Secure Coherent Fiber Communication Encryption Method Based on Digital Fingerprinting and Chaotic Encryption
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-08-11
AI Technical Summary
然而,该类方案缺乏对合法发射端身份的验证机制,导致在复杂光网络中仍存在伪装发射机冒充合法节点的风险
[0027](1)、深度集成,安全性强:将身份认证(数字指纹)与数据加密(混沌加密)在物理层深度融合,使得加密数据与认证信息不可分割,极大增强了系统的整体安全性。
Smart Images

Figure CN121727702B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communication security technology, and more specifically, relates to a secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption. Background Technology
[0002] In high-speed coherent optical communication systems, transmission security faces severe challenges. Common attacks include unauthorized optical access (active attacks) and optical eavesdropping (passive attacks). While existing technologies can employ physical layer encryption (such as chaotic encryption) to defend against passive attacks, they struggle to effectively identify active access initiated by unauthorized legitimate devices.
[0003] Traditional device authentication relies heavily on upper-layer protocols, which are vulnerable to impersonation or cracking. Existing chaotic 4D modulation physical layer encryption schemes [such as Zeng et al., Chaotic 4D Modulation With IntrusionDetection for Secure Data Centers, JLT 2025] can combat unauthorized optical access and eavesdropping, and achieve intrusion detection through constellation common set ratio (CSSR). However, these schemes lack a mechanism to verify the identity of legitimate transmitters, leading to the risk of spoofed transmitters impersonating legitimate nodes in complex optical networks. Therefore, there is an urgent need to propose an optical communication encryption method that can achieve identity identification and authentication at the physical layer, enhancing the system's anti-spoofing capabilities while ensuring high-speed transmission performance. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a secure coherent optical fiber communication encryption method based on digital fingerprint and chaotic encryption. It utilizes the same chaotic source to synchronously generate a chaotic key sequence and a unique digital fingerprint. By embedding the digital fingerprint into the encrypted data stream at the physical layer in a way that dynamically switches the modulation format, it achieves the integration of confidentiality protection of communication data and strong identity authentication of communication entities.
[0005] To achieve the above-mentioned objectives, the present invention provides a secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption, characterized by comprising the following steps:
[0006] (1) Generating a chaotic sequence: The chaotic system generates a chaotic sequence based on the input key. The chaotic sequence consists of three parts: the chaotic key sequence K1, the chaotic key sequence K2, and the binary digital fingerprint sequence.
[0007] (2) Bit-level substitution encryption: The plaintext data to be processed is first converted from serial to parallel, and then bit-level substitution encryption is performed using the chaotic key sequence K1. The encryption method is as follows:
[0008] ;
[0009] Where S is the bit-level substitution encrypted data, P is the plaintext data, and xor is the XOR operation function;
[0010] (3) Time slot group division: The bit-level replacement encrypted data S is mapped to a constellation symbol sequence containing X and Y polarization signals using a dual polarization 16QAM mapper. In the time domain, the polarization constellation symbol sequence is divided into N consecutive symbol groups, each symbol group containing n symbol time slots.
[0011] (4) Digital fingerprint embedding mapping and hybrid modulation: Each bit of the binary digital fingerprint sequence is mapped to each time slot group, and then compared sequentially:
[0012] If a bit of a digital fingerprint is '0', the corresponding time slot group is mapped and modulated using the DP-16QAM format;
[0013] If a bit of a digital fingerprint is '1', the corresponding time slot group is mapped and modulated using the 128SP-QAM format;
[0014] (5) Polarization symbol permutation: The chaotic key sequence K2 is used to perform a joint permutation on the hybrid modulation symbol sequence after embedding the fingerprint. The permutation method is as follows:
[0015] ;
[0016] in, This represents the signal after polarization sign substitution. The sequence of symbols with X and Y polarization after hybrid modulation, sort() is the sorting function according to the given index, and the chaotic key sequence K2 is used as the given index;
[0017] (6) Signal transmission: The signal after polarization sign substitution The signal is input to a coherent transmitter, converted into an optical signal, and transmitted to a coherent receiver via an optical fiber channel.
