Zero-trust quantum key remote secure injection method and system based on PQC
By integrating identity authentication logic into the post-quantum key encapsulation mechanism and combining it with a zero-trust architecture, and using perturbation seeds to generate perturbation public keys for implicit identity authentication, the computational overhead and resistance to quantum attacks of resource-constrained terminals are solved, realizing a lightweight and efficient quantum key injection process that meets the zero-trust security requirements.
Patent Information
- Application Number
- CN202610466845.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-10
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies suffer from high computational overhead, high storage consumption, communication latency, and insufficient resistance to quantum attacks in resource-constrained IoT terminals. They are unable to achieve lightweight and efficient identity authentication and session key negotiation, and lack continuous verification capabilities under a zero-trust architecture.
By deeply integrating the identity authentication logic into the algebraic structure of the post-quantum key encapsulation mechanism, and combining the continuous verification principle in the zero-trust architecture, the PQC and zero-trust quantum key remote secure injection method are adopted. The perturbation seed is used to generate a perturbation public key for implicit identity authentication, and the fault-tolerant characteristics of the lattice cryptosystem are combined for key encapsulation and decapsulation.
It achieves the internalization and lightweighting of authentication logic, reduces computing power consumption and storage footprint, builds an efficient asymmetric authentication model, has strong resistance to resource exhaustion attacks, deeply fits the zero-trust security architecture, ensures an extremely low failure rate in the encapsulation process, and achieves forward security.
Smart Images

Figure CN122027153A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of quantum communication technology, specifically relating to a method and system for remote secure injection of quantum keys based on PQC and zero trust. Background Technology
[0002] With the rapid development of quantum computing technology, traditional public-key cryptosystems based on large integer factorization or discrete logarithm problems are facing the severe challenge of being quickly cracked. Post-quantum cryptography (PQC), as a key technology to protect future information systems from quantum attacks, has become a research hotspot in the fields of network security and secure communication. In complex application scenarios such as the Internet of Things (IoT) and smart grids, the deep integration of quantum key distribution (QKD) technology with classical communication networks is of great strategic significance for building a highly secure distributed key management system.
[0003] Among these, the Authentication Key Exchange (AKE) protocol, as the core component for establishing a secure communication channel, directly determines the security and reliability of the remote key injection process. For the massive number of resource-constrained IoT terminal devices, achieving lightweight and efficient identity authentication and session key negotiation while ensuring resistance to quantum attacks, and guaranteeing end-to-end security of the key injection process, is a key technological direction that urgently needs to be addressed in the field of quantum-secure communication and zero-trust architecture.
[0004] Existing technologies suffer from several drawbacks: First, explicit authentication methods based on digital signatures exhibit extremely high computational and storage overhead in post-quantum algorithm environments, making it difficult for resource-constrained IoT terminals to handle the performance burden of signature generation and verification. Second, existing lightweight authentication schemes often simply superimpose authentication logic and key exchange processes at the protocol layer, failing to achieve deep integration at the cryptographic primitive level. This results in severely constrained terminals still facing significant power consumption and latency challenges when performing independent key encapsulation operations. Third, existing systems lack inherent resistance to resource exhaustion attacks. The server must allocate substantial computational resources to process encapsulation requests before completing identity verification, making it highly susceptible to denial-of-service attacks and system crashes. Finally, traditional authentication mechanisms rely heavily on static trust credentials, lacking the ability to continuously verify terminal identity and computation processes. This makes it difficult to meet the security principle of never trusting and always verifying under a zero-trust architecture. These issues collectively lead to efficiency bottlenecks and security vulnerabilities in the quantum key remote injection process. Therefore, developing a remote secure injection scheme that can achieve endogenous authentication logic, possess quantum attack resistance, and adapt to resource-constrained scenarios is particularly important. Summary of the Invention
[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a remote secure quantum key injection method and system based on PQC and zero trust. Addressing the problems of computational overhead, storage consumption, and communication latency inherent in traditional digital signature-based post-quantum cryptographic authentication methods in resource-constrained IoT terminals, this invention deeply integrates the identity authentication logic into the algebraic structure of the post-quantum key encapsulation mechanism, achieving endogenization and lightweighting of the authentication process. Furthermore, by combining this with the continuous verification principle of the zero-trust architecture, it improves the attack resistance and operational efficiency of the quantum key injection process.
[0006] To achieve the above objectives, the present invention provides the following technical solution: On one hand, it proposes a remote secure injection method for quantum keys based on PQC and zero trust, the method comprising the following steps: After key injection, a quantum cryptographic signature key pair is generated, and a secret seed is assigned. The secret seed is then bound to the terminal's unique identifier and registered in the identity management database of the key injection server. A basic temporary key pair consisting of a basic temporary public key and a basic temporary private key is generated locally. A perturbation seed is calculated based on the current system timestamp, the secret seed, and the basic temporary public key. The perturbation seed drives a deterministic random number generator to generate a perturbation polynomial. The perturbation function is called to add the perturbation polynomial as a vector addend to the polynomial vector component of the basic temporary public key to generate a perturbation public key that contains an identity feature offset in an algebraic structure. Based on the terminal's unique identifier, the corresponding secret seed is retrieved, and the expected perturbation public key is calculated in combination with a preset time window. Implicit identity authentication is achieved by comparing the received perturbation public key with the expected perturbation public key. After successful authentication, the perturbation public key is used to perform a key encapsulation operation to generate a post-quantum cryptography session key and the corresponding encapsulated ciphertext. Obtain the quantum key and use the post-quantum cryptography session key to symmetrically encrypt the quantum key. At the same time, use your own long-term signature private key to digitally sign the key control information containing the session key feature value, the quantum key ciphertext and the request timestamp. The validity of the digital signature is verified. After the verification is successful, the original, undisturbed basic temporary private key is used to decapsulate the encapsulated ciphertext. The fault tolerance characteristics of the lattice cryptosystem are used to offset the offset introduced by the perturbation public key within the error correction threshold. The post-quantum cryptographic session key is extracted. Finally, the post-quantum cryptographic session key is used to decrypt and obtain the quantum key.
[0007] Preferably, the processing of the secret seed further includes: The secret seed is stored in a hardware security module, trusted execution environment, or physically unclonable function unit inside the terminal device; The secret seed is physically isolated and protected by the hardware security module, the trusted execution environment, or the physically unclonable function unit, ensuring that the secret seed is not visible outside the controlled execution environment. The key injection server associates and maps the secret seed with the terminal's unique identifier in the identity management database, and configures a corresponding seed version number for the secret seed.
