OTN encryption method and apparatus
Patent Information
- Application Number
- PCT/CN2026/083542
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-25
- Filing Date
- 2026-03-13
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026083542_01102026_PF_FP_ABST
Abstract
Description
An encryption method and apparatus for OTN
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202510365938.1, filed on March 25, 2025, entitled "An Encryption Method and Apparatus for OTN", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of optical communication technology, and in particular to an encryption method and apparatus for OTN. Background Technology
[0004] Quantum computing utilizes the principles of quantum mechanics, using qubits as the basic computing units to run quantum algorithms. Currently, optical transport network (OTN) communication employs asymmetric cryptographic algorithms for key negotiation. However, the asymmetric cryptographic algorithms used in OTN communication can be broken by quantum computing. To address the security threats posed by quantum computing, quantum key distribution (QKD) devices are used to provide quantum keys; however, QKD devices are expensive. Furthermore, the attenuation of single-photon signals in optical fiber channels limits transmission distance, making it impossible for the transmission distance of QKD devices to match that of OTN devices. Summary of the Invention
[0005] This application provides an encryption method and apparatus for OTN, enabling the encryption process of OTN to be quantum resistant and reducing costs.
[0006] In a first aspect, embodiments of this application provide an encryption method for an Optical Transport Network (OTN), applied to a first OTN device, comprising: generating a first quantum random number using a quantum random number generator; encrypting the first quantum random number using a first preset key to obtain a first encrypted quantum random number; sending the first encrypted quantum random number to a second OTN device; the first quantum random number serving as a session key for data transmission of services between the first OTN device and the second OTN device.
[0007] The above scheme eliminates the need for additional QKD equipment, reducing costs, and the use of pre-set keys provides OTN key transmission with a degree of quantum resistance. The original pre-set key is built into the OTN device, ensuring initial key security. The encryption key for service transmission uses quantum random numbers, i.e., quantum keys, which are quantum resistant. Furthermore, no asymmetric encryption algorithms are used during key exchange, further enhancing resistance to quantum attacks.
[0008] In one possible implementation, the method further includes:
[0009] Receive an enable instruction from the second OTN device, the enable instruction being used to indicate that the first quantum random number is enabled as the session key.
[0010] In the above scheme, by sending an activation instruction from the receiving end, the sending end can be promptly notified to activate the key for encrypting business data.
[0011] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0012] In one possible implementation, the method further includes:
[0013] The first OTN device and the second OTN device negotiate the use of the first preset key from among the plurality of preset keys.
[0014] In the above implementation method, the negotiation between devices can further improve the security of key transmission.
[0015] In one possible implementation, the method further includes:
[0016] Receive configuration information from a network control device, wherein the configuration information indicates the first preset key among the plurality of preset keys.
[0017] In the above scheme, a network control device indicates the preset key to be used by both communicating parties from multiple preset keys. For example, the preset key can be indicated by its sequence number. This can further improve the security of key negotiation.
[0018] In one possible implementation, the method further includes:
[0019] A second quantum random number is generated using the quantum random number generator;
[0020] The second quantum random number is encrypted using the second preset key and the first quantum random number to obtain the second encrypted quantum random number;
[0021] Send the second encrypted quantum random number to the second OTN device; wherein the second quantum random number serves as the updated session key for the data transmission of the service between the first OTN device and the second OTN device.
[0022] In the above scheme, transmitting the updated session key using a pre-set key and the session key used before the update further enhances the security of key transmission. Furthermore, using quantum random numbers as the session key provides resistance to quantum attacks during key transmission.
[0023] In one possible implementation, the second encrypted quantum random number is obtained by encrypting the second quantum random number based on the second preset key and the first quantum random number, including:
[0024] Obtain the XOR result between the first quantum random number and the second preset key, and use the XOR result to encrypt the second quantum random number to obtain the second encrypted quantum random number.
[0025] In one possible implementation, the first preset key is the same as the second preset key; or...
[0026] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or...
[0027] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0028] Secondly, embodiments of this application provide an encryption method for an optical transport network (OTN), applied to a first OTN device, comprising:
[0029] Use an asymmetric encryption algorithm to generate the first public key and the first private key;
[0030] The first public key is encrypted using the first preset key to obtain the first encrypted public key;
[0031] Send the first encryption public key to the second OTN device;
[0032] The device receives a second encrypted public key from the second OTN device and decrypts the second encrypted public key using the first preset key to obtain a second public key; the second encrypted public key is obtained by the second OTN device encrypting the second public key using the first preset key, and the second public key is generated by the second OTN device using the asymmetric encryption algorithm;
[0033] The second public key and the first private key are used to generate a shared key for communicating with the second OTN device.
[0034] The above scheme eliminates the need for additional QKD equipment, reducing costs. It utilizes classical cryptography and enhances key negotiation security through public key encryption, thereby improving the security of business data. This also improves the resistance of OTN network service data transmission to quantum attacks.
[0035] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0036] In one possible implementation, the method further includes:
[0037] The first OTN device and the second OTN device negotiate the use of the first preset key from among the plurality of preset keys.
[0038] In one possible implementation, the method further includes:
[0039] Receive configuration information from the network control device, the configuration information indicating the first preset key.
[0040] In one possible implementation, the method further includes:
[0041] The shared key is used to encrypt the business data to obtain encrypted business data;
[0042] Send encrypted service data to the second OTN device.
[0043] In one possible implementation, the method further includes:
[0044] A third quantum random number is generated using a quantum random number generator;
[0045] The third encrypted quantum random number is obtained by encrypting the third quantum random number based on the shared key and the second preset key;
[0046] Send the third encrypted quantum random number to the second OTN device;
[0047] The business data is encrypted using the third quantum random number to obtain encrypted business data;
[0048] Send encrypted service data to the second OTN device.
[0049] The above scheme uses quantum keys as session keys and further encrypts the transmission of session keys by using a shared key negotiated through an asymmetric encryption algorithm, which can further improve the resistance of key negotiation to quantum attacks.
[0050] In one possible implementation, the third encrypted quantum random number is obtained by encrypting the third quantum random number based on the session key and the second preset key, including:
[0051] Obtain the XOR result between the session key and the second preset key, and use the XOR result to encrypt the third quantum random number to obtain the third encrypted quantum random number.
[0052] In one possible implementation, the first preset key is the same as the second preset key; or...
[0053] The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or...
[0054] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0055] Thirdly, embodiments of this application provide an encryption method for an Optical Transport Network (OTN), applied to a second OTN device, comprising: receiving a first encrypted quantum random number from a first OTN device; the first encrypted quantum random number is obtained by encrypting a first quantum random number using a first preset key by the first OTN device; decrypting the first encrypted quantum random number using the first preset key to obtain the first quantum random number; the first quantum random number serves as a session key for data transmission of services between the first OTN device and the second OTN device.
[0056] In one possible implementation, the method further includes:
[0057] An enable instruction is sent to the first OTN device, the enable instruction being used to enable the first quantum random number as the session key.
[0058] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0059] In one possible implementation, the method further includes:
[0060] The second OTN device and the first OTN device negotiate the use of the first preset key from among the plurality of preset keys.
[0061] In one possible implementation, the method further includes:
[0062] Receive configuration information from the network control device, the configuration information indicating the first preset key.
[0063] In one possible implementation, the method further includes:
[0064] Receive a second encrypted quantum random number from the first OTN device;
[0065] A decryption key is generated based on the second preset key and the first quantum random number;
[0066] The second encrypted quantum random number is decrypted using the decryption key to obtain a second quantum random number, wherein the second quantum random number serves as the session key for the updated first OTN device and the second OTN device to transmit the service data.
