Cooperative office encryption method and system based on non-commutative group transformation and perturbation mapping

By employing encryption methods based on non-commutative group transformation and perturbation mapping, the security and efficiency issues of traditional encryption in a quantum computing environment are resolved, enabling efficient and secure transmission of multi-source heterogeneous data in government and enterprise office environments.

CN122348862APending Publication Date: 2026-07-07HEBEI XIONGAN YUNCHUANG INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HEBEI XIONGAN YUNCHUANG INTELLIGENT TECHNOLOGY CO LTD
Filing Date
2026-05-25
Publication Date
2026-07-07

AI Technical Summary

Technical Problem

Existing encryption methods struggle to balance security and efficiency when facing the threat of quantum computing, especially in government and enterprise integrated office environments. Traditional encryption schemes cannot effectively protect multi-source heterogeneous data and run slowly under high load scenarios. Existing technologies are unable to meet the requirements of high security and high efficiency.

Method used

An encryption method based on non-commutative group transformation and perturbation mapping is adopted. The content feature matrix is ​​obtained through a feature extraction model and encoded into non-commutative polynomial matrix group elements using a multidimensional tensor mapping algorithm. Combined with the error polynomial matrix and dynamic noise vector sequence, conjugate transformation and blinding processing are performed. Dynamic routing identifiers and secondary blinding techniques are introduced to ensure the security and resolvability of encrypted data in a quantum environment.

Benefits of technology

It improves encryption strength, reduces encryption and decryption latency, effectively resists quantum computing attacks, maintains stability within the decryption fault tolerance boundary, and achieves efficient and secure protection for collaborative office data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122348862A_ABST
    Figure CN122348862A_ABST
Patent Text Reader

Abstract

The application provides a kind of collaborative office encryption method and system based on non-commutative group transformation and perturbation mapping, method includes: extracting the feature matrix of the heterogeneous data to be encrypted, and encoding as initial group element sequence after quantization processing;From the discrete Gaussian distribution sampling error polynomial matrix superimposed to the sequence to introduce perturbation;Conjugate transformation is carried out using the system public key to obtain ciphertext polynomial matrix sequence;Random mask matrix embedding group transformation attribute is generated;Blind processing is implemented by group multiplication, and the accumulated noise norm is limited within the decryption fault boundary by cooperating with the module switching mechanism;Dynamic routing identification is generated by analyzing network path state, and encrypted transmission message is constructed;Secondary blind is carried out on load header using algebraic operator, and network layer plaintext resolvable anti-quantum encryption data is generated.The application can effectively resist quantum computing attack and flow statistical analysis, and protect the efficient and safe flow of heterogeneous data in office environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, and in particular to a quantum-resistant collaborative office encryption method and system based on non-commutative group transformation and perturbation mapping. Background Technology

[0002] In today's era of rapid development of government and enterprise informatization, the security and encryption technologies of collaborative office systems, such as archive digitization (e.g., scanning and archiving of various materials in government agencies) and document management (e.g., typesetting, printing and circulation of official documents), are particularly crucial.

[0003] These systems are directly related to the protection of classified documents, sensitive official documents, and long-term archives, as well as the smooth operation of business processes.

[0004] Meanwhile, as the business expands to a comprehensive information platform, a large amount of highly sensitive privacy data inevitably accumulates within the platform, such as housing and personal information of public officials, facial recognition features, license plate numbers, and dining trajectories in the canteen.

[0005] Ensuring the security of these multi-source heterogeneous data during platform transfer and long-term storage has become the cornerstone of information security construction.

[0006] With the rapid development of quantum computing technology, traditional encryption methods are facing unprecedented challenges, and there is an urgent need to explore new protection methods to deal with potential threats.

[0007] Currently, many encryption schemes rely too heavily on fixed mathematical structures in their design, lacking the ability to adapt to dynamic threats. In particular, they are easily cracked when faced with the powerful computing capabilities of quantum computing.

[0008] In addition, existing methods often fail to effectively balance security and computational efficiency when dealing with massive amounts of scanned archived materials, high-frequency printed data, and complex facial / vehicle features in information platforms, resulting in slow system operation under high load scenarios.

[0009] This limitation makes it difficult for existing technologies to meet the dual requirements of high security and high efficiency in modern government and enterprise integrated office environments.

[0010] Against this backdrop, encryption methods based on non-commutative group transformations have become a research hotspot. Their core advantage lies in utilizing the fact that element operations in special group structures do not satisfy the commutative law, thereby significantly increasing the difficulty of cracking quantum algorithms.

[0011] However, the core challenge of this technology lies in how to combine complex mathematical transformations with the characteristics of actual business data (such as the pixel matrix of scanned images and the text flow of typed documents).

[0012] When applied, this transformation is difficult to effectively integrate with the specific forms of data such as archives and official documents, resulting in the encrypted data, while enhancing protection, easily losing the controllability of decryption.

[0013] A deeper question is how to introduce appropriate perturbation mechanisms during the transformation process—that is, to enhance security through additional uncertainties without compromising the recoverability of core archive data.

[0014] Therefore, how to construct a secure and controllable encryption process through non-commutative group transformation for scanning archived materials, typesetting and printing official documents, and various sensitive and private data in the context of information technology and integrated office platforms for archives and documents, while introducing reasonable dynamic perturbations to counter quantum computing attacks, has become a key issue that the industry urgently needs to solve. Summary of the Invention

[0015] This invention provides a quantum-resistant collaborative office encryption method based on non-commutative group transformation and perturbation mapping, mainly comprising:

[0016] S1: Obtain the heterogeneous data to be encrypted in the collaborative office system, extract its content feature matrix using the preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on the preset non-commutative polynomial matrix group through the multidimensional tensor mapping algorithm.

[0017] S2: Calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, determine the error distribution probability according to the data mode type of the heterogeneous data to be encrypted, and sample from the discrete Gaussian distribution to generate an error polynomial matrix with the corresponding norm limit. Superimpose the error polynomial matrix onto the initial group element sequence to generate an adjusted group element set. If the statistical distribution parameters do not meet the preset security baseline threshold, superimpose the basic perturbation polynomial matrix onto the initial group element sequence according to the preset degradation strategy to uniformly generate an adjusted group element set.

[0018] S3: Using the system public key parameter as the conjugate element, perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group to obtain a sequence of ciphertext polynomial matrices.

[0019] S4: Generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties.

[0020] S5: Based on the random mask matrix, the ciphertext polynomial matrix sequence is blinded using the multiplication operation of the non-commutative group, and the target encrypted ciphertext sequence is output. The cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted within the legal decryption tolerance boundary of the non-commutative polynomial matrix group.

[0021] S6: Parse the current network transmission path status parameters and generate a dynamic routing identifier, encapsulate the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol, and construct an encrypted transmission message;

[0022] S7: The application layer service header of the encrypted transmission message is subjected to secondary blinding processing using the algebraic operators of the non-commutative polynomial matrix group. While maintaining the plaintext parsability of the network layer routing header, the final quantum-resistant encrypted network layer data is generated.

[0023] Furthermore, S1 includes:

[0024] Random temporary transform elements in the non-commutative conjugate transform are extracted as seed parameters. A symmetric encryption key is generated through a preset key derivation function. The symmetric encryption key is then used to perform stream encryption on the heterogeneous data to be encrypted to obtain the original ciphertext. At the same time, heterogeneous data to be encrypted is obtained from the collaborative office system. The data is initially screened and sorted through a preset classification algorithm to obtain a classified data set.

[0025] For the categorized dataset, a pre-defined feature extraction model is used to extract content features for each category of data, generating a corresponding content feature matrix.

[0026] By dividing the content feature matrix into blocks, each block of data is mapped into a multidimensional tensor form, and the data unit represented by the multidimensional tensor is determined.

[0027] The data units are encoded using a multidimensional tensor mapping algorithm, which transforms them into initial group elements on a pre-defined non-commutative polynomial matrix group, resulting in an encoded set of elements.

[0028] If the encoded set of elements satisfies the preset noncommutativity condition, the elements that satisfy the condition are combined into an initial group element sequence; if not, the mapping parameters of the multidimensional tensor mapping algorithm are adjusted and re-encoded until an initial group element sequence that satisfies the condition is obtained.

[0029] Based on the initial group element sequence, a consistency check is performed on it using a preset sequence verification algorithm to determine whether the sequence meets the preset structural requirements;

[0030] Once the sequence data that has passed the consistency check is obtained, it is saved to the specified database according to the preset storage strategy, thus completing the preparatory processing before data encryption.

[0031] Furthermore, S4 includes:

[0032] Step 1: Construct an initial dynamic noise vector sequence using a chaotic sequence generation algorithm, and obtain the first noise sequence with nonlinear characteristics through iterative calculation;

[0033] Step 2: For the first noise sequence, apply a preset transformation rule to perform vectorization processing to obtain a structured second vector sequence;

[0034] Step 3: Using a one-way hash mapping algorithm, the second vector sequence is correlated with the generator matrix of the non-commutative polynomial matrix group to obtain a preliminary transformation matrix;

[0035] Step 4: Based on the initial transformation matrix, embed specific group transformation properties to generate a first mask matrix with random characteristics;

[0036] Step 5: If the randomness of the first mask matrix satisfies the preset threshold condition, then retain the matrix as the final result;

[0037] If the conditions are not met, the first mask matrix is ​​locally adjusted to obtain the second mask matrix;

[0038] Step 6: By performing a consistency check on the second mask matrix, determine the matching degree between its embedding transformation properties and the initial dynamic noise vector sequence, and obtain the final random mask matrix.

[0039] Furthermore, S6 includes:

[0040] By parsing the path status parameters in network transmission, the congestion level and delay parameters of the current path can be obtained, and the real-time status of the transmission path can be determined.

[0041] Based on the real-time status of the path, a preset decision algorithm is used to generate dynamic route identifiers, thereby obtaining a routing scheme suitable for the current network environment.

[0042] For dynamic route identifiers, obtain the corresponding route path information, associate the target encrypted ciphertext sequence with the route identifier, and determine whether it meets the requirements of the communication protocol. If it does, determine the embedding position of the encrypted ciphertext sequence.

[0043] By embedding an encrypted ciphertext sequence into the application layer payload of the communication protocol, an initial transmission message is constructed, resulting in a message structure containing encrypted data.

[0044] The format of the initial transmitted message is checked to determine whether the message structure is complete. If it is complete, the final encrypted transmitted message is generated.

[0045] Obtain the verification result of the final encrypted transmission message, send it to the target node using a preset transmission control strategy, and determine the priority and path selection for message transmission;

[0046] In response to changes in path status during transmission, feedback data from network transmission is acquired in real time to determine whether there is path congestion or abnormal delay. If so, the dynamic route identifier is adjusted and a new routing scheme is generated.

