Laser communication terminal quantum key distribution method
Patent Information
- Application Number
- CN202611015850.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-09
- Publication Date
- 2026-09-29
AI Technical Summary
[0007]本发明旨在解决上述技术问题,解决现有激光通信终端仅以量子误码率作为终止密钥分发的单一判定指标,导致低质量或不安全的密钥流入业务加密环节的问题
[0023]在采用上述技术方案的情况下,本发明对量子误码率与有效探测率给出了明确的计算路径,并界定有效探测事件仅统计参与基矢比对且被保留的探测结果,使有效探测率能够真实反映量子信号接收质量与可用密钥素材比例,为权利要求1中的联合判定提供可量化、可复现的指标基础,减少因统计口径不一致造成的误判供钥风险。
Smart Images

Figure CN122845111A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of laser communication technology, and specifically provides a quantum key distribution method for laser communication terminals. Background Technology
[0002] Free-space laser communication (including inter-satellite, satellite-to-ground, and air-to-ground links) has advantages such as large transmission bandwidth, small beam divergence angle, and strong resistance to electromagnetic interference, and has been widely used in satellite relay, remote sensing downlink, and high-speed point-to-point communication. Laser communication terminals typically include pointing, acquisition, and tracking subsystems, optical transceiver subsystems, and service modulation and demodulation subsystems, used to transmit telemetry, remote control, and payload data over high-speed laser links. To ensure the confidentiality and integrity of services, classical cryptographic methods such as symmetric encryption, national cryptographic algorithms, or transport layer security protocols are commonly used in engineering. Its security largely depends on whether the session key can be securely established and updated in a timely manner between the communicating parties.
[0003] Quantum key distribution (QKD) utilizes the principles of quantum mechanics, enabling communicating parties to negotiate and share a random key via weak light quantum signals. Eavesdropping disturbs the quantum state, manifesting as statistical anomalies such as an increased quantum error rate, thus providing a basis for determining the usability of the key in this round. The weak light quantum key distribution protocol, which employs random encoded basis vectors and random measurement basis vectors, publishes and compares the basis vectors on an authenticated classical channel, and then performs error estimation, information coordination error correction, and privacy amplification to obtain the final secure key, is the most widely used protocol in engineering. It should be noted that the engineering application of quantum key distribution should focus on key distribution; the plaintext or ciphertext of the service should still be protected by classical encryption algorithms via the main laser communication link, rather than directly carrying the service payload through the quantum channel.
[0004] A prior art method and system for secure transmission of lidar data based on quantum key distribution (patent number CN122027309A) is disclosed. This scheme employs a random basis-vector comparison-based weak-light quantum key distribution protocol, generating and storing keys through quantum bit error rate estimation and key pool management. LiDAR point cloud data is divided into blocks and XORed with keys in the key pool for encryption, then the ciphertext is transmitted through a classical channel. When the quantum bit error rate exceeds a preset threshold, the current key distribution process is terminated.
[0005] However, when the aforementioned existing technologies are directly applied to satellite-to-ground / air-to-ground laser communication terminal scenarios, they only use the quantum bit error rate as the sole criterion for terminating key distribution, without jointly verifying the effective detection rate and the quantum bit error rate. The effective detection rate directly reflects the reception quality of the quantum signal and the efficiency of key generation. Relying solely on the quantum bit error rate cannot comprehensively assess the security and availability of the key, which may lead to low-quality or insecure keys flowing into the business encryption process, threatening communication security.
[0006] To address these issues, this invention proposes a quantum key distribution and secure key management method for laser communication terminals, aiming to solve the problems existing in the prior art. Summary of the Invention
[0007] The present invention aims to solve the above-mentioned technical problems and address the issue that existing laser communication terminals use only the quantum bit error rate as the sole criterion for terminating key distribution, which leads to low-quality or insecure keys flowing into the business encryption process.
[0008] This invention provides a quantum key distribution method for a laser communication terminal, comprising the following steps after the free-space optical path between the laser communication terminal and the communication peer is ready:
[0009] Weak light quantum key distribution is performed between the laser communication terminal and the communication peer to obtain the sieved bit string;
[0010] Calculate the quantum error rate and effective detection rate of the sieved bit string;
[0011] When the quantum error rate is not greater than the preset upper limit of quantum error rate and the effective detection rate is not lower than the preset lower limit of effective detection rate, error correction and privacy amplification are performed on the sieved bit string to obtain a security key, and the security key is delivered to the service encryption module of the laser communication terminal for encryption or decryption of service data on the main laser communication link.
[0012] When the quantum error rate is greater than the upper limit of the quantum error rate and / or the effective detection rate is lower than the lower limit of the effective detection rate, the current round of key distribution is terminated and no key is supplied to the business encryption module.
[0013] By adopting the above technical solution, this invention uses quantum error rate and effective detection rate as joint judgment conditions before key supply. Weak light quantum key distribution is only performed when the free space optical path is ready. This avoids the shortcomings of the prior art, which delivers the key to the service encryption link based solely on the quantum error rate. When the reception quality is low or the error rate is high, the current round of distribution is terminated and key supply is stopped in a timely manner, thereby suppressing low-quality or insecure keys from entering the main laser communication link and improving the reliability and security of service data encryption in satellite-to-ground / air-to-ground laser communication terminals.