[0067] In one possible implementation, the decryption key is generated based on the second preset key and the first quantum random number, including:
[0068] The XOR result between the first quantum random number and the second preset key is used as the decryption key.
[0069] In one possible implementation, the first preset key is the same as the second preset key; or...
[0070] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or...
[0071] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0072] The beneficial effects of the third aspect mentioned above can be found in the relevant description of the first aspect, and will not be repeated here.
[0073] Fourthly, embodiments of this application provide an encryption method for an optical transport network (OTN), applied to a second OTN device, comprising:
[0074] Use an asymmetric encryption algorithm to generate a second public key and a second private key;
[0075] The second public key is obtained by encrypting the second public key using the first preset key;
[0076] Send the second encryption public key to the first OTN device;
[0077] Receive a first encrypted public key from the first OTN device, and decrypt the first encrypted public key using the first preset key to obtain the first public key;
[0078] The first public key and the second private key are used to generate a shared key for transmitting business data with the first OTN device.
[0079] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0080] In one possible implementation, the method further includes:
[0081] The first OTN device and the second OTN device negotiate the use of the first preset key from among the plurality of preset keys.
[0082] In one possible implementation, the method further includes:
[0083] Receive configuration information from the network control device, the configuration information indicating the first preset key.
[0084] In one possible implementation, the method further includes:
[0085] Receive encrypted service data from the first OTN device;
[0086] The encrypted business data is decrypted using the shared key to obtain the business data.
[0087] In one possible implementation, the method further includes:
[0088] Receive a third encrypted quantum random number from the first OTN device;
[0089] The shared key and the second preset key are used to generate a decryption key, and the decryption key is used to decrypt the third encrypted quantum random number to obtain the third quantum random number;
[0090] The encrypted service data is received from the first OTN device, and the encrypted service data is decrypted using the third quantum random number to obtain the service data.
[0091] In one possible implementation, generating a decryption key based on the shared key and the second preset key includes:
[0092] The XOR result between the shared key and the second preset key is used as the decryption key.
[0093] In one possible implementation, the first preset key is the same as the second preset key; or...
[0094] The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or...
[0095] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0096] The beneficial effects of the fourth aspect mentioned above can be found in the relevant description of the second aspect, and will not be repeated here.
[0097] Fifthly, embodiments of this application provide an encryption device for an optical transport network (OTN), applied to a first OTN device, comprising:
[0098] The processing unit is configured to generate a first quantum random number using a quantum random number generator; and encrypt the first quantum random number using a first preset key to obtain a first encrypted quantum random number.
[0099] The transceiver unit is used to send a first encrypted quantum random number to the second OTN device; the first quantum random number serves as a session key for data transmission of services between the first OTN device and the second OTN device.
[0100] In one possible implementation, the transceiver unit is further configured to: receive an enable instruction from the second OTN device, the enable instruction being used to indicate that the first quantum random number is enabled as the session key.
[0101] In the above scheme, by sending an activation instruction from the receiving end, the sending end can be promptly notified to activate the key for encrypting business data.
[0102] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0103] In one possible implementation, the transceiver unit is further configured to negotiate with the second OTN device to use the first preset key from among the plurality of preset keys.
[0104] In the above implementation method, the negotiation between devices can further improve the security of key transmission.
[0105] In one possible implementation, the transceiver unit is further configured to receive configuration information from a network control device, the configuration information indicating the first preset key among the plurality of preset keys.
[0106] In the above scheme, a network control device indicates the preset key to be used by both communicating parties from multiple preset keys. For example, the preset key can be indicated by its sequence number. This can further improve the security of key negotiation.
[0107] In one possible implementation, the processing unit is further configured to generate a second quantum random number using the quantum random number generator; and encrypt the second quantum random number based on a second preset key and the first quantum random number to obtain a second encrypted quantum random number.
[0108] The transceiver unit is further configured to send the second encrypted quantum random number to the second OTN device; wherein the second quantum random number serves as the updated session key for the first OTN device and the second OTN device to transmit the service data.
[0109] In the above scheme, transmitting the updated session key using a pre-set key and the session key used before the update further enhances the security of key transmission. Furthermore, using quantum random numbers as the session key provides resistance to quantum attacks during key transmission.
[0110] In one possible implementation, the processing unit is specifically used to: obtain the XOR result between the first quantum random number and the second preset key, and use the XOR result to encrypt the second quantum random number to obtain the second encrypted quantum random number.
[0111] In one possible implementation, the first preset key is the same as the second preset key; or...
[0112] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or...
[0113] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0114] The beneficial effects of the fifth aspect mentioned above can be found in the relevant description of the first aspect, and will not be repeated here.
[0115] Sixthly, embodiments of this application provide an encryption device for an optical transport network (OTN), applied to a first OTN device, comprising:
[0116] The processing unit is configured to generate a first public key and a first private key using an asymmetric encryption algorithm; and to encrypt the first public key using a first preset key to obtain a first encrypted public key.
[0117] The transceiver unit is used to send the first encryption public key to the second OTN device and receive the second encryption public key from the second OTN device.
[0118] The processing unit is further configured to decrypt the second encrypted public key using the first preset key to obtain a second public key; the second encrypted public key is obtained by the second OTN device encrypting the second public key using the first preset key, and the second public key is generated by the second OTN device using the asymmetric encryption algorithm; and to generate a shared key for communicating with the second OTN device using the second public key and the first private key.
[0119] The above scheme utilizes classical cryptography to modify the public key, thereby enhancing the security of key negotiation and improving the security of business data. This also improves the resistance of OTN network service data transmission to quantum attacks.
[0120] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0121] In one possible implementation, the transceiver unit is further configured to negotiate with the second OTN device to use the first preset key from among the plurality of preset keys.
[0122] In one possible implementation, the transceiver unit is further configured to receive configuration information from the network control device, the configuration information indicating the first preset key.
[0123] In one possible implementation, the processing unit is further configured to encrypt the service data using the shared key to obtain encrypted service data; the transceiver unit is further configured to send the encrypted service data to the second OTN device.
[0124] In one possible implementation, the processing unit is further configured to generate a third quantum random number using a quantum random number generator; encrypt the third quantum random number based on the shared key and the second preset key to obtain a third encrypted quantum random number; the transceiver unit is further configured to send the third encrypted quantum random number to the second OTN device; the processing unit is further configured to encrypt the service data using the third quantum random number to obtain encrypted service data; and the transceiver unit is further configured to send the encrypted service data to the second OTN device.
[0125] The above scheme uses quantum keys as session keys and further encrypts the transmission of session keys by using a shared key negotiated through an asymmetric encryption algorithm, which can further improve the resistance of key negotiation to quantum attacks.
[0126] In one possible implementation, the processing unit is specifically configured to obtain the XOR result between the session key and the second preset key, and use the XOR result to encrypt the third quantum random number to obtain the third encrypted quantum random number.
[0127] In one possible implementation, the first preset key is the same as the second preset key; or...
[0128] The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or...
[0129] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0130] The beneficial effects of the sixth aspect mentioned above can be found in the relevant description of the second aspect, and will not be repeated here.
[0131] In a seventh aspect, embodiments of this application provide an encryption device for an optical transport network (OTN), applied to a second OTN device, comprising:
[0132] The transceiver unit is configured to receive a first encrypted quantum random number from a first OTN device; the first encrypted quantum random number is obtained by encrypting a first quantum random number using a first preset key by the first OTN device. The processing unit is configured to decrypt the first encrypted quantum random number using the first preset key to obtain a first quantum random number; the first quantum random number serves as a session key for data transmission between the first OTN device and the second OTN device.
[0133] In one possible implementation, the transceiver unit is further configured to send an enable instruction to the first OTN device, the enable instruction being used to enable the first quantum random number as the session key.
