Quantum cipher migration resisting method and system, electronic equipment and storage medium
By extending the transport layer security protocol and adopting a multi-layer cascade key rotation and chain-type post-quantum key generation mechanism, the problems of large key size and low computing efficiency of traditional encryption systems under the threat of quantum computing are solved, and efficient and secure quantum-resistant data transmission is achieved.
Patent Information
- Application Number
- CN202511127691.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-08-13
AI Technical Summary
In the existing technology, traditional encryption systems have the problems of large key size and low computing efficiency when facing the threat of quantum computing, making it difficult to meet the requirements of real-time high-speed transmission, and quantum key distribution is limited and cannot cover large-scale network scenarios.
It adopts a multi-layer cascade key rotation mechanism and a chained post-quantum key generation mechanism, extends the transport layer security protocol, adds a quantum-resistant cryptographic suite, and generates multi-layer cascade keys to achieve secure and efficient data transmission.
It achieves small key size and high computational efficiency in the process of quantum-resistant encryption and decryption, ensures forward and backward security of data transmission, and adapts to the needs of large-scale network scenarios.
Smart Images

Figure CN120639299A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum-resistant data transmission technology, and in particular to a quantum-resistant cryptographic migration method, system, electronic device, and storage medium. Background Art
[0002] In recent years, quantum computing, based on quantum mechanics, has developed rapidly, with the industry already achieving thousand-qubit processors. With the widespread adoption of commercial quantum computers, existing encryption systems for data transmission are facing unprecedented threats. According to research by the National Institute of Standards and Technology (NIST), quantum computers can use Shor's algorithm to crack traditional public-key cryptography systems such as RSA and ECC (Elliptic Curve Cryptography) in polynomial time. The Grover algorithm can also halve the effective key strength of symmetric encryption systems such as AES-128.
[0003] Against this backdrop, quantum-resistant technologies have emerged. These technologies are primarily categorized into two categories: post-quantum cryptography (PQC) and quantum key distribution (QKD). PQC is a quantum-resistant cryptographic algorithm designed based on mathematical problems (such as lattice cryptography and hash signatures). These include lattice-based PQC, such as Kyber, Falcon, and NTRU; code-based PQC, such as Classic McEliece; multivariate-based PQC, such as Rainbow; hash-based PQC, such as SPHINCS+ and XMSS; and the digital signature algorithm Dilithium. However, to achieve quantum resistance, current PQC algorithms generally suffer from large generated key sizes (for example, Kyber's public key is 1.5KB) and low computational efficiency (for example, signing speed is 10 times slower than RSA), making them incapable of meeting the real-time, high-speed data transmission requirements of most applications.
[0004] QKD achieves unconditional secure key transmission based on the quantum non-cloning principle, but QKD relies on dedicated fiber optic channels, has limited transmission distance (satellite-to-ground links require relay extension), and cannot cover large-scale network scenarios.
[0005] Therefore, in the existing technology, there are still many difficulties in the process of cryptographic migration from traditional cryptographic systems to quantum-resistant cryptographic systems. Summary of the Invention
[0006] In response to the technical problems existing in the prior art, the present invention proposes a method, system, electronic device and storage medium for anti-quantum cryptographic migration, which achieves data security and transmission efficiency during anti-quantum cryptographic migration through multi-layer cascade key rotation.
[0007] In order to achieve the above technical problem, according to one aspect of the present invention, the present invention provides a method for resisting quantum cryptography migration, comprising the following steps: Adaptive extensions to the transport layer security protocol include at least the following: adding quantum-resistant cipher suites to the cipher suite list; adding the following to the encryption extension: chained post-quantum key generation mechanism, multi-layer cascade key rotation protocol, encryption / decryption key derivation for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data; The encryption and decryption ends securely transmit application data based on the extended transport layer security protocol. The secure transmission process of application data includes: The encryption end and the decryption end respectively generate the master key, multi-level subkeys and path key chain based on the extended cipher suite according to the chained post-quantum key generation mechanism; The encryption end uses one or more of the partial subkeys as key material to derive an encryption key for symmetric encryption, encrypts the application data using symmetric encryption to generate ciphertext, and sends the ciphertext and the path node key at the end of the path key chain to the decryption end; The decryption end verifies the path node key received along with the ciphertext, and after the verification of the path node key is successful, derives the decryption key using one or more of the partial subkeys as key material, and decrypts the ciphertext; and The encryption end and the decryption end update the multi-layer cascade key based on the multi-layer cascade key rotation protocol.
[0008] Optionally, the content of symmetrically encrypting the application data added in the encryption extension item also includes an encryption mode; Correspondingly, when message authentication is included in the encryption mode, during the secure transmission of application data between the encrypting end and the decrypting end based on the extended transport layer security protocol, the encrypting end encrypts the application data using a symmetric encryption method to generate a ciphertext, and then generates an authentication tag for the ciphertext based on one or more of the other partial subkeys; After verifying that the path node key received along with the ciphertext is passed, the decryption end verifies the authentication tag. After the authentication tag is verified, one or more of the partial subkeys are used as key materials to derive the decryption key and decrypt the ciphertext.
[0009] Optionally, the steps of generating a master key, a multi-level subkey, and a path key chain based on the extended cipher suite according to a chained post-quantum key generation mechanism include: The encryption end and the decryption end determine the shared key through key negotiation based on the extended transport layer security protocol; The encryption end and the decryption end each generate a quantum-resistant master key based on the shared key using the PT hash algorithm constructed by a quantum random circuit in the quantum-resistant cryptographic suite; The encryption end and the decryption end each generate a multi-level subkey based on the master key, wherein the initial value of each subkey level is generated based on the initial value of the master key and / or one or more subkeys of the upper level; The encryption end and the decryption end respectively construct a path key chain, and generate an initial path node key of the path key chain based on the master key and / or one or more subkey initial values.
[0010] Optionally, the step of updating the multi-layer cascade key by the encryption end and the decryption end based on the multi-layer cascade key rotation protocol includes: During the master key update cycle, after one or more of the partial subkeys are used as key material to derive an encryption / decryption key for symmetric encryption, the one or more subkeys used to derive the encryption / decryption key are updated; when the life of a subkey reaches a preset life cycle, the subkey is updated; when the number of updates of a second subkey associated with the first subkey reaches a threshold, the first subkey is updated; When the life of the master key reaches a preset life cycle length, the master key is updated. After the master key is updated, a multi-level new subkey and a new path key chain are generated based on the updated master key.
[0011] Optionally, the step of updating the multi-layer cascade key by the encryption end and the decryption end based on the multi-layer cascade key rotation protocol further includes: After any subkey is updated, a new path node key is generated based on the path node key at the end of the path key chain and at least all the subkeys updated so far, and added to the end of the path key chain; When the master key is updated, after generating multiple levels of new subkeys based on the updated master key, the initial path node key of the new path key chain is generated based on the updated master key and / or one or more new subkey initial values.
[0012] Optionally, the adaptive extension of the transport layer security protocol further includes a rollback mechanism, and the secure transmission process of application data further includes: Monitor key security events; Determining a corresponding first key algorithm component based on the monitored key security event and uninstalling the first key algorithm component; Determining from a component center a second key algorithm component that replaces the secure version of the first key algorithm component; wherein the component center provides a plurality of encryption algorithm components, related key algorithm components, and signature algorithm components; Load the secure version of the second key algorithm component from the component center; Deleting the uninstalled first key algorithm information from the cipher suite list and adding the loaded second key algorithm information; and Based on the updated cipher suite, a new multi-layer cascade key is generated according to a chained post-quantum key generation mechanism and the original multi-layer cascade key is frozen. Application data is transmitted based on the new multi-layer cascade key, and historical application data is decrypted based on the original multi-layer cascade key.