[0014] In the specific implementation of the above-described laser communication terminal quantum key distribution method, the step of performing weak light quantum key distribution to obtain the sieved bit string includes:
[0015] Random data bits, random encoding basis vectors, and random measurement basis vectors are generated by a quantum random number generator, and weak light quantum pulses are sent to perform single-photon detection.
[0016] The two parties exchange synchronization information through the authentication classic channel and disclose their respective basis vector selections at the end of the current session.
[0017] Discard bits with inconsistent basis vectors to obtain the sieved bit string.
[0018] By adopting the above technical solution, the present invention decomposes the random source generation, quantum pulse transmission and reception, authentication classical channel synchronization, and basis vector public screening of weak light quantum key distribution into an implementable sequence of steps, which facilitates sequential execution and joint debugging in the engineering deployment of laser communication terminals. This provides a standardized source of filtered bit strings for accurate statistics of subsequent quantum bit error rate and effective detection rate, and improves the repeatability and verifiability of the key generation process.
[0019] In the specific implementation of the above-described quantum key distribution method for laser communication terminals, the steps of calculating the quantum error rate and effective detection rate of the sieved bit string include:
[0020] Randomly select verification samples from the sieved bit string, and calculate the quantum bit error rate based on the verification samples;
[0021] The effective detection rate is obtained by calculating the proportion of the number of valid detection events at the receiving end to the total number of pulses transmitted at the transmitting end.
[0022] The effective detection event refers to a photon detection event in which the receiver successfully detects a photon and the corresponding bit is included in the basis vector comparison and retained.
[0023] With the above technical solution, the present invention provides a clear calculation path for quantum error rate and effective detection rate, and defines effective detection events as only counting detection results that participate in basis vector comparison and are retained, so that the effective detection rate can truly reflect the quantum signal reception quality and the proportion of available key materials, providing a quantifiable and reproducible indicator basis for the joint determination in claim 1, and reducing the risk of misjudgment key supply caused by inconsistent statistical standards.
[0024] In the specific implementation of the above-mentioned quantum key distribution method for laser communication terminals, the upper limit of the quantum error rate ranges from 1% to 11%, and the lower limit of the effective detection rate is determined based on the pulse repetition frequency of the single photon source and the detection efficiency of the detector.
[0025] With the above technical solution, this invention provides an engineering range of upper limits for quantum bit error rate and associates the lower limit of effective detectivity with the calibration parameters of single photon source and detector, so that the joint threshold can be adapted and calibrated according to the terminal hardware configuration, taking into account the security margin and key production efficiency under different link conditions, and improving the applicability and operability of the judgment threshold in satellite-to-ground / air-to-ground laser communication terminals.
[0026] In a specific embodiment of the above-described quantum key distribution method for laser communication terminals, the emission of the weak light quantum pulse and the single-photon detection multiplex the main optical transceiver link of the laser communication terminal; or
[0027] The emission of the weak light quantum pulse and the single-photon detection work together in conjunction with the main optical transceiver link of the laser communication terminal. The quantum transceiver unit and the main optical transceiver unit share the attitude control signals and optical path alignment information of the pointing, acquisition and tracking subsystems.
[0028] By adopting the above technical solution, the present invention enables the weak light quantum key distribution and the main laser communication terminal to reuse or coordinate in optical links and pointing control, which can reduce the hardware cost and volume weight of adding independent quantum optical paths, and maintain the consistency between quantum optical paths and service optical paths by means of shared attitude control and alignment information. This is conducive to maintaining stable free space coupling under the condition of integrated terminal, thereby indirectly ensuring that the effective detection rate and quantum bit error rate are within an acceptable range.
[0029] In the specific implementation of the above-mentioned quantum key distribution method for laser communication terminals, a unique key number is assigned to the generated security key and key metadata is recorded; when the quantum error rate is greater than the preset upper limit of quantum error rate and / or the effective detection rate is lower than the preset lower limit of effective detection rate, all temporary key materials generated in this round are cleared.
[0030] By adopting the above technical solution, the present invention achieves traceable management of security keys through unique key number and metadata records, and simultaneously clears temporary key materials when indicators are not up to standard, preventing unfinished or unqualified keys from being mistakenly used in terminal storage, strengthening the security boundary throughout the key's life cycle, and meeting the requirements of engineering operation and maintenance and auditing for traceable and controllable key status.
[0031] In the specific implementation of the above-mentioned quantum key distribution method for laser communication terminals, the conditions for determining that the free space optical path between the laser communication terminal and the communication peer is ready are: the tracking residual is lower than a preset upper limit of residual, and / or the received signal-to-noise ratio of the beacon light or communication light is higher than a preset lower limit of signal-to-noise ratio.
[0032] When adopting the above technical solution, the present invention uses online obtainable link parameters such as tracking residual and received signal-to-noise ratio as free space optical path readiness criteria, so that weak light quantum key distribution can be started only after optical path alignment and reception quality meet the standards, thereby reducing the falsely low effective detection rate and abnormally high quantum error rate caused by pointing deviation or insufficient received signal-to-noise ratio, and reducing the probability of invalid quantum sessions and incorrect key supply from the source.
