantum communication systems, thus making the security test results more valuable for practical reference.
[0119] In one alternative implementation, see [link to implementation details]. Figure 4 The virtualization layer 103 in the quantum network security testing system 10 provided in this application embodiment includes: virtual quantum node 1031, virtual classical node 1032 and simulated attack unit 1033.
[0120] The virtual quantum node 1031 is used to simulate quantum communication scenarios involving fiber optic fading and environmental noise in long-distance fiber optic transmission.
[0121] Optionally, the virtual quantum node 1031 is a software simulator for a quantum communication and computing environment. It simulates the operational characteristics of real quantum devices and links using high-fidelity quantum physics and channel models. Specifically, the virtual quantum node 1031 is primarily used to simulate fiber optic fading and environmental noise in long-distance fiber optic transmission scenarios, thereby constructing a realistic quantum simulation communication scenario.
[0122] Specifically, the virtual quantum node 1031 can accurately calculate and simulate the transmission loss, dispersion, and polarization mode dispersion effects experienced by quantum signals at different distances and with different fiber types.
[0123] Furthermore, the virtual quantum node 1031 can simulate unavoidable environmental noise in the real world, such as background light noise and detector thermal noise. This enables researchers to study and evaluate the security challenges and performance limits that quantum protocols and systems may face under complex, harsh, or ultra-long-distance real-world deployment conditions in a laboratory environment, at low cost and with high efficiency.
[0124] The Virtual Classic Node 1032 is used to simulate quantum communication scenarios involving network attack hosts, eavesdropping nodes, and defense nodes.
[0125] Optionally, the virtual classic node 1032 is typically created quickly based on mature virtualization technologies (such as virtual machines or containers) and is mainly used to simulate network attack hosts, eavesdropping nodes, and defense nodes, thereby constructing a complex hybrid network security attack and defense quantum simulation communication scenario.
[0126] Specifically, the virtual classic node 1032 can be used to simulate hosts launching various classical or cross-layer attacks; it can also simulate malicious nodes passively listening to and analyzing network traffic; and it can simulate firewalls, intrusion detection systems, security authentication servers, and other defensive facilities to test their collaborative defense capabilities with the quantum system. In this way, complex network topologies containing a large number of nodes can be quickly constructed, simulating the distribution and behavior of attackers and defenders in a real network environment, providing an indispensable testbed for studying the overall security architecture and dynamic adversarial mechanisms of quantum-classical hybrid networks.
[0127] The simulated attack unit 1033 is used to simulate quantum network attacks in a quantum simulated communication scenario provided by the virtualization layer.
[0128] Optionally, the simulated attack unit 1033 is used to simulate various quantum network attacks in the quantum simulated communication scenario provided by the virtualization layer 103. Specifically, the quantum network attack can be a protocol layer attack simulation, a network layer attack simulation, or a software vulnerability exploitation simulation, etc., and this application does not impose any specific limitations on this.
[0129] In this embodiment, by organically combining virtual quantum nodes, virtual classical nodes, and simulated attack units, large-scale, multi-node parallel testing and preliminary research can be conducted even when physical hardware resources are limited or too costly, significantly reducing the initial threshold and trial-and-error costs of quantum security research. Furthermore, complex test network topologies and attack scenarios can be rapidly created, modified, or destroyed within minutes according to testing needs.
[0130] In one alternative implementation, see [link to implementation details]. Figure 5The management platform 101 in the quantum network security testing system 10 provided in this application embodiment includes: a resource scheduling module 1011 and a console 1012.
[0131] The resource scheduling module 1011 is used to schedule resources for quantum physics communication scenarios and quantum simulation communication scenarios based on the configuration information entered by the user in the graphical interactive interface. The schedulable resources include: computing power resources of quantum computers, bandwidth resources of quantum repeaters, and resolution resources of quantum sensors.
[0132] Optionally, the resource scheduling module 1011 is used to perform unified abstraction, pooling, and on-demand allocation of all available computing, communication, and sensing resources at the underlying level.
