A communication method and apparatus

CN122554077APending Publication Date: 2026-08-11HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

但是量子密钥必须在相邻的两个量子设备间产生,应用密钥可能是跨设备的

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554077A_ABST
    Figure CN122554077A_ABST
Patent Text Reader

Abstract

This application provides a communication method applied to the head node of a target path, where all nodes on the target path are quantum nodes, and the next-hop node of the head node on the target path is the first node. The head node sends a first message to the first node, the first message including first key information and first routing information. The first key information is obtained based on a business key and a first shared quantum key, which is a shared quantum key between the head node and the first node. The first routing information indicates the target path, and is used to guide the forwarding of the first message. Using this scheme, the head node uses the first shared quantum key to protect the security of the business key, thereby ensuring the security of the business key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and in particular to a communication method and apparatus. Background Technology

[0002] Quantum communication utilizes quantum microscopic effects to transmit information openly or confidentially. Quantum key distribution (QKD) leverages quantum microscopic effects to securely establish identical quantum keys unconditionally between legitimate communicating parties. Based on quantum communication principles such as the indivisibility of single quantum particles, the superposition of quantum states, and the no-cloning of quantum states, QKD possesses high security characteristics, including being unpredictable, resistant to eavesdropping, and impossible to copy.

[0003] Quantum secure communication networks are based on QKD networks and can be applied to encrypted services. Specifically, quantum keys can be combined with service keys; for example, during service key distribution, quantum keys can be used to encrypt the service keys to ensure their reliability. However, quantum keys must be generated between two adjacent quantum devices, while application keys may be generated across multiple devices.

[0004] Therefore, how to use quantum key distribution to ensure the reliability of business keys is a problem that remains to be solved. Summary of the Invention

[0005] This application provides a communication method that can utilize quantum key distribution to ensure the reliability of business keys, thereby improving the security of business key distribution.

[0006] Firstly, this application provides a communication method applied to the head node of a target path, where all nodes on the target path are quantum nodes, and the next-hop node of the head node on the target path is a first node. The head node sends a first message to the first node, the first message including first key information and first routing information. The first key information is obtained based on a service key and a first shared quantum key, which is a shared quantum key between the head node and the first node. The first routing information indicates the target path, and is used to guide the forwarding of the first message. The service key is used to securely protect service data between the head node and the tail node of the target path. Using this scheme, the head node uses the first shared quantum key to securely protect the service key, thereby ensuring the security of the service key.

[0007] In one possible implementation, the first message is an Internet Protocol Version 6 (SRv6) segment routing message. In this case, the destination address of the first message is a first SRv6 segment identifier (SID). The first SRv6 SID corresponds to the SID of the quantum connection between the first node and its next-hop node on the target path. The type of the first SRv6 SID instructs the first node to update the first key information based on the second shared quantum key corresponding to the first SRv6 SID. The second shared quantum key corresponding to the first SRv6 SID is a shared quantum key between the first node and its next-hop node on the target path. In this way, after receiving the first message, the first node can update the first key information in the first message based on the type of the first SRv6 SID and further forward the updated message, enabling the service key to be distributed to the tail node of the target path.

[0008] In one possible implementation, the type of the first SRv6 SID further instructs the first node to forward messages based on the quantum connection corresponding to the first SRv6 SID. In this way, after receiving the first message, the first node can forward a second message, updated with the first key information from the first message, through the quantum connection between the first node and its next-hop node on the target path.

[0009] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit sends the first shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit generates the first message based on the first shared quantum key and sends the first message. That is, both the generation and forwarding of the first message are performed by the forwarding plane processing unit of the head node. In this scenario, maintaining the first shared quantum key consumes some resources of the forwarding plane processing unit of the head node.

[0010] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit generates the first message based on the first shared quantum key and transmits the first message to the forwarding plane processing unit, which then sends the first message. In other words, the operation of generating the first message is performed by the head node's control plane processing unit. In this scenario, the head node's forwarding plane processing unit does not need to maintain the first shared quantum key, thus saving resources.

[0011] In one possible implementation, similar to the head node, the first node also includes a control plane processing unit and a forwarding plane processing unit. The operation of updating the first key information is performed by either the control plane processing unit or the forwarding plane processing unit of the first node. In one example, the first message also includes indication information to specify whether the operation of updating the first key information is performed by the control plane processing unit or the forwarding plane processing unit of the first node. As a concrete example, this indication information is an extended header of the first message, which instructs the control plane processing unit of the first node to update the first key information in the first message. If the first message does not include this extended header, then the first key information in the first message is updated by the forwarding plane processing unit of the first node. That is, the first message also includes an extended header that instructs the control plane processing unit of the first node to update the first key information in the first message. Using this method, some resources of the forwarding plane processing unit of the first node can be saved.

[0012] In one implementation, the extension header is a hop-by-hop (HBH) extension header. Specifically, the option type field of the HBH extension header instructs the control plane processing unit of the first node to update the first key information in the first message.

[0013] In one implementation, the first segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the first segment of routing information indicates that the node forwarding the packet based on that SRv6 SID forwards the packet based on the quantum connection corresponding to that SRv6 SID. This approach ensures that the first packet can be forwarded to the tail node through the quantum connections included in the target path.

[0014] In one implementation, the first key information is carried in the payload of the first message. In a specific example, the first key information is carried via a first Internet Control Message Protocol (ICMP) message. In other words, the payload of the first message includes a first ICMP message, and the first ICMP message includes the aforementioned first key information.

[0015] In one possible implementation, the type field of the first ICMP message is further used to indicate that the first message is a business key negotiation message. In one example, after the first node receives the first message, it determines that the first message is a key negotiation message based on the type field of the first ICMP message. Optionally, the business key negotiation message also indicates that the first node does not need to reply to the first message. Secondly, this application provides a communication method applied to intermediate nodes of a target path, where all nodes on the target path are quantum nodes. The intermediate node receives a second message sent by the intermediate node at its previous hop node on the target path. The second message includes second key information and second routing information, wherein the second key information is obtained based on a business key and a second shared quantum key, the second shared quantum key being a shared quantum key between the intermediate node and its previous hop node on the target path, and the second routing information indicating a sub-path from the intermediate node to the tail node of the target path. After receiving the second message, the intermediate node updates the second key information and the second routing information in the second message to obtain a third message and sends the third message. The third message includes third key information and third routing information. The third key information is obtained based on the business key and the third shared quantum key, which is the shared quantum key between the intermediate node and its next-hop node on the target path. The business key is recovered based on the second key information and the second quantum key. The third routing information is obtained by updating the second routing information. The business key is used to securely protect the business data between the head node and the tail node of the target path. Specifically, after receiving the second message, the intermediate node recovers the business key and processes it using the shared quantum key between itself and its next-hop node on the target path to obtain the third key information. It then sends a third message including the third key information. Using this scheme, the intermediate node uses the third shared quantum key to protect the security of the business key, thereby ensuring the security of the business key.

[0016] In one possible implementation, the destination address of the second message is a second SRv6 SID, which is the SID corresponding to the quantum connection between the intermediate node and the next-hop node of the intermediate node on the target path; the type of the second SRv6 SID indicates that the intermediate node updates the second key information according to the third shared quantum key corresponding to the second SRv6 SID.

[0017] In one possible implementation, the type of the second SRv6 SID also indicates that the intermediate node forwards messages based on the quantum connection corresponding to the second SRv6 SID.

[0018] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the third shared quantum key and the second shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key and the second message, and to send the third message.

[0019] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key, and the second message, and to pass the third message to the forwarding plane processing unit, which then sends the third message.

[0020] In one possible implementation, the second message further includes an extension header that instructs the control plane processing unit of the intermediate node to update the second key information in the second message to obtain the third message.

[0021] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the intermediate node to update the second key information in the second message.

[0022] In one possible implementation, the second segment of routing information includes at least one SRv6 SID corresponding to a quantum connection, and the type of each SRv6 SID corresponding to a quantum connection included in the second segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0023] In one possible implementation, the payload of the second message includes a second Internet Control Message Protocol (ICMP) message, which includes the second key information.

[0024] In one possible implementation, the type field of the second ICMP message indicates that the second message is a business key negotiation message.

[0025] In one possible implementation, if the next-hop node of the intermediate node on the target path is the tail node of the target path, then the destination address of the third message is the third SRv6 SID, the third SRv6 SID indicates the tail node, and the first segment information in the third segment routing information is the third SRv6 SID. In this scenario, the type of the third SRv6 SID indicates that the tail node obtains the service key based on the third key information and the third shared quantum key. That is, after receiving the third message, the tail node determines that the destination address is its own SRv6 SID, and recovers the service key based on the type of the third SRv6 SID, using the third shared quantum key and the third key information.

[0026] Thirdly, this application provides a communication method applied to the tail node of a target path, where all nodes on the target path are quantum nodes. The tail node receives a fourth message sent by its predecessor node on the target path. This fourth message includes fourth key information and fourth segment routing information. The destination address of the fourth message indicates the tail node, and the first segment of the fourth segment routing information is the destination address. In other words, forwarding based on the fourth segment routing terminates at the tail node; that is, the tail node of the target path is the endpoint of forwarding based on the fourth segment routing. The fourth key information is obtained based on a service key and a fourth shared quantum key, which is a shared quantum key between the tail node and its predecessor node on the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path. After receiving the fourth message, the tail node obtains the service key based on the fourth key information and the fourth shared quantum key. Therefore, it can be seen that by using this scheme, the tail node uses the fourth shared quantum key to ensure the security of the business key at the previous hop node of the target path, and the tail node recovers the business key based on the fourth shared quantum key, thereby ensuring the security of business key distribution.

