A federated learning training method based on quantum key distribution
Patent Information
- Application Number
- CN202610933933.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-26
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2046-06-26
AI Technical Summary
[0003]然而,现有结合密钥的联邦学习方案仍存在多维度的技术局限:其一,节点准入校验维度单一,仅通过基础身份认证完成节点准入,缺乏时序有效性与密钥完整性的双重校验机制,伪造身份的恶意节点易混入训练流程,且无法甄别超时上传的篡改梯度数据;其二,缺乏针对节点间隐蔽合谋攻击的有效检测手段,仍采用经典统计分析方式识别合谋行为,易被恶意节点通过伪造梯度特征规避检测;其三,密钥全生命周期管理机制不完善,普遍存在密钥跨轮次复用、轮次结束后密钥销毁不彻底的问题,难以保障密钥的前向安全性,单轮密钥泄露会直接波及多轮训练数据的安全;其四,全局模型聚合未与节点安全状态深度关联,普遍采用固定权重进行梯度聚合,存在异常行为的节点所上传的恶意梯度会直接干扰全局模型更新,导致训练收敛速度下降甚至模型偏离正常方向,严重制约多轮迭代联邦学习训练的整体安全性与运行可靠性
1)通过将量子密钥与训练轮次绑定并分发至各节点硬件安全模块,实现密钥的物理级隔离存储,防止密钥被软件层攻击窃取;轮次绑定机制确保每轮训练使用独立密钥,具备前向安全性,即使后续密钥泄露也不会危及历史训练数据;通过梯度时序戳与量子密钥哈希值的双重校验,有效抵御重放攻击和节点身份伪造;在梯度上传前即完成合法性筛选,提前过滤无效或恶意节点,降低全局服务器的计算与通信开销,提升整体效率;通过利用量子纠缠态贝尔态测量验证节点间行为关联性,可有效识别共谋攻击和异常协作节点;通过量子关联特性保证验证过程本身不可篡改,从而生成高可信度的有效参与节点列表,保障后续聚合的数据质量;
Smart Images

Figure CN122452820B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of federated learning technology, and in particular to a federated learning training method based on quantum key distribution. Background Technology
[0002] Federated learning can complete multi-node collaborative model training without leaving the domain of the original local data of each participant. It effectively solves the core contradiction between cross-organizational data silos and data privacy protection, and is widely used in multi-entity collaborative training scenarios such as smart healthcare and industrial internet.
[0003] However, existing federated learning schemes incorporating key authentication still suffer from several technical limitations: First, node admission verification is singular, relying solely on basic identity authentication and lacking a dual verification mechanism for temporal validity and key integrity. Malicious nodes with forged identities can easily infiltrate the training process, and it is impossible to identify tampered gradient data uploaded after a timeout. Second, there is a lack of effective detection methods against covert collusion attacks between nodes, relying on classical statistical analysis to identify collusion behavior, which is easily evaded by malicious nodes by forging gradient features. Third, the key lifecycle management mechanism is imperfect, with common problems such as key reuse across rounds and incomplete key destruction after rounds, making it difficult to guarantee forward key security. A single round of key leakage can directly affect the security of training data in multiple rounds. Fourth, global model aggregation is not deeply linked to node security status, generally using fixed weights for gradient aggregation. Malicious gradients uploaded by nodes with abnormal behavior can directly interfere with global model updates, leading to a decrease in training convergence speed or even model deviation from the normal direction, severely restricting the overall security and operational reliability of multi-round iterative federated learning training. To address these issues, this invention proposes a federated learning training method based on quantum key distribution. Summary of the Invention
[0004] The purpose of this invention is to address the problems in the background art by proposing a federated learning training method based on quantum key distribution.
[0005] To overcome the aforementioned shortcomings of existing technologies and to achieve the above objectives, this invention provides a federated learning training method based on quantum key distribution, comprising:
[0006] S1. Complete the initialization of global training parameters and quantum security parameters, generate quantum key fragments bound to the training rounds and distribute them to the hardware security modules of each registered participating node, and enter the waiting gradient upload state after confirming the distribution is completed. S2. Obtain the gradient generation time stamp and quantum key shard hash value, and perform double verification based on the gradient generation time stamp and quantum key shard hash value to generate an initial list of legal nodes; S3. In the initial list of legitimate nodes, verify the behavioral correlation between nodes through quantum entangled Bell state measurement, generate a list of valid participating nodes, and issue a local training start command after completing full node key synchronization; S4. Effectively participating nodes execute local model training and perform block-based encrypted transmission of gradient parameters based on the corresponding round of quantum key fragmentation; S5. Receive and reassemble all encryption gradient parameters, allocate dynamic weights based on node behavior correlation to complete global model aggregation, destroy all quantum key fragments in this round, and generate quantum key fragments for the next round.
[0007] Further, S1 includes: The global server initializes the global model parameters of federated learning, the total number of training rounds, the single-round training time window, and the quantum security parameters, and simultaneously broadcasts the initialization completion signal and the node identity mapping table to all registered participating nodes. After receiving the initialization completion signal from the global server, the quantum key distribution center generates a quantum key pool bound to this training round and divides the key pool into quantum key fragments evenly according to the number of currently registered participating nodes. Each quantum key slice is embedded with a round identifier, the identity identifier of the corresponding registered participating node, and a time sequence check bit. The quantum key slice is then distributed to the corresponding registered participating node. After each registered participating node receives the quantum key fragment, it stores it in the encrypted isolation partition of the hardware security module, and at the same time sends a receipt confirmation acknowledgment carrying the node's signature back to the quantum key distribution center. After the quantum key distribution center collects the receipt confirmations from all registered participating nodes and verifies the validity of the signatures, it sends a key pre-distribution completion notification to the global server. The global server then starts the single-round training time window timing and enters the waiting state for node gradient uploads.
[0008] Further, S2 includes: The global server continuously listens for gradient update package upload requests from each registered participating node within a single training time window. Upon receiving a gradient update package, it immediately extracts the node identity, gradient generation time stamp, and node signature carried within the gradient update package. Based on the extracted node identity identifier, the corresponding registered participating node's quantum key fragment for this round is retrieved from the quantum key distribution center, and the timing check bit embedded in the quantum key fragment is extracted. The gradient generation time stamp is compared and verified with the time check bit to obtain the time check result; If the timing verification passes, the global server sends a key integrity verification request carrying a random challenge value to the corresponding registered participating node. The registered participating node extracts the quantum key fragment for this round from the hardware security module, calculates the hash value by combining it with the random challenge value, signs it, and returns it. After the global server verifies the validity of the node signature, it compares the returned hash value with the pre-stored standard hash value. If the two match, the registered participating node is determined to be an initial legitimate node and added to the initial legitimate node list.
[0009] Further, S3 includes: After the global server obtains the generated initial list of legal nodes, it uses a random number generator to generate a list of node pairs without repetition, and assigns a pair of entangled particles to each pair of initial legal nodes. One entangled particle from each pair of entangled particles is sent to the first initial legitimate node in the node pairing list via an independent quantum channel, and the other entangled particle is sent to the second initial legitimate node. At the same time, a Bell state measurement command is sent to each pair of initial legitimate nodes. After each pair of initial legitimate nodes receives the entangled particle and Bell state measurement instructions, it performs Bell state measurement on the entangled particles it holds, generates Bell state measurement data, signs it with its local private key, and then uploads it to the global server. After the global server verifies the validity of the signatures of each pair of initial legitimate nodes, it compares the Bell state measurement results of the two initial legitimate nodes and calculates the behavioral correlation between the nodes. Node pairs whose behavioral correlation exceeds a preset abnormal threshold are marked as suspicious node pairs. The initial legitimate nodes with abnormal behavior in the suspicious node pairs are located and removed. The remaining nodes are the valid participating nodes, and a list of valid participating nodes is generated.
[0010] Furthermore, S3 also includes: After generating the list of valid participating nodes, the global server sends a key synchronization instruction carrying the unified key synchronization identifier for this round to all valid participating nodes in the list; After receiving the key synchronization instruction, each valid participating node extracts the quantum key fragment for this round from the hardware security module, calculates the latest hash value by combining it with the key synchronization identifier, signs it, and uploads it to the global server. The global server performs consistency checks on the hash values uploaded by all valid participating nodes, filters out valid participating nodes whose hash values are inconsistent with the standard hash values, and sends targeted redistribution instructions to the quantum key distribution center. The quantum key distribution center redistributes the complete quantum key fragments of this round to valid participating nodes with inconsistent hash values through a secure quantum channel. After the valid participants receive and verify the integrity and legitimacy of the new quantum key fragments, they update the quantum key fragment data in their local encrypted isolation partitions. After the global server confirms that the quantum key distribution status of all valid participating nodes is completely unified, it sends a local training start command carrying the latest global model parameters to all valid participating nodes.
