Internet of Things test platform adaptation method, system and device based on post quantum cryptography
By building a dynamic adaptation system driven by quantum threat perception, the security upgrade problem of IoT devices in the post-quantum computing era is solved, and efficient PQC algorithm execution and low-latency key update of resource-constrained devices are realized.
Patent Information
- Application Number
- CN202510318184.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-07-18
AI Technical Summary
When traditional IoT devices face post-quantum computing threats, they have problems such as static adaptation defects, performance bottlenecks and lack of evaluation systems. They cannot effectively deal with real-time quantum threats and are resource-constrained devices that are difficult to deploy NIST standardized post-quantum cryptography algorithms.
Build a dynamic adaptation system driven by quantum threat perception, and realize dynamic password switching and hardware acceleration optimization through quantum situational awareness module, heterogeneous cryptographic adaptation engine, performance evaluation matrix and trusted execution environment, and support dynamic loading of algorithms with dual architectures of Xilinx Zynq UltraScale+MPSoC and ARM Cortex-M33.
It improves the execution efficiency of PQC algorithms of resource-constrained devices, reduces the delay in key updates, and achieves the optimal balance between security and availability.
Smart Images

Figure CN120342587A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things encryption, and specifically relates to a method, system and device for adapting an Internet of Things test platform based on post-quantum cryptography. Background Art
[0002] With the rapid development of quantum computing technology (e.g., the IBM Osprey quantum processor has achieved 433 qubits), traditional public-key cryptosystems (RSA, ECC) face significant security threats. Internet of Things devices are difficult to directly deploy NIST-standardized post-quantum cryptography algorithms due to limited computing resources and difficult firmware updates. The prior art has the following defects: (1) Static adaptation defect: The PQC firmware upgrade scheme proposed in CN114726531A lacks a dynamic switching mechanism and cannot cope with real-time quantum threats; (2) Performance bottleneck: The lattice cipher accelerator designed in CN113438091B does not consider the memory and energy consumption constraints of Internet of Things devices; (3) Lack of evaluation system: Existing test platforms (such as the RFC 8446 compatibility test suite) do not integrate quantum attack simulation functions.
[0003] The innovation of the present invention lies in constructing a dynamic adaptation system driven by quantum threat perception to achieve the optimal balance between security and usability. Summary of the Invention
[0004] The present invention aims at the shortcomings in the prior art and provides a method, system and device for adapting an Internet of Things test platform based on post-quantum cryptography.
[0005] To solve the above technical problems, the present invention is solved by the following technical solutions:
[0006] A method for adapting an Internet of Things test platform based on post-quantum cryptography, comprising the following steps:
[0007] (1) Construct a quantum threat perception model, dynamically collect the hardware fingerprint information, network behavior characteristics and quantum computing evolution index of the target Internet of Things device, integrate a quantum random number generator and a Shor algorithm simulator, calculate the quantum attack success probability in real time, and output it to the heterogeneous cipher adaptation engine;
[0008] (2) Based on the heterogeneous cipher adaptation engine and the performance evaluation matrix generation unit, construct a comprehensive evaluation function including throughput, anti-side-channel attack ability and firmware update cost, establish a multi-dimensional adaptation decision matrix, comprehensively evaluate the device computing power level, energy consumption constraint and security level requirements, and generate a set of candidate post-quantum cryptography algorithms {PQCi};
[0009] (3) Execute dynamic injection of the cryptographic protocol, deeply couple the selected PQC algorithm with the lightweight TLS1.3 protocol stack, achieve lossless replacement of the encryption suite in the communication layer, and enable the heterogeneous cryptographic adaptation engine to support dynamic loading of algorithms for both the Xilinx Zynq UltraScale+ MPSoC and ARM Cortex-M33 architectures;
[0010] (4) Implement physical isolation storage and operation of key materials based on the trusted execution environment Intel SGX2.0 technology, deploy a runtime performance monitoring engine, and collect data on encryption and decryption latency, memory occupancy rate, and electromagnetic radiation characteristics in real time;
[0011] (5) Build an algorithm switching decision tree based on reinforcement learning, and trigger dynamic migration of cryptographic algorithms when quantum attack characteristics or device performance threshold breakthroughs are detected.
