A denial of service attack resistant routing method and apparatus
Patent Information
- Application Number
- CN202611170788.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-04
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]当前现有的防御方案在应对DoS攻击和保障密钥可用性方面存在诸多不足,主要表现为以检测为主(如密钥池余量监测),缺乏网络通信层的主动防护机制
[0016]相比起现有技术,本发明通过多指标融合检测机制实时扫描网络链路,精准识别受拒绝服务(DoS)攻击的链路,并动态调整其密钥池的补给周期与最大容量,以增强密钥供应能力。其次,实施业务分级路由策略:为高安全业务计算最短有效路径,并严格分配高新鲜度的一级时隙资源;为低安全业务提供多路径选择,并在所有路径均受攻击时降级使用经典加密保通。最后,结合网络安全态势评估得分,自适应执行密钥池的部分更新或全量更新。
Smart Images

Figure CN122845276A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum communication technology, and in particular to a routing method and apparatus for resisting denial-of-service attacks. Background Technology
[0002] With the continuous development of quantum key distribution (QKD) technology, it uses the principles of quantum mechanics to establish an uneavesdroppable key between communicating parties, providing a high level of security for information transmission and demonstrating great application potential in the field of secure communication.
[0003] However, despite the theoretical information-theoretic security of QKD, quantum key distribution networks still face various security threats in practical applications, among which denial-of-service (DoS) attacks are relatively common and severely destructive. In quantum key distribution networks, DoS attacks can originate from multiple layers, including the physical layer, data link layer, and network layer. Attackers consume network resources by generating large bursts of traffic, interfering with quantum channels, or launching malicious requests to network nodes, leading to a decrease in key generation rate, depletion of key pool resources, and ultimately paralyzing network services, severely compromising key availability. Therefore, effectively resisting DoS attacks and ensuring key availability in quantum key distribution networks has become a critical issue that urgently needs to be addressed.
[0004] Current defense solutions have several shortcomings in addressing DoS attacks and ensuring key availability. These shortcomings primarily stem from a reliance on detection (such as key pool balance monitoring) and a lack of proactive protection mechanisms at the network communication layer. Furthermore, existing solutions suffer from flawed path redundancy designs, failing to consider coordinated attacks on multiple links or core nodes when employing backup path strategies. Additionally, current technologies neglect differences in business security, failing to differentiate between the protection needs of high- and low-security services. This leads to high-security services being more prone to congestion due to resource contention, and the static key update cycle is easily predictable by attackers. Furthermore, outdated key pool slots that are not updated in a timely manner can pose a serious risk of key theft. Summary of the Invention
[0005] This invention provides a routing method and apparatus to resist denial-of-service attacks. By detecting DoS attacks through multiple indicators and dynamically adjusting the key pool, combined with service hierarchical routing and time slot freshness mechanism, it effectively resists attacks, reduces service blocking rate, avoids theft risk, and ensures network key availability.
[0006] To achieve the above objectives, a first aspect of this application provides a routing method resistant to denial-of-service attacks, comprising: Regularly scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links. Receive service requests and distinguish between high-security-level and low-security-level services; For high-security-level services, the D algorithm is used to calculate the preferred path, and first-level time slot resources are allocated to the valid preferred path. For low-security-level services, the K-shortest path algorithm is used to calculate multiple shortest paths, and second-level time slot resources are allocated to one of the valid shortest paths. The time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, and the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness. The first time slot freshness is less than the second time slot freshness. The keys in the key pool are updated based on the preset partial update cycle, full update cycle, and security posture assessment score.
[0007] In one possible implementation of the first aspect, the periodic scanning of all links in the network and the identification of attacked links resistant to denial-of-service attacks based on a preset multi-index fusion detection mechanism specifically includes: Periodically scan all links in the network to obtain flags for abnormal key generation rate, abnormal link bit error rate, abnormal node request frequency, and abnormal traffic burst characteristics. The weighted score is calculated based on the values of the key generation rate anomaly flag, the link error rate anomaly flag, the node request frequency anomaly flag, and the traffic burst characteristic anomaly flag. If the weighted score of a link is greater than the attack threshold, the link is added to the attacked link set.
[0008] In one possible implementation of the first aspect, the dynamic adjustment of the key pool parameters of the attacked link specifically includes: The dynamic replenishment period is calculated based on the baseline replenishment period, network load rate, service urgency, and adjustment coefficient. Boundary constraints are applied in conjunction with network status. When the network load rate is greater than the set high load threshold or a denial-of-service attack is detected, the dynamic replenishment period is not less than the minimum replenishment period. When the network load rate is less than the set low load threshold and there are no network anomalies, the dynamic replenishment period does not exceed the maximum replenishment period. Based on the baseline capacity, security factor, the proportion of the number of currently attacked links to the total number of network links, and the proportion of historical peak attack strength to reference attack strength, the increase in the maximum capacity of the key pool is calculated to obtain the adjusted maximum capacity, and the adjusted maximum capacity does not exceed the hardware limit. For links where multiple indicators have returned to normal, update the key pool parameters of the link in a timely manner and remove the link from the set of attacked links.