[0013] According to another aspect of the present invention, the present invention further provides a quantum cryptography migration resistant system, comprising: A protocol adapter module configured to adapt and extend the transport layer security protocol for data, the extensions including at least: adding a quantum-resistant cipher suite to the cipher suite list; adding to the encryption extensions: a chained post-quantum key generation mechanism, a multi-layer cascade key rotation protocol, encryption / decryption key derivation for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data; The data transmission module is configured to securely transmit application data between the encryption end and the decryption end based on the extended transport layer security protocol, wherein the secure transmission process of the application data includes: The encryption end and the decryption end respectively generate the master key, multi-level subkeys and path key chain based on the extended cipher suite according to the chained post-quantum key generation mechanism; The encryption end uses one or more of the partial subkeys as key material to derive an encryption key for symmetric encryption, encrypts the application data using symmetric encryption to generate ciphertext, and sends the ciphertext and the path node key at the end of the path key chain to the decryption end; The decryption end verifies the path node key received along with the ciphertext, and upon successful verification of the path node key, derives a decryption key using one or more of the partial subkeys as key material, and decrypts the ciphertext; and The encryption end and the decryption end update the multi-layer cascade key based on the multi-layer cascade key rotation protocol.
[0014] Optionally, when the transport layer security protocol is adaptively extended, the extended content also includes a rollback mechanism. The system further includes a security rollback module, which is configured to monitor key security events. After monitoring a key security event, it rolls back to the secure version of the key algorithm, regenerates the multi-layer cascade key based on the secure version of the key algorithm, and freezes the original multi-layer cascade key. Application data is transmitted based on the new multi-layer cascade key, and historical application data is decrypted based on the original multi-layer cascade key.
[0015] According to another aspect of the present invention, the present invention also provides an electronic device, including a processor and a memory, wherein the memory stores computer instructions, and the processor executes the aforementioned anti-quantum cryptography migration method when running the computer instructions.
[0016] According to another aspect of the present invention, the present invention also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed by a processor, the aforementioned quantum-resistant cryptography migration method is executed.
[0017] Based on a chained post-quantum key generation mechanism and a quantum-resistant multi-layer cascade key rotation protocol, the present invention constructs a multi-layer linkage key and related communication method, which can achieve quantum-resistant encryption / decryption while reducing the key size, and realize efficient and secure data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Below, the preferred embodiments of the present invention will be further described in detail with reference to the accompanying drawings, in which: Figure 1 This is a flow chart of a method for quantum cryptography migration according to one embodiment of the present invention; Figure 2 is a flow chart of a method for securely transmitting application data between an encryption end and a decryption end based on an extended transport layer security protocol according to an embodiment of the present invention; Figure 3 is a flow chart of a method for determining a shared key according to one embodiment of the present invention; Figure 4 is a flow chart of a method for generating multi-layer cascade keys according to one embodiment of the present invention; Figure 5 This is a schematic diagram of the structure principle of a quantum random circuit according to an embodiment of the present invention; Figure 6 This is a flow chart of a method for generating a quantum-resistant master key based on a shared key using a PT hash function (PTHash for short) algorithm constructed using a quantum random circuit according to one embodiment of the present invention; Figure 7 is a schematic diagram of the evolution process of a path key chain according to an embodiment of the present invention; Figure 8 is a principle block diagram of a quantum cryptography migration system according to an embodiment of the present invention; and Figure 9 It is a structural principle block diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0020] In the detailed description that follows, reference may be made to the various drawings that form part of this application and illustrate specific embodiments of the present application. In the drawings, similar reference numerals describe substantially similar components in different figures. Each specific embodiment of the present application is described below in sufficient detail to enable a person of ordinary skill in the art to implement the technical solutions of the present application. It should be understood that other embodiments may be utilized or that structural, logical, or electrical changes may be made to the embodiments of the present application.
[0021] To address the threat posed by quantum computing to encryption systems during current data transmission, the present invention provides a quantum-resistant cryptographic migration method. This method generates quantum-resistant multi-layer cascade keys through a Locks Chain Post-Quantum Key Generation Mechanism (LocksChainPQ) and a quantum-resistant multi-layer cascade key rotation protocol (MLR Protocol). This method features a small key size and high key calculation efficiency, ensuring both forward and backward security of data transmission while achieving quantum-resistant encryption and decryption.
[0022] See also Figure 1 , Figure 1 This is a flow chart of a method for quantum-resistant cryptography migration according to one embodiment of the present invention. The method for quantum-resistant cryptography migration includes the following steps: Step S10: Adaptively extend the transport layer security protocol. The extensions include at least: adding a quantum-resistant cipher suite to the cipher suite list; and adding the following to the encryption extension: a chained post-quantum key generation mechanism, a multi-layer cascade key rotation protocol, derivation of encryption / decryption keys for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data.
[0023] In step S20, the encryption end and the decryption end perform secure transmission of application data based on the extended transport layer security protocol.
[0024] The transport layer security protocol used for data transmission usually includes a list of cipher suites and encryption extensions. Examples of such security protocols include TSSL / TLS (Secure Sockets Layer / Transport Layer Security), SSH (Secure Shell), S / MIME (Secure / Multipurpose Internet Mail Extensions), and blockchain. Taking TLS 1.3 as an example, the cipher suite list is as follows: TLS_AES_256_GCM_SHA384 TLS_CHACHA20_POLY1305_SHA256 TLS_AES_128_GCM_SHA256 TLS_AES_128_CCM_8_SHA256 TLS_AES_128_CCM_SHA256 …….
[0025] In order to achieve quantum-resistant cryptographic migration, the present invention adds quantum-resistant cryptographic suites to the cryptographic suite list, for example: PTHash_Kyber_SPHINCS+_PTHash_ AES_256_GCM PTHash_SM3_Kyber_XMSS_ AES_256 SM3_SHA3_512_CRYSTALS-KEM_PTHash_ AES_256_GCM …….
[0026] Add the following extensions to the TLS 1.3 encryption extension: Chained post-quantum key generation mechanism; Multi-layer cascade key rotation protocol; Derives encryption / decryption keys for application data based on multi-layer cascade keys; Path keychain verification; Symmetrically encrypt application data.
[0027] Through the aforementioned adaptive expansion of the transport layer security protocol, when data is transmitted between the two ends of a communication system (hereinafter referred to as a quantum-resistant cryptographic migration system), such as a client and a server, a quantum-resistant cryptographic suite is used according to a chained post-quantum key generation mechanism to generate multi-layer cascade keys. During the transmission of application data after the handshake, encryption keys are derived from the multi-layer cascade keys, and the application data is encrypted using symmetric encryption. Path key chain verification is required before decryption, and decryption is only possible after successful verification. For ease of explanation, the present invention refers to the two ends of the quantum-resistant cryptographic migration system as the encryption end and the decryption end, respectively. These can be either a client or a server providing certain services, or two user ends.
[0028] The chained post-quantum key generation mechanism in this invention provides a post-quantum key generation specification, including the key level, number of subkeys, applied key algorithm, and calculation method for path node keys. The multi-layer cascade key rotation protocol specifies the update conditions, trigger conditions, and calculation method for each key, which will be detailed in the subsequent password migration method.
[0029] Specifically, see Figure 2 , Figure 2 The present invention is a flowchart of a method for securely transmitting application data between an encryption end and a decryption end based on an extended transport layer security protocol according to an embodiment of the present invention. The method for securely transmitting application data includes the following steps: In step S21, the encryption end and the decryption end perform key negotiation based on the expanded transport layer security protocol to determine a shared key.
[0030] In step S221, the encryption end generates a multi-layer cascade key of the encryption end using the shared key as key material, including a master key, multi-level subkeys, and a path key chain.
[0031] In step S231 , the decryption end generates a multi-layer cascade key of the decryption end using the shared key as key material, including a master key, multi-level subkeys, and a path key chain.
[0032] When the encryption end receives a data transmission request, it performs the following steps: In step S222, the encryption end uses one or more of the partial subkeys as key materials to derive an encryption key for symmetric encryption.
[0033] Step S223: Encrypt the application data in a symmetric encryption manner to generate a ciphertext.