[0012] As an implementable approach, the multi-dimensional adaptation decision matrix in step (2) includes the following steps:
[0013] Hardware accelerator support matrix: Identify whether the device integrates the ARMv9 Cryptography Extension or the RISC-V vector instruction set extension;
[0014] Energy consumption sensitivity assessment model: Establish the power consumption-throughput relationship;
[0015] Security level mapping table: Configure weight coefficients for the third-round candidate algorithms of the NIST PQC standardization process according to MLWE and Hash-based classifications.
[0016] As an implementable approach, the protocol adaptation process in step (3) further includes the following steps:
[0017] a) Build a cryptographic suite fingerprint library to support the hybrid key exchange mode of CRYSTALS-Kyber and X25519;
[0018] b) Implement frame structure reorganization of the NTRU Prime algorithm and the DTLS record layer, and the encapsulation format complies with the IEEE802.15.4e standard;
[0019] c) Develop a customized header compression algorithm for LoRaWAN to optimize the PQC signature length to within 1.5 times the original ECDSA.
[0020] As an implementable approach, the algorithm switching in step (5) further includes the following steps:
[0021] i) When the quantum threat index QTI > 0.7, forcibly enable the Falcon-1024 digital signature scheme;
[0022] ii) When the remaining battery power of the device is detected to be less than 20%, automatically degrade to the SABER algorithm;
[0023] iii) In a wireless channel environment with a packet loss rate exceeding 5%, switch to the RLCE - Based encoding and decoding scheme.
[0024] As an implementable method, further, the above - mentioned solution further includes the following steps:
[0025] Propose a post - quantum key fusing mechanism based on a trusted execution environment. When side - channel attack characteristics are detected, automatically destroy the PQC master key and trigger blockchain evidence storage;
[0026] Design a sparse polynomial ring accelerator for resource - constrained devices to increase the key generation speed of the SABER algorithm by 3.2 times.
[0027] An Internet of Things test platform adaptation system based on post - quantum cryptography, including:
[0028] Quantum situation awareness module: Integrate a quantum random number generator and a Shor algorithm simulator to calculate the quantum attack success probability in real - time;
[0029] Heterogeneous cryptography adaptation engine: Support the dynamic loading of algorithms for both the Xilinx Zynq UltraScale + MPSoC and ARM Cortex - M33 architectures;
[0030] Performance evaluation matrix generation unit: Construct a comprehensive evaluation function including throughput, anti - side - channel attack ability, and firmware update cost;
[0031] Trusted execution environment: Use Intel SGX2.0 technology to achieve physical isolation storage and operation of key materials.
[0032] A computer - readable storage medium stores a computer program, and when the computer program is executed by a processor, the following method steps are implemented:
[0033] (1) Construct a quantum threat awareness model, dynamically collect the hardware fingerprint information, network behavior characteristics, and quantum computing evolution index of the target Internet of Things device;
[0034] (2) Establish a multi - dimensional adaptation decision matrix, comprehensively evaluate the device computing power level, energy consumption constraints, and security level requirements, and generate a set of candidate post - quantum cryptography algorithms {PQCi};
[0035] (3) Execute dynamic injection of the cryptographic protocol, deeply couple the selected PQC algorithm with the lightweight TLS1.3 protocol stack, and achieve lossless replacement of the communication - layer encryption suite;
[0036] (4) Deploy a runtime performance monitoring engine to collect data on encryption / decryption latency, memory occupancy rate, and electromagnetic radiation characteristics in real time;
[0037] (5) Build an algorithm switching decision tree based on reinforcement learning to trigger dynamic migration of cryptographic algorithms when quantum attack characteristics or device performance threshold breakthroughs are detected.