[0047] Furthermore, S7 includes:

[0048] Step 1: Obtain the application layer service header data in encrypted transmission. Using a non-commutative matrix as the basic structure, the data is initially grouped using the mathematical properties of the non-commutative polynomial matrix group to obtain the initially grouped payload header data block.

[0049] Step 2: For the initially grouped load header data blocks, perform the first blinding operation using algebraic operators. Transform the data blocks according to the operation rules of the non-commutation matrix to determine the intermediate data results after the first blinding.

[0050] Step 3: Starting from the intermediate data results after the first blinding, the same algebraic operators are used for the second blinding process. The intermediate data is then re-encrypted using the dynamic adjustment mechanism of the non-commutative polynomial matrix group to determine the encrypted data of the payload header after the second blinding.

[0051] Step 4: Obtain the network layer routing header data. If the routing header data is not encrypted, keep it in plaintext and verify its readability using a parsing tool to obtain plaintext parsable routing header data.

[0052] Step 5: Based on the encrypted payload header data after secondary blinding and the plaintext parsable routing header data, a data reassembly algorithm is used to integrate the two to determine the reassembled network layer data structure.

[0053] Step Six: For the recombined network layer data structure, use a quantum-resistant verification algorithm to perform security checks on the overall data. If the check results meet the preset security standards, the final quantum-resistant encrypted network layer data is generated.

[0054] This invention also provides a quantum-resistant collaborative office encryption system based on non-commutative group transformation and perturbation mapping, mainly comprising:

[0055] The data acquisition and encoding module is used to acquire heterogeneous data to be encrypted in the collaborative office system, extract its content feature matrix using a preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on a preset non-commutative polynomial matrix group through a multidimensional tensor mapping algorithm.

[0056] The statistical analysis and error superposition module is used to calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, the error distribution probability is determined according to the data mode type of the heterogeneous data to be encrypted, and the error polynomial matrix corresponding to the norm limit is generated by sampling from the discrete Gaussian distribution. The error polynomial matrix is ​​superimposed on the initial group element sequence to generate the adjusted group element set.

[0057] The conjugate transformation encryption module is used to perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group using the system public key parameter as the conjugate element, to obtain a sequence of ciphertext polynomial matrices.

[0058] The dynamic noise mask generation module is used to generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and to perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties.

[0059] The blinding processing module is used to perform blinding processing on the ciphertext polynomial matrix sequence based on the random mask matrix using the multiplication operation of the non-commutative group, and output the target encrypted ciphertext sequence, wherein the cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted within the legal decryption fault tolerance boundary of the non-commutative polynomial matrix group.

[0060] The message encapsulation module is used to parse the current network transmission path status parameters and generate a dynamic routing identifier, and encapsulate the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol to construct an encrypted transmission message;

[0061] The secondary blinding and data generation module is used to perform secondary blinding processing on the application layer service header of the encrypted transmission message using the algebraic operators of the non-commutative polynomial matrix group, and generate the final quantum-resistant encrypted network layer data while keeping the plaintext of the network layer routing header parseable.

[0062] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0063] This invention discloses a quantum-resistant collaborative office encryption method based on non-commutative group transformation and perturbation mapping. Addressing the risks of quantum computing cracking and security challenges in dynamic network environments for heterogeneous data encryption transmission in collaborative office systems, it proposes a comprehensive solution integrating data feature extraction, group transformation encryption, and dynamic perturbation masking. This invention extracts the content feature matrix of the heterogeneous data to be encrypted and maps it to the elements of a non-commutative polynomial matrix group. Combined with a perturbation mechanism using an error polynomial matrix and a dynamic noise vector sequence, it ensures that the ciphertext is difficult to crack in a quantum environment. Simultaneously, it uses a random mask matrix and conjugate transformation to blind the ciphertext, and employs dynamic routing identifiers and secondary blinding techniques to ensure the security and resolvability of transmitted messages. The core innovation lies in the combination of non-commutative group transformation and multi-layer perturbation mapping, which not only improves encryption strength but also maintains stability within the decryption tolerance boundary, ultimately achieving efficient, secure, and quantum-resistant transmission protection of collaborative office data in complex network environments.

[0064] Compared to traditional office encryption schemes based on RSA or ECC, this invention uses non-commutative group transformations to replace highly complex modular exponentiation operations, reducing encryption and decryption latency by approximately [percentage missing] when processing massive amounts of scanned documents. By introducing a perturbation mapping and modulus switching mechanism based on discrete Gaussian distribution, this scheme effectively resists quantum algorithm attacks targeting the conjugate search problem, and its security strength is significantly improved by orders of magnitude compared to conventional lattice cryptography schemes for the same ciphertext length. Furthermore, this scheme's secondary blinding processing of the application layer header completely hides the statistical characteristics of the service flow without altering the existing network protocol architecture, possessing extremely high industrial practical value. Attached Figure Description

[0065] Figure 1 This is a flowchart of a quantum-resistant collaborative office encryption method based on non-commutative group transformation and perturbation mapping according to the present invention.

[0066] Figure 2 This is a schematic diagram of a quantum-resistant collaborative office encryption method based on non-commutative group transformation and perturbation mapping according to the present invention.

[0067] Figure 3 This is another schematic diagram of a quantum-resistant collaborative office encryption method based on non-commutative group transformation and perturbation mapping according to the present invention.

[0068] Figure 4 This is a schematic diagram of the structure of a quantum-resistant collaborative office encryption system based on non-commutative group transformation and perturbation mapping according to the present invention. Detailed Implementation

[0069] To further understand the content of this invention, a detailed description of the invention is provided in conjunction with the accompanying drawings and embodiments. The specific embodiments described herein are for illustrative purposes only and are not intended to limit the invention. It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0070] Terminology Explanation

[0071] Non-commutative group transformation and perturbation mapping: This refers to a quantum-resistant encryption mechanism that integrates nonlinear algebraic structures and dynamic random disturbances. Its general definition utilizes the property that matrix multiplication in an algebraic group does not satisfy the commutative law (i.e., AB ≠ BA), combined with the introduction of controllable small errors into the mathematical space. In the application scenario of this invention, this technology is mainly used to solve the security protection problem of heterogeneous data (such as documents, images, and personnel information) under the threat of quantum computing in collaborative office environments. Through non-commutative group transformation, the original features are mapped to a high-dimensional and complex mathematical space, increasing the difficulty of cracking quantum search and decomposition algorithms. Simultaneously, dynamic noise is introduced through perturbation mapping, ensuring that the ciphertext possesses quantum resistance strength while maintaining the stability of the decryption process within the fault-tolerant boundary.

[0072] Quantum-resistant collaborative office encryption method: This refers to a novel encryption scheme capable of resisting attacks from quantum computers (such as those using Shor's algorithm or Grover's algorithm), specifically designed for office systems in the digital transformation of government and enterprises. In the application scenario of this invention, this method not only focuses on traditional text data, but also specifically addresses multi-source heterogeneous data unique to the office field, such as digitized scanned documents, document management instructions, and public officials' private data. By introducing mathematical challenges such as lattice cryptography, error-correcting codes, or non-commutative group theory, it achieves quantum-resistant security protection for data throughout its entire lifecycle of acquisition, storage, and transfer.

[0073] Collaborative office system: refers to a comprehensive office platform that integrates multiple business functions such as digital file management, document printing and typesetting, official document circulation, logistics management, and information services. In the application scenario of this invention, this system is not only the source of encrypted data but also the physical environment for encrypted message transmission, covering the entire link from scanning terminals, office computers, printing equipment to the backend server. Furthermore, because it contains a large amount of highly sensitive public official privacy information (such as housing details, facial recognition features, and license plate numbers), it has extremely high requirements for the real-time performance and security of data encryption.

[0074] Feature extraction model: refers to a mathematical model based on deep learning or statistical learning algorithms, used to identify and extract core information from raw office data. In the application scenario of this invention, this model can extract pixel matrix features from scanned documents, semantic vector features from official documents, or biometric features from faces and license plates. Its output is the content feature matrix, providing a unified mathematical expression basis for subsequent non-commutative group mapping.

[0075] Content feature matrix: This refers to the standardized matrix representation formed after feature extraction from the original heterogeneous data. It is the "digital fingerprint" of the data at the algorithm processing level. In the application scenario of this invention, this matrix not only contains the core semantic information of office documents, but also retains the statistical characteristics of data distribution, such as sparsity and information entropy, so that the algorithm can determine the security requirements of the current data and generate the corresponding error polynomial.

[0076] Multidimensional tensor mapping algorithm: refers to the mathematical transformation process of mapping a low-dimensional content feature matrix to a high-dimensional tensor space and encoding it as specific group elements. In the application scenario of this invention, this algorithm is responsible for transforming the segmented archive or office data into an initial group element sequence on a non-commutative polynomial matrix group. By increasing the mathematical dimension of the data, it greatly expands the search range of the encryption space.

[0077] Non-commutative polynomial matrix group: refers to a special group-theoretic algebraic structure whose elements consist of matrices with polynomial coefficients and satisfy the non-commutative property of matrix multiplication. In the application scenario of this invention, this group structure is the core "carrier" against quantum encryption. Its non-commutativity prevents quantum algorithms from obtaining private key information through simple logarithmic operations or linear decomposition, thereby ensuring the underlying algebraic security of official documents and private data.

[0078] Initial group element sequence: refers to the preliminary encoded sequence that conforms to the non-commutative group structure after processing by the multidimensional tensor mapping algorithm. In the application scenario of this invention, this sequence is the first mapping of the archive data or personnel information to be encrypted in the group theory space, and is the logical basis for subsequent conjugate transformation and blinding processing.

[0079] Sparsity refers to the proportion of non-zero elements in a matrix, used to measure the dispersion of the feature distribution of office data. In the application scenario of this invention, sparsity, as one of the statistical distribution parameters, is used to reflect the feature density of archival images or formatted documents, helping the system determine the strength of the error matrix introduced during the encryption process.

[0080] Information entropy: A mathematical indicator that measures the uncertainty or information content of data. In this invention, the information entropy H(X) is expressed using the Shannon entropy formula. Perform calculations, where This represents the quantized eigenvalues ​​in the content feature matrix. This indicates the probability of that value occurring.

[0081] In the application scenario of this invention, by calculating the information entropy of the content feature matrix, the system can quantify the complexity of office data. If the information entropy meets the preset safety baseline threshold, it indicates that the data has sufficient confusion and can further perform high-intensity error superposition operations.

[0082] Data modality type: refers to the classification of physical attributes of data from different sources in the office platform, such as text modality, image modality, video stream modality, or structured numerical modality. In the application scenario of this invention, the system determines the most suitable error distribution probability based on the data modality type (e.g., distinguishing whether the currently processed data is a public official housing information form or a facial recognition video stream) to achieve targeted encryption.

