A data transmission integrity verification system and method based on polynomial rings
By utilizing a polynomial ring-based data transmission integrity verification system, and employing a symmetric key library and polynomial modulo operations, the system addresses the challenges of resisting attacks from artificial intelligence and quantum computing in existing technologies. It achieves unconditionally secure data transmission integrity verification, making it suitable for cloud storage and application update scenarios.
Patent Information
- Application Number
- CN202510784892.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2045-06-12
AI Technical Summary
Existing technologies are insufficient to defend against cryptographic attacks brought about by artificial intelligence and quantum computing, especially reducing the security of classical cryptographic systems. A new method for verifying the integrity of data transmission is needed to improve security.
A data transmission integrity verification system based on polynomial rings is adopted. Data integrity verification is performed by using keys in a symmetric key library and polynomial modulo operations to ensure that data is not tampered with during transmission. Security relies on mathematical principles rather than mathematical problems.
It achieves the ability to resist cryptographic attacks from artificial intelligence and quantum computing, possesses unconditional security, and effectively prevents data tampering in cloud storage and application update scenarios.
Smart Images

Figure CN120301597B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a polynomial ring-based data transmission integrity verification system and method, belonging to the technical field of data security. BACKGROUND
[0002] The tide of artificial intelligence and quantum computing, as the core force of new generation of technological revolution, is profoundly changing human society. Artificial intelligence and quantum computing promote social progress, while also having a profound impact on the field of network security. Artificial intelligence improves the level of automated defense of information systems, and quantum computing drives the computing revolution, enabling secure distribution of secret keys. However, while artificial intelligence and quantum computing help develop network security, they also pose a significant challenge to network security. In particular in the field of cryptography, artificial intelligence and quantum computing will reshape the pattern of cryptanalysis. Artificial intelligence breaks through the limits of cryptanalysis through deep learning, enabling autonomous identification of encryption mechanisms and automated mining of cryptographic protocol vulnerabilities. Quantum computing significantly reduces the security level of classical cryptographic systems. Quantum Shor algorithm can directly break RSA and Elliptic Curve Cryptography (ECC) through the parallelism and superposition of quantum computing. Quantum Grover algorithm can directly halve the security strength of symmetric encryption and hash algorithms. The global wave of post-quantum cryptography (PQC) is currently underway. The United States will replace PQC in its entirety by 2035. The China Commercial Cryptography Standard Research Institute officially launched a call for new generation of quantum-resistant cryptographic algorithms in February 2025.
[0003] The current country is developing a trusted data space, and data transmission is the basis for ensuring data security and building a trusted data space. Because data is subject to security threats such as impersonation, forgery, and tampering during transmission, it is important to establish a high-trust integrity verification algorithm for data transmission to verify the trustworthiness of the transmitted data in real time.
[0004] In view of the great threat of artificial intelligence and quantum computing to the cryptographic system, the present application proposes a polynomial ring-based data transmission integrity verification method to resist cryptanalysis through random distribution, whose security only depends on mathematical principles and has unconditional security. SUMMARY
[0005] The technical problem to be solved by the present application is to provide a polynomial ring-based data transmission integrity verification system and method, which is different from the conventional cryptographic design based on mathematical problems, and only relies on mathematical principles to design an integrity verification mechanism to resist various cryptographic attacks based on artificial intelligence and quantum computing, thereby improving the security of data integrity verification to resist security threats from artificial intelligence and quantum computing.
[0006] To solve the above technical problems, the technical solution adopted by the present application is:
[0007] The system of the present application comprises two entities, user A and user B, which have the same structure. For the convenience of description, it is assumed that user A is responsible for sending data and user B is responsible for receiving data.
[0008] The user A (user B) structure comprises a symmetric key library, an integrity checking module and a data transmission module. Among them, the data transmission module is mainly responsible for accepting the binary stream data transmitted and converting it into an element in the polynomial ring for subsequent checking by the integrity checking module, and is also responsible for converting the checked data into a binary stream and sending it; the integrity checking module is responsible for sequentially selecting keys from the symmetric key library and checking the integrity of the data through polynomial modulo operation to ensure that the data is not tampered with. The data involved in the technical solution refers to the data stored by the computing device and the network communication data.
[0009] The symmetric key library stores a plurality of symmetric keys shared by user A and user B. Each key is stored according to an entry, and the specific structure of each entry is as follows:
[0010] .
[0011] is the key label, is the key, is the base used to calculate the check value. Among them, and have the same length and are ), both of which are randomly selected in the key space K and the base space F. is the number of key library data entries. Note that each entry in the symmetric key library is used only once, and then moved sequentially by one. The key is only used by the integrity checking module and is stored in a secure manner.