[0018] (7) Signal reception and preprocessing: The coherent receiver receives the optical signal and converts it into an electrical signal, and then performs digital processing and equalization compensation on the electrical signal;
[0019] (8) Inverse polarization symbol permutation: The received X and Y polarization symbol sequences are inversely permuted using the chaotic key sequence K2 synchronized with the transmitter to restore the time order of the symbols;
[0020] (9) Constellation co-occurrence rate calculation: Divide the X and Y polarized symbol sequences after inverse permutation into time slot groups in the same way as the transmitter, and calculate the constellation co-occurrence rate (CSSR) value of the symbol sequence in each time slot group;
[0021] (10) Fingerprint extraction: The constellation co-occurrence rate (CSSR) value of each time slot group symbol sequence is compared with the constellation co-occurrence rate preset threshold. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to DP-16QAM modulation, the modulation format of the time slot group symbol sequence is determined to be DP-16QAM modulation, thereby recovering the corresponding digital fingerprint bit '0'. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to 128SP-QAM modulation, the modulation format of the time slot group symbol sequence is determined to be 128SP-QAM modulation, thereby recovering the corresponding digital fingerprint bit '1'. Finally, the bit values corresponding to each time slot group after recovery are reassembled into a complete digital fingerprint sequence.
[0022] (11) Identity verification: Compare the reconstructed digital fingerprint sequence with the digital fingerprint sequence generated by the chaotic system to verify the legitimacy of the sender's identity. If the verification fails, trigger an alarm and terminate communication; otherwise, proceed to step (12).
[0023] (12) Demodulation and decryption: After identity verification, the recombined digital fingerprint sequence is used to demodulate the symbol sequence of each time slot group, and the chaotic key sequence K1 is used to perform bit-level reverse substitution decryption to finally recover the plaintext data.
[0024] The objective of this invention is achieved as follows:
[0025] This invention is a secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption. It utilizes the same chaotic source to synchronously generate a chaotic key sequence and a unique digital fingerprint sequence. Then, by dynamically switching the modulation format of the digital fingerprint at the physical layer, it completes the digital fingerprint embedding mapping and hybrid modulation. Finally, at the receiving end, the fingerprint is extracted by calculating the constellation co-location rate value of the symbol sequence of each time slot group, and reconstructed into a complete digital fingerprint sequence. After identity verification, the reconstructed digital fingerprint sequence is demodulated and decrypted to recover the plaintext data, ultimately achieving the integration of confidentiality protection of communication data and strong identity authentication of communication entities.
[0026] Furthermore, the secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption of this invention also has the following beneficial effects:
[0027] (1) Deep integration and strong security: The identity authentication (digital fingerprint) and data encryption (chaotic encryption) are deeply integrated at the physical layer, making the encrypted data and authentication information inseparable, which greatly enhances the overall security of the system.
[0028] (2) Dual protection and active defense: It prevents data leakage through encryption and verifies the sender's identity through a unique digital fingerprint, effectively resisting passive and active attacks such as eavesdropping and unauthorized access.
[0029] (3) Good concealment and difficult to detect: Digital fingerprints are embedded through dynamic switching of modulation format, hidden in normal signal feature changes, and are difficult to be identified and stripped by third parties.
[0030] (4) Lightweight implementation with low overhead: Authentication information is extracted through physical layer features (CSSR), without the need for complex cryptographic operations or additional signaling, achieving lightweight security hardening with low latency and low complexity. Attached Figure Description
[0031] Figure 1 This is a flowchart of the secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption according to the present invention;
[0032] Figure 2 This is a schematic diagram of digital fingerprint embedding mapping and modulation;
[0033] Figure 3 This is a schematic diagram of the DP-16QAM modulation method and the 128SP-QAM modulation method. Detailed Implementation
[0034] The specific embodiments of the present invention will now be described with reference to the accompanying drawings to enable those skilled in the art to better understand the invention. It should be particularly noted that in the following description, detailed descriptions of known functions and designs that might obscure the main content of the invention will be omitted here.
[0035] Example
[0036] In this embodiment, as Figure 1 As shown, this invention provides a secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption, including a transmitting end processing flow and a receiving end processing flow. The specific processing steps are as follows:
[0037] S1. Sending end processing flow:
[0038] (1) Generate chaotic sequence: The chaotic system generates a chaotic sequence based on the input key. The chaotic sequence consists of three parts: chaotic key sequence K1, chaotic key sequence K2 and binary digital fingerprint sequence. The digital fingerprint sequence needs to be uniquely verified to ensure that it does not duplicate any existing fingerprint in the known database.