[0027] In one possible implementation, the destination address of the fourth message is a fourth SRv6 SID, and the type of the fourth SRv6 SID indicates that the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

[0028] In one possible implementation, the tail node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the fourth shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0029] In one possible implementation, the intermediate node includes a control plane processing unit, which is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0030] In one possible implementation, the fourth message further includes an extension header that instructs the control plane processing unit of the tail node to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0031] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header indicates that the control plane processing unit of the tail node obtains the service key based on the fourth shared quantum key and the fourth key information.

[0032] In one possible implementation, the fourth segment of routing information includes at least one SRv6 SID corresponding to a quantum connection. The type of each SRv6 SID corresponding to a quantum connection included in the fourth segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0033] In one possible implementation, the payload of the fourth message includes a third Internet Control Message Protocol (ICMP) message, which includes the fourth key information.

[0034] In one possible implementation, the type field of the third ICMP message indicates that the fourth message is a service key negotiation message.

[0035] Fourthly, this application provides a communication device applied to the head node of a target path, wherein all nodes on the target path are quantum nodes. The device includes: a sending unit, configured to send a first message to a first node, the first message including first key information and first segment routing information, the first key information being obtained based on a service key and a first shared quantum key, the first shared quantum key being a shared quantum key between the head node and the first node, the first segment routing information indicating the target path, the first node being the next-hop node of the head node on the target path, and the service key being used to securely protect service data between the head node and the tail node of the target path.

[0036] In one possible implementation, the destination address of the first message is a first SRv6 SID, which is the SID corresponding to the quantum connection between the first node and the next-hop node of the first node on the target path; the type of the first SRv6 SID indicates that the first node updates the first key information according to the second shared quantum key corresponding to the first SRv6 SID.

[0037] In one possible implementation, the type of the first SRv6 SID also indicates that the first node forwards messages based on the quantum connection corresponding to the first SRv6 SID.

[0038] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the first shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit is used to generate the first message based on the first shared quantum key and send the first message.

[0039] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit generates the first message based on the first shared quantum key and passes the first message to the forwarding plane processing unit, which then sends the first message.

[0040] In one possible implementation, the first message further includes an extension header that instructs the control plane processing unit of the first node to update the first key information in the first message.

[0041] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the first node to update the first key information in the first message.

[0042] In one possible implementation, the first segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the first segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0043] In one possible implementation, the payload of the first message includes a first Internet Control Message Protocol (ICMP) message, which includes the first key information.

[0044] In one possible implementation, the type field of the first ICMP message indicates that the first message is a business key negotiation message.

[0045] Fifthly, this application provides a communication device applied to an intermediate node of a target path, wherein all nodes on the target path are quantum nodes. The device includes: a receiving unit, configured to receive a second message sent by the intermediate node to its previous hop node on the target path. The second message includes second key information and second routing information. The second key information is obtained based on a business key and a second shared quantum key. The second shared quantum key is a shared quantum key between the intermediate node and its previous hop node on the target path. The second routing information indicates a sub-path in the target path from the intermediate node to the tail node of the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path; the processing unit is used to obtain a third message based on the second message, the third message including third key information and third segment routing information, the third key information being obtained based on the service key and a third shared quantum key, the third shared quantum key being a shared quantum key between the intermediate node and its next-hop node on the target path, the service key being recovered based on the second key information and the second quantum key, and the third segment routing information being obtained by updating the second segment routing information; the sending unit is used to send the third message.

[0046] In one possible implementation, the destination address of the second message is a second SRv6 SID, which is the SID corresponding to the quantum connection between the intermediate node and the next-hop node of the intermediate node on the target path; the type of the second SRv6 SID indicates that the intermediate node updates the second key information according to the third shared quantum key corresponding to the second SRv6 SID.

[0047] In one possible implementation, the type of the second SRv6 SID also indicates that the intermediate node forwards messages based on the quantum connection corresponding to the second SRv6 SID.

[0048] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the third shared quantum key and the second shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key and the second message, and to send the third message.

[0049] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key, and the second message, and to pass the third message to the forwarding plane processing unit, which then sends the third message.

[0050] In one possible implementation, the second message further includes an extension header that instructs the control plane processing unit of the intermediate node to update the second key information in the second message to obtain the third message.

[0051] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the intermediate node to update the second key information in the second message.

[0052] In one possible implementation, the second segment of routing information includes at least one SRv6 SID corresponding to a quantum connection, and the type of each SRv6 SID corresponding to a quantum connection included in the second segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0053] In one possible implementation, the payload of the second message includes a second Internet Control Message Protocol (ICMP) message, which includes the second key information.

[0054] In one possible implementation, the type field of the second ICMP message indicates that the second message is a business key negotiation message.

[0055] In one possible implementation, the destination address of the third message is a third SRv6 SID, the third SRv6 SID indicates the tail node, the first segment information in the third segment routing information is the third SRv6 SID, and the third SRv6 SID indicates that the tail node obtains the service key based on the third key information and the third shared quantum key.

[0056] Sixthly, this application provides a communication device applied to a tail node of a target path, wherein all nodes on the target path are quantum nodes. The device includes: a receiving unit, configured to receive a fourth message sent by the tail node to the previous hop node of the target path, the fourth message including fourth key information and fourth segment routing information, the destination address of the fourth message indicating the tail node, the first segment information in the fourth segment routing information being the destination address, the fourth key information being obtained based on a service key and a fourth shared quantum key, the fourth shared quantum key being a shared quantum key between the tail node and the previous hop node of the tail node on the target path, and the service key being used to securely protect service data between the head node and the tail node of the target path; and a processing unit, configured to obtain the service key based on the fourth key information and the fourth shared quantum key.

[0057] In one possible implementation, the destination address of the fourth message is a fourth SRv6 SID, and the type of the fourth SRv6 SID indicates that the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

[0058] In one possible implementation, the tail node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the fourth shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0059] In one possible implementation, the intermediate node includes a control plane processing unit, which is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0060] In one possible implementation, the fourth message further includes an extension header that instructs the control plane processing unit of the tail node to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0061] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header indicates that the control plane processing unit of the tail node obtains the service key based on the fourth shared quantum key and the fourth key information.

[0062] In one possible implementation, the fourth segment of routing information includes at least one SRv6 SID corresponding to a quantum connection. The type of each SRv6 SID corresponding to a quantum connection included in the fourth segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0063] In one possible implementation, the payload of the fourth message includes a third Internet Control Message Protocol (ICMP) message, which includes the fourth key information.

[0064] In one possible implementation, the type field of the third ICMP message indicates that the fourth message is a service key negotiation message.

[0065] In a seventh aspect, this application provides an apparatus. The apparatus includes a processor and a memory. The memory is used to store instructions or computer programs. The processor is used to execute the instructions or computer program in the memory to perform the methods described in the first aspect and any one of the first aspects above. Alternatively, the processor is used to execute the instructions or computer program in the memory to perform the methods described in the second aspect and any one of the second aspects above; or, the processor is used to execute the instructions or computer program in the memory to perform the methods described in the third aspect and any one of the third aspects above.

[0066] Eighthly, this application provides a computer-readable storage medium including instructions or a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and any one of the first aspects above, or causes the computer to perform the methods described in the second aspect and any one of the second aspects above, or causes the computer to perform the methods described in the third aspect and any one of the third aspects above.

[0067] Ninthly, this application provides a computer program product comprising instructions or a computer program, which, when run on a computer, causes the computer to perform the method described in any one of the first aspects above, or causes the computer to perform the method described in the second aspect above and any one of the second aspects above, or causes the computer to perform the method described in the third aspect above and any one of the third aspects above.

[0068] In a tenth aspect, this application provides a communication system comprising at least two of the following: a head node of a target path, an intermediate node of a target path, or a tail node of a target path, wherein the head node of the target path is used to perform the method described in the first aspect above and any one of the first aspects above, the intermediate node of the target path is used to perform the method described in the second aspect above and any one of the second aspects above, and the tail node of the target path is used to perform the method described in the third aspect above and any one of the third aspects above. Attached Figure Description

[0069] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0070] Figure 1a This is a schematic diagram of an application scenario provided by an embodiment of this application;

[0071] Figure 1b This is a schematic diagram illustrating another application scenario provided by an embodiment of this application;

[0072] Figure 2 A flowchart illustrating a communication method provided in the application embodiment;

[0073] Figure 3 A flowchart illustrating another communication method provided in the application embodiment;

[0074] Figure 4 A flowchart illustrating another communication method provided in the application embodiment;

[0075] Figure 5a This is a schematic diagram of the structure of a first ICMP message provided in an embodiment of this application;

[0076] Figure 5b This is a schematic diagram of the structure of an HBH extension head provided in an embodiment of this application;

[0077] Figure 6a This is a schematic diagram of a communication method provided in an embodiment of this application;

[0078] Figure 6b A schematic diagram illustrating another communication method provided in this application embodiment;

[0079] Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0080] Figure 8 This is a schematic diagram of the structure of a device provided in an embodiment of this application. Detailed Implementation

[0081] Before introducing the communication method provided in this application, we will first introduce an exemplary application scenario of this application.

[0082] See Figure 1a , Figure 1a This is a schematic diagram of an application scenario provided by an embodiment of this application.

[0083] Figure 1a The network 100 shown includes multiple network devices, including quantum devices and non-quantum devices. Quantum devices are those capable of quantum key generation, or those that include a QKD board. Non-quantum devices are those that do not have quantum key generation capabilities and do not have a QKD board.