[0012] The function of the integrity checking module is divided into two parts:
[0013] Integrity checking module (when sending data):
[0014] 1) Convert the input data into an element in the polynomial ring . Let the input data be , where is the data label of the data, is the length of the data, and the data content . The data encoding module converts into an element in . At this time, the element group is formed, is the element polynomial.
[0015] 2) Calculate the check value. Take the next key entry from the symmetric key library in order , for Calculate the check value
[0016]
[0017] 3) Convert to bit binary data stream MAC. Send to the transmission module.
[0018] Integrity check module (when receiving data):
[0019] Suppose the received data is , take the key entry with label from the symmetric key library , decrypt to get the data content , and convert it to an element in the polynomial ring . Suppose the converted element polynomial is , and judge:
[0020]
[0021] If it is true, output T=1, indicating that the data has not been tampered with in the transmission process, otherwise output T=0, indicating that the data has been tampered with in the transmission process.
[0022] Transmission module:
[0023] 1) When sending data, send the data to the data receiver through the public network.
[0024] 2) When receiving data, receive the data through the public network and send it to the integrity check module.
[0025] The method of the application comprises the following steps:
[0026] Initialization phase: The symmetric key libraries of user A and user B share N key entries. The initial key label KID=0.
[0027] Step one: input data, the integrity check module of user A converts the data content of the input data into an element in the polynomial ring , and generates an element group.
[0028] Step two: the integrity check module of user A selects key entries in the symmetric key library in order.
[0029] Step three: the integrity check module of user A uses the element polynomial to solve the modulus of the base, converts the check value obtained by solving the modulus into a binary stream, encrypts the binary stream using the secret key, and splices the encrypted binary stream with the original data to send to the transmission module of user A.
[0030] Step four: the transmission module of user A sends the data to user B through a public network.
[0031] Step five: the transmission module of user B receives the data and forwards the data to the integrity check module of user B.
[0032] Step six: the integrity check module of user B takes the secret key item from the symmetric key library according to the secret key label, and decrypts the integrity check value.
[0033] Step seven: the integrity check module of user B converts the decrypted data content into an element polynomial in the polynomial ring .
[0034] Step eight: user B uses the element polynomial to solve the modulus of the base, and if the result is 0, outputs T=1, indicating that the data has not been tampered with in the transmission process, otherwise outputs T=0, indicating that the data has been tampered with in the transmission process.
[0035] The beneficial effects of the present application are:
[0036] 1、The present application is different from the conventional password based on mathematical problems, which is difficult to resist the password analysis based on artificial intelligence and quantum computing, and only relies on the design of integrity check mechanism based on mathematical principles, and the random selection of the base of the polynomial ring is used for data integrity check to resist various password attacks based on artificial intelligence and quantum computing.
[0037] 2、The security of the present application only depends on mathematical principles, and does not depend on any mathematical problems, and has the property of unconditional security. BRIEF DESCRIPTION OF DRAWINGS
[0038] Figure 1 Data transmission integrity check system based on polynomial ring;
[0039] Figure 2 Data transmission integrity check system based on polynomial ring working flow chart. DETAILED DESCRIPTION
[0040] The system framework diagram of the present application is shown as Figure 1 , the working flow chart of the data transmission integrity check system based on polynomial ring is shown as Figure 2 , and the background mathematical knowledge of the method of the present application is as follows:
[0041] 1、Polynomial ring satisfies the following properties:
[0042] (1)
[0043] (2) Let , then
[0044] (3) Let , , then
[0045] .
[0046] 2、 The set of polynomials of degree n is defined as follows:
[0047] .
[0048] 3、 The set of irreducible polynomials of degree n is defined as follows:
[0049]
[0050] .
[0051] 4、 Let be a polynomial of degree n, satisfying
[0052] ,
[0053] If: then define The modulo operation on is:
[0054] ,
[0055] is called the remainder polynomial.
[0056] 5、Define the base space is a set with not less than elements. The base is an element in the base space .
[0057] 6、Define the key space is a set with not less than elements. The key is an element in the key space .
[0058] The technical solutions of the present application will be described in detail below in combination with two specific examples.
[0059] Embodiment 1: Integrity verification of data transmission in cloud storage scenario
[0060] User A (file uploader) uploads a file to cloud storage service provider (user B) through client application. In order to ensure that the file is not tampered during the uploading process, the cloud storage service uses the integrity verification method proposed in the present application.