[0133] Specifically, the resource scheduling module 1011 automatically parses the resource requirements of the test task based on the configuration information input by the user in the graphical interface, and performs unified scheduling of physical and virtual resources in the quantum physics communication scenario and the quantum simulation communication scenario.
[0134] Among them, schedulable computing resources refer to the number of qubits, quantum gate operation time slices, and dedicated computing periods allocated to specific test tasks. The resource scheduling module 1011 can fairly and efficiently allocate scarce quantum computing resources among multiple concurrent test tasks. The bandwidth resources of quantum repeaters refer to the channel capacity and time window of quantum repeaters used for entanglement distribution or signal forwarding. The resource scheduling module 1011 can dynamically adjust the operating frequency or duty cycle of each repeater node to adapt to the bandwidth requirements of different test scenarios. The resolution resources of quantum sensors refer to the computing resources used for real-time processing and analysis of the raw data stream of quantum sensors and the bandwidth for data upload. The resource scheduling module 1011 ensures that the sensor data can be resolved in a timely and accurate manner for secure analysis.
[0135] Console 1012 is used to configure parameters for quantum physics communication scenarios and quantum simulation communication scenarios based on the configuration information entered by the user in the graphical interactive interface, so as to trigger the corresponding test tasks.
[0136] Optionally, the console 1012 can be used for parameter configuration and triggering test tasks. Parameter configuration involves the user inputting configuration information through the graphical interface. The console provides rich parameter configuration interfaces for detailed parameter settings in both quantum physics communication and quantum simulation communication scenarios. Triggering test tasks refers to the user issuing the final execution command through the console after completing resource configuration and parameter settings. The console then formally submits the integrated task request to the control management layer, thereby triggering the corresponding test task to start execution.
[0137] In one alternative implementation, see [link to implementation details]. Figure 5The management platform 101 in the quantum network security testing system 10 provided in this application embodiment also includes a security audit module 1013.
[0138] The security audit module 1013 is used to monitor security events and quantum channel attack events during the quantum key distribution process at the physical hardware layer and virtualization layer.
[0139] Optionally, the security audit module 1013 is primarily used to monitor security events during the quantum key distribution process. Specifically, the security audit module 1013 deeply intervenes in the entire execution cycle of the quantum key distribution protocol, from initial negotiation, quantum state transmission, basis vector comparison, error correction to final privacy amplification, monitoring and analyzing in real time all security-related events reported by the control layer 102 and the underlying physical hardware layer 104. It is worth noting that the monitoring scope of the security audit module 1013 includes, but is not limited to, protocol handshake anomalies, authentication failures, abnormally high quantum bit error rates, key negotiation aborts, and privacy amplification process alarms.
[0140] Optionally, the security audit module 1013 is also used to record quantum channel attack events, mainly for collecting and recording attack events that occur throughout the test environment and are directly related to the quantum channel. These quantum channel attack events may be actively triggered by the attack injection module of the physical hardware layer 104, or generated by the simulation attack unit of the virtualization layer 103, or even unknown interference that is accidentally discovered during testing.
[0141] Specifically, the security audit module 1013 can record in detail the type of attack, the timestamp of the attack, the physical or virtual target of the attack, the attack parameters and strength, and the corresponding preliminary detection results of the system.
[0142] In one alternative implementation, see [link to implementation details]. Figure 5 The management platform 101 in the quantum network security testing system 10 provided in this application embodiment also includes a visual interface 1014.
[0143] The visualization interface 1014 is used to display the network topology, quantum state fidelity, quantum sensing data, and security indicators of quantum physics communication scenarios and quantum simulation communication scenarios in real time.
