Hybrid networking method for 5G and quantum communication
By pre-building a hierarchical quantum resource pool and a secure context migration mechanism, the problems of quantum key switching delay and security state isolation in 5G mobile communication are solved, realizing seamless switching and continuity of security state, and improving resource utilization and communication robustness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-03-13
AI Technical Summary
Existing technologies in quantum key distribution for 5G mobile communication suffer from switching delays and security risks, fail to effectively utilize quantum resources, and result in communication discontinuity and reduced security due to the isolation of secure states.
By pre-building a tiered quantum resource pool, combining user mobility and service quality predictions, and negotiating and migrating security contexts in advance, seamless switching of quantum keys is achieved, and a verifiable trust chain is built through key derivation and evolution mechanisms.
It achieves low latency, high reliability, service continuity and security, optimizes the utilization of quantum resources, and enhances the robustness and security of end-to-end communication.
Smart Images

Figure CN121664418A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of mobile communication and quantum security technology, specifically to a hybrid networking method of 5G and quantum communication. Background Technology
[0002] Fifth-generation mobile communication technology (5G), as a new generation of communication infrastructure, aims to provide diverse services such as ultra-reliable low-latency communication (URLLC) and enhanced mobile broadband (eMBB). To ensure the data security of 5G communications, especially in critical application scenarios involving national security, financial transactions, and autonomous driving, quantum key distribution (QKD) technology, due to its unconditional security based on the fundamental principles of quantum mechanics, is considered an ideal technical means to ensure the security of future communication networks. Therefore, integrating QKD technology into the 5G network architecture to build a mobile communication system with quantum security capabilities has become an important direction in current technological development.
[0003] However, in the actual deployment of QKD technology in 5G mobile communications, existing technical solutions have several inherent defects that are difficult to overcome. When a mobile user equipment needs to hand over between different base stations, existing technologies typically adopt a "disconnect first, reconnect later" or "negotiate while handing over" mode. This means that the QKD session between the user equipment and the source base station must be interrupted, and a complete quantum key negotiation must be re-initiated with the target base station. This negotiation process, including steps such as quantum state transmission, basis vector comparison, error correction, and security enhancement, inherently involves physical interaction and post-processing computation, resulting in significant time delays. These delays far exceed the millisecond-level handover requirements of 5G networks. The resulting long key gap not only causes serious interruptions to upper-layer services but also exposes serious security risks at the moment of handover.
[0004] Furthermore, existing technologies lack the ability to perceive the diverse needs of 5G services when allocating quantum resources. One of the core features of 5G networks is providing differentiated Quality of Service (QoS) guarantees for different applications, but existing QKD networking methods typically treat all key requests equally with a "one-size-fits-all" approach. This model fails to prioritize the allocation of valuable, high-quality quantum resources to critical services with the highest security requirements (such as URLLC), and also fails to select more cost-effective security strategies for ordinary services that are not sensitive to latency. This results in inefficient utilization of quantum resources, limiting the service capabilities and scalability of the entire hybrid networking system.
[0005] Another significant drawback lies in the isolation of security states in the current handover scheme. Each QKD session established after a handover generates a session key that is cryptographically completely independent of the previous session. This "security state reset" breaks the security trust chain of the user device throughout its entire movement trajectory. This session isolation means that attackers can focus their attacks on the handover vulnerability, and the system lacks a mechanism to correlate and verify the security states before and after the handover. This makes it unable to effectively defend against context forgery or replay attacks targeting the handover process, thus reducing the overall security of end-to-end communication. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to provide a hybrid networking method and system for 5G and quantum communication that enables seamless switching of quantum secure keys and ensures continuous evolution of the security state in 5G mobile communication scenarios.
[0007] The first aspect of this invention provides a hybrid networking method for 5G and quantum communication. This method, by pre-building a hierarchical quantum resource pool and combining predictions of user mobility and service quality, pre-completes key negotiation and security context migration. At the moment of handover, only the pre-set key needs to be activated, thus eliminating the key negotiation delay in traditional "disconnect first, reconnect later" or "negotiate while disconnecting" modes and achieving a smooth transition of secure sessions. Simultaneously, by constructing a context-bound key derivation and evolution mechanism, it ensures that when user equipment roams between different base stations, its security state can form a cryptographically verifiable chain of trust. The method includes:
[0008] S1. Establish a regionalized, hierarchical entanglement resource pool: Establish an entanglement resource pool, which includes a pre-built quantum link between a user equipment unit and a base station unit in at least one potential handover target set, and classify the entanglement resources corresponding to the quantum link according to their security levels.