[0038] An adaptation device for an Internet of Things test platform based on post - quantum cryptography, comprising a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the following method steps are implemented:
[0039] (1) Build a quantum threat perception model to dynamically collect hardware fingerprint information, network behavior characteristics, and quantum computing evolution index of target Internet of Things devices;
[0040] (2) Establish a multi - dimensional adaptation decision matrix, comprehensively evaluate the device computing power level, energy consumption constraints, and security level requirements, and generate a set of candidate post - quantum cryptographic algorithms {PQCi};
[0041] (3) Execute dynamic injection of cryptographic protocols, deeply couple the selected PQC algorithm with a lightweight TLS1.3 protocol stack to achieve lossless replacement of communication layer encryption suites;
[0042] (4) Deploy a runtime performance monitoring engine to collect data on encryption / decryption latency, memory occupancy rate, and electromagnetic radiation characteristics in real time;
[0043] (5) Build an algorithm switching decision tree based on reinforcement learning to trigger dynamic migration of cryptographic algorithms when quantum attack characteristics or device performance threshold breakthroughs are detected.
[0044] Compared with the prior art, due to the adoption of the above - mentioned technical solutions, the present invention constructs an Internet of Things security adaptation system driven by quantum threat perception. By introducing a dynamic password switching mechanism, a hardware acceleration optimization scheme, and a trusted execution environment, the present invention solves the problem of security upgrade faced by traditional Internet of Things devices in the post - quantum era. The present invention can improve the execution efficiency of PQC algorithms for resource - constrained devices and reduce the key update delay, with significant technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 It is a flowchart of the adaptation method for the Internet of Things test platform based on post - quantum cryptography of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] To clearly illustrate the present invention and make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the accompanying drawings in the embodiments of the present invention are combined below, and the technical solutions in the embodiments of the present invention are described clearly and completely, so that those skilled in the art can implement them with reference to the text of the specification. The technology of the present invention will be described in detail below in combination with specific embodiments with reference to the accompanying drawings.
[0047] Figure 1 A implementation form according to the present invention is shown, and a basic flowchart of the adaptation method of the Internet of Things test platform based on post-quantum cryptography of the present invention is shown. The present invention realizes an adaptation method of an Internet of Things test platform based on post-quantum cryptography. The specific implementation steps include:
[0048] Step 1: Construct a quantum threat perception model to dynamically collect the hardware fingerprint information, network behavior characteristics, and quantum computing evolution index of the target Internet of Things device;
[0049] Step 2: Establish a multi-dimensional adaptation decision matrix, comprehensively evaluate the device computing power level, energy consumption constraint, and security level requirements, and generate a candidate set of post-quantum cryptography algorithms {PQCi};
[0050] Among them, the multi-dimensional adaptation decision matrix includes the following steps:
[0051] Step 1-1: Hardware accelerator support matrix: Identify whether the device integrates the ARMv9 Cryptography Extension (Reduced Instruction Set Microprocessor Cryptography Extension) or the RISC-V (Open Instruction Set Architecture) vector instruction set extension; among them, ARM: Advanced RISC Machine, RISC: Reduced Instruction Set Computer.
[0052] Step 1-2: Energy consumption sensitivity evaluation model: Establish a power consumption-throughput relationship;
[0053] Step 1-3: Security level mapping table: Configure weight coefficients for the third-round candidate algorithms of the NIST PQC (Post-Quantum Cryptography) standardization process according to MLWE (Lattice Cryptography) and Hash-based.