[0144] Optionally, the visualization interface 1014 can display the network topology in real time. The network topology refers to the dynamic display of the real-time network connection status of quantum physics communication scenarios and quantum simulation communication scenarios in the form of nodes and connection diagrams. Based on the network topology, the current connection relationships, on / off status, and traffic flow of physical quantum devices, virtual nodes, optical switches, and the links between them (quantum channels and classical channels) can be clearly understood. Optionally, the visualization interface 1014 can also plot or digitally display the fidelity change curves of key quantum states in real time. For example, it can show the evolution of the fidelity of a specific target quantum state over time or operation steps during the execution of an algorithm by a quantum computer; or show the change of the entanglement fidelity of entangled photon pairs in quantum communication with transmission distance or attack interference.
[0145] Optionally, the visualization interface 1014 can visualize the high-precision sensing data resolved by the quantum sensor controller in real time in the form of waveforms, spectrum graphs, or numerical dashboards. For example, it can display the curve of the change of the ambient magnetic field strength monitored by the atomic magnetometer over time, helping users intuitively perceive the subtle disturbances in the physical environment.
[0146] Optionally, the visualization interface 1014 can also centrally display a series of core security performance indicators, such as the real-time quantum bit error rate, key generation rate, security event alarm statistics, and attack injection status of each QKD link.
[0147] In this embodiment, quantum physicists, cybersecurity experts, and engineers will be able to quickly and intuitively grasp the macroscopic state and microscopic details of the entire complex testing platform without having to delve into command lines or analyze raw logs, greatly improving the efficiency of cross-domain collaboration and problem localization.
[0148] Figure 6 A schematic diagram of a quantum network relay node attack test process provided in this application is shown below. Figure 6The process of the quantum entanglement network intermediate node hijacking attack test scenario based on the quantum network security test system is as follows: (1) First, complete the physical hardware layer deployment: deploy two quantum communication endpoints A and B and an entangled relay node R in the physical hardware layer. Endpoints A and B are each equipped with a single photon detector (SPD) and a polarization analyzer (PA) for receiving and measuring quantum states; an entangled photon source (EPS) is configured at the relay node R to generate and distribute entangled photon pairs; (2) Configure test parameters and start test tasks in the control management layer: the control management layer models and configures the quantum and classical channels of A→R→B through the SDN controller, and then starts the experimental orchestration engine, loads the preset "relay hijacking" test script, and prepares to execute the attack. Test; (3) Simulation and injection of quantum network attacks: A controllable optical attenuator and a programmable delay unit are inserted into the classical control and attack injection module to simulate the tampering behavior of relay node R, such as interfering with the transmission of quantum entanglement by attenuating photon signals or introducing delay, simulating attack methods in the real world; (4) Real-time monitoring and data acquisition: During the experiment, the monitoring and log acquisition unit collects the measured bit error rate (QBER), key throughput and detected abnormal events of endpoints A and B in real time; (5) Report generation and analysis: After the experiment, the management platform automatically generates a detailed test report and displays the change curves of key security indicators such as QBER and key rate under different hijacking strengths and tampering strategies.
[0149] Figure 7 A quantum network security testing method provided for this application, see [link to relevant documentation]. Figure 7 This method is applied to the aforementioned quantum network security testing system 10. The quantum network security testing method provided in this application embodiment includes: S701. Each quantum device is interconnected via a fiber optic backbone network to form a quantum physics communication scenario; a virtualization layer is used to simulate quantum communication scenarios and quantum network attacks under different operating conditions. S702 provides a graphical user interface based on the management platform to obtain user requests for resource scheduling and parameter configuration for quantum physics communication scenarios and quantum simulation communication scenarios, and issues test tasks to the control management layer in response to user input commands; S703, based on resource scheduling instructions and parameter configuration instructions issued by the management platform, sends corresponding control signals to each quantum device and virtualization layer in the quantum physical communication scenario to adjust the quantum physical communication scenario and the quantum simulation communication scenario. At the same time, based on the test tasks issued by the management platform, it loads preset test scripts to control the execution of test tasks in the quantum physical communication scenario and the quantum simulation communication scenario, and monitors the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario in real time. The response behavior includes: device operation behavior and network behavior.