[0084] like Figure 1a As shown, Figure 1a The network shown includes two types of connections: classical links and quantum links. Classical links are... Figure 1a The solid line represents a classic connection, also known as a traditional connection, which refers to a connection between two network devices that have a connection relationship. Quantum connections... Figure 1a The dotted lines represent quantum connectivity, which refers to the connection between quantum devices. Quantum connectivity and classical connectivity can overlap or be independent; this application does not impose specific limitations. For example, as... Figure 1a As shown, the classical and quantum connections between quantum device 3 and quantum device 4 overlap, while... Figure 1a Other quantum connections are independent of other classical connections.

[0085] In one example Figure 1a The network 100 shown also has a corresponding controller, such as Figure 1b As shown, the controller is used to control or manage network devices in network 100. For example, the controller can collect the network topology of network 100 and send control or management signaling to the network devices in network 100 to control or manage the network devices in network 100.

[0086] The controller mentioned in the embodiments of this application is a functional module that implements control and / or management functions, or a physical entity that runs the relevant functional module. The physical entity may be, for example, a server with relevant software installed, which is used to implement the controller's functions. Alternatively, the physical entity may be a device running a network management system (NMS).

[0087] In some scenarios, Figure 1b The controller in the network is called the path calculation element (PCE), and the network device in the network 100 is called the path calculation client (PCC).

[0088] Currently, two quantum devices with quantum connectivity can establish the same quantum key. This shared quantum key between the two quantum devices is also known as the shared quantum key between them. For example, in... Figure 1a and Figure 1b In the scenario shown, quantum device 1 and quantum device 2 can establish the same quantum key. This shared quantum key between quantum device 1 and quantum device 2 is called the shared quantum key between quantum device 1 and quantum device 2. Similarly, quantum device 2 and quantum device 3 can establish the same quantum key. This shared quantum key between quantum device 2 and quantum device 3 is called the shared quantum key between quantum device 2 and quantum device 3. Furthermore, quantum device 3 and quantum device 4 can establish the same quantum key. This shared quantum key between quantum device 3 and quantum device 4 is called the shared quantum key between quantum device 3 and quantum device 4.

[0089] Because quantum keys offer extremely high security, combining them with business keys can effectively guarantee the security of the business keys. Business keys refer to the keys used to securely protect business data. Business keys include, but are not limited to, encryption keys and integrity calculation keys.

[0090] However, quantum keys must be generated between two adjacent quantum devices, or in other words, between two adjacent quantum devices that are quantum connected. For example, in Figure 1a and Figure 1b In the scenario shown, quantum device 1 and quantum device 3 are connected by quantum device 2, meaning that quantum device 1 and quantum device 3 cannot generate the same quantum key. However, application keys can be cross-device. For example, in... Figure 1a and Figure 1b In the scenario shown, quantum device 1 and quantum device 4 are able to establish the same business key.

[0091] How to combine business keys that can be generated across devices with quantum keys that can only be generated between adjacent quantum devices is a problem that remains to be solved.

[0092] In view of this, this application provides a communication method that can use quantum keys to ensure the reliability of business keys, thereby improving the security of business key distribution.

[0093] See Figures 2 to 4 , Figures 2 to 4 The flowcharts for the three communication methods provided in the embodiments of the application are shown. Wherein:

[0094] Figure 2 The method shown is executed by the head node of the target path. Figure 3 The method shown is executed by intermediate nodes of the target path. Figure 4 The method shown is executed by the tail node of the target path. Figures 2 to 4 The method shown is used to distribute the business key from the head node of the target path to the tail node of the target path. Wherein:

[0095] All nodes on the target path are quantum nodes. In one example, the target path is calculated by the head node of the target path based on the business key distribution request and the QKD topology of the target network. In another example, the target path is calculated by the controller based on the business key distribution request and the QKD topology of the target network. After calculating the target path, the controller sends the target path to the head node of the target path, and the head node stores the received target path. All nodes on the target path are nodes in the target network. In one example, the target network corresponds to... Figure 1a or Figure 1b In network 100, the target path is: Quantum Device 1 → Quantum Device 2 → Quantum Device 3 → Quantum Device 4. Quantum Device 1 is the head node of the target path, and Quantum Device 4 is the tail node of the target path.

[0096] A business key distribution request includes at least the address of the source device and the address of the destination device for business key distribution. The source device is the head node of the aforementioned target path, and the destination device is the tail node of the aforementioned target path. In addition to the addresses of the source and destination devices, the business key distribution request also includes other information, such as path constraints. These path constraints indicate the conditions that the path used for business key distribution must meet. This application does not specifically limit the path constraints. As an example, the path constraints may be related to the distribution frequency of the business key. In this scenario, to ensure the security of the business key, the quantum devices on the business key distribution path need to possess sufficient quantum keys to guarantee the security of the business key. In this scenario:

[0097] In one example, the path constraint includes the quantum key generation rate of the quantum devices included on the path of business key distribution. For instance, the path constraint includes the minimum quantum key generation rate of the quantum devices included on the path of business key distribution. The minimum quantum key generation rate is greater than the distribution frequency of the business key.

[0098] In another example, the path constraint includes the quantum key reserve of the quantum devices included in the path of the business key distribution. For example, the path constraint includes the minimum quantum key reserve of the quantum devices included in the path of the business key distribution. The minimum quantum key reserve is greater than a certain threshold to ensure that the quantum devices have sufficient quantum keys to guarantee the security of the business key.

[0099] In another example, the path constraint includes the physical distance between adjacent quantum devices on the path of the business key distribution. The path constraint also includes the maximum physical distance between adjacent quantum devices on the path of the business key distribution. The physical distance between adjacent quantum devices can be mapped to the quantum key reserve of the quantum devices. In one example, the maximum physical distance is, for example, less than a certain distance, thereby ensuring that the quantum devices have sufficient quantum keys to guarantee the security of the business key.

[0100] As another example, the path constraint is not related to the frequency of service key distribution, but to the devices through which the service key distribution passes. For example, the path constraint includes devices that the service key distribution must pass through, or devices that the service key distribution needs to bypass, etc., which will not be described in detail here.

[0101] As another example, the service key distribution request includes a service identifier to indicate the service corresponding to the service key distribution request. This application embodiment does not specifically limit the service identifier; the service identifier may be, for example, a service number or other identifier.

[0102] In this application, the QKD topology of the target network includes the connectivity between quantum devices in the target network and the QKD capabilities of the quantum devices in the target network. The connectivity between quantum devices in the target network indicates which quantum devices have quantum connections. The QKD capabilities of the quantum devices are capabilities related to quantum key distribution.

[0103] Regarding the QKD capability of quantum devices, we will now illustrate it using the QKD capability of the first quantum device in the target network as an example. The first and second quantum devices are connected via a quantum connection. In one example, the QKD capability of the first quantum device includes one or more of the following: whether the first quantum device can generate a quantum key, the quantum key generation rate of the first quantum device, the quantum key reserve of the first quantum device, the identifier of the quantum connection between the first and second quantum devices, the connection status of the quantum connection between the first and second quantum devices, or the physical distance between the first and second quantum devices.

[0104] in:

[0105] An identifier for the quantum connection between the first quantum device and the second quantum device. As an example, this identifier might be the identifier of the port used by the first quantum device to connect to the second quantum device. As another example, this identifier might be the identifier assigned by the first quantum device to the quantum connection. As a specific example, the first quantum device assigns an SRv6 SID to the quantum connection; in this scenario, the identifier of the quantum connection is the SRv6 SID assigned by the first quantum device. In the scenario where the first quantum device assigns an SRv6 SID to the quantum connection, a new type is also defined for this SRv6 SID. This new type is used to indicate that forwarding based on this SRv6 SID requires forwarding through the quantum connection. In other words, the type of the SRv6 SID indicates that forwarding based on this SRv6 SID requires forwarding through the quantum connection. Specifically, when forwarding based on this SRv6 SID, the first quantum device first determines the quantum connection corresponding to the SRv6 SID, and then forwards the connection based on the quantum connection corresponding to the SRv6 SID. This application does not specifically limit the type corresponding to the aforementioned SRv6 SID. The type corresponding to the SRv6 SID may be, for example, Endpoint Key Management (END.KM).

[0106] The state of the quantum connection between the first quantum device and the second quantum device includes a normal state and an abnormal state. The normal state is also known as a successful connection (link up), and the abnormal state is also known as a broken connection (link down).

[0107] Next, in turn... Figures 2 to 4 The method shown will be introduced.

[0108] Figure 2 The method shown includes the following steps S101-S102.

[0109] S101: The head node of the target path generates a first message, which includes first key information and first segment routing information. The first key information is obtained based on the business key and the first shared quantum key. The first shared quantum key is the shared quantum key between the head node and the first node. The first segment routing information indicates the target path. The first node is the next-hop node of the head node on the target path.

[0110] S102: The head node of the target path sends the first message to the first node.

[0111] In this application, the next hop node of the head node on the target path is the first node. The head node and the first node can generate the same quantum key, wherein the shared key generated by the head node and the first node is the first shared quantum key.

[0112] The head node uses the first shared quantum key to calculate the service key, obtaining the first key information. For example, the head node employs a specific calculation method to calculate the service key based on the first shared quantum key, thereby obtaining the first key information. This application embodiment does not specifically limit the calculation method; such a method is, for example, an XOR algorithm, i.e., performing an XOR calculation on the service key and the first shared quantum key to obtain the first key information. The head node uses the first shared quantum key to protect the security of the service key, thereby ensuring the security of the service key.

[0113] In this application, the first message includes not only the first key information, but also the first segment of routing information. The first segment of routing information indicates the target path. That is, after receiving the first message, the forwarding node forwards the first message based on the first segment of routing information, so that the first message can be forwarded to the tail node of the target path through the target path.

[0114] In one example, all devices on the target path support Segment Routing Multi-Protocol Label Switching (SR MPLS), and in this scenario, the first packet is an SR-MPLS packet. Correspondingly, the first segment routing information in the first packet is the MPLS label stack of the first packet.