[0011] Further, S4 includes: After receiving the local training start command, the active participating node verifies the integrity of the command signature and global model parameters. If the verification is successful, it loads the local training dataset and the latest global model parameters. The model is trained according to the preset number of local training iterations, learning rate and batch size, and the local gradient parameters for this round are generated after training is completed. According to the structure of the model network layers, the local gradient parameters are divided into multiple parameter blocks, and a unique continuous index identifier is assigned to each parameter block. Extract the quantum key fragments for this round from the local hardware security module, divide the quantum key fragments into a corresponding number of sub-key segments according to the number of parameter blocks, and establish a mapping relationship between parameter block index identifiers and sub-key segments; The encryption method adopts one-time pad encryption, and each parameter block is encrypted block by block using the corresponding sub-key segment to generate encrypted parameter blocks; at the same time, a local temporary backup of all plaintext parameter blocks is saved to the temporary partition of the hardware security module; all encrypted parameter blocks are combined with the corresponding index identifier in a randomized order to form a gradient encrypted data packet, which is then signed and uploaded to the global server through the classic communication channel.
[0012] Furthermore, S4 also includes quantum channel security monitoring and abnormal retransmission steps during gradient transmission: During the transmission of gradient encrypted data packets, the global server and each participating node monitor the status of the quantum channel and the classical communication channel in real time, with a focus on monitoring the photon error rate of the quantum channel and the packet loss rate of the classical channel. When the quantum channel photon bit error rate of any valid participating node exceeds the preset security threshold, it is determined that the subkey segment currently used by the valid participating node is at risk of leakage, and the global server immediately sends a transmission interruption command to the valid participating node. After receiving a transmission interruption command, the active participating node terminates the transmission of the current data packet, extracts the pre-generated backup sub-key segment from the quantum key fragment of this round, and re-encrypts the plaintext parameter block corresponding to the encrypted parameter block that failed to be transmitted. After the active participating node completes encryption using the spare subkey segment, it sends a retransmission request carrying the new index mapping relationship to the global server. After the global server confirms, the active participating node continues to upload the re-encrypted encryption parameter block and the corresponding new index identifier.
[0013] Furthermore, S4 also includes the classic communication channel packet loss retransmission step in the gradient transmission process: The global server monitors the packet loss rate of the classic communication channel in real time. When it detects that a packet loss has occurred in the gradient encryption data packet of any valid participating node, it immediately sends a packet loss retransmission instruction carrying the index of the lost encryption parameter block to that valid participating node. After receiving the packet loss retransmission instruction, the active participating node extracts the corresponding indexed encrypted parameter block from the local temporary backup and retransmits the encrypted parameter block to the global server; the steps are repeated until all encrypted parameter blocks of the active participating node in this round have been transmitted.
[0014] Further, S5 includes: After receiving the gradient encryption data packets from all valid participating nodes and verifying the signature validity, the global server sorts and reassembles the encryption parameter blocks according to the index identifier in the gradient encryption data packets to recover the complete encrypted gradient data of each valid participating node. Obtain the global complete key for this round from the quantum key distribution center, and use the global key to decrypt the encrypted gradient data of each valid participating node to obtain the plaintext gradient parameters of each valid participating node; Retrieve the behavioral correlation of each effective participating node and assign corresponding dynamic weights to the plaintext gradient parameters of different effective participating nodes; The plaintext gradient parameters of all valid participating nodes are aggregated and calculated using a weighted average method to obtain the global gradient update amount for this round. The global model parameters are updated using the global gradient update amount, and the updated global model parameters are generated and hashed for verification.
[0015] Furthermore, S5 also includes: After the global model parameters are updated and verified to be correct, the global server sends an irrevocable key destruction instruction to all valid participating nodes and the quantum key distribution center. The instruction carries the destruction identifier and the number of overwrites required for this round. After each valid participating node receives the destruction command and verifies its legality, it performs a preset number of overwrite destruction operations on all quantum key fragments, subkey segments, spare subkey segments, and temporary encrypted data generated during training stored in the encrypted isolation partition of its local hardware security module. After receiving the destruction instruction and verifying its legitimacy, the quantum key distribution center overwrites and destroys all key materials for this round, and returns a destruction completion receipt with the center's signature to the global server. At the same time, send the next round of key generation instructions to the quantum key distribution center; After receiving the instruction, the quantum key distribution center generates a brand-new quantum key pool that is uniquely bound to the next round, and divides the quantum key into fragments according to the updated list of valid participating nodes.
[0016] Compared with existing technologies, the beneficial effects of this invention in providing a federated learning training method based on quantum key distribution are as follows: 1) By binding quantum keys to training rounds and distributing them to the hardware security modules of each node, physical-level isolated storage of keys is achieved, preventing keys from being stolen by software-layer attacks; the round binding mechanism ensures that each training round uses an independent key, providing forward security, and even if subsequent keys are leaked, historical training data will not be compromised; dual verification using gradient time stamps and quantum key hash values effectively resists replay attacks and node identity forgery; legitimacy screening is completed before gradient uploading, filtering out invalid or malicious nodes in advance, reducing the computational and communication overhead of the global server, and improving overall efficiency; by using quantum entangled Bell state measurements to verify the behavioral correlation between nodes, collusion attacks and abnormal cooperative nodes can be effectively identified; the quantum correlation properties ensure that the verification process itself is immutable, thereby generating a highly reliable list of valid participating nodes and ensuring the quality of subsequent aggregated data; 2) By employing a one-time pad method to encrypt gradient parameters in blocks, combined with quantum key distribution, information-theoretic security-level confidentiality is achieved. Block encryption ensures that the leakage of a single key will not lead to the exposure of all gradients, and random shuffling of the transmission order can effectively resist traffic analysis attacks, comprehensively guaranteeing the confidentiality and integrity of the gradient transmission process. By allocating dynamic weights based on the correlation of node behavior, the aggregation result can better reflect the contribution of trusted nodes, improving the accuracy of the global model. After each round of training, all quantum key fragments are destroyed and new keys are generated immediately, completely eliminating the risk of key reuse. Even if an attacker obtains the current key, they cannot reverse engineer historical training information, achieving strict forward and backward security. Attached Figure Description
[0017] Figure 1 This is a flowchart of a federated learning training method based on quantum key distribution proposed in this invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Please see Figure 1 This invention provides a federated learning training method based on quantum key distribution, comprising: S1. Complete the initialization of global training parameters and quantum security parameters, generate quantum key fragments bound to the training rounds and distribute them to the hardware security modules of each registered participating node. After confirming the distribution is completed, enter the waiting gradient upload state. The hardware security module is a physical security component independent of the node's general-purpose processor. It integrates an encrypted isolation partition, a true random number generator, a cryptographic hash engine and a quantum-resistant signature coprocessor. It is responsible for the storage of quantum key fragments, key derivation, encryption and decryption operations and signature operations. Its memory access control list strictly prohibits any unauthorized process from reading the key plaintext, thus preventing key leakage at the physical level. S2. Obtain the gradient generation time stamp and quantum key shard hash value, and perform double verification based on the gradient generation time stamp and quantum key shard hash value to generate an initial list of legal nodes; S3. In the initial list of legitimate nodes, verify the behavioral correlation between nodes through quantum entangled Bell state measurement, generate a list of valid participating nodes, and issue a local training start command after completing full node key synchronization; S4. Effectively participating nodes execute local model training and perform block-based encrypted transmission of gradient parameters based on the corresponding round of quantum key fragmentation; S5. Receive and reassemble all encryption gradient parameters, allocate dynamic weights based on node behavior correlation to complete global model aggregation, destroy all quantum key fragments in this round, and generate quantum key fragments for the next round.