[0061] Initialization phase: The client application of user A and the cloud storage server of user B share N key entries in advance through an out-of-band secure channel (for example, when the user registers or through a secure key exchange protocol). These key entries are stored in the symmetric key library of user A and user B respectively. Each key entry contains key label KID, key Key and base KID is the label of the key entry, used to identify the key entry used in the subsequent data transmission process. The initial key label KID=0, the base space F is the set of 256 irreducible polynomials , and the key space is the set of 256 binary numbers. Uniformly randomly select in the base space A (use random number generator and use the irreducible polynomial judgment method in GF(2)[x] to repeatedly generate polynomials and judge). Uniformly randomly select the key Key in the key space (space) (use random number generator to generate polynomials). The generated base and key Key form a key entry. The key entry is shared between user A and user B.
[0062] Step one: The client application of user A divides the file to be uploaded into multiple data blocks. Each data block is processed as a separate input data. The data encoding module converts the data content of each data block into an element in the polynomial ring , for example, assuming that the data content is 300-bit binary data "100……001", the data encoding module converts it into element polynomial , where the data length is required. The data encoding module generates an element group for the data block, which represents the ID of the data block, the data length, and the converted element polynomial respectively.
[0063] Step two: The integrity verification module of the client application of user A selects a key entry from its symmetric key library in order.
[0064] Step three: The integrity verification module of the client application of user A uses the element polynomial The base is taken modulo the key entry in the selected key entry to get the check value . is converted to a 256-bit binary data stream MAC. The MAC is concatenated with the original data to form a data packet .
[0065] Step four: the transmission module of user A sends the data packet to user B through a public network.
[0066] Step five: the transmission module of the cloud storage server of user B receives the data packet and forwards it to the integrity check module of user B.
[0067] Step six: the integrity check module of user B sequentially takes out the key entry from the symmetric key library , parses out , and uses the same data encoding method as user A to convert it into an element in the polynomial ring GF(2)[ ].
[0068] Step seven: the integrity check module of user B takes the base in the retrieved key entry modulo the base to determine whether the remainder is 0. If it is, output T = 1, indicating that the data has not been tampered with during transmission, and the cloud storage server of user B can continue to process the data block, for example, store it in the storage system. Otherwise, output T = 0, indicating that the data has been tampered with during transmission, and the cloud storage server of user B can discard the data block and send an error report to user A, asking for re-uploading of the data.
[0069] Embodiment 2: integrity check of data transmission in an application program update scenario
[0070] The user end requests a software package from a trusted software warehouse. To ensure that the file is not tampered with during download transmission, the user end and the trusted software warehouse use the integrity check method proposed by the present application.
[0071] Initialization phase: the user end and the trusted software warehouse pre-share key entries. These key entries are stored in the symmetric key libraries of the user end and the trusted software warehouse respectively. Each key entry contains a key label , a key , and a base (x) KID is the label of the key entry, used to identify the key entry used in the subsequent data transmission process, the initial key label KID = 0, the base space F is the 256 times irreducible polynomial space , the key space is the set of 256-bit binary numbers. Uniformly randomly select in the base space A (use a random number generator and use the irreducible polynomial discrimination method in to repeatedly generate polynomials and discriminate). The key Key is uniformly randomly selected in the key space (adopt a random number generator to generate a polynomial). The generated base and the key Key form a key entry. The key entry is shared between the user end and the trusted software warehouse.
[0072] Step one: in the generation of the check information phase, the trusted software warehouse divides the data to be uploaded into multiple data blocks. Each data block is processed as a separate input data. The data encoding module converts the data content of each data block into an element in the polynomial ring , for example, assuming that the data content is 300-bit binary data "100……001", the data encoding module converts it into the element polynomial , here it is required that the data length . The data encoding module generates an element group for the data block, respectively representing the , data length and converted polynomial of the data block.
[0073] Step two: the integrity check module of the trusted software warehouse selects a key entry from its symmetric key library in order.
[0074] Step three: the integrity check module of the trusted software warehouse uses the element polynomial to perform a modulo operation on the base in the selected key entry (modulo is equivalent to CRC256), and converts to a bit binary data stream MAC. The MAC is spliced with the original data to form a data packet .
[0075] Step four: the transmission module of the trusted software warehouse sends the data packet to the user end.
[0076] Step five: the transmission module of the user end receives the data packet and hands it over to the integrity check module of the user end.
[0077] Step six: the integrity verification module of the user end sequentially takes out the key entries from the symmetric key library and parses out the element group which is converted into an element in the polynomial ring GF(2)[ ]。 .
[0078] Step seven: the integrity verification module of user B carries out a modulo operation on the base in the retrieved key entry, judges whether the remainder is 0 or not, if yes, outputs T=1, indicating that the data has not been tampered with in the transmission process, the data integrity verification passes, and outputs . The user end can continue to process the data block. Otherwise, outputs T=0, indicating that the data has been tampered with in the transmission process, the user end can discard the data block and send an error report to the trusted software warehouse to request to resend the data.