[0115] In another example, all devices on the target path support SRv6; in this scenario, the first packet is an SRv6 packet. Regarding SRv6, it should be noted that:

[0116] SRv6 is a protocol designed based on source routing principles for forwarding IPv6 packets over a network. SRv6 achieves hop-by-hop forwarding by inserting a segment routing header (SRH) into IPv6 packets. The SRH includes an offset address stack and an explicit IPv6 address stack. Intermediate nodes continuously update the destination address and offset address stack to perform hop-by-hop forwarding. The explicit IPv6 address stack corresponds to the segment identifier list in the SRH (also known as the segment list), and the offset address stack corresponds to the segment left (SL) in the SRH.

[0117] In SRv6, the element used for forwarding is the SRv6 segment. An SRv6 segment is in IPv6 address form and is often referred to as an SRv6 segment identifier (SID). An SRv6 SID consists of two parts: a locator and a function. The format of an SRv6 SID is Locator:Function, where the locator occupies the high-order bits of the IPv6 address, and the function occupies the remaining bits.

[0118] The Locator has routing capabilities, so it must generally be unique within the SR domain. Other nodes in the network can locate this device through the Locator network segment route, and all SRv6 SIDs advertised by this device can also be reached through this Locator network segment route. The Function represents the device's instructions, which are all pre-defined by the device. The Function section is used to instruct the device that generated the SRv6 SID to perform the corresponding functional operations.

[0119] The Function section can also be divided into an optional Arguments section. In this case, the SRv6 SID is represented in the format of Locator:Function:Arguments. Arguments occupy the low bits of the IPv6 address. Information such as packet flow and services can be defined through the Arguments field.

[0120] In scenarios where the first message is an SRv6 message, the first segment routing information in the first message is an SRH. This SRH includes a segment identifier list, often simply referred to as a segment list, which contains multiple SRv6 SIDs. In this application, the segment list of the first message includes at least one SRv6 SID corresponding to a quantum connection. For example: assuming the head node of the target path corresponds to... Figure 1a Quantum device 1 in the target path corresponds to the tail node. Figure 1a The quantum device 4 shown has a target path of: quantum device 1 → quantum device 2 → quantum device 3 → quantum device 4. Therefore, the segment list of the first packet includes: SRv6 SID1 corresponding to the quantum connection between quantum device 1 and quantum device 2, SRv6 SID2 corresponding to the quantum connection between quantum device 2 and quantum device 3, and SRv6 SID3 corresponding to the quantum connection between quantum device 3 and quantum device 4. In addition, the segment list of the first packet also includes the SRv6 SID of the tail node to indicate the tail node for SRv6 forwarding.

[0121] For any SRv6 SID corresponding to a quantum connection included in the segment list of the first message, the type of the SRv6 SID indicates that forwarding based on that SRv6 SID requires traversing through a quantum connection. Specifically, when quantum device 1 forwards based on SRv6 SID1, it is a quantum device forwarding between quantum device 1 and quantum device 2; when quantum device 2 forwards based on SRv6 SID2, it is a quantum device forwarding between quantum device 2 and quantum device 3; and when quantum device 3 forwards based on SRv6 SID3, it is a quantum device forwarding between quantum device 3 and quantum device 4. Thus, the first message is sent to quantum device 4 via the target path.

[0122] In the scenario where the first message is an SRv6 message, the destination address of the first message is the first SRv6 SID, where the first SRv6 SID is the SID corresponding to the quantum connection between the first node and its next-hop node on the target path. In this application, the first SRv6 SID is used to instruct the first node to update the first key information according to the second shared quantum key corresponding to the first SRv6 SID. As a specific example, the type of the first SRv6 SID instructs the first node to update the first key information according to the second shared quantum key corresponding to the first SRv6 SID. After receiving the first message, the first node determines that the destination address of the first message is its own corresponding SID (specifically, the SRv6 SID assigned to itself and its next-hop node on the target path). Therefore, the first node updates the first key information according to the type of the first SRv6 SID and the second shared quantum key corresponding to the first SRv6 SID, thus obtaining the second key information. Specifically, the first node first uses the first shared quantum key and the first key information to recover the business key. Then, the first node uses the second shared quantum key and the recovered business key to obtain the second key information. For example, the first node first performs an XOR operation on the first shared quantum key and the first key information to obtain the business key. Then, it performs an XOR operation on the business key and the second shared quantum key to obtain the second key information.

[0123] As described above, the first segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the first segment of routing information indicates that forwarding based on the SRv6 SID requires forwarding through a quantum connection. In other words, for any SRv6 SID corresponding to a quantum connection included in the first segment of routing information, that SRv6 SID indicates that the node forwarding the packet based on that SRv6 SID should forward the packet based on the quantum connection corresponding to that SRv6 SID. The first SRv6 SID is the SRv6 SID corresponding to one of the quantum connections included in the first segment of routing information; therefore, the type of the first SRv6 SID can also indicate that the first node should forward the packet based on the quantum connection corresponding to the first SRv6 SID. Specifically, the first node forwards the aforementioned second packet based on the quantum connection corresponding to the first SRv6 SID.

[0124] In this application, the first key information is carried in the payload of the first message. The embodiments of this application do not specifically limit the carrier of the first key information. In a specific example, the first key information is carried in a first ICMP message. In other words, the payload of the first message includes a first ICMP message, and the first ICMP message includes the aforementioned first key information. The structure of the first ICMP message can be understood with reference to Figure 5. Figure 5a This is a schematic diagram illustrating the structure of a first ICMP message provided in an embodiment of this application. Figure 5a As shown, the first ICMP message includes: a type field, a code field, a checksum field, and a message body field. The message body field carries the aforementioned first key information.

[0125] The type field indicates that the message is an ICMP message, or the type field and the code field together indicate that the message is an ICMP message.

[0126] The checksum field is a checksum of three fields: type field, code field, and message body field.

[0127] In one example, the type field of the first ICMP message indicates that the first message is a service key negotiation message. In another example, after the first node receives the first message, it determines that the first message is a key negotiation message based on the type field of the first ICMP message. Optionally, the service key negotiation message also indicates that the first node does not need to reply to the first message.

[0128] In another example, the first key information is carried via a first Transmission Control Protocol (TCP) message. In other words, the payload of the first message includes a first TCP message, which contains the aforementioned first key information.

[0129] In one example, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is, for example, a central processing unit (CPU), a field-programmable gate array (FPGA), a network processor (NP), or an artificial intelligence chip. The forwarding plane processing unit is a forwarding chip, which may be, for example, an NP-architecture chip or a pipelined architecture chip. In some scenarios, the forwarding plane processing unit may also be referred to as the data plane processing unit.

[0130] In one example, the first shared quantum key is negotiated between the control plane processing unit of the head node and the control plane processing unit of the first node; that is, the first shared quantum key is managed by the control plane processing unit of the head node. In another example, the control plane processing unit of the head node sends the first shared quantum key to the forwarding plane processing unit of the head node, which then generates and sends the first message based on the first shared quantum key.

[0131] In another example, the control plane processing unit of the head node does not send the first shared quantum key to the forwarding plane processing unit of the head node to save the resources of the forwarding plane processing unit. In this scenario, the control plane processing unit of the head node generates the first message based on the first shared quantum key. After generating the first message, the control plane processing unit of the head node sends the first message to the forwarding plane processing unit of the head node, which then sends the first message to the first node.

[0132] As previously described, the type of the first SRv6 SID indicates that the first node updates the first key information based on the second shared quantum key corresponding to the first SRv6 SID. Similar to the head node, the first node also includes a control plane processing unit and a forwarding plane processing unit. The operation of updating the first key information is performed by either the control plane processing unit or the forwarding plane processing unit of the first node. In one example, the first message also includes indication information to indicate whether the operation of updating the first key information is performed by either the control plane processing unit or the forwarding plane processing unit of the first node. As a specific example, this indication information is an extended header of the first message, which instructs the control plane processing unit of the first node to update the first key information in the first message. If the first message does not include this extended header, then the first key information in the first message is updated by the forwarding plane processing unit of the first node.

[0133] In one example, considering that each SRv6 node on the forwarding path can parse the HBH extension header during SRv6-based forwarding, the extension header is an HBH extension header in the scenario where the first packet is an SRv6 packet. As an example, a specific field in the HBH extension header instructs the control plane processing unit of the first node to update the first key information in the first packet. This specific field can be any available field in the HBH extension header. In a specific example, the structure of the HBH extension header is as follows: Figure 5b As shown, Figure 5b This is a schematic diagram of the structure of an HBH extension head provided in an embodiment of this application. Figure 5bAs shown: The HBH extended header includes: Next Header field, Extended Header Length (Hdr Ext Len) field, Option Type field, and Option Data Length (OptionDataLen) field. Among them:

[0134] The Next Header indicates the type of the next header; in one example, the type of the next header is SRH.

[0135] Hdr Ext Len indicates the length of the current message header (i.e., the HBH extension header).

[0136] Option Type: This field specifies the option type. If the receiving node does not recognize this header, it will discard the message. In one example, the Option Type field instructs the control plane processing unit of the first node to update the first key information in the first message. For instance, the first two bits of Option Type are defined as 01 to instruct the control plane processing unit of the first node to update the first key information in the first message.

[0137] OptionDataLen: The length of the option data. In one example, the option data is not included in the HBH extension header, so the value of OptionDataLen is 0.

[0138] Next, for Figure 3 The method shown will be introduced. Figure 3 The method shown includes the following steps S201-S203.

[0139] In this application, any intermediate node on the target path is executed. Figure 3 As shown in S201-S203, the message is sent to the tail node of the target path.