[0039] (2) Bit-level substitution encryption: The plaintext data to be processed is first converted from serial to parallel, and then bit-level substitution encryption is performed using the chaotic key sequence K1. The encryption method is as follows:
[0040] ;
[0041] Where S is the bit-level substitution encrypted data, P is the plaintext data, and xor is the XOR operation function;
[0042] (3) Time slot group division: The bit-level replacement encrypted data S is mapped to a constellation symbol sequence containing X and Y polarization signals using a dual polarization 16QAM mapper. In the time domain, the polarization constellation symbol sequence is divided into N consecutive symbol groups, each symbol group containing n symbol time slots.
[0043] (4) Digital fingerprint embedding mapping and hybrid modulation: Each bit of the binary digital fingerprint sequence is mapped to each time slot group, and then compared sequentially:
[0044] If a bit of a digital fingerprint is '0', the corresponding time slot group is mapped and modulated using the DP-16QAM format;
[0045] If a bit of a digital fingerprint is '1', the corresponding time slot group is mapped and modulated using the 128SP-QAM format;
[0046] In this embodiment, as Figure 2 As shown, the upper part represents the division of the dual-polarization (X-polarization and Y-polarization) symbol data stream into N consecutive time slot groups in the time domain, with each time slot group containing n symbol time slots. The lower part represents a binary digital fingerprint sequence of length N.
[0047] The mapping rule determines the modulation format of the corresponding time slot group based on each bit value of the digital fingerprint: when the fingerprint bit is '1', the corresponding time slot group uses 128SP-QAM modulation; when the fingerprint bit is '0', the corresponding time slot group uses DP-16QAM modulation. This intuitive correspondence forms the basis for embedding digital fingerprints at the physical layer.
[0048] Figure 3 These are schematic diagrams of the DP-16QAM modulation method and the 128SP-QAM modulation method, as shown below. Figure 3 The left side illustrates the 128SP-QAM modulation method: its input consists of seven bits, b1 to b7. Bits b1 to b7 are XORed to generate an eighth bit, b8. Subsequently, bits b1-b4 and b5-b8 are fed into a 16QAM mapper to generate constellation symbols for X-polarization and Y-polarization, respectively. This structure demonstrates the inherent correlation of 128SP-QAM through set partitioning.
[0049] like Figure 3The diagram on the right illustrates the DP-16QAM modulation method: its input consists of eight bits, b1 to b8. These eight bits are evenly divided into two groups: the first four bits (b1-b4) are directly input to the upper 16QAM mapper, and the last four bits (b5-b8) are directly input to the lower 16QAM mapper, independently generating constellation symbols for X-polarization and Y-polarization, respectively. This structure indicates that the modulation processes of the two polarization branches are independent of each other.
[0050] (5) Polarization symbol permutation: The chaotic key sequence K2 is used to perform joint permutation on the hybrid modulation symbol sequence after embedding the fingerprint to enhance security. The permutation method is as follows:
[0051] ;
[0052] in, This represents the signal after polarization sign substitution. The sequence of symbols with X and Y polarization after hybrid modulation, sort() is the sorting function according to the given index, and the chaotic key sequence K2 is used as the given index;
[0053] S2. Receiver processing flow:
[0054] (6) Signal transmission: The signal after polarization sign substitution The signal is input to a coherent transmitter, converted into an optical signal, and transmitted to a coherent receiver via an optical fiber channel.
[0055] (7) Signal reception and preprocessing: The coherent receiver receives the optical signal and converts it into an electrical signal, and then performs digital processing and equalization compensation on the electrical signal;
[0056] (8) Inverse polarization symbol permutation: The received X and Y polarization symbol sequences are inversely permuted using the chaotic key sequence K2 synchronized with the transmitter to restore the time order of the symbols;
[0057] (9) Constellation co-occurrence rate calculation: Divide the X and Y polarized symbol sequences after inverse permutation into time slot groups in the same way as the transmitter, and calculate the constellation co-occurrence rate (CSSR) value of the symbol sequence in each time slot group;
[0058] In this embodiment, the constellation co-occurrence rate (CSSR) is calculated as follows:
[0059] ;
[0060] Where n is the total number of constellation symbol pairs in the time slot group; Indicates the first in the same time slot Whether a pair of constellation symbols belongs to the same constellation set, when =1, indicating the first Groups of constellation symbols belong to the same constellation set; when =0, indicating the first The constellation symbols do not belong to the same constellation set; and These are the constellation sets to which the i-th time slot constellation symbol of the X and Y polarization branches belongs;
[0061] (10) Fingerprint extraction: The constellation co-occurrence rate (CSSR) value of each time slot group symbol sequence is compared with the constellation co-occurrence rate preset threshold. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to DP-16QAM modulation, the modulation format of the time slot group symbol sequence is determined to be DP-16QAM modulation, thereby recovering the corresponding digital fingerprint bit '0'. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to 128SP-QAM modulation, the modulation format of the time slot group symbol sequence is determined to be 128SP-QAM modulation, thereby recovering the corresponding digital fingerprint bit '1'. Finally, the bit values corresponding to each time slot group after recovery are reassembled into a complete digital fingerprint sequence.