[0009] In one possible implementation of the first aspect, the calculation of the preferred path using the D algorithm specifically includes: The D algorithm is used to calculate multiple candidate paths from the source node to the destination node, and the path with the shortest number of hops is selected as the preferred path from the multiple candidate paths. Each link on the preferred path is checked one by one to see if it belongs to the set of attacked links. If none of the links on the preferred path belong to the set of attacked links, then the preferred path is determined to be valid.
[0010] In one possible implementation of the first aspect, allocating first-level time slot resources to the valid preferred path specifically includes: Collect key pool time slot resource information for each link on the effective preferred path, and calculate the number of time slots required by the service based on the number of keys required by the service and the link key generation rate; If the number of time slots in the primary available time slot set is sufficient to meet the number of time slots required by the business, then primary time slot resources will be allocated to the business first; otherwise, the business request will be blocked.
[0011] In one possible implementation of the first aspect, the K-shortest path algorithm is used to calculate multiple shortest paths, and secondary time slot resources are allocated to one of the valid shortest paths, specifically including: Traverse the multiple shortest paths and find the path with an unattacked link as the valid shortest path for the allocation of secondary time slot resources; If all of the shortest paths pass through the attacked link, then other key encryption schemes will be used.
[0012] In one possible implementation of the first aspect, when allocating resources for the effective shortest path, the allocation also includes allocating wavelength resources for low-security-level services: Following the principles of wavelength consistency and wavelength continuity, a first-hit algorithm is used to select a suitable wavelength.
[0013] In one possible implementation of the first aspect, the keys in the key pool are updated according to a preset partial update cycle, a full update cycle, and a security posture assessment score, specifically including: The security situation assessment score is calculated by combining the key pool consumption rate, attack detection flags, and business importance level. When the running time reaches the preset partial update cycle, a partial update is performed, or when the security situation assessment score is less than the set low-risk threshold, a partial update is performed; when performing a partial update, a first proportion of keys are randomly selected from the key pool to replace the original key, a new key is generated and synchronously updated to the corresponding link node; When the security situation assessment score is greater than or equal to the low-risk threshold and less than the set high-risk threshold, the first ratio is increased to the second ratio to perform a partial update as a transitional strategy, where the second ratio is greater than the first ratio.
[0014] In one possible implementation of the first aspect, updating the keys in the key pool based on a preset partial update cycle, a full update cycle, and a security posture assessment score specifically includes: A full update is performed when the runtime reaches the full update cycle, or when an attack indicating key leakage is detected, or when an attack exceeding the duration and strength thresholds is detected, or when the security situation assessment score is greater than or equal to the set high-risk threshold. During a full update, all keys in the key pool are replaced, and the current business connection using the old key is forcibly interrupted, requiring renegotiation of the key before communication is restored.
[0015] A second aspect of this application provides a routing apparatus resistant to denial-of-service attacks, comprising: The scanning and adjustment module is used to periodically scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links. The service differentiation module is used to receive service requests and differentiate between high-security-level services and low-security-level services. The resource allocation module is used to calculate the preferred path using the D algorithm for high-security-level services and allocate first-level time slot resources to the valid preferred path; for low-security-level services, it uses the K-shortest path algorithm to calculate multiple shortest paths and allocates second-level time slot resources to one of the valid shortest paths; the time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness, and the first time slot freshness is less than the second time slot freshness; The key update module is used to update the keys in the key pool according to the preset partial update cycle, full update cycle and security status assessment score.
[0016] Compared to existing technologies, this invention uses a multi-indicator fusion detection mechanism to scan network links in real time, accurately identify links under denial-of-service (DoS) attacks, and dynamically adjust the replenishment cycle and maximum capacity of their key pools to enhance key supply capabilities. Secondly, it implements a service-tiered routing strategy: calculating the shortest effective path for high-security services and strictly allocating high-freshness first-level time slot resources; providing multiple path options for low-security services, and downgrading to classic encryption to ensure connectivity when all paths are under attack. Finally, based on network security situation assessment scores, it adaptively performs partial or full updates to the key pool. First, in attack scenarios, dynamic key pool management and hierarchical routing effectively alleviate resource consumption, significantly reduce service blockage rates, and ensure high key availability. Second, the innovative introduction of a time slot freshness threshold avoids the long-term retention of old time slots, preventing key theft and replay attacks and achieving collaborative optimization of confidentiality. Third, through a flexible design that prioritizes high-security services for fresh quantum resources and degrades low-security services to ensure connectivity, efficient utilization of network resources is achieved, improving the overall connectivity and stability of the entire network. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a routing method for resisting denial-of-service attacks according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a routing device for resisting denial-of-service attacks provided in an embodiment of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] To resolve the above issues, please refer to [link / reference]. Figure 1 An embodiment of the present invention provides a routing method for resisting denial-of-service attacks, comprising: S10. Periodically scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on the preset multi-index fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links.
[0020] S11. Receive service requests and distinguish between high-security-level services and low-security-level services.
[0021] S12. For high-security-level services, the preferred path is calculated using the D algorithm, and first-level time slot resources are allocated to the valid preferred path; for low-security-level services, multiple shortest paths are calculated using the K-shortest path algorithm, and second-level time slot resources are allocated to one of the valid shortest paths; the time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness, and the first time slot freshness is less than the second time slot freshness.