[0140] S201: An intermediate node of the target path receives a second message sent by the intermediate node to the previous hop node of the target path. The second message includes second key information and second routing information. The second key information is obtained based on a business key and a second shared quantum key. The second shared quantum key is a shared quantum key between the intermediate node and the previous hop node of the intermediate node on the target path. The second routing information indicates a sub-path in the target path from the intermediate node to the tail node of the target path.

[0141] In one example, if the intermediate node is the aforementioned first node, then the second message is the aforementioned first message, and correspondingly, the second key information is the aforementioned first key information, and the second segment routing information is the aforementioned first segment routing information.

[0142] In another example, if the intermediate node is not the aforementioned first node, then the second message is the message obtained after the aforementioned first message has been forwarded by at least one node; that is, the second message is an updated version of the first message. Assume that there are N quantum nodes between the intermediate node and the head node, and these N quantum nodes are all quantum nodes on the target path. Then, the second message is obtained by updating the first message N times, where each of these N quantum nodes updates the message it receives. The principle of each quantum node updating the received message is the same as described in S202 and will not be described in detail here.

[0143] In scenarios where the intermediate node is not the first node, the following should be noted regarding the second segment of routing information:

[0144] The second segment of routing information is largely the same as the first segment. Specifically, the segment list in the second segment is identical to that in the first segment; the main difference lies in the value of the SL field. The value of the SL field in the second segment is less than the value of the SL field in the first segment.

[0145] In this application, intermediate nodes and their upstream nodes on the target path can generate the same quantum key. The shared key generated between an intermediate node and its upstream node on the target path is called a second shared quantum key. In the scenario where the intermediate node is the aforementioned first node, the second shared quantum key is the same as the aforementioned first shared quantum key.

[0146] The intermediate node's upstream node on the target path uses the second shared quantum key to calculate the service key, obtaining the second key information. The principle behind this calculation is the same as the head node's calculation using the first shared quantum key; refer to the previous description of the head node's calculation using the first shared quantum key, which will not be repeated here. The intermediate node's upstream node on the target path uses the second shared quantum key to protect the security of the service key, thus ensuring its security.

[0147] Similar to the first message, the second message is an SRv6 message or an SR-MPLS message.

[0148] In the scenario where the second message is an SRv6 message, for any SRv6 SID corresponding to a quantum connection included in the segment list of the second message, the type corresponding to the SRv6 SID is used to indicate that when forwarding based on the SRv6 SID, it needs to be forwarded through a quantum connection.

[0149] In the scenario where the second message is an SRv6 message, the destination address of the second message is the second SRv6 SID. The second SRv6 SID is the SID corresponding to the quantum connection between the intermediate node and its next-hop node on the target path. In the scenario where the intermediate node is the aforementioned first node, the second SRv6 SID is the same as the aforementioned first SRv6 SID. In this application, the second SRv6 SID is used to instruct the intermediate node to update the second key information based on the third shared quantum key corresponding to the second SRv6 SID. As a specific example, the type of the second SRv6 SID instructs the intermediate node to update the second key information based on the third shared quantum key corresponding to the second SRv6 SID.

[0150] As described above, the second segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the second segment of routing information indicates that forwarding based on the SRv6 SID requires forwarding through a quantum connection. The second SRv6 SID is the SRv6 SID corresponding to one of the quantum connections included in the second segment of routing information. Therefore, the type of the second SRv6 SID can also instruct the intermediate node to forward packets based on the quantum connection corresponding to the second SRv6 SID. Specifically, the intermediate node forwards the third packet updated from the second packet based on the quantum connection corresponding to the second SRv6 SID. Regarding the third packet, refer to the relevant description in S202; it will not be described in detail here.

[0151] In this application, the second key information is carried in the payload of the second message. Similar to how the first key information is carried in the first message, in a specific example, the second key information is carried in a second ICMP message. In other words, the payload of the second message includes a second ICMP message, and the second ICMP message includes the aforementioned second key information. Regarding the structure of the second ICMP message, refer to the description of the structure of the first ICMP message above, and it will not be repeated here.

[0152] In one example, similar to the first ICMP message, the type field of the second ICMP message indicates that the second message is a service key negotiation message. In another example, after the intermediate node receives the second message at its next-hop node on the target path, it determines that the second message is a key negotiation message based on the type field of the second ICMP message. Optionally, the service key negotiation message also indicates that the intermediate node's next-hop node on the target path does not need to reply to the second message.

[0153] In another example, the payload of the second message includes a second TCP message, which includes the aforementioned second key information.

[0154] S202: The intermediate node of the target path obtains a third message based on the second message. The third message includes third key information and third segment routing information. The third key information is obtained based on the service key and the third shared quantum key. The third shared quantum key is a shared quantum key between the intermediate node and the next-hop node of the intermediate node on the target path. The service key is recovered based on the second key information and the second quantum key. The third segment routing information is obtained by updating the second segment routing information.

[0155] S203: The intermediate node of the target path sends the third message.

[0156] After receiving the second message, the intermediate node determines that the destination address of the second message (i.e., the second SRv6 SID) is its own corresponding SID (specifically, the SRv6 SID assigned to itself for the quantum connection between itself and its next-hop node on the target path). Therefore, the intermediate node updates the second key information according to the type of the second SRv6 SID and the third shared quantum key corresponding to the second SRv6 SID, thus obtaining the third key information. Specifically, the intermediate node first uses the second shared quantum key and the second key information to recover the service key. Further, the intermediate node uses the third shared quantum key and the recovered service key to obtain the third key information. For example, the intermediate node first performs an XOR operation on the second shared quantum key and the second key information to obtain the service key. Further, it performs an XOR operation on the service key and the third shared quantum key to obtain the third key information.

[0157] In one example, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. Regarding the control plane processing unit and the forwarding plane processing unit, refer to the previous descriptions of the control plane processing unit and the forwarding plane processing unit of the head node; they will not be repeated here. In one example, the second shared quantum key is negotiated between the control plane processing unit of the intermediate node and the control plane processing unit of the node's previous hop on the target path, and the third shared quantum key is negotiated between the control plane processing unit of the intermediate node and the control plane processing unit of the node's next hop on the target path. That is, the control plane processing unit of the intermediate node manages the second and third shared quantum keys. In one example, the control plane processing unit of the intermediate node sends the second shared quantum key and the third shared quantum key to the forwarding plane processing unit of the intermediate node. The forwarding plane processing unit of the intermediate node updates the second key information in the second message to obtain the third message. Specifically, the forwarding plane processing unit of the intermediate node obtains the third key information based on the second shared quantum key, the third shared quantum key, and the second key information, and generates and sends the third message including the third key information.

[0158] In another example, the control plane processing unit of the intermediate node does not send the second shared quantum key and the third shared quantum key to the forwarding plane processing unit of the intermediate node to save the resources of the forwarding plane processing unit. In this scenario, the control plane processing unit of the intermediate node updates the second key information in the second message to obtain the third message. Specifically, the control plane processing unit of the intermediate node obtains the third key information based on the second shared quantum key, the third shared quantum key, and the second key information, and generates a third message including the third key information. After generating the third message, the control plane processing unit of the intermediate node sends the third message to the forwarding plane processing unit of the intermediate node, which then sends the third message.

[0159] In one example, the second message also includes indication information to specify whether the operation of updating the second key information is performed by the control plane processing unit or the forwarding plane processing unit of the intermediate node. As a concrete example, this indication information is an extended header of the second message, which instructs the control plane processing unit of the intermediate node to update the second key information in the intermediate message. In other words, after receiving the second message, if the second message includes an extended header, the control plane processing unit of the intermediate node updates the second key information in the second message to obtain the third message. For the specific implementation of updating the second key information in the second message to obtain the third message, please refer to the relevant description above; it will not be repeated here.

[0160] In one example, the extended header in the aforementioned second message is an HBH extended header. As an example, a specific field in the HBH extended header instructs the control plane processing unit of the intermediate node to update the second key information in the second message. As a concrete example, this specific field is the Option Type field of the HBH extended header.

[0161] In this application, the intermediate node sends a third message, specifically by sending a third message to its next-hop node on the target path. For ease of description, the next-hop node on the target path is referred to as the second node. Similar to the second message, the third message is either an SRv6 message or an SR-MPLS message. Specifically, if the second message is an SRv6 message, then the third message is also an SRv6 message; if the second message is an SR-MPLS message, then the third message is also an SR-MPLS message.

[0162] In one example, the second node is an intermediate node on the target path.

[0163] In one example, if the second node is the tail node of the target path, then the destination address of the third message is the third SRv6 SID, which indicates the tail node. Furthermore, the destination address of the third message is the first segment information in the third segment routing information. Specifically, in the scenario where the third message is an SRv6 message, the destination address of the third message is the first SRv6 SID in the third segment routing information. In this scenario, the type of the third SRv6 SID indicates that the tail node obtains the service key based on the third key information and the third shared quantum key. That is, after receiving the third message, the tail node determines that the destination address is its own SRv6 SID, and based on the type of the third SRv6 SID, recovers the service key using the third shared quantum key and the third key information.

[0164] In another example, if the second node is not the tail node of the target path, then the destination address of the third message is the fifth SRv6 SID. The fifth SRv6 SID is the SID corresponding to the quantum connection between the second node and the next-hop node of the second node on the target path; the type of the fifth SRv6 SID indicates that the second node updates the third key information according to the fifth shared quantum key corresponding to the fifth SRv6 SID.

[0165] Next, for Figure 4 The method shown will be introduced. Figure 4 The method shown includes the following steps S301-S302.