[0008] Specifically, the generated secret seed has a predetermined bit length, and the secret seed is stored in the hardware security module, trusted execution environment, or physically unclonable function unit inside the terminal device to achieve physical-level isolation protection of the secret seed.
[0009] Preferably, the process of calculating the perturbation seed includes: Obtain the current system timestamp and discretize it using a preset time step to generate the current time window identifier; Invoke the secure hash algorithm to perform a concatenated hash operation on the secret seed, the time window identifier, and the basic temporary public key; The perturbation seed, which has time-varying and identity-related characteristics, is generated through the cascaded hash operation, wherein the perturbation seed changes dynamically with the change of the time window.
[0010] Preferably, the process of generating the perturbation polynomial includes: The lattice-based post-quantum cryptography algorithm specification uses the perturbation seed to initialize a predetermined deterministic random number generator; Coefficients conforming to a preset distribution are extracted from the deterministic random number generator, wherein the preset distribution is a central binomial distribution; Based on the extracted coefficients, a small-norm polynomial is constructed, which is comparable in magnitude to the intrinsic noise of the post-quantum cryptography algorithm in terms of norm size, and serves as the perturbation polynomial. When performing the accumulation operation, the perturbation function maintains the dimension and algebraic field properties of the perturbation public key consistent with those of the base temporary public key, introducing only a controlled algebraic offset in the coefficient distribution. Specifically, when applied to a lattice-based key encapsulation mechanism algorithm, the perturbation function acts as a vector addend, accumulating the perturbation polynomial as a vector addend to the polynomial vector components in the base temporary public key to generate the perturbation public key; this process does not change the dimension and algebraic field properties of the public key, only introducing a controlled offset in the coefficient distribution.
[0011] Preferably, the process of generating the post-quantum cryptographic session key and its corresponding encapsulated ciphertext includes: The key injection server obtains the current time window and at least one adjacent historical time window to compensate for time asynchrony caused by network transmission delay. For each time window obtained, the key injection server calculates the corresponding expected perturbation public key by combining the retrieved secret seed with the basic temporary public key; The received perturbation public key is compared with each of the expected perturbation public keys; When the received perturbation public key matches any of the expected perturbation public keys, the authentication is deemed successful.
[0012] Preferably, after successful authentication, a replay attack prevention check step is also included: the key injection server queries the cache database to check whether the feature value of the currently received perturbation public key has been processed within a preset historical time threshold; if a record exists, it is determined to be a replay attack; if not, the feature value is stored in the cache and an expiration time is set.
[0013] Preferably, the key encapsulation operation is a cryptographic operation triggered only after the client's identity is verified; the key injection server uses the perturbation public key as an encryption parameter, generates a session key by executing the key encapsulation function, and encapsulates it in ciphertext constructed for the perturbation public key.
[0014] Preferably, the communication between the key injection server and the quantum key distribution device is achieved through an internal trusted bus or a secure channel with two-way authentication, ensuring the confidentiality of the quantum key during the transfer process.
[0015] Preferably, the decapsulation operation performed by the terminal security agent utilizes the fault-tolerance characteristics of the lattice cryptosystem; since the difference between the perturbation public key and the basic temporary public key is constrained within the error correction threshold, the basic temporary private key can recover the same session key from the ciphertext generated based on the perturbation public key.
[0016] In addition, the secret seed has an online secure rotation mechanism: the key injection server can generate a new secret seed, encrypt it together with the quantum key, and send it to the terminal security agent; after successfully decrypting, the terminal security agent replaces the old seed stored locally with the new secret seed according to the update instruction sent along with it.
[0017] Furthermore, when the perturbation function processes lattice-based polynomial operations, the norm of the coefficients of the perturbation polynomial introduced is restricted to ensure that the norm of the total noise term is less than the error correction threshold of the post-quantum cryptography algorithm with a predetermined probability; by employing a distribution function related to the algorithm's intrinsic noise, the decapsulation failure rate is ensured to remain at a preset extremely low level.
[0018] Furthermore, the key injection server employs an asynchronous processing architecture when processing injection requests, decoupling the front-end identity comparison and filtering from the back-end key encapsulation and computation. During the identity comparison phase, by performing low-overhead computation and public key comparison, the processing cost of a single illegal request is controlled within a preset time threshold, thereby building the ability to defend against denial-of-service attacks.
[0019] On another front, a quantum key remote secure injection system based on PQC and zero trust is proposed, employing the aforementioned method. The system includes: A Key Injection Server (KME) is deployed in the same security domain as the receiver in the quantum key distribution device. The KME acts as an authorized agent for the receiver, performing server-side functions. The KME is responsible for retrieving quantum keys from the receiver's key pool and maintaining an identity management database that stores the secret seeds of all remote terminal identities. The KME is configured to execute a post-quantum cryptographic implicit authentication protocol and inject the quantum key into the target terminal through an established secure channel. The endpoint security agent (TSA) runs in a controlled execution environment on a remote terminal device, acting as a client of the system. The endpoint security agent is pre-loaded with the identity public key of the key injection server and the unique secret seed of the terminal. The endpoint security agent is configured to initiate an injection request and cooperate with the key injection server to complete the implicit authentication and key negotiation process based on the perturbation public key, and to receive and decrypt the injected quantum key. The perturbation function module is configured as a defined algebraic processing unit that receives a base temporary public key and a perturbation polynomial derived from the secret seed as input, and outputs a perturbation public key that is algebraically associated with the base temporary public key but contains an identity feature offset; the perturbation function module ensures that the offset is within the error correction threshold range of the post-quantum cryptography algorithm.
[0020] Preferably, the key injection server adopts an asynchronous processing architecture: The key injection server decouples the front-end identity comparison and filtering logic from the back-end key encapsulation and operation logic. During the identity verification phase, the key injection server pre-authenticates the injection request by performing a low-overhead perturbation public key consistency comparison. The key injection server controls the processing cost of a single illegal request within a preset time threshold and uses the pre-authentication mechanism to filter illegal requests, thereby building the ability to defend against denial-of-service attacks. After the pre-authentication is successful, the key injection server triggers the backend key encapsulation function to perform asymmetric cryptographic operations.