[0009] S2. Perform initial access and quantum security context generation: When the user equipment unit initially accesses a source base station unit, it generates an initial session key based on the entanglement resources in the entanglement resource pool, and generates a first quantum security context digest based on the initial session key.
[0010] S3. Key pre-activation based on mobility and quality of service prediction: When a handover warning to a target base station unit is triggered, the first quantum security context digest is migrated to the target base station unit; and according to the quality of service level of the user equipment unit, entangled resources with a security level matching the level are selected from the entangled resource pool to generate a backup session key associated with the first quantum security context digest.
[0011] S4. Seamless handover execution and security context evolution: When handover is performed, the backup session key is activated for communication between the user equipment unit and the target base station unit, and a second quantum security context digest is generated based on the activated backup session key.
[0012] In one specific embodiment, the security level classification of the entangled resources corresponding to the quantum link in S1 specifically includes:
[0013] The entanglement fidelity F and the bit error rate E of the quantum link are periodically acquired. q ;
[0014] Calculate the quality factor of a quantum link based on preset weight coefficients w1 and w2:
[0015] Q factor =w1·F-w2·E q ;
[0016] Based on a preset threshold strategy, the quantum link quality factor Q is... factor Mapped to the corresponding security level.
[0017] Preferably, the establishment of the entanglement resource pool is performed by a software-defined quantum control plane unit. The software-defined quantum control plane unit identifies the user equipment unit and the potential handover target set based on network topology information, and instructs an entanglement distribution node unit to distribute entangled photon pairs to the user equipment unit and the base station units in the potential handover target set.
[0018] In one specific embodiment, the generation of a first quantum secure context digest based on the initial session key is specifically performed by the user equipment unit and the source base station unit respectively processing the initial session key. The first set of random numbers N u and Session metadata M s and session identifier I s As input, it is processed through a pre-defined cryptographic hash function. The first quantum-safe context digest is calculated. The formula is:
[0019]
[0020] in:
[0021] Indicates a bitwise XOR operation;
[0022] The symbol ‖ represents the concatenation operation of strings or byte streams.
[0023] Preferably, the migration of the first quantum security context digest is specifically achieved by the source base station unit encapsulating the first quantum security context digest in a handover preparation message of the next-generation application protocol, and sending it to the target base station unit via the access and mobility management function entity.
[0024] In one specific embodiment, selecting entangled resources with a security level matching the service quality level of the user equipment unit from the entangled resource pool includes:
[0025] A software-defined quantum control plane unit obtains the 5G quality of service identifier of the user equipment unit from a policy control function entity;
[0026] A preset mapping strategy is executed to map the 5G quality of service identifier to a target security level;
[0027] Based on the target security level, entangled resources are queried and locked in the entangled resource pool.
[0028] Preferably, the specific method for generating a backup session key associated with the first quantum security context digest is as follows:
[0029] The user equipment unit and the target base station unit generate an initial key material based on the selected entanglement resources.
[0030] The original key material As input key material, and the first quantum security context digest The identity identifier I of the user equipment unit u The combined value is used as the salt value or context information, and the backup session key is calculated using a key derivation function KDF(·). The formula is:
[0031]
[0032] Here, ‖ represents the concatenation operation of strings or byte streams.
[0033] In one specific embodiment, activating the backup session key includes:
[0034] After the user equipment unit receives the handover execution command, a software-defined quantum control plane unit synchronously sends a key activation instruction to the user equipment unit and the target base station unit to set the backup session key as the primary communication key.
[0035] Preferably, the generation of a second quantum-secure context digest based on the activated backup session key is specifically performed by the user equipment unit and the target base station unit using the backup session key. The second set of random numbers, new session metadata, and a new session identifier are used as inputs to calculate the second quantum-secure context digest using the cryptographic hash function.
[0036] A second aspect of the present invention provides a hybrid networking system of 5G and quantum communication, the system being used to perform any of the foregoing methods, comprising:
[0037] User equipment unit, source base station unit, target base station unit, entanglement distribution node unit, and software-defined quantum control plane unit.
[0038] The software-defined quantum control plane unit is used to instruct the entanglement distribution node unit to establish an entanglement resource pool including the user equipment unit and the target base station unit, and to classify the entanglement resources in the entanglement resource pool into security levels.