[0166] S301: The tail node of the target path receives a fourth message sent by the tail node to the previous hop node of the target path. The fourth message includes fourth key information and fourth segment routing information. The destination address of the fourth message indicates the tail node. The first segment information in the fourth segment routing information is the destination address. The fourth key information is obtained based on the business key and the fourth shared quantum key. The fourth shared quantum key is the shared quantum key between the tail node and the previous hop node of the tail node on the target path.

[0167] In one example, if the previous hop node of the tail node in the target path is the aforementioned... Figure 3 If the fourth message is an intermediate node in the process, then the fourth message is the aforementioned third message, and correspondingly, the fourth key information is the aforementioned third key information, and the fourth segment routing information is the aforementioned third segment routing information.

[0168] In another example, if the tail node's previous hop node on the target path is not the aforementioned... Figure 3 If the third message is forwarded by at least one node, then the fourth message is obtained by updating the third message. Assuming there are M quantum nodes between the intermediate and tail nodes, and these M quantum nodes are all on the target path, then the fourth message is obtained by updating the third message M times. Each of these M quantum nodes updates the messages it receives. The principle behind each quantum node updating the received messages is the same as described in S202 and will not be described in detail here.

[0169] The preceding hop node of the tail node in the target path is not the aforementioned one. Figure 3 In the scenario involving intermediate nodes, regarding the fourth segment of routing information, it is necessary to clarify the following:

[0170] The fourth segment of routing information is largely the same as the third segment. Specifically, the segment list in the fourth segment is identical to that in the third segment; the main difference lies in the value of the SL field. The SL field value in the third segment is greater than 0, while the SL field value in the third segment is 0.

[0171] In this application, the tail node and the previous hop node of the tail node on the target path can generate the same quantum key. The same shared key generated between the tail node and the previous hop node of the tail node on the target path is the fourth shared quantum key.

[0172] The tail node's upstream node on the target path uses the fourth shared quantum key to calculate the service key, obtaining the fourth key information. The principle behind the tail node's upstream node's calculation of the service key using the fourth shared quantum key is the same as that of the head node's calculation using the first shared quantum key; relevant details can be found in the previous section describing the head node's calculation using the first shared quantum key, and will not be repeated here. The tail node's upstream node on the target path uses the fourth shared quantum key to protect the security of the service key, thus ensuring its security.

[0173] Similar to the third message, the fourth message is an SRv6 message or an SR-MPLS message.

[0174] In the scenario where the fourth message is an SRv6 message, for any SRv6 SID corresponding to a quantum connection included in the segment list of the fourth message, the type corresponding to the SRv6 SID is used to indicate that when forwarding based on the SRv6 SID, it needs to be forwarded through a quantum connection.

[0175] In this application, the destination address of the fourth message is the fourth SRv6 SID. For the fourth SRv6 SID, please refer to the previous description of the third SRv6 SID. The description will not be repeated here.

[0176] In this application, the fourth key information is carried in the payload of the fourth message. Similar to how the first key information is carried in the first message, in a specific example, the fourth key information is carried in a third ICMP message. In other words, the payload of the fourth message includes a third ICMP message, and the third ICMP message includes the aforementioned fourth key information. The structure of the third ICMP message is described above in the section describing the structure of the first ICMP message, and will not be repeated here.

[0177] In one example, similar to the first ICMP message, the type field of the third ICMP message indicates that the fourth message is a service key negotiation message. In one example, after the tail node receives the fourth message, it determines that the fourth message is a key negotiation message based on the type field of the third ICMP message. Optionally, the service key negotiation message also indicates that the next-hop node on the target path does not need to reply to the fourth message.

[0178] In another example, the payload of the fourth message includes a third TCP message, which includes the aforementioned fourth key information.

[0179] S302: The tail node of the target path obtains the service key based on the fourth key information and the fourth shared quantum key.

[0180] After receiving the fourth message, the tail node determines that the destination address of the fourth message (i.e., the fourth SRv6 SID) is its own corresponding SID. Therefore, the intermediate node determines that it needs to perform the operation to recover the service key based on the type of the fourth SRv6 SID. Specifically, the tail node obtains the service key based on the fourth key information and the fourth shared quantum key. For example, the tail node performs an XOR operation on the fourth shared quantum key and the fourth key information to obtain the service key.

[0181] In one example, the tail node includes a control plane processing unit and a forwarding plane processing unit. In another example, the fourth shared quantum key is negotiated between the tail node's control plane processing unit and the control plane processing unit of the tail node's previous hop node on the target path. That is, the fourth shared quantum key is managed by the tail node's control plane processing unit. In another example, the tail node's control plane processing unit sends the fourth shared quantum key to the tail node's forwarding plane processing unit, which then obtains the service key based on the fourth key information and the fourth shared quantum key.

[0182] In another example, the control plane processing unit of the tail node does not send the fourth shared quantum key to the forwarding plane processing unit of the tail node to save the resources of the forwarding plane processing unit. In this scenario, the control plane processing unit of the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

[0183] In one example, the fourth message further includes indication information to specify whether the operation of obtaining the service key based on the fourth key information and the fourth shared quantum key is performed by the control plane processing unit or the forwarding plane processing unit of the tail node. As a concrete example, this indication information is an extended header of the fourth message, which instructs the control plane processing unit of the tail node to obtain the service key based on the fourth key information and the fourth shared quantum key. In other words, after receiving the fourth message, if the fourth message includes an extended header, the control plane processing unit of the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

[0184] In one example, the extended header in the aforementioned fourth message is an HBH extended header. As an example, a specific field in the HBH extended header instructs the control plane processing unit of the tail node to obtain the service key based on the fourth key information and the fourth shared quantum key. As a concrete example, the specific field is the Option Type field of the HBH extended header.

[0185] The communication method provided in the embodiments of this application has been described above. Next, in conjunction with... Figure 6a and Figure 6b The scenario shown illustrates two possible implementation methods of the embodiments of this application.

[0186] Figure 6a and Figure 6b The diagram illustrates the process of two communication methods provided in the embodiments of this application.

[0187] exist Figure 6a and Figure 6b In the scenario shown:

[0188] The target path is: Quantum Device 1 → Quantum Device 2 → Quantum Device 3 → Quantum Device 4. The SRv6 SID corresponding to the quantum connection between Quantum Device 1 and Quantum Device 2 is A:1::1, and the shared quantum key between Quantum Device 1 and Quantum Device 2 is K. 12 The SRv6 SID corresponding to the quantum connection between quantum device 2 and quantum device 3 is A:2::1, and the shared quantum key between quantum device 2 and quantum device 3 is K. 23 The SRv6 SID corresponding to the quantum connection between quantum device 3 and quantum device 4 is A:3::1, and the shared quantum key between quantum device 3 and quantum device 4 is K. 34 Quantum device 4 also corresponds to SRv6 SID A:3::100, and the IPv6 address of the head node is B:1::1.

[0189] like Figure 6a As shown:

[0190] In the IPv6 header of the first message sent by the head node (i.e., quantum device 1), the source address is B:1::1 and the destination address is A:2::1. The SRH of the first message sent by the head node includes four SRv6 SIDs, where segment list[0] = A:3::100, segment list[1] = A:3::1, segment list[2] = A:2::1, and segment list[3] = A:1::1. Based on segment list[3], the head node determines the quantum connection forwarding based on A:1::1. In addition, before forwarding the first message, the head node decrements the value of the SL field in the SRH by 1. Therefore, the value of the SL field in the first message sent by the head node is 2. The payload of the first message includes the first key information. Figure 6a In the middle, with K1⊕K 12 This represents the first key information, where: K1 is the business key, ⊕ indicates the XOR operation, and K12 corresponds to the first shared quantum key in the above embodiments.

[0191] Among them, segment list[0] is the first SID in the segment list of the first message, and segment list[3] is the last SID in the segment list of the first message.

[0192] The first message does not include the HBH extension header.

[0193] After receiving the first message from the head node, quantum device 2 determines that it needs to forward the first message based on the quantum connection corresponding to the destination address A:2::1. Before forwarding the first message, quantum device 2 determines, based on the type field of A:2::1, that the first key information in the payload of the first message needs to be updated. Specifically, quantum device 2 first uses K... 12 and K1⊕K 12 Perform an XOR operation to obtain K1, and then perform a cross-validation operation on K1 and K... 23 Perform an XOR operation to obtain K1⊕K 23 , using K1⊕K 23 Replace K1⊕K in the first message 12 In addition, quantum device 2 subtracts 1 from the value of SL in the first message to get 1, and updates the destination address of the first message to the value of segment list[1] to get message 1. Therefore, the destination address of message 1 sent by quantum device 2 is A:3::1, the value of the SL field is 1, and the payload includes key information 1: K1⊕K 23 .

[0194] The message 1 mentioned here, for example, corresponds to the second message in the above embodiments, and correspondingly, the key information 1 in message 1 corresponds to the second key information in the above embodiments.

[0195] Since the first message does not include the HBH extension header, the operation of updating the first key information in the first message by the quantum device 2 is performed by the forwarding plane processing unit of the quantum device 2.

[0196] After receiving message 1 from quantum device 2, quantum device 3 determines that it needs to forward message 1 based on the quantum connection corresponding to the destination address A:3::1. Before forwarding message 1, quantum device 3 determines, based on the type field of A:3::1, that the key information 1 in the payload of message 1 needs to be updated. Specifically, quantum device 3 first uses K... 23 and K1⊕K 23 Perform an XOR operation to obtain K1, and then perform a cross-validation operation on K1 and K... 34 Perform an XOR operation to obtain K1⊕K 34 , using K1⊕K 34 Replace K1⊕K in the first message 23 Additionally, quantum device 3 subtracts 1 from the value of SL in message 1, resulting in 0, and updates the destination address of message 1 to the value of segmentlist[0], thus obtaining message 2. Therefore, the destination address of message 2 sent by quantum device 3 is A:3::100, the value of the SL field is 0, and the payload includes key information 2: K1⊕K 34 .