[0020] In this embodiment of the invention, the detailed process of S1 initializing global training parameters and quantum security parameters, generating quantum key fragments bound to the training rounds and distributing them to the hardware security modules of each registered participating node, and confirming that the distribution is completed before entering the waiting gradient upload state includes: S11. The global server initializes the global model parameters of federated learning, the total number of training rounds, the single-round training time window, and the quantum security parameters, and simultaneously broadcasts the initialization completion signal and the node identity mapping table to all registered participating nodes. Specifically, the global server starts the initialization process in its trusted execution environment, calls the quantum random number generator to generate a true random seed, and uses the true random seed to initialize the parameters of the federated learning global model, making the initial weights and biases unpredictable and preventing the parameter initialization rules from being exploited by external attackers. The global server is the centralized coordination unit for federated learning training tasks. It runs in a trusted execution environment and is responsible for global model parameter initialization, training round scheduling, double verification of node legality, entanglement measurement behavior analysis, gradient aggregation and model update. It also interacts with the quantum key distribution center to complete key synchronization and destruction. All critical security logic is executed in its secure memory area. The global model parameters for federated learning are encapsulated into structured data blocks, including parameter tensors, version numbers, and timestamps, and an integrity checksum is generated for each data block. The total number of training epochs is determined by considering the model convergence analysis results, the number of participating nodes, and the heterogeneity of the dataset, and is set to 500 epochs. This value is written into the epoch control field of the global configuration file. The length of the single-epoch training time window is calculated based on the sum of the quantum key distribution end-link latency, the upper limit of the node's local training computation time, and the network jitter buffer time, for example, a value of 600 seconds. This duration is encoded with second-level precision. Integer values are stored in the time window field; quantum security parameters include the selected quantum key distribution protocol version identifier, polarization compensation parameters for entangled photon pairs, Bell state measurement basis vector selection algorithm identifier, and cryptographic hash algorithm strength used for key derivation and authentication, etc. Quantum security parameters are combined into a parameter set and fixed in the secure storage area of the global server in the form of a structure; after the global server completes parameter initialization, it generates a session identifier for this training task, concatenates all parameters with the session identifier, and uses the server's quantum security private key to generate a digital signature, which together constitutes the initialization completion signal; The server retrieves a pre-configured identity mapping table for registered participating nodes. This table assigns a permanent node identifier to each registered participating node that has passed identity verification and binds it to its current network address, public key fingerprint, quantum channel port identifier, and hardware security module serial number. During the construction of the identity mapping table, the corresponding relationships are injected into the local trusted storage of the registered participating nodes through an offline secure channel. The global server uses a classic communication channel and a reliable multicast protocol based on the publish-subscribe model to multicast a message containing a digital signature, initialization completion signal, and mapping table to all registered participating nodes. Each message also carries a sequence number and timeliness identifier to prevent replay attacks.
[0021] S12. After receiving the initialization completion signal from the global server, the quantum key distribution center generates a quantum key pool bound to this training round and divides the key pool into independent and non-overlapping quantum key fragments according to the number of currently registered participating nodes. Specifically, the initialization completion signal is analyzed to include the current training round identifier, session identifier, and the number of currently valid registered participating nodes. An initial true random bit stream is generated based on an independent entropy source, and this bit stream is used to drive the point-to-point key generation process of the quantum key distribution protocol. A quantum key pool with a total length of L bits is generated in the quantum random number generation array inside the center. The value of L is set to an integer multiple of the key length required by each node with a margin. During the key pool generation process of this round, fresh randomness is continuously injected through a quantum random process. The generated key bit string is concatenated with the round identifier and subjected to a cryptographic hash operation to generate a key pool verification tag bound to the round. This tag is stored in the center's tamper-proof log. The quantum key distribution center reads the list of currently registered participating nodes and determines the number of nodes N. It then divides the key pool into N independent and non-overlapping quantum key fragments according to byte alignment, with each fragment having the same length. During the division process, bits are extracted from the key pool without overlap, ensuring that no two quantum key fragments share bits and avoiding information correlation between fragments. After each quantum key fragment is generated, it is assigned a quantum key fragment sequence number, and its cryptographic hash value is calculated as an integrity benchmark. These benchmark values are centrally stored in the center's key integrity record table. The quantum key distribution center temporarily stores the divided quantum key fragments in a quantum-safe storage unit; at this point, no node-specific information has been injected into the quantum key fragments.
[0022] S13. Embed a round identifier, the identity identifier of the corresponding registered participating node, and a timing check bit bound to the start and end times of the single round training time window for each quantum key slice. Distribute the quantum key slice to the corresponding registered participating node through an independent quantum channel corresponding to each registered participating node. Specifically, after the quantum key distribution center obtains all the quantum key fragments generated in the previous stage, it begins to perform structured encapsulation on each quantum key fragment; it extracts the current training round identifier, which is composed of a training session identifier and a round number, and embeds the training session identifier into a fixed-length field in the header of the fragment data; According to the allocation target, the identity identifier of the corresponding registered participating node is read. The identity identifier is a cryptographic hash value of the node's permanent identifier, which is also embedded in the second fixed field of the shard. Based on the start and end times of the single-round training time window set by the global server, a time-series check code with strict time constraints is generated. This time-series check code is encoded as a binary sequence and embedded in the time-series field area of the shard data structure. The encoding rule is to convert the start and end UTC timestamps of the time window into fixed-length bit strings using a secure date and time encoding algorithm, and then perform an XOR operation to generate the final time-series check bit. This time-series check bit can only be correctly decoded by the matching check algorithm within the specified time window. After encapsulation, the quantum key distribution center establishes a binding between each quantum key fragment and an independent quantum channel of the target node, and sends the encapsulated quantum key fragment through the target node's dedicated quantum channel. During transmission, the quantum key distribution center monitors channel security and uses a one-time pad method to encode the fragment data into quantum states. The receiving quantum receiving device completes the decoding based on the pre-shared measurement basis vector sequence.
[0023] S14. After each registered participating node receives the quantum key fragment, it stores it in the encrypted isolation partition of the hardware security module, prohibiting any unauthorized process from accessing it. At the same time, it returns a receipt confirmation receipt carrying the node's signature to the quantum key distribution center. Specifically, after each registered participating node receives the fragmented quantum signal from the quantum key distribution center, its quantum receiver performs single-photon detection according to a preset measurement basis sequence, converting the quantum state into a classical bit stream. After error correction and security enhancement algorithms, the complete quantum key fragment data is recovered. The secure boot firmware within the node immediately transmits this quantum key fragment data to the encrypted isolation partition of the hardware security module via an internal dedicated bus. This encrypted isolation partition consists of a set of independent non-volatile storage units within the hardware security module, physically isolated from the processing unit running the general-purpose operating system. Before receiving the quantum key fragment, the memory access control list within the hardware security module has set the access permissions to allow only the key management firmware to read and write, prohibiting... Any general-purpose application, debugging interface, or network protocol stack can access this storage area. While storing quantum key fragments, the node calculates the cryptographic hash value of each fragment and compares it with the expected value stored internally to confirm the integrity of the data transmission. After successful storage, the node's hardware security module uses its device private key to generate a digital signature on the data structure containing the received quantum key fragment sequence number, round identifier, current timestamp, and quantum key fragment hash value, forming a reception confirmation receipt. This receipt is sent to the quantum key distribution center through a classical communication channel. The receipt message also includes a reference to the node's certificate chain, facilitating the center's verification of the signature's credibility. During this process, the node does not output any fragment plaintext information to insecure areas, and all log records are stored in encrypted form within the hardware security module.
[0024] S15. After the quantum key distribution center collects the receipt confirmations from all registered participating nodes and verifies the validity of the signatures, it sends a key pre-distribution completion notification to the global server. The global server then starts the single-round training time window timing and enters the waiting state for node gradient upload. Meanwhile, the global server divides the data into independent quantum channels for quantum key and entangled particle transmission, and classical communication channels for gradient data and control command transmission. Specifically, the quantum key distribution center continuously monitors the reception confirmation acknowledgments sent by each node on the classical communication channel and maintains a state machine for each expected node. It extracts the digital signature and node certificate chain from the message, verifies the certificate validity level by level, checks the certificate revocation list, and then uses the node's public key to verify whether the signature covers key shard sequence number, round identifier, and timestamp, among other key fields. After successful verification, the node is marked as having completed key distribution, and the quantum key shard hash value is compared with the previously stored benchmark value for secondary confirmation. When the acknowledgments for all registered participating nodes have been verified and the status is marked, a key pre-distribution completion notification message is generated. This message carries the round identifier, completion timestamp, and an aggregated proof of the integrity of all node shards. The message is then signed using the center's private key and sent to the global server. Upon receiving the notification, the global server verifies the signature of the verification center and then reads the completion status of distribution from each node in the message. It immediately reads the system's high-precision clock, records this moment as the starting point of the single-round training time window, and loads the preset window duration into a countdown timer. The state machine then enters the waiting phase for gradient upload, at which point the server is ready to receive gradient update packets from the nodes. Simultaneously, the global server allocates channel resources, designating independent wavelength quantum channels from the optical switching network for quantum key distribution and entangled particle transmission. These quantum channels employ dedicated optical fibers and photon counting detectors, physically isolating them from the classical communication channels carrying gradient data and control commands. The classical communication channels use encrypted links based on the TLS protocol to transmit gradient parameters and control messages.