[0039] The user equipment unit and the source base station unit are used to generate an initial session key during initial access and jointly generate a first quantum security context digest.
[0040] The software-defined quantum control plane unit is also used to control the source base station unit to migrate the first quantum security context digest to the target base station unit when a handover warning is triggered, and to allocate entangled resources of a specified security level to the user equipment unit and the target base station unit according to the quality of service level of the user equipment unit.
[0041] The user equipment unit and the target base station unit are further configured to pre-generate a backup session key based on the allocated entanglement resources and the first quantum security context digest of the migration; and to activate the backup session key during handover, and then jointly generate a second quantum security context digest.
[0042] This invention provides a hybrid networking method combining 5G and quantum communication. It offers the following advantages:
[0043] 1. This invention pre-generates a backup session key with the target base station during the handover warning phase using a pre-built entanglement resource pool. During handover execution, only this key needs to be synchronously activated, rather than undergoing time-consuming real-time quantum key negotiation. This mechanism decouples the key negotiation process from the handover execution process, eliminating negotiation delays on the critical path and ensuring the continuity and security of low-latency, high-reliability services in mobile scenarios. It also achieves seamless handover for quantum-secure communication, significantly reducing service interruption time during the handover process.
[0044] 2. This invention quantifies and classifies the quality of quantum links, and uses software-defined quantum control plane units to map the service quality requirements in 5G networks to specific security levels. This enables the allocation of the most suitable security resources to services of different levels as needed, avoiding the resource waste caused by using a single high-level security strategy for all services, and improving the resource utilization and scalability of the entire hybrid networking method. It also establishes a dynamic mapping mechanism between service quality levels and security levels, realizing the refined and efficient utilization of quantum resources.
[0045] 3. This invention uses the quantum-secure context digest as input to the key derivation function, creating a strong cryptographic association between the newly generated backup session key and the historical security state. After each handover, a new context digest is generated based on the new key, forming an interlocking, forward-bound chain structure. This mechanism effectively resists context forgery or replay attacks that may occur during handover, greatly enhancing the robustness of end-to-end communication, constructing a continuously evolving secure context trust chain, and ensuring the integrity and traceability of the security state of user equipment during mobile roaming. Attached Figure Description
[0046] Figure 1 This is a schematic diagram of the architecture of a 5G and quantum communication hybrid networking system according to an embodiment of the present invention;
[0047] Figure 2 This is a flowchart illustrating a 5G and quantum communication hybrid networking method according to an embodiment of the present invention;
[0048] Figure 3 A detailed flowchart illustrating the establishment of a regionalized, hierarchical entanglement resource pool according to an embodiment of the present invention;
[0049] Figure 4 This is a detailed flowchart illustrating the initial access and quantum security context generation process according to an embodiment of the present invention.
[0050] Figure 5 This is a detailed flowchart of key pre-activation based on mobility and quality of service prediction according to an embodiment of the present invention;
[0051] Figure 6 This is a detailed flowchart illustrating the seamless handover execution and security context evolution according to an embodiment of the present invention.
[0052] Among them, 110 is the resource awareness and hierarchical module; 120 is the cross-domain signaling interface module; 130 is the policy mapping and decision-making module; and 140 is the session control and state management module. Detailed Implementation
[0053] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0054] See attached document Figure 1 This invention provides a hybrid networking system combining 5G and quantum communication. The system may include: a software-defined quantum control plane unit, at least one enhanced 5G base station unit, at least one enhanced user equipment unit, and at least one entanglement distribution node unit. The software-defined quantum control plane unit interacts with network functional entities in the 5G core network via signaling.
[0055] The software-defined quantum control plane unit is the control core of the system of the present invention. Its internal logic functions may include: a resource awareness and hierarchical module 110, a cross-domain signaling interface module 120, a policy mapping and decision module 130, and a session control and state management module 140.
[0056] The entanglement distribution node unit is responsible for generating entangled photon pairs and, based on the network topology information issued by the software-defined quantum control plane unit, distributing one photon from each entangled photon pair to a designated enhanced user equipment unit (AUE), while simultaneously distributing the other photon to one or more designated enhanced 5G base station units (BJUs). This establishes a shared quantum correlation between the AUE and multiple BJUs, forming an entanglement resource pool.
[0057] The resource awareness and classification module 110 periodically acquires the physical parameters of each "user equipment-base station" quantum link in the entangled resource pool. The physical parameters include the entanglement fidelity F and the quantum bit error rate E. q The resource awareness and classification module 110 calculates the quantum link quality factor Q based on physical parameters. factor Based on a preset threshold strategy, the entangled resources in the entangled resource pool are dynamically divided into multiple security levels.