[0134] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0135] In one possible implementation, the first preset key is determined by negotiation between the second OTN device and the first OTN device from the plurality of preset keys.
[0136] In one possible implementation, the transceiver unit is further configured to receive configuration information from the network control device, the configuration information indicating the first preset key.
[0137] In one possible implementation, the transceiver unit is configured to receive a second encrypted quantum random number from the first OTN device; the processing unit is further configured to generate a decryption key based on a second preset key and the first quantum random number; and to decrypt the second encrypted quantum random number using the decryption key to obtain a second quantum random number, wherein the second quantum random number serves as the updated session key for the first OTN device to transmit the service data with the second OTN device.
[0138] In one possible implementation, the processing unit is specifically configured to use the XOR result between the first quantum random number and the second preset key as the decryption key.
[0139] In one possible implementation, the first preset key is the same as the second preset key; or...
[0140] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or...
[0141] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0142] The beneficial effects of the seventh aspect mentioned above can be found in the relevant description of the third aspect, and will not be repeated here.
[0143] Eighthly, this application provides an encryption device for an Optical Transport Network (OTN), applied to a second OTN device, comprising: a processing unit, configured to generate a second public key and a second private key using an asymmetric encryption algorithm; and to encrypt the second public key using a first preset key to obtain a second encrypted public key. A transceiver unit, configured to send the second encrypted public key to a first OTN device; and to receive a first encrypted public key from the first OTN device. The processing unit is further configured to decrypt the first encrypted public key using the first preset key to obtain a first public key; and to generate a shared key for transmitting business data with the first OTN device using the first public key and the second private key.
[0144] In one possible implementation, the first preset key is one of a plurality of preset keys configured between the first OTN device and the second OTN device.
[0145] In one possible implementation, the first preset key is determined through negotiation between the first OTN device and the second OTN device from among the plurality of preset keys.
[0146] In one possible implementation, the transceiver unit is further configured to receive configuration information from the network control device, the configuration information indicating the first preset key.
[0147] In one possible implementation, the transceiver unit is further configured to receive encrypted service data from the first OTN device; the processing unit is further configured to decrypt the encrypted service data using the shared key to obtain the service data.
[0148] In one possible implementation, the transceiver unit is further configured to receive a third encrypted quantum random number from the first OTN device. The processing unit is further configured to generate a decryption key using the shared key and the second preset key, and to decrypt the third encrypted quantum random number using the decryption key to obtain the third quantum random number. The transceiver unit is further configured to receive encrypted service data from the first OTN device, and to decrypt the encrypted service data using the third quantum random number to obtain the service data.
[0149] In one possible implementation, the processing unit is specifically configured to use the XOR result between the shared key and the second preset key as the decryption key.
[0150] In one possible implementation, the first preset key is the same as the second preset key; or...
[0151] The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or...
[0152] The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
[0153] The beneficial effects of the eighth aspect mentioned above can be found in the relevant description of the fourth aspect, and will not be repeated here.
[0154] Ninthly, this application provides a first OTN device. The first OTN device includes: a processor coupled to a memory for storing instructions, which, when executed by the processor, cause the device to implement the method of the first aspect or any possible implementation thereof; or cause the device to implement the method of the second aspect or any possible implementation thereof.
[0155] In a tenth aspect, this application provides a second OTN device. The second OTN device includes: a processor coupled to a memory for storing instructions, which, when executed by the processor, cause the device to implement the methods of the third aspect or any possible implementation thereof; or cause the device to implement the methods of the fourth aspect or any possible implementation thereof.
[0156] In one aspect, this application provides an encrypted communication system, which includes a first OTN device as described in the ninth aspect and a second OTN device as described in the tenth aspect.
[0157] In a twelfth aspect, this application provides a computer-readable storage medium storing instructions that, when executed, cause a computer to perform the method described in the first aspect or any possible implementation of the first aspect, or to perform the method described in the second aspect or any possible implementation of the second aspect.
[0158] In a thirteenth aspect, this application provides a computer-readable storage medium storing instructions that, when executed, cause a computer to perform the methods described in the third aspect or any possible implementation of the third aspect, or to perform the methods described in the fourth aspect or any possible implementation of the fourth aspect.
[0159] In a fourteenth aspect, this application provides a chip connected to a memory for reading and executing program code stored in the memory to implement the method described in the first aspect or any possible implementation of the first aspect, or to implement the method described in the second aspect or any possible implementation of the second aspect.
[0160] In a fifteenth aspect, this application provides a chip connected to a memory for reading and executing program code stored in the memory to implement the method in the third aspect or any possible implementation of the third aspect, or to implement the method in the fourth aspect or any possible implementation of the fourth aspect.
[0161] In a sixteenth aspect, a computer program product comprising instructions is provided, which, when executed on an encryption device, cause the encryption to perform the method described in any of the preceding aspects. The encryption device may be a first OTN device as described in the first or second aspect, or a device comprising the first OTN device, or a device included in the first OTN device, such as a chip or system-on-a-chip; or, the encryption device may be a second OTN device as described in the third or fourth aspect, or a device comprising the second OTN device, or a device included in the second OTN device, such as a chip or system-on-a-chip.
[0162] Based on the implementations provided in the above aspects, this application can be further combined to provide more implementations. Attached Figure Description
[0163] Figure 1 is a schematic diagram of the optical network architecture applicable to the embodiments of this application;
[0164] Figure 2 is a schematic diagram of the OTN device structure applicable to the embodiments of this application;
[0165] Figure 3 is a schematic diagram of an asymmetric encryption algorithm.
[0166] Figure 4 is a schematic diagram of the network system architecture applicable to the embodiments of this application;
[0167] Figure 5A is a schematic diagram of an OTN encryption process provided in an embodiment of this application;
[0168] Figure 5B is a schematic diagram of another OTN encryption process provided in an embodiment of this application;
[0169] Figure 6A is a schematic diagram of another OTN encryption process provided in an embodiment of this application;
[0170] Figure 6B is a schematic diagram of another OTN encryption process provided in the embodiments of this application;
[0171] Figure 7 is a schematic diagram of the encryption device structure of OTN provided in the embodiment of this application;
[0172] Figure 8 is a schematic diagram of the structure of the device 800 provided in the embodiment of this application. Detailed Implementation
[0173] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0174] In the description of this application, unless otherwise stated, "multiple" refers to two or more. Additionally, " / " indicates that the related objects are in an "or" relationship; for example, A / B can represent A or B. "And / or" in this application merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, to facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that "first" and "second" are not necessarily different. It should also be noted that, unless specifically stated, the specific description of some technical features in one embodiment can also be used to explain the corresponding technical features mentioned in other embodiments.
[0175] This application applies to optical networks, such as OTN. An OTN typically consists of multiple OTN devices connected by optical fibers, and can be configured into different topologies such as linear, ring, and mesh, depending on specific needs. As shown in Figure 1, the OTN consists of two OTN networks. Each OTN network comprises a certain number of OTN devices (N1 to N7). Depending on actual needs, an OTN device may have different functions. Generally, OTN devices are divided into optical layer devices, electrical layer devices, and optoelectronic hybrid devices. Optical layer devices refer to devices capable of processing optical layer signals, such as optical amplifiers (OA). Electrical layer devices refer to devices capable of processing electrical layer signals, such as devices capable of processing OTN signals. Optoelectronic hybrid devices refer to devices capable of processing both optical layer and electrical layer signals. It should be noted that, depending on specific integration needs, a single OTN device can integrate multiple different functions. The technical solutions provided in this application are applicable to OTN devices of different forms and integration levels. The network devices involved in the embodiments of this application can be OTN devices, which can also be called network nodes, or simply nodes.