[0197] The message 2 mentioned here corresponds, for example, to the third and fourth messages in the above embodiments (the third and fourth messages are the same). Correspondingly, the key information 2 in message 2 corresponds to the third and fourth key information in the above embodiments (the third and fourth key information are the same).

[0198] Similar to the first message, message 1 does not include the HBH extension header. Therefore, the operation of updating the key information 1 in message 1 by quantum device 3 is performed by the forwarding plane processing unit of quantum device 3.

[0199] After receiving message 2, quantum device 4, since the destination address is its own SRv6 SID and the SL field value in the first message is 0, determines that it needs to perform an operation to recover the service key based on the type A:3::100. Specifically, quantum device 4 uses K... 34 and K1⊕K 34 Perform an XOR operation to obtain K1.

[0200] Similar to the first message, message 2 also does not include the HBH extension header. Therefore, the operation of restoring the service key by quantum device 4 is performed by the forwarding plane processing unit of quantum device 4.

[0201] Figure 6b The process shown is the same as Figure 6a The overall process is the same; the difference lies in: Figure 6b In the first message sent by quantum node 1, an HBH extension header is included. Correspondingly, the messages received by quantum nodes 2 through 4 also include HBH extension headers. Therefore, based on the HBH extension header in the received first message, quantum node 2 determines that its control plane processing unit should perform the operation of updating the first key information in the first message. Similarly, based on the HBH extension header in the received message 1, quantum node 3 determines that its control plane processing unit should perform the operation of updating key information 1 in message 1. Based on the HBH extension header in the received message 2, quantum node 4 determines that its control plane processing unit should perform the operation of restoring the service key.

[0202] Using this scheme, when distributing business keys, all quantum nodes on the target path except the tail node need to use the shared quantum key between themselves and their next-hop node on the target path to protect the security of the business key, thereby effectively ensuring the security of the business key.

[0203] Based on the communication method provided in the above embodiments, this application also provides a corresponding communication device, which will be described below with reference to the accompanying drawings.

[0204] See Figure 7 The figure is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Figure 7 The communication device 700 shown includes a transceiver unit 710 and a processing unit 720, wherein the processing unit 720 is optional. The transceiver unit 710 is used to perform receiving and / or transmitting operations, and the processing unit 720 is used to perform other operations besides receiving and transmitting operations. The transceiver unit 710 includes a receiving unit 711 and / or a transmitting unit 712, wherein the receiving unit 711 is used to perform receiving operations, and the transmitting unit 712 is used to instruct transmitting operations.

[0205] In one example Figure 7 The communication device 700 shown is applied to the head node of the target path and is used to execute the communication method provided in the above embodiments, which is executed by the head node of the target path. For example, it executes... Figure 2 The communication method shown in the diagram involves quantum nodes along the target path. For this case:

[0206] The sending unit 712 is configured to send a first message to a first node. The first message includes first key information and first routing information. The first key information is obtained based on a service key and a first shared quantum key, whereby the first shared quantum key is a shared quantum key between the head node and the first node. The first routing information indicates the target path, and the first node is the next-hop node of the head node on the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path.

[0207] In one possible implementation, the destination address of the first message is a first SRv6 SID, which is the SID corresponding to the quantum connection between the first node and the next-hop node of the first node on the target path; the type of the first SRv6 SID indicates that the first node updates the first key information according to the second shared quantum key corresponding to the first SRv6 SID.

[0208] In one possible implementation, the type of the first SRv6 SID also indicates that the first node forwards messages based on the quantum connection corresponding to the first SRv6 SID.

[0209] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the first shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit is used to generate the first message based on the first shared quantum key and send the first message.

[0210] In one possible implementation, the head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit generates the first message based on the first shared quantum key and passes the first message to the forwarding plane processing unit, which then sends the first message.

[0211] In one possible implementation, the first message further includes an extension header that instructs the control plane processing unit of the first node to update the first key information in the first message.

[0212] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the first node to update the first key information in the first message.

[0213] In one possible implementation, the first segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the first segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0214] In one possible implementation, the payload of the first message includes a first Internet Control Message Protocol (ICMP) message, which includes the first key information.

[0215] In one possible implementation, the type field of the first ICMP message indicates that the first message is a business key negotiation message.

[0216] In another example, Figure 7 The communication device 700 shown is applied to an intermediate node of the target path and is used to execute the communication method provided in the above embodiments, which is executed by the intermediate node of the target path. For example, it executes... Figure 3 The communication method shown in the diagram involves quantum nodes along the target path. For this case:

[0217] The receiving unit 711 is configured to receive a second message sent by the intermediate node to the previous hop node on the target path. The second message includes second key information and second routing information. The second key information is obtained based on a service key and a second shared quantum key. The second shared quantum key is a shared quantum key between the intermediate node and its previous hop node on the target path. The second routing information indicates a sub-path in the target path from the intermediate node to the tail node of the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path.

[0218] The processing unit 720 is configured to obtain a third message based on the second message. The third message includes third key information and third segment routing information. The third key information is obtained based on a service key and a third shared quantum key. The third shared quantum key is a shared quantum key between the intermediate node and the next-hop node of the intermediate node on the target path. The service key is recovered based on the second key information and the second quantum key. The third segment routing information is obtained by updating the second segment routing information.

[0219] The sending unit 712 is used to send the third message.

[0220] In one possible implementation, the destination address of the second message is a second SRv6 SID, which is the SID corresponding to the quantum connection between the intermediate node and the next-hop node of the intermediate node on the target path; the type of the second SRv6 SID indicates that the intermediate node updates the second key information according to the third shared quantum key corresponding to the second SRv6 SID.

[0221] In one possible implementation, the type of the second SRv6 SID also indicates that the intermediate node forwards messages based on the quantum connection corresponding to the second SRv6 SID.

[0222] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the third shared quantum key and the second shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key and the second message, and to send the third message.

[0223] In one possible implementation, the intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key, and the second message, and to pass the third message to the forwarding plane processing unit, which then sends the third message.

[0224] In one possible implementation, the second message further includes an extension header that instructs the control plane processing unit of the intermediate node to update the second key information in the second message to obtain the third message.

[0225] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the intermediate node to update the second key information in the second message.

[0226] In one possible implementation, the second segment of routing information includes at least one SRv6 SID corresponding to a quantum connection, and the type of each SRv6 SID corresponding to a quantum connection included in the second segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0227] In one possible implementation, the payload of the second message includes a second Internet Control Message Protocol (ICMP) message, which includes the second key information.

[0228] In one possible implementation, the type field of the second ICMP message indicates that the second message is a business key negotiation message.

[0229] In one possible implementation, the destination address of the third message is a third SRv6 SID, the third SRv6 SID indicates the tail node, the first segment information in the third segment routing information is the third SRv6 SID, and the third SRv6 SID indicates that the tail node obtains the service key based on the third key information and the third shared quantum key.

[0230] In one example Figure 7 The communication device 700 shown is applied to the tail node of the target path and is used to execute the communication method provided in the above embodiments, which is executed by the tail node of the target path. For example, it executes... Figure 4 The communication method shown in the diagram involves quantum nodes along the target path. For this case:

[0231] The receiving unit 711 is configured to receive a fourth message sent by the tail node to the previous hop node of the target path. The fourth message includes fourth key information and fourth segment routing information. The destination address of the fourth message indicates the tail node. The first segment information in the fourth segment routing information is the destination address. The fourth key information is obtained based on the service key and the fourth shared quantum key. The fourth shared quantum key is a shared quantum key between the tail node and the previous hop node of the tail node on the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path.

[0232] The processing unit 720 is used to obtain the service key based on the fourth key information and the fourth shared quantum key.

[0233] In one possible implementation, the destination address of the fourth message is a fourth SRv6 SID, and the type of the fourth SRv6 SID indicates that the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

[0234] In one possible implementation, the tail node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the fourth shared quantum key to the forwarding plane processing unit, and the forwarding plane processing unit is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0235] In one possible implementation, the intermediate node includes a control plane processing unit, which is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0236] In one possible implementation, the fourth message further includes an extension header that instructs the control plane processing unit of the tail node to obtain the service key based on the fourth shared quantum key and the fourth key information.

[0237] In one possible implementation, the extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header indicates that the control plane processing unit of the tail node obtains the service key based on the fourth shared quantum key and the fourth key information.

[0238] In one possible implementation, the fourth segment of routing information includes at least one SRv6 SID corresponding to a quantum connection. The type of each SRv6 SID corresponding to a quantum connection included in the fourth segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

[0239] In one possible implementation, the payload of the fourth message includes a third Internet Control Message Protocol (ICMP) message, which includes the fourth key information.

[0240] In one possible implementation, the type field of the third ICMP message indicates that the fourth message is a service key negotiation message.

[0241] For details on the implementation of each unit of the device 700, please refer to the relevant descriptions in the above embodiments; they will not be repeated here.

[0242] In this application, the aforementioned communication device 700 may have the following hardware structure: Figure 8 The structure shown, Figure 8 This is a schematic diagram of the structure of a device provided in an embodiment of this application.

[0243] Please see Figure 8As shown, device 800 includes: a processor 810, a communication interface 820, and a memory 830. The number of processors 810 in device 800 can be one or more. Figure 8 Taking a processor as an example. In this embodiment, the processor 810, communication interface 820, and memory 830 can be connected via a bus system or other means, wherein, Figure 8 Taking the connection between China and Israel via the 840 bus system as an example.