[0034] Step S224: Send the ciphertext and the path node key at the end of the path key chain to the decryption end.
[0035] Step S225: Update the key, wherein at least one or more of the multiple subkeys used to generate the encryption key are updated.
[0036] Step S232: The decryption end verifies the path node key received along with the ciphertext.
[0037] If the verification of the path node key fails, in step S233, a path verification failure message is sent to the encryption end.
[0038] If the verification of the path node key is successful, in step S234, a decryption key is derived using one or more of the partial subkeys as key material.
[0039] Step S235: decrypt the ciphertext.
[0040] Step S236: Send a decryption success message to the encryption end.
[0041] Step S237: Update the key, wherein at least one or more of the multiple subkeys used to generate the decryption key are updated.
[0042] See also Figure 3 , Figure 3 1 is a flow chart of a method for determining a shared key according to an embodiment of the present invention. In this embodiment, the steps of determining a shared key through key negotiation between an encryption end and a decryption end based on an expanded transport layer security protocol include: Step S210: Initialize a key pair to obtain an RSA key pair and a post-quantum key pair. For example, an RSA key pair is obtained based on an RSA component (e.g., Elliptic Curve Diffie-Hellman), including a private key d and a public key Q. The public key Q = d·G, where G represents the base point and • represents the multiplication relationship.
[0043] Based on the CRYSTALS-KEM post-quantum component, a post-quantum key pair is obtained, including a secret vector r and a public key vector b. Specifically, a secret vector r and a public key matrix A are selected, and the public key vector b is calculated based on formula (1-1).
[0044] b=A•r+e(1-1) where e represents the error vector.
[0045] Step S211: Generate a first shared key S1 and a second shared key S2 respectively.
[0046] The first shared key S1 is calculated based on the RSA key pair according to formula (1-2).
[0047] S1=d A •Q B (1-2) Among them, A and B represent the encryption end and decryption end respectively, d A is the encryption end private key, Q B is the public key of the decryption end. S1 is the shared key calculated by the encryption end. The shared key calculated by the decryption end is the same as the shared key calculated by the encryption end, that is, S1=d A • Q B =d B • Q A =d A •d B •G.
[0048] The second shared key S2 is calculated based on the post-quantum key pair according to formula (1-3).
[0049] S2 =H(b T •r+d) (1-3) Where H represents the hash operation, d represents the error vector, and b T Represents the transpose of the public key vector b.
[0050] Step S212: Calculate the first shared key S1 and the second shared key S2 to obtain a shared key S. For example, the shared key S is obtained by concatenating the first shared key S1 and the second shared key S2 according to formula (1-4).
[0051] S = S1 || S2 (1-4) In this embodiment, the data transmission channel type is a hybrid type. Therefore, a traditional encryption algorithm is used to obtain the first shared key S1, and a quantum-resistant encryption algorithm is used to obtain the second shared key S2. The two shared keys are then concatenated using formula (1-4), and the concatenated result is used as the shared key S for generating the master key. However, it can be seen that if the data transmission channel type is a traditional type, the first shared key S1 can be used as the key material for generating the master key. If the data transmission channel type is a post-quantum type, the second shared key S2 can be used as the key material for generating the master key.
[0052] The encryption and decryption ends use the same method to generate multi-layer cascade keys based on the extended cipher suite and the shared key as the key material according to the multi-layer cascade key rotation protocol, see Figure 4 , Figure 4 1 is a flow chart of a method for generating a multi-layer cascade key according to an embodiment of the present invention. In this embodiment, taking the encryption end as an example, the method for generating a multi-layer cascade key includes the following steps: Step S31: construct a quantum random circuit. The quantum random circuit acts on multiple quantum bits arranged in sequence from low to high. Corresponding to each quantum bit, multiple rotation quantum gates and entangled quantum gates are arranged in sequence. The control bits and target bits of the multiple entangled quantum gates act on each quantum bit in a cyclic shift manner.
[0053] Step S32: Generate a quantum-resistant master key based on the acquired shared key using a PT hash function (PTHash for short) algorithm component constructed by a quantum random circuit.
[0054] Step S33: Generate multi-level subkey initial values based on the master key, wherein the initial value of each subkey is generated according to the master key and / or one or more subkey initial values of the upper level.
[0055] Step S34: constructing a path key chain, wherein the initial value of the path node key of the path key chain is initially generated based on the master key and all the multi-level subkeys.
[0056] See also Figure 5 , Figure 5 The figure is a schematic diagram of the structure of a quantum random circuit according to one embodiment of the present invention. For ease of explanation, a 4-qubit quantum random circuit is used as an example. The quantum random circuit includes four subcircuits, each of which acts on a qubit. Each subcircuit is sequentially arranged from left to right with multiple parametric rotation quantum gates and entangled quantum gates. As shown in the figure, from left to right, they are Rx gate, Ry gate, Rz gate, followed by Rx gate and Ry gate, and then CNOT gate. CNOT gates are entangled quantum gates that act on two qubits. The control bits and target bits of multiple CNOT gates act on each qubit in a cyclic shift manner. For example, when the difference between the number of qubits affected by the control bit and the target bit is 1, the control bit of the first CNOT gate is q0 and the target bit is q1. The control bit of the second CNOT gate is q1 and the target bit is q2. The control bit of the third CNOT gate is q2 and the target bit is q3. The control bit of the fourth CNOT gate is q3 and the target bit is q0. When the difference between the number of control bits and the target bit is 2, the control bit of the first CNOT gate is q0, the target bit is q2, the control bit of the second CNOT gate is q1, the target bit is q3, the control bit of the third CNOT gate is q2, the target bit is q0, the control bit of the fourth CNOT gate is q3, and the target bit is q1. And so on, the cycle is set. The parameter of each parameterized rotation quantum gate is the rotation angle θ, and its main value range is 0≤θ<2π. The present invention constructs a quantum-resistant hash algorithm based on quantum random circuits, which is referred to as PT hash function or PTHash algorithm in the present invention.
[0057] Among them, see Figure 6 , Figure 6The present invention is a flowchart of a method for generating a quantum-resistant master key based on a shared key using a PT hash function (PTHash) algorithm constructed using a quantum random circuit according to an embodiment of the present invention. The method includes the following steps: Step 321: Process the key material to obtain parameter values for the quantum random circuit. In one specific embodiment, the key string is obtained based on the HMAC-based Extract-and-Expand Key Derivation Function (HKDF). The HKDF algorithm includes two calculation steps.
[0058] First, the key material is extracted (HKDF-Extract) using the following formula (2-1) to obtain the random number PRK: PRK= HMAC (salt, IKM) (2-1) Wherein, salt is the salt value, which can be None, and IKM is the key material. The key material in this embodiment is the aforementioned shared key S.
[0059] Then, the key string OKM (output keying material) is obtained by performing an expansion operation (HKDF -Expand) using the following formula (2-2): OKM=HMAC (PRK, inf ||counter) (2-2) Inf is a random vector, which can be empty, and counter is a counter.
[0060] In another embodiment, the shared key S may be directly used as the key string and the following processing may be performed.
[0061] The key string OKM is encoded into a byte sequence according to a certain encoding rule. In one embodiment, the key string is encoded using the UTF-8 (8-bit, Universal Character Set / Unicode Transformation Format) encoding rule to obtain a byte sequence B, B={b0,b1,…,b i ,…,b L}, b i∈={0, 1,…, 255}, where L is the total number of bytes in the byte sequence. The preferred value of L is an integer multiple of the total number of qubits used by the quantum random circuit. When the total number of bytes, L, is an integer multiple N (N ≥ 1) of the total number of qubits used by the quantum random circuit, the byte sequence B is sequentially divided into N groups to obtain N subsequences. If the total number of bytes, L, is not an integer multiple of the total number of qubits used by the quantum random circuit, for example, if the integer multiple N has a remainder of M bytes, the byte sequence B is sequentially divided into N+1 groups. The number of bytes in the first N subsequences is the same as the total number of qubits, and the N+1th subsequence contains M bytes.