[0021] Preferably, the key injection server is configured to perform replay attack prevention checks: After successful identity authentication, the key injection server checks whether the feature value of the currently received perturbation public key has been processed within a preset historical time threshold by querying the cache database. If the cache database contains a record of the feature value, it is determined to be a replay attack and the injection request is rejected; If the feature value does not exist in the cache database, then the feature value is stored in the cache database and an expiration time is set.
[0022] Preferably, the system is configured to support secure online rotation of secret seeds: The ciphertext, the encrypted quantum key, and the digital signature are packaged into a response packet; when generating the response packet, the key injection server generates a new secret seed and encrypts the new secret seed together with the quantum key using the post-quantum cryptography session key; After successfully decrypting and obtaining the quantum key, the terminal security agent extracts the new secret seed; The terminal security agent, based on the accompanying update instruction, replaces the locally stored old secret seed with the new secret seed and updates the local seed version number. The key injection server synchronously updates the corresponding secret seed record in the identity management database to achieve forward security.
[0023] Preferably, the system is configured to perform zero-trust continuous verification based on geospatial characteristics: When the terminal security agent initiates the injection request, it obtains the current geographic location coordinates of the terminal device and uses the geographic location coordinates as one of the inputs of the cascaded hash operation to generate the perturbation seed containing geospatial characteristics. The terminal security agent generates the perturbation public key containing geospatial feature offsets through the perturbation function; After receiving the injection request, the key injection server uses the received geographic location coordinates to verify whether the terminal device is operating within the authorized area; The key injection server determines that the terminal device meets the zero-trust continuous verification criterion under the dual conditions that the perturbation public key comparison is successful and the geographical location coordinate verification is successful. The key injection server supports batch processing mode, injecting multiple quantum key pairs in a single established secure channel using segmented encryption.
[0024] Compared with the prior art, the advantages and positive effects of the present invention are as follows: 1. Achieved endogenous and lightweight authentication logic: This invention integrates the authentication process with the key exchange process by modifying the algebraic structure of the quantum cryptographic public key. On the resource-constrained client side, authentication overhead is significantly reduced, decreasing computational power consumption and storage footprint.
[0025] 2. An efficient asymmetric authentication model was constructed: This scheme adopts a combination of implicit authentication from the client to the server and explicit signature authentication from the server to the client, which optimizes the communication efficiency of the uplink and reduces the data packet length.
[0026] 3. Possesses strong resistance to resource exhaustion attacks: By introducing a pre-authentication mechanism before performing post-quantum cryptographic encapsulation operations, the server can filter out illegal requests with low computational cost, ensuring system stability.
[0027] 4. Deeply aligned with zero-trust security architecture: This invention relies on the self-consistency of cryptographic computations in each round of the session to achieve the core principle of continuous verification of zero trust, thereby improving the security of quantum key injection.
[0028] 5. Guaranteed extremely high decryption accuracy and security: By constraining the norm of the perturbation polynomial, the failure rate of the decryption and encapsulation process is kept at an extremely low level, and forward security is achieved by combining the secret seed rotation mechanism. Attached Figure Description
[0029] Figure 1 This is a schematic diagram of the overall technical architecture of the quantum key remote secure injection method based on PQC and zero trust proposed in this invention.
[0030] Figure 2 This is a schematic diagram of the core principle framework of the quantum key remote secure injection system based on PQC and zero trust in this invention.
[0031] Figure 3 This is a schematic diagram of the asymmetric system architecture in the scenario of quantum key distribution and remote key injection in the power system distribution network automation terminal of the present invention.
[0032] Figure 4 This is the core flowchart of the quantum key remote secure injection method based on PQC and zero trust in this invention. Detailed Implementation
[0033] Example 1, see Figure 3This embodiment uses quantum key security injection into power system distribution network automation terminals as an application scenario. In the distribution network, distribution automation terminals distributed across various lines need to periodically acquire high-strength quantum keys to ensure encrypted transmission of telemetry, telesignaling, and remote control data. Due to the complex deployment environment of distribution terminals and the limitation of hardware resources—constrained by low-power processors and limited storage space—traditional, cumbersome post-quantum digital signature authentication systems cannot be supported. This embodiment achieves lightweight remote injection by injecting identity-related perturbations into the public key of the post-quantum cryptographic algorithm.
[0034] This embodiment provides a remote secure quantum key injection system based on post-quantum cryptography and zero trust. The system consists of a key injection server, a terminal security agent, and a perturbation function module. The key injection server is deployed in the secure access area of the power distribution station and connected to the receiver of the quantum key distribution device via a dedicated fiber optic network. The key injection server integrates an identity management database that stores the unique identifiers and corresponding secret seeds of 3000 power distribution terminals across the network. The key injection server adopts an asynchronous processing architecture; its front-end communication interface receives injection requests from terminals, while the back-end processing logic performs identity verification and key encapsulation.
[0035] The terminal security agent runs within the embedded operating system of the power distribution terminal and is configured as a client of the system. The terminal security agent internally stores a long-term identity public key for the key injection server and uses a hardware security module to store the terminal's unique 32-byte secret seed. The perturbation function module is configured as a deterministic algebraic processing unit; its core logic is to transform identity features into algebraic offsets within a lattice-based cryptosystem. This module receives the basic temporary public key and a perturbation polynomial derived from the secret seed, outputting a perturbation public key containing the identity features. The perturbation function module ensures that the offset is within the error correction threshold range of the post-quantum cryptography algorithm by constraining the norm of the perturbation polynomial's coefficients.
[0036] See Figure 1 and Figure 4 This embodiment provides a quantum key remote secure injection method based on post-quantum cryptography and zero trust, and the specific execution steps are as follows: Step S110, Initialization Phase: In an offline environment, a high-entropy random number generator is used to generate a long-term post-quantum cryptographic signature key pair for the key injection server. A lattice-based digital signature algorithm is selected, with the private key stored in the physical encryption machine by the key injection server, and the public key distributed to all terminals. For each power distribution terminal, the system assigns a unique secret seed with a 256-bit entropy value. This secret seed is bound to the terminal's hardware serial number and registered in the key injection server's identity management database. Before the terminal leaves the factory, the secret seed is stored in the terminal's internal hardware security module via a secure programming interface, achieving physical-level isolation protection.