[0022] S13. Update the keys in the key pool according to the preset partial update cycle, full update cycle and security status assessment score.
[0023] In S10 and S13, underlying link status monitoring and dynamic key pool replacement are performed. The underlying network links are periodically scanned, and a multi-indicator fusion detection mechanism accurately identifies attacked links suffering from DoS attacks, directly and dynamically adjusting the key pool parameters of those links. Simultaneously, a preset partial or full update cycle, along with a real-time calculated security posture assessment score (let this score be...), are used. (Used to quantify the overall threats and load status currently faced by the network), adaptively triggering the cleaning and replacement of old keys in the pool.
[0024] This mechanism, combining passive monitoring with proactive compensation, enables the network to offset the malicious consumption of key resources by denial-of-service attacks, ensuring the basic key supply capacity even in extremely harsh environments. Furthermore, the dynamic replacement strategy based on situational awareness prevents attackers from long-term probing and decryption of outdated keys, thus strengthening the underlying security foundation.
[0025] S11 and S12 involve hierarchical routing of services and utilization of time slot freshness matching. After receiving a service request, the application layer performs security-based traffic reduction and triage. For high-security services, the D (Dijkstra) algorithm is used to quickly identify the preferred path and force the allocation of a first-level time slot resource with an extremely short dwell time (assuming the key's dwell time in the pool is...). The allocation requirement is For low-security-level services, the K-shortest path algorithm is used to discover multiple alternative shortest paths, and secondary time slot resources with a wider freshness requirement are allocated (the allocation requirement is...). Due to the freshness of the first time slot. Less than the freshness of the second time slot (That is, the smaller the value, the shorter the retention time and the fresher the key.) For example, core confidential data will be assigned a newly generated, absolutely fresh key, while ordinary file transfers can reuse redundant keys that were generated a little longer but are still within the security threshold. The aforementioned design breaks the disorderly competition for quantum resources between high- and low-security services in traditional networks, enabling core high-security services to have priority access to the freshest keys that are most difficult to crack without interference, significantly reducing the routing congestion rate of critical services. At the same time, the system provides ordinary services with space for multi-path exploration and secondary resource matching, achieving efficient utilization of network resources and a comprehensive improvement in network connectivity without blindly increasing hardware costs.
[0026] In summary, this solution deeply integrates the underlying "dynamic self-healing and key replacement" with the application layer's "hierarchical scheduling and freshness ladder matching" to build a highly available elastic routing system that can ensure the absolute confidentiality of core business keys while taking into account the connectivity of network services and resource utilization when subjected to denial-of-service attacks.
[0027] For example, the periodic scanning of all links in the network, and the identification of attacked links resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, specifically includes: Periodically scan all links in the network to obtain flags for abnormal key generation rate, abnormal link error rate, abnormal node request frequency, and abnormal traffic burst characteristics.
[0028] The weighted score is calculated based on the values of the key generation rate anomaly flag, the link error rate anomaly flag, the node request frequency anomaly flag, and the traffic burst characteristic anomaly flag. If the weighted score of a link is greater than the attack threshold, the link is added to the attacked link set.
[0029] The above scheme is based on joint analysis and quantitative evaluation of multi-dimensional cross-layer characteristics. The system periodically scans the underlying links to extract four core anomaly flags reflecting the overall network status: anomaly flags for key generation rate and link bit error rate reflecting the quantum physics layer status, and anomaly flags for node request frequency and traffic burst characteristics reflecting the classical network communication status. ① Anomaly in key generation rate refers to real-time monitoring of the key generation rate per unit time. When it is below a preset threshold (Right now ① Mark as suspected attack; ② Sudden increase in link bit error rate, i.e., monitor link bit error rate. If it exceeds the normal baseline value in a short period of time of times (i.e.) ,in Generally, a value of 3 to 5 is used to mark it as abnormal; ③ Abnormal node request frequency, that is, the frequency of key requests by the node per unit time. When it exceeds the preset threshold Furthermore, requests from sources that exhibit centralized or randomized characteristics of DDoS attacks are marked as abnormal; ④ Traffic burst detection, i.e., monitoring classic channel traffic, if within a time interval... Internal flow exceeds historical average of More than twice ( If a key pool consumption accelerates (typically between 5 and 10), it is marked as abnormal. The system calculates a weighted score based on the values of the four flags. If the weighted score of a link exceeds the preset attack threshold, it is determined that it has suffered a denial-of-service attack and is added to the set of attacked links. In practice, the system assigns corresponding weight coefficients to the features of these four dimensions (assuming the weights of each flag bit are respectively...). , , , ), and combined with the real-time values of each flag bit (assuming the value is ), The comprehensive weighted score of this link is calculated using mathematical models such as linear superposition. in For the first The weighting coefficients of each anomaly flag bit. This corresponds to the value of the anomaly flag. For example, if a link experiences a traffic surge only due to a normal business peak, only the traffic surge characteristic flag might be triggered, and the overall weighted score will be affected. It remains at a low level; however, if it encounters a real denial-of-service attack, the attacker will use a massive number of invalid requests to congest the channel, causing not only a simultaneous surge in traffic and node request frequency, but also further squeezing resources and causing a sharp drop in the key generation rate. At this time, multiple high-weight flag bits are triggered simultaneously, resulting in a weighted score. The attack threshold will be quickly accumulated and exceed the preset threshold, which will allow the system to diagnose the attack on the link and isolate it into the set of attacked links.