[0033] In the specific implementation of the above-mentioned quantum key distribution method for laser communication terminals, when the pointing, capturing, and tracking subsystem loses lock, the transmission of the weak light quantum pulse is paused, and all temporary key materials generated in this round are cleared.
[0034] When the above technical solution is adopted, the present invention immediately suspends the weak light quantum pulse emission and clears the temporary key of the current round when the pointing, capturing and tracking lock is lost. This avoids the continued accumulation of unreliable quantum bits and key materials in the unstable stage of the optical path, prevents the transmission of bit errors and detection statistical distortion caused by tracking failure to the business encryption link, and improves the key security handling capability under abnormal link conditions.
[0035] In the specific implementation of the above-described quantum key distribution method for laser communication terminals, the service data transmitted on the main laser communication link is at least one of telemetry data, remote control commands, or payload data; the service encryption module uses a symmetric block cipher algorithm and / or a national cryptographic algorithm to encrypt or decrypt the service data; and / or
[0036] The delivery of the security key to the business encryption module and the initiation of a new round of weak light quantum key distribution when the key pool balance is lower than a preset threshold are both determined based on whether the quantum error rate and the effective detection rate simultaneously meet the upper and lower limits.
[0037] By adopting the above technical solution, this invention clearly defines the key application object as the telemetry, remote control, or payload service data on the main laser communication link, and uses symmetric block ciphers or national cryptographic algorithms for encryption protection, which is in line with the actual service form of laser communication terminals. At the same time, the key supply and key pool replenishment triggering are uniformly incorporated into the joint judgment system of quantum bit error rate and effective detection rate, so that the key delivery and replenishment decisions are based on the dual standards of reception quality and security, avoiding blind key supply or replenishment under a single bit error rate indicator, and enhancing the overall security of the main link communication.
[0038] In the specific implementation of the above-mentioned quantum key distribution method for laser communication terminals, the temperature deviation between the primary mirror, secondary mirror, and / or azimuth turntable motor in the laser communication terminal and the preset steady-state temperature is monitored in real time; when the temperature deviation exceeds the thermal control early warning threshold, the upper limit of the quantum bit error rate is appropriately tightened; when the temperature deviation exceeds the thermal control fault threshold, the key supply to the service encryption module is suspended until the temperature returns to the preset steady-state window.
[0039] By adopting the above technical solution, the present invention links the terminal thermal control state with the quantum bit error rate threshold and key supply control. Before temperature drift causes changes in the optical axis or detector performance, a safety margin is reserved by tightening the upper limit of the bit error rate. When the temperature drift is severe, the key supply is actively suspended to suppress the increase in quantum bit error rate and the decrease in effective detection rate caused by thermal environment disturbance. This ensures the stability of the joint judgment index during long-term operation and extends the availability time of the weak light quantum key distribution link under on-orbit / outdoor conditions. Attached Figure Description
[0040] The preferred embodiments of the present invention are described below with reference to the accompanying drawings, in which:
[0041] Figure 1 This is a flowchart of the main steps of an embodiment of the quantum key distribution method for laser communication terminals of the present invention;
[0042] Figure 2 This is a flowchart of the main steps in an embodiment of the present invention for determining the readiness of a free-space optical path;
[0043] Figure 3 This is a flowchart of the main steps of an embodiment of weak light quantum key distribution performed by S101 of the present invention;
[0044] Figure 4 This is a flowchart of a possible implementation of the quantum key distribution method for laser communication terminals of the present invention. Detailed Implementation
[0045] Preferred embodiments of this application are described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of this application and are not intended to limit the scope of protection of this application. Those skilled in the art can make adjustments as needed to adapt to specific application scenarios.
[0046] like Figure 1As shown, to address the problem that existing laser communication terminals rely solely on quantum error rate as the single criterion for terminating key distribution, leading to low-quality or insecure keys flowing into the service encryption stage, this invention provides a quantum key distribution method for laser communication terminals applied to space-to-ground / air-to-ground free-space laser communication scenarios. The laser communication terminal includes a pointing, acquisition, and tracking subsystem, a main optical transceiver link, a quantum transmitter, a quantum receiver, a quantum random number generator, a key management system, and a service encryption module; the communication peer has corresponding quantum transceiver and laser communication capabilities. The main laser communication link is used to transmit service data such as telemetry, remote control, and payload; weak-light quantum key distribution is completed on a free-space quantum channel, used only for negotiating and delivering secure keys to the service encryption module; service plaintext or ciphertext is not transmitted through the quantum channel. The quantum key distribution method for the laser communication terminal, after the free-space optical path between the laser communication terminal and the communication peer is ready, includes the following steps:
[0047] S101, weak light quantum key distribution is performed between the laser communication terminal and the communication peer to obtain a filtered bit string. For example, between the satellite-to-ground laser communication terminal and the ground station peer, the quantum transmitter sends a weak light quantum pulse to the peer. After the peer completes single-photon detection and basis vector filtering, both parties obtain a string of bit data that can be used for subsequent processing; this bit data is the filtered bit string. Furthermore, the length of the filtered bit string is usually less than the total number of pulses sent in this round, and its specific length is determined by the number of effective detection events and the basis vector consistency ratio. The laser communication terminal can be a satellite-based terminal, a ground station terminal, or an airborne terminal, and the communication peer is the peer device that establishes a free-space laser communication link with the terminal.