[0037] Step S120, Terminal Injection Request Phase: When the terminal security agent needs to update the quantum key, it first calls the hardware random number generator to generate a pair of basic temporary keys. This key pair is generated based on the post-quantum cryptography key encapsulation mechanism and includes a basic temporary public key and a basic temporary private key. Subsequently, the terminal security agent obtains the current system's 64-bit timestamp and discretizes it using a 60-second time step to generate the current time window identifier. The terminal security agent calls a secure hash algorithm to perform a concatenated hash operation on the secret seed, time window identifier, and basic temporary public key to generate a 32-byte perturbation seed with time-varying and identity-associated characteristics.
[0038] The terminal security agent uses this perturbation seed to drive a deterministic random number generator to produce a perturbation polynomial. This process strictly follows the specifications of lattice-based post-quantum cryptography algorithms, extracting coefficients conforming to a central binomial distribution from the generator to construct a small-norm polynomial whose norm is comparable to the magnitude of the algorithm's intrinsic noise. The perturbation function uses this perturbation polynomial as a vector addend, accumulating it onto the polynomial vector components of the underlying temporary public key to generate the perturbation public key. The calculation process is as follows:
[0039] in, Represents the underlying temporary public key, Let represent the perturbation public key, Δ represent the perturbation polynomial, and q represent the modulus of the algebraic field. The generated perturbation public key does not change the dimension or algebraic field properties of the original public key. Finally, the endpoint security agent encapsulates the endpoint unique identifier, the basic temporary public key, and the perturbation public key into a request packet and sends it to the key injection server.
[0040] Step S130, Server-side Implicit Authentication and Session Key Establishment Phase: After receiving the request packet, the key injection server extracts the terminal's unique identifier and retrieves the corresponding secret seed from the identity management database. To compensate for time asynchrony caused by network transmission, the key injection server obtains the current time window and one adjacent historical time window. For each time window, the key injection server, combining the retrieved secret seed and the basic temporary public key in the request packet, repeats the hash operation and random number generation process on the terminal side to calculate the expected perturbation public key.
[0041] The key injection server performs implicit authentication by comparing the received perturbation public key with the expected perturbation public key. If the received perturbation public key matches any expected value exactly, the terminal's identity is deemed legitimate. After successful authentication, the key injection server performs a replay attack prevention check by querying the cache database to confirm that the characteristic value of the perturbation public key has not been processed in the past 300 seconds. If no duplicate record is found, the characteristic value is stored in the cache and an expiration time is set.
[0042] After verifying the client's identity, the key injection server invokes the key encapsulation function. This operation uses the perturbation public key as an encryption parameter to generate a 256-bit post-quantum cryptography session key and a corresponding encapsulated ciphertext. This encapsulated ciphertext is constructed against the perturbation public key and can only be decrypted by the entity holding the corresponding private key. Because the server has completed pre-authentication through low-overhead public key comparison before performing the expensive key encapsulation operation, the system possesses the ability to defend against malicious denial-of-service attacks.
[0043] Step S140, Quantum Key Secure Injection Stage: The key injection server securely retrieves a 128-bit quantum key from the collaboratively deployed quantum key distribution device via an internal trusted bus interface. Using the post-quantum cryptography session key generated in step S130, the key injection server encrypts the quantum key using a symmetric encryption algorithm to generate quantum key ciphertext. Simultaneously, the key injection server uses its long-term signing private key to digitally sign critical control information, including the session key feature value, the quantum key ciphertext, and the request timestamp.
[0044] The key injection server encapsulates the ciphertext, quantum key ciphertext, and digital signature into a response packet. This response packet is sent back to the terminal security agent via a public network. During transmission, the security of the quantum key is guaranteed by symmetric encryption provided by the post-quantum cryptographic session key, while the integrity and authenticity of the message are guaranteed by the digital signature.
[0045] Step S150, Terminal Decryption and Acquisition Stage: After receiving the response packet, the terminal security agent first verifies the legality of the digital signature using the pre-set key injection server public key. Upon successful verification, the terminal security agent invokes the decapsulation operation. Since the difference between the perturbation public key and the underlying temporary public key is constrained within the algorithm's error correction threshold, the terminal security agent can recover the same post-quantum cryptographic session key from the encapsulated ciphertext using the original, unperturbed underlying temporary private key. Noise processing during decapsulation follows this logic: m rec = c2- s T c1 (mod q) Here, c1 and c2 are the ciphertext components, and s is the basic temporary private key. Since the perturbation term is treated as additional noise, decryption correctness can be ensured as long as the total noise norm is less than q / 4. Finally, the endpoint security agent uses the recovered session key to decrypt the quantum key ciphertext, obtains the quantum key, and stores it in a controlled execution environment.
[0046] Example 2 uses a quantum-safe video surveillance system in a mobile edge computing environment as an application scenario. In the mobile edge computing scenario, a large number of mobile monitoring terminals need to access the quantum-safe management platform via a 5G network. Since mobile terminals are prone to network fluctuations and time synchronization deviations during cross-base station handover, this example, based on Example 1, introduces a dynamic perturbation mechanism based on challenge values and an online secret seed rotation mechanism to enhance the system's robustness and forward security.
[0047] The system architecture of this embodiment includes a key injection server, a terminal security agent, and a physically unclonable function unit deployed inside the mobile terminal. The key injection server is configured to support a high-concurrency asynchronous processing mode. Its identity management database, in addition to recording the initial secret seed for each terminal, also maintains a state machine to track the seed version number of each terminal. The terminal security agent runs in the restricted execution environment of the mobile terminal and is responsible for managing communication with the base station and local key storage.
[0048] This embodiment provides a quantum key remote secure injection method based on post-quantum cryptography and zero trust, and the specific execution steps are as follows: Step S110, Initialization Phase: In a controlled offline environment, a lattice-based signature key pair is generated for the key injection server. For each mobile monitoring terminal, a unique physical characteristic value is generated using the terminal's internal physically non-cloning function unit. This characteristic value is hashed and used as the initial secret seed. The key injection server binds and stores this seed with the terminal's International Mobile Equipment Identity (IMEI). The terminal stores the secret seed in an encrypted storage area within the controlled execution environment, ensuring that even if the operating system is compromised, attackers cannot directly read the seed content.
[0049] Step S120, Terminal Initiates Injection Request Stage: Before initiating the request, the terminal security agent first sends a synchronization request to the key injection server to obtain a 64-bit random challenge value generated by the server. This challenge value is used to replace the timestamp in Embodiment 1 to solve the time synchronization problem in the mobile network. After generating a basic temporary key pair consisting of a basic temporary public key and a basic temporary private key, the terminal security agent concatenates the secret seed, the random challenge value, and the basic temporary public key using a hash function to calculate the dynamic perturbation seed.