[0079] The algorithm of the present application is implemented on Xilinx FPGA 100MHZ, and compared with the mainstream algorithms SM3, SHA2-256 and SHA3-256, and the results are as follows:
[0080] The present invention SM3 SHA2-256 SHA3-256 Throughput 9 Gbps 3.5 Gbps 3 Gbps 4 Gbps Occupied resources (LUT) 280 600 650 450 Occupied resources (FF) 190 500 500 380
[0081] It can be seen that the present application is superior to the existing algorithms in both throughput and resource occupation.
[0082] The data involved in the technical solution refers to any record of information in electronic or other forms, and especially the data refers to the data stored by a computing device and network communication data.
Claims
1. A polynomial ring based data transmission integrity checking system, characterized by, Two entities including user A and user B, user A is responsible for sending data, user B is responsible for receiving data; The composition of user A and user B both includes symmetric key library, integrity check module and data transmission module; The data involved refers to the data stored by the computing device and the network communication data; The data transmission module is responsible for receiving the binary stream data transmitted, converting the binary stream data into elements in the polynomial ring for subsequent checking by the integrity check module, and converting the checked data into binary stream and sending; The binary stream data is information recorded in electronic form; The integrity check module is responsible for selecting keys in the symmetric key library in turn and checking the input binary stream data by polynomial modulo method; The symmetric key library is used to store the symmetric keys shared by user A and user B; Each key is stored in the symmetric key library according to the entry, and the specific structure of each entry is as follows: , is a key tag, is a key, is a base for calculating the check value; wherein, and are equal in length and are , and are randomly selected in the key space K and the base space F, is the number of key library data entries, each entry in the symmetric key library is used only once, and then moved one step in sequence, and the key is only used for the integrity check module, and a secret storage method is adopted; Definition of base space is a set with not less than elements; base is an element in base space ; Definition of secret key space is a set with not less than elements; secret key is an element in secret key space ; is a polynomial ring; is defined as follows, .
2. The data transmission integrity check system based on polynomial ring according to claim 1, characterized in that, The working process of the integrity check module in user A is as follows: 1) Convert the input binary stream data into a polynomial ring. The elements in; let the input binary stream data be ,in Data labels for binary stream data. The length of the binary stream data. The data encoding module will Turn to Middle elements , forming an element group , It is an element-polynomial; 2) Calculate Check Value; Sequentially fetch next key entry from symmetric key vault , For Using On Modulo generation check value ; Convert to bit binary data stream MAC, send to transmission module; The working process of the integrity check module in user B is as follows: Let the input binary stream data be , the key entry with label is taken out from the symmetric key library , and the data content is decrypted to be an element in the polynomial ring , and let the transformed element polynomial be , and the modulus operation is performed by using , and the remainder is judged, if it is 0, then output T=1, indicating that the binary stream data has not been tampered in the transmission process, otherwise output T=0, indicating that the binary stream data has been tampered in the transmission process.
3. A polynomial ring based data transmission integrity checking system according to claim 1, wherein, The transmission module is both the data sender and the data receiver: 1) The transmission module sends data through the public network when sending data; to the data recipient; 2) When the transmission module receives data, the data is received through the public network; and sent to the integrity check module.
4. A method for data transmission integrity verification using the system of any one of claims 1-3, characterized in that, The method comprises the following steps: Initialization stage: the symmetric key libraries of user A and user B share N key entries, and the initial key label KID=0; Step one: input binary stream data, the integrity check module of user A converts the data content of the input binary stream data into elements in the polynomial ring and generates an element group; Step two: the integrity check module of user A selects key entries in the symmetric key library in order; Step three: the integrity check module of user A uses element polynomial to modulo the base, converts the check value obtained by modulo into binary stream, encrypts the binary stream with the key, and splices the binary stream data input in step one to send to the transmission module of user A; Step four: the transmission module of user A sends the spliced binary stream data to user B through the public network; Step five: the transmission module of user B receives the spliced binary stream data sent by A and forwards the data to the integrity check module of user B; Step six: the integrity check module of user B takes out the key entry from the symmetric key library according to the key label, and decrypts the integrity check value; Step seven: The integrity check module of user B converts the decrypted data content into an element polynomial in the polynomial ring Zq. Step eight: user B uses element polynomial to modulo the base, if the result is 0, output T=1, indicating that the binary stream data has not been tampered with in the transmission process, otherwise output T=0, indicating that the binary stream data has been tampered with in the transmission process.
Citation Information
Patent Citations
Hardware processing device of digital signature algorithm
CN119675854A