[0048] S102, calculate the quantum error rate and effective detection rate of the sieved bit string. For example, randomly select a portion of bits from the sieved bit string as a verification sample, and after verifying the publicly available bit values through a classical channel, calculate the proportion of inconsistencies between the two parties to obtain the quantum error rate; simultaneously, calculate the ratio of the number of effective detection events in this round to the total number of pulses transmitted by the transmitter to obtain the effective detection rate.
[0049] S103: When the quantum error rate is not greater than the preset upper limit of the quantum error rate and the effective detection rate is not lower than the preset lower limit of the effective detection rate, error correction and privacy amplification are performed on the sieved bit string to obtain a security key. The security key is then delivered to the service encryption module of the laser communication terminal for encryption or decryption of service data on the main laser communication link. For example, after error correction and privacy amplification, a 128-bit or 256-bit security key is obtained, which is written into the key pool by the key management system and then read by the service encryption module.
[0050] S104. When the quantum error rate exceeds the upper limit and / or the effective detection rate falls below the lower limit, the current round of key distribution is terminated, and no key is supplied to the business encryption module. For example, the key management system records an alarm and stops key supply output for this round; the business encryption module can continue to use historical keys that are still valid in the key pool until a new round of qualified keys is generated.
[0051] This invention uses quantum error rate and effective detection rate as joint criteria before key supply. Weak light quantum key distribution is only performed when the free space optical path is ready. This avoids the shortcomings of existing technologies that rely solely on quantum error rate as the sole indicator for key delivery to the service encryption stage. When the reception quality is low or the error rate is high, the current round of distribution is terminated and key supply is stopped in a timely manner, thereby preventing low-quality or insecure keys from entering the main laser communication link and improving the reliability and security of service data encryption in satellite-to-ground / air-to-ground laser communication terminals.
[0052] In a preferred embodiment, the step of establishing a free-space optical path between the laser communication terminal and the communication peer further includes:
[0053] S201, acquire the tracking residual output by the pointing, acquisition, and tracking subsystem, and the received signal-to-noise ratio (SNR) of the beacon light or communication light at the receiving end. In this application, the tracking residual refers to the deviation between the actual spot position and the preset target position; the received SNR refers to the ratio of the output signal power of the receiver detector to the noise power.
[0054] S202, when the tracking residual is lower than a preset upper limit and / or the received signal-to-noise ratio (SNR) is higher than a preset lower limit, the free-space optical path between the laser communication terminal and the communication peer is determined to be ready. For example, the tracking residual is measured in microradians, with a typical upper limit of 10 μrad; the received SNR is measured in decibels, with a typical lower limit of 15 dB. Those skilled in the art can also use either the tracking residual or the received SNR as the sole criterion, or combine both, depending on system performance requirements.
[0055] When adopting the above technical solution, the present invention uses online obtainable link parameters such as tracking residual and received signal-to-noise ratio as free space optical path readiness criteria, so that weak light quantum key distribution can be started only after optical path alignment and reception quality meet the standards, thereby reducing the falsely low effective detection rate and abnormally high quantum error rate caused by pointing deviation or insufficient received signal-to-noise ratio, and reducing the probability of invalid quantum sessions and incorrect key supply from the source.
[0056] In a preferred embodiment, the step of performing weak light quantum key distribution on S101 to obtain the sieved bit string further includes:
[0057] S301 generates random data bits, random encoding basis vectors, and random measurement basis vectors using a quantum random number generator, transmits weak light quantum pulses, and performs single-photon detection. Specifically, weak light quantum key distribution refers to the process by which two communicating parties negotiate and share a random key on a free-space channel using quantum signals with an average photon count far lower than that of a single photon. For example, the transmitting end's encoding involves the quantum transmitter of the laser communication terminal randomly selecting horizontal / vertical basis vectors (linear basis vectors) or 45° / 135° basis vectors (diagonal basis vectors), encoding randomly generated 0s and 1s onto the polarization state of a single photon, and transmitting it to the communicating partner through the quantum channel. The receiving end's measurement involves the quantum receiver of the communicating partner randomly selecting one of the above two basis vectors, measuring each received photon to obtain a string of 0s and 1s, and recording whether each pulse was effectively detected.
[0058] S302, the authentication classical channel is used to exchange synchronization information with the communication peer, and each party discloses its basis vector selection after the current session ends. In this invention, the authentication classical channel can use the main laser communication link of the laser communication terminal or an independent classical wireless communication link, and must have message authentication capabilities to prevent eavesdroppers from tampering with the basis vector information and synchronization information. For example, during pulse transmission and reception, the frame synchronization word and pulse sequence number are exchanged; after the session ends, both parties disclose the basis vector used for each bit, but do not disclose the specific bit value.