[0050] The endpoint security agent initializes a deterministic random number generator using a dynamic perturbation seed, generating a perturbation polynomial with a specific distribution. The norm of the polynomial's coefficients is strictly limited to within 2 to minimize its impact on decapsulation accuracy. A perturbation function injects this polynomial into the base temporary public key, generating a perturbation public key containing characteristics of the current session. The endpoint then sends the identification code, challenge value, base temporary public key, and perturbation public key to the server.
[0051] Step S130, Server-side Implicit Authentication and Session Key Establishment Phase: After receiving the request, the key injection server verifies the validity of the challenge value. If the challenge value is valid and unused, the server retrieves the secret seed of the corresponding terminal. Using this seed and information from the request packet, the server reconstructs the expected perturbation public key. By comparing the received value with the expected value, the server completes the authentication of the terminal without performing any asymmetric decryption operations.
[0052] After successful authentication, the server uses the perturbation public key to perform the key encapsulation process. In this embodiment, the server adopts a batch processing mode, preparing three sets of quantum keys for the terminal. The session key generated by the server is used not only to encrypt the quantum key for the current round but also to protect the secret seed used in the next round. The server calculates the session key and encapsulated ciphertext in memory, ensuring that no plaintext leakage occurs during the calculation process.
[0053] Step S140, Quantum Key Security Injection Stage: The key injection server retrieves three sets of quantum keys from the quantum key distribution device. Simultaneously, the server generates a new 256-bit random number as a new secret seed. The server uses the post-quantum cryptographic session key to concatenately encrypt the three sets of quantum keys and the new secret seed. Subsequently, the server uses the signing private key to sign the encrypted data packet and the current logical sequence number.
[0054] The response packet contains encapsulated ciphertext, encrypted mixed data, and a signature. The server sends the response packet to the mobile terminal via the 5G core network. In this step, multiple sets of keys are injected and identity credentials are updated through the establishment of a single secure channel, significantly improving communication efficiency and reducing the frequency of the terminal's radio frequency module activation.
[0055] Step S150, Terminal Decryption and Acquisition Stage: After the terminal security agent verifies the signature, it performs decapsulation using the basic temporary private key. Because the offset introduced by the perturbation function is extremely small, the terminal can recover the session key with nearly 100% probability. The terminal uses the session key to decrypt and obtain three sets of quantum keys, storing them in the key pool. Subsequently, the terminal extracts a new secret seed and overwrites the locally stored old seed. This secret seed rotation mechanism ensures that even if the current secret seed is leaked, attackers cannot deduce previous communication content, thus achieving robust forward security.
[0056] Example 3 uses a large-scale secure communication network spanning multiple regions as its application scenario. This network contains multiple levels of management nodes, and quantum keys need to be remotely and securely injected between the headquarters center and terminals in various branches. Due to the large network span, multiple gateway levels, and complex routing strategies, this example, based on Example 1, focuses on optimizing the zero-trust verification logic and batch processing architecture of the injection process to ensure highly reliable key distribution even in an untrusted network environment.
[0057] The system in this embodiment includes a central key injection server deployed at headquarters, edge key proxies deployed in various branch offices, and ultimately, remote terminals. The central key injection server, as the root source of identity authentication, is responsible for maintaining the identity profiles of all terminals across the network. The edge key proxies are only responsible for packet pass-through and traffic cleaning, and do not access any decryption keys. The remote terminals integrate an enhanced terminal security proxy that supports adaptive switching between various post-quantum cryptography algorithms.
[0058] This embodiment provides a quantum key remote secure injection method based on post-quantum cryptography and zero trust, and the specific execution steps are as follows: Step S110, Initialization Phase: The central key injection server generates multiple sets of post-quantum cryptographic parameter sets with different security levels. For high-security terminals, a secret seed with a 512-bit entropy value is assigned. All initialization data is distributed to terminals in each branch office via offline USB flash drive or dedicated quantum encryption link. Each terminal's secret seed incorporates geographical location constraint information during generation; that is, the seed contains the encoding of the terminal's predetermined deployment area.
[0059] Step S120, Terminal Initiates Injection Request Phase: The terminal security agent automatically selects appropriate post-quantum cryptography algorithm parameters based on the current network environment. After generating a basic temporary key pair consisting of a basic temporary public key and a basic temporary private key, the terminal obtains its own geographical location coordinates and uses them, along with the secret seed, the current time window, and the basic temporary public key, as input to the hash function. The generated perturbation seed possesses not only temporal characteristics but also geospatial characteristics.
[0060] The terminal security agent generates a perturbation public key using a perturbation function. In this embodiment, to further enhance resistance to analysis, a non-uniform injection strategy is employed when injecting the perturbation polynomial, i.e., only offsetting specific index positions in the public key vector. The terminal sends a request packet containing geolocation information to the central server.
[0061] Step S130, Server-side Implicit Authentication and Session Key Establishment Phase: After receiving the request, the central server first performs continuous verification under the zero-trust principle. The server not only compares the perturbation public key, but also uses the received geographical coordinates to verify whether the terminal is operating within the authorized area. If the coordinate deviation exceeds a preset threshold, the server will reject the injection request even if the public key comparison passes.
[0062] After multi-dimensional verification, the server confirms the terminal's identity. The server then performs high-strength key encapsulation operations to generate a session key. To handle large-scale concurrency, the server employs a hardware-accelerated key encapsulation architecture, achieving a processing capacity of over 10,000 operations per second. While generating the ciphertext, the server records the terminal's access frequency to prevent a single terminal from abnormally consuming quantum key resources.
[0063] Step S140, Quantum Key Secure Injection Phase: The central server retrieves the quantum key from the corresponding quantum key pool based on the branch to which the terminal belongs. To improve injection efficiency, the server employs a segmented encryption method. The first segment is key control information, including the key's validity period and algorithm identifier; the second segment is the encrypted quantum key body. The server uses the session key to symmetrically encrypt both segments of information and attaches a digital signature.
[0064] The response packet is transparently transmitted to the terminal through a multi-level gateway. At each gateway level, the edge key agent performs integrity verification on the response packet, but cannot decrypt the quantum key content within it. This design ensures that the quantum key remains encrypted throughout the end-to-end transmission, conforming to the principle of "not establishing persistent trust in intermediate nodes" in zero-trust architecture.