[0030] The aforementioned multi-indicator fusion detection mechanism effectively overcomes the shortcomings of traditional network defenses that rely on single indicators (such as bandwidth utilization or single-end error rate), which are prone to false positives and false negatives. It achieves a technological leap from single-point monitoring to multi-dimensional cross-verification. By weighting and quantizing quantum-level physical key indicators with classical-level network traffic characteristics, the system can extremely sensitively and accurately depict complex attack profiles, perfectly filtering out interference from normal network fluctuations or benign congestion. This judgment method, based on quantitative scores, not only significantly improves the accuracy of identification and system robustness against new and covert denial-of-service attacks, but also provides extremely accurate and reliable pre-decision basis for subsequently triggering dynamic key pool compensation and implementing business evasion routing.
[0031] For example, the dynamic adjustment of the key pool parameters of the attacked link specifically includes: The dynamic replenishment period is calculated based on the baseline replenishment period, network load rate, service urgency, and adjustment coefficient. Boundary constraints are applied in conjunction with network status. When the network load rate is greater than the set high load threshold or a denial-of-service attack is detected, the dynamic replenishment period is not less than the minimum replenishment period. When the network load rate is less than the set low load threshold and there are no network anomalies, the dynamic replenishment period does not exceed the maximum replenishment period. Based on the baseline capacity, security factor, the proportion of the number of currently attacked links to the total number of network links, and the proportion of historical peak attack strength to reference attack strength, the increase in the maximum capacity of the key pool is calculated to obtain the adjusted maximum capacity, and the adjusted maximum capacity does not exceed the hardware limit. For links where multiple indicators have returned to normal, update the key pool parameters of the link in a timely manner and remove the link from the set of attacked links.
[0032] The above steps are based on a key resource elastic scaling and self-healing mechanism with deep awareness of network operation status. In the calculation of the dynamic replenishment cycle, the system uses the baseline replenishment cycle under normal conditions as the base, and introduces the network load rate reflecting the current concurrent service pressure, the service urgency that distinguishes service priorities, and the adjustment coefficient used for smooth calculation to perform joint calculations to obtain the dynamic replenishment cycle. At the same time, in order to cope with extreme scenarios, the system applies strict boundary constraints: for example, when the network load rate exceeds the set high load threshold or a denial-of-service attack is diagnosed, the dynamic replenishment cycle is forced to be no less than the minimum replenishment cycle (to prevent frequent triggering of the refresh mechanism from overwhelming the system's computing power), while when the network is in a healthy idle state below the low load threshold, it is limited to not exceeding the maximum replenishment cycle (to prevent excessive key aging). In calculating the maximum capacity expansion of the key pool, the system starts with a baseline capacity, combines a preset security coefficient, and deeply integrates indicators representing "attack breadth" (i.e., the proportion of currently attacked links to the total number of network links) and indicators representing "attack depth" (i.e., the ratio of historical peak attack strength to reference attack strength) to accurately calculate the required capacity increase, thereby deriving the adjusted maximum capacity that will never exceed the upper limit of the underlying hardware. Furthermore, the system maintains real-time monitoring of link health. Once it confirms that multiple indicators for a link have returned to normal, it immediately triggers a state rollback, updates and resets the key pool parameters for that link, and securely removes it from the set of attacked links.
[0033] Specifically, during the dynamic adjustment of the replenishment cycle, the system can first define the network load rate. (in This represents the number of currently active services. (Based on the network's maximum concurrent service capacity) and the urgency of services that are prioritized. Subsequently, the system uses the baseline replenishment cycle under normal conditions. Based on, combined with adjustment coefficient Through formula Calculate the dynamic replenishment cycle Simultaneously, strict boundary constraints are imposed: when the network load rate... Limit when high load threshold is exceeded or when a denial-of-service (DoS) attack is detected. Not less than the minimum replenishment cycle However, under low load and without abnormalities, its supply cycle is limited to no more than the maximum replenishment cycle. ( (Generally, the timeframe is 60-120 minutes). For dynamic adjustments to the maximum capacity, the system comprehensively assesses the current attack breadth (i.e., the number of currently attacked links). Total number of network links The ratio of attack intensity to attack depth (i.e., historical peak attack intensity) Compared with reference attack strength (proportion), using the formula (in For safety margin, a value of 1.2 to 2.0 is generally used. Calculate the expansion increment based on the baseline capacity. Finally, the adjusted maximum capacity was obtained. and with hardware limits As a final truncation protection, it prevents memory overflow.