[0150] The specific implementation process and technical effects of this method are exactly the same as those of the aforementioned quantum network security testing system, and will not be repeated here.
[0151] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps in the various method embodiments described above.
[0152] Optionally, this application also provides a program product, such as a computer-readable storage medium, including a program that, when executed by a processor, is used to perform an embodiment of any of the above-described quantum network security testing methods.
[0153] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute certain steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0154] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0155] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A quantum network security testing system, characterized in that, The quantum network security testing system includes: a management platform, a control management layer, a virtualization layer, and a physical hardware layer; multiple quantum devices and an optical fiber backbone network are deployed on the physical hardware layer, and the quantum devices are interconnected through the optical fiber backbone network to form a quantum physical communication scenario. The virtualization layer is used to simulate quantum communication scenarios and quantum network attacks under different operating conditions; The management platform is used to provide a graphical user interface so that users can perform resource scheduling and parameter configuration for the quantum physics communication scenario and the quantum simulation communication scenario through the graphical user interface. The management platform responds to the user's input instructions and issues test tasks to the control management layer. The control management layer is used to send corresponding control signals to each quantum device and the virtualization layer in the quantum physical communication scenario based on the resource scheduling instructions and parameter configuration instructions issued by the management platform, so as to adjust the quantum physical communication scenario and the quantum simulation communication scenario. At the same time, the control management layer loads a preset test script based on the test task issued by the management platform to control the quantum physical communication scenario and the quantum simulation communication scenario to execute the test task, and monitors the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario in real time. The response behavior includes device operation behavior and network behavior.
2. The quantum network security testing system according to claim 1, characterized in that, The plurality of quantum devices include: at least one quantum computer, at least one quantum repeater, at least one quantum sensor, and at least one optical switch; the optical fiber backbone network includes: optical fiber and dense wavelength division multiplexing optical fiber. Each of the quantum computers and each of the quantum sensors are connected to each of the optical switches via the optical fiber. Each of the optical switches is connected to each of the quantum repeaters or the optical switches via the dense wavelength division multiplexing optical fiber to form a ring or mesh topology. Each of the quantum computers described is used to test the security of quantum computing power; Each of the aforementioned quantum repeaters is used for entanglement distribution and signal amplification to measure the security of long-distance quantum communication; Each of the aforementioned quantum sensors is used to acquire quantum sensing data of the object under test; Each of the optical switches is used to isolate quantum channels and classical channels.
3. The quantum network security testing system according to claim 1, characterized in that, The physical hardware layer also includes an attack injection module, which includes an optical fiber splitter, a variable optical attenuator, and an electronic jammer. The attack injection module is used to simulate quantum attack operations of eavesdropping or splitting quantum signals at the physical hardware layer through the fiber optic splitter; The attack injection module is also used to simulate signal loss or perform denial-of-service quantum attack operations on the physical hardware layer through the variable optical attenuator. The attack injection module is also used to perform electromagnetic interference on each quantum device at the physical hardware layer through the electronic jammer in order to simulate side-channel attack operations.
4. The quantum network security testing system according to claim 2, characterized in that, The control management layer includes: a quantum computing controller, a quantum communication controller, a quantum sensing controller, a software-defined network controller, an orchestration engine, and a monitoring and log acquisition unit; The quantum computing controller is used to run quantum compilation and error correction algorithms, and controls each quantum computer through the instruction set of the quantum processing unit, so that each quantum computer loads and runs the corresponding quantum program, and reads the loading and running results of each quantum computer; The quantum communication controller is used to coordinate the establishment of secure channels for each node in the quantum physics communication scenario, and to control the preparation and distribution of quantum states as well as the transmission and measurement of quantum signals; The quantum sensing controller is used to analyze the quantum sensing data uploaded by each quantum sensor in real time; The software-defined network controller is used to dynamically modify the routing, injected traffic, and redirection signals in the quantum physics communication scenario and the quantum simulation communication scenario, so as to reconstruct the network topology in the quantum physics communication scenario and the quantum simulation communication scenario; The orchestration engine is used to automatically deploy the quantum physics communication scenario and the quantum simulation communication scenario according to a preset test script; The monitoring and log collection unit is used to monitor the response behavior of the quantum physics communication scenario and the quantum simulation communication scenario in real time, and generate logs and alarm information based on the response behavior.