[0025] In this embodiment of the invention, the detailed implementation steps of S2, which involves obtaining the gradient generation time stamp and the quantum key shard hash value, and performing dual verification based on the gradient generation time stamp and the quantum key shard hash value to generate an initial list of legitimate nodes, include: S21. The global server continuously listens for gradient update package upload requests from each registered participating node within a single training time window. Upon receiving a gradient update package, it immediately extracts the node identity, gradient generation time stamp, and node signature carried within the gradient update package. Specifically, after the global server enters the gradient upload waiting state, it opens a multiplexed listening socket at the transport layer and starts a gradient update packet receiving event loop at the application layer. The global server's network interface card performs hardware filtering on the arriving data packets, allowing only packets with source addresses matching the registered participating node list; packets with other source addresses are discarded directly at the network interface card level. Whenever a complete gradient update packet is received, the global server performs integrity verification on the data packet at the operating system kernel layer, confirming that the transport layer checksum is correct and the application layer packet length matches the declaration. Subsequently, the data is copied to the user space secure processing buffer, where fields are extracted in the order of the gradient update packet's data protocol format. This protocol specifies that the data packet header contains a fixed magic number. The data packet header includes a number, version number, and total length. The fixed magic number is a constant value preset in the header to quickly identify and verify whether the data packet belongs to the format defined by this protocol. Next is the node identity field, which stores the encrypted form of the node's permanent identifier. Following this is the gradient generation timing stamp field, which is read and inserted by the node from the secure clock of the hardware security module at the moment the gradient calculation is completed. Finally, there is the node signature field, which is a digital signature made by the node using its hardware security module's private key for the entire gradient update packet header and payload. The signature algorithm adopts a lattice-based quantum-resistant signature scheme to ensure long-term security.
[0026] S22. Based on the extracted node identity identifier, call the corresponding registered participating node's quantum key fragment for this round pre-stored in the quantum key distribution center, and extract the timing check bits embedded in the quantum key fragment, including: The global server converts the node identity extracted in the previous step into an index key value and initiates a query to the locally maintained key shard index table. This key shard index table is pushed to the global server by the quantum key distribution center through a secure interface during the key pre-distribution phase. Each record in this table contains a cryptographic hash index of the node identity and the corresponding encrypted key handle. Based on the query result, a token is obtained, and a call request is sent to the quantum key distribution center using this token. The request includes the node identity, round identifier, and call reason code. After receiving the call request, the quantum key distribution center verifies the server signature and permissions, and then locates the quantum key shard backup data of the current round for that node in its secure hardware storage based on the index. The key shard data structure is parsed in a secure computing environment to locate the fixed offset position of the stored timing check bit. The ciphertext of this timing check bit is extracted using a secure decryption module. The ciphertext is decrypted using an internal timing key to restore the original binary sequence of the timing check bit, which contains time window binding information and verification encoding. The decrypted timing check bit is encapsulated in a response message and transmitted back to the global server using a point-to-point encrypted channel.
[0027] S23. Compare the gradient generation time stamp with the time check bit to verify whether the gradient generation time stamp is within the preset time window of this round and completely matches the encoding rule of the time check bit. The process of obtaining the time check result is as follows: The first half of the timing check bit is converted into a start time constraint value using a pre-defined decoding algorithm, and the second half is converted into an end time constraint value. These two time constraint values constitute the trusted encoding mapping for the corresponding single-round training time window. The extracted gradient-generated timing stamp value is compared with the decoded start and end time constraint values to determine whether the time represented by the timing stamp is greater than or equal to the start time and less than or equal to the end time. This comparison operation uses a secure comparison function to prevent attacks based on timing side channels. If the timing stamp falls within the time window range, the global server continues encoding rule matching. Verification: Based on the pre-defined encoding rules, the algorithm derives the gradient-generated time stamp itself as input to generate the expected encoding rule bit pattern. This expected pattern is then compared bit by bit with the encoding rule field originally embedded in the time check bit, requiring complete consistency. Complete consistency means that the values at every bit position match without any deviation. The global server only sets the time check result to a passed state if both the time range check and encoding rule matching pass; otherwise, it records the time check as failed and generates a corresponding error code. Finally, the time check result is locked as a Boolean state value. The duration of the single-round training time window is set based on the maximum clock deviation caused by quantum key distribution, the difference in computing power of different nodes, and the statistical upper limit of the maximum round-trip latency of the network. In a typical implementation, the 99th percentile value of the gradient calculation time distribution of each node is obtained by pre-testing the clock synchronization accuracy and measuring the training computation time of all registered participating nodes in the network, and adding the 50-second time margin required for quantum channel establishment and key distribution, the time window length is finally determined to be 600 seconds.
[0028] S24. If the timing verification passes, the global server sends a key integrity verification request carrying a random challenge value to the corresponding registered participating node. The registered participating node extracts the quantum key fragment for this round from the hardware security module, calculates the hash value by combining it with the random challenge value, signs it, and returns it. Understandably, when the timing verification result of a registered participating node returns as passed, the global server immediately calls the hardware random number generator to generate a strong random challenge value with a length of no less than 256 bits; this random challenge value is appended to a key integrity verification request message, which also contains the node identity identifier, round identifier, and request sequence number; the global server encrypts the request message using the session key negotiated with the target node and sends it to the node through the classic communication channel; Upon receiving an encryption request, the node decrypts and verifies the request's sequence number and timeliness. The node's main processor sends a security instruction to the local hardware security module, which can only be executed after being verified by the module's internal hardware. The instruction requires the hardware security module to read the complete quantum key fragment for this round from the encrypted isolation partition; this reading operation is completed entirely within the module's internal bus. The hardware security module concatenates the binary data of the quantum key fragment with the received random challenge value, and inputs the concatenation result into the hardware security module's built-in cryptographic hash engine. This engine uses the SHA-3 algorithm to calculate a fixed-length hash value. After the hash value is calculated, the hardware security module uses its internally stored device private key to sign the hash value along with the challenge value and the node's identity identifier, generating a signed response data packet. This response data packet is returned to the node's main processor through a secure channel, and the main processor encapsulates it and immediately uploads it to the global server.
[0029] S25. After the global server verifies the validity of the node signature, it compares the returned hash value with the pre-stored standard hash value. If the two match, the registered participating node is determined to be an initial legitimate node and is added to the initial legitimate node list. If any verification fails, the registered participating node is rejected from participating in this round and the abnormal behavior is recorded. Specifically, the global server reads the node's public key certificate from its local certificate storage and uses this public key to verify the digital signature of the response data packet. It checks whether the signature truly covers the hash value, challenge value, and node identity, while also verifying the validity and timeliness of the certificate chain. If signature verification fails, the global server immediately terminates the verification process for that node, generates an audit log for invalid signature, and rejects the node's participation. If signature verification passes, the global server proceeds to the hash value comparison phase. Prior to this, the global server has already obtained a list of standard hash values for each quantum key fragment combined with each random challenge value from the quantum key distribution center during the key pre-distribution phase. This list is pre-calculated in a secure environment and stored in the server's protected hash table. Based on the node identity and the currently used random challenge value index, the corresponding standard hash value is retrieved from the hash table. The standard hash value is pre-calculated by the quantum key distribution center after key pre-distribution, using the same random challenge value as the node, for each key fragment, and synchronized to the global server in encrypted form. The cryptographic hash algorithm used for its calculation is SHA-3-256 to resist length expansion attacks and quantum computing threats, and the output hash value is 256 bits long. For example, for a node key fragment 0xAB…F3 and a random challenge value 0x12…CD, the pre-calculated standard hash value is 0x3A5B…9E. The hash value returned by the node is compared byte by byte with the retrieved standard hash value. If all bytes match, the registered participating node is determined to hold the correct quantum key fragment. Under the dual conditions of valid signature and consistent hash value, the registered participating node is marked as an initial legitimate node and its node identifier is inserted into the initial legitimate node list. If the signature verification passes but the hash value is inconsistent, the participation qualification is also rejected and a key abnormality warning event is generated.
[0030] In this embodiment of the invention, the specific implementation of step S3, which verifies the behavioral correlation between nodes through quantum entangled Bell state measurement in the initial list of legitimate nodes, generates a list of valid participating nodes, and issues a local training start command after completing full node key synchronization, is as follows: S31. After obtaining the generated initial list of legal nodes, the global server uses a random number generator to generate a list of unique node pairs. For each pair of initial legal nodes, a pre-generated and unused pair of entangled particles is assigned, including: Obtain a list of M initial valid nodes, arranged in lexicographical order based on their identifiers; use an entropy source conforming to the NIST SP 800-90B standard to generate an unpredictable random seed, and use this seed to initialize a deterministic random number generator; map the node identifiers of the initial valid node list to consecutive integer indices, and then randomly scramble the index sequence to obtain a shuffled node sequence; group this node sequence into pairs to form K pairs of node pairings, where K equals M divided by two and rounded down; if the total number of nodes is odd, the remaining node will not participate in this round of entanglement pairing, but will still retain its valid participation qualification and will be processed through a separate security assessment path; After generating the node pairing list, the global server sends an entanglement allocation request to the quantum key distribution center. The request includes the node pairing list and the required number of entangled particle pairs K. The quantum key distribution center maintains a pre-generated entangled particle pair storage pool, where the entangled particle pairs are, in a preferred embodiment, entangled photon pairs, which are continuously generated and stored in the quantum buffer through a spontaneous parametric downconversion process. Each pair of entangled particles has the highest degree of polarization entanglement fidelity. According to the request, an unused pair of entangled particles is allocated to each pair of nodes one by one. During allocation, the unique identifier of the entangled particle pair is recorded and bound to the pairing relationship. At the same time, an entanglement resource allocation list is generated and sent back to the global server.