[0062] (11) Identity verification: Compare the reconstructed digital fingerprint sequence with the digital fingerprint sequence generated by the chaotic system to verify the legitimacy of the sender's identity. If the verification fails, trigger an alarm and terminate communication; otherwise, proceed to step (12).
[0063] (12) Demodulation and decryption: After identity verification, the recombined digital fingerprint sequence is used to demodulate the symbol sequence of each time slot group, and the chaotic key sequence K1 is used to perform bit-level reverse substitution decryption to finally recover the plaintext data.
[0064] Example 1
[0065] This embodiment is set in a single-carrier 400G coherent optical communication system, with a transmission distance of 80km in standard single-mode fiber (SSMF) and a symbol baud rate of 60 GBaud.
[0066] Chaotic system parameters: A 2D-LTMM chaotic system is adopted, with the initial parameter set set as follows: a1=50.12345678901234, b1=50.98765432109876, x1=0.1234567890123456, y1=0.9876543210987654, used to generate keystream K1; a2=51.12345678901234, b2=51.98765432109876, x2=0.2234567890123456, y2=0.8765432109876543, used to generate keystream K2; a3=52.12345678901234, b3=52.98765432109876, x3=0.3234567890123456, y3=0.7654321098765432, are used to generate digital fingerprint sequences.
[0067] Digital fingerprint parameters: Set the digital fingerprint sequence length N=256 bits, the total number of time slot packets is 256, the number of symbols in each group is n=256, and the total number of transmitted symbols is 256 groups × 256 symbols / group = 65536 symbols.
[0068] Modulation formats: The first modulation format is DP-16QAM, and the second modulation format is 128SP-QAM.
[0069] Confidence threshold: Set the CSSR decision confidence threshold based on the system communication transmission test results.
[0070] Sending end workflow:
[0071] 1) Start the chaotic system, input the initial parameters, and synchronously generate the chaotic keystream (K1, K2) and a binary digital fingerprint sequence of length N required for encryption. The system ensures the global uniqueness of this sequence by querying the fingerprint database.
[0072] 2) Plaintext data generation: A pseudo-random generator is used to generate a bit sequence of appropriate length for plaintext data.
[0073] 3) Data encryption: After the plaintext data is converted from serial to parallel, it is encrypted using the key stream K1 with bit-level XOR.
[0074] 4) Fingerprint Embedding: After mapping, the encrypted bitstream is divided into N time slot groups by corresponding dual-polarization symbols. Mapping rule: The unique digital fingerprint sequence is read, and the modulator is controlled according to the value of each bit ('0' or '1') to dynamically select either DP-16QAM or 128SP-QAM modulation format for each time slot group. Thus, the digital fingerprint is seamlessly and covertly embedded into the physical layer signal.
[0075] 5) Symbol scrambling: The key stream K2 is used to perform polarization symbol substitution on the modulated symbol sequence, which disrupts its spatiotemporal order and increases security.
[0076] 6) Transmission: The processed signal is sent into the optical fiber channel by a coherent transmitter.
[0077] Receiver workflow:
[0078] 1) The coherent receiver receives the signal and performs clock recovery, equalization and other compensations through the DSP.
[0079] 2) Inverse scrambling: Use the synchronized key stream K2 to perform inverse polarization symbol replacement to restore the original symbol order.
[0080] 3) Authentication: The recovered symbol sequence is grouped into N groups (n time slots per group), identical to the one used at the transmitting end, and the CSSR of each group is calculated. Since the theoretical CSSR of 128SP-QAM modulation is much higher than that of DP-16QAM, the fingerprint bits ('1' or '0') corresponding to each group can be accurately determined by comparing the confidence threshold, thus reconstructing the digital fingerprint sequence. This fingerprint is then matched with the database to complete the authentication.
[0081] (4) Decryption: After authentication, the signal is demodulated and decrypted using key stream K1, and finally the recovered plaintext data is output.
[0082] Although the illustrative specific embodiments of the present invention have been described above to enable those skilled in the art to understand the invention, it should be understood that the invention is not limited to the scope of the specific embodiments. For those skilled in the art, various changes are obvious as long as they are within the spirit and scope of the invention as defined and determined by the appended claims, and all inventions utilizing the concept of the present invention are protected.