[0059] S303, discard bits with inconsistent basis vectors to obtain the filtered bit string. For example, after comparison between the two parties, bits with inconsistent basis vectors are discarded, and only bits with completely consistent basis vectors are retained and concatenated according to their original sequence numbers; the retained bit string is the filtered bit string (also called the filtering key), which is the direct input for subsequent calculation of quantum bit error rate, error correction, and privacy amplification. In this way, the present invention decomposes the random source generation, quantum pulse transmission and reception, authentication classical channel synchronization, and basis vector public filtering of weak light quantum key distribution into an implementable sequence of steps, which is convenient for sequential execution and joint debugging in the engineering deployment of laser communication terminals. This provides a standardized source of filtered bit strings for accurate statistics of subsequent quantum bit error rate and effective detection rate, and improves the repeatability and verifiability of the key generation process.
[0060] It should be noted that the above is a preferred implementation of S101, and those skilled in the art can adjust the above steps according to specific application scenarios. For example, the encoding basis vector can also use phase encoding or time binning encoding instead of polarization encoding; the synchronization information can also be embedded in the quantum pulse timestamp field, which is returned by the receiving end to complete the alignment.
[0061] In a preferred embodiment, step S301, which involves transmitting a weak quantum pulse and performing single-photon detection, further includes: multiplexing the transmission of the weak quantum pulse and single-photon detection using the main optical transceiver link of the laser communication terminal. For example, the quantum signal and the main service laser signal share the same primary mirror, secondary mirror, turntable, and optical transceiver link, and are split by a wavelength division multiplexer. The quantum wavelength and the service wavelength enter the quantum transceiver unit and the service modulation and demodulation unit, respectively.
[0062] In another preferred embodiment, the emission of weak-light quantum pulses and single-photon detection are coordinated with the main optical transceiver link. The quantum transceiver unit and the main optical transceiver unit share the attitude control signals and optical path alignment information of the pointing, acquisition, and tracking subsystems. For example, an independent optical transceiver antenna is configured on the quantum side, but the turntable pointing angle and fine tracking error compensation are shared with the main link, ensuring that the quantum optical axis is consistent with the service optical axis. In this way, the present invention enables the multiplexing or coordination of weak-light quantum key distribution and the main laser communication terminal in terms of optical link and pointing control. This reduces the hardware cost and size / weight of adding an independent quantum optical path, and maintains the consistency between the quantum optical path and the service optical path by means of shared attitude control and alignment information. This is beneficial for maintaining stable free-space coupling under the condition of integrated terminal, thereby indirectly ensuring that the effective detection rate and quantum bit error rate are within an acceptable range.
[0063] It should be noted that the above is the preferred method for deploying the optical link. Those skilled in the art can also adopt an installation method in which the quantum side is completely independent of the optical engine and only shares the base vibration reduction. The reuse method and the collaborative method can also be switched on orbit according to the mission phase.
[0064] In a preferred embodiment, step S102, calculating the quantum error rate and effective detectivity of the sieved bit string, further includes:
[0065] S401: Randomly select check samples from the sieved bit string and calculate the quantum error rate based on the check samples. The quantum error rate equals the number of bits in the check samples where the results from both parties are inconsistent, divided by the total number of bits in the check samples. For example, 10% of the bits are randomly selected from the sieved bit string as check samples. The communicating parties publish the bit values of the check samples through an authenticated classical channel, count the inconsistent bits, and divide by the total number of bits in the check samples to obtain the quantum error rate for this round.
[0066] S402, the effective detection rate is obtained by calculating the ratio of the number of valid detection events at the receiving end to the total number of pulses transmitted at the transmitting end. A valid detection event refers to a photon detection event that the receiving end successfully detects, and whose corresponding bit participates in the basis vector comparison and is retained. The statistics of valid detection events do not include detector dark count events, background light noise events, or detection events discarded due to basis vector inconsistency. The total number of transmitted pulses refers to the total number of all weak light quantum pulses emitted by the transmitting end in this round of quantum key distribution session. For example, if 10,000 weak light quantum pulses are transmitted in this round, and after screening, at least one event is validly detected and retained, then the effective detection rate is not less than 1 × 10⁻⁴. Thus, this invention provides a clear calculation path for the quantum error rate and the effective detection rate, and defines valid detection events as only those detection results that participate in the basis vector comparison and are retained. This allows the effective detection rate to truly reflect the quantum signal reception quality and the proportion of usable key material, providing a quantifiable and reproducible indicator basis for the joint determination in claim 1, and reducing the risk of misjudgment in key supply caused by inconsistent statistical methods.
[0067] It should be noted that the above is a preferred implementation of S102. Those skilled in the art can adjust the verification sample ratio according to the link conditions, for example, using 5% or 15%. The statistics of effective detection rate can also only include detection results with instantaneous signal-to-noise ratio higher than the threshold, so as to further suppress dark counting and background light interference.