[0083] Error distribution probability: refers to the statistical distribution model and its probability parameters followed by the sampled values ​​when generating the perturbation term. In the application scenario of this invention, the system dynamically adjusts this probability according to the data mode to ensure that the generated error multinomial matrix can effectively obfuscate the original data without causing excessive noise that makes it impossible to restore legitimate archival data.

[0084] Discrete Gaussian distribution: refers to a discrete probability distribution with Gaussian (normal) distribution characteristics defined on integer lattice points, and is the foundation of lattice cryptography and related quantum-resistant algorithms. In the application scenario of this invention, the system samples from the discrete Gaussian distribution to generate error terms. This sampling method not only has extremely high mathematical security, but also ensures that noise is controlled within the norm bound.

[0085] Error polynomial matrix: refers to a perturbation matrix generated according to a specific probability distribution and superimposed on the initial group element sequence. In the application scenario of this invention, this matrix is ​​equivalent to injecting "legitimate noise" into the original office data, making it impossible for a quantum computer to eliminate the uncertainties caused by the error polynomial through precise calculations even if it obtains some group element information.

[0086] System public key parameters: These are the publicly disclosed mathematical parameters in a non-commutative group encryption system, used to perform encryption transformations. In the application scenario of this invention, the public key parameters act as "conjugate elements" in the conjugate transformation, enabling the sending end in the collaborative office system to perform asymmetric transformations on document data using the public key, while only the receiving end holding the corresponding private key can decrypt the data using the inverse multiplication operation of the non-commutative group.

[0087] Conjugate element: refers to the element that plays a key transformation role in group theory conjugate transformations. In the application scenario of this invention, the system uses the public key parameter as the conjugate element to perform a similar transformation on the group elements of the archive data. The transformation operation is used to achieve a non-linear scramble of the original data structure.

[0088] Conjugate transformation operation: refers to a linear or nonlinear algebraic transformation performed on the elements of a target group using conjugate elements. In the application scenario of this invention, this operation further masks the archive data with error perturbations within the complex orbit of a non-commutative matrix group, outputting a sequence of ciphertext polynomial matrices.

[0089] Ciphertext polynomial matrix sequence: refers to a set of polynomial matrices in an encrypted state after undergoing conjugate transformation. In the application scenario of this invention, this represents the state of archives or public official information after the first layer of algebraic transformation, possessing preliminary resistance to quantum attacks.

[0090] Chaotic sequence generation algorithm: refers to an algorithm that uses nonlinear dynamical systems (such as Logistic mappings or Lorenz systems) to generate pseudo-random sequences with high initial value sensitivity. In the application scenario of this invention, this algorithm is used to generate dynamic noise vector sequences containing nonlinear characteristics, and its unpredictability provides a high-quality random source for generating random mask matrices.

[0091] Nonlinear characteristics refer to features in data that do not follow simple proportional relationships and possess high complexity and unpredictability. In the application scenario of this invention, the nonlinear characteristics generated by chaotic systems can effectively resist decryption methods based on linear regression or linear algebra.

[0092] Dynamic noise vector sequence: refers to a random vector sequence that changes dynamically with time or environmental conditions. In the application scenario of this invention, this sequence is the raw material for constructing a random mask matrix, ensuring that different perturbation masks are used for office data in each frame and each document transmission.

[0093] Preset generator matrix: refers to a special fundamental matrix in a non-commutative polynomial matrix group that can generate the entire group space through group operations. In the application scenario of this invention, the dynamic noise vector sequence is combined with the generator matrix through hash mapping to ensure that the generated random mask matrix not only has randomness but also perfectly adapts to the current group algebra structure.

[0094] One-way hash mapping: refers to a mathematical transformation that maps an input of arbitrary length to an output of fixed length, and is computationally irreversible. In the application scenario of this invention, this mapping associates dynamic noise with the generator matrix, ensuring that the process of embedding group transformation properties is irreversible, increasing the difficulty of deciphering encrypted messages.

[0095] Embedded group transformation properties: This refers to introducing algebraic features of a non-commutative group into a random mask, enabling it to maintain the integrity of the group structure when participating in blinding operations. In the application scenario of this invention, this process ensures that the random mask is not simply additive noise, but a structured mask capable of performing group multiplication operations with the ciphertext polynomial matrix.

[0096] Random mask matrix: This refers to a matrix generated jointly by a chaotic sequence and a group generator, used to ultimately obfuscate the ciphertext. In the application scenario of this invention, this matrix serves as a second layer of protection, combining with the ciphertext generated by the conjugate transformation to further obscure the statistical characteristics of the office data.

[0097] Multiplication of noncommutative groups: refers to multiplication operations that follow the definition of a noncommutative matrix group and do not satisfy the commutative law. In the application scenario of this invention, this operation is used to apply a random mask matrix to the ciphertext sequence, utilizing noncommutativity to ensure the security of the blinding process.

[0098] Blinding processing refers to masking data using randomization factors, so that the processed data hides its original characteristics without affecting the final decryption result. In the application scenario of this invention, blinding processing ensures that extremely sensitive data such as public officials' dining trajectories and facial recognition features are presented in a completely random form during network transmission.

[0099] Cumulative noise norm: refers to the "length" or strength index of the total noise introduced by the error polynomial matrix and the random mask matrix during encryption in mathematical space. In the application scenario of this invention, the system monitors this norm in real time to ensure that the total noise does not compromise the recoverability of the underlying office data.

[0100] Legitimate decryption tolerance boundary: This refers to the maximum noise interference limit allowed by the encryption algorithm. Within this boundary, the receiving end can perfectly restore the original data using error correction technology. In the application scenario of this invention, this boundary ensures that after multiple layers of quantum-resistant encryption, the decryption and restoration of digitized archival scans will not result in image distortion or garbled text.

[0101] Path status parameters refer to real-time physical status data of network transmission links, such as congestion level, end-to-end latency, and packet loss rate. In the application scenario of this invention, by analyzing these parameters, the system can perceive dynamic changes in the network environment and select the safest transmission path for archives and printed data.

[0102] Feedback status parameters refer to the real-time performance indicators and physical status information of the network transmission link. In the application scenario of this invention, these parameters specifically include real-time feedback data such as the congestion level of the collaborative office network path (e.g., reflected by the ECN flag), latency parameters (e.g., latency calculated by RTT), bandwidth utilization, and packet loss rate. The system obtains these parameters by parsing the communication packet header or network node feedback, which are used to determine the load status of the transmission path in real time and serve as the core decision-making basis for generating dynamic routing identifiers. This ensures that high-value encrypted office messages can avoid high-risk or high-latency links, achieving intelligent guidance and efficient and secure data flow in complex government and enterprise network environments.

[0103] Dynamic routing identifier: A unique logical label generated based on real-time network conditions to guide data packets through the network. In the application scenario of this invention, this identifier is associated with the target encrypted ciphertext sequence, enabling intelligent guidance of office data in dynamic and complex network environments.

[0104] Pre-defined communication protocol: refers to the data exchange specifications agreed upon in the collaborative office platform, such as HTTP / HTTPS, FTP, or specific office workflow protocols. In the application scenario of this invention, the encrypted ciphertext is encapsulated in the application layer of this protocol to ensure compatibility with existing office network infrastructure.

[0105] Application layer payload: This refers to the portion of the communication message structure that actually carries business data (such as documents, video streams, and personnel information). In the application scenario of this invention, the target encrypted ciphertext sequence, after quantum-resistant processing, is placed here, becoming the core protected content of the message.

[0106] Algebraic operators: These refer to algebraic operation tools defined within a non-commutative polynomial matrix group. In the application scenario of this invention, algebraic operators are used to perform secondary processing on the header to achieve fine-grained encryption control.

[0107] Secondary masking: This refers to the additional masking operation performed on the header information (payload header) of the message using algebraic operators after the application layer encapsulation is completed. In the application scenario of this invention, this technology ensures that the network layer routing information (used for transmission) remains readable in plaintext, while the business logic header (containing information such as file type and recipient) is encrypted again, achieving a balance between security and transmission efficiency.

[0108] Quantum-resistant encrypted network layer data refers to data packets that have undergone a complete encryption process and are ultimately circulated within the office network. In the application scenario of this invention, this data is characterized by highly encrypted application layer content and payload headers, while the network layer header can be parsed normally. This effectively defends against quantum computing attacks and ensures the absolute security of digitized archives, document printing, and platform privacy data.

[0109] Heterogeneous data refers to various types of data in a collaborative office system that differ in format, source, and structure, such as scanned images (unstructured), official documents (semi-structured), personal information forms for public officials (structured), and cafeteria surveillance videos (streaming data). In this invention, this term emphasizes the system's ability to generalize and process all data from the office platform.

[0110] Block processing: This refers to the process of dividing a large-scale content feature matrix into several smaller sub-matrices according to a preset dimension. In this invention, this process is not only to improve computational efficiency, but also to ensure that each piece of data can find a corresponding group element mapping point in the non-commutative polynomial matrix group.

[0111] Non-commutativity condition: refers to the condition that must be satisfied during mathematical transformations. This is a fundamental constraint. In this invention, if the encoded element does not satisfy this condition, the system will remap it to ensure that the encryption process has quantum-resistant algebraic complexity.

[0112] Consistency check: This refers to the structured verification of the generated group element sequence to determine whether it conforms to preset algebraic norms and structural requirements. In this invention, this is the final quality checkpoint before data is stored in the database, ensuring the integrity of the pre-encryption preparation work.

[0113] Structured decomposition refers to the process of breaking down a complex set of group elements into substructures with specific distribution patterns. In this invention, this is used to extract deep-seated statistical patterns from archives or private data, thereby constructing a more accurate distribution pattern matrix.

[0114] Matching degree: refers to the degree of similarity between two mathematical vectors or matrices in the feature space. In this invention, by calculating the matching degree between the vector mapping result and the initial content feature matrix, the preservation of data features during the encryption process can be verified, thereby ensuring security without losing decryption controllability.

[0115] Error correction matrix: This refers to an auxiliary matrix constructed based on a sampling strategy, specifically designed to correct for the effects of channel noise or encryption bias. In this invention, it ensures that encrypted public official privacy data can still be stably restored even in complex network environments.

[0116] Formatting: This refers to converting non-standard algebraic calculation results into standard data formats that conform to communication protocol specifications. In this invention, this ensures that complex ciphertext polynomial sequences can be correctly encapsulated in network packets such as TCP / IP.

[0117] Security baseline threshold: This refers to the minimum standard value set by the system to determine data security risks and encryption strength. In this invention, if the statistical parameters of the data reach this threshold, the system will activate a higher-order anti-quantum perturbation mechanism.

[0118] Example 1: Quantum-resistant encrypted transmission example based on an archival digitization project

[0119] In this embodiment, the quantum-resistant collaborative office encryption method and system are deeply applied to the archive digitization project of government agencies. During the archive digitization process, a massive amount of scanned file images, text extracted by optical character recognition, and archive metadata are generated. This data constitutes the heterogeneous data to be encrypted in the collaborative office system.