[0058] The cross-domain signaling interface module 120 is designed to establish and maintain signaling connections with the Access and Mobility Management Function (AMF) entity and the Policy Control Function (PCF) entity in the 5G core network. Through these signaling connections, the cross-domain signaling interface module 120 receives mobility prediction information about enhanced user equipment units (UEs) from the AMF entity and obtains the Quality of Service (QoS) level corresponding to the current service flow of the UE from the PCF entity.
[0059] The policy mapping and decision module 130 receives the QoS level and maps it to a preset QoS-security level policy function. Determine the target quantum resource security level G that matches the QoS level. req Upon receiving mobility prediction information, the policy mapping and decision-making module 130 queries and reserves links that meet the target quantum resource security level G in the resource status maintained by the resource awareness and classification module 110 for the predicted handover target. req Entangled resources.
[0060] The session control and state management module 140 generates and issues control commands. Specifically, the session control and state management module 140 instructs the enhanced 5G base station unit and the enhanced user equipment unit to perform the post-processing procedure for quantum key negotiation; the instruction source base station unit sends the generated quantum security context digest D... qs The user equipment unit is migrated to the target base station unit; the enhanced user equipment unit and the target base station unit are instructed to initiate a context-bound key pre-activation process; and a key activation instruction is issued synchronously when the 5G network performs a handover.
[0061] Both the enhanced 5G base station unit and the enhanced user equipment unit are equipped with a quantum communication interface and a key post-processing computation module. The computation module is used to execute the standard QKD post-processing algorithm and, based on the current session key S... k Random number N, session metadata M s and Session I s Through cryptographic hash functions Computational Quantum Security Context Summary
[0062] Simultaneously, the computation module is also used to execute a context-bound key derivation function KDF(·), which uses a new original key material R. k and the transferred quantum security context summary D qs As input, generate a backup session key S′ associated with the previous session. k =KDF(R) k D qs ||I u ).
[0063] See attached document Figure 2 This invention provides a hybrid networking method combining 5G and quantum communication. Applied to the aforementioned system embodiments, this method may include the following steps:
[0064] Step S1: Establish a regionalized, hierarchical entangled resource pool. Entangled photon pairs are distributed by entangled distribution node units to a user equipment unit and one or more potential handover target base station units, forming shared quantum resources. Software-defined quantum control plane units characterize the link quality of the quantum resources and dynamically classify them into multiple security levels.
[0065] Step S2: Perform initial access and quantum security context generation. The user equipment unit connects to a source base station unit, and the two parties negotiate and generate an initial session key. Subsequently, based on the initial session key and other session parameters, both parties jointly computed and stored a quantum-safe context digest. The calculation formula is as follows:
[0066]
[0067] in, Represents a cryptographic hash function. N represents the initial session key. u and M represents the random numbers generated by the user equipment unit and the source base station unit, respectively. s Represents session metadata, I s ‖ represents the session identifier, and ‖ represents the concatenation operation.
[0068] Step S3: Key pre-activation based on mobility and quality of service prediction. The software-defined quantum control plane unit obtains mobility prediction information and service quality of service level Q for the user equipment unit from the 5G core network. svc Software-defined quantum control planar units are based on quality of service level Q. svc Allocate entanglement resources of appropriate security level to the user equipment unit and the predicted target base station unit. The source base station unit will then use the generated quantum-safe context summary. The user equipment unit (UE) migrates to the target base station unit. The UE and target base station units utilize the newly allocated entanglement resources and bind together, transferring the migrated quantum-safe context digest. Pre-generate a backup session key Its derived formula is:
[0069]
[0070] Where KDF(·) represents the key derivation function, This represents the original key material generated through a new quantum measurement. I represents the transferred quantum-safe context summary. u This indicates the identity identifier of the user equipment unit.
[0071] Step S4: Seamless handover execution and security context evolution. When the 5G network executes the handover command, the user equipment unit and the target base station unit immediately activate the generated backup session key. Used for secure communication after handover. After handover, the user equipment unit and the new serving base station unit repeat step S2 to generate a new quantum-secure context digest based on the current session. This is used for the next possible switch, thus forming a continuous chain of safe state evolution.