[0068] In a preferred embodiment, the upper limit of the quantum error rate is set within the range of 1% to 11%, and the lower limit of the effective detectivity is determined based on the pulse repetition frequency of the single-photon source and the detection efficiency of the detector. For example, the typical upper limit of the quantum error rate is 5%; when the system operates in a near-Earth orbit space-to-ground link with good atmospheric conditions, it can be appropriately increased to 8%; when the system operates in a ground-to-air link or in a scenario with strong atmospheric turbulence, it can be appropriately reduced to 3%. The typical value of the lower limit of the effective detectivity is 1×10⁻⁴, that is, for every 10,000 weak light quantum pulses transmitted, there is at least one effective detection event. Thus, this invention provides an engineering range for the upper limit of the quantum error rate and correlates the lower limit of the effective detectivity with the calibration parameters of the single-photon source and detector, so that the joint threshold can be adapted and calibrated according to the terminal hardware configuration, taking into account the security margin and key production efficiency under different link conditions, and improving the applicability and operability of the judgment threshold in space-to-ground / air-to-ground laser communication terminals.
[0069] It should be noted that the above thresholds are preferred calibration values. Those skilled in the art can also dynamically adjust the upper limit based on the actual quantum error rate distribution, or prioritize the distribution round with a lower quantum error rate for key supply, provided that the effective detection rate is qualified.
[0070] In a preferred embodiment, when the pointing, capturing, and tracking subsystem loses lock, the transmission of weak light quantum pulses is paused. In this application, losing lock refers to a tracking residual exceeding a preset lock-out threshold, or the received signal-to-noise ratio of the beacon light / communication light falling below a preset lock-out threshold, causing the system to be unable to maintain a stable tracking state of the communication peer. For example, the drive signal of the quantum transmitter is immediately cut off, stopping the transmission of weak light quantum pulses; simultaneously, the output interface of the key management system is locked, preventing the current round of key materials from entering the service encryption module. All temporary key materials generated in this round are cleared; when the pointing, capturing, and tracking subsystem relocks and the optical path returns to a ready state, a new round of weak light quantum key distribution is automatically started. For example, the temporary key materials include the filtered bit string, verification sample data, error correction intermediate data, bit strings that have not undergone privacy amplification, and intermediate calculation results related to this round of distribution. When the above technical solution is adopted, the present invention immediately suspends the weak light quantum pulse emission and clears the temporary key of the current round when the pointing, capturing and tracking lock is lost. This avoids the continued accumulation of unreliable quantum bits and key materials in the unstable stage of the optical path, prevents the transmission of bit errors and detection statistical distortion caused by tracking failure to the business encryption link, and improves the key security handling capability under abnormal link conditions.
[0071] It should be noted that the above is the preferred procedure for handling lost lock. Those skilled in the art may also first suspend transmission, and then clear the temporary key material after the number of consecutive lost locks exceeds a preset number. The conditions for determining whether the optical path is ready to be restored can be the same as or appropriately relaxed as S202.
[0072] In a preferred embodiment, a unique key number is assigned to the generated security key, and key metadata is recorded. For example, key metadata includes key generation time, key validity period, key length, distribution session identifier, communication peer identifier, current round quantum error rate, current round effective detection rate, and usage status flag. When the quantum error rate exceeds a preset upper limit and / or the effective detection rate falls below a preset lower limit, all temporary key materials generated in this round are cleared. For example, temporary key materials include the filtered bit string, verification sample data, error correction intermediate data generated during information coordination, bit strings that have not undergone privacy amplification, and all intermediate calculation results related to this round of key distribution. Thus, traceable management of security keys is achieved through unique key numbers and metadata records, and temporary key materials are simultaneously cleared when indicators fail to meet requirements. This prevents unfinished or unqualified keys from remaining in terminal storage and being mistakenly used, strengthening the security boundary throughout the key's lifecycle and meeting the requirements of engineering operation and maintenance and auditing for traceable and controllable key status.
[0073] It should be noted that the above is a preferred method for key management. Those skilled in the art can also mark unqualified rounds as disabled and delay physical erasure; the key number can also be encoded using a combination of timestamp and terminal identifier.
[0074] In a preferred embodiment, the service data transmitted on the main laser communication link is at least one of telemetry data, remote control commands, or payload data; the service encryption module uses a symmetric block cipher algorithm and / or a national cryptographic algorithm to encrypt or decrypt the service data. For example, symmetric block cipher algorithms include AES-128 and AES-256; national cryptographic algorithms include the SM4 symmetric encryption algorithm.
[0075] When adopting the above technical solution, the present invention clearly defines the application object of the key as the business data such as telemetry, remote control or payload on the main laser communication link, and uses symmetric block cipher or national cryptographic algorithm to implement encryption protection, which is in line with the actual business form of laser communication terminal and is different from radar data transmission schemes that mainly use point cloud XOR encryption.
[0076] In a preferred embodiment, the delivery of a security key to the business encryption module and the initiation of a new round of weak-light quantum key distribution when the key pool balance falls below a preset threshold are both determined based on whether the quantum error rate and effective detection rate simultaneously meet their upper and lower limits. For example, the preset threshold for the key pool is set according to the system's key consumption rate, with a typical value being 20% of the total key pool capacity; key supply or supplementary distribution is only executed when the joint indicators are qualified. By adopting the above technical solution, this invention clearly defines the key application object as business data such as telemetry, remote control, or payloads on the main laser communication link, and uses symmetric block ciphers or national cryptographic algorithms for encryption protection, aligning with the actual business form of laser communication terminals; simultaneously, key supply and key pool replenishment triggering are uniformly incorporated into the joint determination system of quantum error rate and effective detection rate, ensuring that key delivery and replenishment decisions are based on the dual standards of reception quality and security, avoiding blind key supply or replenishment under a single error rate indicator, and enhancing the overall security of the main link communication.