[0054] Step 3: Execute dynamic injection of the cryptographic protocol, deeply couple the selected PQC algorithm (post-quantum cryptography algorithm) with the lightweight TLS1.3 protocol (Transport Layer Security Protocol) stack, and realize the lossless replacement of the communication layer encryption suite;
[0055] Among them, the protocol adaptation process further includes the following steps:
[0056] Step 2-1: Construct a cipher suite fingerprint library to support the hybrid key exchange mode of CRYSTALS-Kyber (lattice-based key encapsulation mechanism) and X25519 (elliptic curve-based key exchange protocol);
[0057] Step 2-2: Implement NTRU Prime (reorganization of the frame structure based on the Polynomial Rings algorithm and the DTLS (Datagram Transport Layer Security Protocol) record layer, with the encapsulation format conforming to the IEEE 802.15.4e standard; IEEE 802.15.4 is a technical standard that defines the protocol for low-rate wireless personal area networks (LR-WPANs), specifies the physical layer and media access control of LR-WPANs, and is maintained by the IEEE 802.15 working group, which defined this standard in 2003;
[0058] Step 2-3: Develop a customized header compression algorithm for LoRaWAN (Long Range Wide Area Network) to optimize the PQC signature length to within 1.5 times the original ECDSA. LoRaWAN is a low-power, long-range communication protocol designed specifically for the Internet of Things field.
[0059] Step 4: Deploy a runtime performance monitoring engine to collect real-time data on encryption and decryption latency, memory occupancy rate, and electromagnetic radiation characteristics;
[0060] Step 5: Build an algorithm switching decision tree based on reinforcement learning to trigger dynamic migration of cryptographic algorithms when quantum attack characteristics or device performance threshold breakthroughs are detected.
[0061] Among them, the algorithm switching further includes the following steps:
[0062] Step 3-1: When the quantum threat index QTI > 0.7, forcibly enable the Falcon-1024 (lattice-based digital signature algorithm) digital signature scheme;
[0063] Step 3-2: When it is detected that the remaining battery power of the device is less than 20%, automatically degrade to the SABER algorithm (lattice-based key encapsulation algorithm);
[0064] Step 3-3: In a wireless channel environment with a packet loss rate exceeding 5%, switch to the RLCE-Based coding and decoding (coding and decoding based on random linear coding) (Random Linear Code, RLC) scheme.
[0065] Among them, the implementation of the above step solutions further includes the following steps:
[0066] Step 4-1: Propose a post-quantum key fusing mechanism based on a trusted execution environment. When side-channel attack characteristics are detected, automatically destroy the PQC master key and trigger blockchain evidence storage;
[0067] Step 4-2: Design a sparse polynomial ring accelerator for resource-constrained devices to boost the key generation speed of the SABER algorithm by 3.2 times.
[0068] Another embodiment of the present invention proposes an Internet of Things test platform adaptation system based on post-quantum cryptography, specifically including:
[0069] Quantum situation awareness module: Integrate a quantum random number generator and a Shor algorithm simulator to calculate the quantum attack success probability in real time; The Shor algorithm is based on period discovery and quantum Fourier transform and can solve the integer factorization problem in polynomial time;
[0070] Heterogeneous cipher adaptation engine: Support the dynamic loading of algorithms for dual architectures of Xilinx Zynq UltraScale+ MPSoC and ARM Cortex-M33; Xilinx Zynq UltraScale+ MPSoC is a high-performance, multi-functional system-on-chip (SoC) solution launched by Xilinx, designed specifically for embedded systems, high-performance computing, and data acceleration applications. ARM Cortex-M33 is a high-performance, low-power embedded processor core belonging to the ARMv8-M architecture. The configuration of the heterogeneous cipher adaptation engine includes:
[0071] The heterogeneous cipher adaptation engine includes:
[0072] Lattice-based cipher hardware acceleration core: Optimize the Number Theoretic Transform unit of the Kyber algorithm (a post-quantum cryptography algorithm for encryption and key encapsulation);
[0073] Hash post-quantum coprocessor: Integrate the HyperTree parallel constructor of the SPHINCS+ algorithm (a digital signature algorithm based on hash functions);
[0074] Coded cipher conversion layer: Provide a seamless migration interface from Classic McEliece (a key encapsulation mechanism KEM with IND-CCA2 security level) to the BIKE algorithm; IND-CCA2 (Indistinguishability under Chosen-Ciphertext Attack 2) refers to indistinguishability under adaptive chosen-ciphertext attack, which is a standard used in cryptography to evaluate the security of encryption algorithms, especially in public-key encryption algorithms, and IND-CCA2 is one of the strongest security requirements;
[0075] Performance evaluation matrix generation unit: construct a comprehensive evaluation function including throughput, resistance to side-channel attacks, and firmware update cost;
[0076] Trusted Execution Environment: Use Intel SGX 2.0 technology to achieve physical isolation storage and operation of key materials. Intel SGX 2.0 technology is a security technology launched by Intel to enhance software security.
