CN106712941B - Dynamic updating method and system for quantum key in optical network - Google Patents

Dynamic updating method and system for quantum key in optical network Download PDF

Info

Publication number
CN106712941B
CN106712941B CN201611267815.1A CN201611267815A CN106712941B CN 106712941 B CN106712941 B CN 106712941B CN 201611267815 A CN201611267815 A CN 201611267815A CN 106712941 B CN106712941 B CN 106712941B
Authority
CN
China
Prior art keywords
key
quantum key
updating
quantum
data service
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201611267815.1A
Other languages
Chinese (zh)
Other versions
CN106712941A (en
Inventor
郁小松
王�华
赵永利
张会彬
张�杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing University of Posts and Telecommunications
Original Assignee
Beijing University of Posts and Telecommunications
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing University of Posts and Telecommunications filed Critical Beijing University of Posts and Telecommunications
Priority to CN201611267815.1A priority Critical patent/CN106712941B/en
Publication of CN106712941A publication Critical patent/CN106712941A/en
Application granted granted Critical
Publication of CN106712941B publication Critical patent/CN106712941B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0891Revocation or update of secret information, e.g. encryption key update or rekeying
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • H04L9/16Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation

Abstract

The invention provides a dynamic updating method and a dynamic updating system for a quantum key in an optical network. The method includes S1, generating a new quantum key for the duration of a data service and for a key update period based on the dynamic key update mechanism; and S2, acquiring the transmission resource of the new quantum key in the optical network, and transmitting the new quantum key to encrypt the data service. The invention provides a dynamic key updating mechanism according to different requirements of an optical network, and particularly provides two quantum key updating period configuration strategies; the arrival of a key updating request is dynamically triggered according to a configuration strategy of a quantum key updating period, so that the problem that the quantum key fixed updating period is easy to damage is solved; and a retransmission mechanism after the quantum key updating fails is provided, the condition of the quantum key updating failure is processed, and the effective transmission of the quantum key is ensured, so that the encrypted transmission of the data service is ensured.