[0031] S32. Send one entangled particle from each pair of entangled particles to the first initial legitimate node in the node pairing list through an independent quantum channel, and send the other entangled particle to the second initial legitimate node. At the same time, send a Bell state measurement command carrying the measurement basis vector sequence to each pair of initial legitimate nodes. Specifically, the quantum key distribution center, based on the allocated entanglement resource list, begins the distribution of entangled particles. For each pair of entangled particles, the center's optical switch matrix, under the command of the control system, routes one entangled particle to the transmission port of an independent quantum channel pointing to the first initial legitimate node, and routes the other entangled particle to the transmission port pointing to the second initial legitimate node. The transmission process employs a strict time synchronization mechanism to ensure that the two entangled particles are emitted within the same time window, maintaining the non-local correlation of entanglement. Simultaneously, as the two entangled particles enter their respective quantum channels for transmission, the quantum key distribution center, according to... A pre-selected measurement basis selection scheme generates a measurement basis sequence. This measurement basis sequence specifies the basis combination to be used in each measurement time slot during Bell state measurement. The basis includes horizontal, vertical, and diagonal basis, and the sequence length is consistent with the number of time slices at the expected arrival time of the entangled particle pair. The measurement basis sequence is encapsulated into a Bell state measurement command, which includes the measurement start time, measurement duration, entangled particle arrival sequence number, and return data format requirements. This command is sent to the two initially legitimate nodes in the pair, with the transmission completed through a classical control channel and protected by a node-specific symmetric encryption key to prevent the measurement basis information from being eavesdropped.
[0032] S33. After each pair of initially legitimate nodes receives the entangled particle and Bell state measurement instructions, it performs Bell state measurements on its respective entangled particles according to the measurement basis sequence within a preset measurement time window, generates Bell state measurement data, signs it with its local private key, and uploads it to the global server. Specifically: After receiving an entangled particle, the quantum receiving port of each initially legitimate node sends the quantum state signal corresponding to the entangled particle to the front end of the Bell state analyzer, which consists of a circulator and a beam splitter. According to the measurement start time specified in the Bell state measurement command, the high-speed gating circuit is triggered in time to activate the single-photon detector within the preset measurement time window. This measurement time window is pre-calibrated based on the quantum channel transmission delay and detector jitter characteristics. Within the measurement time window, the node steps according to the measurement basis sequence. For each arrival time slot, the measurement control logic dynamically switches the electro-optic modulator to select the corresponding measurement basis, projects the incident entangled particle onto the selected basis, and then the superconducting nanowire single-photon detector records the detection event. Each measurement result is converted into a binary value and stored in two independent data streams. After the sequence recording of the entire measurement cycle is completed, the raw measurement data is aligned and formatted to generate a Bell state measurement dataset containing the arrival time stamps of entangled particles, the selected basis vector sequence numbers, and the corresponding measurement results. This Bell state measurement dataset is then sent to the hardware security module, where the device's private key is used to digitally sign the measurement data, generating an upload packet containing the signature and measurement data. The signature operation protects the data integrity, preventing the measurement data from being tampered with during transmission. The signed upload packet is then sent to the global server via a classic communication channel.
[0033] S34. After the global server verifies the validity of the signatures of each pair of initial legitimate nodes, it compares the Bell state measurement results of the two initial legitimate nodes and calculates the behavioral correlation between the nodes. The higher the behavioral correlation, the greater the suspicion of collusion between the nodes. Specifically, after the global server receives the Bell state measurement data packets uploaded by the two initially legitimate nodes in the same node pair, it verifies the signatures using the public key certificates of both parties to ensure that the measurement basis vector sequence and measurement results have not been tampered with. Then, it synchronizes and aligns the measurement result sequences of both parties according to the time tag to eliminate the fixed offset introduced by channel delay. Based on the CHSH type Bell inequality, it substitutes the basis vector selection and measurement results of the corresponding time slots of both parties into the correlation function to calculate the correlation value. The calculated correlation value is compared with the correlation value interval established based on the historical normal node group: if the correlation value falls within the correlation value interval, it indicates that the measurement behavior of the node pair conforms to the standard entanglement correlation statistics and the correlation behavior is normal; if the correlation value deviates from the correlation value interval, it is judged that the behavior is abnormal, and there may be basis vector collusion or result manipulation. The correlation value interval is set to a range of ±3 times the standard deviation of the mean after a large number of Bell state measurement experiments are conducted using known trusted nodes in an attack-free environment during the initialization phase. The deviation between the correlation value and the boundary of the correlation value interval is mapped to a normalized behavioral correlation degree, and the larger the value, the higher the degree of abnormality.
[0034] S35. Mark the node pairs whose behavior correlation exceeds the preset abnormal threshold as suspicious node pairs, locate the initial legal nodes with abnormal behavior in the suspicious node pairs and remove them. The remaining nodes are the valid participating nodes, and generate a list of valid participating nodes. The abnormal threshold is obtained by having a trusted third party organize a large number of normal node pairs to perform entanglement measurement in an attack-free experimental environment, collect normal behavior correlation samples, calculate their mean and standard deviation, and take the sum of the mean and three times the standard deviation as the abnormal threshold.
[0035] S36. After generating the list of valid participating nodes, the global server sends a key synchronization instruction carrying the unified key synchronization identifier for this round to all valid participating nodes in the list.
[0036] S37. After receiving the key synchronization command, each valid participating node extracts the quantum key fragment for this round from the hardware security module, calculates the latest hash value by combining it with the key synchronization identifier, signs it, and uploads it to the global server. The implementation method is as follows: The key synchronization instruction is decrypted and the unified key synchronization identifier for this round is extracted. The node master controller sends a key synchronization hash request to the hardware security module, and passes the key synchronization identifier along with the request. The node master controller is responsible for executing the deep learning training framework, loading the local dataset, calculating gradient parameters, and initiating key reading and encryption requests to the hardware security module. However, it cannot directly access the quantum key fragment plaintext. All key operations must be completed through the restricted interface of the hardware security module. The hardware security module locates the flash memory block storing the quantum key fragments for this round within the encrypted isolation partition, reads the complete key fragment data into the module's internal volatile operation buffer, concatenates the key fragment data and key synchronization identifier in the order of identifier first, key last, and then calls the hardware security module's built-in cryptographic hash engine to calculate the SHA-3 hash value. This hash value is then signed by the hardware security module's signature coprocessor using the device's private key, with the signing process covering the hash value, key synchronization identifier, and current timestamp. After signing, the signature result and hash value are packaged together and output to the node master controller. The node master controller encapsulates the above data into a key synchronization response message and securely transmits it to the global server through the classical communication channel.
[0037] S38. The global server performs consistency verification on the hash values uploaded by all valid participating nodes, filters out valid participating nodes whose hash values are inconsistent with the standard hash values, and sends targeted redistribution instructions to the quantum key distribution center. The process involves the global server collecting key synchronization response messages from all valid participating nodes, verifying the signatures one by one, and extracting the key fragment hash value reported by each node. It then retrieves the saved standard hash value, calculated using the same hash algorithm based on correct key fragments and identical key synchronization identifiers. Each node's reported hash value is compared bit-by-bit with this standard hash value. Nodes with identical hash values are marked as having synchronized keys. Nodes with inconsistent hash values are immediately added to the list of nodes to be redistributed. The targeted redistribution command sent includes the list of identifiers of the nodes to be redistributed, the current round identifier, and a redistribution reason indicating key synchronization issues.
[0038] S39. The quantum key distribution center redistributes the complete quantum key fragments of this round to valid participating nodes with inconsistent hash values through a secure quantum channel. After valid participants receive and verify the integrity and legitimacy of the new quantum key fragments, they update the quantum key fragment data in their local encrypted isolation partitions, including: After receiving a targeted redistribution instruction from the global server, the quantum key distribution center verifies the instruction signature and extracts the list of nodes to be redistributed. Based on the round identifier and node identity identifier, it re-extracts the original complete quantum key fragments corresponding to these nodes. Each fragment is re-structured and encapsulated, including the round identifier, node identity identifier, newly generated timing check bits, and redistribution flag bits. For each node to be redistributed, its dedicated independent quantum channel is re-enabled. After the channel is established, the complete quantum key fragment is securely sent to the corresponding node in the form of single-photon pulses using a decoy state quantum key distribution protocol. After the quantum receiver at the receiving node completes signal detection and error correction, it obtains candidate data for a new quantum key fragment. It then checks the round identifier and redistribution flag of the new quantum key fragment to confirm that the fragment is indeed for the current round and is a legitimate redistribution operation. Next, it calculates the hash value of the combination of the new quantum key fragment and the key synchronization identifier, compares it with the standard hash value reported by the global server, and verifies its integrity and legitimacy. After successful verification, the hardware security module performs a secure erasure of the original quantum key fragment storage area in the encrypted isolation partition, and then writes the new fragment data into the same partition.