[0077] It should be noted that the above are preferred methods for business encryption and key pool management. Those skilled in the art can also use security keys of different lengths for remote control commands and payload data; the key pool threshold can also be dynamically adjusted according to the task stage.
[0078] In a preferred embodiment, the temperature deviation between the primary mirror, secondary mirror, and / or azimuth turntable motor in the laser communication terminal and a preset steady-state temperature is monitored in real time. When the temperature deviation exceeds a thermal control warning threshold, the upper limit of the quantum bit error rate is appropriately tightened; when the temperature deviation exceeds a thermal control fault threshold, key supply to the service encryption module is suspended until the temperature returns to the preset steady-state window. For example, the typical value of the thermal control warning threshold is ±2℃, and the typical value of the thermal control fault threshold is ±5℃; when the temperature deviation exceeds the warning threshold, the upper limit of the quantum bit error rate can be tightened from 5% to 3%; when the temperature returns to the steady-state window and stabilizes for 30 seconds, the original upper limit of the quantum bit error rate is automatically restored and key supply is resumed. Thus, by adopting the above technical solution, the present invention links the terminal thermal control state with the quantum error rate threshold and key supply control. Before temperature drift causes changes in the optical axis or detector performance, a safety margin is reserved by tightening the upper limit of the error rate. When the temperature drift is severe, key supply is actively suspended to suppress the increase in quantum error rate and the decrease in effective detection rate caused by thermal environment disturbances. This ensures the stability of the joint judgment index during long-term operation and extends the available time of the weak light quantum key distribution link under on-orbit / field conditions.
[0079] It should be noted that the above is a preferred method for thermal control linkage. Those skilled in the art can also extend the single-photon detection integration time during the warning phase without tightening the upper limit of the quantum error rate; the stabilization waiting time after the temperature returns to the steady-state window can also be set to 10 to 60 seconds. It should be further noted that the preset steady-state temperature varies depending on the component model, and those skilled in the art can set it individually for each component based on the specific application scenario, which will not be elaborated here.
[0080] The process of a laser communication terminal quantum key distribution method according to an embodiment of the present invention includes the following steps:
[0081] S501, acquire the tracking residual output of the pointing, acquisition and tracking subsystem, and the received signal-to-noise ratio of the beacon light or communication light at the receiver;
[0082] S502, determine whether the tracking residual is lower than the preset residual upper limit and / or whether the received signal-to-noise ratio is higher than the preset signal-to-noise ratio lower limit; if not, return to S501; if yes, execute S503.
[0083] S503, determine whether the pointing, capturing and tracking subsystem has lost lock; if yes, execute S504 and return to S501; if no, execute S505.
[0084] S504: Pause the transmission of weak light quantum pulses, clear the temporary key material for this round, and lock the output interface of the key management system;
[0085] S505 generates random data bits and basis vectors by a quantum random number generator, sends weak light quantum pulses and performs single-photon detection, exchanges synchronization information through a certified classical channel, publishes the basis vectors and discards inconsistent bits after the session ends, and obtains the sieved bit string.
[0086] S506 monitors the temperature deviation of the primary mirror, secondary mirror and / or azimuth turntable motors in real time; if the temperature exceeds the thermal control warning threshold, the upper limit of quantum bit error rate is tightened; if the temperature exceeds the thermal control fault threshold, the key supply is suspended until the temperature returns to the steady state window.
[0087] S507, extract verification samples to calculate the quantum error rate and statistically analyze the effective detection rate;
[0088] S508, determine whether the quantum error rate is not greater than the upper limit and whether the effective detection rate is not lower than the lower limit; if yes, proceed to S509; if no, proceed to S515.
[0089] S509: Perform error correction and privacy amplification on the filtered bit string to obtain a security key, assign a key number and record key metadata;
[0090] S510 delivers the security key to the business encryption module for encryption or decryption of telemetry, remote control or payload data on the main laser communication link.
[0091] S511, determine whether the key pool balance is lower than the preset threshold; if yes, and the joint indicators are still qualified, return to S505 to start a new round of distribution; otherwise, execute S516.
[0092] S515: Terminate the current round of key distribution, clear the temporary key materials, and record the alarm; the business encryption module continues to use the historical keys within their validity period, and executes S516.
[0093] S516, wait for the next key distribution cycle, or return to S501 after readjusting the optical path according to the pointing, acquisition and tracking status.
[0094] It should be noted that the above process is a preferred serial arrangement of executable logic; S506 can be executed in parallel with S507, and S504 can be inserted at any time during the execution of S505; those skilled in the art can refine S505 into S301 to S303 and S507 into S401 to S402 according to the terminal architecture.
[0095] After terminating the current key distribution in S104, the system automatically waits for the next key distribution cycle, or readjusts the optical path based on the status of the pointing, capturing, and tracking subsystems before executing S101. During this period, the service encryption module continues to use the previously delivered key that is still valid. Those skilled in the art will understand that the step numbers in S101 to S104 and in each preferred embodiment are only used to illustrate logical relationships; the optical path ready step corresponding to claim 7 is executed before S101, and the thermal control monitoring step corresponding to claim 10 can be executed in parallel with S102. The above order does not constitute a limitation on the scope of protection of this invention.