[0176] Figure 2 shows a possible OTN device structure. Here, the OTN device can refer to the OTN nodes (N1-N7) in Figure 1. Specifically, an OTN device includes a power supply, a fan, auxiliary boards, and may also include tributary boards, line boards, cross-connect boards, optical layer processing boards, and system control and communication boards. The power supply provides power to the OTN device and may include primary and backup power supplies. The fan is used for heat dissipation. Auxiliary boards provide auxiliary functions such as external alarms or access to external clocks. Tributary boards, cross-connect boards, and line boards are mainly used to process the electrical layer signals of the OTN. The tributary board is used to receive and transmit various customer services, such as SDH services, packet services, Ethernet services, and fronthaul services. Furthermore, the tributary board can be divided into customer-side optical modules and signal processors. The customer-side optical module can be an optical transceiver used to receive and / or transmit customer-side data. The signal processor is used to perform mapping and demapping processing of customer-side data to data frames. Cross-connect boards are used to exchange data frames, completing the exchange of one or more types of data frames. Line boards primarily handle line-side data frames. Specifically, line boards can be divided into line-side optical modules and signal processors. The line-side optical modules can be line-side optical transceivers, used to receive and / or transmit data frames. Signal processors are used to multiplex and demultiplex line-side data frames, or to perform mapping and demapping processing. System control and communication boards are used to implement system control and communication. Specifically, information can be collected from different boards through a backplane, or control commands can be sent to the corresponding boards. It should be noted that, unless otherwise specified, a specific component (e.g., a signal processor) can be one or more, and this application does not impose any limitations. It should also be noted that this application embodiment does not impose any limitations on the types of boards included in the device, or the specific functional design and quantity of the boards.
[0177] It should be noted that the specific types and number of circuit boards included in each device may differ. For example, a network device acting as a core node may not have any tributary boards, while a network device acting as an edge node may have multiple tributary boards.
[0178] In some possible implementations, the electrical layer functions in an OTN device can be deployed within an OTN chip. The electrical layer functions can also be modularly described as an OTN processing module. The OTN processing module has one or more of the functions of a tributary board, a line board, a cross-connect board, or a system control and communication board.
[0179] The following is an explanation of the relevant technologies or concepts involved in this application.
[0180] (1) Asymmetric encryption algorithm.
[0181] Asymmetric encryption algorithms require two keys for encryption and decryption: a public key and a private key.
[0182] The following describes the flow of the asymmetric encryption algorithm. See Figure 3, which is a schematic diagram of the asymmetric encryption algorithm flow.
[0183] S301, the source uses an asymmetric encryption algorithm to generate the first public-private key pair. The first public-private key pair includes public key A and private key A.
[0184] S302, the source sends public key A to the destination.
[0185] S303, the destination uses an asymmetric encryption algorithm to generate a second public-private key pair. The second public-private key pair includes public key B and private key B.
[0186] S304, the destination receives public key A and uses public key A and private key B to calculate session key Key.
[0187] S305, the destination sends public key B to the source.
[0188] S306, the source receives public key B and uses public key B and private key A to calculate session key Key.
[0189] The session key calculated at the source end is the same as the session key calculated at the destination end. The session key is used for subsequent business communication between the source and destination ends.
[0190] (2) Symmetric encryption algorithm.
[0191] Symmetric encryption algorithms are encryption methods that use a single-key cryptosystem. The same key can be used for both encryption and decryption of information. This type of encryption method is called symmetric encryption, also known as single-key encryption.
[0192] (3) Quantum Random Number Generator (QRNG).
[0193] A quantum random number generator (QRNG) is a device that generates random numbers based on a quantum random entropy source, and it has high random number generation efficiency. QRNG features high physical integration, unpredictability, inability to be eavesdropped on by third parties, compliance with One-Time Password (OTP) requirements, and process monitoring and verification.
[0194] (4) The pre-shared key (PSK) is an encryption password set in the router, mainly used to protect the security of the wireless network. It is usually associated with Wi-Fi Protected Access (WPA) / WPA2-PSK encryption methods and is an important security credential for logging into the router and the management interface.
[0195] Currently, communication between OTN devices uses asymmetric encryption algorithms, but these algorithms can be broken by quantum computing. To address the security threats posed by quantum computing, one approach is to use quantum key distribution (QKD) devices to provide quantum keys, but QKD devices are expensive. Another approach is to use post-quantum cryptography (PQC) as a quantum-resistant key exchange scheme, which mainly involves replacing existing cryptographic components with quantum-resistant algorithms. However, this method is inefficient and very costly.
[0196] Based on this, this application provides an encryption method for OTN to achieve quantum resistance in OTN communication, which does not require external QKD hardware or switching to the PQC algorithm, and is low in cost and high in efficiency.
[0197] To reduce costs, this application provides two exemplary implementations for key negotiation between OTN devices for business data transmission.
[0198] In the first possible implementation, symmetric encryption is used to protect the public key transmission process, making the public key non-transparent and unobtainable during transmission, thereby improving its quantum resistance.
[0199] In the second possible implementation, the asymmetric encryption algorithm negotiation process is directly abandoned, and the two ends of the encryption directly use symmetric encryption to transmit the session key, thereby improving the quantum resistance.
[0200] The following example illustrates the need for service data transmission between a first OTN device and a second OTN device. Referring to Figure 4, the network system includes a first OTN device and a second OTN device. In some implementation scenarios, a network control device may also be included. The network control device manages the OTN devices in the network system, such as configuring them. For example, the network control device configures the symmetric key of the OTN device. For instance, the network control device could be an NCE-T (Network Cloud Engine-Transport) network cloud engine-transmission device, or other devices; this embodiment does not limit the specific devices used.
[0201] The first possible implementation will be explained below.
[0202] Referring to Figures 5A and 5B, a schematic flowchart of an OTN encryption method provided in an embodiment of this application is shown. Both the first OTN device and the second OTN device are configured with one or more preset keys. The preset key may also be called a pre-defined key, or use other names; this embodiment of the application does not limit this. In some possible embodiments, the preset key may be generated by the same key derivation algorithm used by both the first OTN device and the second OTN device. For example, both the first OTN device and the second OTN device are configured with the same one or more root keys and the same derivation algorithm. Thus, the first OTN device and the second OTN device use the same derivation algorithm and the same root key to generate one or more preset keys.
[0203] Referring to Figures 5A and 5B, the encryption method flow includes S501-S504.
[0204] S501, the first OTN device generates a first quantum random number through a quantum random number generator.
[0205] In some embodiments, the quantum random number generator can be integrated into the first OTN device, or it can be located outside the first OTN device and connected to the first OTN device.
[0206] S502, the first OTN device uses a first preset key to encrypt the first quantum random number to obtain a first encrypted quantum random number.
[0207] Encrypting the first quantum random number using the first preset key can be achieved using a symmetric encryption algorithm. This application does not specifically limit the symmetric encryption algorithm used. For example, the symmetric encryption algorithm can employ an Advanced Encryption Standard (AES), such as AES-256. SM4, etc., can also be used.
[0208] In one possible example, both the first OTN device and the second OTN device are configured with a preset key, which is called the first preset key. Specifically, the network control device can configure this first preset key for both the first OTN device and the second OTN device.
[0209] In another possible example, the first OTN device and the second OTN device may also be configured with multiple preset keys. The first preset key is one of multiple preset keys. For example, N preset keys may be configured, where N is a positive integer.
[0210] As an example, the first OTN device and the second OTN device negotiate and determine the first preset key from multiple preset keys.
[0211] For example, each of the multiple preset keys has a sequence number. For instance, there are N preset keys, numbered key1 to keyN. The first OTN device and the second OTN device can negotiate and determine the sequence number of a preset key, such as key1.