[0039] S40. After the global server confirms that the quantum key distribution status of all valid participating nodes is completely unified, it sends a local training start command carrying the latest global model parameters to all valid participating nodes. Understandably, the generated local training start command contains the latest global model parameters, which are serialized into a binary tensor stream and encrypted and protected for integrity using a global session key. The command also carries the model version number and round number, and generates a signature using the server's private key. The command is sent to all valid participating nodes via a classic communication channel to start the local training computation process on each node.
[0040] In this embodiment of the invention, the detailed implementation steps of the S4 effective participating node performing local model training and transmitting gradient parameters in blocks with encryption based on the corresponding round of quantum key fragmentation include: S41. After receiving the local training start command, the active participating node verifies the integrity of the command signature and global model parameters. If the verification is successful, it loads the local training dataset and the latest global model parameters.
[0041] S42. Execute model training according to the preset number of local training iterations, learning rate and batch size, and generate local gradient parameters for this round after training is completed; The number of local training iterations is determined by multiplying the ratio of the local dataset sample size to the batch size by the number of traversal rounds. When the local dataset of a node contains 10,000 samples and the batch size is set to 128, one traversal cycle consists of approximately 79 iterations. Setting 5 traversal cycles results in a total of 395 iterations, which is rounded up to 400 in the actual system. The initial learning rate is selected based on the loss reduction curve of the model on small batches of data during the warm-up phase, choosing the maximum learning rate that allows the loss to decrease smoothly, such as 0.01. The batch size is determined based on the GPU memory capacity, choosing a larger value while ensuring high efficiency in each iteration without causing memory overflow. 128 is a commonly used equilibrium value.
[0042] S43. Divide the local gradient parameters into multiple non-overlapping parameter blocks with fixed dimensions according to the structure of the model network layers, and assign a unique continuous index identifier to each parameter block, including: After obtaining the complete set of local gradient parameter tensors, gradient block partitioning is performed. The model structure definition file is read, which describes the parameter shape and memory layout of each layer of the network. For each trainable layer, its corresponding gradient tensor is expanded into a one-dimensional vector in row-major order, and then partitioned according to a predefined fixed block size. The fixed block size is determined based on the effective encryption length of the quantum key distribution subkey segment, for example, each parameter block contains 1024 floating-point values. The partitioning process uses a sliding window algorithm with a window step size equal to the block size, ensuring that there is no overlap between all parameter blocks and that the gradient data is completely covered. Each parameter block obtained after partitioning is assigned a unique continuous index identifier, with the index incrementing from zero.
[0043] S44. Extract the quantum key fragments for this round from the local hardware security module, divide the quantum key fragments into a corresponding number of sub-key segments according to the number of parameter blocks, and establish a mapping relationship between parameter block index identifiers and sub-key segments. Specifically, the node master processor requests the key partitioning service from the hardware security module, reads the plaintext of the quantum key fragments for this round from the encrypted isolation partition, obtains the total number P of the current parameter blocks, and divides the effective encrypted bit stream of the quantum key fragments into P segments based on this value. If the length of the quantum key fragment is not divisible by P, the remaining bits are filled into the last sub-key segment. Each sub-key segment has the same length and does not overlap with each other. The hardware security module generates a segment identifier for each sub-key segment and creates a security mapping table to map each parameter block index to a sub-key segment identifier.
[0044] S45. Employ a one-time pad encryption method, using the corresponding sub-key segment to encrypt each parameter block one by one, generating encrypted parameter blocks; simultaneously, save a local temporary backup of all plaintext parameter blocks to the temporary partition of the hardware security module; combine all encrypted parameter blocks in a randomly shuffled order with the corresponding index identifier to form a gradient encrypted data packet, sign it, and then upload it to the global server through the classic communication channel. Specifically, the parameters are processed one by one according to the parameter block index. For each parameter block, its plaintext data is a floating-point array, which is converted into a byte sequence and then passed to the encryption coprocessor of the hardware security module along with the corresponding subkey segment. A one-time pad encryption operation is used, and the subkey segment is XORed with the parameter block byte stream to generate the encrypted parameter block in ciphertext form. Since each subkey segment is only used to encrypt one parameter block and is used only once, even if a global attacker intercepts part of the ciphertext, they cannot deduce the keys of other parameter blocks. After each encryption is completed, the node also backs up a copy of the plaintext parameter block in a temporary partition of the hardware security module. This temporary partition is divided within the hardware security module, has write protection characteristics, and only allows storage and reading during the encryption process. The backup data also has a lifecycle tag.
[0045] S46. During the transmission of gradient encrypted data packets, the global server and each effective participating node monitor the status of the quantum channel and the classical communication channel in real time, focusing on monitoring the photon bit error rate of the quantum channel and the packet loss rate of the classical channel. For quantum channels, the photon count, dark count rate, and bit error rate obtained through test pulse calibration are statistically analyzed per unit time. The photon bit error rate is defined as the ratio of events where the known encoded value at the transmitting end and the measured value at the receiving end are inconsistent, without considering the dark count. This statistic is summarized into a minute-level average and periodically reported to the global server through the classical control channel. For classical communication channels, the packet loss rate is calculated in real time based on the sequence number gap and duplicate acknowledgment count of the TCP or QUIC protocol layer. The packet loss rate is defined as the proportion of data packets that have been sent but have not been acknowledged within the retransmission timeout period to the total number of packets sent.
[0046] S47. When the quantum channel photon bit error rate of any valid participating node exceeds the preset security threshold, it is determined that the subkey segment currently used by the valid participating node is at risk of leakage. The global server immediately sends a transmission interruption command to the valid participating node and records the index of the successfully received encrypted parameter block. The security threshold was obtained by conducting multiple eavesdropping simulation tests in the experimental fiber optic channel before actual deployment: using beam splitting attacks to simulate different eavesdropping intensities, recording the relationship curve between the photon bit error rate and the final security key rate, and selecting the bit error rate inflection point that reduces the security key rate to an unusable level, for example, 5%.
[0047] S48. After receiving the transmission interruption command, the active participating node terminates the transmission of the current data packet, extracts the pre-generated spare sub-key segment from the quantum key fragment of this round, and re-encrypts the plaintext parameter block corresponding to the encrypted parameter block that failed to be transmitted.
[0048] S49. After the effective participating node completes encryption using the spare subkey segment, it sends a retransmission request carrying the new index mapping relationship to the global server. After the global server confirms, the effective participating node continues to upload the re-encrypted encryption parameter block and the corresponding new index identifier.
[0049] S50: The global server monitors the packet loss rate of the classic communication channel in real time. When packet loss is detected in the gradient encryption data packets of any valid participating node, it immediately sends a packet loss retransmission command carrying the index of the lost encryption parameter block to that valid participating node.
[0050] S51. After receiving the packet loss retransmission instruction, the active participating node extracts the encrypted parameter block with the corresponding index from the local temporary backup and retransmits the encrypted parameter block to the global server; repeat the above packet loss detection and retransmission steps until all encrypted parameter blocks of the active participating node in this round have been transmitted.
[0051] In this embodiment of the invention, the specific implementation of S5 receiving and recombining all encryption gradient parameters, allocating dynamic weights based on node behavior correlation to complete global model aggregation, destroying all quantum key fragments in the current round, and generating quantum key fragments for the next round is as follows: S51. After receiving the gradient encryption data packets from all valid participating nodes and verifying the signature validity, the global server sorts and reassembles the encryption parameter blocks according to the index identifier in the gradient encryption data packets to recover the complete encrypted gradient data of each valid participating node. After receiving all encrypted parameter blocks from all participating nodes, the global server performs integrity processing on the gradient encrypted data packets sent by each node. First, it verifies the global signature of the data packet. If the signature verification fails, the node's data for this round is discarded and an anomaly is reported. After successful verification, the global server reads the index identifier attached to each encrypted parameter block and sorts the disordered encrypted parameter blocks in ascending order based on the index identifier value, forming an ordered sequence of encrypted parameter blocks. The original index identifier is used during sorting, rather than the transmission order, thus ignoring the random shuffling operation at the node end and recovering the layer-by-layer gradient ciphertext representation of the node's complete model. The global server binds this ordered ciphertext sequence with the node's identity identifier and stores it in the ciphertext gradient temporary storage area, preparing for decryption.