[0034] This flexible parameter adjustment mechanism enables the network to transform from a mechanical, static defense to an intelligent, dynamic countermeasure when dealing with denial-of-service attacks, significantly improving network resource utilization efficiency and survivability in extreme environments. Through dynamic scaling of replenishment cycles based on load rate and urgency, coupled with strict boundary constraints, the system is prevented from collapsing due to endless key generation requests during peak traffic or attacks, while also avoiding unnecessary waste of computing resources when the network is completely idle. Furthermore, dynamic maximum capacity expansion based on the breadth and depth of attacks provides a highly precise and tailored "pressure buffer" for attacked links, effectively absorbing the key consumption surge caused by sudden attacks and greatly delaying or preventing the key pool from drying up. Finally, combined with agile parameter reset and state recovery mechanisms, the entire system forms a virtuous cycle of "perception-expansion-resistance-self-healing," preventing links from being falsely killed or resources from being locked indefinitely, thereby fundamentally enhancing the network's continuous supply capacity and overall robustness.
[0035] For example, the calculation of the preferred path using the D algorithm specifically includes: The D algorithm is used to calculate multiple candidate paths from the source node to the destination node, and the path with the shortest number of hops is selected as the preferred path from the multiple candidate paths. Each link on the preferred path is checked one by one to see if it belongs to the set of attacked links. If none of the links on the preferred path belong to the set of attacked links, then the preferred path is determined to be valid.
[0036] The above method implements a cross-validation mechanism based on classical routing algorithm optimization and dynamic network security status. First, the network topology is abstracted into a graph model. (in Represents the set of quantum nodes in the network. The system uses a set of links between nodes and employs Dijkstra's algorithm to quickly diverge and search the graph, calculating multiple feasible candidate paths from the source node to the destination node. Redundant routes are directly eliminated, and the path with the fewest relay nodes and shortest hop count is selected as the initial preferred path. Subsequently, a veto logic for security isolation is introduced, examining each link along this preferred path to check if they match the "attacked link set" detected at the lower level. For example, when transmitting a highly confidential document, the system not only plans a "direct express lane" with the fewest relay stations but also rigorously examines each segment of the lane like a security check. Only when it is confirmed that the entire line is 100% free from any denial-of-service (DoS) attacks (i.e., all links are not in the attacked set) will the transmission be finally allowed, and it will be determined as a valid preferred path for subsequent resource allocation. By locking onto the path with the shortest hop count, the end-to-end communication latency is significantly reduced from a physical network architecture perspective, fundamentally decreasing the total consumption of quantum key pools along the route for a single service, effectively conserving network resources. The subsequent rigorous segment-by-segment link screening mechanism is equivalent to adding a front-end physical firewall to this high-priority path, preventing the blind introduction of core confidential services into "black hole" links that are already congested or paralyzed by attackers or at high risk of eavesdropping. This two-layer screening not only avoids service interruptions and communication resource waste caused by link unavailability but also ensures that high-secret data always flows within the purest and most efficient absolutely secure channel in the network, significantly improving the resilience of core communications under extreme attack scenarios.
[0037] For example, allocating first-level time slot resources to the valid preferred path specifically includes: Collect key pool time slot resource information for each link on the effective preferred path, and calculate the number of time slots required by the service based on the number of keys required by the service and the link key generation rate; If the number of time slots in the primary available time slot set is sufficient to meet the number of time slots required by the business, then primary time slot resources will be allocated to the business first; otherwise, the business request will be blocked.
[0038] The implementation principle of this step is based on precise resource requirement quantification and a rigorous freshness matching mechanism. The system first comprehensively collects real-time time-slot resource information of the key pool for each link along the preferred path that has already undergone security verification, and then introduces a quantitative evaluation formula: Let the number of keys required by the current business be... The key generation rate of the corresponding link is The system calculates This accurately determines the actual number of time slots required for the service. Subsequently, the system executes a strict "quality over quantity" allocation logic, allocating the required number of time slots. The system compares the available time slots with the available first-level time slots that meet extremely high freshness requirements. For example, when processing a classified military instruction, the system rigorously checks whether the current freshest first-level time slot resources are sufficient; if the surplus is enough to cover... If the system prioritizes allocating sufficient high-quality resources, it will not compromise and downgrade to use older resources in the pool if there is insufficient high-freshness resources. Instead, it will decisively trigger the protection mechanism and directly determine that the business request is blocked. It should be noted that the slot freshness parameter Its calculation formula is ,in Representing the current moment, This represents the time when the key was generated or the most recent update within that time slot. The value reflects the time difference of a key's residence in the pool; the smaller the difference, the fresher the key. Subsequently, the system imposed stringent security constraints on high-security-level services, setting differentiated time-slot freshness thresholds. (For example, forcibly limiting access to an extremely short time window of 10 minutes to 1 hour). During the resource selection process, the system executes a "best of the best" admission logic, only accepting resources whose dwell time meets the criteria. Fresh time slots are included in the first-level available time slot set, and during actual allocation, priority is given to allocating the highest freshness (i.e., retention time) slots to high-security-level services. The absolute freshest time slot resource (with the lowest value).
[0039] This quantification mechanism, based on precise timestamp calculation and stringent threshold access, constructs a dynamic, time-dimensional encryption defense for core data transmission. By forcing high-security services to use only newly generated, short-lived key resources, the system completely eliminates the risk of older time slots being continuously probed, intercepted, or even reverse-engineered by attackers due to long-term retention. Simultaneously, the "greedy" scheduling strategy, which prioritizes the allocation of the freshest resources, greatly enhances the unpredictability and timeliness of the key stream, giving the network natural immunity to high-dimensional threats such as complex key replay attacks. This achieves deep synergistic optimization of key confidentiality and high service availability at the underlying logic level.
