arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

WLPA:一种在最弱链路暴露下分配稀缺量子安全链路姿态的网络管理框架

WLPA: A Network Management Framework for Allocating Scarce Quantum-Safe Link Postures under Weakest-Link Exposure

Bhanwar Gupta, Sanjeev Rana

arXiv 2610.04897首次发表:更新:

发表机构

Maharishi Markandeshwar (Deemed to be) University(玛哈里希·马尔坎德什瓦尔大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对量子安全迁移中稀缺QKD资源的分配问题,提出WLPA框架,以闭式解和高效算法实现最弱链路姿态最优分配,并通过二分法指导启发式方法的适用性,实验验证其有效性。

AI 中文摘要

网络运营商在将分布式系统迁移至后量子与量子安全密码学时面临一个资源管理问题:量子密钥分发(QKD)提供现有最强的安全保障,但硬件稀缺且成本高昂,因此部署中只有一部分链路能够获得该保障。默认做法——按流量或中心性对链路排序并升级排名最高的链路——孤立地优化每条链路,而分布式任务的实际安全性由最终最弱的活跃链路决定。我们提出WLPA(最弱链路姿态分配),一个可直接实施的决策框架和算法,用于在硬件、延迟和合规约束下分配稀缺的量子安全姿态。WLPA以闭式形式计算最优最弱链路姿态,并在O(|E| log |E|)时间内返回分配结果——在笔记本电脑上处理20,000条链路的网络仅需125毫秒——其泄露感知的细化方法在常见条件下与精确整数规划相匹配。我们的核心贡献是一个二分法,精确告知运营商现有逐链路启发式方法何时已匹配该最优解,以及何时系统性失效:在恒定升级成本和均匀流量驱动风险下,两者完全一致;一旦成本变化或对手集中攻击弱目标,启发式方法会使最弱链路无保护地暴露,且差距无界。我们通过19个实验验证WLPA:四种微服务拓扑、一个真实企业网络(SNAP email-Eu-core)、一个后量子延迟基准、一个Qiskit BB84模拟以及IBM ibm_marrakesh处理器上的真实硬件BB84运行,对照真实生产流量轨迹的检查、CVE校准的相关妥协研究、贝叶斯不确定性量化,以及七种基线方法。具体安全性归约作为理论基座,而非主要贡献。

英文摘要

Network operators migrating distributed systems to post-quantum and quantum-safe cryptography face a resource-management problem: quantum key distribution (QKD) gives the strongest guarantee available but is hardware-scarce and costly, so only a fraction of a deployment's links can receive it. Default practice -- ranking links by traffic or centrality and upgrading the top scorers -- optimizes each link in isolation, while a distributed job's real security is set by whichever active link ends up weakest. We present WLPA (Weakest-Link Posture Assignment), an implementation-ready decision framework and algorithm for allocating scarce quantum-safe postures under hardware, latency, and compliance constraints. WLPA computes the optimal weakest-link posture in closed form and returns an assignment in O(|E| log |E|) time -- 125 ms for a 20,000-link network on a laptop -- with a breach-aware refinement matching an exact integer program under common conditions. Our central contribution is a dichotomy telling operators exactly when existing per-link heuristics already match this optimum and when they systematically fail: under constant upgrade cost and uniform traffic-driven risk the two coincide exactly; once costs vary or an adversary concentrates on weak targets, heuristics leave the weakest link unprotected, unboundedly. We validate WLPA across 19 experiments: four microservice topologies, a real enterprise network (SNAP email-Eu-core), a post-quantum latency benchmark, a Qiskit BB84 simulation and a real-hardware BB84 run on IBM's ibm_marrakesh processor, checks against real production traffic traces, a CVE-calibrated correlated-compromise study, Bayesian uncertainty quantification, and seven baseline methods. A concrete-security reduction grounds the framework as theoretical foundation, not primary contribution.

CommentsNetwork resource management; Quantum-safe network design; Post-quantum migration; Cloud and cluster network operations; Quantum key distribution; Security allocation algorithms; Zero Trust architecture

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