[0120] In the data acquisition and encoding phase, the system first connects to the archival digitization scanning terminal and storage server to acquire heterogeneous data to be encrypted, including high-resolution scanned images and text metadata. To effectively process this unstructured and semi-structured data, the system invokes a pre-defined feature extraction model. Here, the feature extraction model employs a fusion architecture of a deep residual network and a bidirectional encoder representation model. Its input parameters are the original archival image pixel array and text sequence, and its output parameter is a content feature matrix of a unified dimension. The content feature matrix is ​​a mathematical abstraction of the original business data in the feature space, recording the texture edges of the images and the semantic key information of the text. Subsequently, the system divides the content feature matrix into blocks and encodes each data block into an initial group element sequence on a pre-defined non-commutative polynomial matrix group using a multidimensional tensor mapping algorithm. The so-called multidimensional tensor mapping algorithm refers to the technique of further extending two-dimensional or dimensionality-reduced matrix data into a higher-dimensional spatial structure for expression; while the non-commutative polynomial matrix group refers to a matrix whose elements are composed of polynomials, and these matrices do not satisfy the commutative law when performing multiplication operations (i.e., A multiplied by B is not equal to B multiplied by A). This non-commutativity is the core mathematical foundation for resisting the Shor algorithm attack of quantum computers. After mapping, the original archive data is transformed into an initial group element sequence.

[0121] It should be noted that, to ensure bit-level lossless restoration of collaborative office data (such as official documents and legal files), this embodiment of the invention employs a dual-path encryption mechanism: the first path is a feature-secure path, namely, the non-commutative group encryption of the content feature matrix mentioned above, and the generated ciphertext is used for secure semantic retrieval and compliance auditing in the cloud; the second path is a plaintext protection path, where the system uses intermediate parameters (such as temporary transform elements r generated by conjugate transformation) in the non-commutative polynomial matrix group transformation process to generate a symmetric encryption key (such as AES-256) through a key derivation function (KDF) to perform stream encryption on the original heterogeneous data. During decryption, the legitimate recipient first restores the initial group element sequence to synchronously negotiate parameters, and then uses the derived symmetric key to decrypt the plaintext ciphertext, thereby ensuring high-fidelity lossless restoration of office data while possessing quantum resistance.

[0122] It is worth emphasizing that the security of the symmetric encryption key derived in the original protected path is controlled by the conjugate transformation parameters of the non-commutative polynomial matrix group. Since the conjugate search problem (CSP) has extremely high algebraic complexity in a quantum computing environment, this ensures that even when using traditional stream ciphers to process the original text, the key negotiation process is resistant to quantum attacks.

[0123] The innovation of this dual-path mechanism lies in the fact that it uses non-commutative group transformation to process the "feature path," which solves the problem that features are easily leaked in traditional stream encryption under quantum conditions. At the same time, it uses intermediate parameters to derive the key to process the "original path," avoiding the performance bottleneck caused by directly performing complex non-commutative transformations on massive images. Thus, it achieves a balance between security and practicality that is difficult to achieve with existing technologies.

[0124] In the statistical analysis and error superposition phase, the system calculates the sparsity and information entropy of the aforementioned content feature matrix as statistical distribution parameters. Sparsity reflects the proportion of zero elements in the feature matrix, while information entropy quantifies the disorder and complexity of the archival data features. When these statistical distribution parameters are determined to meet the preset security baseline threshold (i.e., the data features are sufficiently rich and difficult to guess), the system determines the error distribution probability based on the data modality type of the heterogeneous data to be encrypted (e.g., distinguishing between scanned image modality and text modality). Next, the system samples from the discrete Gaussian distribution to generate an error multinomial matrix corresponding to the norm bound. The discrete Gaussian distribution is a mathematical model that presents a bell-shaped probability distribution on integer grid points, serving as the basis for introducing the quantum-resistant fault-tolerant learning problem. The system uses the generated error multinomial matrix as a perturbation term, superimposing it onto the initial group element sequence to generate an adjusted group element set. This operation subtly introduces small and controllable noise into the archival data.

[0125] During the conjugate transformation encryption phase, the system uses the system public key parameter as the conjugate element to perform a conjugate transformation operation on the adjusted set of group elements over a non-commutative polynomial matrix group. The conjugate element can be understood as a "public key" for performing a specific transformation. The specific operation of the conjugate transformation involves performing sequential multiplications on the target element in the set, the inverse matrix of its corresponding conjugate element, and the conjugate element itself. Due to the properties of non-commutative groups, this transformation completely scrambles the original group elements throughout the mathematical space, thus obtaining a preliminary encrypted sequence of ciphertext polynomial matrices.

[0126] In the dynamic noise mask generation stage, to further enhance the anti-cracking capability of archive data before transmission, the system utilizes a chaotic sequence generation algorithm to generate a dynamic noise vector sequence containing nonlinear characteristics. The chaotic sequence generation algorithm is a pseudo-random number generation mechanism that is extremely sensitive to initial conditions. Its inputs are timestamps and internal system environmental parameters, and its output is a highly unpredictable nonlinear feature vector. The system performs a one-way hash mapping on this dynamic noise vector sequence and a preset generator matrix of the non-commutative polynomial matrix group (i.e., the fundamental matrix that generates the entire group structure). The one-way hash mapping ensures an irreversible transformation from input to output, thereby obtaining a random mask matrix embedding group transformation properties. This random mask matrix not only possesses randomness but also inherently contains the algebraic structural characteristics of the non-commutative group.

[0127] During the blinding process, the system uses the multiplication operation of the non-commutative group to blind the sequence of ciphertext polynomial matrices based on the acquired random mask matrix. Blinding refers to the technique of completely masking the data to be protected using additional random information; the output is the target encrypted ciphertext sequence. In this process, the system strictly controls the perturbation limits to ensure that the cumulative noise norm (i.e., a comprehensive measure of the mathematical length or magnitude of the noise) generated after the superposition of the error polynomial matrix and the random mask matrix is ​​always limited within the legal decryption tolerance boundary of the non-commutative polynomial matrix group. The legal decryption tolerance boundary refers to the maximum noise tolerance limit that the receiver, holding the private key, can use error correction algorithms to eliminate noise and perfectly restore the original archive data. Once this boundary is exceeded, the archive data will be permanently corrupted.

[0128] During the message encapsulation and network transmission phases, the system parses the current network transmission path status parameters (including bandwidth utilization and node latency of the government intranet) and generates dynamic routing identifiers accordingly. The system encapsulates the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol to construct an encrypted transmission message. The application layer payload is the core area in the data packet that actually carries the encrypted archive data.

[0129] During the secondary blinding and data generation stages, to prevent archival data from being eavesdropped on by traffic analysis at complex network routing nodes, the system uses algebraic operators of a non-commutative polynomial matrix group (i.e., basic operational rules such as addition and multiplication defined within the group) to perform secondary blinding processing on the application layer service headers of encrypted transmission messages. This operation specifically re-encrypts application layer control information while maintaining the plaintext parsing capability of the network layer routing headers during processing, ensuring that government network routers can correctly identify the target address. Ultimately, the system generates quantum-resistant encrypted network layer data containing historical archival materials, achieving absolutely secure transfer of scanned archival materials.

[0130] Example 2: Quantum-resistant encrypted transmission based on high-frequency document circulation in document printing projects

[0131] In this embodiment, the technical solution is customized and applied to the document printing project within the integrated office platform. Document printing operations involve the typesetting of confidential documents, the issuance of printing instructions, and the circulation of electronic documents between different departments. This type of data is characterized by high frequency, strong real-time requirements, and standardized formats (such as formatted documents, offline printer files, etc.).

[0132] When processing heterogeneous data to be encrypted in a document printing system, the system extracts electronic documents and printing control instructions in the typesetting and circulation stage. At this point, the feature extraction model parses the layout marks, font size matrix, and printing instruction codes of the typesetting document. The input parameter is a structured layout document flow, and the output parameter is a content feature matrix mapping the typesetting layout and text content. Similarly, the system divides this matrix into blocks and, using a multidimensional tensor mapping algorithm, transforms the document data blocks into an initial group element sequence on a predefined non-commutative polynomial matrix group. For document circulation, this matrix group transformation can resist any attack attempting to enumerate document content using quantum computing.

[0133] To analyze the statistical characteristics of printed document data, the system extracts the sparsity and information entropy of the content feature matrix. Considering the large amount of white space and repetitive formatting control characters (resulting in high sparsity) in official document layout data, when the statistical distribution parameters meet a preset safety baseline threshold, the system sets a specific error distribution probability based on the unique data modality type of the printed document data and extracts the corresponding error multinomial matrix from the discrete Gaussian distribution. This error multinomial matrix is ​​then fused into the initial group element sequence to generate an adjusted group element set. This process is equivalent to introducing legitimate "printing noise" into the underlying mathematical expression of the official document; this noise is difficult to remove at the algebraic level.

[0134] Using the public key parameters of the government system as conjugate elements, the system performs a conjugate transformation operation on the adjusted set of group elements over a non-commutative polynomial matrix group. In this scenario, the conjugate transformation completely disassembles and reassembles the plaintext layout logic of the official document, outputting a corresponding ciphertext polynomial matrix sequence. Even if the document printing network is compromised externally, the attacker will only intercept mathematical matrices that have no layout logic or reading significance.

[0135] To address the complexity of printing terminal devices, the system employs a chaotic sequence generation algorithm to capture minute physical oscillations or clock offsets of the print server as nonlinear features, generating a dynamic noise vector sequence. After performing a one-way hash mapping with a preset generator matrix, the system constructs a random mask matrix specifically for this printing task. This matrix possesses one-time pad properties and incorporates group transformation attributes.

[0136] The system then utilizes multiplication operations of non-commutative groups and employs the aforementioned random mask matrix to blind the ciphertext polynomial matrix sequence, outputting the encrypted ciphertext sequence of the printing target. During this stage, the system's internal fault-tolerance mechanism operates in real time, ensuring that the cumulative noise norm of the document content remains absolutely within the legal decryption tolerance boundary. This guarantees that the terminal classified printer, upon receiving the instruction, can accurately parse every Chinese character and official seal of the document, preventing garbled printing due to noise exceeding the boundary.

[0137] When distributing print jobs, the system monitors the path status parameters of each print node in real time and generates dynamic routing identifiers to avoid congested or risky subnets. The system embeds the encrypted ciphertext sequence of the print target into the application layer payload of a preset communication protocol (such as a network printing protocol) to construct the message. Subsequently, algebraic operators are used to apply a second round of blinding processing to the application layer business header, ensuring that only designated classified printers can decrypt the application layer header. Network switching devices forward data packets only based on the plaintext network layer routing header, thereby generating the final quantum-resistant encrypted network layer data, ensuring end-to-end security of confidential documents from typesetting to final print output.