[0077] The implementation of the above-mentioned Internet of Things test platform adaptation system based on post-quantum cryptography further includes:
[0078] Develop a blockchain-based algorithm certificate deposit network, bind the evaluation results of PQC algorithms with device fingerprints, and write them into Hyperledger Fabric (consortium blockchain);
[0079] Design a Verifiable Delay Function (VDF) as a post-quantum secure timestamp service to resist quantum-assisted replay attacks.
[0080] Another embodiment of the present invention proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it can implement the same or similar steps as in the method embodiment, which will not be elaborated here.
[0081] Another embodiment of the present invention proposes an Internet of Things test platform adaptation device based on post-quantum cryptography. This Internet of Things test platform adaptation device based on post-quantum cryptography can be a server or a mobile terminal. This computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database is used for all data of the computer device. The network interface of this computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements the Internet of Things test platform adaptation method based on post-quantum cryptography.
[0082] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0083] The above description of the embodiments is to enable those of ordinary skill in the art to understand and apply the present invention. It is obvious that those skilled in the art can easily make various modifications to the above embodiments and apply the general principles described herein to other embodiments without creative labor. Therefore, the present invention is not limited to the above embodiments, and the improvements and modifications made by those skilled in the art to the present invention according to the disclosure of the present invention should be within the protection scope of the present invention.
Claims
1. An adaptation method for an Internet of Things test platform based on post-quantum cryptography, characterized in that, Including the following steps: Build a quantum threat perception model, dynamically collect the hardware fingerprint information, network behavior characteristics and quantum computing evolution index of the target Internet of Things device, integrate a quantum random number generator and a Shor algorithm simulator, calculate the quantum attack success probability in real time, and output it to the heterogeneous cryptographic adaptation engine; Based on the heterogeneous cryptographic adaptation engine and the performance evaluation matrix generation unit, build a comprehensive evaluation function including throughput, anti-side-channel attack ability and firmware update cost, establish a multi-dimensional adaptation decision matrix, comprehensively evaluate the device computing power level, energy consumption constraint and security level requirements, and generate a set of candidate post-quantum cryptographic algorithms {PQCi}; Execute cryptographic protocol dynamic injection, deeply couple the selected PQC algorithm with the lightweight TLS1.3 protocol stack, realize the lossless replacement of the communication layer encryption suite, and realize the algorithm dynamic loading of the heterogeneous cryptographic adaptation engine supporting the Xilinx Zynq UltraScale+ MPSoC and ARM Cortex-M33 dual architectures; Based on the Intel SGX2.0 technology of the trusted execution environment, realize the physical isolation storage and operation of key materials, deploy a runtime performance monitoring engine, and collect data on encryption and decryption latency, memory occupancy rate and electromagnetic radiation characteristics in real time; Build an algorithm switching decision tree based on reinforcement learning, and trigger dynamic migration of cryptographic algorithms when quantum attack characteristics or device performance threshold breakthroughs are detected.