[0052] S52. Obtain the global complete key for this round from the quantum key distribution center, and use the global key to decrypt the encrypted gradient data of each valid participating node to obtain the plaintext gradient parameters of each valid participating node, including: The global server initiates a global complete key request to the quantum key distribution center, carrying the round identifier and a list of identities of all valid participating nodes. After verifying the server's permissions, the quantum key distribution center retrieves the main quantum key pool for that round from its secure storage and generates a global complete key that can be used to decrypt data from all nodes. The length and algorithm of this global key are functionally related to the total number of keys used for one-time pad encryption by each valid participating node, and it can completely restore all gradient parameters. After receiving the global complete key, it loads it into the hardware security module in the memory isolation area. For each valid participating node, the hardware security module uses the global complete key, combined with the identity of the valid participating node and the parameter block index, to derive the decryption key corresponding to each encrypted parameter block, and decrypts the encrypted parameter blocks one by one to restore the plaintext gradient parameters. After decryption, the temporarily stored ciphertext data is erased, and the plaintext gradient parameters are retained in secure memory.
[0053] S53. Retrieve the behavioral correlation of each effective participating node, and assign corresponding dynamic weights to the plaintext gradient parameters of different effective participating nodes according to the principle that the closer the behavioral correlation is to the normal threshold, the higher the weight. The global server reads the behavioral correlation scores of each valid participating node in the current round from the security log. The preset normal correlation threshold is 0.1, representing the most trustworthy independent participation behavior. A weight allocation algorithm is executed, based on the difference between the behavioral correlation score of each node and the normal threshold, using an inverse proportional function relationship between weight and difference to calculate the dynamic weight of each valid participating node. Specifically, the closer the behavioral correlation score of a valid participating node is to 0.1, the larger its assigned weight coefficient; the farther the correlation score deviates from 0.1, the smaller its weight coefficient, thereby suppressing the influence of potential colluding nodes on the aggregation direction. The sum of the dynamic weight coefficients assigned to each valid participating node is normalized to an integer 1, forming the node weight vector for this round. This vector is stored in secure memory and access control is applied.
[0054] S54. The plaintext gradient parameters of all valid participating nodes are aggregated and calculated using a weighted average method to obtain the global gradient update amount for this round, including: The global server processes the plaintext gradients of all valid participating nodes block by block. For each trainable parameter position in each layer of the model, it reads the gradient values of all valid participating nodes at that position and the corresponding dynamic weight coefficients, calculates the product of the gradient value of each node and the dynamic weight, and then sums all the products to obtain a weighted sum. Since the weight coefficients have been normalized, this weighted sum is the weighted average. After performing this operation on all parameter positions, a global gradient update tensor with a shape completely consistent with the global model is formed.
[0055] S55. Update the global model parameters using the global gradient update amount, generate the updated global model parameters and perform hash verification to ensure that the parameter update is correct before storing them in the global model database. Understandably, the global server multiplies the global gradient update amount obtained in the previous step by the global learning rate, then subtracts the update amount element by element from the current global model parameters, or executes a more advanced update rule based on the optimizer state to generate updated global model parameters. After the update is completed, the cryptographic hash value of the new model parameters is calculated and compared with the hash value expected to be calculated based on the model parameters before the update and the gradient update amount. If the two match, it proves that the update operation is correct. After the model parameters that have passed the hash verification are serialized, a version number and a timestamp are appended, and they are stored in a tamper-proof global model database. Every write operation to the database is recorded in the audit log.
[0056] S56. After the global model parameters are updated and verified to be correct, the global server sends an irrevocable key destruction instruction to all valid participating nodes and the quantum key distribution center. The instruction carries the destruction identifier and overwrite requirement for this round.
[0057] S57. After each valid participating node receives the destruction command and verifies its legality, it performs a preset number of overwrite destructions on all quantum key fragments, subkey segments, spare subkey segments, and temporary encrypted data generated during training stored in the local hardware security module's encrypted isolation partition. After receiving the destruction command, the active participating node verifies the command signature and confirms that the destruction identifier has not been replayed within the hardware security module. After successful verification, the hardware security module executes the overwrite destruction sequence for the logical storage units in the encrypted isolation partition that belong to this round. The overwrite process is strictly performed according to the number of times specified in the command. Each overwrite uses a combination of complementary data mode, random data mode and all-zero mode to ensure that the residual charge of the underlying floating gate transistor is completely eliminated. Among them, the complementary data mode refers to the first overwrite using a data mode that is completely opposite to the logical value of each bit of the original data. That is, the cell that originally stored 0 is written with 1, and the cell that stored 1 is written with 0. This is intended to reverse the residual charge polarity of the floating gate transistor memory cell and eliminate the charge traces of the original data. The random data mode is the second overwrite using a completely random binary sequence generated by a hardware true random number generator. This makes the final state of each memory cell unpredictable and prevents attackers from recovering the original data after a simple inversion operation through charge residue analysis. The all-zero mode means that the last overwrite writes all memory cells to a uniform logical 0 value, so that the storage medium returns to a uniform known ground state, eliminates the differential charge distribution that may remain from random writing, and provides a clean initial state for possible reuse of the memory block in the future. The overwrite targets include the main region of the quantum key fragment, all sub-key segment regions, the spare sub-key segment region, and the temporary plaintext and ciphertext backup regions generated during training; after each region is overwritten, the verification bit is read to ensure that the data is unrecoverable; after all destruction operations are completed, a signed destruction completion statement is output. The preset number of overwrites is based on the requirements for data destruction in the national information security technical standards. For example, the number of overwrites is set to 3 for secret-level data and 7 for confidential-level data.
[0058] S58. After receiving the destruction instruction and verifying its legitimacy, the quantum key distribution center overwrites and destroys all key materials for this round, and returns a destruction completion receipt with the center's signature to the global server. The total key materials include the global complete key, all quantum key fragment backups, key generation logs, and related data on entangled particle pairs. After receiving the destruction command, the quantum key distribution center verifies the command signature and permissions through an internal multi-level verification process. Upon confirmation, it locks the key material storage area, prohibiting all read and write operations. Subsequently, it performs multiple overwrite and erasure operations on the global complete key, the quantum key fragment backups corresponding to all nodes, the security log of the current key generation process, and the entangled particle pair association data table used for Bell state measurements. After the destruction operation is completed, the center generates a destruction completion receipt containing a destruction identifier and a list of destroyed resources, signs it with the center's private key, and sends it back to the global server. Upon receiving the receipt, the server declares the key material for this round completely cleared, and the relevant resources are released for use in the next round.
[0059] S59. Simultaneously, the quantum key distribution center sends a key generation instruction for the next round. Upon receiving the instruction, the quantum key distribution center generates a brand-new quantum key pool uniquely bound to the next round, and divides the quantum key pool into segments according to the updated list of valid participating nodes to prepare for the key pre-distribution of the next round. Specifically, the new quantum key pool is evenly divided according to the number of nodes in the updated list of valid participating nodes to obtain new quantum key segments. Each segment embeds the identifier and timing information of the new round and re-establishes the quantum channel binding relationship with the nodes.
[0060] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
[0061] It should be noted that all formulas in this manual are calculated by removing dimensions and taking their numerical values. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.