[0138] Example 3: Quantum-resistant encrypted transmission based on information platform for protecting the privacy of public officials

[0139] In this embodiment, the application scope of the quantum-resistant collaborative office encryption system is extended to the comprehensive information platform, focusing on encrypting and protecting highly sensitive structured privacy data such as housing information and personal resumes of public officials within the platform.

[0140] When business systems need to transfer the housing information of public officials, the records in these relational databases constitute heterogeneous data to be encrypted. The feature extraction model here is transformed into a joint extractor of database field attributes and text record features. The model's input parameters are a vector of form fields containing sensitive information such as the person's name, ID number, property location, and area; the output parameter is a highly condensed content feature matrix. Subsequently, a multidimensional tensor mapping algorithm encodes the three-dimensional mapping (personnel attributes, property attributes, timestamp) of each personnel record into a non-commutative polynomial matrix group, generating an initial sequence of group elements representing the personal privacy data.

[0141] Given the rigorous structure and low redundancy of data such as personal housing information, its information entropy is typically high. After verifying that the statistical distribution parameters meet the security baseline threshold, the system identifies the current data modality as high-density structured privacy data. It then dynamically adjusts the error distribution probability, collecting a smaller amplitude but more discrete error multinomial matrix from a discrete Gaussian distribution. This error multinomial matrix is ​​then superimposed on the privacy data sequence to form an adjusted set of group elements. This effectively prevents differential attacks targeting specific public officials' identity characteristics.

[0142] The system uses the platform's public key parameters as conjugate elements to perform a conjugate transformation operation on the adjusted set of group elements over a non-commutative polynomial matrix group. After undergoing this non-linear distortion of the non-commutative space, the sensitive privacy of public officials is transformed into a sequence of ciphertext polynomial matrices, fundamentally preventing unauthorized internal queries and the risk of external database breaches.

[0143] To combat long-term static cryptanalysis targeting high-value privacy data, the system introduces a chaotic sequence generation algorithm. Based on the random jitter of concurrent requests from the information platform server, a nonlinear feature is generated, deriving a dynamic noise vector sequence. Through the one-way hash mapping of a preset generator matrix, the system custom-generates a random mask matrix for each privacy data query or transmission task, deeply imprinting group transformation properties within it.

[0144] Based on this random mask matrix, the system invokes multiplication operations of the non-commutative group to blind the sequence of ciphertext polynomial matrices carrying public officials' housing information. The system precisely calculates the cumulative noise norm, strictly constraining it within the legal decryption tolerance boundary of the non-commutative polynomial matrix group. This precise control ensures that personnel or housing management departments, when authorized to decrypt, can recover the original personal file information with 100% losslessness, avoiding mutations in critical data (such as property area and ID number) due to tolerance boundary overflow.

[0145] During cross-departmental data transfer, the system parses the path status parameters of the interaction between the e-government extranet and intranet, assigning them dedicated dynamic routing identifiers. Personal privacy data is then encapsulated into the application layer payload of a pre-defined communication protocol (such as an encrypted database synchronization protocol). Through secondary blinding processing of the application layer business header, algebraic operators completely hide structural information such as table names and column names in the message. The underlying network devices rely solely on the plaintext network layer routing header to deliver the quantum-resistant encrypted network layer data to the destination database, enabling the stealthy movement of public officials' core privacy data within the information platform.

[0146] Example 4: Quantum-resistant encrypted transmission of integrated security and logistics data streams based on an information platform

[0147] In this embodiment, we further extend our focus to the smart park logistics and security scenarios within the integrated information platform, with a focus on protecting continuous, high-concurrency streaming media and biometric data such as dining trajectories in the canteen, license plate recognition videos, and facial feature vectors.

[0148] In this scenario, front-end IoT sensing devices deployed in government canteens, parking lot gates, and access control points continuously generate heterogeneous data to be encrypted. The feature extraction model acts as a central hub for streaming media and biometric processing. For face and license plate data, the model's input parameters are a continuous matrix of video frame pixels, and its output parameters are a content feature matrix composed of highly abstract feature vectors (such as facial feature keypoint encoding and license plate character identifiers). For canteen dining trajectories, sequential features in a spatiotemporal coordinate system are extracted. A multidimensional tensor mapping algorithm encodes these multimodal features in real-time into a pre-defined non-commutative polynomial matrix group, forming a continuous sequence of initial group elements.

[0149] Streaming media and biometric data possess extremely high information entropy and extremely low sparsity. The system analyzes these statistical distribution parameters in real time. When a security baseline threshold is met, the system determines the current data modality to be continuous biosensing data, sets the corresponding error distribution probability, and samples frequently from a discrete Gaussian distribution to generate a series of coherent error multinomial matrices. These matrices are then superimposed onto the initial swarm element sequence to generate a dynamically fluctuating adjusted swarm element set. This perturbation mechanism significantly enhances resistance to replay attacks targeting unique biometric data such as facial features.

[0150] As security data flows, the system utilizes the public key parameters of the security subnet as conjugate elements to continuously perform conjugate transformation operations on the constantly generated adjusted set of group elements. The plaintext security data and trajectory information is rapidly converted into a complex sequence of ciphertext polynomial matrices within a non-commutative polynomial matrix group, making it impossible to reconstruct the facial features of any public officials or vehicle entry / exit records even when sniffing within a local area network.

[0151] When processing high-frequency concurrent security data, the chaotic sequence generation algorithm uses camera frame rate jitter and temperature and humidity sensor data as seeds to extract nonlinear features and generate a high-frequency dynamic noise vector sequence. After one-way hash mapping, the preset generator matrix is ​​combined with the noise vector to generate a rapidly iterating random mask matrix. This frequently updated mask ensures that each face swipe or license plate recognition has an independent encryption protection layer with embedded group transformation properties.

[0152] Based on the aforementioned random mask matrix, multiplication operations of non-commutative groups perform instantaneous blinding processing on the ciphertext polynomial matrix sequence, outputting an encrypted ciphertext sequence of the security target. To ensure both the continuity of the surveillance video stream and high accuracy of face comparison, the system applies extreme compression to the cumulative noise norm generated by the interleaving of the error polynomial matrix and the random mask matrix, ensuring it is far below the legal decryption tolerance boundary. This allows the platform's backend AI analysis server to still perform accurate face comparison and license plate recognition after legal decryption.

[0153] Given the complexity of security network architecture, the system extracts real-time path status parameters of video stream transmission (such as the microsecond-level latency from the monitoring subnet to the central computer room) to generate dynamic routing identifiers that ensure low-latency video transmission. The target encrypted ciphertext sequence is sliced ​​and encapsulated into the application layer payload of a preset communication protocol (such as Real-Time Streaming Protocol, RTSP). To completely hide the business attributes of the data (preventing external entities from identifying which data stream represents a face and which represents a license plate through traffic characteristics), the system uses algebraic operators to perform secondary blinding processing on the application layer business header of the security video stream. While maintaining plaintext in the network layer routing header to guide rapid exchange, a continuous stream of quantum-resistant encrypted network layer data is securely converged into the data lake of the information platform, constructing an impregnable logistical and security data defense line for government agencies.

[0154] See Figure 1-3 The present invention provides a quantum-resistant collaborative office encryption method and system based on non-commutative group transformation and perturbation mapping, which specifically includes:

[0155] S1: Obtain the heterogeneous data to be encrypted from the collaborative office system, generate a symmetric encryption key using intermediate parameters in the non-commutative polynomial matrix group transformation process, and use the symmetric encryption key to perform stream encryption processing on the heterogeneous data to be encrypted to obtain the original ciphertext; at the same time, extract its content feature matrix using a preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on the preset non-commutative polynomial matrix group through a multidimensional tensor mapping algorithm.

[0156] Heterogeneous data to be encrypted is obtained from a collaborative office system. The data is initially screened and organized using a pre-defined classification algorithm to obtain a categorized dataset. For each categorized dataset, a pre-defined feature extraction model is used to extract content features, generating a corresponding content feature matrix. Specifically, the feature extraction model is fine-tuned during the pre-training phase for OFD, PDF, and high-noise scanned images commonly found in government office scenarios. At the network's end, the original classification layer is removed and replaced with a linear mapping layer containing 1024 neurons, and a Dropout mechanism (dropout rate set to 0.3-0.5) is used to enhance the generalization ability of the feature vectors under heterogeneous data streams. This specific architecture ensures that even documents with slight formatting deviations or scanning noise maintain semantic center consistency in the high-dimensional feature space. By dividing the content feature matrix into blocks, each block is mapped to a multi-dimensional tensor, determining the data unit represented by the multi-dimensional tensor. A multidimensional tensor mapping algorithm is used to encode data units, transforming them into initial group elements on a preset non-commutative polynomial matrix group, resulting in an encoded element set. If the encoded element set satisfies a preset non-commutativity condition, it is further combined into a sequence to generate an initial group element sequence; otherwise, the process returns to the previous step of remapping the multidimensional tensor. Based on the initial group element sequence, a preset sequence verification algorithm is used to perform a consistency check to determine if the sequence conforms to preset structural requirements. The sequence data that passes the consistency check is obtained and saved to a designated database according to a preset storage strategy, completing the preparatory processing before data encryption.

[0157] In step S1, the following normalization preprocessing logic is adopted for heterogeneous data to be encrypted in different modalities: 1) For archival image data, bilinear interpolation is first used to scale it to 512×512 pixels, followed by grayscale processing and extraction of its pixel grayscale matrix; 2) For official document text data, a preset word vector model (such as BERT) is used to convert the text sequence into a 768-dimensional embedding vector, and zero-padding or truncation is performed to align it to a fixed length to form a text feature tensor; 3) For structured form data (such as personal information), numerical fields are normalized, category fields are one-hot encoded, and they are merged into a one-dimensional feature vector before matrix rearrangement. This preprocessing ensures that heterogeneous data has a unified mathematical expression dimension before entering the feature extraction model.

[0158] Specifically, the deep learning network with a linear mapping layer employs the following quantization mapping logic when encoding data units into initial group elements: first, the content feature matrix is ​​divided into blocks. Expand into one-dimensional feature vectors Then, each element in the vector Mapped to a polynomial quotient ring The coefficients in the polynomial are used to construct the polynomial. Finally, fill the resulting polynomials into the preset positions. In an empty matrix of dimension 1, the matrix is ​​ensured to be in a finite field by using diagonal padding techniques. The above satisfies the determinant The reversibility requirement is met. This mapping method ensures that the statistical properties of heterogeneous office data can be losslessly transformed into a non-commutative group algebraic structure, providing a stable input basis for resistance to quantum transformations.

[0159] In one embodiment, heterogeneous data to be encrypted is obtained from a collaborative office system.

[0160] For example, internal documents, spreadsheets, and image files within a company, such as employee reports, sales data, and design drawings, can be initially filtered and organized using pre-defined classification algorithms, such as those based on file type and content keywords, to obtain a categorized dataset. For instance, text data can be grouped into group A and numerical data into group B, thus facilitating subsequent processing.