[0065] Step S150, Terminal Decryption and Acquisition Stage: After receiving the response packet, the terminal security agent executes dual verification logic. First, it verifies the signature of the central server to confirm the data source. Then, it uses the locally stored basic temporary private key for decapsulation. Due to the use of an adaptive parameter set, the terminal can dynamically adjust the decapsulation precision according to the current computing load.
[0066] After obtaining the session key, the terminal decrypts the key control information and the quantum key body sequentially. Based on the requirements in the control information, the terminal configures the quantum key into the corresponding communication protocol stack. Throughout the process, the terminal does not establish permanent trust in the server; each injection request requires resubmitting a perturbed public key containing the geographical location and timestamp. This verification mechanism, based on cryptographic self-consistency, completely resolves the security vulnerabilities of traditional static authentication.
[0067] Example 4 provides a simplified quantum key injection scheme for industrial sensor nodes with extremely limited resources. In this scenario, the sensor node only has basic arithmetic capabilities and cannot perform complex hash algorithms or high-order matrix operations. This example further reduces authentication costs by optimizing the algebraic structure of the perturbation function.
[0068] The system in this embodiment consists of a lightweight key injection server, a micro-terminal agent, and a hardware perturbation unit. The micro-terminal agent is embedded in the sensor's read-only memory, occupying less than 10KB of storage space. The hardware perturbation unit utilizes logic gates within the sensor chip, enabling it to perform polynomial addition operations with extremely low power consumption.
[0069] This embodiment provides a quantum key remote secure injection method based on post-quantum cryptography and zero trust, and the specific execution steps are as follows: Step S110, Initialization Phase: The key injection server allocates a short-length secret seed, typically 128 bits, to the sensor node. The seed is recorded inside the chip during the sensor packaging stage using laser etching technology. The server's public key is stored in a compressed format to save non-volatile storage space in the sensor.
[0070] Step S120, Terminal Initiates Injection Request Phase: The sensor node generates a simplified version of the basic temporary key pair locally. To reduce computational load, the generation of the perturbation seed does not employ complex concatenated hashing, but instead utilizes a lightweight block cipher encryption process. The sensor uses the secret seed as the key, encrypts a portion of the basic temporary public key as plaintext, and uses the output as the perturbation value.
[0071] The hardware perturbation unit directly maps the perturbation value to the coefficients of a polynomial and adds it to the underlying temporary public key. This process does not require floating-point operations, but only involves simple integer addition and shift operations. The sensor sends the generated perturbation public key to the server via an industrial wireless network.
[0072] Step S130, Server-Side Implicit Authentication and Session Key Establishment Phase: The server possesses powerful computing capabilities, enabling it to simulate the lightweight encryption process of the sensors. The server generates a table of expected perturbation public keys for all online sensors through rapid retrieval and pre-computation. When a request arrives, the server completes identity verification within nanoseconds using a table lookup method.
[0073] After successful authentication, the server performs standard key encapsulation operations. To maintain security, the session key generated by the server remains 256 bits long to ensure its resistance to quantum attacks is not compromised. The server then compresses the generated ciphertext to adapt to the low-bandwidth characteristics of industrial wireless networks.
[0074] Step S140, Quantum Key Secure Injection Stage: After obtaining the quantum key, the server encrypts it using a stream encryption algorithm. The stream encryption algorithm consumes very few computational resources at the sensor end. The server uses a lightweight signature algorithm to protect critical instructions. The response packet is streamlined to its minimum size, containing only the necessary ciphertext components.
[0075] Step S150, Terminal Decryption and Acquisition Stage: After receiving the data, the micro-terminal agent verifies the signature using a hardware acceleration module. Subsequently, decapsulation is performed using the basic temporary private key. Because the perturbation quantity is designed to avoid critical sensitive bits of the public key, the sensor can quickly recover the session key. Finally, the quantum key can be decrypted through an XOR operation. This scheme reduces the sensor's operating power consumption by more than 60% while ensuring security, significantly extending the lifespan of battery-powered nodes.
[0076] Example 5: This example provides a highly mobile, high-frequency quantum key remote injection scheme for autonomous vehicles in a vehicle-to-everything (V2X) scenario. In V2X, vehicles need to frequently exchange keys with roadside units while traveling at high speeds, placing extremely high demands on the real-time performance of authentication.
[0077] The system in this embodiment includes a roadside key distribution station, an in-vehicle security chip, and a cloud-based identity management center. The roadside key distribution station acts as a key injection server, interacting with the vehicle via a dedicated short-range communication protocol. The in-vehicle security chip integrates a high-speed post-quantum cryptography unit, capable of supporting millisecond-level key negotiation.
[0078] This embodiment provides a quantum key remote secure injection method based on post-quantum cryptography and zero trust, and the specific execution steps are as follows: Step S110, Initialization Phase: The cloud-based identity management center issues a unique identity credential to each vehicle and generates a corresponding secret seed. The secret seed is securely distributed to the vehicle's security chip. Simultaneously, roadside distribution stations nationwide periodically synchronize incremental updates of the terminal identity database from the cloud to ensure the identification of vehicles entering their coverage area.
[0079] Step S120, Terminal Initiates Injection Request Phase: After the vehicle enters the coverage area of the roadside unit, the on-board security chip automatically triggers the injection process. The chip generates a basic temporary key pair consisting of a basic temporary public key and a basic temporary private key, and calculates the perturbation seed by combining the vehicle's current driving speed, position vector, and secret seed. The generation process of the perturbation polynomial introduces a dynamic adjustment factor, which automatically selects the perturbation strength according to the current channel quality.
[0080] The perturbation function injects a polynomial into the public key. In this embodiment, the construction of the perturbation public key also references residual features from the previous session, forming a chain-like authentication logic. The vehicle sends a request packet containing motion state information to the roadside unit via its onboard antenna.
[0081] Step S130, Server-side Implicit Authentication and Session Key Establishment Phase: After receiving the request, the roadside unit uses edge computing nodes to verify the identity. The server verifies the validity of the request by combining the vehicle's trajectory prediction information. After implicit authentication, the roadside unit immediately performs key encapsulation and preloads a batch of quantum keys using a caching mechanism to cope with possible continuous injection requests.
[0082] Step S140, Quantum Key Secure Injection Stage: The roadside unit encrypts the quantum key using a high-speed session key. To ensure transmission reliability during high-speed movement, the server employs redundant coding technology. The response packet contains multiple check bits to ensure that even if partial bit errors occur during vehicle reception, the original ciphertext can be recovered through error correction algorithms.