5. The quantum network security testing system according to claim 4, characterized in that, The quantum communication controller includes: an entangled photon source, a single-photon detector, and a polarization analyzer; The quantum communication controller generates a specific quantum state via the entangled photon source and controls the distribution of the specific quantum state according to a preset path; The quantum communication controller receives, analyzes, and measures the quantum signal from the quantum channel through the single-photon detector and the polarization analyzer.
6. The quantum network security testing system according to claim 1, characterized in that, The virtualization layer includes: virtual quantum nodes, virtual classical nodes, and simulated attack units; The virtual quantum node is used to simulate quantum communication scenarios involving fiber optic fading and environmental noise in long-distance fiber optic transmission. The virtual classical node is used to simulate quantum-simulated communication scenarios of network attack hosts, eavesdropping nodes, and defense nodes; The simulated attack unit is used to simulate quantum network attacks in the quantum simulated communication scenario provided by the virtualization layer.
7. The quantum network security testing system according to claim 1, characterized in that, The management platform includes: a resource scheduling module and a console; The resource scheduling module is used to schedule resources for the quantum physics communication scenario and the quantum simulation communication scenario according to the configuration information input by the user in the graphical interactive interface. The schedulable resources include: the computing power resources of the quantum computer, the bandwidth resources of the quantum repeater, and the resolution resources of the quantum sensor. The console is used to configure parameters for the quantum physics communication scenario and the quantum simulation communication scenario based on the configuration information entered by the user in the graphical interface, so as to trigger the corresponding test tasks.
8. The quantum network security testing system according to claim 7, characterized in that, The management platform also includes: a security audit module; The security audit module is used to monitor security events and quantum channel attack events in the physical hardware layer and the virtualization layer during the quantum key distribution process.
9. The quantum network security testing system according to claim 8, characterized in that, The management platform also includes: a visual interface; The visualization interface is used to display the network topology, quantum state fidelity, quantum sensing data, and security indicators of the quantum physics communication scenario and the quantum simulation communication scenario in real time.
10. A quantum network security testing method, characterized in that, The method is applied to the quantum network security testing system according to any one of claims 1-9, and the method includes: The quantum devices are interconnected via the fiber optic backbone network to form a quantum physics communication scenario; the virtualization layer simulates quantum communication scenarios and quantum network attacks under different operating conditions. The management platform provides a graphical user interface to obtain user requests for resource scheduling and parameter configuration for the quantum physics communication scenario and the quantum simulation communication scenario, and issues test tasks to the control management layer in response to user input commands. Based on the resource scheduling instructions and parameter configuration instructions issued by the management platform, corresponding control signals are sent to each quantum device and the virtualization layer in the quantum physical communication scenario to adjust the quantum physical communication scenario and the quantum simulation communication scenario. At the same time, based on the test tasks issued by the management platform, a preset test script is loaded to control the execution of test tasks in the quantum physical communication scenario and the quantum simulation communication scenario, and the response behavior of the quantum physical communication scenario and the quantum simulation communication scenario is monitored in real time. The response behavior includes device operation behavior and network behavior.
Citation Information
Patent Citations
Control system for realizing attack and defense demonstration of multiple quantum communication
CN114629561A
Quantum communication network simulation test platform and method
CN120185725A
Internet of Things test platform adaptation method, system and device based on post quantum cryptography
CN120342587A
Intelligent resource allocation based on security profile of edge device network
US20230370468A1