[0161] For example, for a categorized dataset, a pre-defined feature extraction model is used to extract content features for each category of data. This model can be based on a deep learning-based convolutional neural network (CNN) framework.

[0162] Specifically, in the extraction process, the data is first input into the input layer of the model, and then local features are captured through convolutional layers, such as the frequency of keywords in text or the edge contours in images. Then, pooling layers reduce the dimensionality and generate the corresponding content feature matrix.

[0163] Furthermore, to meet the alignment requirements of mapping heterogeneous office data to the algebraic group space, the preset feature extraction model specifically adopts a fusion architecture combining ResNet-50 as the backbone extraction network and a multilayer perceptron (MLP). Its network input is configured to receive normalized data... A pixel matrix or a 768-dimensional text embedding vector. During the feature mapping stage, the network outputs a dimension of [missing value] through the last residual block. The high-dimensional feature tensor. To ensure model convergence under complex data streams, the model employs a triplet loss function during the training phase, with the calculation formula set as follows: This constraint minimizes the Euclidean distance between heterogeneous data with the same business semantics in the feature space, thereby providing a stable low-variance feature basis for subsequent multidimensional tensor mapping. The output of the linear mapping layer uses a nonlinear scaling factor. (where k is the dimension of the feature vector), quantizing the floating-point components in the high-dimensional feature tensor into the integer field. The discrete coefficients within the continuous feature space. This quantization strategy ensures that even in the presence of environmental noise (such as color cast of scanned documents or slight shifts in layout) in heterogeneous collaborative office data, the initial group element sequence mapped to the non-commutative polynomial matrix group can still maintain the consistency of classification and reconstruction, thereby avoiding decryption failure due to feature drift.

[0164] Specifically, in the feature mapping stage, the linear mapping layer employs the following parameterized quantization logic: setting the quantization step size. Where B is the bit width of the feature component, which is 10 in this embodiment. The floating-point feature vector... Convert to integer field After applying the coefficients, if the generated matrix A does not satisfy the condition after verification... Then, the diagonal compensation algorithm is executed: tiny perturbation values ​​are cyclically superimposed on the diagonal elements of the matrix. This continues until the invertibility condition of the group elements is met.

[0165] For example, if the quantized feature vector The first four components are [125, 430, 88, 210], and the matrix order is set. The initially constructed matrix Calculate its determinant. In the model In a finite field, If the result is 0, then the matrix is ​​directly used as the initial group element; if the result is 0, then the perturbation value is accumulated on the diagonal elements 125. Re-verify.

[0166] When processing heterogeneous office data, the Multilayer Perceptron (MLP) serves as a feature alignment layer. Its core logic lies in mapping the outputs of different modalities to the same linear space. Specifically, regardless of the input... Whether it's the archive image tensor or the 768-dimensional document text embedding vector, MLP forces the feature dimensions to align using a dynamically adjusted weight matrix. The standard feature vector. Then, the feature vector is rearranged using the quantization mapping logic to... The original feature matrix of dimension is obtained, thus ensuring that data of different modalities can be seamlessly entered into a unified non-commutative polynomial matrix group for algebraic operations, solving the stability problem of the difficulty in integrating heterogeneous data forms and group theory transformations.

[0167] Specifically, the multilayer perceptron (MLP) comprises a three-layer fully connected structure, wherein the number of input layer nodes dynamically adapts to the modal output dimension (image is...). (The text is 768), the hidden layer uses the ReLU activation function for non-linear feature projection, and the output layer is fixed at... Each node. By pre-training on a government and enterprise anonymized office dataset, the MLP learned to map the semantic cores of different modalities to a weight distribution in a unified tensor space, ensuring the standardization of subsequent group operations at the algebraic level.

[0168] Specifically, the multilayer perceptron is trained by minimizing the distance between semantic features of similar business in the feature space, enabling the model to learn the high-dimensional nonlinear mapping from heterogeneous raw inputs (such as pixel matrices or text embeddings) to non-commuting quotient ring coefficients. This training mechanism ensures that data from different modalities can achieve semantic alignment at the mathematical level, providing a stable feature basis for subsequent unified entry into non-commuting polynomial matrix group operations.

[0169] In a preferred embodiment, the specific architecture of the multilayer perceptron (MLP) is as follows: the input layer dimension is adapted to the feature vector k, and the hidden layer consists of two fully connected layers. The first layer contains 1024 neurons, and the second layer contains 512 neurons. Each layer is equipped with a ReLU activation function and a Dropout layer (dropout rate of 0.3). This deep mapping structure can effectively capture the high-order correlations of heterogeneous office data in the nonlinear space.

[0170] For example, for a sales report, keyword vectors such as "sales amount: 5000" and "date: 2023" can be extracted to form a two-dimensional matrix, where rows represent feature dimensions and columns represent data points. This quantifies the data content to support encryption preparation. This extraction can effectively identify the core information of the data, reduce redundancy, and improve processing efficiency.

[0171] In one embodiment, the data unit represented by the multidimensional tensor is determined by dividing the content feature matrix into blocks and mapping each block of data into a multidimensional tensor form.

[0172] For example, a matrix can be divided into 4x4 blocks, each of which is mapped to a three-dimensional tensor (height, width, and channels). For instance, a sales data block can be mapped to a tensor containing numerical, time, and category channels, thereby capturing multi-dimensional relationships.

[0173] For example, a multidimensional tensor mapping algorithm is used to encode data units, transforming them into initial group elements on a pre-defined non-commutative polynomial matrix group, resulting in an encoded set of elements. This algorithm is based on the principle of group theory, where non-commutativity refers to the fact that matrix multiplication does not satisfy the commutative law.

[0174] Specifically, the polynomial representation of the tensor is first calculated, such as fitting the tensor elements to a polynomial function, and then mapped to a matrix group, such as a subgroup of the GL(n) group, generating elements such as off-diagonal matrices. If the non-commutativity condition is satisfied, such as AB≠BA, then the elements are combined into a sequence; otherwise, they are remapped, thereby ensuring the security of the encoding.

[0175] To enable those skilled in the art to understand the specific mathematical logic behind the above mapping algorithm for constructing a quantum-resistant cryptographic foundation, the execution flow of the multidimensional tensor mapping algorithm is as follows: First, the system initializes the underlying algebraic ring of the preset non-commutative polynomial matrix group as a finite field. Polynomial quotient on Where n is a power of 2 parameter; subsequently, a norm-preserving mapping function is used. The aforementioned generated high-dimensional feature tensor Each local slice is mapped sequentially as The corresponding polynomial coefficient elements of a dimensional matrix Finally, the system performs group algebra verification on the generated initial matrix A using the diagonal-dominant algorithm. If its determinant satisfies... If the condition is met, then it is incorporated into the initial group element sequence; otherwise, perturbation values ​​are injected into the redundant dimensions of the tensor until the group invertibility requirement is met.

[0176] Specifically, in the group of noncommutative polynomial matrices in finite fields Noncommutative polynomial matrix group and its polynomial quotient ring noncommutative polynomial matrix group In the context of non-commutative polynomial matrix groups, the diagonal dominance algorithm is implemented by determining whether the number of non-zero coefficients or their norm of the polynomials in each row of the matrix are significantly greater than the corresponding parameters of the polynomials in other positions of that row. Since diagonal dominance is a sufficient but not necessary condition for a matrix to be invertible on the quotient ring, this check can quickly filter out polynomial matrix groups that satisfy the non-commutative polynomial matrix group requirement. ( The initial matrix of the non-commutative polynomial matrix group is used to ensure the invertibility and uniqueness of the group elements in the algebraic space.

[0177] When constructing the m×m initial matrix A, the system employs an asymmetric diagonal cross-filling logic: coprime primitive polynomial coefficients are preferentially injected at off-diagonal positions (i,j), and a discrete variant of the Gram-Schmidt orthogonalization process is used to perform nonlinear corrections on the matrix. This construction process ensures that any two generated group elements A and B do not satisfy the commutative law (i.e., AB≠BA) with a very high probability, thus providing a solid algebraic foundation for subsequent quantum conjugate transformations.

[0178] In one embodiment, the initial group element sequence is subjected to consistency detection by a preset sequence verification algorithm. This tool can be a hash function-based verifier to determine whether the sequence meets preset structural requirements, such as consistent length and element order.

[0179] For example, obtain sequence data that has passed the consistency check, and save it to a designated database according to a preset storage strategy to complete the preparatory processing before data encryption.

[0180] For example, encryption key indexes can be stored in a cloud database, thus providing a reliable foundation for subsequent encryption.

[0181] S2: Calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, determine the error distribution probability according to the data mode type of the heterogeneous data to be encrypted, and sample from the discrete Gaussian distribution to generate the error polynomial matrix with the corresponding norm limit. Superimpose the error polynomial matrix onto the initial group element sequence to generate the adjusted group element set.

[0182] By performing a structured decomposition on the adjusted set of group elements, core distribution patterns are extracted, and a corresponding distribution pattern matrix is ​​constructed to obtain a preliminary distribution pattern matrix. Based on this distribution pattern matrix, a stratified sampling method is used to prioritize the key elements in the matrix, determining the sorted key element sequence. If the element distribution in the key element sequence meets a preset uniformity threshold, vector mapping is performed on the key element sequence to generate a corresponding vector mapping result. For the vector mapping result, its matching degree with the initial content feature matrix is ​​obtained. If the matching degree reaches a preset matching threshold, a suitable vector mapping set is determined. From the vector mapping set, a new error correction matrix is ​​constructed using a sampling strategy based on discrete Gaussian distribution, resulting in a corrected error correction matrix. By superimposing the error correction matrix with the adjusted set of group elements, the final encryption protection matrix is ​​generated, and the integrity of the encryption protection matrix is ​​determined.

[0183] In this invention, the selection of the security baseline threshold and the error distribution probability follows the security constraints of lattice cipher. The preset parameter set includes the multinomial dimension n, the modulus q, and the standard deviation of the Gaussian distribution. To ensure escort safety, the parameters must be selected such that n is a power of 2 (e.g., 512 or 1024), and The coefficients in the error polynomial matrix From a mean of 0 and a variance of Discrete Gaussian distribution Mid-sampling. By setting... This ensures that even after multiple conjugate transformations, the accumulated noise terms can still be stripped away through modulo operations, thereby maintaining the correctness of encryption and decryption.

[0184] To balance the computational efficiency and quantum security of the collaborative office system, the preferred range for the polynomial dimension n is a power of 2 between 512 and 2048, and the modulus... Selected as satisfied Prime numbers with a bit length between 30 and 64 bits are preferred to support efficient number-theoretic transformations (NTT) for accelerated computation. The standard deviation of the discrete Gaussian distribution is also considered. The range is set within [3.2, 8.0]. This range has been verified by simulation to ensure that the cumulative noise norm is always kept within the legal decryption tolerance boundary while introducing sufficiently complex perturbations to resist conjugate search attacks (CSP).