Description

Dynamic updating method and system for quantum key in optical network
Technical Field
The present invention relates to the field of communications technologies, and in particular, to a method and a system for dynamically updating a quantum key in an optical network.
Background
At present, an optical network has great security problems and hidden dangers, and a Quantum Key Distribution (QKD) system can provide security encryption guarantee for the optical network. Because quantum itself has 'absolute security' in theory, the quantum key distribution system can ensure the absolute security of key transmission. In an optical network based on a quantum key distribution system, a data channel, a quantum key channel and a measurement base channel are established in an optical fiber by utilizing a wavelength division multiplexing technology to ensure that the quantum key is feasible in the encryption process of the optical network. The data channel is used for transmitting data services, the quantum key channel is used for transmitting quantum keys for corresponding data services, and the measurement base channel is used for transmitting information synchronous with the quantum channels.
Although quantum keys can improve security in network data traffic transmission, the keys themselves still have the possibility of being compromised. In order to improve the security of the key, in the symmetric cryptographic technology standard, a method for updating the key at a fixed period is provided, that is, the data service is encrypted by updating the key periodically for many times. As shown in fig. 1, the transmission time of each quantum key is set to a fixed time slot T, and in the case of a fixed key update period, the quantum key of each data service is dynamically updated once every period T. The key updating method based on the fixed period has strong regularity and is easy to be damaged by attack, so that a more flexible key updating method is needed.
Disclosure of Invention
The present invention provides a quantum key channel transmission method and system based on optical time division multiplexing that overcomes or at least partially solves the above mentioned problems.
According to an aspect of the present invention, there is provided a method for dynamically updating a quantum key in an optical network, including:
s1, generating a new quantum key in the duration of a data service and a key updating period based on the dynamic key updating mechanism;
and S2, acquiring the transmission resource of the new quantum key in the optical network, and transmitting the new quantum key to encrypt the data service.
Further, the method for dynamically updating the quantum key in the optical network further includes:
and S3, retransmitting the new quantum key failed to update within the duration of the data service by using a key retransmission mechanism based on the time window.
Specifically, the dynamic key update mechanism in S1 includes:
based on the quantum key wavelength channels, different quantum key wavelength channels provide different first key updating periods, and the quantum keys are updated on one quantum key wavelength channel according to the same time interval; and/or
And based on a random distribution strategy, providing a randomized second key updating period for different data services, and updating the quantum key of the data service on one quantum key wavelength channel according to a randomized time interval.
Further, the S1 further includes:
s1.1, determining a specific key updating period of the data service;
s1.2, based on the specific key updating cycle, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key, and if so, generating a new quantum key.
Further, the S2 further includes:
s2.1, taking the source node and the destination node of the data service as end points, and obtaining a shortest path as a key route of the new quantum key in the optical network physical topology;
s2.2, quantum key wavelength resources are obtained on each path of the key route, and the new quantum key is transmitted according to the quantum key wavelength.
Further, the S3 further includes:
s3.1, taking a time period from the current time to the completion of the data service transmission as a retransmission time window, and randomly selecting the starting time of one time period in the specific key updating period as retransmission time in the retransmission time window;
s3.2, judging whether the transmission of the new quantum key can be finished in the time period from the retransmission time to the completion of the data service transmission;
and S3.3, if the transmission of the new quantum key can be completed, distributing routing and quantum key wavelength resources for the new quantum key and transmitting the new quantum key.
Further, the S1.1 further includes: and after the first quantum key transmission is finished, determining the first key updating period or the second key updating period as the specific key updating period.
Further, the S1.2 further includes:
s1.2.1, after the transmission of the current quantum key is finished, generating a next quantum key updating request;
s1.2.2, based on the update request, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key;
s1.2.3, if sufficient rekeying occurs, a new quantum key is generated at the particular rekeying period.
Further, a time slot resource of the quantum key wavelength resource is obtained, and the new quantum key is transmitted on the time slot resource.
According to another aspect of the present invention, there is also provided a system for dynamically updating a quantum key in an optical network, including:
the new key triggering module is used for generating a new quantum key within the duration of a data service and a key updating period based on a dynamic key updating mechanism;
and the new secret key transmission module is used for acquiring the transmission resource of the new quantum secret key in the optical network and transmitting the new quantum secret key to encrypt the data service.
And the key retransmission module is used for retransmitting the new quantum key which fails to be updated within the duration of the data service based on a key retransmission mechanism of the time window.
The application provides a dynamic updating method and a system of quantum keys in an optical network, provides a dynamic key updating mechanism according to different requirements of the optical network, and particularly provides two quantum key updating period configuration strategies; the arrival of a key updating request is dynamically triggered according to a configuration strategy of a quantum key updating period, so that the problem that the quantum key fixed updating period is easy to damage is solved; and a retransmission mechanism after the quantum key updating fails is provided, the condition of the quantum key updating failure is processed, and the effective transmission of the quantum key is ensured, so that the encrypted transmission of the data service is ensured.
Drawings
FIG. 1 is a diagram illustrating a quantum key update mechanism based on a fixed period in the prior art;
FIG. 2 is a schematic diagram of an end-to-end quantum key distribution system of the present invention;
FIG. 3 is a flow chart of a method for dynamically updating quantum keys in an optical network according to the present invention;
FIG. 4 is a schematic diagram of a dynamic key update mechanism based on quantum key wavelength channels according to the present invention;
FIG. 5 is a diagram illustrating a dynamic key update mechanism based on a random distribution policy according to the present invention;