[0096] Those skilled in the art will understand that all or part of the processes in the method of the above embodiment of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable storage medium can include any entity or device capable of carrying computer program code, media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory, random access memory, electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable storage medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable storage medium does not include electrical carrier signals and telecommunication signals.
[0097] The various component embodiments of the present invention can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the server or client according to embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (e.g., a PC program and PC program products) for performing some or all of the methods described herein. Such programs implementing the present invention can be stored on a PC-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0098] Those skilled in the art will understand that although some embodiments described herein include certain features included in other embodiments but not others, combinations of features from different embodiments are intended to be within the scope of this application and form different embodiments. For example, any of the claimed embodiments in the claims of this application can be used in any combination.
[0099] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will all fall within the scope of protection of the present invention.
Claims
1. A quantum key distribution method for a laser communication terminal, characterized in that, After the free-space optical path between the laser communication terminal and the communication peer is ready, the following steps are included: Weak light quantum key distribution is performed between the laser communication terminal and the communication peer to obtain the sieved bit string; Calculate the quantum error rate and effective detection rate of the sieved bit string; When the quantum error rate is not greater than the preset upper limit of quantum error rate and the effective detection rate is not lower than the preset lower limit of effective detection rate, error correction and privacy amplification are performed on the sieved bit string to obtain a security key, and the security key is delivered to the service encryption module of the laser communication terminal for encryption or decryption of service data on the main laser communication link. When the quantum error rate is greater than the upper limit of the quantum error rate and / or the effective detection rate is lower than the lower limit of the effective detection rate, the current round of key distribution is terminated and no key is supplied to the business encryption module.
2. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, The step of performing weak light quantum key distribution to obtain the sieved bit string includes: Random data bits, random encoding basis vectors, and random measurement basis vectors are generated by a quantum random number generator, and weak light quantum pulses are sent to perform single-photon detection. The two parties exchange synchronization information through the authentication classic channel and disclose their respective basis vector selections at the end of the current session. Discard bits with inconsistent basis vectors to obtain the sieved bit string.
3. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, The steps for calculating the quantum error rate and effective detection rate of the sieved bit string include: Randomly select verification samples from the sieved bit string, and calculate the quantum bit error rate based on the verification samples; The effective detection rate is obtained by calculating the proportion of the number of valid detection events at the receiving end to the total number of pulses transmitted at the transmitting end. The effective detection event refers to a photon detection event in which the receiver successfully detects a photon and the corresponding bit is included in the basis vector comparison and retained.
4. The quantum key distribution method for laser communication terminals according to claim 3, characterized in that, The upper limit of the quantum error rate ranges from 1% to 11%, and the lower limit of the effective detectivity is determined based on the pulse repetition frequency of the single-photon source and the detection efficiency of the detector.
5. The quantum key distribution method for laser communication terminals according to claim 2, characterized in that, The emission of the weak quantum pulse and the single-photon detection are multiplexed using the main optical transceiver link of the laser communication terminal; or The emission of the weak light quantum pulse and the single-photon detection work together in conjunction with the main optical transceiver link of the laser communication terminal. The quantum transceiver unit and the main optical transceiver unit share the attitude control signals and optical path alignment information of the pointing, acquisition and tracking subsystems.
6. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, Assign a unique key number to the generated security key and record key metadata; when the quantum error rate is greater than the preset upper limit of quantum error rate and / or the effective detection rate is lower than the preset lower limit of effective detection rate, clear all temporary key materials generated in this round.
7. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, The conditions for determining that the free space optical path between the laser communication terminal and the communication peer is ready are: the tracking residual is lower than the preset upper limit of the residual, and / or the received signal-to-noise ratio of the beacon light or communication light is higher than the preset lower limit of the signal-to-noise ratio.
8. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, When the pointing, capturing, and tracking subsystem loses its lock, the emission of the weak light quantum pulse is paused, and all temporary key materials generated in this round are cleared.
9. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, The service data transmitted on the main laser communication link is at least one of telemetry data, remote control commands, or payload data; the service encryption module uses a symmetric block cipher algorithm and / or a national cryptographic algorithm to encrypt or decrypt the service data; and / or The delivery of the security key to the business encryption module and the initiation of a new round of weak light quantum key distribution when the key pool balance is lower than a preset threshold are both determined based on whether the quantum error rate and the effective detection rate simultaneously meet the upper and lower limits.
10. The quantum key distribution method for laser communication terminals according to claim 1, characterized in that, The temperature deviation between the primary mirror, secondary mirror, and / or azimuth turntable motor in the laser communication terminal and the preset steady-state temperature is monitored in real time; when the temperature deviation exceeds the thermal control early warning threshold, the upper limit of the quantum error rate is appropriately tightened. When the temperature deviation exceeds the thermal control fault threshold, the key supply to the service encryption module is suspended until the temperature returns to the preset steady-state window.
Citation Information
Patent Citations
Laser radar data secure transmission method and system based on quantum key distribution
CN122027309A