[0062] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
Claims
1. A federated learning training method based on quantum key distribution, characterized in that, include: S1. Complete the initialization of global training parameters and quantum security parameters, generate quantum key fragments bound to the training rounds and distribute them to the hardware security modules of each registered participating node, and enter the waiting gradient upload state after confirming the distribution is completed. S2. Obtain the gradient generation time stamp and quantum key shard hash value, and perform double verification based on the gradient generation time stamp and quantum key shard hash value to generate an initial list of legal nodes; S3. In the initial list of legitimate nodes, verify the behavioral correlation between nodes through quantum entangled Bell state measurements, generate a list of valid participating nodes, and after completing full node key synchronization, issue a local training start command, including: After the global server obtains the generated initial list of legal nodes, it uses a random number generator to generate a list of node pairs without repetition, and assigns a pair of entangled particles to each pair of initial legal nodes. One entangled particle from each pair of entangled particles is sent to the first initial legitimate node in the node pairing list via an independent quantum channel, and the other entangled particle is sent to the second initial legitimate node. At the same time, a Bell state measurement command is sent to each pair of initial legitimate nodes. After each pair of initial legitimate nodes receives the entangled particle and Bell state measurement instructions, it performs Bell state measurement on the entangled particles it holds, generates Bell state measurement data, signs it with its local private key, and then uploads it to the global server. After the global server verifies the validity of the signatures of each pair of initial legitimate nodes, it compares the Bell state measurement results of the two initial legitimate nodes and calculates the behavioral correlation between the nodes. Node pairs whose behavioral correlation exceeds the preset abnormal threshold are marked as suspicious node pairs. The initial legitimate nodes with abnormal behavior in the suspicious node pairs are located and removed. The remaining nodes are the valid participating nodes, and a list of valid participating nodes is generated. S4. Effectively participating nodes execute local model training and perform block-based encrypted transmission of gradient parameters based on the corresponding round of quantum key fragmentation; S5. Receive and reassemble all cryptographic gradient parameters, assign dynamic weights based on node behavior correlation to complete global model aggregation, destroy all quantum key fragments of this round, and generate quantum key fragments for the next round; wherein, receiving and reassembling all cryptographic gradient parameters and assigning dynamic weights based on node behavior correlation to complete global model aggregation includes: After receiving the gradient encryption data packets from all valid participating nodes and verifying the signature validity, the global server sorts and reassembles the encryption parameter blocks according to the index identifier in the gradient encryption data packets to recover the complete encrypted gradient data of each valid participating node. Obtain the global complete key for this round from the quantum key distribution center, and use the global key to decrypt the encrypted gradient data of each valid participating node to obtain the plaintext gradient parameters of each valid participating node; Retrieve the behavioral correlation of each effective participating node and assign corresponding dynamic weights to the plaintext gradient parameters of different effective participating nodes; The plaintext gradient parameters of all valid participating nodes are aggregated and calculated using a weighted average method to obtain the global gradient update amount for this round.
2. The federated learning training method based on quantum key distribution according to claim 1, characterized in that, S1 includes: The global server initializes the global model parameters of federated learning, the total number of training rounds, the single-round training time window, and the quantum security parameters, and simultaneously broadcasts the initialization completion signal and the node identity mapping table to all registered participating nodes. After receiving the initialization completion signal from the global server, the quantum key distribution center generates a quantum key pool bound to this training round and divides the key pool into quantum key fragments evenly according to the number of currently registered participating nodes. Each quantum key slice is embedded with a round identifier, the identity identifier of the corresponding registered participating node, and a time sequence check bit. The quantum key slice is then distributed to the corresponding registered participating node. After each registered participating node receives the quantum key fragment, it stores it in the encrypted isolation partition of the hardware security module, and at the same time sends a receipt confirmation acknowledgment carrying the node's signature back to the quantum key distribution center. After the quantum key distribution center collects the receipt confirmations from all registered participating nodes and verifies the validity of the signatures, it sends a key pre-distribution completion notification to the global server. The global server then starts the single-round training time window timing and enters the waiting state for node gradient uploads.
3. The federated learning training method based on quantum key distribution according to claim 1, characterized in that, S2 includes: The global server continuously listens for gradient update package upload requests from each registered participating node within a single training time window. Upon receiving a gradient update package, it immediately extracts the node identity, gradient generation time stamp, and node signature carried within the gradient update package. Based on the extracted node identity identifier, the corresponding registered participating node's quantum key fragment for this round is retrieved from the quantum key distribution center, and the timing check bit embedded in the quantum key fragment is extracted. The gradient generation time stamp is compared and verified with the time check bit to obtain the time check result; If the timing verification passes, the global server sends a key integrity verification request carrying a random challenge value to the corresponding registered participating node. The registered participating node extracts the quantum key fragment for this round from the hardware security module, calculates the hash value by combining it with the random challenge value, signs it, and returns it. After the global server verifies the validity of the node signature, it compares the returned hash value with the pre-stored standard hash value. If the two match, the registered participating node is determined to be an initial legitimate node and added to the initial legitimate node list.
4. The federated learning training method based on quantum key distribution according to claim 1, characterized in that, S3 includes: After generating the list of valid participating nodes, the global server sends a key synchronization instruction carrying the unified key synchronization identifier for this round to all valid participating nodes in the list; After receiving the key synchronization instruction, each valid participating node extracts the quantum key fragment for this round from the hardware security module, calculates the latest hash value by combining it with the key synchronization identifier, signs it, and uploads it to the global server. The global server performs consistency checks on the hash values uploaded by all valid participating nodes, filters out valid participating nodes whose hash values are inconsistent with the standard hash values, and sends targeted redistribution instructions to the quantum key distribution center. The quantum key distribution center redistributes the complete quantum key fragments of this round to valid participating nodes with inconsistent hash values through a secure quantum channel. After the valid participants receive and verify the integrity and legitimacy of the new quantum key fragments, they update the quantum key fragment data in their local encrypted isolation partitions. After the global server confirms that the quantum key distribution status of all valid participating nodes is completely unified, it sends a local training start command carrying the latest global model parameters to all valid participating nodes.
5. The federated learning training method based on quantum key distribution according to claim 1, characterized in that, S4 includes: After receiving the local training start command, the active participating node verifies the integrity of the command signature and global model parameters. If the verification is successful, it loads the local training dataset and the latest global model parameters. The model is trained according to the preset number of local training iterations, learning rate and batch size, and the local gradient parameters for this round are generated after training is completed. According to the structure of the model network layers, the local gradient parameters are divided into multiple parameter blocks, and a unique continuous index identifier is assigned to each parameter block. Extract the quantum key fragments for this round from the local hardware security module, divide the quantum key fragments into a corresponding number of sub-key segments according to the number of parameter blocks, and establish a mapping relationship between parameter block index identifiers and sub-key segments; The encryption method adopts one-time pad encryption, and each parameter block is encrypted block by block using the corresponding sub-key segment to generate encrypted parameter blocks; at the same time, a local temporary backup of all plaintext parameter blocks is saved to the temporary partition of the hardware security module; all encrypted parameter blocks are combined with the corresponding index identifier in a randomized order to form a gradient encrypted data packet, which is then signed and uploaded to the global server through the classic communication channel.
6. The federated learning training method based on quantum key distribution according to claim 5, characterized in that, The S4 also includes a quantum channel security monitoring and abnormal retransmission step during the gradient transmission process: During the transmission of gradient encrypted data packets, the global server and each participating node monitor the status of the quantum channel and the classical communication channel in real time, with a focus on monitoring the photon error rate of the quantum channel and the packet loss rate of the classical channel. When the quantum channel photon bit error rate of any valid participating node exceeds the preset security threshold, it is determined that the subkey segment currently used by the valid participating node is at risk of leakage, and the global server immediately sends a transmission interruption command to the valid participating node. After receiving a transmission interruption command, the active participating node terminates the transmission of the current data packet, extracts the pre-generated backup sub-key segment from the quantum key fragment of this round, and re-encrypts the plaintext parameter block corresponding to the encrypted parameter block that failed to be transmitted. After the active participating node completes encryption using the spare subkey segment, it sends a retransmission request carrying the new index mapping relationship to the global server. After the global server confirms, the active participating node continues to upload the re-encrypted encryption parameter block and the corresponding new index identifier.
7. The federated learning training method based on quantum key distribution according to claim 6, characterized in that, The S4 also includes the classic communication channel packet loss retransmission step in the gradient transmission process: The global server monitors the packet loss rate of the classic communication channel in real time. When it detects that a packet loss has occurred in the gradient encryption data packet of any valid participating node, it immediately sends a packet loss retransmission instruction carrying the index of the lost encryption parameter block to that valid participating node. After receiving the packet loss retransmission instruction, the active participating node extracts the corresponding indexed encrypted parameter block from the local temporary backup and retransmits the encrypted parameter block to the global server; the steps are repeated until all encrypted parameter blocks of the active participating node in this round have been transmitted.
8. The federated learning training method based on quantum key distribution according to claim 1, characterized in that, S5 includes: The global model parameters are updated using the global gradient update amount, and the updated global model parameters are generated and hashed for verification. After the global model parameters are updated and verified to be correct, the global server sends an irrevocable key destruction instruction to all valid participating nodes and the quantum key distribution center. The instruction carries the destruction identifier and the number of overwrites required for this round. After each valid participating node receives the destruction command and verifies its legality, it performs a preset number of overwrite destruction operations on all quantum key fragments, subkey segments, spare subkey segments, and temporary encrypted data generated during training stored in the encrypted isolation partition of its local hardware security module. After receiving the destruction instruction and verifying its legitimacy, the quantum key distribution center overwrites and destroys all key materials for this round, and returns a destruction completion receipt with the center's signature to the global server. At the same time, send the next round of key generation instructions to the quantum key distribution center; After receiving the instruction, the quantum key distribution center generates a brand-new quantum key pool that is uniquely bound to the next round, and divides the quantum key into fragments according to the updated list of valid participating nodes.
Citation Information
Patent Citations
Quantum key distribution side channel attack detection method based on federal deep learning
CN118784204A
Data security transmission method and device based on quantum key, equipment and medium
CN120856319A