fig. 6 is a schematic diagram of a system for dynamically updating a quantum key in an optical network according to the present invention.
Detailed Description
The following detailed description of embodiments of the present invention is provided in connection with the accompanying drawings and examples. The following examples are intended to illustrate the invention but are not intended to limit the scope of the invention.
Fig. 2 is a schematic diagram of an end-to-end quantum key distribution system, which is a basis for implementing the present invention.
As shown in fig. 2, the quantum key distribution system includes an Alice sender and a Bob receiver, where the Alice sender includes a quantum transmitter and a sender data transceiver; the Bob receiver comprises a quantum receiver and a receiver data transceiver; the quantum key distribution system also comprises an optical fiber connecting the Alice sender and the Bob receiver, and a data channel (TDCh), a quantum key channel (QKCh) and a measurement base channel (MBCh) shared by the Alice sender and the Bob receiver are realized on the optical fiber through a Wavelength Division Multiplexing (WDM) technology.
The Quantum Key Distribution (QKD) system guarantees theoretically unconditional secure communication based on the "measurement collapse theory", "heisenberg inaccuracy principle" and "quantum unclonable law" in quantum mechanics. The Quantum Key Distribution (QKD) system utilizes three types of channels for communication, namely a data channel (TDCh), a quantum key channel (QKCh), and a measurement base channel (MBCh); the data channel (TDCh) is used for transmitting data service information, the data channel (TDCh) is used for transmitting a quantum key, the data channel (TDCh) is used for transmitting and receiving end information interaction and finishing measurement base information confirmation, and two states which are mutually orthogonal can be regarded as a measurement base. The function and implementation principle of the three channels can refer to BB84 protocol.
As shown in fig. 3, a method for dynamically updating a quantum key in an optical network includes:
s1, generating a new quantum key in the duration of a data service and a key updating period based on the dynamic key updating mechanism;
and S2, acquiring the transmission resource of the new quantum key in the optical network, and transmitting the new quantum key to encrypt the data service.
The invention provides a dynamic key updating mechanism for solving the problem that the fixed updating period of a quantum key is easy to damage; generating new quantum keys regularly according to the updating period of the quantum keys within the duration of one data service for updating the quantum keys of the data service; the quantum key and the data service are transmitted synchronously all the time to ensure the safety of the data service.
The method for dynamically updating the quantum key in the optical network further comprises the following steps:
and S3, retransmitting the new quantum key failed in transmission within the duration of the data service by using a key retransmission mechanism based on the time window.
In the communication transmission process, the problem of transmission failure or other problems causing the update failure of the new quantum key inevitably exists, so the invention provides a key retransmission mechanism based on a time window, and the key retransmission mechanism is used for retransmitting the key which is failed to update.
The transmission failure includes two cases:
first, the key update fails for the first time.
And secondly, retransmitting the key after the key updating fails for the first time, but failing again, and the failure times are not limited.
For the quantum key failed in transmission, no matter how many times the quantum key fails, retransmission is carried out according to a key retransmission mechanism as long as the data service is not transmitted and enough time is available for retransmitting the quantum key within the remaining duration of the data service.
Specifically, the dynamic key update mechanism in S1 includes:
based on the quantum key wavelength channels, different quantum key wavelength channels provide different first key updating periods, and the quantum key is updated on one quantum key wavelength channel according to a preset time interval; and/or
And based on a random distribution strategy, providing a randomized second key updating period for different data services, and updating the quantum key of the data service on one quantum key wavelength channel according to a randomized time interval.
Fig. 4 is a schematic diagram of a dynamic key update mechanism based on quantum key wavelength channels according to the present invention. A quantum key updating period service is provided in one quantum key wavelength channel, and different quantum key wavelength channels provide different quantum key updating period services.
The quantum key updating mechanism based on the quantum key wavelength channel comprises two conditions that:
firstly, updating the quantum key on a quantum key wavelength channel according to a fixed time interval.
And secondly, updating the quantum key on one quantum key wavelength channel according to a certain period of time interval. For example, a period {1, 2, 3, 4} is set for a quantum key wavelength channel, and the quantum key is periodically updated at time intervals of 1 second, 2 seconds, 3 seconds and 4 seconds; a period {4, 2, 1, 3} is set for another quantum key wavelength channel, and the quantum key is periodically updated at intervals of 4 seconds, 2 seconds, 1 second, and 1 second.
As shown in fig. 4, for an update period of a fixed time, the quantum key wavelength channels with four wavelengths respectively provide four different quantum key update period services; the horizontal axis with arrows indicates that one wavelength is time-slotted in the time dimension, and the time-slotted intervals are different for different wavelengths. Compared with a configuration method of a fixed key updating period, the key updating period configuration method based on the quantum key wavelength channel can provide more kinds of key updating period services.
Fig. 5 is a schematic diagram of a dynamic key update mechanism based on a random allocation policy according to the present invention. The quantum key update period of each data service may be randomly selected according to a certain distribution, such as: random distribution, gaussian distribution, rayleigh distribution, or the like. As shown in fig. 5, the quantum key update period of each service is completely randomized, and the configuration method of the quantum key update period is not easily cracked by an attacker, so that the quantum key is prevented from being damaged, and the security of the quantum key can be further improved.
The dynamic key updating mechanism based on the quantum key wavelength channel and the dynamic key updating mechanism based on the random distribution strategy can be mixed in an optical network and can also be respectively and independently used. For example, in an optical network, a dynamic key updating mechanism based on a quantum key wavelength channel is adopted for all network data services; or a dynamic key updating mechanism based on a random distribution strategy is adopted; or a dynamic key updating mechanism based on a quantum key wavelength channel is adopted for one part of data services in the optical network, and a dynamic key updating mechanism based on a random distribution strategy is adopted for the other part of data services in the optical network.