[0212] As another example, the network control device can specify the preset keys to be used for the first OTN device and the second OTN device. Specifically, the network control device sends the sequence number of the preset key to the first OTN device and the second OTN device respectively. For example, N preset keys are configured, with sequence numbers from key 1 to key N. For example, key1.
[0213] As another example, the first OTN device can directly specify a preset key sequence number to the second OTN device. For example, there are N preset keys, numbered from key 1 to key N. The first OTN device randomly selects a preset key sequence number, such as key1.
[0214] S503, the first OTN device sends a first encrypted quantum random number to the second OTN device. The second OTN device then receives the first encrypted quantum random number.
[0215] In some embodiments, the first OTN device may carry the first encrypted quantum random number in the overhead region of the optical transport unit (OTU) or the overhead region of the optical data unit (ODU) to send the first encrypted quantum random number to the second OTN device.
[0216] S504, the second OTN device uses the first preset key to decrypt the first encrypted quantum random number to obtain the first quantum random number. The first quantum random number serves as the session key for data transmission of services between the first OTN device and the second OTN device.
[0217] In an alternative implementation, as shown in Figure 5B, the above encryption method flow may further include S505.
[0218] S505, the second OTN device sends an enable instruction to the first OTN device. The enable instruction is used to indicate that the first quantum random number is enabled as the session key.
[0219] Furthermore, the first OTN device receives an enable instruction from the second OTN device. Data transmission between the first OTN device and the second OTN device can use a first quantum random number as a session key. For example, service data can be transmitted encrypted. Referring to Figure 5B, the encryption method flow may further include S506-S508.
[0220] S506, the first OTN device uses the first quantum random number to encrypt the service data, thus obtaining the encrypted service data.
[0221] S507, the first OTN device sends encrypted service data to the second OTN device.
[0222] S508, the second OTN device receives the encrypted service data and uses the first quantum random number to decrypt the encrypted service data to obtain the service data.
[0223] The embodiments of this application can be applied to encrypting the payload unit of data frames in an OTN network, and can be performed by a tributary board or a line board.
[0224] OTN network data frames are used to carry various service data, enabling the management and monitoring of this data. OTN frames can be fine-grained optical transport network (fgOTN) frames. OTN frames can also be optical data unit-k (ODUk), ODUn, ODUflex, optical transport unit (OTU)k, OTUCn, optical payload unit (OPU), flexible OTN (FlexO) frames, or optical service unit (OSU), etc. Data frames can also be other frame structures suitable for optical networks.
[0225] In one possible example, the encryption operation can be located on the access side of the customer service of the first OTN device, and the encrypted object is the payload of the ODU of the low-level scheduling on the customer side.
[0226] For example, the customer service can be loaded into the low-level scheduling ODU via the access port on the client side of the first OTN device, and then the optical payload unit (OPU) of the ODU can be encrypted. Alternatively, the customer service can be loaded into the low-level scheduling ODU via the tributary board of the first OTN device, and then the optical payload unit (OPU) of the ODU can be encrypted. The decryption operation can be performed by the tributary board of the second OTN device to decrypt the optical payload unit (OPU) of the ODU.
[0227] For example, the customer service can be loaded into the Optical Service Unit (OSU) via the access port on the customer side of the first OTN device, and then the payload unit of the OSU can be encrypted. Alternatively, the customer service can be loaded into the OSU via the tributary board of the first OTN device, and then the payload unit of the OSU can be encrypted. The decryption operation can be performed by the tributary board of the second OTN device to decrypt the payload unit of the OSU.
[0228] For example, the client's service can be loaded into an fgOTN frame via the client-side access port of the first OTN device, and the payload unit of the fgOTN frame can be encrypted. Alternatively, the client's service can be loaded into an fgOTN frame via the tributary board of the first OTN device, and the payload unit of the fgOTN frame can be encrypted. The decryption operation can be performed by the tributary board of the second OTN device to decrypt the payload unit of the fgOTN frame.
[0229] In another possible example, the encryption operation is performed on the line transmission side of the first OTN device, and the object of encryption is the payload of the higher-order OTUs on the line side. For example, after multiple lower-order ODUs are multiplexed to the OPU of a higher-order ODU, the payload of the higher-order ODUs is encrypted. For instance, the line board of the first OTN device can multiplex multiple lower-order ODUs to the OPU of a higher-order ODU and encrypt the payload of the higher-order ODUs. The decryption operation can be performed by the line board of the second OTN device, decrypting the payload of the higher-order ODUs.
[0230] In another possible example, the encryption operation is performed on the line transmission side of the first OTN device, and the object of encryption is the payload unit of the ODUk on the line side.
[0231] Specifically, when the object of encryption is the payload of the customer-side ODU, the first OTN device can encrypt the payloads of optical channel payload units (OPUk, k = 0, 1, 2, flex...) at various rate levels, thereby achieving encryption of service data streams at different rate levels. After the encrypting party completes the encryption of the optical scheduling OPU payload, it will transmit it to the decrypting party's second OTN device via the optical transport network.
[0232] It should be understood that if the second OTN device has service data to send to the first OTN device, the second OTN device uses a first quantum random number to encrypt the service data to be sent to the first OTN device. The first OTN device uses the first quantum random number to decrypt the service data from the second OTN device.
[0233] In one possible implementation, the first OTN device and the second OTN device can also periodically update the session key they use to further improve communication security. For example, the session key can be updated every hour, half hour, or every day. Specifically, a quantum random number can be used as the updated session key.
[0234] In one example, when multiple preset keys are configured between the first OTN device and the second OTN device, the updated session key can be transmitted by using a new preset key.
[0235] In another example, the session key before the update can be used to transmit the updated session key.
[0236] In another example, the updated session key can be transmitted based on a preset key and the session key before the update. This approach further enhances the security of the transmitted updated session key, thereby improving the security of business data.
[0237] For example, as shown in Figure 5B, the OTN encryption process may also include S509-S512.
[0238] S509, the first OTN device generates a second quantum random number through a quantum random number generator.
[0239] S510, the first OTN device uses the second preset key and the first quantum random number to encrypt the second quantum random number to obtain the second encrypted quantum random number.
[0240] The following examples describe several possible ways to encrypt a second quantum random number using a second preset key and a first quantum random number.
[0241] In one example, the XOR result between a first quantum random number and a second preset key can be obtained, and the second quantum random number can be encrypted using the XOR result to obtain the second encrypted quantum random number.
[0242] In another example, a second preset key and a first quantum random number can be used to perform bit permutations to obtain an encryption key to encrypt the second quantum random number.
[0243] In another example, the second preset key and the first quantum random number can be used to perform a modular operation to obtain an encryption key, which can then be used to encrypt the second quantum random number. The modular operation can be either addition or multiplication.
[0244] In another example, an encryption key can be obtained by using a hash algorithm or key concatenation method based on the second preset key and the first quantum random number to encrypt the second quantum random number.
[0245] In some possible implementations, if the first OTN device and the second OTN device are configured with only one preset key, the first preset key and the second preset key are the same.
[0246] In another possible implementation, when the first OTN device and the second OTN device are configured with multiple preset keys, each preset key corresponds to a sequence number. The second preset key can be a preset key that is in the sequence number following the first preset key. For example, if the first preset key is the preset key with sequence number 4, the second preset key can be the preset key with sequence number 5. The sorting can be done in a cyclical manner; for example, the preset key after the last sequence number can be the preset key with sequence number 1.
[0247] In another possible implementation, if the first OTN device and the second OTN device are configured with multiple preset keys, the first OTN device and the second OTN device can also negotiate to determine the second preset key from the multiple preset keys by means of renegotiation.