[0072] See attached document Figure 3 Step S1, establishing a regionalized, hierarchical entanglement resource pool, has the following specific steps:
[0073] S101. Multi-target distribution of entangled pairs: Based on network topology information obtained from the 5G network, the software-defined quantum control plane unit identifies an active user equipment unit (UE) and a potential handover target set consisting of its serving base station units' neighboring base station units. The software-defined quantum control plane unit then distributes the identification information of the UE and the potential handover target set to the designated entanglement distribution node unit.
[0074] The entanglement distribution node unit continuously generates entangled photon pairs according to this instruction. For each pair of entangled photons generated, the entanglement distribution node unit sends one photon to the user equipment unit and distributes the other photon to one or more base station units in the potential handover target set through a multi-port output device.
[0075] One specific implementation of the multi-port output device is to use an optical splitter to broadcast photons to all potential target base station units. Another optional implementation is to use an optical switching matrix to selectively transmit photons, point-to-multipoint, to a specified subset of target base station units according to dynamic routing instructions. This step pre-establishes parallel quantum channels between the user equipment unit and multiple potential target base station units, forming a schedulable pool of entangled resources.
[0076] S102. Periodic characterization of link quality: The resource awareness and hierarchical module 110 in the software-defined quantum control plane unit periodically quantifies the physical transmission quality of each “user equipment-base station” quantum link in the entangled resource pool to obtain its real-time link state parameters.
[0077] One specific method for obtaining link state parameters is active probing. Specifically, the resource awareness and classification module 110 controls the entanglement distribution node unit to insert test photon pairs with known quantum states into the service entangled photon sequence. By analyzing the deviation of the measurement results of the test photon pairs at the receiving end, the entanglement fidelity F and the qubit error rate E of the link are calculated. q .
[0078] Another specific way to obtain link state parameters is through passive monitoring. That is, the resource awareness and classification module 110 analyzes the statistical data of recently successfully completed quantum key negotiation sessions on this link and extracts the historical average entanglement fidelity F and qubit error rate E. q As an assessment value of the current link quality.
[0079] S103. Dynamic Security Classification of Resource Pools: Based on the link state parameters obtained in step S102, the resource awareness and classification module 110 classifies the security level of each entangled resource in the entangled resource pool. This classification process provides a basis for subsequent resource scheduling based on quality of service.
[0080] The resource perception and classification module 110 first determines the entanglement fidelity F and the bit error rate E of the qubit based on the acquired entanglement fidelity F and bit error rate E. q Calculate a comprehensive quantum link quality factor Q. factor An example calculation method is as follows:
[0081] Q factor =w1·F-w2·E q ;
[0082] Among them, w1 and w2 are preset, non-negative weighting coefficients used to adjust the importance of fidelity and bit error rate in the overall evaluation.
[0083] Subsequently, the resource awareness and classification module 110 classifies entangled resources into different security levels G based on a multi-level threshold strategy configurable by the network administrator. For example, the logic for classifying a three-level security level can be defined as follows:
[0084]
[0085] Among them, G H G S G B These represent three safety levels: high, standard, and basic. and These are the fidelity threshold and bit error rate threshold corresponding to the high security level and standard security level, respectively.
[0086] The resource perception and classification module 110 binds the calculated security level G with the corresponding entangled resources and updates its status information in real time to the resource status database inside the software-defined quantum control plane unit for subsequent querying and scheduling.
[0087] See attached document Figure 4 When a user equipment unit first accesses the network or completes a handover, it needs to establish a current session and generate its security context. The specific steps are as follows:
[0088] S201. Initial Key Negotiation: After the user equipment unit is powered on or moves to a new network coverage area, it connects to its initial serving base station unit, denoted here as the source base station unit gNB. A Upon receiving an access request, the software-defined quantum control plane unit allocates a set of available entangled resources from the entanglement resource pool for the "user equipment-source base station" link.
[0089] User Equipment Unit and Source Base Station Unit (gNB) A Based on the allocated entanglement resources, both parties measure the entangled photon sequences they receive. Subsequently, they perform standard quantum key distribution post-processing procedures through a public classical channel.
[0090] The post-processing process specifically includes: basis vector alignment to filter out the original key sequences obtained by both parties using the same basis measurement;
[0091] Parameter negotiation and estimation to evaluate parameters such as the bit error rate of the quantum channel;
[0092] Error correction involves removing erroneous bits from the original key sequence by executing an error correction algorithm.
[0093] In addition, security is enhanced by hashing and compressing the corrected key sequence to eliminate some information that an attacker might obtain. The final output of this process is a session key shared by both parties, denoted as...