In an alternative embodiment, in an optical fiber of the optical network, a wavelength data channel D1 is used to transmit a data service a, and the data service a is encrypted by using a dynamic key update mechanism based on a quantum key wavelength channel, that is, a quantum key channel Q1 is selected, and a quantum key of the data service a is updated according to a key update period of the quantum key channel Q1. In the same optical fiber, a wavelength data channel D2 is used to transmit a data service B, the data service B is encrypted by using a dynamic key update mechanism based on a random allocation strategy, that is, a quantum key channel Q2 is selected, a random key update period is generated for the data service B, and a quantum key of the data service B is updated on the quantum key channel Q1 according to the random key update period, thereby realizing the hybrid use of the quantum dynamic update mechanism.
As an alternative embodiment, the S1 further includes:
s1.1, determining a specific key updating period of the data service;
s1.2, based on the specific key updating cycle, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key, and if so, generating a new quantum key.
This embodiment specifically determines whether the data service updates the quantum key according to the dynamic key update mechanism based on the quantum key wavelength channel or according to the dynamic key update mechanism based on the random allocation policy.
For each key update in the update period, whether the key update can be performed needs to be judged, if the key update can be performed, a new quantum key is generated, and otherwise, the new quantum key cannot be generated and directly enters the next update period. After the generation and transmission of the quantum key are completed in one updating period, the next updating period is entered, and whether the updating can be carried out or not is judged according to the same method.
As an alternative embodiment, the S1.1 further comprises: and after the first quantum key transmission is finished, determining the first key updating period or the second key updating period as the specific key updating period.
As an alternative embodiment, the S1.2 further comprises:
s1.2.1, after the transmission of the current quantum key is finished, generating a next quantum key updating request;
s1.2.2, based on the update request, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key;
s1.2.3, if sufficient rekeying occurs, a new quantum key is generated at the particular rekeying period.
In an alternative embodiment, a data traffic arrives for a duration of 10s, taking the first rekeying period. And assuming that the updating period of the quantum key is a fixed value of 2s, judging whether the remaining duration of the data service is enough for carrying out next key updating, if so, triggering the next quantum key updating process after 2s, otherwise, ending the quantum key updating process. Assuming that the remaining duration of the data service is 1s and is less than one quantum key update period, ending the quantum key update process; and assuming that the remaining duration of the data service is 2s and is enough for one quantum key updating period, triggering the next quantum key updating process.
As an alternative embodiment, the S2 further includes:
s2.1, taking the source node and the destination node of the data service as end points, and obtaining a shortest path as a key route of the new quantum key in the optical network physical topology;
s2.2, quantum key wavelength resources are obtained on each path of the key route, and the new quantum key is transmitted according to the quantum key wavelength.
The embodiment completes the routing calculation and transmission resource allocation of the quantum key channel. Since the new quantum key serves the data service, the new quantum key and the data service have the same source node and sink node, so that the source node and sink node perform routing to obtain the key route.
And on each path of the key route, acquiring wavelength resources according to the quantum key channel distributed by the new quantum key, and transmitting the new quantum key on the wavelength.
As an optional embodiment, the present invention may further perform time slot division on the wavelength resource of the quantum key channel, obtain the time slot resource of the wavelength resource of the quantum key according to the time slot allocated by the new quantum key, and transmit the new quantum key on the time slot resource.
As an alternative embodiment, the S3 further includes:
s3.1, taking a time period from the current time to the completion of the data service transmission as a retransmission time window, and randomly selecting the starting time of one time period in the specific key updating period as retransmission time in the retransmission time window;
s3.2, judging whether the transmission of the new quantum key can be finished in the time period from the retransmission time to the completion of the data service transmission;
and S3.3, if the transmission of the new quantum key can be completed, distributing routing and quantum key wavelength resources for the new quantum key and transmitting the new quantum key.
The present embodiment has similar operations to the normal quantum key update process, selects retransmission time, determines whether transmission is possible, and obtains transmission resources for transmission. And when the transmission of the new quantum key cannot be completed in the time period from the retransmission time to the completion of the data service transmission, not retransmitting the new quantum key.
As shown in fig. 6, the present invention further provides a system for dynamically updating a quantum key in an optical network, including:
the new key triggering module is used for generating a new quantum key within the duration of a data service and a key updating period based on a dynamic key updating mechanism;
and the new secret key transmission module is used for acquiring the transmission resource of the new quantum secret key in the optical network and transmitting the new quantum secret key to encrypt the data service.
And the key retransmission module is used for retransmitting the new quantum key which fails to be updated within the duration of the data service based on a key retransmission mechanism of the time window.
The application provides a method and a system for dynamically updating a quantum key in an optical network, which have the core that the updating period of the quantum key is dynamically set, so that an attacker cannot easily damage the distribution of the quantum key. Firstly, determining a corresponding dynamic key updating mechanism according to different network service conditions; then judging whether the data service duration needs to update the next key or not so as to trigger the next key updating request; and performing calculation and resource allocation on each arriving request for updating the key. Finally, a quantum key failure retransmission mechanism based on a time window is provided for the condition of key update failure.
The dynamic key updating mechanism of the invention effectively solves the problem that the fixed updating period of the key is easy to damage, avoids the problem of key leakage after key distribution, particularly overcomes the problem that the key is damaged in the transmission process, and has good beneficial effect.
Finally, the method of the present application is only a preferred embodiment and is not intended to limit the scope of the present invention. Any modification, equivalent replacement, or improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims (9)