[0062] Then, based on the normalization function formula (2-3), the rotation angle θ of the rotating gate acting on the corresponding quantum bit is calculated for each byte.
[0063] (2-3) Based on byte b i The rotation angle of the quantum gate Rk acting on the i-th quantum bit is calculated, where the quantum gates when k is x, y, and z are Rx gate, Ry gate, and Rz gate respectively; λx, λy, and λz are three constants that are different from each other. In one embodiment, λx, λy, and λz are three phase seeds in a Porter-Thomas distribution (PT distribution), respectively, with λx=0, λy=85, and λz=170.
[0064] When the byte sequence B is divided into multiple subsequences, the byte b described in formula (2-3) i The byte sequence number in a subsequence.
[0065] Step S322, assign the parameter values to the parameterized rotation quantum gates. i Mapped to quantum bit q in quantum random circuit i , will be based on byte b i The calculated rotation angle of the Rk quantum gate is assigned to the Rx gate, Ry gate and Rz gate acting on the i-th quantum bit in the quantum random circuit.
[0066] Step S323: Run the quantum circuit and perform final state measurement to obtain a measurement result. The final state measurement result of the quantum random circuit is an R-bit sequence m consisting of 0s and 1s expressed as shown in Expression (2-4).
[0067] m=(m1,m2,…,m R ) (2-4) Among them, m∈{0,1}^R.
[0068] When byte sequence B is divided into multiple subsequences, steps S322 and S323 are performed for each subsequence to obtain a measurement result corresponding to each subsequence. The corresponding measurement results are then concatenated according to the order in which the subsequences were separated to obtain the final measurement result. If the total number of bytes in the subsequences is less than the total number of qubits in the quantum random circuit, when the final state measurement is performed on all qubits, the measurement data corresponding to the qubits not used in the measurement result is deleted; alternatively, only the final state of the used qubits is measured.
[0069] Step S324: Convert the measurement result into a string of the preset symbol encoding system. Specifically, first truncate or fold the measurement result to a fixed length. If the number of bits R of the sequence m is greater than the number of bits J of the string of the preset symbol encoding system, then truncate the first J bits of the sequence m to obtain the sequence m. (J) Alternatively, perform a linear fold on sequence m according to formula (2-5) to obtain sequence m (J) .
[0070] (2-5) If the number of bits R of sequence m is less than the number of bits J of the string of the preset symbol encoding system, the quantum random circuit will continue to be triggered to run, and the final state measurement will be performed, and the sequence corresponding to the measurement result will be spliced together with the sequence corresponding to the previous measurement result until the number of bits R of the spliced sequence is greater than or equal to the number of bits J of the string of the preset symbol encoding system. At this time, the sequence m (J) is the quantum entropy preimage.
[0071] Then perform hexadecimal encoding. Specifically, first convert the sequence m (J) Grouping into groups of 4, we get expression (2-6).
[0072] (m0,m1,m2,m3) (m4,m5,m6,m7)…… (2-6) Convert each 4 bits into an integer v between 0 and 15 according to formula (2-7) j .
[0073] (2-7) in, .
[0074] Then use the hexadecimal notation {0,1,2,3,4,5,6,7,8,9,a,b,c,d,e,f} to convert v j Mapped to c j .
[0075] Then sequentially splice c j , thus obtaining a string C, C=(c0,c1,…,cj , …, c (J / 4-1) ), the string C is a true random number that conforms to the PT distribution. As can be seen from the above description, when an input string (such as the aforementioned key material) is calculated through a quantum random circuit, a true random number is obtained. Therefore, the present invention constructs a function using a quantum random circuit, the calculation result of which is a true random number that conforms to the PT distribution. In the present invention, the function constructed by the quantum random circuit is called a PT hash function or PTHash function, the corresponding algorithm is called a PTHash algorithm, and the component that implements the PTHash algorithm is called a PTHash algorithm component.
[0076] In one embodiment, the character string C is used as the master key, or the first preset number of characters in the character string C are truncated as the master key. The above process is simplified to the following calculation formula (2-8).
[0077] Kmaster=PTHash(IKM) (2-8) Wherein, the IKM is a key material.
[0078] In another embodiment, a key can be derived from the string C, and the derived key can be used as the master key. For example, based on the Multi-Layer Rotation Protocol (MLR) and the Locks Chain Post-Quantum Key Generation Mechanism (LocksChainPQ) provided by the present invention, a key derivation function MKDF is proposed.
[0079] The MKDF algorithm component includes two calculation processes. The first process is to derive a cryptographically strong true random key based on the key material IKM, which can be an authentication code of the key material IKM. The other process changes the length of the true random key calculated by the first process. Specifically, First, the key material is extracted (LocksChainPQ-Extract) using the following formula (2-9) to obtain the true random number RRK: RRK= LocksChainPQ (C, O) =PTHash (C⊕opad || PTHHash (C⊕ipad || O)) (2-9) Among them, C is a string, O is additional information; ipad (inner padding) represents internal padding, which is a byte sequence with the same size as the string C; opad (outer padding) represents external padding, which is another byte sequence with the same size as the string C; ⊕ represents a bitwise exclusive OR operation; || represents a concatenation (splicing) operation. Figure 6 The PTHash function shown in the figure calculates a true random number RRK of a certain number of digits according to formula (2-9).
[0080] Then, according to formula (2-10), the number of bits of the true random number RRK is changed to obtain a character string D_OKM with a preset number of bytes.
[0081] D_OKM= LocksChainPQ (RRK, inf ||counter) (2-10) Where, Inf is a random vector, which can be empty, and counter is a counter. In this step, after multiple rounds of PTHash calculation, a string D_OKM with a preset number of bytes is output.
[0082] In this embodiment, the parameters of the quantum rotation gate are generated using a classical algorithm, achieving a deep fusion of quantum computing and traditional cryptography. When calculating the shared key based on HKDF, the deterministic generation of quantum circuit parameters is ensured by the use of fixed-bit random numbers, such as fixed-bit salt values and Inf values. The Rx, Ry, and Rz quantum gates in each layer (strip) of the quantum random circuit ensure that even small changes in the input data lead to significant differences in the quantum state, resulting in an avalanche effect. The connection pattern of the CNOT gates in the quantum circuit dynamically changes with the number of layers (strips), forming a dynamically entangled network, further enhancing the avalanche effect and thus producing a truly random number.
[0083] Because the cipher suite specifies the corresponding key algorithms, encryption algorithms, and so on, the handshake process between the encryption and decryption ends determines the key algorithm components or algorithm parameters used when generating multi-layer cascade keys and the key algorithm components or algorithm parameters used when updating subkeys. The key algorithm components described in the present invention are key algorithm components or key derivation algorithm components used in symmetric, asymmetric, or post-quantum encryption algorithms. In one specific embodiment, multiple key algorithm components are available for each level. Therefore, in step S33, the initial subkey values for the corresponding level are generated by executing the key algorithm components for each level. In another embodiment, when a single key algorithm component is configured to generate all initial subkey values, the subkeys at different levels have corresponding algorithm parameters. For ease of explanation, the subkeys are denoted as Kij, where i represents the level, a natural number starting from 1; j represents the sequence number, an integer starting from 0. The multiple initial subkeys generated in step S33 can be denoted as K10, K20, K30, etc.
[0084] The path key chain in step S34 is composed of multiple path node keys, each of which includes a node name Path i And specific key data. Among them, based on the master key and all initial subkeys, a key algorithm component is used to generate the initial path node key of the path key chain, named Path0, and the specific key data is a string of several bits.
[0085] In the present invention, based on the extended transport layer security protocol, symmetric encryption is used to encrypt application data, making full use of the advantages of the symmetric encryption algorithm to improve data transmission efficiency.
[0086] Furthermore, when extending the transport layer security protocol, you can also specify a specific encryption mode in the encryption extension. For example, you can specify AES-256 or AES_256_GCM in the encryption extension. If TLS1.3 is used, you can directly use the encryption mode in the original encryption extension, such as TLS_AES_256_GCM_SHA384.
[0087] When a message authentication code (such as the aforementioned AES_256_GCM) is included in the encryption mode, the encryption end and the decryption end, during the secure transmission of application data based on the extended transport layer security protocol, encrypt the application data in a symmetric encryption manner to generate a ciphertext, and then generate an authentication tag for the ciphertext based on one or more of the other partial subkeys.
[0088] After verifying that the path node key received along with the ciphertext is passed, the decryption end verifies the authentication tag. After the authentication tag is verified, one or more of the partial subkeys are used as key materials to derive the decryption key and decrypt the ciphertext.
[0089] The master key and each subkey in the present invention have corresponding update conditions. For example, these conditions may occur when a subkey's lifespan reaches a preset length, when a subkey is used to generate a plaintext encryption / decryption key, when a subkey encryption security incident occurs, or when the number of updates to the associated subkey reaches a threshold. When a subkey is updated, its associated subordinate subkeys are also updated. For example, a multi-layer cascade key includes a master key Kmaster, a first subkey K1, and a second subkey K2. The relationship between them is as follows: K1 = M(Kmaster), K2 = M(K1). M is a universal identifier for key algorithm components, and M() indicates calculation based on the data within the brackets. The first subkey K1 is a subordinate key of the master key Kmaster, and the second subkey K2 is a subordinate key of the first subkey K1. When the first subkey K1 is updated, the second subkey K2 is also updated. After the master key Kmaster is updated, the first and second subkeys K1 and K2 are regenerated.
[0090] Different subkeys in the present invention can have the same or different lifecycles. The lifecycles are measured in time or by the number of updates of the associated subkeys. For example, a multi-layer cascade key includes a master key Kmaster, a first subkey K1, and a second subkey K2, with the following relationship: K1 = M(Kmaster), K2 = M(Kmaster). The first subkey K1 and the second subkey K2 are subordinate subkeys of the master key Kmaster. When the first subkey K1 is updated a preset number of times (e.g., three times), the second subkey K2 is triggered to update. Therefore, the first subkey K1 is associated with the second subkey K2, and the association between the first subkey K1 and the second subkey K2 is established through the update relationship.
[0091] Furthermore, in the present invention, when a subkey is detected being used to generate encryption / decryption keys for application data, the subkey is updated. This ensures that each encryption / decryption key used during data transmission is different. Even if the current encryption key is leaked, historical data cannot be decrypted, ensuring forward security of communications. Furthermore, because the master key and each subkey are periodically updated, even if the current encryption key is leaked or cracked, future keys cannot be predicted, ensuring backward security of communications.
[0092] Furthermore, when a key security incident occurs, if the encryption key is leaked or cracked, it rolls back to the secure version of the key algorithm component, regenerates the master key and all subkeys through the secure version of the key algorithm component, and constructs a new path key chain.
[0093] When a monitored key meets its update conditions, the key is recalculated. In one specific calculation method, the updated key is calculated using a key algorithm component different from that used to generate the updated key, and the calculation result is used as the new key. For example, when calculating the initial value of the first subkey K1, the first key algorithm component M1 is used based on the master key Kmaster, and the corresponding formula is: K10 = M1 (Kmaster). When updating the first subkey K1, the second key algorithm component M2 is used to calculate the updated first subkey K11 using the initial value K10 of the first subkey K1 before the update, and the corresponding formula is: K11 = M2 (K10). Alternatively, the calculation is still based on the master key Kmaster, and the corresponding formula is: K11 = M2 (Kmaster).
[0094] In another specific calculation method, the key algorithm component used when generating the key to be updated is used to perform an update calculation on the key to be updated based on updated algorithm parameters, and the calculation result is used as the new key. For example, when calculating the initial value of the first subkey K1, the first key algorithm component M1 is used based on the master key Kmaster, and the corresponding formula is: K10 = M1 (Kmaster). When updating the first subkey K1, the first key algorithm component M1 is still used, and the initial value K10 of the first subkey K1 before the update is used to calculate the updated first subkey K11. The corresponding formula is: K11 = M1 (K10).
[0095] The initial value calculation formula for the first subkey K1 can also be: K10 = M1 (Kmaster, salt1, info). Salt1 is the salt value of the first subkey K1, and its specific value is, for example, "subkey1". Info is additional information, and when calculating the initial value, info is, for example, "init".
[0096] The update calculation formula for the first subkey K1 is: K1i=M1(self.current_key, salt1, info), where self.current_key is the current value of the first subkey K1. For example, when calculating the first updated value K11, self.current_key is K10, and when calculating the second updated value K12, self.current_key is K11. For example, salt1 is "subkey1," and info is "update." In this embodiment, the same key algorithm component is used for subkey generation and subkey update. Each update uses new algorithm parameters. The algorithm parameters can be the current key or, in combination with other parameters, such as the aforementioned salt value or additional information, to calculate the new key.
[0097] When a subkey is updated, the path key chain is updated. When a master key is updated, the path key chain is regenerated. The present invention destroys (i.e., securely erases) the old path node key after each update to obtain a new path node key, thereby preventing the old path node key from being backtracked and cracked after the current path node key is obtained through a human attack. For example, the initial path node key Path0 is updated to obtain Path1, and the specific key data of Path0 is destroyed, and Path0 is marked as unavailable. When the path key chain update condition is met again, Path1 is updated to obtain Path2, and Path1 is destroyed, and so on. It can be seen that the Path0, Path1, Path2, etc. obtained in sequence form a path key chain. For details, see Figure 7 . Figure 7This is a schematic diagram of the evolution of a path key chain according to one embodiment of the present invention. During each update, a new path key is generated based on the path node key at the end of the path key chain and all currently updated subkeys. In one embodiment, the last path node key in the path key chain and all currently updated subkeys are concatenated, then hashed or post-hashed, with the hash value used as the new path node key. Alternatively, the last path node key in the path key chain and all currently updated subkeys are subjected to a specific calculation, such as an exclusive-or calculation or a specific function calculation. Such specific functions can include lattice-based operations such as modular addition / multiplication, or hash combinations. The result is then hashed or post-hashed, with the hash value used as the new path node key. The path key chain in the present invention records the key update path and indirectly records the key application process during encryption. If the path key chain is broken, it indicates a security risk to the current data.
[0098] The multi-level cascade key system in this invention uses a quantum-resistant master key as a seed to drive the generation of subkeys at other levels. Each subkey level is independently generated by a key algorithm component, thus isolating the subkeys at each level. When transmitting application data, some subkeys can be used as encryption / decryption keys or as seeds for generating encryption / decryption keys, and some subkeys can be used as encryption keys for business data or as seeds for generating encryption keys. Based on a multi-level linkage architecture, this invention implements mechanical-like hierarchical dependencies (such as the Luban lock) and chain-like path constraints (similar to the nine-ring chain), increasing the difficulty of key cracking and effectively resisting quantum brute force attacks. This achieves the dual security goals of "historical data cannot be decrypted and future risks are actively isolated" with flexibility. Symmetric algorithms such as AES-256 and SM4 are used for encryption / decryption of application data, balancing efficiency and compatibility. The present invention also generates a path key chain to record the key update sequence and forcibly destroys (erases) the old key after each update to prevent human attacks and backtracking during communication. During data transmission, verifying the integrity of the path key chain can effectively ensure the legitimacy of key updates, guarantee the security of application data, and prevent backtracking attacks.
[0099] Application Examples In mobile payment scenarios, the mobile payment system consists of a user-side wallet application (APP) and a server. The user-side wallet app initializes a key pair locally, for example, by generating a post-quantum key pair through the Kyber component, and the private key is encrypted and stored in a TEE or secure zone. When users register with the server through the user-side wallet app, they upload their public key and use biometric identification (such as fingerprint or FaceID) to strengthen key access rights.
[0100] During the process of establishing a communication connection between the user-side wallet app and the server, a handshake is performed using the extended Transport Layer Security protocol. During this handshake, the cipher suite is determined, which includes the key algorithm components used to generate and update keys at all levels. In one embodiment, the user-side wallet app and the server negotiate to generate a shared key based on a post-quantum key pair, which serves as the master key material.
[0101] On the user side: 1. The user wallet app generates the master key Kmaster_c based on the PTHash component. For example: master key Kmaster_c = b3c6a8d648840e42...
[0102] 2. Based on the master key, derive the initial value K10_c of the first subkey K1_c and the initial value K20_c of the second subkey K2_c using formulas (3-1) and (3-2) respectively.
[0103] K10_c =MLR(Kmaster,'subkey1','init') (3-1) K20 _c =MLR(Kmaster,'subkey2','init') (3-2) Here, MLR() can be any of the aforementioned key derivation algorithms based on LocksChainPQ, such as the MKDF algorithm or the PTHash algorithm, or improvements to existing key algorithms based on LocksChainPQ according to the present invention, or other quantum-resistant key algorithms that comply with LocksChainPQ, such as Kyber, XMSS, SPHINCS, or FALCON.
[0104] When the master key Kmaster_c = b3c6a8d648840e42..., K10_c = a9fd1a30fb9b5f5d..., K20_c = 46b17c75f4adc441...
[0105] 3. Based on the master key Kmaster_c, the initial value K10_c of the first subkey K1_c, and the initial value K20_c of the second subkey K2_c, calculate the initial path node key Path0_c according to formula (3-3).
[0106] Path0_c =PTHash(Kmaster_c || K10_c || K20_c) (3-3) In this embodiment, Path0_c = a9fd1a30fb9b5f5d...
[0107] 4. During the transaction phase, the user-side wallet app generates a session key Ksession based on formula (3-4). The session key Ksession is the encryption key for the transaction data.
[0108] Ksession =MLR(K10_c || K20_c,'session') (3-4) In this embodiment, Ksession = 4475e36eb9695530...
[0109] 5. Using the session key Ksession, use the symmetric encryption algorithm component to encrypt the transaction data 'Pay5yuan...' according to formula (3-5) to obtain the ciphertext ciphertext.
[0110] ciphertext=AES-GCM(Ksession,nonce,'Pay5yuan...') (3-5) 6. Update the first subkey K1_c according to formula (3-6): K1i+1 _c =MLR(K1i _c,'subkey1','update') (3-6) In this embodiment, i=0, that is, K11_c = fadfdc266e5b92aa...
[0111] 7. Update the path node key according to formula (3-7): Pathn+1 =PTHash(Pathn c || K1i+1 ∥K2j ) (3-7) In this step of the present embodiment, i=0, j=0, n=0, that is: Path1_c =PTHash(Path0_c || K11_c || K20_c ).
[0112] In this embodiment, Path1_c = 6db3e1c96450a64b...
[0113] The user-side wallet APP sends the ciphertext ciphertext and path node key Path1_c to the server.
[0114] On the server side: After receiving the data sent by the user's wallet app, the server parses the data to obtain the user ID, ciphertext, and path node key Path1_c. The server performs the following processing: 1. Determine the corresponding master key material based on the user ID and generate the master key Kmaster_s based on the PTHash component. Here, the master key Kmaster_s = b3c6a8d648840e42...
[0115] 2. Based on the master key, derive the initial values K10_s and K20_s of the first and second subkeys K1_s, respectively. K10_s = a9fd1a30fb9b5f5d..., and K20_s = 46b17c75f4adc441...
[0116] 3. Initialize the path key chain on the server side and calculate the initial path node key Path0_s. In this embodiment, Path0_s = a9fd1a30fb9b5f5d...
[0117] 4. Verify that the current path node key (i.e., the initial path node key Path0_s) of the path key is consistent with the received path node key Path0_c. By comparing, Path0_s = Path0_c, thus the path verification succeeds. If the verification fails, the server terminates the process and returns a verification failure message to the user's wallet app.
[0118] 5. Generate the decryption key Kdecrypt based on the initial value K10_s of the first subkey K1_s and the initial value K20_s of the second subkey K2_s, and decrypt the received ciphertext ciphertext according to formula (3-8) to obtain the plaintext data plaintext: plaintext=AES (Kdecrypt,nonce,ciphertext) (3-8) In this embodiment, Kdecrypt = 4475e36eb9695530..., and the decrypted civilized data is the transaction data "Pay5yuan...".
[0119] 6. Update the first subkey K1_s and path node keys. The updated first subkey K1_s is: K11_s = fadfdc266e5b92aa..., Path1_s = 6db3e1c96450a64b...
[0120] At this point, the data transmission process of a transaction data is completed.
[0121] On the other hand, the user ID's user wallet app and server each update keys according to the update mechanism of the multi-layer cascade key rotation protocol in the expanded security protocol. As previously described, the user wallet app updates the first subkey K1_c after each session key Ksession is generated, and the server updates the first subkey K1_s after each decryption. After the first subkey K1 is updated a preset number of times, the second subkey K2 is updated. Periodic renegotiations are conducted to determine a new shared key as the master key material, regenerate the master key Kmaster, subkey initial values, and a new path key chain. During the key update process, after the updated key is generated, the old key is destroyed. This ensures that historical transactions cannot be decrypted if the current key is compromised, thus ensuring the security of transaction data.
[0122] The present invention provides a key with a multi-level linkage architecture, which manages keys at each level in a hierarchical manner and updates them according to their respective update conditions. Through the dynamic dependency and irreversible path constraints of multi-level keys, forward / backward security and anti-quantum attack capabilities are achieved.
[0123] Because the subkeys in this invention are updated unidirectionally (e.g., K1i → K1i+1), when used, the old key can be immediately destroyed when the new key is generated, thus ensuring that historical data cannot be decrypted and achieving forward security of communication. The periodic reset of the master key and subkeys isolates future keys from old data, achieving backward security of communication. The multi-layered cascaded key provided by this invention offers quantum-proof advantages. However, due to the hierarchical relationship, cracking a single key requires cracking multiple associated keys, which is computationally complex. This complexity is further exacerbated when different keys are generated using different algorithms.
[0124] For example, the cracking time of a level 3 key is T 破解 =T 主密钥 ×T 子密钥1 ×T 子密钥2 .
[0125] Among them, the single-layer cracking time T 单层= 2^b operations, where b is the bit strength of the key. For the key generated by the Kyber-1024 algorithm component, its security strength is b=173 bits (NIST estimated value). Assuming that the attacker can perform 1018 operations per second (the current supercomputer computing power), we can get: T 单层 = 11972621413014756705924586149611790497021399392059392 = 1.197e+52 seconds = 3.796e+44 years.
[0126] Total cracking time of three-level linkage: T 破解 =(T 单层 ) 3 =(3.796e+44) 3 ≈1.716e+156 years. This value far exceeds actual physical limitations (for example, the age of the universe is approximately 10^17 seconds). Therefore, after reducing the single-layer key size, even if the generated key size is smaller than that provided by the Kyber-1024 algorithm, it still requires a sufficiently long cracking time. While ensuring resistance to quantum advantage, this reduces the computational complexity and time of the key, lowers the requirements for system performance, and improves processing speed.
[0127] In addition, the present invention also monitors key security events, such as vulnerabilities in quantum-resistant key algorithms, key leakage events, and the like. When a key security event is monitored, the corresponding first key algorithm key is determined based on the monitored key security event and the first key algorithm is uninstalled. Then, a second key algorithm that replaces the secure version of the first key algorithm is determined from the component center, and the secure version of the second key algorithm is loaded from the component center. Then, based on the aforementioned unloading and loading operations of the key algorithm information and the corresponding key algorithm information, the cryptographic suite is updated, that is, the uninstalled first key algorithm information is deleted from the cryptographic suite list, and the loaded second key algorithm information is added. Based on the updated cryptographic suite, a new multi-layer cascade key is generated according to the multi-layer cascade key rotation protocol and the original multi-layer cascade key is frozen. In the subsequent transmission of application data, application data is transmitted based on the new multi-layer cascade key. After the original multi-layer cascade key is frozen, it is in a read-only state and can decrypt historical application data when needed.
[0128] In the present invention, the component center can be a supplementary system to the quantum-resistant cryptographic migration system or a system provided by a third party. The algorithm component library it provides includes a variety of encryption algorithm components and related key algorithm components, signature algorithm components, and so on. In one embodiment, the component center acts as an independent third-party system and includes two types of users. One type of user is the algorithm developer, who provides corresponding algorithms based on the component center's requirements. The component center encapsulates each algorithm as a component with a standard interface and provides corresponding download channels or APIs. This enables the components of the present invention to be hot-swappable, loading when needed and uninstalling when not needed, without affecting data transmission in the quantum-resistant cryptographic migration system. The other type of user is the algorithm user, whose system is the quantum-resistant cryptographic migration system of the present invention. The algorithm user can download the required algorithm components from the component center as needed or call the required algorithm component's API. For example, when a key security event is detected, the corresponding algorithm component is uninstalled and a new algorithm component is loaded from the component center. Furthermore, during the key management process, the present invention monitors the validity of the key algorithm components installed in the quantum-resistant cryptographic migration system. If an installed key algorithm component in the quantum-resistant cryptographic migration system is invalid, the invalid key algorithm component is uninstalled from the system. In one specific embodiment, the component center's configuration file records the validity conditions of the key algorithm component, such as usage duration and manually marked invalid flags. The quantum-resistant cryptographic migration system queries the configuration file through periodic polling to determine whether the algorithm currently installed in the system is valid. Alternatively, the component center monitors the validity of the algorithm components in its configuration file and notifies the corresponding user (i.e., the corresponding encrypted communication system) if the algorithm is invalid. This ensures that the subkey or master key can be updated in a timely manner without affecting data transmission in the communication system.
[0129] On the other hand, the present invention also provides a quantum cryptography migration resistant system, see Figure 8 , Figure 8 This is a block diagram of the principles of a quantum-resistant cryptographic migration system according to an embodiment of the present invention. In this embodiment, the quantum-resistant cryptographic migration system includes a protocol adaptation module 10 and a data transmission module 20. The protocol adaptation module 10 adaptively extends the data transport layer security protocol. The extensions include at least: adding a quantum-resistant cryptographic suite to the cipher suite list; and adding the following to the encryption extension: a chained post-quantum key generation mechanism, a multi-layer cascade key rotation protocol, encryption / decryption key derivation for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data. The data transmission module 20 securely transmits application data between the encryption and decryption ends based on the extended transport layer security protocol.
[0130] The quantum-resistant cryptographic migration system further includes a secure rollback module 30, which monitors key security events. After monitoring a key security event, the secure rollback module 30 rolls back to a secure version of the key algorithm, regenerates a multi-layer cascade key based on the secure version of the key algorithm, and freezes the original multi-layer cascade key. Application data is transmitted based on the new multi-layer cascade key, and historical application data is decrypted based on the original multi-layer cascade key.
[0131] The data transmission module 20 includes a key management unit 201, an encryption unit 202, a verification unit 203, and a decryption unit 204. The encryption end and the decryption end each include a key management unit 201. The key management unit 201 generates a master key, multi-level subkeys, and a path key chain based on the extended cipher suite according to a chained post-quantum key generation mechanism, and updates the multi-level cascade key according to a multi-layer cascade key rotation protocol. The encryption unit 202 is located on the encryption end and uses one or more of the partial subkeys as key material to derive an encryption key for symmetric encryption. It encrypts application data using symmetric encryption to generate ciphertext, and sends the ciphertext and the path node key at the end of the path key chain to the decryption end.
[0132] The verification unit 203 and the decryption unit 204 are located at the decryption end. After receiving the data sent by the encryption end, the decryption end parses the ciphertext and the path node key therefrom, and then verifies the path node key through the verification unit 203. After the verification of the path node key is successful, the decryption unit 204 derives the decryption key using one or more of the partial subkeys as key materials and decrypts the ciphertext.
[0133] When the encryption mode includes a message authentication code, the encryption unit 202 encrypts the application data using symmetric encryption to generate ciphertext, and then uses one or more subkeys from another part to generate a first authentication tag for the ciphertext. The first authentication tag is sent to the decryption end along with the ciphertext and the path node key at the end of the path key chain. Correspondingly, after the verification unit 203 successfully verifies the path, it uses one or more subkeys to generate a second authentication tag for the ciphertext. The first authentication tag and the second authentication tag are compared. If the first authentication tag and the second authentication tag match, the ciphertext is authenticated. The decryption unit 204 uses one or more of the partial subkeys as key material to derive a decryption key and decrypt the ciphertext. If the first authentication tag and the second authentication tag do not match, the ciphertext is authenticated and decryption of the ciphertext is terminated.
[0134] On the other hand, an embodiment of the present invention further provides an electronic device, see Figure 9 , Figure 9 FIG. 1 is a block diagram showing the structural principle of an electronic device according to an embodiment of the present invention. Figure 9As shown, the electronic device includes a processor 601 and a memory 602, wherein the memory stores computer instructions, and when the processor 601 runs the computer instructions, the anti-quantum cryptography migration method provided by the present invention is executed.
[0135] Specifically, processor 601 may include a central processing unit (CPU) or a graphics processing unit (GPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits according to embodiments of the present invention. Memory 602 includes storage for data or instructions. For example, memory 602 may be at least one of the following: a hard disk drive (HDD), read-only memory (ROM), random access memory (RAM), a floppy disk drive, flash memory, an optical disk, a magneto-optical disk, a magnetic tape, a universal serial bus (USB) drive, or other physical / tangible storage device. For another example, memory 602 may include removable or non-removable (or fixed) media. For another example, memory 602 may be internal or external to the integrated gateway disaster recovery device. Memory 602 may be non-volatile solid-state memory. In other words, memory 602 typically includes a tangible (non-transitory) computer-readable storage medium (such as a memory device) encoded with executable instructions. When the stored executable instructions are executed by processor 601 (e.g., by one or more processors), the quantum-resistant cryptographic migration method according to embodiments of the present invention can be implemented.
[0136] In one example, Figure 9 The electronic device shown may also include a communication interface 603 and a bus 610. The processor 601, memory 602, and communication interface 603 are connected and communicate with each other via the bus 610. The communication interface 603 is primarily used to enable communication between modules, devices, units, and / or devices in the electronic device.
[0137] Bus 610 includes hardware, software, or both. For example, the bus may include at least one of the following: an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industrial Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable bus. Bus 610 may include one or more buses. Although embodiments of the present invention describe or illustrate a particular bus, embodiments of the present invention contemplate any suitable bus or interconnect.
[0138] In another aspect, embodiments of the present invention further provide a computer-readable storage medium storing computer program instructions that, when executed by a processor, implement the aforementioned quantum cryptographic migration-resistant method. The computer-readable storage medium includes classical computer-readable storage media, such as the aforementioned memory 602, namely, read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible storage devices. It may also include storage media for storing quantum information and readable by a quantum computer, such as quantum random access memory (QRAM). QRAM can be considered a quantum version of RAM in classical computers. QRAM can create quantum superposition states containing information. Compared to RAM, which requires reading data individually, QRAM can read superpositioned data using superpositioned addresses. QRAM can be implemented using physical methods such as optics, semiconductor quantum dots, superconducting circuits, and ion traps.
[0139] The above illustrative flowcharts and / or block diagrams of the methods and systems of the embodiments of the present invention are described, along with various related aspects. It should be understood that each block in the flowcharts and / or block diagrams, or any combination thereof, may be implemented by computer program instructions, by dedicated hardware that performs the specified functions or actions, or by a combination of dedicated hardware and computer instructions. When implemented in hardware, this may be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc.; when implemented in software, this may be a program or code segment used to perform the desired task. The program or code segment may be stored in a memory or transmitted via a data signal carried in a carrier wave over a transmission medium or communication link. The code segment may be downloaded via a computer network such as the Internet or an intranet.
[0140] The above embodiments are only used to illustrate the present invention, and are not intended to limit the present invention. Ordinary technicians in the relevant technical field can make various changes and modifications without departing from the scope of the present invention. Therefore, all equivalent technical solutions should also fall within the scope of the present invention.
Claims
1. A quantum cryptography migration method, characterized in that: include: Adaptive extensions to the transport layer security protocol include at least the following: adding quantum-resistant cipher suites to the cipher suite list; adding the following to the encryption extension: chained post-quantum key generation mechanism, multi-layer cascade key rotation protocol, encryption / decryption key derivation for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data; The encryption and decryption ends securely transmit application data based on the extended transport layer security protocol. The secure transmission process of application data includes: The encryption end and the decryption end respectively generate the master key, multi-level subkeys and path key chain based on the extended cipher suite according to the chained post-quantum key generation mechanism; The encryption end uses one or more of the partial subkeys as key material to derive an encryption key for symmetric encryption, encrypts the application data using symmetric encryption to generate ciphertext, and sends the ciphertext and the path node key at the end of the path key chain to the decryption end; The decryption end verifies the path node key received along with the ciphertext, and after the verification of the path node key is successful, derives the decryption key using one or more of the partial subkeys as key material, and decrypts the ciphertext; and The encryption end and the decryption end update the multi-layer cascade key based on the multi-layer cascade key rotation protocol.
2. The quantum cryptography migration method according to claim 1, characterized in that: The symmetric encryption of application data added in the encryption extension also includes the encryption mode; Correspondingly, when the encryption mode includes the message authentication mode, during the secure transmission of application data between the encrypting end and the decrypting end based on the extended transport layer security protocol, the encrypting end encrypts the application data using a symmetric encryption method to generate a ciphertext, and then generates an authentication tag for the ciphertext based on one or more of the other partial subkeys; After verifying that the path node key received along with the ciphertext is passed, the decryption end verifies the authentication tag. After the authentication tag is verified, one or more of the partial subkeys are used as key materials to derive the decryption key and decrypt the ciphertext.
3. The quantum cryptography migration method according to claim 1 or 2, characterized in that: The steps of generating a master key, a multi-level subkey, and a path key chain by the encryption end and the decryption end respectively based on the extended cipher suite according to the chained post-quantum key generation mechanism include: The encryption end and the decryption end determine the shared key through key negotiation based on the extended transport layer security protocol; The encryption end and the decryption end each generate a quantum-resistant master key based on the shared key using the PT hash algorithm constructed by a quantum random circuit in the quantum-resistant cryptographic suite; The encryption end and the decryption end each generate a multi-level subkey based on the master key, wherein the initial value of each subkey level is generated based on the initial value of the master key and / or one or more subkeys of the upper level; The encryption end and the decryption end respectively construct a path key chain, and generate an initial path node key of the path key chain based on the master key and / or one or more subkey initial values.
4. The method for quantum cryptography migration according to claim 3, wherein: The steps for the encryption end and the decryption end to update the multi-layer cascade key based on the multi-layer cascade key rotation protocol include: During the master key update cycle, after one or more of the partial subkeys are used as key material to derive an encryption / decryption key for symmetric encryption, the one or more subkeys used to derive the encryption / decryption key are updated; when the life of a subkey reaches a preset life cycle, the subkey is updated; when the number of updates of a second subkey associated with the first subkey reaches a threshold, the first subkey is updated; When the life of the master key reaches a preset life cycle length, the master key is updated. After the master key is updated, a multi-level new subkey and a new path key chain are generated based on the updated master key.
5. The method for quantum cryptography migration according to claim 4, characterized in that: The steps of updating the multi-layer cascade key based on the multi-layer cascade key rotation protocol at the encryption end and the decryption end also include: After any subkey is updated, a new path node key is generated based on the path node key at the end of the path key chain and at least all the subkeys updated so far, and added to the end of the path key chain; When the master key is updated, after generating multiple levels of new subkeys based on the updated master key, the initial path node key of the new path key chain is generated based on the updated master key and / or one or more new subkey initial values.
6. The method for quantum cryptography migration according to claim 1, wherein: The adaptive extensions to the transport layer security protocol also include a rollback mechanism. The secure transmission process of application data also includes: Monitor key security events; Determining a corresponding first key algorithm component based on the monitored key security event and uninstalling the first key algorithm component; Determining from a component center a second key algorithm component that replaces the secure version of the first key algorithm component; wherein the component center provides a plurality of encryption algorithm components, related key algorithm components, and signature algorithm components; Load the secure version of the second key algorithm component from the component center; Deleting the uninstalled first key algorithm information from the cipher suite list and adding the loaded second key algorithm information; and Based on the updated cipher suite, a new multi-layer cascade key is generated according to a chained post-quantum key generation mechanism and the original multi-layer cascade key is frozen. Application data is transmitted based on the new multi-layer cascade key, and historical application data is decrypted based on the original multi-layer cascade key.
7. A quantum-resistant cryptographic migration system, characterized in that: include: A protocol adapter module configured to adapt and extend the transport layer security protocol for data, the extensions including at least: adding a quantum-resistant cipher suite to the cipher suite list; adding to the encryption extensions: a chained post-quantum key generation mechanism, a multi-layer cascade key rotation protocol, encryption / decryption key derivation for application data based on multi-layer cascade keys, path key chain verification, and symmetric encryption of application data; The data transmission module is configured to securely transmit application data between the encryption end and the decryption end based on the extended transport layer security protocol, wherein the secure transmission process of the application data includes: The encryption end and the decryption end respectively generate the master key, multi-level subkeys and path key chain based on the extended cipher suite according to the chained post-quantum key generation mechanism; The encryption end uses one or more of the partial subkeys as key material to derive an encryption key for symmetric encryption, encrypts the application data using symmetric encryption to generate ciphertext, and sends the ciphertext and the path node key at the end of the path key chain to the decryption end; The decryption end verifies the path node key received along with the ciphertext, and upon successful verification of the path node key, derives a decryption key using one or more of the partial subkeys as key material, and decrypts the ciphertext; and The encryption end and the decryption end update the multi-layer cascade key based on the multi-layer cascade key rotation protocol.
8. The quantum cryptography migration system according to claim 7, characterized in that: When the transport layer security protocol is adaptively extended, the extension content also includes a rollback mechanism. The system further includes: The security rollback module is configured to monitor key security events. After monitoring a key security event, it rolls back to the secure version of the key algorithm, regenerates the multi-layer cascade key based on the secure version of the key algorithm, and freezes the original multi-layer cascade key. Application data is transmitted based on the new multi-layer cascade key, and historical application data is decrypted based on the original multi-layer cascade key.
9. An electronic device comprising a processor and a memory, characterized in that: The memory stores computer instructions, and when the processor runs the computer instructions, it executes the anti-quantum cryptography migration method according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the anti-quantum cryptography migration method according to any one of claims 1 to 6 is executed.
Citation Information
Patent Citations
Internet of Things equipment information secure transmission method and system based on quantum key
CN118900205A
Double-ratchet password communication method and system based on mixed quantum and asymmetric password
CN118972049A
Certificate-based post-quantum encryption migration system, method, device and medium
CN119906543A
Data link security management and control system and method based on dynamic encryption
CN120165965A
Secure Session Resumption using Post-Quantum Cryptography
US20230308424A1
Cited By
High-availability network access authentication method and system based on multiple optical modules
CN121967085A
High availability network access authentication method and system based on multiple optical modules
CN121967085B