[0094] S202. Generation of Quantum Security Context Digest: To solidify the security state of this session and provide cryptographic credentials for the continuity of subsequent sessions, the User Equipment Unit (UE) and the Source Base Station Unit (gNB)... A Successfully generated session key Then, a quantum-safe context summary of the current session needs to be jointly calculated.
[0095] Quantum Security Context Summary The generation requires the following data as input: the current session key. A random number N generated independently by the user equipment unit. u ; by the source base station unit gNB A An independently generated random number Metadata M of this QKD session s ; and the unique identifier I for this session s .
[0096] In one specific embodiment, session metadata M sThis may include: the identifier of the QKD protocol used, the hash value of the basis vector alignment negotiation sequence, and the summary information of the parity check matrix used in the error correction process.
[0097] User Equipment Unit and Source Base Station Unit (gNB) A Perform the same calculations according to the following formulas respectively:
[0098]
[0099] in:
[0100] A hash function that represents a cryptographically secure hash function, including but not limited to the secure hash algorithm SHA-256 or SHA-3.
[0101] This represents the current session key generated in step S201.
[0102] N u and These represent the random numbers generated by the user equipment unit and the source base station unit, respectively, used to ensure the uniqueness of the digest and resistance to replay attacks.
[0103] M s This represents session metadata.
[0104] I s Represents the session identifier.
[0105] This indicates a bitwise XOR operation.
[0106] The symbol ‖ represents the concatenation operation of strings or byte streams.
[0107] To ensure consistency of calculations, both parties exchange their calculated results through an established authentication channel. The value. After verification, the source base station unit gNB. A The quantum-safe context summary is stored in its secure storage area. In preparation for subsequent switching process calls.
[0108] See attached document Figure 5 Step S3 is initiated when the user equipment unit is moved and a handover warning is triggered. The specific steps are as follows:
[0109] S301. Acquisition of Mobility and QoS Information: When a user equipment unit requests mobility and QoS information from its current serving base station unit (i.e., the source base station unit gNB)... A When the reported signal measurement report from a neighboring cell meets the preset handover triggering conditions of the 5G network, the source base station unit gNB... A The event is reported to the Access and Mobility Management Function (AMF) entity in the 5G core network.
[0110] Based on the measurement report and network topology, the AMF entity analyzes and identifies a high-probability handover target base station unit (gNB). B Subsequently, the AMF entity sends a message to the software-defined quantum control plane unit containing the identity of the user equipment unit and the target base station unit gNB. B The warning signal for the switching of identity identifiers.
[0111] Upon receiving a handover warning signal, the Software-Defined Quantum Control Plane Unit (SDPC) immediately initiates a policy query request to the Policy Control Function (PCF) entity in the 5G core network. Based on the user equipment unit's subscription data and currently active service flow information, the PCF entity returns the Quality of Service (QoS) level corresponding to the service to the SPC. This level can be specified as a 5G QoS identifier, denoted as Q. svc .
[0112] S302, QoS-Security Level Policy Mapping: The policy mapping and decision module 130 in the software-defined quantum control plane unit obtains the service quality level Q. svc Then, a preset QoS-security level mapping policy function is executed. To determine the required quantum resource security level G for this switchover. req .
[0113] Mapping strategy function One specific implementation is to maintain a static or dynamic lookup table. For example, when the input Q... svc When the value is 1, this value corresponds to the Ultra-Reliable Low-Latency Communication (URLLC) service, and the target security level G output by the function is... req For high security level G H When Q is entered svc When the value is 9, this value corresponds to enhanced mobile broadband (eMBB) video services, and the target security level G output by the function is... req Standard safety level G S .
[0114] S303. Allocation and Locking of Target Resources: The strategy mapping and decision-making module 130 determines the target security level G based on step S302. req In its managed resource status database, query "User Equipment - Target Base Station gNB" B The link status is "available" and the security level meets G requirements. req The module updates the logical status of the resource to "reserved" after a successful query to prevent it from being occupied by other sessions or processes.
[0115] S304. Encapsulation and migration of security context: From software-defined quantum control plane unit to source base station unit gNB A Issue a context migration command. Source base station unit (gNB) A Upon receiving the instruction, the generated quantum-safe context summary is read from its secure storage area.
[0116] Source base station unit gNB A Quantum security context summary D qsA This is encapsulated within a dedicated information element of a 5G core network handover preparation message. In one specific embodiment, this message is a handover preparation message for the Next Generation Application Protocol (NGAP). This message is routed to the target base station unit (gNB) via the AMF entity. B Target base station unit gNB B Parse the digest from the received message. And temporarily store it in the local secure storage area.
[0117] S305, Context-Bound Key Derivation: Software-Defined Quantum Control Plane Unit to User Equipment Unit and Target Base Station Unit (gNB) B A key pre-activation command is issued synchronously. Both parties activate the entanglement resources reserved in step S303 and execute the post-processing procedure for quantum key distribution. After the security enhancement step, a temporary, internally used original key material is generated, denoted as...
[0118] Subsequently, the user equipment unit and the target base station unit gNB B Execute a context-bound key derivation function KDF(·) to generate the final backup session key. The function is executed as follows:
[0119]
[0120] in:
[0121] KDF(·) represents a standard key derivation function, instances of which include, but are not limited to, the HMAC-based key extraction and expansion function KDF.
[0122] This refers to the raw key material used as input keying material (IKM).
[0123] This represents a quantum security context summary migrated from the source base station unit.
[0124] I uIt represents a long-term or temporary identity identifier for a user equipment unit, such as a universally unique subscription identifier (SUPI).
[0125] The symbol ‖ represents the concatenation operation of strings or byte streams. with I u The concatenated value is used as the salt or context information parameter of the key derivation function KDF(·). This step ensures the newly generated backup session key. Cryptographically, this is a summary of the security state of the previous session. This strong association creates a secure key evolution chain.
[0126] See attached document Figure 6 Step S4 describes the final stage of 5G network handover and the continuous maintenance of the security context. The specific steps are as follows:
[0127] S401. Key Synchronization Activation: After completing the key pre-activation in step S3, when the 5G core network or source base station unit gNB... A When sending a formal handover execution command to the user equipment unit, this method simultaneously initiates the activation process of the prepared key.
[0128] Source base station unit gNB A By issuing signaling messages such as Radio Resource Control (RRC) Reconfiguration messages, the user equipment unit is instructed to transfer data from the source base station unit (gNB). A The communication link is switched to the target base station unit gNB. B The communication link.
[0129] The user equipment unit begins attempting to access the target base station unit (gNB). B In that instant, the software-defined quantum control plane unit sends a signal to the target base station unit gNB. B The "activation key" command is issued synchronously with the user equipment unit. Target base station unit (gNB) B After successfully establishing a wireless link with the user equipment unit, the backup session key pre-generated in step S305 is immediately activated. This backup session key This key then becomes the primary communication key for the current session, used to encrypt subsequent business data. This process requires no additional quantum key negotiation time, thus achieving seamless switching of secure sessions.
[0130] S402. Generation and updating of new security context: User equipment unit and target base station unit gNB B Once secure communication between the parties is established and running stably, in order to maintain the continuity and traceability of the security state, both parties need to generate and update a new quantum security context digest.
[0131] User Equipment Unit and Target Base Station Unit (gNB) B Following the procedure in step S202, jointly calculate the quantum-safe context digest for the current session. The formula for calculating this abstract is:
[0132]
[0133] in: Represents a cryptographic hash function; Indicates the currently active session key; N u 'and These represent the user equipment unit and the target base station unit (gNB), respectively. B The new random number selected for this abstract generation; M s ′ represents a summary of the key parameter metadata for this session; I s ′ represents a unique identifier for this session; || represents a bitwise XOR operation; || represents a string or byte stream concatenation operation.
[0134] Target base station unit gNB B The generated quantum security context summary Stored securely locally. This will serve as a new context credential, used to respond to the next possible request from the user equipment unit to another base station unit (e.g., gNB). C The invention ensures that the quantum security context of a user equipment unit evolves continuously and in a chain throughout the entire movement process, thereby constructing a secure trust chain that always maintains cryptographic coherence.
[0135] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A hybrid networking method combining 5G and quantum communication, characterized in that, Includes the following steps: S1. Establish a regionalized, hierarchical entanglement resource pool: Establish an entanglement resource pool, which includes a pre-built quantum link between a user equipment unit and a base station unit in at least one potential handover target set, and classify the entanglement resources corresponding to the quantum link according to their security levels. S2. Perform initial access and quantum security context generation: When the user equipment unit initially accesses the source base station unit, it generates an initial session key based on the entanglement resources in the entanglement resource pool, and generates a first quantum security context digest based on the initial session key. S3. Key pre-activation based on mobility and quality of service prediction: When a handover warning to the target base station unit is triggered, the first quantum security context digest is migrated to the target base station unit; and according to the quality of service level of the user equipment unit, entangled resources with a security level matching the quality of service level are selected from the entangled resource pool to generate a backup session key associated with the first quantum security context digest. S4. Seamless handover execution and security context evolution: When handover is performed, the backup session key is activated and used for communication between the user equipment unit and the target base station unit, and a second quantum security context digest is generated based on the activated backup session key.