1. A method for dynamically updating quantum keys in an optical network, comprising:
s1, generating a new quantum key in the duration of a data service and a key updating period based on the dynamic key updating mechanism;
s2, obtaining the transmission resource of the new quantum key in the optical network, and transmitting the new quantum key to encrypt the data service;
the dynamic key update mechanism in S1 includes:
based on the quantum key wavelength channels, different quantum key wavelength channels provide different first key updating periods, and the quantum keys are updated on one quantum key wavelength channel according to the same time interval; and/or
And based on a random distribution strategy, providing a randomized second key updating period for different data services, and updating the quantum key of the data service on one quantum key wavelength channel according to a randomized time interval.
2. The method of claim 1, further comprising:
and S3, retransmitting the new quantum key failed to update within the duration of the data service by using a key retransmission mechanism based on the time window.
3. The method of claim 1, wherein the S1 further comprises:
s1.1, determining a specific key updating period of the data service;
s1.2, based on the specific key updating cycle, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key, and if so, generating a new quantum key.
4. The method of claim 1, wherein the S2 further comprises:
s2.1, taking the source node and the destination node of the data service as end points, and obtaining a shortest path as a key route of the new quantum key in the optical network physical topology;
s2.2, quantum key wavelength is obtained on each path of the key route, and the new quantum key is transmitted according to the quantum key wavelength.
5. The method of claim 2, wherein the S3 further comprises:
s3.1, taking a time period from the current time to the completion of the data service transmission as a retransmission time window, and randomly selecting the starting time of one time period in a specific key updating period in the retransmission time window as retransmission time;
s3.2, judging whether the transmission of the new quantum key can be finished in the time period from the retransmission time to the completion of the data service transmission;
and S3.3, if the transmission of the new quantum key can be completed, distributing routing and quantum key wavelength resources for the new quantum key and transmitting the new quantum key.
6. The method of claim 3, wherein the S1.1 further comprises: and after the first quantum key transmission is finished, determining the first key updating period or the second key updating period as the specific key updating period.
7. The method of claim 3, wherein the S1.2 further comprises:
s1.2.1, after the transmission of the current quantum key is finished, generating a next quantum key updating request;
s1.2.2, based on the update request, judging whether the time period from the current time to the completion of the data service transmission is enough to update the key;
s1.2.3, if sufficient rekeying occurs, a new quantum key is generated at the particular rekeying period.
8. The method of claim 4 or 5, wherein a time slot resource of the quantum key wavelength resource is obtained, and the new quantum key is transmitted on the time slot resource.
9. A system for dynamically updating quantum keys in an optical network, comprising:
the new key triggering module is used for generating a new quantum key within the duration of a data service and a key updating period based on a dynamic key updating mechanism; the dynamic key update mechanism comprises: based on the quantum key wavelength channels, different quantum key wavelength channels provide different first key updating periods, and the quantum keys are updated on one quantum key wavelength channel according to the same time interval; and/or based on a random distribution strategy, providing a randomized second key updating period for different data services, and updating the quantum key of the data service on a quantum key wavelength channel according to a randomized time interval;
a new key transmission module, configured to obtain a transmission resource of the new quantum key in an optical network, and transmit the new quantum key to encrypt the data service;
and the key retransmission module is used for retransmitting the new quantum key which fails to be updated within the duration of the data service based on a key retransmission mechanism of the time window.
CN201611267815.1A 2016-12-31 2016-12-31 Dynamic updating method and system for quantum key in optical network Active CN106712941B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201611267815.1A CN106712941B (en) 2016-12-31 2016-12-31 Dynamic updating method and system for quantum key in optical network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201611267815.1A CN106712941B (en) 2016-12-31 2016-12-31 Dynamic updating method and system for quantum key in optical network