[0244] Processor 810 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. Processor 810 may further include hardware chips. These hardware chips may be application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or combinations thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0245] Memory 830 may include volatile memory, such as random-access memory (RAM); memory 830 may also include non-volatile memory, such as flash memory, hard disk drive (HDD), or solid-state drive (SSD); memory 830 may also include combinations of the above types of memory. Figure 8 When the device 800 shown is the head node of the target path, the memory 830 stores, for example, the aforementioned target path; when Figure 8 When the device 800 shown is an intermediate node, the memory 830 stores, for example, the second quantum shared key and the third shared quantum key; when Figure 8 When the device 800 shown is the tail node of the aforementioned target path, the memory 830 stores, for example, a fourth shared quantum key.

[0246] Optionally, the memory 830 stores an operating system and programs, executable modules, or data structures, or subsets thereof, or extended sets thereof. The programs may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and handling hardware-based tasks. The processor 810 can read the programs in the memory 830 to implement the communication methods provided in the embodiments of this application.

[0247] The bus system 840 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus system 840 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 8 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0248] This application also provides a computer-readable storage medium, including instructions or a computer program, which, when run on a computer, causes the computer to perform the communication method provided in the above embodiments.

[0249] This application also provides a computer program product containing instructions or computer programs, which, when run on a computer, causes the computer to execute the communication method provided in the above embodiments.

[0250] This application also provides a communication system, which includes at least one of the head node, intermediate node, or tail node of the target path mentioned in the above embodiments. The head node of the target path is used to perform the operations performed by the head node of the target path provided in the above embodiments, the intermediate node of the target path is used to perform the operations performed by the intermediate node of the target path provided in the above embodiments, and the tail node of the target path is used to perform the operations performed by the tail node of the target path provided in the above embodiments.

[0251] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0252] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0253] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0254] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0255] Furthermore, the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software business unit.

[0256] If the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0257] Those skilled in the art will recognize that, in one or more of the examples above, the services described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.

[0258] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention.

[0259] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A communication method, characterized in that, The method, applied to the head node of a target path where all nodes are quantum nodes, includes: A first message is sent to the first node. The first message includes first key information and first routing information. The first key information is obtained based on a service key and a first shared quantum key. The first shared quantum key is a shared quantum key between the head node and the first node. The first routing information indicates the target path. The first node is the next-hop node of the head node on the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path.

2. The method according to claim 1, characterized in that, The destination address of the first message is the first Internet Protocol version 6 segment routing segment identifier (SRv6 SID), and the first SRv6 SID is the SID corresponding to the quantum connection between the first node and the next-hop node of the first node on the target path; the type of the first SRv6 SID indicates that the first node updates the first key information according to the second shared quantum key corresponding to the first SRv6 SID.

3. The method according to claim 2, characterized in that, The type of the first SRv6 SID also indicates that the first node forwards messages based on the quantum connection corresponding to the first SRv6 SID.

4. The method according to any one of claims 1-3, characterized in that, The head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the first shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to generate the first message based on the first shared quantum key and send the first message.

5. The method according to any one of claims 1-3, characterized in that, The head node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to generate the first message based on the first shared quantum key and pass the first message to the forwarding plane processing unit, which then sends the first message.

6. The method according to any one of claims 1-5, characterized in that, The first message also includes an extension header, which instructs the control plane processing unit of the first node to update the first key information in the first message.

7. The method according to claim 6, characterized in that, The extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the first node to update the first key information in the first message.

8. The method according to any one of claims 1-7, characterized in that, The first segment of routing information includes multiple SRv6 SIDs corresponding to quantum connections. The type of each SRv6 SID corresponding to a quantum connection included in the first segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

9. The method according to any one of claims 1-8, characterized in that, The payload of the first message includes a first Internet Control Message Protocol (ICMP) message, and the first ICMP message includes the first key information.

10. The method according to claim 9, characterized in that, The type field of the first ICMP message indicates that the first message is a service key negotiation message.

11. A communication method, characterized in that, The method, applied to intermediate nodes of a target path where all nodes are quantum nodes, includes: The system receives a second message sent by the intermediate node to the previous hop node on the target path. The second message includes second key information and second routing information. The second key information is obtained based on a service key and a second shared quantum key. The second shared quantum key is a shared quantum key between the intermediate node and the previous hop node on the target path. The second routing information indicates a sub-path in the target path from the intermediate node to the tail node of the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path. A third message is obtained based on the second message. The third message includes third key information and third segment routing information. The third key information is obtained based on the business key and the third shared quantum key. The third shared quantum key is the shared quantum key between the intermediate node and the next-hop node of the intermediate node on the target path. The business key is recovered based on the second key information and the second quantum key. The third segment routing information is obtained by updating the second segment routing information. Send the third message.

12. The method according to claim 11, characterized in that, The destination address of the second message is the second Internet Protocol version 6 segment routing segment identifier (SRv6 SID), and the second SRv6 SID is the SID corresponding to the quantum connection between the intermediate node and the next-hop node of the intermediate node on the target path; the type of the second SRv6 SID indicates that the intermediate node updates the second key information according to the third shared quantum key corresponding to the second SRv6 SID.

13. The method according to claim 12, characterized in that, The type of the second SRv6 SID also indicates that the intermediate node forwards messages based on the quantum connection corresponding to the second SRv6 SID.

14. The method according to any one of claims 11-13, characterized in that, The intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the third shared quantum key and the second shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key and the second message and to send the third message.

15. The method according to any one of claims 11-13, characterized in that, The intermediate node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to obtain the third message based on the third shared quantum key, the second shared quantum key and the second message, and to pass the third message to the forwarding plane processing unit, which then sends the third message.

16. The method according to claim 15, characterized in that, The second message also includes an extension header, which instructs the control plane processing unit of the intermediate node to update the second key information in the second message to obtain the third message.

17. The method according to claim 16, characterized in that, The extension header is a hop-by-hop HBH extension header, and the option type field of the HBH extension header instructs the control plane processing unit of the intermediate node to update the second key information in the second message.

18. The method according to any one of claims 11-17, characterized in that, The second segment of routing information includes at least one SRv6 SID corresponding to a quantum connection. The type of each SRv6 SID corresponding to a quantum connection included in the second segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

19. The method according to any one of claims 11-18, characterized in that, The payload of the second message includes a second Internet Control Message Protocol (ICMP) message, which includes the second key information.

20. The method according to claim 19, characterized in that, The type field of the second ICMP message indicates that the second message is a service key negotiation message.

21. The method according to any one of claims 11-20, characterized in that, The destination address of the third message is the third SRv6 SID, the third SRv6 SID indicates the tail node, the first segment information in the third segment routing information is the third SRv6 SID, and the third SRv6 SID indicates that the tail node obtains the service key based on the third key information and the third shared quantum key.

22. A communication method, characterized in that, The method, applied to the tail node of a target path where all nodes are quantum nodes, includes: The system receives a fourth message sent by the tail node to the previous hop node on the target path. The fourth message includes fourth key information and fourth segment routing information. The destination address of the fourth message indicates the tail node. The first segment information in the fourth segment routing information is the destination address. The fourth key information is obtained based on the service key and the fourth shared quantum key. The fourth shared quantum key is a shared quantum key between the tail node and the previous hop node on the target path. The service key is used to securely protect the service data between the head node and the tail node of the target path. The business key is obtained based on the fourth key information and the fourth shared quantum key.

23. The method according to claim 22, characterized in that, The destination address of the fourth message is the fourth Internet Protocol version 6 segment routing segment identifier (SRv6 SID). The type of the fourth SRv6 SID indicates that the tail node obtains the service key based on the fourth key information and the fourth shared quantum key.

24. The method according to claim 22 or 23, characterized in that, The tail node includes a control plane processing unit and a forwarding plane processing unit. The control plane processing unit is used to send the fourth shared quantum key to the forwarding plane processing unit. The forwarding plane processing unit is used to obtain the service key based on the fourth shared quantum key and the fourth key information.

25. The method according to claim 22 or 23, characterized in that, The intermediate node includes a control plane processing unit, which is used to obtain the business key based on the fourth shared quantum key and the fourth key information.

26. The method according to claim 25, characterized in that, The fourth message also includes an extension header, which instructs the control plane processing unit of the tail node to obtain the service key based on the fourth shared quantum key and the fourth key information.

27. The method according to claim 26, characterized in that, The extension header is a hop-by-hop HBH extension header. The option type field of the HBH extension header indicates that the control plane processing unit of the tail node obtains the service key based on the fourth shared quantum key and the fourth key information.

28. The method according to any one of claims 22-27, characterized in that, The fourth segment of routing information includes at least one SRv6 SID corresponding to a quantum connection. The type of each SRv6 SID corresponding to a quantum connection included in the fourth segment of routing information indicates that the node forwarding packets based on the SRv6 SID forwards packets based on the quantum connection corresponding to the SRv6 SID.

29. The method according to any one of claims 22-28, characterized in that, The payload of the fourth message includes a third Internet Control Message Protocol (ICMP) message, which contains the fourth key information.

30. The method according to claim 29, characterized in that, The type field of the third ICMP message indicates that the fourth message is a service key negotiation message.

31. A communication device, characterized in that, The device includes multiple functional modules that interact with each other to implement the method as described in any one of claims 1-30.

32. A communication device, comprising a processor and a memory, the memory for storing program code, the processor for calling the program code in the memory to cause the communication device to perform the method as described in any one of claims 1-30.

33. A computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-30.

34. A computer program product, characterized in that, Includes program code that, when a computer runs the computer program product, causes the computer to perform the method as described in any one of claims 1-30.

35. A communication system, characterized in that, The system includes at least two of the following: The head node of the method according to any one of claims 1-10, the middle node of the method according to any one of claims 11-21, or the tail node of the method according to any one of claims 22-30.