2. The method for adapting an Internet of Things test platform based on post-quantum cryptography according to claim 1, wherein The multi-dimensional adaptation decision matrix includes the following steps: Hardware accelerator support matrix: Identify whether the device integrates the ARMv9 Cryptography Extension or the RISC-V vector instruction set extension; Energy consumption sensitivity evaluation model: Establish a power consumption-throughput relationship; Security level mapping table: Configure weight coefficients for the third-round candidate algorithms of the NIST PQC standardization process according to MLWE and Hash-based classifications.
3. The method for adapting an Internet of Things test platform based on post-quantum cryptography according to claim 1, wherein The protocol adaptation process also includes the following steps: Build a cryptographic suite fingerprint library to support the hybrid key exchange mode of CRYSTALS-Kyber and X25519; Realize the frame structure reorganization of the NTRU Prime algorithm and the DTLS record layer, and the encapsulation format conforms to the IEEE 802.15.4e standard; Develop a customized header compression algorithm for LoRaWAN to optimize the PQC signature length to less than 1.5 times the original ECDSA.
4. The method for adapting an Internet of Things test platform based on post-quantum cryptography according to claim 1, characterized in that The algorithm switching also includes the following steps: When the quantum threat index QTI > 0.7, forcibly enable the Falcon-1024 digital signature scheme; When it is detected that the remaining battery power of the device is less than 20%, automatically degrade to the SABRE algorithm; In a wireless channel environment with a packet loss rate exceeding 5%, switch to the RLCE-Based encoding and decoding scheme.
5. The method for adapting an Internet of Things test platform based on post-quantum cryptography according to claim 4, wherein It also includes the following: Propose a post-quantum key fusing mechanism based on the trusted execution environment. When side-channel attack characteristics are detected, automatically destroy the PQC master key and trigger blockchain evidence storage; Design a sparse polynomial ring accelerator for resource-constrained devices to increase the key generation speed of the SABER algorithm by 3.2 times.
6. An Internet of Things test platform adaptation system based on post-quantum cryptography, characterized in that, Including: Quantum Situation Awareness Module: Integrates a quantum random number generator and a Shor algorithm simulator to calculate the quantum attack success probability in real time; Heterogeneous Cryptography Adaptation Engine: Supports dynamic loading of algorithms for both Xilinx Zynq UltraScale+ MPSoC and ARM Cortex-M33 architectures; Performance Evaluation Matrix Generation Unit: Constructs a comprehensive evaluation function including throughput, resistance to side-channel attacks, and firmware update cost; Trusted Execution Environment: Implements physical isolation storage and operation of key materials using Intel SGX 2.0 technology.
7. The Internet of Things test platform adaptation system according to claim 6, wherein the heterogeneous cryptography adaptation engine includes: Lattice-based Cryptography Hardware Acceleration Core: Optimizes the Number Theoretic Transform unit of the Kyber algorithm; Hash Post-Quantum Coprocessor: Integrates the HyperTree parallel constructor of the SPHINCS+ algorithm; Coded Cryptography Conversion Layer: Provides a seamless migration interface from Classic McEliece to BIKE algorithm.
8. The Internet of Things test platform adaptation system according to claim 6, wherein It further includes: Develops a blockchain-based algorithm certificate deposit network, binds the evaluation results of PQC algorithms with device fingerprints and writes them into the consortium blockchain; Designs a verifiable delay function VDF as a post-quantum secure timestamp service to resist quantum-assisted replay attacks.
9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method steps described in any one of claims 1 to 5.
10. An Internet of Things test platform adaptation device based on post-quantum cryptography, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the method steps described in any one of claims 1 to 5.
Citation Information
Patent Citations
Power switching circuit
CN113438091B
Asymmetric encryption algorithm
CN114726531A
Cited By
Equipment communication method and device and related equipment
CN120567397A
Device communication method, apparatus and related device
CN120567397B
Anti-quantum cryptography migration method and system for power system
CN121173467A
AI-driven post-quantum cryptography algorithm adaptive optimization method
CN121418102A
Anti-quantum cryptographic dual-mode cryptographic algorithm switching method and system based on dynamic scheduling
CN121441499A