Claims
1. A secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption, characterized in that, Includes the following steps: (1) Generating a chaotic sequence: The chaotic system generates a chaotic sequence based on the input key. The chaotic sequence consists of three parts: the chaotic key sequence K1, the chaotic key sequence K2, and the binary digital fingerprint sequence. (2) Bit-level substitution encryption: The plaintext data to be processed is first converted from serial to parallel, and then bit-level substitution encryption is performed using the chaotic key sequence K1. The encryption method is as follows: ; Where S is the bit-level substitution encrypted data, P is the plaintext data, and xor is the XOR operation function; (3) Time slot group division: The bit-level replacement encrypted data S is mapped to a constellation symbol sequence containing X and Y polarization signals using a dual polarization 16QAM mapper. In the time domain, the polarization constellation symbol sequence is divided into N consecutive symbol groups, each symbol group containing n symbol time slots. (4) Digital fingerprint embedding mapping and hybrid modulation: Each bit of the binary digital fingerprint sequence is mapped to each time slot group, and then compared sequentially: If a bit of a digital fingerprint is '0', the corresponding time slot group is mapped and modulated using the DP-16QAM format; If a bit of a digital fingerprint is '1', the corresponding time slot group is mapped and modulated using the 128SP-QAM format; (5) Polarization symbol permutation: The chaotic key sequence K2 is used to perform a joint permutation on the hybrid modulation symbol sequence after embedding the fingerprint. The permutation method is as follows: ; in, This represents the signal after polarization sign substitution. The sequence of symbols with X and Y polarization after hybrid modulation, sort() is the sorting function according to the given index, and the chaotic key sequence K2 is used as the given index; (6) Signal transmission: The signal after polarization sign substitution The signal is input to a coherent transmitter, converted into an optical signal, and transmitted to a coherent receiver via an optical fiber channel. (7) Signal reception and preprocessing: The coherent receiver receives the optical signal and converts it into an electrical signal, and then performs digital processing and equalization compensation on the electrical signal; (8) Inverse polarization symbol permutation: The received X and Y polarization symbol sequences are inversely permuted using the chaotic key sequence K2 synchronized with the transmitter to restore the time order of the symbols; (9) Constellation co-occurrence rate calculation: Divide the X and Y polarized symbol sequences after inverse permutation into time slot groups in the same way as the transmitter, and calculate the constellation co-occurrence rate (CSSR) value of the symbol sequence in each time slot group; (10) Fingerprint extraction: Compare the constellation co-occurrence rate (CSSR) value of each time slot group symbol sequence with the constellation co-occurrence rate preset threshold. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to DP-16QAM modulation, the modulation format of the time slot group symbol sequence is determined to be DP-16QAM modulation, thereby recovering the corresponding digital fingerprint bit '0'. If the CSSR is within the range of the constellation co-occurrence rate preset threshold corresponding to 128SP-QAM modulation, the modulation format of the time slot group symbol sequence is determined to be 128SP-QAM modulation, thereby recovering the corresponding digital fingerprint bit '1'. Finally, the bit values corresponding to each time slot group after recovery are reassembled into a complete digital fingerprint sequence. (11) Identity verification: Compare the reconstructed digital fingerprint sequence with the digital fingerprint sequence generated by the chaotic system to verify the legitimacy of the sender's identity. If the verification fails, trigger an alarm and terminate communication; otherwise, proceed to step (12). (12) Demodulation and decryption: After identity verification, the recombined digital fingerprint sequence is used to demodulate the symbol sequence of each time slot group, and the chaotic key sequence K1 is used to perform bit-level reverse substitution decryption to finally recover the plaintext data.
2. The secure coherent optical fiber communication encryption method based on digital fingerprinting and chaotic encryption according to claim 1, characterized in that, The calculation method for the constellation co-occurrence rate (CSSR) is as follows: ; Where n is the total number of constellation symbol pairs in the time slot group; Indicates the first in the same time slot Whether a pair of constellation symbols belongs to the same constellation set, when =1, indicating the first Groups of constellation symbols belong to the same constellation set; when =0, indicating the first The constellation symbols do not belong to the same constellation set; and These are the constellation sets to which the i-th time slot constellation symbol of the X and Y polarization branches belongs.
Citation Information
Patent Citations
Information encrypted transmission method of access network
CN107579961A
Optical access network constellation shaping security access method
CN112929318A