[0185] In another embodiment, the security baseline threshold is set in tiers based on business sensitivity. For high-privacy modalities such as public officials' housing information and facial recognition data, the information entropy threshold... Set to 6.5, when the calculated information entropy At that time, the system automatically triggers a higher-order perturbation mechanism to adjust the standard deviation of the discrete Gaussian distribution. Increased to 1.5 times the baseline value; for image modal data such as scanned documents, its sparsity threshold is... Set to 0.85, when sparsity At that time, pseudo-random components are injected through the error polynomial matrix to ensure that a quantum security strength of more than 128 bits can be achieved under different data modes.

[0186] The aforementioned security baseline thresholds were determined based on statistical security experiments using office data: where the information entropy threshold... This ensures that the search space remains intact when the feature matrix is ​​subjected to a lattice-cutting attack (BKZ algorithm). Critical value of magnitude; sparsity threshold This is set based on the typical ratio of background pixels (zero values) to text feature pixels in official document images. In actual deployment, the system will fine-tune these parameters in real time according to the business security level: for example, when processing data of 'confidential' level or higher, the system will automatically adjust the settings. Increase by 20%, and simultaneously increase the discrete Gaussian sampling standard deviation. .

[0187] Should The threshold value was determined based on the statistical mean of the feature distribution of 100,000 standard government documents (OFD format). Experiments have shown that when the information entropy is higher than this value, the randomness of the feature matrix is ​​sufficient to resist heuristic lattice attacks based on the Shortest Vector Problem (SVP); while This is the critical point that distinguishes between "plain text documents" and "scanned documents containing images," guiding the system to select different noise injection intensities.

[0188] Specifically, the process for setting the security baseline threshold is as follows: A predetermined number of historical plaintext data samples from the office system are pre-acquired; the statistical distribution parameters of the content feature matrix of each sample are calculated; the value at the 85th percentile of the cumulative probability is extracted based on the normal distribution model as the initial threshold; and fine-tuning is performed within 10%-15% above or below the threshold based on the current business security level. This process ensures that the threshold setting can dynamically adapt to changes in the office data environment, rather than being a fixed, manually preset value.

[0189] In one possible implementation, the information entropy threshold It was determined through statistical analysis of a massive sample of government documents, and it represents the content feature matrix's ability to maintain its integrity when subjected to lattice-reduction attacks (such as the BKZ algorithm). The above represents a safety threshold for search complexity. When the measured information entropy falls below this value, the system will increase the standard deviation of the discrete Gaussian distribution. (e.g., from 3.2 to 5.0) to artificially compensate for randomness, thereby ensuring that the quantum resistance of the escorted data does not decrease due to the singularity of the original data characteristics.

[0190] It should be noted that the above and These are all preferred reference values ​​derived from statistical analysis of a large-scale sample of government documents. In actual deployment, the system can adjust these thresholds in real time through a preset parameter mapping function based on the security level of the office environment (such as "normal", "secret", or "confidential") or the sensitivity of the business scenario, in order to achieve a dynamic balance between encryption / decryption efficiency and quantum resistance strength.

[0191] In one possible implementation, the adjusted set of group elements is structurally decomposed by first dividing the set into multiple subsets. For example, when processing group elements of document and table data in a collaborative office system, they are separated according to data type, such as text and numerical values, thereby extracting the core distribution pattern.

[0192] Specifically, this decomposition is based on the principle of matrix factorization, where the core distribution pattern refers to the statistical regularity of elements in the non-commutative group. For example, principal component analysis is used to identify patterns. The process involves calculating the covariance matrix of the elements, and then obtaining the dominant pattern through eigenvalue decomposition, thereby constructing a distribution pattern matrix. The rows of this matrix represent the pattern dimension, and the columns represent the element weights, thus obtaining a preliminary distribution pattern matrix.

[0193] For example, based on the distribution pattern matrix, a stratified sampling method is used to prioritize the key elements in the matrix. This method first divides the matrix into high-frequency and low-frequency pattern layers, and then randomly samples and sorts within each layer to determine the sorted sequence of key elements. If the distribution of elements in the sequence meets a preset uniformity threshold, for example, when the threshold is set to 0.8, the variance of the sequence is calculated and compared. If it is less than the threshold, it is considered uniform. Then, the sequence is vector-mapped to generate the corresponding vector mapping result. This mapping can use an embedding function to project the elements into Euclidean space.

[0194] In one possible implementation, for the vector mapping result, its matching degree with the initial content feature matrix is ​​obtained, for example, by using cosine similarity calculation. The process includes vectorizing the two matrices, calculating their inner product, and dividing by the modulus. If the matching degree reaches a preset threshold, such as 0.9, then a suitable set of vector mappings is determined. From this set, a new error correction matrix is ​​constructed using a sampling strategy based on discrete Gaussian distribution. This strategy involves sampling error vectors from a Gaussian distribution and discretizing them, for example, sampling a distribution with a mean of 0 and a variance of 1 and adjusting it to integer form to obtain the corrected error correction matrix, thereby reducing noise interference in office data encryption.

[0195] For example, by superimposing the error correction matrix with the adjusted set of group elements, a final encryption protection matrix is ​​generated. This operation can be achieved by simply adding the elements of the two matrices to determine the integrity of the matrix, such as by checking that the determinant is non-zero to ensure invertibility, thereby achieving data protection. This method ensures the robustness of the encryption matrix.

[0196] S3: Using the system public key parameter as the conjugate element, perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group to obtain a sequence of ciphertext polynomial matrices.

[0197] The process begins by obtaining the system public key parameters and the adjusted set of group elements. Conjugate elements are defined for the public key parameters, and an initial conjugate transformation rule is determined through mapping on the non-commutative polynomial matrix group. Based on this rule, a conjugate operation is performed on each element in the group element set to obtain a pre-transformed matrix data sequence. This sequence undergoes structural verification. If the verification result indicates that the matrix sequence does not meet the non-commutativity requirement, a secondary adjustment is performed to obtain a compliant intermediate matrix sequence. Using this intermediate matrix sequence as the base data, a conjugate operation within the polynomial group is performed on each matrix element to determine the final target encrypted ciphertext sequence. Based on the final target encrypted ciphertext sequence and the system public key parameters, a formatting process is performed to generate a standardized ciphertext polynomial matrix sequence. Finally, an integrity check is performed on the standardized ciphertext polynomial matrix sequence. If data is missing or abnormal, a supplementary calculation process is triggered to obtain the complete ciphertext output sequence.

[0198] In one possible implementation, the system first obtains public key parameters such as the modulus q and the polynomial ring dimension n, and defines conjugate elements in combination with the adjusted set of group elements. For example, the basis element g in the public key parameters is mapped to its conjugate form g' through an inner automorphism, thereby determining the initial conjugate transformation rule.

[0199] For example, in the mapping process on a non-commutative polynomial matrix group, the group consists of n×n matrices whose elements are polynomials with coefficients over a finite field, and whose multiplication does not satisfy the commutative law.

[0200] Specifically, the conjugate transformation operation constructs an asymmetric cryptographic trapdoor mechanism based on the Conjugacy Search Problem (CSP). The system key generation center pre-selects the publicly available fundamental generator g from the group, and the target receiver generates a private, non-commutative, invertible matrix s as the private key, calculating the publicly available public key parameters. During the encryption transformation process, the system utilizes the public key parameter h and introduces a locally randomly generated temporary transform element r to apply a non-commutative conjugate operation with randomness to the feature element a in the group element set. Specifically, this involves calculating... As a result of the transformation, this rule ensures that even if an attacker intercepts the ciphertext data sequence and obtains the publicly available parameters g and h, without the private key s, the existing quantum Shor's Algorithm cannot solve the hidden subgroup problem of the non-commutative group in polynomial time. This builds a solid algebraic quantum-resistant barrier for collaborative office systems.

[0201] Specifically, the conjugate transformation The execution process is as follows: The system first uses a temporary random element r to locally shuffle the public key h, generating a transformation factor bound to the current session. Since matrix multiplication within a non-commutative group does not satisfy the commutative law (i.e., ... This operation allows the same feature element 'a' to generate ciphertext 'c' with completely different statistical characteristics at different times. At the decryption end, only the legitimate user holding the private key 's' can decrypt it. The effects of conjugate elements are counteracted, and quantum algorithms, when faced with such non-commutative group hidden subgroup problems, cannot achieve fast deciphering through large number prime factorization as they can with RSA modular exponentiation.

[0202] In this way, a conjugate operation is performed on each element in the group element set to obtain a preliminary transformed matrix data sequence. For example, assuming the group element set contains matrices A1 and A2, A1^h and A2^h are calculated to form a sequence S.

[0203] It should be noted that when performing structure verification on the matrix data sequence after the initial transformation, it is checked whether it satisfies noncommutativity, that is, to verify that any two elements AB ≠ BA. If it does not satisfy the condition, a secondary adjustment is performed, such as introducing a perturbation polynomial e to sample from the Gaussian distribution and superimpose it into the sequence to obtain the intermediate matrix sequence M, thereby ensuring the integrity of the group structure of the sequence.

[0204] In one embodiment, M is used as the base, and a conjugate operation within the polynomial group is performed on each matrix element. For example, the conjugate m_i^k of the group element k is applied to the element m_i of M to generate the final target encrypted ciphertext sequence C.

[0205] For example, C is formatted using the system's public key parameters, such as normalizing the coefficient modulo q, to ​​generate a standardized sequence C'. Integrity checks are performed; if a missing part is detected, supplementary calculations are triggered, such as resampling the missing portion, to obtain the complete output. This achieves secure ciphertext generation.

[0206] S4: Generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties.

[0207] Step 1: Construct an initial dynamic noise vector sequence using a chaotic sequence generation algorithm, and obtain a first noise sequence with nonlinear characteristics through iterative calculation. Step 2: Vectorize the first noise sequence using a preset transformation rule to obtain a structured second vector sequence. Step 3: Associate the second vector sequence with the generator matrix of the non-commutative polynomial matrix group using a one-way hash mapping algorithm to obtain a preliminary transformation matrix. Step 4: Based on the preliminary transformation matrix, embed specific group transformation attributes to generate a first mask matrix with random characteristics. Step 5: If the random characteristics of the first mask matrix meet a preset threshold condition, retain the matrix as the final result; otherwise, locally adjust the first mask matrix to obtain a second mask matrix. Step 6: Perform a consistency check on the second mask matrix to determine the matching degree between its embedded transformation attributes and the initial dynamic noise vector sequence, and obtain the final random mask matrix.

[0208] In one embodiment, a chaotic sequence generation algorithm is used to construct an initial dynamic noise vector sequence.