Publications (2)

Publication Number Publication Date
CN106712941A CN106712941A (en) 2017-05-24
CN106712941B true CN106712941B (en) 2020-09-04

Family

ID=58905654

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201611267815.1A Active CN106712941B (en) 2016-12-31 2016-12-31 Dynamic updating method and system for quantum key in optical network

Country Status (1)

Country Link
CN (1) CN106712941B (en)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107171792A (en) * 2017-06-05 2017-09-15 北京邮电大学 A kind of virtual key pond and the virtual method of quantum key resource
CN109067519B (en) * 2018-07-25 2021-11-09 科华数据股份有限公司 Method, system and related device for adjusting quantum key updating frequency
CN109167637B (en) * 2018-08-13 2021-06-01 国科量子通信网络有限公司 Key pool filling resource determination method, device, equipment and readable storage medium
CN111049588B (en) * 2019-10-31 2021-05-18 北京邮电大学 Quantum service deployment method and device based on quantum key pool state
CN114071264B (en) * 2021-11-12 2024-01-23 国网上海市电力公司 Communication method of network service on endogenous safe optical network and endogenous safe optical network

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103023579A (en) * 2012-12-07 2013-04-03 安徽问天量子科技股份有限公司 Method for conducting quantum secret key distribution on passive optical network and passive optical network
CN106230585A (en) * 2016-07-22 2016-12-14 安徽皖通邮电股份有限公司 A kind of method that quantum key Fast synchronization updates

Also Published As

Publication number Publication date
CN106712941A (en) 2017-05-24

Similar Documents

Publication Publication Date Title
CN106712941B (en) Dynamic updating method and system for quantum key in optical network
Cao et al. Key on demand (KoD) for software-defined optical networks secured by quantum key distribution (QKD)
CN110581763B (en) Quantum key service block chain network system
Cao et al. KaaS: Key as a service over quantum key distribution integrated optical networks
EP2366231B1 (en) Method of establishing a quantum key for use between network nodes
EP2003812B1 (en) Method and device for managing cryptographic keys in secret communications network
CN108111305B (en) Multi-type quantum terminal compatible converged network access system and method
CN105471576A (en) Quantum key relaying method, quantum terminal nodes and quantum key relaying system
CN106850204A (en) Quantum key distribution method and system
CN103685217A (en) Method and apparatus for determining a cryptographic key in a network
CN109660337B (en) Quantum and classical converged communication network system and key distribution method thereof
US20210367773A1 (en) Quantum key distribution method and system based on tree qkd network
JP2017514404A (en) How to generate a secret or key in the network
US20090279698A1 (en) Hub Device for a Network Comprising Quantum Cryptographic Connections and Node Module for Said Hub Device
KR20120105507A (en) Method and system for establishing secure connection between user terminals
CN101662705A (en) Equipment authentication method of Ethernet passive optical network (EPON) and system thereof
JP2007053591A (en) Quantum encryption key distribution system and method
US20150139425A1 (en) Key managing system and method for sensor network security
CN102546184A (en) Method and system for message secure transmission or key distribution in sensor network
Wang et al. A flexible key-updating method for software-defined optical networks secured by quantum key distribution
CN111342952A (en) Safe and efficient quantum key service method and system
CN103888940A (en) Multi-level encryption and authentication type WIA-PA network handheld device communication method
US20070055870A1 (en) Process for secure communication over a wireless network, related network and computer program product
KR101602497B1 (en) Method for providing mac protocol for data communication security in wireless network communication
EP3782325B1 (en) Path computation engine and method of configuring an optical path for quantum key distribution

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant