Agent-based anti-quantum security enhancement method and device

By deploying quantum-resistant security enhancement devices PA and PB between communication entities, and using post-quantum cryptography for secure authentication and encryption/decryption of data streams, the security challenges of existing information systems under the threat of quantum computing are solved, achieving low-cost, loosely coupled quantum-resistant secure migration and system compatibility.

CN121098543APending Publication Date: 2025-12-09FUDAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511147699.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing information systems face difficulties in implementing quantum security enhancements in a low-cost, loosely coupled manner when confronted with quantum computing threats. In particular, the security of classical public-key cryptography is challenged, necessitating a smooth migration method to resist quantum computing attacks.

Method used

Deploy paired proxy-based quantum-resistant security enhancement devices PA and PB between communication entities A and B. Use proxy technology to direct the key negotiation data stream to PA and PB, and use post-quantum cryptography for security authentication and encryption/decryption to ensure forward security and backward compatibility of the communication process.

Benefits of technology

It enables low-cost, loosely coupled quantum-resistant security enhancement without altering existing information systems, ensuring the security of communication links while maintaining system compatibility and user workflows.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098543A_ABST
    Figure CN121098543A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information security, and particularly relates to an agent-based anti-quantum security enhancement method and device. According to the method disclosed by the invention, anti-quantum security enhancement is carried out on the existing communication system under the condition that a cryptographic algorithm, a security protocol, cryptographic equipment and a software and hardware system related to the existing security communication system and an information security protection system thereof are not changed. According to the method, quantum security migration resistance can be carried out on various security communication protocols including TLS, TLCP, DTLS, IPSec, SSH and WireGuard in a relatively low-cost, low-coupling and smoother manner, and forward security and backward compatibility of a communication link are guaranteed. And the anti-quantum security upgrading of the existing information system based on the method and the device disclosed by the invention is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information security, and particularly relates to a proxy-based quantum-resistant security enhancement method and device. BACKGROUND

[0002] With the continuous development of the engineering construction of quantum computers, the classical public key cryptography system is facing a real threat. The theoretical achievements represented by the SHOR algorithm show that the large integer factorization problem, the discrete logarithm problem on prime fields and the discrete logarithm problem on elliptic curves have polynomial time solving algorithms under the quantum computing model. This means that after solving the problems of quantum bit scaling, quantum error correction and quantum coherence time, the classical public key cryptography system based on the difficulty of large integer factorization and discrete logarithm problems such as RSA and ECC will no longer be secure. On the other hand, based on existing theoretical achievements, the academic and industrial circles generally believe that the quantum security bit number of well-designed cryptographic hash functions and symmetric encryption algorithms is about half of the classical security bit number.

[0003] To cope with the security threat of quantum computing to the classical public key cryptography system and the "harvest now-decrypt later" attack, the academic circles continue to carry out research work on post-quantum cryptography (PQC) or quantum-resistant cryptography (QRC), governments successively carry out standardization work of PQC algorithms, and the industrial circles successively carry out pilot work of migration of classical cryptography to quantum-resistant cryptography.

[0004] The migration of quantum-resistant cryptography is a comprehensive system engineering involving cryptographic algorithms, security protocols, cryptographic devices, software and hardware systems. It is necessary to spend a lot of manpower, material resources and time cost to redesign security protocols, develop new cryptographic devices and software and hardware systems based on PQC algorithms for a large number of existing information systems and their information security protection mechanisms. How to enhance the quantum-resistant security of information systems based on the existing information system and its information security protection system in a low-cost, low-coupling and more smooth way has become a real problem that the academic and industrial circles need to solve.

[0005] The migration of quantum-resistant cryptography is a comprehensive system engineering involving cryptographic algorithms, security protocols, cryptographic devices, software and hardware systems. It is necessary to spend a lot of manpower, material resources and time cost to redesign security protocols, develop new cryptographic devices and software and hardware systems based on PQC algorithms for a large number of existing information systems and their information security protection mechanisms. How to enhance the quantum-resistant security of information systems based on the existing information system and its information security protection system in a low-cost, low-coupling and more smooth way has become a real problem that the academic and industrial circles need to solve. SUMMARY

[0006] The purpose of this invention is to provide a proxy-based quantum security enhancement method and apparatus, which can enhance the quantum security of existing information systems without changing the cryptographic algorithms, security protocols, cryptographic devices and hardware and software systems involved in the existing information system and its information security protection system; so as to realize the quantum security migration of existing information systems in a lower cost, looser coupling and smoother manner, and ensure the forward security and backward compatibility of communication links.

[0007] The proxy-based quantum security enhancement method provided by this invention specifically includes:

[0008] Based on existing secure communication systems, deploy paired, agent-based quantum-resistant security enhancement devices P between communication entities A and B. A and P B , where P A Deployed on test A, P B Deployed on test B; the device here can be a hardware system, a software system, or a combination of both; the key negotiation data stream between A and B is redirected through P via proxy technology. A and P B And the data content of the data stream can be P A and P B The data flow from A to B passes through A and P in sequence. A P B B, and the data flow from B to A passes through B and P in sequence. B P A A;

[0009] When the key negotiation data stream from A to B passes through P A At that time, in P A In the process, some or all of the data items in the key negotiation are used for security authentication and / or encryption using post-quantum cryptography; when the key negotiation data stream from A to B passes through P B At that time, in P B The corresponding key-negotiated data items are then securely decrypted and / or verified using post-quantum cryptography.

[0010] When the key negotiation data stream from B to A passes through P B At that time, in P B In the process, some or all of the data items in the key negotiation are used for security authentication and / or encryption using post-quantum cryptography; when the key negotiation data stream from B to A passes through P... A At that time, in P A The corresponding key-negotiated data items are then securely decrypted and / or verified using post-quantum cryptography.

[0011] For user A or B, the workflow can not be affected or unperceived; using the above framework, the existing security communication entities can complete the black box, unperceived, low-cost quantum resistance security enhancement function.

[0012] The application can be resistant to quantum security enhancement for all secure communication systems that meet the following conditions:

[0013] Condition 1: The data communication process of the secure communication system can be divided into four stages, namely the plaintext-based key agreement stage, the session key acquisition stage, the session key initial application stage, and the optional session key subsequent application stage.

[0014] Condition 2: In the plaintext-based key agreement stage, the communication entities A and B will perform several rounds of data communication. Without loss of generality, it is assumed that A transmits n A data items to B in plaintext, in order And B transmits n B data items to A in plaintext, in order

[0015] Condition 3: In the session key acquisition stage, communication entities A and B first determine the key derivation function KDF based on their own "current owned data items"; here "current owned data items" include default data items, current cache data items including interactive data items in the "plaintext-based key agreement stage", and data items obtained based on "current owned data items" after polynomial time complexity calculation; then, using their own current owned KDF input data items, which are a subset of "current owned data items", as the input of KDF, locally calculate the KDF function value and use it as the session key ssk; without loss of generality, it is assumed that A has m A KDF input data items, respectively The corresponding KDF function value is ssk A = ssk; while B has m B KDF input data items, respectively The corresponding KDF function value is ssk B = ssk; It should be noted that the session key ssk may be divided into different parts according to the functional needs, including symmetric encryption keys from A to B, symmetric authentication keys from B to A, etc.; in addition, there is no data interaction between A and B in this stage.

[0016] Condition 4: In the session key initial application stage, communication entities A and B first determine the authentication encryption algorithm AEAD based on their own "current owned data items", and then use the session key ssk obtained in the "session key acquisition stage" to encrypt and authenticate the data to be transmitted after the "plaintext-based key agreement stage" to protect the transmission.

[0017] Condition 5: In the optional session key subsequent application stage, communication entities A and B can perform ciphertext-based key agreement, session key switching, and encryption and authentication protection transmission of subsequent data to be transmitted by applying a new session key under the encryption and authentication protection transmission mechanism thereof in the current key application stage, i.e., the session key initial application stage or the session key subsequent application stage.

[0018] Condition 6: If the interaction data of the "plaintext-based key agreement stage" between communication entities A and B and the interaction data of other stages, i.e., the session key initial application stage and the optional session key subsequent application stage, are concatenated in the original relative order, there is a method with a polynomial time complexity to identify and separate the two, i.e., the interaction data of the "plaintext-based key agreement stage" and the interaction data of other stages.

[0019] Condition 7: If the interaction data of the "plaintext-based key agreement stage" between communication entities A and B are concatenated in the original relative order, there is a method with a polynomial time complexity to identify and separate the data items.

[0020] It should be noted that the current mainstream secure communication protocols meet the above conditions 1 to 7, including TLS, TLCP, DTLS, IPSec, SSH, WireGuard, etc.

[0021] Further:

[0022] The post-quantum cryptography refers to a public key cryptography system capable of resisting classical computing and quantum computing attacks, including key encapsulation mechanisms, public key encryption, digital signature, and key agreement algorithms based on lattices, cryptographic hash functions, coding, multivariate, homology.

[0023] The "P A deployed in the A station, P B deployed in the B station" means that the key agreement data flow from A to B needs to pass through P A first, then reach P B and finally reach B, and the key agreement data flow from B to A needs to pass through P B first, then reach P A and finally reach A; wherein the non-key agreement data flow from A to B can not pass through P A and / or P B , or can pass through P A and / or P B ; the non-key agreement data flow from B to A can not pass through P B and / or P A , or can pass through P , and / or P A; P A is the deployment location of A, including being in the same physical device, or being in the same virtual machine, or being behind the same gateway, or P A is the default gateway of A; P B is the deployment location of B, including being in the same physical device, or being in the same virtual machine, or being behind the same gateway, or P B is the default gateway of B;

[0024] The "proxy technology" in the "proxy technology is used to guide the key negotiation data flow between A and B through P A and P B " refers to all data flow guiding technologies that meet the following conditions: the key negotiation data flow from A to B passes through A, P A P B , B in turn, and the key negotiation data flow from B to A passes through B, P B , P A , A in turn.

[0025] The "security authentication and / or encryption" can only provide encryption function without authentication function, or can provide both encryption function and authentication function;

[0026] The "security decryption and / or verification" can only provide decryption function without verification function, or can provide both decryption function and verification function;

[0027] The "security authentication and / or encryption using post-quantum cryptography" and "security decryption and / or verification using post-quantum cryptography" require P A , P B to complete the bidirectional security authentication and encryption and decryption verification function between A and B in cooperation, and do not require P A and / or P B to have post-quantum key encapsulation and decapsulation capabilities at the same time.

[0028] For the convenience of description, the following symbols and name conventions are used: Assuming that there are two data items d and u appearing in the process of executing a secure communication protocol, we say that "u is not related to d" or "d has no contribution to u" if only modifying the value of d can ensure that the protocol still executes according to the original execution path to the appearance of u and the value of u remains unchanged; otherwise, we say that "u is related to d" or "d has contribution to u". For example: If there are integer data items d1, d2, d3 and u = 2d3 appearing in the process of executing a protocol in turn, where d2 is not related to d1, and d3 is related to d1 but not related to d2, then u is related to d1, and u is not related to d2. For integers i and j that satisfy i≤j, let [i, j] be the set of all integers x that satisfy i≤x≤j. Let Let D be the set of all KDF input data items during the session key acquisition phase. A→B ={d i,A→B There exist u∈U and i∈[1, n] A ] Make u is d i,A→B The relevant set is the collection of all data items that contribute to the session key ssk, transmitted in plaintext from A to B during the "plaintext-based key negotiation phase". Let D be the set of these data items. B→A ={d i,B→A There exist u∈U and i∈[1, n] B ] Make u is d i,B→A The relevant set is the collection of all data items that contribute to the session key ssk, transmitted in plaintext from B to A during the "plaintext-based key negotiation phase". Let be the relevant data. Let D be a non-empty subset of the set of all data items that contribute to the session key ssk and transmitted in plaintext between A and B during the "plaintext-based key negotiation phase". A,B These can be given in the form of system configuration parameters. Post-quantum cryptosystems used for quantum-resistant security enhancements are given in the form of system configuration parameters.

[0029] Assume the secure communication system to be enhanced against quantum security meets conditions 1 to 7 above. The agent-based method for enhancing quantum security proposed in this invention has the following specific steps:

[0030] P A The steps include:

[0031] Step A1: Listen for incoming P A The communication data stream is used to determine whether it belongs to the "plaintext-based key negotiation phase" interaction data between A and B. If it does, proceed to step A2; otherwise, proceed to step A4.

[0032] Step A2: Identify and segment all data items contained in the data stream, and denote the set of segmented data items as D, then proceed to step A3; if not segmented, then D contains all the interactive data items between A and B in the "plaintext-based key negotiation phase", then proceed directly to step A3.

[0033] Step A3: For each data item d∈D in D, perform the following processing: If If the data stream direction is A→B, then the content of the corresponding data item d in the data stream remains unchanged or is authenticated and / or encrypted using post-quantum cryptography; otherwise, if the data stream direction is A→B, then the content of data item d is authenticated and encrypted using post-quantum cryptography; otherwise, the content of data item d is decrypted and verified using post-quantum cryptography; after all data items in D have been processed, proceed to step A4.

[0034] Step A4: Perform local operations required for necessary quantum-resistant enhancements; if the data flow direction is B→A, peel off the real existing quantum-resistant security auxiliary data from the data stream, then send the peeled-off data to A, go to Step Al; otherwise, send the data stream together with necessary quantum-resistant security enhancement auxiliary data to P B , then go to Step Al.

[0035] P B The steps include:

[0036] Step Bl: Listen to the incoming communication data stream of P B , determine whether the data stream belongs to the interactive data of the "plain-text-based key agreement phase" between A and B, if yes, go to Step B2; otherwise, go to Step B4.

[0037] Step B2: Identify and segment all data items contained in the data stream, and denote the segmented data item set as D, go to Step B3; if no segmentation, D contains all the interactive data items of the "plain-text-based key agreement phase" between A and B, go to Step B3 directly.

[0038] Step B3: Process each data item d∈D as follows: if , keep the content of the corresponding data item d in the data stream unchanged or encrypt and / or authenticate it using post-quantum cryptography; otherwise, if the direction of the data stream is B→A, authenticate and encrypt the content of the data item d using post-quantum cryptography; otherwise, decrypt and verify the content of the data item d using post-quantum cryptography; when all data items in D are processed, go to Step B4.

[0039] Step B4: Perform local operations required for necessary quantum-resistant enhancements; if the data flow direction is A→B, peel off the real existing quantum-resistant security auxiliary data from the data stream, then send the peeled-off data to B, go to Step Bl; otherwise, send the data stream together with necessary quantum-resistant security enhancement auxiliary data to P A , then go to Step Bl.

[0040] In the present application, the "local operations required for necessary quantum-resistant security enhancement" and "necessary quantum-resistant security enhancement auxiliary data" in step A4 and step B4 are related to the following requirements: the "authentication encryption using post-quantum cryptography" and "decryption verification using post-quantum cryptography" in step A3 and step B3 require the corresponding device to have sufficient capabilities to successfully complete, which include having certain public key information, private key information, ciphertext information, symmetric key information, etc. These capabilities are obtained by completing "local operations required for necessary quantum-resistant security enhancement" and "sending data stream together with necessary quantum-resistant security enhancement auxiliary data" before a certain stage. In step A4 and step B4 of a certain stage, if a certain local operation does not cause the subsequent step A3 or step B3 to fail due to insufficient capabilities, then the operation is not necessary in the current stage, i.e. it can be delayed; similarly, in step A4 and step B4 of a certain stage, if the "sending data stream together with necessary quantum-resistant security enhancement auxiliary data" operation is replaced with a "sending data stream" operation, and does not cause the subsequent step A3 or step B3 to fail due to insufficient capabilities, then the quantum-resistant security enhancement auxiliary data is not necessary in the current stage, i.e. it can be sent later.

[0041] The present application also discloses a proxy-based quantum-resistant security enhancement device, specifically comprising:

[0042] According to the proxy technology and deployment method used, the proxy-based quantum-resistant security enhancement device can be divided into two categories: the first category is a proxy-based quantum-resistant security enhancement device that shares a communication identifier; the second category is a proxy-based quantum-resistant security enhancement device that exclusively uses a communication identifier. The communication identifier is used to uniquely identify each communication data stream, and the communication identifier is composed of a source identifier and a destination identifier. For example, in the transport layer protocol of OSI, the communication identifier is a four-tuple (source IP address, source port address, destination IP address, destination port address), the source identifier is a two-tuple (source IP address, source port address), and the destination identifier is a two-tuple (destination IP address, destination port address). In the proxy-based quantum-resistant security enhancement device that shares a communication identifier, the outgoing proxy data and the incoming original data use the same communication identifier; in the proxy-based quantum-resistant security enhancement device that exclusively uses a communication identifier, the outgoing proxy data and the incoming original data use different communication identifiers.

[0043] The anti-quantum security enhancement device has the ability to authenticate and encrypt data streams based on post-quantum cryptography and decrypt and verify; the existence form of the anti-quantum security enhancement device based on the agent includes a software module with network communication function, a pluggable hardware device, a pure functional independent hardware device, an independent hardware device integrating other network functions including DNS and gateway; the anti-quantum security enhancement device based on the agent has the proxy forwarding capability of data communication, and the proxy forwarding technologies used include HTTP proxy technology, transparent proxy technology, SOCKS proxy technology, eBPF-based proxy technology and self-defined proxy technology.

[0044] The present application enhances the anti-quantum security of the existing communication system without changing the existing security communication system and the information security protection system related to the cryptographic algorithm, security protocol, cryptographic device and software and hardware system. The method can perform anti-quantum security migration of various security communication protocols including TLS, TLCP, DTLS, IPSec, SSH and WireGuard in a low-cost, low-coupling and more smooth manner, and ensure the forward security and backward compatibility of the communication link. The existing information system based on the method and device of the present application is ensured to be upgraded to anti-quantum security. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figure 1 It is a typical network topology diagram.

[0046] Figure 2 It is a message interaction diagram of TLS1.3 complete handshake process.

[0047] Figure 3 It is a workflow schematic diagram of using the anti-quantum security enhancement method based on the agent to enhance the anti-quantum security of TLS1.3. DETAILED DESCRIPTION

[0048] The present application will be further described below by examples in conjunction with the drawings. The described examples are not all examples. All other examples obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0049] Figure 1 It is a typical network topology diagram, and the method of the present application will be illustrated below based on the topology diagram. The diagram includes six network entities, i.e. communication entities A and B, devices P A and P B , gateway G A and domain name resolution server DNS; the gateway G A has three network interfaces and connects three network segments, wherein the network interface ethagg is configured with an IPv4 address

[0050] IPag (172.16.1.88) connects to the internet. Its network interface `ethag` is configured with the IPv4 address `$ipag=192.168.10.1` as the default gateway for LAN 1. Its network interface `ethpg` is configured with the IPv4 address `$ippg=192.168.20.1` as the default gateway for LAN 2. The DNS server has one network interface `ethd` configured with the IPv4 address `$ipd=192.168.10.200` connected to LAN 1. Entity A has one network interface `etha` configured with the IPv4 address `$ipa=192.168.10.100` connected to LAN 1. Entity A uses DNS as its domain name resolution server. Device P... A There is one network interface ethp configured with an IPv4 address $ipp=192.168.20.66 connected to LAN 2, device P A Listening on TCP port $portp=443, device P A The data content of the data stream entering $ipp:$portp can be obtained; device P B There are two network interfaces connecting two network segments. The network interface `ethq` is configured with the IPv4 address `$ipq=192.168.10.1` as the default gateway for LAN 3. The network interface `ethqg` is configured with the IPv4 address `$ipqg=10.10.10.80` and the domain name `demo.xxx.edu.cn` to connect to the Internet. Device P... B The underlying system listens on TCP port $portn=443 and uses port mapping technology to map $ipqg:$portn to port $portb of entity B within LAN 3. Entity B then provides TLS 1.3 service functionality to the Internet. Additionally, device P... B Listen on TCP port $portq=9443 at address $ipq, device P B The data content entering the $ipq:$portq data stream can be obtained; Entity B has one network interface ethb configured with an IPv4 address $ipb=192.168.10.200 to connect to LAN 3. Entity B enables TLS 1.3 service by listening on TCP port $portb=8443, supplemented by device P. B The port mapping provides TLS 1.3 service functionality to the Internet.

[0051] The following section introduces a series of related proxy technologies, demonstrating how to redirect the data flow between entities A and B through device P. A and P B And make device P A and P B The data stream can be obtained such that the data stream from A to B passes through A and P in sequence.A , P B , B, and the data flow from B to A direction successively passes through B, P B , P A , A.

[0052] Proxy technique one: set the device as the only access to the data communication between the communication entities, to ensure that all data flows between the communication entities pass through the device.

[0053] In particular, if two communication entities are in different networks, for one or both of the communication entities, the corresponding proxy-based anti-quantum security enhancement device is used as the default and only gateway for the communication entity to communicate with the external network.

[0054] For example, as shown in the network topology diagram of Figure 1 , communication entities A and B are in different local area networks and are connected through the Internet. By setting the device P B as the default gateway and the only gateway for entity B to access the Internet, all communication data flows between A and B can be ensured to pass through the device P B .

[0055] Proxy technique two: domain name resolution guidance.

[0056] Suppose the peer communication entity and / or its corresponding device has a domain name, the local communication entity obtains the IP address of the peer through the domain name resolution service, and through domain name guidance, i.e. resolving the IP address corresponding to the peer domain name into the IP address of the local corresponding anti-quantum security enhancement device, the data flow between the local communication entity and the peer communication entity is guided to the local corresponding anti-quantum security enhancement device; further, by performing port listening in the local corresponding anti-quantum security enhancement device, and the listening port number is the same as the port number of the peer facing the Internet to provide services, the local corresponding anti-quantum security enhancement device can obtain all data flows from the local communication entity to the peer communication entity.

[0057] For example, as shown in the network topology diagram of Figure 1 , communication entity B implements the TLS1.3 service function facing the Internet through the port mapping of the device P B , and the device P B has a domain name demo.xxx.edu.cn and is bound to an IPv4 address $ipqg=10.10.10.80; now suppose that communication entity A initiates a connection request to entity B, entity A first requests the DNS to resolve the domain name demo.xxx.edu.cn, and then the DNS resolves demo.xxx.edu.cn into 192.168.20.66, i.e. the device P Bentity A and $ipp:$portn, i.e. $ipp:$portp, establish connection and send data stream, device P A will obtain all data stream sent by entity A to entity B.

[0058] Proxy technique three: data relay and forwarding.

[0059] Suppose the data content of data stream sent by a communication terminal to the opposite terminal can be obtained by the device corresponding to the terminal, the device will send the data stream to the device of the opposite terminal after changing the source identifier of the corresponding data stream into the source identifier of the device itself, and the device of the opposite terminal will send the data stream to the communication entity of the opposite terminal, thus realizing the function that the data stream in single direction flows through the communication entity of the local terminal, the device of the local terminal, the device of the opposite terminal and the communication entity of the opposite terminal in sequence; it should be pointed out that at this time the device of the opposite terminal only completes the guidance of the data stream and does not necessarily obtain the data of the data stream.

[0060] Take the network topology diagram shown in Figure 1 as an example, based on proxy technique two, i.e. domain name resolution guidance technique, device P A will obtain all data stream sent by entity A to entity B. A relay and forwarding: when entity A establishes connection with $ipp:$portp, device P A establishes connection with $ipqg:$portn, at this time device P A establishes connection with $ipqg:$portn with the source IP address of $ipp instead of the IP address $ipa of entity A, when entity A sends data stream to $ipp:$portp, device P A sends data stream to $ipqg:$portn; since the port mapping from $ipqg:$portn to $ipb:$portb is set in device P B , the data stream successfully reaches communication entity B; it should be noted that the port mapping is a system bottom function, the data stream flows through device P B but the data content is not obtained by device P B .

[0061] Proxy technique four: routing rule configuration.

[0062] In a specific network topology, the routing rule configuration can be used to change the data stream direction to meet the data stream sequence requirement required by the present application, i.e. the data stream in "A to B direction" sequentially passes through A, P A , P B , B, while the data stream in "B to A direction" sequentially passes through B, P B , P AIn addition, with the help of routing rule configuration, the problem of data flow passing through a device but the device failing to obtain the data flow content can be solved: listen to a certain transport layer port in the device and use routing configuration rules to make the data flow enter the transport layer port.

[0063] by Figure 1 Taking the network topology diagram shown as an example, without using domain name redirection technology, it is done through gateway G A Adding the following routing rule will allow the data stream from communication terminal A to B to first enter device P. A And device P A Data to terminal B is transmitted through gateway G. A Then it directly enters the Internet: "For a certain data stream, if its destination IP address and TCP port number are $ipqg and $portn respectively, and the data stream does not enter the gateway G from the network interface ethpg." A Then the data stream will be routed through the network interface ethpg to the network device with IPv4 address $ipp.

[0064] by Figure 1 Taking the network topology diagram shown as an example, through device P A Adding the following routing rule will allow access to device P. A The data stream from communication terminal A to B enters $ipp:$portp, so its data content can be accessed by device P. A Obtain; and device P A Data to B goes through gateway G A Then it directly enters the Internet: "For a certain data stream, if its destination IP address and TCP port number are $ipqg and $portn respectively, and the data stream enters device P from the network interface ethp..." A Then the data stream will be handed over to $ipp:$portp for processing.

[0065] by Figure 1 Taking the network topology diagram shown as an example, through device P B Adding the following routing rule will allow the data flow from communication terminal A to B to enter $ipq:$portq, thus enabling its data content to be accessed by device P. B The data stream from $ipq:$portq to communication terminal B is directly sent to B: "For a certain data stream, if its destination IP address and TCP port number are $ipb and $portb respectively, and the data stream enters gateway P from network interface ethqg..." B If so, the data stream will be handled by $ipq:$portq.

[0066] Proxy technology five: Transparent proxy technology.

[0067] If the data relay and forwarding of the proxy technology three is applied in a device, the source identifier of the data stream entering the device is not the same as the source identifier of the data stream going out of the device, and such proxy-based anti-quantum security enhancement device is an exclusive communication identifier proxy-based anti-quantum security enhancement device; the data relay and forwarding function similar to that in the proxy technology three can be realized by using transparent proxy technology, and the difference is that the transparent proxy technology supports the device to use the original source identifier and destination identifier of the data stream for data relay and forwarding, and the device using the transparent proxy technology for data relay and forwarding is a shared communication identifier proxy-based anti-quantum security enhancement device; the method of using the transparent proxy technology in the TCP / IP protocol is as follows: the transparent proxy attribute IP_TRANSPARENT is used when creating a SOCKET, and the source address is set to the original source address when constructing a transport layer packet.

[0068] As shown in the network topology diagram, Figure 1 Two complete schemes are given below to meet the requirement that the key negotiation data stream between the communication entities A and B passes through P A and P B , and the data content of the data stream can be obtained by P A and P B , wherein the data stream in the A to B direction passes through A, P A , P B , and B in turn, and the data stream in the B to A direction passes through B, P B , P A , and A in turn.

[0069] Scheme one: when receiving the resolution application of the domain name demo.xxx.edu.cn, the DNS returns the IPv4 address $ipp of the device P A ; the device P A listens to the TCP port $portp at the address $ipp, and it is required that $portp = $portn is established; the data relay and forwarding of the proxy technology three is used in the device P A : all connection establishment requests to $ipp:$portp are accepted, and after the connection is successfully established, a connection is established with $ipqg:$portn and the two connections are paired; for the paired two connections, when the data stream from one of them is received, the data stream is processed and forwarded to the other; when one of the connections is disconnected, the connection with the other is disconnected; the port mapping is set in the device P B , and $ipqg:$portn is mapped to $ipq:$portq; the port mapping is set in the device P BThe data relay and forwarding is performed by using proxy technology: accept all connection establishment requests to $ipq:$portq, and establish a connection with $ipb:$portb after the connection is successfully established, and pair the two connections; for the paired two connections, when a data stream is received from one of them, the data stream is processed and forwarded to the other; when one of the connections is disconnected, the connection with the other is disconnected.

[0070] The device P in scheme one A and P B are both proxy-based anti-quantum security enhancement devices based on exclusive communication identifiers, wherein the device P A is a pure functional independent hardware device, and the device P B is an independent hardware device integrated with gateway functions.

[0071] Scheme two: adding two routing rules in the gateway G A : "for a data stream, if its target IP address and TCP port number are $ipqg and $portn respectively, and the data stream does not enter the gateway G A from the network interface ethpg, then route the data stream to the network device with an IPv4 address of $ipp through the network interface ethpg", "for a data stream, if its source IP address and TCP port number are $ipqg and $portn respectively, and the data stream does not enter the gateway G A from the network interface ethpg, then route the data stream to the network device with an IPv4 address of $ipp through the network interface ethpg". The device P A listens to the TCP port $portp at the address $ipp, and here it is not mandatory to require that $portp=$portn; two routing rules are added in the device P A : "for a data stream, if its target IP address and TCP port number are $ipqg and $portn respectively, and the data stream enters the device P A from the network interface ethp, then hand over the data stream to $ipp:$portp for processing", "for a data stream, if its source IP address and TCP port number are $ipqg and $portn respectively, and the data stream enters the device P A from the network interface ethp, then hand over the data stream to $ipp:$portp for processing"; in the device P ATransparent proxy technology is used for data relay and forwarding: It accepts all connection establishment requests to $ipp:$portp, and after a successful connection establishment, establishes a connection with $ipqg:$portn and pairs the two connections; for the paired connections, when a data stream is received from one, it processes the data stream and forwards it to the other; when one connection is broken, the connection with the other is disconnected; in device P... B Configure port mapping in the configuration file, mapping $ipqg:$portn to $ipb:$portb; in device P... B Add two routing rules: "For a certain data flow, if its destination IP address and TCP port number are $ipb and $portb respectively, and the data flow enters the gateway P from the network interface ethqg." B "If the data stream is indeed connected to the network interface ethq, then the data stream will be handled by $ipq:$portq." "For a data stream, if its source IP address and TCP port number are $ipb and $portb respectively, and the data stream enters the gateway P from the network interface ethq..." B If so, the data stream will be handled by $ipq:$portq; in device P B Transparent proxy is used for data relay and forwarding: it accepts all connection establishment requests to $ipq:$portq, and after a successful connection is established, it establishes a connection with $ipb:$portb and pairs the two connections; for the two paired connections, when a data stream is received from one of them, the data stream is processed and forwarded to the other; when one connection is broken, the connection with the other is broken.

[0072] The device P given in Scheme 2 A and P B Both are proxy-based quantum-secure enhancement devices that share communication identifiers, where device P A It is a purely functional, stand-alone hardware device, device P B It is a standalone hardware device that integrates gateway functionality.

[0073] by Figure 2 Taking the message exchange of the complete TLS 1.3 handshake process as an example, we briefly explain that TLS 1.3 is a secure communication protocol that satisfies conditions 1 to 7: The TLS 1.3 protocol can be divided into four phases. Figure 2 Lines 3-10 correspond to the "plaintext-based key negotiation phase" of the TLS 1.3 protocol; lines 11-19 correspond to the "initial application phase" of the session key in the TLS 1.3 protocol; and line 20 corresponds to the "optional subsequent application phase" of the session key in the TLS 1.3 protocol. In the complete TLS 1.3 handshake process, communication entities A and B only interact once. Figure 2The ClientHello in the 3rd row and the ServerHello in the 8th row, and the ClientHello message contains a limited number of data items, including the protocol version number, the Nonce random number r A of entity A, the cipher suite set, the extension item, etc., the ServerHello message contains the protocol version number, the Nonce random number r B of entity B, the cipher suite selection, the extension item, etc.; the TLS 1.3 calculates the session key ssk by using all the data messages of the ClientHello and the ServerHello; the TLS 1.3 is a connection-oriented and stream data-based security protocol, and the conditions 6 and 7 are satisfied.

[0074] Because the TLS 1.3 calculates the session key ssk by using all the data messages of the ClientHello and the ServerHello, all the data items of the “plain text-based key agreement phase” contribute to the session key, and D A,B may be an arbitrary non-empty subset of the set of all the data items of the “plain text-based key agreement phase”.

[0075] Next, the fixed D A,B ={r B} is used as an example to illustrate the proxy-based quantum-resistant security enhancement method of the application; the PQ-KEM, the PQ-KDF and the PQ-AEAD are used to represent the selected post-quantum key encapsulation mechanism, the key derivation function and the authentication encryption algorithm for quantum-resistant security enhancement. It is noted that r B is the data item of the ServerHello, that is, ServerHello.random, which means that the device P B must have the public key or the private key corresponding to the key encapsulation mechanism before sending the ServerHello to the device P A The device P A and the device P B must have the public key or the private key corresponding to the key encapsulation mechanism before sending the ServerHello to the device P A The public-private key pair must be generated before the device P B sends the ClientHello, and if the public-private key pair is not prepared in advance and distributed to the devices P A and P B , the public-private key pair can only be generated by the device P A before sending the ClientHello to the device P B , and sent together with the ClientHello, so that: the key pair generation function PQ-KEM.KeyPair() of the PQ-KEM needs to be called to obtain the public-private key pair (pk, sk) before the device P A forwards the ClientHello, and pk is sent to the device PB ; in P B After receiving ClientHello and pk, pk needs to be stripped out; P B When forwarding ServerHello, r B Encrypted protection processing is performed; P A After receiving the processed ServerHello message, decryption processing needs to be performed; finally, the Figure 3 work flow shown.

[0076] Next, the work flow of the anti-quantum security enhancement of TLS1.3 shown in Figure 3 is consistent with the execution steps A1-A4 of P A and the execution steps B1-B4 of P B :

[0077] Note that at this time, the "steering the key negotiation data flow between A and B through the proxy technology to pass through P A and P B , and the data content of the data flow can be obtained by P A and P B , wherein the data flow from A to B passes through A, P A , P B , B in turn, and the data flow from B to A passes through B, P B , P A , A in turn" requirement of the present application has been met. Therefore, the execution steps A1-A4 of P A and the execution steps B1-B4 of P B of the method described in the present application can be verified according to the data flow order of TLS1.3 shown in Figure 3 :

[0078] The communication terminal A first sends the ClientHello message to the terminal B; the message flows into the device P A , triggering P A to execute step A1, P A to determine that the data flow belongs to the interaction data of the "clear text-based key negotiation phase" between A and B; to execute step A2 and split to form the data item set D; to enter step A3, because D∩D A,B is an empty set, the current data flow content is unchanged; to execute step A4, to call the key pair generation function PQ-KEM.KeyPair() of PQ-KEM to generate a temporary public and private key pair (pk, sk), at this time the data flow direction is A→B, to send the processed data, i.e., the original data of ClientHello, together with the anti-quantum enhancement auxiliary data pk to P B ; the device P A enters step A1 to wait for new data to flow into PA ; ClientHello along with pk message flows into device P B , triggers step B1 to be executed; judges that the data stream is the interactive data of the "plain-text-based key agreement phase", step B2 is executed; obtains the data item set D, step B3 is executed; since no data modification item is contained in D, step B4 is executed; the data stream direction is A→B, the ClientHello is sent to B after the anti-quantum auxiliary data pk is stripped, P B enters step B1 to wait for new data to flow into P B ; after B receives the ClientHello, the original protocol of TLS1.3 is executed, that is, the ServerHello message is constructed, the session key is calculated, the session key is used to protect the extension item and the Finish message to obtain {EncryptedExtensions} and {Finished}, and these messages are sent to the terminal A together, and pass through the device P B triggers P B to execute step B1; P B first judges that the ServerHello belongs to the interactive data of the "plain-text-based key agreement phase" between A and B, step B2 is executed; after the data item segmentation of the ServerHello message is performed to obtain D, step B3 is executed; at this time, r B , that is, ServerHello.random, is the only data item in D∩D A,B , and the data stream direction is B→A, r B is authenticated and encrypted: the key material k and the key encapsulation ciphertext ct are obtained by calling the key encapsulation function PQ-KEM.Encaps(pk) of PQ-KEM, the key (key, nonce, ad) is obtained by calling the key expansion function PQ-KDF(k), and the ciphertext dnar and the authentication tag tag are obtained by calling the encryption and authentication function PQ-AEAD.Seal(key, nonce, ad, ServerHello.random) of the authenticated encryption algorithm; ServerHello.random in the ServerHello message is replaced by ct|dnar|tag, that is, the separable data string composed of ct, dnar and tag, the ServerHello message is converted into the replaced HelloServer message, and step B4 is executed; at this time, the data stream direction is B→A, and the HelloServer is sent to P A , step B1 is executed; judges that {EncryptedExtensions} does not belong to the interactive data of the "plain-text-based key agreement phase" between A and B, step B4 is executed; at this time, the data stream direction is B→A, and {EncryptedExtensions} is sent to P A, execute step B1; determine that {Finished} is not the interactive data between A and B in the "plain-text-based key agreement phase", execute step B4; at this time, the data flow direction is B→A, send {Finished} to P A , enter step B1 to wait for new data to flow into P B ; HelloServer and {EncryptedExtensions}, {Finished} flow into device P A , trigger P A to execute step A1; determine that HelloServer is the interactive data between A and B in the "plain-text-based key agreement phase", execute step A2; obtain D and execute step A3; at this time, r B , even if the post-quantum encryption authentication protection ServerHello.random is replaced by ct|dnar|tag, is the only data item in D∩D A,B , and the data flow direction is B→A, decrypt and verify r B using the post-quantum cryptography: call the key decapsulation function PQ-KEM.Decaps(sk, ct) to obtain the key material k; call the key derivation function PQ-KDF(k) to obtain (key, nonce, ad); call the decryption and verification function PQ-AEAD.Open(key, nonce, ad, dnar, tag) of the authentication encryption algorithm to obtain the original random number random, restore r B in HelloServer to obtain the original ServerHello = Replace(HelloServer, ct|dnar|tag, random), execute step A4; because the data flow direction is B→A, and there is no real anti-quantum secure auxiliary data in the ServerHello message, send ServerHello to A, and go to step A1; later P A successively determine that {EncryptedExtensions}, {Finished} are not the interactive data between A and B in the "plain-text-based key agreement phase", send {EncryptedExtensions}, {Finished} to A in step A4, and go to step A1 to wait for new data to flow into P A ; ServerHello and {EncryptedExtensions}, {Finished} enter the communication terminal A, and terminal A constructs and sends the message {Finished} encrypted and protected using the session key to B, triggering device P A to execute step A1; subsequent other messages are not the interactive data between A and B in the "plain-text-based key agreement phase", and device PA and P B Only data is forwarded as is, and in particular along A, P A , P B , B directions{Finished}.

[0079] The above-described embodiments of the present application have been further described in detail, and the purpose, technical means and beneficial effects of the present application have been further explained. It should be understood that the above-described embodiments are only specific embodiments of the present application and are not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A proxy-based method for enhancing quantum security, characterized in that: Based on existing secure communication systems, a pair of agent-based quantum-resistant security enhancement devices P are deployed between communication entities A and B. A and P B , where P A Deployed on test A, P B Deployed at test B; the device here is a hardware or software system, or a combination of both; the key negotiation data stream between A and B is redirected through P via proxy technology. A and P B And the data content of the data stream can be P A and P B The data flow from A to B passes through A, PA, PB, and B in sequence, while the data flow from B to A passes through B, PB, PA, and A in sequence. When the key negotiation data stream from A to B passes through P A At that time, in P A In the process, some or all of the data items in the key negotiation are used for security authentication and / or encryption using post-quantum cryptography; when the key negotiation data stream from A to B passes through P B At that time, in P B The corresponding key-negotiated data items are then securely decrypted and / or verified using post-quantum cryptography. When the key negotiation data stream from B to A passes through P B At that time, in P B In the process, some or all of the data items in the key negotiation are used for security authentication and / or encryption using post-quantum cryptography; when the key negotiation data stream from B to A passes through P... A At that time, in P A The corresponding key-negotiated data items are then securely decrypted and / or verified using post-quantum cryptography. Through the above process, a black-box, seamless, and low-cost quantum-resistant security enhancement function is achieved between existing secure communication entities; The existing secure communication system satisfies the following conditions 1 to 7: Condition 1: The data communication process of a secure communication system is divided into four stages: plaintext-based key negotiation, session key acquisition, initial session key application, and optional subsequent session key application. Condition 2: During the plaintext-based key negotiation phase, communication entities A and B will engage in several rounds of data communication; without loss of generality, assume that A transmits n plaintext messages to B during this phase. A The data items are as follows: B transmitted n in plaintext to A. B The data items are as follows: Condition 3: During the session key acquisition phase, communication entities A and B first determine the key derivation function (KDF) based on their respective "currently owned data items" information. Here, "currently owned data items" includes the default setting data items, the interactive data items from the "plaintext-based key negotiation phase," and the data items obtained after polynomial time complexity calculation based on the "currently owned data items." Then, using their respective currently owned KDF input data items, which are a subset of the "currently owned data items," as input to the KDF, they calculate the KDF function value locally and use this function value as the session key (ssk). Without loss of generality, assume that A has m... A The KDF input data items are as follows: The corresponding KDF function value is ssk A =ssk; while B has m B The KDF input data items are as follows: The corresponding KDF function value is ssk B =ssk; Here, the session key ssk may be divided into different parts according to functional needs, including the symmetric encryption key from A to B, and the symmetric authentication key from B to A; Condition 4: In the initial application phase of the session key, communication entities A and B first determine the authentication encryption algorithm AEAD based on their respective "currently owned data items" information, and then use the session key ssk obtained in the "session key acquisition phase" to encrypt and authenticate the data to be transmitted after the "plaintext-based key negotiation phase" ends. Condition 5: In the optional subsequent application phase of the session key, communication entities A and B can conduct key negotiation based on ciphertext, switch session keys, and apply the new session key to encrypt and authenticate the subsequent data to be transmitted under their encryption and authentication protection transmission mechanism in the current key application phase, i.e., the initial application phase of the session key or the subsequent application phase of the session key. Condition 6: If the interaction data of the "plaintext-based key negotiation phase" between communication entities A and B is concatenated with the interaction data of other phases, namely the initial application phase of the session key and the optional subsequent application phase of the session key, in the original relative order, then there exists a method with polynomial time complexity to identify and separate the interaction data of the two phases, namely the interaction data of the "plaintext-based key negotiation phase" and the interaction data of other phases. Condition 7: If the interactive data of the "plaintext-based key negotiation phase" between communication entities A and B are concatenated in their original relative order, then there exists a method with polynomial time complexity to identify and segment each data item.

2. The quantum security enhancement method according to claim 1, characterized in that: The post-quantum cryptography mentioned refers to public-key cryptosystems that can resist attacks from both classical and quantum computing, including lattice-based, cryptographic hash function-based, encoding-based, multivariate-based, homologous key encapsulation mechanisms, public-key encryption, digital signatures, and key negotiation algorithms. The "P" mentioned A Deployed on test A, P B "Deployed on B test" means that the key negotiation data stream from A to B must first pass through P. A Then reach P B Finally, the data stream reaching B, and the key negotiation data stream from B to A, first passes through P. B Then reach P A Finally, it reaches A; the non-key-negotiation data stream from A to B does not pass through P. A and / or P B or through P A and / or P B The non-key-negotiated data stream from B to A does not pass through P. B and / or P A Or through P B and / or P A In actual deployment, P A The deployment location of A includes being on the same physical device, in the same virtual machine, behind the same gateway, or P. A It is A's default gateway; P B The deployment location of B includes being on the same physical device, in the same virtual machine, behind the same gateway, or P. B It is B's default gateway; The phrase "directing the key negotiation data stream between A and B through P using proxy technology" is also mentioned. A and P B The term "proxy technology" in this context refers to all data flow guidance technologies that meet the following conditions: the key negotiation data flow from A to B passes through A, P in sequence. A ,P B B, and the key negotiation data stream from B to A passes through B, P in sequence. B P A A; The "security authentication and / or encryption" mentioned above may only provide encryption functionality without authentication functionality, or may provide both encryption and authentication functionality simultaneously. The "secure decryption and / or verification" mentioned above may only provide decryption functionality without verification functionality, or may provide both decryption and verification functionality simultaneously. The aforementioned "using post-quantum cryptography for secure authentication and / or encryption" and "using post-quantum cryptography for secure decryption and / or verification" require P A P B To complete the two-way secure authentication encryption and decryption verification function between A and B, P is not required. A and / or P B It also has the capability of post-quantum key encapsulation and decapsulation.

3. The quantum security enhancement method according to claim 2, characterized in that: If, during the execution of a secure communication protocol, there are two data items d and u that appear sequentially, then "u is unrelated to d" or "d contributes nothing to u". If modifying only the value of d can ensure that the protocol still follows the original execution path until u appears and the value of u remains unchanged, then "u is related to d" or "d contributes to u". For integers i and j satisfying i ≤ j, let [i, j] be the set of all integers x satisfying i ≤ x ≤ j; let... Let D be the set of all KDF input data items in the session key acquisition phase; A→B ={d i,A→B There exist u∈U and i∈[1, n] A ] Make u is d i,A→B The relevant set is the set of all data items that contribute to the session key ssk, transmitted in plaintext from A to B during the "plaintext-based key negotiation phase"; let D be the set of data items that contribute to the session key ssk. B→A ={d i,B→A There exist u∈U and i∈[1, n] B ] Make u is d i,B→A The relevant set is the set of all data items that contribute to the session key ssk, transmitted in plaintext from B to A during the "plaintext-based key negotiation phase"; denoted as Let D be a non-empty subset of the set of all data items that contribute to the session key ssk and transmitted in plaintext between A and B during the "plaintext-based key negotiation phase". A,B The parameters can be given in the form of system configuration parameters; post-quantum cryptography used for quantum security enhancement can be given in the form of system configuration parameters; P A The execution steps include: Step A1: Listen for incoming P A The communication data stream is used to determine whether it belongs to the "plaintext-based key negotiation phase" interaction data between A and B. If it does, proceed to step A2; otherwise, proceed to step A4. Step A2: Identify and segment all data items contained in the data stream, and denote the set of segmented data items as D, then proceed to step A3; if not segmented, then D contains all the interactive data items between A and B in the "plaintext-based key negotiation phase", then proceed directly to step A3. Step A3: For each data item d∈D in D, perform the following processing: If If the data stream direction is A→B, then the content of the corresponding data item d in the data stream remains unchanged or is authenticated and / or encrypted using post-quantum cryptography; otherwise, if the data stream direction is A→B, then the content of data item d is authenticated and encrypted using post-quantum cryptography; otherwise, the content of data item d is decrypted and verified using post-quantum cryptography; after all data items in D have been processed, proceed to step A4. Step A4: Perform the necessary local operations required for quantum security enhancement; if the data flow direction is B→A, remove the actual quantum security enhancement auxiliary data from the data flow, then send the removed data to A, and proceed to step A1; otherwise, merge the data flow with the necessary quantum security enhancement auxiliary data and send it to P. B Then proceed to step A1; P B The execution steps include: Step B1: Listen for incoming P B The communication data stream is determined to determine whether it belongs to the "plaintext-based key negotiation phase" interaction data between A and B. If it does, proceed to step B2; otherwise, proceed to step B4. Step B2: Identify and segment all data items contained in the data stream, and denote the set of segmented data items as D, then proceed to step B3; if not segmented, then D contains all the interactive data items between A and B in the "plaintext-based key negotiation phase", then proceed directly to step B3. Step B3: For each data item d∈D in D, perform the following processing: If If the data flow direction is B→A, then the content of the corresponding data item d in the data stream remains unchanged or is encrypted and / or authenticated using post-quantum cryptography; otherwise, if the data flow direction is B→A, then the content of data item d is authenticated and encrypted using post-quantum cryptography; otherwise, the content of data item d is decrypted and verified using post-quantum cryptography; after all data items in D have been processed, proceed to step B4. Step B4: Perform the necessary local operations required for quantum security enhancement; if the data flow direction is A→B, remove the actual quantum security enhancement auxiliary data from the data flow, then send the removed data to B, and proceed to step B1; otherwise, merge the data flow with the necessary quantum security enhancement auxiliary data and send it to P. A Then proceed to step B1.

4. The quantum security enhancement method according to claim 3, characterized in that: The "necessary local operations required for quantum security enhancement" and "necessary auxiliary data for quantum security enhancement" are related to the following requirements: In steps A3 and B3, "authentication encryption using post-quantum cryptography" and "decryption verification using post-quantum cryptography" require the corresponding devices to have sufficient capabilities to be successfully completed. These capabilities include possessing public key information, private key information, ciphertext information, and symmetric key information. These capabilities are obtained by completing the "necessary local operations required for quantum security enhancement" and "merging and sending the data stream along with the necessary auxiliary data for quantum security enhancement" before a specific stage. In steps A4 and B4 of a certain stage, if not performing a certain local operation will not cause subsequent stages A3 or B3 to fail due to insufficient capabilities, then that operation is not necessary in the current stage and can be postponed. If, in steps A4 and B4 of a certain stage, the operation of "sending the data stream along with the necessary quantum security enhancement auxiliary data" is not performed, but instead replaced with the operation of "sending the data stream", and the subsequent steps A3 or B3 do not fail due to insufficient capacity, then the quantum security enhancement auxiliary data is not necessary in the current stage, and can be postponed for merging and sending.

5. The quantum security enhancement method according to claim 2, characterized in that, The key negotiation data stream used to achieve "from A to B" passes through A, P in sequence. A P B B, and the key negotiation data stream from B to A passes through B, P in sequence. B P A The "proxy techniques" of target A include: Proxy technology 1: Set the device as the sole entry and exit point for data communication between communication entities to ensure that all data flows between communication entities pass through the device; in particular, if two communication entities are in different networks, for one or both communication entities, their corresponding proxy-based quantum security enhancement device is used as the default and sole gateway for communication between the communication entity and the external network. Proxy Technology 2: Domain Name Resolution Guidance; Assuming the peer communication entity and / or its corresponding device have a domain name, the local communication entity obtains the peer's IP address through a domain name resolution service. Through domain name guidance, the IP address corresponding to the peer's domain name is resolved to the IP address of the local quantum-safety enhancement device, thus guiding the data flow between the local and peer communication entities to the local quantum-safety enhancement device. Furthermore, by performing port listening on the local quantum-safety enhancement device, and when the listening port number is the same as the port number used by the peer to provide services to the internet, the local quantum-safety enhancement device can obtain all data flows from the local communication entity to the peer communication entity. Proxy Technology 3: Data Relay and Forwarding; Assuming that the data content of a data stream sent from a communication terminal to the other end can be obtained by the device corresponding to the terminal, the device changes the source identifier of the corresponding data stream to its own source identifier and then sends the data stream to the device at the other end. The device at the other end then sends the data stream to the communication entity at the other end, thereby realizing the function of a unidirectional data stream flowing sequentially through the local communication entity, the local device, the device at the other end, and the communication entity at the other end; at this time, the device at the other end only completes the guidance of the data stream, and may not necessarily be able to obtain the data of the data stream; Proxy Technology 4: Routing Rule Configuration; In a specific network topology, the direction of data flow can be changed through routing rule configuration to meet the data flow sequence requirements of this invention, that is, "the data flow from A to B passes through A, P in sequence". A P B B, and the data flow from B to A passes through B and P in sequence. B P A In addition, with the help of routing rule configuration, the problem of data flow passing through a device but the device failing to obtain the data flow content can be solved: listen to a certain transport layer port in the device and use routing configuration rules to make the data flow enter the transport layer port. Proxy Technology 5: Transparent Proxy; This technology uses transparent proxy to achieve data relay and forwarding functions similar to those in Proxy Technology 3.

6. The quantum security enhancement method according to claim 5, characterized in that, Proxy technologies applicable to network topology graphs include: Option 1: When a DNS resolution request for the domain name demo.xxx.edu.cn is received, the DNS return device P... A IPv4 address $ipp; device P A Listen on TCP port $portp at address $ipp, which requires $portp = $portn to hold true; on device P A The system uses proxy technology 3 for data relay and forwarding: it accepts all connection establishment requests to $ipp:$portp, and after a successful connection establishment, establishes a connection with $ipqg:$portn and pairs the two connections; for the paired connections, when a data stream is received from one of them, it processes the data stream and forwards it to the other; when one connection is broken, the connection with the other is broken; in device P... B Configure port mapping in the settings, mapping $ipqg:$portn to $ipq:$portq; on device P... B The system uses proxy technology 3 for data relay and forwarding: it accepts all connection establishment requests to $ipq:$portq, and after a successful connection is established, it establishes a connection with $ipb:$portb and pairs the two connections; for the two paired connections, when a data stream is received from one of them, the data stream is processed and forwarded to the other; when one connection is broken, the connection with the other is broken. Option 2: At gateway G A Add two routing rules: "For a certain data flow, if its destination IP address and TCP port number are $ipqg and $portn respectively, and the data flow does not enter the gateway G from the network interface ethpg." A "Then the data stream will be routed through the network interface ethpg to the network device with IPv4 address $ipp". "For a data stream, if its source IP address and TCP port number are $ipqg and $portn respectively, and the data stream does not enter gateway G from the network interface ethpg..." A Then the data stream will be routed through the network interface ethpg to the network device with IPv4 address $ipp; device P A Listen on TCP port $portp at address $ipp; it is not mandatory for $portp = $portn to be true. On device P... A Add two routing rules: "For a certain data stream, if its destination IP address and TCP port number are $ipqg and $portn respectively, and the data stream enters device P from the network interface ethp..." A "Then the data stream will be processed by $ipp:$portp". "For a data stream, if its source IP address and TCP port number are $ipqg and $portn respectively, and the data stream enters device P from the network interface ethp..." A Then the data stream will be handed over to $ipp:$portp for processing; in device P A Transparent proxy technology is used for data relay and forwarding: It accepts all connection establishment requests to $ipp:$portp, and after a successful connection establishment, establishes a connection with $ipqg:$portn and pairs the two connections; for the paired connections, when a data stream is received from one, it processes the data stream and forwards it to the other; when one connection is broken, the connection with the other is disconnected; in device P... B Configure port mapping in the configuration file, mapping $ipqg:$portn to $ipb:$portb; in device P... B Add two routing rules: "For a certain data flow, if its destination IP address and TCP port number are $ipb and $portb respectively, and the data flow enters the gateway P from the network interface ethqg." B "If the data stream is indeed connected to the network interface ethq, then the data stream will be handled by $ipq:$portq". "For a given data stream, if its source IP address and TCP port number are $ipb and $portb respectively, and the data stream enters the gateway P from the network interface ethq..." B If so, the data stream will be handled by $ipq:$portq; in device P B Transparent proxy is used for data relay and forwarding: it accepts all connection establishment requests to $ipq:$portq, and after a successful connection is established, it establishes a connection with $ipb:$portb and pairs the two connections; for the two paired connections, when a data stream is received from one of them, the data stream is processed and forwarded to the other; when one connection is broken, the connection with the other is broken. The network topology diagram includes six network entities: communication entities A and B, and device P. A and P B Gateway G A and Domain Name System (DNS); Gateway G A There are 3 network interfaces connecting to 3 networks. Network interface `ethagg` is configured with the IPv4 address `$ipagg` to connect to the internet; network interface `ethag` is configured with the IPv4 address `$ipag` as the default gateway for LAN 1; and network interface `ethpg` is configured with the IPv4 address `$ippg` as the default gateway for LAN 2. The DNS server has one network interface `ethd` configured with the IPv4 address `$ipd` to connect to LAN 1. Entity A has one network interface `etha` configured with the IPv4 address `$ipa` to connect to LAN 1, and Entity A uses DNS as its domain name resolution server. Device P has one network interface `ethp` configured with the IPv4 address `$ipp` to connect to LAN 2. Device P... A Listening on TCP port $portp, device P A The data content of the data stream entering $ipp:$portp can be obtained; device P B There are two network interfaces connecting two network segments. The ethq network interface is configured with the IPv4 address $ipq as the default gateway for LAN 3. The ethqg network interface is configured with the IPv4 address $ipqg and the domain name demo.xxx.edu.cn to connect to the internet. Device P... B The underlying system listens on TCP port $portn and uses port mapping technology to map port $ipqg:$portn to port $portb of entity B within LAN 3. Entity B then provides TLS 1.3 service functionality to the Internet. Additionally, device P... B Listen on TCP port $portq at address $ipq, device P B The data content entering the $ipq:$portq data stream can be obtained; Entity B has one network interface ethb configured with an IPv4 address $ipb connected to LAN 3. Entity B enables TLS 1.3 service by listening on TCP port $portb, supplemented by device P. B The port mapping provides TLS 1.3 service functionality to the Internet.

7. The quantum security enhancement method according to claim 3, characterized in that, Post-quantum cryptography is CPA, CCA, or 1CCA secure; the key encapsulated by the post-quantum key encapsulation mechanism is a subset of the transmitted information, including one-time random noise, or derived from it.

8. A proxy-based quantum security enhancement device, characterized in that: Based on the proxy technology used and the deployment method, proxy-based quantum security enhancement devices are divided into two categories: the first category is proxy-based quantum security enhancement devices that share communication identifiers; The second category is proxy-based quantum security enhancement devices with exclusive communication identifiers. The communication identifier is used to uniquely identify each communication data stream and consists of a source identifier and a destination identifier. In the OSI transport layer protocol, the communication identifier is a quadruple: (source IP address, source port address, destination IP address, destination port address), the source identifier is a binary tuple: (source IP address, source port address), and the destination identifier is a binary tuple: (destination IP address, destination port address). In proxy-based quantum security enhancement devices with shared communication identifiers, the outgoing proxy data and the incoming original data use the same communication identifier. In proxy-based quantum security enhancement devices with exclusive communication identifiers, the outgoing proxy data and the incoming original data use different communication identifiers.

9. The quantum security enhancement device according to claim 8, characterized in that, The aforementioned quantum-resistant security enhancement device has the ability to authenticate, encrypt, and decrypt data streams based on post-quantum cryptography. The proxy-based quantum-resistant security enhancement device exists in various forms, including software modules with network communication functions, pluggable hardware devices, purely functional standalone hardware devices, and standalone hardware devices integrating other network functions, including DNS and gateways. The proxy-based quantum-resistant security enhancement device has proxy forwarding capabilities for data communication, and the proxy forwarding technologies used include HTTP proxy technology, transparent proxy technology, SOCKS proxy technology, eBPF-based proxy technology, and custom proxy technology.