[0083] Step S150, Terminal Decryption and Acquisition Stage: After receiving the response packet, the vehicle-mounted security chip performs signature verification and decapsulation operations in parallel using a hardware pipeline. Due to the adoption of chained authentication logic, the vehicle can quickly verify the continuous legitimacy of the server. The decrypted quantum key is immediately used in the vehicle bus encryption, ensuring end-to-end security of the autonomous driving control commands. This embodiment achieves dual authentication in both physical and logical spaces by incorporating physical motion characteristics into cryptographic perturbations.
[0084] See Figure 2 Example 6: This example proposes a quantum key remote secure injection system based on PQC and zero trust. The system includes: A Key Injection Server (KME) is deployed in the same security domain as the receiver in the quantum key distribution device. The KME acts as an authorized agent for the receiver, performing server-side functions. The KME is responsible for retrieving quantum keys from the receiver's key pool and maintaining an identity management database that stores the secret seeds of all remote terminal identities. The KME is configured to execute a post-quantum cryptographic implicit authentication protocol and inject the quantum key into the target terminal through an established secure channel. The endpoint security agent (TSA) runs in a controlled execution environment on a remote terminal device, acting as a client of the system. The endpoint security agent is pre-loaded with the identity public key of the key injection server and the unique secret seed of the terminal. The endpoint security agent is configured to initiate an injection request and cooperate with the key injection server to complete the implicit authentication and key negotiation process based on the perturbation public key, and to receive and decrypt the injected quantum key. The perturbation function module is configured as a defined algebraic processing unit that receives a base temporary public key and a perturbation polynomial derived from the secret seed as input, and outputs a perturbation public key that is algebraically associated with the base temporary public key but contains an identity feature offset; the perturbation function module ensures that the offset is within the error correction threshold range of the post-quantum cryptography algorithm.
[0085] The key injection server adopts an asynchronous processing architecture: The key injection server decouples the front-end identity comparison and filtering logic from the back-end key encapsulation and operation logic. During the identity verification phase, the key injection server pre-authenticates the injection request by performing a low-overhead perturbation public key consistency comparison. The key injection server controls the processing cost of a single illegal request within a preset time threshold and uses the pre-authentication mechanism to filter illegal requests, thereby building the ability to defend against denial-of-service attacks. After the pre-authentication is successful, the key injection server triggers the backend key encapsulation function to perform asymmetric cryptographic operations.
[0086] The key injection server is configured to perform replay attack prevention checks: After successful identity authentication, the key injection server checks whether the feature value of the currently received perturbation public key has been processed within a preset historical time threshold by querying the cache database. If the cache database contains a record of the feature value, it is determined to be a replay attack and the injection request is rejected; If the feature value does not exist in the cache database, then the feature value is stored in the cache database and an expiration time is set.
[0087] The system is configured to support secure online rotation of secret seeds: The ciphertext, the encrypted quantum key, and the digital signature are packaged into a response packet; when generating the response packet, the key injection server generates a new secret seed and encrypts the new secret seed together with the quantum key using the post-quantum cryptography session key; After successfully decrypting and obtaining the quantum key, the terminal security agent extracts the new secret seed; The terminal security agent, based on the accompanying update instruction, replaces the locally stored old secret seed with the new secret seed and updates the local seed version number. The key injection server synchronously updates the corresponding secret seed record in the identity management database to achieve forward security.
[0088] The system is configured to perform zero-trust continuous verification based on geospatial characteristics: When the terminal security agent initiates the injection request, it obtains the current geographic location coordinates of the terminal device and uses the geographic location coordinates as one of the inputs of the cascaded hash operation to generate the perturbation seed containing geospatial characteristics. The terminal security agent generates the perturbation public key containing geospatial feature offsets through the perturbation function; After receiving the injection request, the key injection server uses the received geographic location coordinates to verify whether the terminal device is operating within the authorized area; The key injection server determines that the terminal device meets the zero-trust continuous verification criterion under the dual conditions that the perturbation public key comparison is successful and the geographical location coordinate verification is successful. The key injection server supports batch processing mode, injecting multiple quantum key pairs in a single established secure channel using segmented encryption.
[0089] The post-quantum cryptography algorithm employs a predetermined key encapsulation mechanism and a predetermined signature mechanism; the hash function uses a predetermined hash algorithm to ensure that the overall scheme has the security strength to resist quantum attacks.
[0090] When generating a basic temporary key pair consisting of a basic temporary public key and a basic temporary private key, the terminal security agent uses a hardware random number generator to generate the private key and then transforms it to obtain the public key, in order to ensure the unpredictability of the basic key pair.
[0091] When the key injection server performs the signing operation, the content of its signature includes the current session key characteristic value, the quantum key ciphertext, and the request timestamp, thereby ensuring the integrity of the injection process.
[0092] The quantum key injection process supports batch processing mode, meaning that the key injection server can inject multiple quantum key pairs in a single established secure channel through segmented encryption to meet the key consumption requirements of terminal devices.
[0093] The zero-trust verification logic runs through the entire injection process. The key injection server does not establish a persistent trust relationship with any terminal. Each quantum key injection request must re-execute dynamic authentication based on the perturbation public key.
[0094] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A quantum key remote secure injection method based on PQC and zero trust, characterized in that, The method includes the following steps: After key injection, a quantum cryptographic signature key pair is generated, and a secret seed is assigned. The secret seed is then bound to the terminal's unique identifier and registered in the identity management database. A basic temporary key pair consisting of a basic temporary public key and a basic temporary private key is generated locally. A perturbation seed is calculated based on the current system timestamp, secret seed, and basic temporary public key. A perturbation polynomial is generated through the perturbation seed. The perturbation function is called to accumulate the perturbation polynomial onto the polynomial vector components to generate a perturbation public key. The corresponding secret seed is retrieved based on the terminal's unique identifier, and the expected perturbation public key is calculated. Implicit identity authentication is achieved by comparing the received perturbation public key with the expected perturbation public key. After successful authentication, the perturbation public key is used to perform key encapsulation, generating the post-quantum cryptography session key and the corresponding encapsulated ciphertext. Obtain the quantum key and use post-quantum cryptography for symmetric encryption. At the same time, use your own long-term signature private key to digitally sign the key control information containing the session key feature value, the quantum key ciphertext, and the request timestamp. The validity of the digital signature is verified. After verification, the encapsulated ciphertext is decapsulated using the basic temporary private key to offset the offset introduced by the perturbation public key. The quantum key is then extracted and decrypted using the post-quantum cryptographic session key.