[0040] For example, the K-shortest path algorithm is used to calculate multiple shortest paths, and secondary time slot resources are allocated to one of the valid shortest paths, specifically including: Traverse the multiple shortest paths and find the path with an unattacked link as the valid shortest path for the allocation of secondary time slot resources; If all of the shortest paths pass through the attacked link, then other key encryption schemes will be used.
[0041] For low-security services, the system first employs the K-Shortest Path (KSP) algorithm (where K represents the total number of shortest paths calculated by the system) to perform a divergent search in the network topology, generating a candidate set containing multiple routing schemes. Subsequently, the system traverses these K candidate paths, attempting to find a clean path that completely avoids the attacked link. Once found, it is treated as the valid shortest path and allocated secondary time slot resources with relatively lenient latency constraints (e.g., allowing reuse of redundant quantum keys with slightly longer generation times but still within the basic security threshold). However, in scenarios where the network encounters extreme denial-of-service (DoS) attacks, if the traversal reveals that all K candidate paths are susceptible to attack and pass through the attacked link, the system does not directly reject the service. Instead, it triggers a degradation and continuity protection mechanism, automatically switching to other classic key encryption schemes (such as the AES algorithm) to take over the data encryption transmission requirements of the service. For example, when transmitting routine environmental monitoring logs (low security level), the system will first try its best to find an attack-free quantum channel through K alternative paths for transmission; if the entire network suffers a large-scale attack that causes all quantum paths to be blocked, the system will automatically downgrade to use classical encryption to send the logs back, ensuring uninterrupted communication.
[0042] A relatively lenient slot freshness threshold has been set for low-security-level services. (satisfy The typical value range is 2 to 24 hours, with 4 to 12 hours being preferred. This threshold is significantly wider than the stringent requirements for high-security-level services. Limitations. On the selected valid path, the system also collects link time slot resource information and checks time slot freshness. Compliance assessment: As long as the slot freshness is met. This means that low-security-level services are allowed to use secondary time slot resources with relatively long dwell times and slightly lower freshness during resource allocation, thereby achieving on-demand, tiered resource matching and scheduling.
[0043] This tiered and differentiated loose freshness matching mechanism significantly improves network resource utilization efficiency and service accessibility while ensuring basic security. By allowing secondary time slots with longer retention times in the low-security-level service reuse pool, but still within the security threshold, the system effectively avoids the needless consumption of valuable high-freshness metric keys on ordinary services, thereby achieving peak-shifting and reasonable resource allocation for high and low-security services. At the same time, the wider threshold range greatly expands the available resource candidate space for low-priority services, significantly reducing the probability of blocking caused by resource mismatch in ordinary services, and ensuring that low-security-level services can still maintain extremely high service accessibility and service continuity in high-concurrency or complex network environments.
[0044] For example, when allocating resources for the effective shortest path, the method also includes allocating wavelength resources for low-security-level services: Following the principles of wavelength consistency and wavelength continuity, a first-hit algorithm is used to select a suitable wavelength.
[0045] When allocating underlying physical channels for the shortest effective path of low-security services, the system strictly adheres to the two core physical principles of quantum key distribution network transmission: "wavelength continuity" and "wavelength consistency." This requires that services occupy the same conflict-free wavelength channel end-to-end along the entire transmission path from the source node to the destination node. To quickly complete resource scheduling under these strict physical constraints, the system employs a "First-Fit" algorithm. This algorithm rapidly traverses the list of available wavelength resources along the path in a fixed sequence. Once the first idle wavelength that simultaneously satisfies the consistency and continuity conditions is found, the search immediately stops and it is assigned to the service, thus completing the construction of the underlying physical channel.
[0046] For example, the keys in the key pool are updated according to a preset partial update cycle, a full update cycle, and a security posture assessment score, specifically including: The security situation assessment score is calculated by combining the key pool consumption rate, attack detection flags, and business importance level. When the running time reaches the preset partial update cycle, a partial update is performed, or when the security situation assessment score is less than the set low-risk threshold, a partial update is performed; when performing a partial update, a first proportion of keys are randomly selected from the key pool to replace the original key, a new key is generated and synchronously updated to the corresponding link node; When the security situation assessment score is greater than or equal to the low-risk threshold and less than the set high-risk threshold, the first ratio is increased to the second ratio to perform a partial update as a transitional strategy, where the second ratio is greater than the first ratio.
[0047] The system first comprehensively considers the key pool consumption rate, underlying attack detection flags, and the importance level of current services to quantitatively calculate a security posture assessment score that reflects the overall network threat situation. Subsequently, the system combined this with a preset low-risk threshold. With high risk threshold Deploy tiered logic response: When the runtime reaches a preset normal cycle (e.g., 24 hours) or the security situation assessment score is in the low-risk range (i.e., When no attack is detected and the error rate is normal, the system triggers a basic update, randomly selecting only the first proportion from the key pool. (e.g., 20%~30%) of the old keys are replaced, generated, and synchronized to the corresponding nodes; while when the security situation assessment score climbs to the medium risk range (i.e., When the system detects an increase in potential threats, it automatically switches to a transition strategy, changing the key replacement ratio from the initial ratio. Actively upgrade to a larger second proportion ( (e.g., 40%~50%), by increasing the intensity of key cleaning to smoothly cope with the increasing security risks.