[0248] S511, the first OTN device sends a second encrypted quantum random number to the second OTN device. The second OTN device then receives the second encrypted quantum random number from the first OTN device. This second quantum random number serves as the updated session key for data transmission between the first and second OTN devices.
[0249] S512, the second OTN device decrypts the second encrypted quantum random number based on the second preset key and the first quantum random number to obtain the second quantum random number.
[0250] Optionally, the OTN encryption process may also include S513.
[0251] S513, the second OTN device sends a second enable instruction to the first OTN device, the second enable instruction being used to enable a second quantum random number as a session key for transmitting service data between the first OTN device and the second OTN device.
[0252] The first OTN device and the second OTN device can update the session key from a first quantum random number to a second quantum random number. Then, the first OTN device and the second OTN device use the second quantum random number as the session key to encrypt the service data transmitted between them.
[0253] The methods described in this application embodiment enable OTN key transmission to possess a certain degree of quantum resistance using a pre-set key. The original pre-set key is built into the OTN device, ensuring initial key security. The encryption key for service transmission uses quantum random numbers, i.e., quantum keys, which are quantum resistant. Furthermore, no asymmetric encryption algorithms are used during key exchange, further enhancing resistance to quantum attacks.
[0254] The second possible implementation method is explained below.
[0255] Referring to Figures 6A and 6B, a schematic flowchart of an OTN encryption method provided in an embodiment of this application is shown. Both the first OTN device and the second OTN device are configured with one or more preset keys. The relevant explanations regarding the preset keys have been described above and will not be repeated here.
[0256] Referring to Figures 6A and 6B, the encryption method flow includes S601-S610.
[0257] S601, the first OTN device uses an asymmetric encryption algorithm to generate a first public key and a first private key.
[0258] This application does not specifically limit the asymmetric encryption algorithm. For example, RSA encryption algorithm, elliptic curve cryptography (ECC), elliptic curve Diffie-Hellman ephemeral key exchange algorithm, digital signature algorithm (DSA), Diffie-Hellman algorithm, etc. can be used.
[0259] S602, the first OTN device uses the first preset key to encrypt the first public key to obtain the first encrypted public key.
[0260] S603, the first OTN device sends the first encryption public key to the second OTN device.
[0261] In some embodiments, the first OTN device may carry the first encryption public key in the overhead area of the optical transport unit (OTU) or the overhead area of the optical data unit (ODU) to send the first encryption public key to the second OTN device.
[0262] S604, the second OTN device receives the first encryption public key from the first OTN device and decrypts the first encryption public key using the first preset key to obtain the first public key.
[0263] S605, the second OTN device uses an asymmetric encryption algorithm to generate a second public key and a second private key.
[0264] S606, the second OTN device uses the first preset key to encrypt the second public key to obtain the second encrypted public key.
[0265] S607, the second OTN device sends the second encryption public key to the first OTN device.
[0266] In one possible example, both the first OTN device and the second OTN device are configured with a preset key, which is called the first preset key. Specifically, the network control device can configure this first preset key for both the first OTN device and the second OTN device.
[0267] In another possible example, the first OTN device and the second OTN device may also be configured with multiple preset keys. The first preset key is one of multiple preset keys. For example, N preset keys may be configured, where N is a positive integer.
[0268] As an example, the first OTN device and the second OTN device negotiate and determine the first preset key from multiple preset keys.
[0269] For example, each of the multiple preset keys has a sequence number. For instance, there are N preset keys, numbered key1 to keyN. The first OTN device and the second OTN device can negotiate and determine the sequence number of a preset key, such as key1.
[0270] As another example, the network control device can specify the preset keys to be used for the first OTN device and the second OTN device. Specifically, the network control device sends the sequence number of the preset key to the first OTN device and the second OTN device respectively. For example, N preset keys are configured, with sequence numbers from key 1 to key N. For example, key1.
[0271] As another example, the first OTN device can directly specify a preset key sequence number to the second OTN device. For example, there are N preset keys, numbered from key 1 to key N. The first OTN device randomly selects a preset key sequence number, such as key1.
[0272] S608, the first OTN device receives the second encryption public key from the second OTN device, and uses the first preset key to decrypt the second encryption public key to obtain the second public key.
[0273] S609, the second OTN device uses the first public key and the second private key to generate a shared key between the second OTN device and the first OTN device.
[0274] S610, the first OTN device uses the second public key and the first private key to generate a shared key between the first OTN device and the second OTN device.
[0275] For example, the first OTN device can use a common public-private key encryption algorithm to generate a shared key between the first OTN device and the second OTN device. The specific algorithm is not limited in the embodiments of this application.
[0276] In some possible implementations, the shared key can be directly used as the session key to encrypt the service data. The first OTN device uses the shared key as the session key to encrypt the service data to be transmitted and sends it to the second OTN device.
[0277] In other possible implementations, the first OTN device and the second OTN device can also use quantum random numbers as session keys. A shared key can be used to encrypt the quantum random numbers to improve the session key's resistance to quantum attacks.
[0278] In other possible implementations, the first OTN device and the second OTN device can also use quantum random numbers as session keys. Shared keys and preset keys can be used to encrypt the quantum random numbers to improve the session key's resistance to quantum attacks.
[0279] As shown in Figure 6B, the encryption process of the OTN described above may also include S611-S614.
[0280] S611, the first OTN device generates a third quantum random number through a quantum random number generator.
[0281] In some embodiments, the quantum random number generator can be integrated into the first OTN device, or it can be located outside the first OTN device and connected to the first OTN device.
[0282] S612, the first OTN device encrypts the third quantum random number based on the shared key and the second preset key to obtain the third encrypted quantum random number.
[0283] The following examples illustrate several possible ways to encrypt a third quantum random number using a second preset key and a shared key.
[0284] In one example, the XOR result between the shared key and the second preset key can be obtained, and the XOR result can be used to encrypt the third quantum random number to obtain the third encrypted quantum random number.
[0285] In another example, a second preset key and a shared key can be used to perform bit permutations to obtain an encryption key to encrypt a third quantum random number.
[0286] In another example, a modular operation can be performed on the second preset key and the shared key to obtain an encryption key, which can then be used to encrypt the third quantum random number. The modular operation can be either addition or multiplication.
[0287] In another example, a hash algorithm or key concatenation method can be used to obtain an encryption key based on a second preset key and a shared key to encrypt a third quantum random number.
[0288] In some possible implementations, if the first OTN device and the second OTN device are configured with only one preset key, the first preset key and the second preset key are the same.
[0289] In another possible implementation, when the first OTN device and the second OTN device are configured with multiple preset keys, each preset key corresponds to a sequence number. The second preset key can be the preset key that is in the sequence number following the first preset key. For example, if the first preset key is the preset key with sequence number 4, the second preset key can be the preset key with sequence number 5. The sorting can be done in a cyclical manner; for example, the preset key after the last sequence number can be the preset key with sequence number 1.
[0290] In another possible implementation, if the first OTN device and the second OTN device are configured with multiple preset keys, the first OTN device and the second OTN device can also negotiate to determine the second preset key from the multiple preset keys by means of renegotiation.
[0291] S613, the first OTN device sends a third encrypted quantum random number to the second OTN device.
[0292] S614, the second OTN device decrypts the third encrypted quantum random number based on the shared key and the second preset key to obtain the third quantum random number.
[0293] Furthermore, the encryption process of the aforementioned OTN may also include S615-S617.