2. The quantum key remote secure injection method based on PQC and zero trust according to claim 1, characterized in that, The processing of the secret seed also includes: The secret seed is stored in a hardware security module, trusted execution environment, or physically unclonable function unit inside the terminal device; The secret seed is physically isolated and protected by the hardware security module, the trusted execution environment, or the physically unclonable function unit, ensuring that the secret seed is not visible outside the controlled execution environment. The key injection server associates and maps the secret seed with the terminal's unique identifier in the identity management database, and configures a corresponding seed version number for the secret seed.
3. The quantum key remote secure injection method based on PQC and zero trust according to claim 1, characterized in that, The process of calculating the perturbation seed includes: Obtain the current system timestamp and discretize it using a preset time step to generate the current time window identifier; Invoke the secure hash algorithm to perform a concatenated hash operation on the secret seed, the time window identifier, and the basic temporary public key; The perturbation seed, which has time-varying and identity-related characteristics, is generated through the cascaded hash operation, wherein the perturbation seed changes dynamically with the change of the time window.
4. The quantum key remote secure injection method based on PQC and zero trust according to claim 1, characterized in that, The process of generating the perturbation polynomial includes: The lattice-based post-quantum cryptography algorithm specification uses the perturbation seed to initialize a predetermined deterministic random number generator; Coefficients conforming to a preset distribution are extracted from the deterministic random number generator, wherein the preset distribution is a central binomial distribution; Based on the extracted coefficients, a small-norm polynomial is constructed, which is comparable in magnitude to the intrinsic noise of the post-quantum cryptography algorithm in terms of norm size, and serves as the perturbation polynomial. When performing the accumulation operation, the perturbation function maintains the dimension and algebraic field properties of the perturbation public key consistent with those of the base temporary public key, and only introduces a controlled algebraic offset in the coefficient distribution.
5. The quantum key remote secure injection method based on PQC and zero trust according to claim 1, characterized in that, The process of generating the post-quantum cryptographic session key and its corresponding encapsulated ciphertext includes: Obtain the current time window and at least one adjacent historical time window to compensate for time asynchrony caused by network transmission delay; For each time window obtained, the expected perturbation public key is calculated by combining the retrieved secret seed with the basic temporary public key. The received perturbation public key is compared with each of the expected perturbation public keys; When the received perturbation public key matches any of the expected perturbation public keys, the authentication is deemed successful.
6. A quantum key remote secure injection system based on PQC and zero trust, employing the quantum key remote secure injection method based on PQC and zero trust as described in any one of claims 1 to 5, characterized in that, The system includes: A key injection server is deployed in the same security domain as the receiver in the quantum key distribution device, acting as an authorized agent of the receiver to perform server functions. The key injection server is responsible for retrieving quantum keys from the receiver's key pool and maintaining an identity management database that stores the secret seeds of the identity roots of all remote terminals. The key injection server is configured to execute a post-quantum cryptographic implicit authentication protocol and inject the quantum key into the target terminal through an established secure channel. The terminal security agent runs in a controlled execution environment of a remote terminal device, acting as a client of the system. The terminal security agent is pre-loaded with the identity public key of the key injection server and the unique secret seed of the terminal. The terminal security agent is configured to initiate an injection request and cooperate with the key injection server to complete the implicit authentication and key negotiation process based on the perturbation public key, and to receive and decrypt the injected quantum key. The perturbation function module is configured as a defined algebraic processing unit that receives a base temporary public key and a perturbation polynomial derived from the secret seed as input, and outputs a perturbation public key that is algebraically associated with the base temporary public key but contains an identity feature offset; the perturbation function module ensures that the offset is within the error correction threshold range of the post-quantum cryptography algorithm.
7. The quantum key remote secure injection system based on PQC and zero trust according to claim 6, characterized in that, The key injection server adopts an asynchronous processing architecture: The key injection server decouples the front-end identity comparison and filtering logic from the back-end key encapsulation and operation logic. During the identity verification phase, the key injection server pre-authenticates the injection request by performing a low-overhead perturbation public key consistency comparison. The key injection server controls the processing cost of a single illegal request within a preset time threshold and uses the pre-authentication mechanism to filter illegal requests, thereby building the ability to defend against denial-of-service attacks. After the pre-authentication is successful, the key injection server triggers the backend key encapsulation function to perform asymmetric cryptographic operations.
8. The quantum key remote secure injection system based on PQC and zero trust according to claim 6, characterized in that, The key injection server is configured to perform replay attack prevention checks: After successful identity authentication, the key injection server checks whether the feature value of the currently received perturbation public key has been processed within a preset historical time threshold by querying the cache database. If the cache database contains a record of the feature value, it is determined to be a replay attack and the injection request is rejected; If the feature value does not exist in the cache database, then the feature value is stored in the cache database and an expiration time is set.
9. The quantum key remote secure injection system based on PQC and zero trust according to claim 6, characterized in that, The system is configured to support secure online rotation of secret seeds: The ciphertext, the encrypted quantum key, and the digital signature are packaged into a response packet. When generating a response packet, the key injection server generates a new secret seed and encrypts the new secret seed together with the quantum key using a post-quantum cryptography session key. After successfully decrypting and obtaining the quantum key, the terminal security agent extracts the new secret seed; The terminal security agent, based on the accompanying update instruction, replaces the locally stored old secret seed with the new secret seed and updates the local seed version number. The key injection server synchronously updates the corresponding secret seed record in the identity management database to achieve forward security.
10. The quantum key remote secure injection system based on PQC and zero trust according to claim 6, characterized in that, The system is configured to perform zero-trust continuous verification based on geospatial characteristics: When the terminal security agent initiates the injection request, it obtains the current geographic location coordinates of the terminal device and uses the geographic location coordinates as one of the inputs to the cascaded hash operation to generate a perturbation seed containing geospatial characteristics. The terminal security agent generates the perturbation public key containing geospatial feature offsets through the perturbation function; After receiving the injection request, the key injection server uses the received geographic location coordinates to verify whether the terminal device is operating within the authorized area; The key injection server determines that the terminal device meets the zero-trust continuous verification criterion under the dual conditions that the perturbation public key comparison is successful and the geographical location coordinate verification is successful. The key injection server supports batch processing mode, injecting multiple quantum key pairs in a single established secure channel using segmented encryption.