2. The hybrid networking method of 5G and quantum communication according to claim 1, characterized in that, The security level classification of entangled resources corresponding to the quantum link in S1 specifically includes: The entanglement fidelity and bit error rate of the quantum link are periodically obtained; The quantum link quality factor is calculated based on preset weighting coefficients; Based on a preset threshold strategy, the quantum link quality factor is mapped to the corresponding security level.
3. The hybrid networking method of 5G and quantum communication according to claim 1, characterized in that, The establishment of the entanglement resource pool in S1 is performed by the software-defined quantum control plane unit. The software-defined quantum control plane unit identifies the user equipment unit and the potential handover target set based on network topology information, and instructs the entanglement distribution node unit to distribute entangled photon pairs to the user equipment unit and the base station unit in the potential handover target set.
4. The hybrid networking method of 5G and quantum communication according to claim 1, characterized in that, The generation of the first quantum-secure context digest based on the initial session key in step S2 specifically includes: The user equipment unit and the source base station unit respectively take the initial session key, the first set of random numbers, session metadata and session identifier as input, and calculate the first quantum secure context digest through a preset cryptographic hash function.
5. A hybrid networking method for 5G and quantum communication according to claim 1, characterized in that, The transfer of the first quantum security context digest in S3 specifically includes: The source base station unit encapsulates the first quantum security context digest in a handover preparation message of the next-generation application protocol and sends it to the target base station unit via the access and mobility management function entity.
6. A hybrid networking method for 5G and quantum communication according to claim 3, characterized in that, The step S3, selecting entangled resources with a security level matching the service quality level of the user equipment unit from the entangled resource pool, includes: The software-defined quantum control plane unit obtains the 5G quality of service identifier of the user equipment unit from the policy control function entity; A preset mapping strategy is executed to map the 5G quality of service identifier to a target security level; Based on the target security level, entangled resources are queried and locked in the entangled resource pool.
7. A hybrid networking method for 5G and quantum communication according to claim 1, characterized in that, The generation of the backup session key associated with the first quantum security context digest in S3 includes: The user equipment unit and the target base station unit generate the original key material based on the selected entanglement resources; Using the original key material as input key material, and the combined value of the first quantum security context digest and the identity identifier of the user equipment unit as salt value or context information, the backup session key is calculated through a key derivation function.
8. A hybrid networking method for 5G and quantum communication according to claim 1, characterized in that, Activating the backup session key in S4 includes: After the user equipment unit receives the handover execution command, the software-defined quantum control plane unit synchronously sends a key activation instruction to the user equipment unit and the target base station unit to set the backup session key as the primary communication key.
9. A hybrid networking method for 5G and quantum communication according to claim 4, characterized in that, The generation of a second quantum-secure context digest based on the activated backup session key in step S4 includes: The user equipment unit and the target base station unit take the backup session key, the second set of random numbers, the new session metadata, and the new session identifier as input, and calculate the second quantum secure context digest through a cryptographic hash function.
10. A hybrid networking system combining 5G and quantum communication, characterized in that, include: User equipment unit, source base station unit, target base station unit, entanglement distribution node unit, and software-defined quantum control plane unit; The software-defined quantum control plane unit is used to instruct the entanglement distribution node unit to establish an entanglement resource pool including the user equipment unit and the target base station unit, and to classify the entanglement resources in the entanglement resource pool into security levels. The user equipment unit and the source base station unit are used to generate an initial session key during initial access and jointly generate a first quantum security context digest. The software-defined quantum control plane unit is also used to control the source base station unit to migrate the first quantum security context digest to the target base station unit when a handover warning is triggered, and to allocate entangled resources of a specified security level to the user equipment unit and the target base station unit according to the quality of service level of the user equipment unit; The user equipment unit and the target base station unit are further configured to pre-generate a backup session key based on the allocated entanglement resources and the migrated first quantum security context digest; The backup session key is activated during the switchover, and a second quantum-secure context digest is then jointly generated.