[0294] S615, the first OTN device uses a third quantum random number to encrypt the service data, thus obtaining the encrypted service data;
[0295] In one possible example, the encryption operation can be performed on the access side of the customer service of the first OTN device, encrypting the payload of the ODU in the low-level scheduling on the customer side. For example, the customer service can be loaded into the low-level scheduling ODU by the access port on the customer side of the first OTN device, and then the optical payload unit (OPU) of the ODU can be encrypted. Alternatively, the customer service can be loaded into the low-level scheduling ODU by the tributary board of the first OTN device, and then the optical payload unit (OPU) of the ODU can be encrypted. The decryption operation can be performed by the tributary board of the second OTN device to decrypt the optical payload unit (OPU) of the ODU.
[0296] In another possible example, the encryption operation is performed on the line transmission side of the first OTN device, and the object of encryption is the payload of the higher-order OTUs on the line side. For example, after multiple lower-order ODUs are multiplexed to the OPU of a higher-order ODU, the payload of the higher-order ODUs is encrypted. For instance, the line board of the first OTN device can multiplex multiple lower-order ODUs to the OPU of a higher-order ODU and encrypt the payload of the higher-order ODUs. The decryption operation can be performed by the line board of the second OTN device, decrypting the payload of the higher-order ODUs.
[0297] Specifically, when the object of encryption is the payload of the customer-side ODU, the first OTN device can encrypt the payloads of optical channel payload units (OPUk, k = 0, 1, 2, flex...) at various rate levels, thereby achieving encryption of service data streams at different rate levels. After the encrypting party completes the encryption of the optical scheduling OPU payload, it will transmit it to the decrypting party's second OTN device via the optical transport network.
[0298] It should be understood that if the second OTN device has service data to send to the first OTN device, the second OTN device uses a third quantum random number to encrypt the service data to be sent to the first OTN device. The first OTN device uses the third quantum random number to decrypt the service data from the second OTN device.
[0299] S616, the first OTN device sends encrypted service data to the second OTN device.
[0300] S617, the second OTN device uses a third quantum random number to decrypt the encrypted service data in order to obtain the service data.
[0301] In one possible implementation, the first OTN device and the second OTN device can also periodically update the session key they use to further improve communication security. For example, the session key can be updated every hour, half hour, or every day. Specifically, the updated session key can be generated by updating the public and private keys.
[0302] In one example, when multiple pre-configured keys are configured between the first OTN device and the second OTN device, an updated public key can be transmitted using a new pre-configured key. The pre-configured keys can be refreshed periodically to ensure one-time pad encryption during public key exchanges, thereby improving the security of key transmission.
[0303] In another example, the previous session key can be used to transmit the updated public key. Using the previous session key to transmit the updated public key ensures that a different key is used for each public key transmission, thereby improving the security of key transmission.
[0304] In another example, the updated public key can be transmitted based on the updated preset key and the original session key. This approach further enhances the security of the updated session key transmission, thereby improving the security of business data.
[0305] This application's embodiments, through the above-described scheme, utilize classical cryptography to modify the key exchange and enhance the security of business data by encrypting the public key. This improves the resistance of OTN network service data transmission to quantum attacks.
[0306] It should also be understood that, in the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0307] It should also be understood that in some of the above embodiments, the examples are mainly based on devices in existing network architectures (such as OTN devices), and this application does not limit the specific form of the devices in the embodiments. For example, any device that can achieve the same function in the future is applicable to this application.
[0308] The encryption method for OTN provided in this application has been described in detail above with reference to the accompanying drawings. It is understood that, in order to achieve the above functions, the second OTN device and the first OTN device include hardware structures and / or software modules corresponding to the execution of each function.
[0309] The following describes in detail the OTN encryption device provided in the embodiments of this application. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for content not described in detail, please refer to the method embodiments above. For the sake of brevity, some content will not be repeated.
[0310] This application embodiment can divide the first OTN device or the second OTN device into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of functional modules according to each function as an example.
[0311] As shown in Figure 7, the device includes a processing unit 710 and a transceiver unit 720.
[0312] In one example, the apparatus is applied to a first OTN device, and the transceiver unit 720 is used to perform the receiving and transmitting operations performed by the first OTN device as mentioned in any of the above embodiments. The processing unit 710 is used to perform operations other than the receiving and transmitting operations (such as encryption and decryption) performed by the first OTN device as mentioned in any of the above embodiments. The transceiver unit 720 may include a transmitting unit and a receiving unit. The transmitting unit is used to perform the transmitting operations performed by the first OTN device as mentioned in any of the above embodiments. The receiving unit is used to perform the receiving operations performed by the first OTN device as mentioned in any of the above embodiments.
[0313] In one example, the apparatus is applied to a second OTN device, and the transceiver unit 720 is used to perform the receiving and transmitting operations performed by the second OTN device mentioned in any of the above embodiments. The processing unit 710 is used to perform operations other than the receiving and transmitting operations (such as encryption and decryption) performed by the second OTN device mentioned in any of the above embodiments. The transceiver unit 720 may include a transmitting unit and a receiving unit. The transmitting unit is used to perform the transmitting operations performed by the second OTN device mentioned in any of the above embodiments. The receiving unit is used to perform the receiving operations performed by the second OTN device mentioned in any of the above embodiments.
[0314] This device can be used in a first OTN device or a second OTN device. Specifically, the device can be a processor, a chip, a chip system, or a module in the processor used to execute the functions of the first OTN device or the second OTN device. This device can be implemented by the branch board or circuit board shown in Figure 2.
[0315] Figure 8 is a schematic diagram of another OTN encryption device provided in an embodiment of this application. As shown in Figure 8, the device 800 includes a processor 801, a transceiver 802, and a memory 803. The memory 803 is optional. The device 800 can be applied to both transmitting-side devices (e.g., the first OTN device described above) and receiving-side devices (e.g., the second OTN device described above). Exemplarily, the processor 801, memory 803, and transceiver 802 can be connected via a bus 804.
[0316] When applied to the first OTN device, the processor 801 and transceiver 802 are used to implement the methods performed by the first OTN device shown in Figures 5A-5B or 6A-6B. During implementation, each step of the processing flow can be accomplished by the integrated logic circuitry in the hardware of the processor 801 or by instructions in software form, such as performing encryption or decryption operations. The transceiver 802 is used to receive a second encryption public key or an enable instruction, or to send a first encryption public key or a first encryption quantum random number to the second OTN device, etc.
[0317] When applied to a second OTN device, the processor 801 and transceiver 802 implement the methods performed by the second OTN device shown in Figures 5A-5B or 6A-6B. The transceiver 802 receives a first encrypted quantum random number or a first encrypted public key sent by the first OTN device and sends it to the processor 801 for subsequent processing. During implementation, each step of the processing flow can be accomplished by the integrated logic circuitry in the processor 801 or by software instructions to perform the methods described in the aforementioned figures, such as performing encryption or decryption operations. The memory 803 stores instructions so that the processor 801 can execute the steps mentioned in the figures above. Alternatively, the memory 803 can also store other instructions to configure the parameters of the processor 801 to achieve corresponding functions.
[0318] It should be noted that, in the OTN device hardware structure diagram shown in Figure 2, the processor 801 and memory 803 may be located in a branch board, a single board combining branch and line circuits, or a circuit board. Alternatively, multiple processors 801 and memory 803 may be included, located on the branch board and circuit board respectively, with the two boards working together to complete the aforementioned method steps.
[0319] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0320] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM can include a variety of forms, such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0321] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0322] As will be apparent to those skilled in the art, the units and steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, and such implementations should be considered within the scope of protection of this application.
[0323] Based on the same concept as the above method embodiments, this application also provides a computer-readable storage medium storing program instructions (or computer programs, instructions) thereon. When the program instructions are executed by a processor, they cause the computer to perform the operations performed by the first OTN device and the second OTN device in any possible implementation of the above method embodiments and method embodiments.