[0048] This situational score-driven, tiered partial update strategy achieves a high degree of balance between ensuring high business continuity and implementing proactive security defenses. When the network is operating smoothly or in a low-risk phase, a lower initial update ratio is used to minimize network jitter and computational overhead caused by large-scale key renegotiation for concurrent business communications, ensuring smooth operation of services with high load and high continuity requirements. In the medium-risk phase, where threats are just emerging, an adaptive transition to a second update ratio achieves a preventative defense contraction, accelerating the replacement cycle of potentially compromised or outdated keys, effectively blocking the possibility of attackers accumulating key intelligence, and preventing widespread system service outages caused by sudden full updates.
[0049] For example, updating the keys in the key pool based on preset partial update cycles, full update cycles, and security posture assessment scores specifically includes: A full update is performed when the runtime reaches the full update cycle, or when an attack indicating key leakage is detected, or when an attack exceeding the duration and strength thresholds is detected, or when the security situation assessment score is greater than or equal to the set high-risk threshold. During a full update, all keys in the key pool are replaced, and the current business connection using the old key is forcibly interrupted, requiring renegotiation of the key before communication is restored.
[0050] It should be noted that a full update has a higher execution priority than a partial update.
[0051] This embodiment is based on a key full reset and service forced circuit breaker reconnection mechanism driven by strong security constraints. The system monitors the network operation status and security indicators in real time, and immediately performs a full (all) update when any of the following high-risk trigger conditions are met: ① The running time reaches the preset periodic full update cycle. (Generally 7-30 days); ② Detection of key leakage risk (e.g., persistently abnormal link error rate and a sudden drop in key generation rate, judged as an attack by multi-indicator fusion); ③ Suffering a severe denial-of-service (DoS) attack and the duration and intensity of the attack exceeding the preset attack duration threshold. ④ Security situation assessment score Greater than or equal to the set high-risk threshold When a full update is triggered, the system adopts a "thorough cleanup" strategy, replacing all existing keys in the key pool at once. At the same time, it forcibly interrupts all current business connections that are still using the old keys, just like cutting off the power. Both parties are required to renegotiate and obtain new keys before subsequent data transmission can be resumed.
[0052] One embodiment of this application provides a routing device for resisting denial-of-service attacks, including: a scanning adjustment module 20, a service differentiation module 21, a resource allocation module 22, and a key update module 23.
[0053] The scanning and adjustment module 20 is used to periodically scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links.
[0054] The service differentiation module 21 is used to receive service requests and differentiate between high-security-level services and low-security-level services.
[0055] The resource allocation module 22 is used to calculate the preferred path using the D algorithm for high-security-level services and allocate first-level time slot resources to the valid preferred path; for low-security-level services, it uses the K-shortest path algorithm to calculate multiple shortest paths and allocates second-level time slot resources to one of the valid shortest paths; the time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness, and the first time slot freshness is less than the second time slot freshness.
[0056] The key update module 23 is used to update the keys in the key pool according to the preset partial update cycle, full update cycle and security status assessment score.
[0057] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the anti-denial-of-service attack routing device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0058] One embodiment of this application provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the anti-denial-of-service attack routing method described above.
[0059] One embodiment of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the anti-denial-of-service attack routing method described above.
[0060] The computer device may be a smartphone, tablet, desktop computer, or cloud server, among other computing devices. This computer device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the figures are merely examples of computer devices and do not constitute a limitation on the computer device. It may include more or fewer components than illustrated, or a combination of certain components, or different components, such as input / output devices, network access devices, etc.
[0061] The processor referred to can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0062] In some embodiments, the memory may be an internal storage unit of the computer device, such as a hard drive or RAM. In other embodiments, the memory may be an external storage device of the computer device, such as a plug-in hard drive, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the memory may include both internal and external storage units of the computer device. The memory is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory can also be used to temporarily store data that has been output or will be output.
[0063] This application provides a computer program product that, when run on a computer device, enables the computer device to execute the steps described in the various method embodiments above.
[0064] In the several embodiments provided in this application, it will be understood that each block in the flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the figures. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved.
[0065] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0066] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A routing method resistant to denial-of-service attacks, characterized in that, include: Regularly scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links. Receive service requests and distinguish between high-security-level and low-security-level services; For high-security-level services, the D algorithm is used to calculate the preferred path, and first-level time slot resources are allocated to the valid preferred path. For low-security-level services, the K-shortest path algorithm is used to calculate multiple shortest paths, and second-level time slot resources are allocated to one of the valid shortest paths. The time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, and the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness. The first time slot freshness is less than the second time slot freshness. The keys in the key pool are updated based on the preset partial update cycle, full update cycle, and security posture assessment score.
2. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, The periodic scanning of all links in the network, based on a preset multi-indicator fusion detection mechanism, identifies attacked links resistant to denial-of-service attacks, specifically including: Periodically scan all links in the network to obtain flags for abnormal key generation rate, abnormal link bit error rate, abnormal node request frequency, and abnormal traffic burst characteristics. The weighted score is calculated based on the values of the key generation rate anomaly flag, the link error rate anomaly flag, the node request frequency anomaly flag, and the traffic burst characteristic anomaly flag. If the weighted score of a link is greater than the attack threshold, the link is added to the attacked link set.
3. The anti-denial-of-service attack routing method as described in claim 2, characterized in that, The dynamic adjustment of the key pool parameters of the attacked link specifically includes: The dynamic replenishment period is calculated based on the baseline replenishment period, network load rate, service urgency, and adjustment coefficient. Boundary constraints are applied in conjunction with network status. When the network load rate is greater than the set high load threshold or a denial-of-service attack is detected, the dynamic replenishment period is not less than the minimum replenishment period. When the network load rate is less than the set low load threshold and there are no network anomalies, the dynamic replenishment period does not exceed the maximum replenishment period. Based on the baseline capacity, security factor, the proportion of the number of currently attacked links to the total number of network links, and the proportion of historical peak attack strength to reference attack strength, the increase in the maximum capacity of the key pool is calculated to obtain the adjusted maximum capacity, and the adjusted maximum capacity does not exceed the hardware limit. For links where multiple indicators have returned to normal, update the key pool parameters of the link in a timely manner and remove the link from the set of attacked links.
4. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, The calculation of the preferred path using the D algorithm specifically includes: The D algorithm is used to calculate multiple candidate paths from the source node to the destination node, and the path with the shortest number of hops is selected as the preferred path from the multiple candidate paths. Each link on the preferred path is checked one by one to see if it belongs to the set of attacked links. If none of the links on the preferred path belong to the set of attacked links, then the preferred path is determined to be valid.
5. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, The allocation of first-level time slot resources to the valid preferred path specifically includes: Collect key pool time slot resource information for each link on the effective preferred path, and calculate the number of time slots required by the service based on the number of keys required by the service and the link key generation rate; If the number of time slots in the primary available time slot set is sufficient to meet the number of time slots required by the business, then primary time slot resources will be allocated to the business first; otherwise, the business request will be blocked.
6. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, The K-shortest path algorithm is used to calculate multiple shortest paths. Secondary time slot resources are allocated to one of the valid shortest paths, specifically including: Traverse the multiple shortest paths and find the path with an unattacked link as the valid shortest path for the allocation of secondary time slot resources; If all of the shortest paths pass through the attacked link, then other key encryption schemes will be used.
7. The anti-denial-of-service attack routing method as described in claim 6, characterized in that, When allocating resources for the effective shortest path, the process also includes allocating wavelength resources for low-security-level services: Following the principles of wavelength consistency and wavelength continuity, a first-hit algorithm is used to select a suitable wavelength.
8. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, Based on preset partial update cycles, full update cycles, and security posture assessment scores, the keys in the key pool are updated, specifically including: The security situation assessment score is calculated by combining the key pool consumption rate, attack detection flags, and business importance level. When the running time reaches the preset partial update cycle, a partial update is performed, or when the security situation assessment score is less than the set low-risk threshold, a partial update is performed; when performing a partial update, a first proportion of keys are randomly selected from the key pool to replace the original key, a new key is generated and synchronously updated to the corresponding link node; When the security situation assessment score is greater than or equal to the low-risk threshold and less than the set high-risk threshold, the first ratio is increased to the second ratio to perform a partial update as a transitional strategy, where the second ratio is greater than the first ratio.
9. The anti-denial-of-service attack routing method as described in claim 1, characterized in that, The step of updating the keys in the key pool based on preset partial update cycles, full update cycles, and security posture assessment scores specifically includes: A full update is performed when the runtime reaches the full update cycle, or when an attack indicating key leakage is detected, or when an attack exceeding the duration and strength thresholds is detected, or when the security situation assessment score is greater than or equal to the set high-risk threshold. During a full update, all keys in the key pool are replaced, and the current business connection using the old key is forcibly interrupted, requiring renegotiation of the key before communication is restored.
10. A routing device resistant to denial-of-service attacks, characterized in that, include: The scanning and adjustment module is used to periodically scan all links in the network, identify attacked links that are resistant to denial-of-service attacks based on a preset multi-indicator fusion detection mechanism, and dynamically adjust the key pool parameters of the attacked links. The service differentiation module is used to receive service requests and differentiate between high-security-level services and low-security-level services. The resource allocation module is used to calculate the preferred path using the D algorithm for high-security-level services and allocate first-level time slot resources to the valid preferred path; for low-security-level services, it uses the K-shortest path algorithm to calculate multiple shortest paths and allocates second-level time slot resources to one of the valid shortest paths; the time slot freshness of the first-level time slot resources is less than or equal to the first time slot freshness, the time slot freshness of the second-level time slot resources is less than or equal to the second time slot freshness, and the first time slot freshness is less than the second time slot freshness; The key update module is used to update the keys in the key pool according to the preset partial update cycle, full update cycle and security status assessment score.