[0324] Based on the same concept as the above method embodiments, this application also provides a computer program product, including program instructions. When the computer program product is invoked and executed by a computer, it can enable the computer to perform the operations performed by the first OTN device and the second OTN device in any possible implementation of the above method embodiments and method embodiments.
[0325] Based on the same concept as the above-described method embodiments, this application also provides a chip or chip system, which is coupled to a transceiver for implementing the operations performed by the first OTN device and the second OTN device in any possible implementation of the above-described method embodiments. The chip system may include the chip, as well as components including a memory, a communication interface, etc.
[0326] Based on the same concept as the above-described method embodiments, this application also provides a communication system. The communication system includes a first OTN device and a second OTN device.
[0327] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the communication system described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0328] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) containing computer-usable program code.
[0329] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0330] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An encryption method for an optical transport network (OTN), characterized in that, Applied to the first OTN device, including: The first quantum random number is generated using a quantum random number generator; The first quantum random number is encrypted using the first preset key to obtain the first encrypted quantum random number; Send a first encrypted quantum random number to the second OTN device; the first quantum random number serves as the session key for data transmission of services between the first OTN device and the second OTN device.
2. The method as described in claim 1, characterized in that, The method further includes: Receive an enable instruction from the second OTN device, the enable instruction being used to indicate that the first quantum random number is enabled as the session key.
3. The method as described in claim 1 or 2, characterized in that, The first preset key is one of a plurality of preset keys configured for the first OTN device and the second OTN device.
4. The method as described in claim 3, characterized in that, The method further includes: The first OTN device and the second OTN device negotiate the use of the first preset key from among the plurality of preset keys.
5. The method as described in claim 3, characterized in that, The method further includes: Receive configuration information from the network control device, the configuration information indicating the first preset key.
6. The method according to any one of claims 1-5, characterized in that, The method further includes: A second quantum random number is generated using the quantum random number generator; The second quantum random number is encrypted using the second preset key and the first quantum random number to obtain the second encrypted quantum random number; Send the second encrypted quantum random number to the second OTN device; wherein the second quantum random number serves as the updated session key for the data transmission of the service between the first OTN device and the second OTN device.
7. The method as described in claim 6, characterized in that, The second encrypted quantum random number is obtained by encrypting the second quantum random number based on the second preset key and the first quantum random number, including: Obtain the XOR result between the first quantum random number and the second preset key, and use the XOR result to encrypt the second quantum random number to obtain the second encrypted quantum random number.
8. The method as described in claim 6 or 7, characterized in that: The first preset key is the same as the second preset key; or, The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or... The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
9. An encryption method for an optical transport network (OTN), characterized in that, Applied to the first OTN device, including: Use an asymmetric encryption algorithm to generate the first public key and the first private key; The first public key is encrypted using the first preset key to obtain the first encrypted public key; Send the first encryption public key to the second OTN device; The device receives a second encrypted public key from the second OTN device and decrypts the second encrypted public key using the first preset key to obtain a second public key; the second encrypted public key is obtained by the second OTN device encrypting the second public key using the first preset key, and the second public key is generated by the second OTN device using the asymmetric encryption algorithm; The second public key and the first private key are used to generate a shared key for communicating with the second OTN device.
10. The method as described in claim 9, characterized in that, The first preset key is one of a plurality of preset keys configured for the first OTN device and the second OTN device.
11. The method as described in claim 10, characterized in that, The method further includes: The first OTN device and the second OTN device negotiate the use of the first preset key from among the plurality of preset keys.
12. The method as described in claim 11, characterized in that, The method further includes: Receive configuration information from the network control device, the configuration information indicating the first preset key.
13. The method according to any one of claims 9-12, characterized in that, The method further includes: The shared key is used to encrypt the business data to obtain encrypted business data; Send encrypted service data to the second OTN device.
14. The method according to any one of claims 9-12, characterized in that, The method further includes: A third quantum random number is generated using a quantum random number generator; The third encrypted quantum random number is obtained by encrypting the third quantum random number based on the shared key and the second preset key; Send the third encrypted quantum random number to the second OTN device; The business data is encrypted using the third quantum random number to obtain encrypted business data; Send encrypted service data to the second OTN device.
15. The method as described in claim 14, characterized in that, The first encrypted quantum random number is obtained by encrypting the third quantum random number based on the shared key and the second preset key, including: Obtain the XOR result between the shared key and the second preset key, and use the XOR result to encrypt the third quantum random number to obtain the third encrypted quantum random number.
16. The method as described in claim 14 or 15, characterized in that: The first preset key is the same as the second preset key; or, The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or... The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
17. An encryption method for an optical transport network (OTN), characterized in that, Applied to second OTN devices, including: The system receives a first encrypted quantum random number from a first OTN device; the first encrypted quantum random number is obtained by encrypting a first quantum random number using the first preset key by the first OTN device. The first quantum random number is obtained by decrypting the first encrypted quantum random number using the first preset key; the first quantum random number is used as the session key for data transmission of services between the first OTN device and the second OTN device.
18. The method as described in claim 17, characterized in that, The method further includes: An enable instruction is sent to the first OTN device, the enable instruction being used to enable the first quantum random number as the session key.
19. The method as described in claim 17 or 18, characterized in that, The method further includes: Receive a second encrypted quantum random number from the first OTN device; A decryption key is generated based on the second preset key and the first quantum random number; The second encrypted quantum random number is decrypted using the decryption key to obtain a second quantum random number, wherein the second quantum random number serves as the session key for the updated first OTN device and the second OTN device to transmit the service data.
20. The method as described in claim 19, characterized in that: The first preset key is the same as the second preset key; or, The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is the preset key that is in the next order after the first preset key among the multiple preset keys arranged in sequence; or... The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
21. An encryption method for an optical transport network (OTN), characterized in that, Applied to second OTN devices, including: Use an asymmetric encryption algorithm to generate a second public key and a second private key; The second public key is obtained by encrypting the second public key using the first preset key; Send the second encryption public key to the first OTN device; Receive a first encrypted public key from the first OTN device, and decrypt the first encrypted public key using the first preset key to obtain the first public key; A shared key for communicating with the first OTN device is generated using the first public key and the second private key.
22. The method as described in claim 21, characterized in that, The method further includes: Receive encrypted service data from the first OTN device; The encrypted business data is decrypted using the shared key to obtain the business data.
23. The method as described in claim 21, characterized in that, The method further includes: Receive a third encrypted quantum random number from the first OTN device; The shared key and the second preset key are used to generate a decryption key, and the decryption key is used to decrypt the third encrypted quantum random number to obtain the third quantum random number; The encrypted service data is received from the first OTN device, and the encrypted service data is decrypted using the third quantum random number to obtain the service data.
24. The method as described in claim 23, characterized in that: The first preset key is the same as the second preset key; or, The first OTN device and the second OTN device are each configured with multiple preset keys, each preset key corresponding to a sequence number. The second preset key is the preset key that follows the first preset key in the sequence numbered order among the multiple preset keys; or... The first OTN device and the second OTN device are each configured with multiple preset keys, and the second preset key is a preset key that the first OTN device and the second OTN device negotiate and determine from the multiple preset keys.
25. An encryption device for an optical transport network (OTN), characterized in that, Including the processor and memory, of which: The memory is used to store program code; The processor is configured to read and execute program code stored in the memory to implement the method as described in any one of claims 1 to 8, or the method as described in any one of claims 9 to 16, or the method as described in any one of claims 17 to 20, or the method as described in any one of claims 21 to 24.
26. A chip, characterized in that, The chip is connected to a memory and is used to read and execute program code stored in the memory to implement the method as described in any one of claims 1 to 8, or the method as described in any one of claims 9 to 16, or the method as described in any one of claims 17 to 20, or the method as described in any one of claims 21 to 24.