[0209] For example, by iteratively calculating the Logistic mapping function, setting an initial value x0=0.5 and a parameter μ=4, the sequence x_{n+1}=μ x_n (1-x_n) is generated, thus obtaining a first noisy sequence with nonlinear characteristics. This method ensures the chaotic behavior of the sequence and provides a basis for pseudo-randomness.

[0210] In iterative calculations, the initial value Select a value between 0.1 and 0.9, avoiding fixed points such as 0.25, 0.5, and 0.75; control parameters The region of strong chaos, ranging from 3.9 to 4.0, was selected to ensure that the generated noise sequence has an isotropic distribution in the phase space.

[0211] For example, for the first noise sequence, a preset transformation rule is applied for vectorization processing.

[0212] Specifically, the sequence elements are mapped to a vector space, and a one-dimensional sequence is transformed into a multi-dimensional structured second vector sequence through linear transformations such as matrix multiplication, which facilitates subsequent correlation calculations.

[0213] In one embodiment, a one-way hash mapping algorithm is used to associate the second vector sequence with the generator matrix of the non-commutative polynomial matrix group.

[0214] For example, the vector sequence is hashed using the SHA-256 hash function, and then modulo operations are performed element-wise with each element of the generator matrix to obtain a preliminary transformation matrix. This associative computation ensures the irreversibility and security of the matrix.

[0215] For example, based on the initial transformation matrix, specific group transformation properties are embedded to generate a first mask matrix with random characteristics.

[0216] Specifically, applying conjugate transformations to non-commutative groups such as the Brauer group incorporates random elements into the matrix structure, thereby enhancing the unpredictability of the mask.

[0217] In one embodiment, if the randomness of the first mask matrix satisfies a preset threshold condition, the matrix is ​​retained as the final result; otherwise, the first mask matrix is ​​locally adjusted.

[0218] For example, a second mask matrix can be obtained by adding Gaussian noise or element permutation. This adjustment mechanism optimizes the random distribution of the matrix.

[0219] For example, by performing a consistency check on the second mask matrix, the matching degree between its embedding transformation properties and the initial dynamic noise vector sequence can be determined, and the final random mask matrix can be obtained, thereby providing a reliable masking tool in encryption services and improving data protection effectiveness.

[0220] S5: Based on the random mask matrix, the ciphertext polynomial matrix sequence is blinded using multiplication operations of a non-commutative group, and the target encrypted ciphertext sequence is output. The cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted to satisfying... Within the legal decryption tolerance boundary.

[0221] A random mask matrix is ​​constructed using a pre-defined random generation algorithm, generating an initial mask data structure and outputting the mask matrix result. The mathematical definition of a non-commutative group is used to constrain the multiplication rules of the generated mask matrix result, determining the intermediate matrix data after computation. Blinding processing is performed on the intermediate matrix data and the input ciphertext polynomial matrix sequence to obtain a blinded ciphertext data sequence. The blinded ciphertext data sequence is obtained, and combined with the error polynomial data, the accumulated noise value is calculated, outputting the noise calculation result. If the noise calculation result exceeds the pre-defined fault tolerance range, the blinded ciphertext data sequence is adjusted, the noise value is recalculated, and it is determined whether the adjusted noise meets the requirements. Based on the comparison between the adjusted noise value and the fault tolerance range, the final target encrypted ciphertext sequence is generated, and the encrypted data output is determined.

[0222] In one embodiment, a random mask matrix is ​​constructed using a preset random generation algorithm. For example, a pseudo-random number generator is used in an encryption system to generate initial elements, thereby generating an initial mask data structure and outputting the mask matrix result to ensure the randomness of data processing.

[0223] In one embodiment, the mathematical definition of a non-commutative group is used to constrain the multiplication rules of the generated mask matrix result. A non-commutative group refers to a group structure in which matrix multiplication does not satisfy the commutative law. For example, in the matrix group GL(n,R), two matrices A and B satisfy AB ≠ BA. By constraining the operation rules through this definition, the mask matrix is ​​multiplied with a preset generator to determine the intermediate matrix data after the operation, thereby introducing non-commutativity into the encryption process to enhance security.

[0224] Specifically, the implementation of this constraint involves first selecting the primitives of a non-commutative polynomial matrix group, such as a 2x2 matrix group, where the elements are polynomial coefficients. Then, group multiplication is applied to the mask matrix, i.e., calculating M * G, where M is the mask matrix and G is the group generator. Intermediate matrix data is obtained through iterative multiplication. This process ensures the irreversibility of the operation and provides a basis for blinding processing in subsequent steps. For example, in practical business scenarios such as homomorphic encryption, this intermediate matrix can be used to protect user privacy data, avoid directly exposing the original information, and thus optimize the robustness of encryption.

[0225] In one embodiment, a blinding process is performed on the intermediate matrix data and the input ciphertext polynomial matrix sequence. The blinding process refers to hiding the real data by adding a random mask, such as multiplying the intermediate matrix and the ciphertext sequence element by element to obtain the blinded ciphertext data sequence.

[0226] In one embodiment, the blinded ciphertext data sequence is obtained and the accumulated noise value is calculated by combining the error polynomial data. For example, the noise calculation result is obtained by summing the coefficients of the error polynomial, thereby evaluating the encryption stability.

[0227] In one embodiment, if the noise calculation result exceeds the preset fault tolerance range, the blinded ciphertext data sequence is adjusted, for example, by recalculating the noise value through a scaling factor, and determining whether the adjusted noise meets the requirements, so as to maintain the fault tolerance capability of encryption.

[0228] Here, the "preset fault tolerance range" is rigorously quantified based on the infinity norm of the ciphertext matrix elements. The system monitors the accumulated noise matrix resulting from the superposition of the error polynomial and the random mask matrix in real time during computation. To ensure strong consistency of the final decryption algorithm, the system must ensure... The norm condition is always satisfied in quotient ring operations. If the calculated accumulated noise value exceeds the legal limit, a modulus switching mechanism is triggered, employing a linear scaling function. , map the ciphertext element \(c\) in the large modulus \(q\) space to the smaller prime modulus \(p\) space to forcibly suppress the noise within the legal limit; scale the polynomial coefficients of the current blinded ciphertext data sequence proportionally as a whole to forcibly suppress the noise within the legal limit, so as to achieve an optimal balance between combating quantum channel probes and maintaining the decryptability of the system.

[0229] In particular, since the linear proportional mapping adopted by the modulus switching mechanism is essentially a scalar multiplication operation, and the scalar matrix is located at the center (Center) of this non-commutative matrix group and commutes with any element in the group. Therefore, while compressing the noise norm, the modulus switching operation does not破坏 the original non-commutative homomorphism property of the ciphertext polynomial matrix, ensuring the continuity of the decryption logic.

[0230] The system linearly maps the high-noise ciphertext elements in the large modulus \(q\) space to the small modulus \(p\) space through the modulus switching mechanism, thereby forcibly compressing the absolute value of the non-linear chaotic noise and ensuring that the accumulated noise always remains within the legal fault tolerance limit. This closed-loop control ensures that even under long-distance unstable network transmissions or extremely high concurrent loads, office data can still be restored with high fidelity.

[0231] The specific execution steps of the modulus switching mechanism are as follows: when it is detected that the accumulated noise norm is close to the fault tolerance boundary , the system calculates the scaling factor , where \(p < q\) and \(p\) is a preset small modulus; then multiply all the polynomial coefficients of the ciphertext matrix by and round. This operation compresses the absolute value of the noise proportionally without changing the plaintext information carried by the ciphertext, reserving sufficient fault tolerance space for subsequent secondary blinding and long-distance transmission.

[0232] Specifically, the modulus switching mechanism uses a linear proportional mapping function to map the ciphertext element \(c\) in the large modulus \(q\) space to the small modulus \(p\) space. The mapping formula is expressed as , where \(p\) is a smaller prime number that meets the security requirements. This operation effectively filters the high-frequency tail jitter generated by non-linear chaotic noise during the encryption and decryption process by linearly scaling the ciphertext coefficients in the large modulus \(q\) space. This process not only compresses the absolute value of the noise, but also since both \(p\) and \(q\) are prime numbers that meet , it ensures that the algebraic homomorphism property of the non-commutative group transformation can still be maintained after scaling, suppressing the relative noise ratio (RNR) below the sampling threshold of the decryption discrimination circuit, thereby ensuring the accuracy of office data restoration under long-distance unstable network transmissions and extremely high loads.

[0233] To prove the stability of this mechanism in the noncommutative space, the noise evolution during the mode switching process satisfies the following relation: Because the present invention monitors the accumulated noise norm in step S5, it ensures... Always restricted to Within this range, therefore the scaled noise term The legal decryption fault tolerance boundary is still within the small module space. Within this range. This linear scaling not only compresses the absolute value of chaotic noise but also preserves the algebraic homomorphism of the non-commutative polynomial matrix group, avoiding the overflow of statistical characteristics of the encrypted data.

[0234] In one embodiment, the final target encrypted ciphertext sequence is generated based on the comparison between the adjusted noise value and the fault tolerance range, thereby determining the data output after encryption processing and achieving an efficient encryption process.

[0235] S6: Parse the current network transmission path status parameters and generate a dynamic routing identifier, encapsulate the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol, and construct an encrypted transmission message.

[0236] By parsing path state parameters in network transmission, the congestion level and latency parameters of the current path are obtained to determine the real-time status of the transmission path. Based on the real-time path status, a preset decision algorithm is used to generate dynamic route identifiers, resulting in a routing scheme suitable for the current network environment. For the dynamic route identifier, the corresponding routing path information is obtained, and the target encrypted ciphertext sequence is associated with the route identifier to determine whether it conforms to the requirements of the communication protocol. If it does, the embedding position of the encrypted ciphertext sequence is determined. The encrypted ciphertext sequence is embedded in the application layer payload of the communication protocol to construct the initial transmission message, resulting in a message structure containing encrypted data. The format of the initial transmission message is validated to determine whether the message structure is complete. If complete, the final encrypted transmission message is generated. The validation result of the final encrypted transmission message is obtained, and it is sent to the target node using a preset transmission control strategy to determine the message transmission priority and path selection. For changes in path status during transmission, feedback data from network transmission is obtained in real time to determine whether there is path congestion or latency anomalies. If so, the dynamic route identifier is adjusted, and a new routing scheme is generated.

[0237] In one possible implementation, by parsing the path status parameters in network transmission, the congestion notification field and timestamp information can be extracted from the packet header. For example, in the TCP protocol, the congestion level is represented by the ECN flag, and the delay parameter is calculated by RTT, thereby determining the real-time status of the transmission path. For example, when the path load rate exceeds 80%, it is marked as high congestion.

[0238] For example, the preset decision algorithm may involve a threshold comparison mechanism for the real-time status of the path. The decision algorithm is defined as follows: if the delay exceeds 50ms and the congestion level is higher than medium, the backup path is selected first, and a dynamic route identifier such as path ID "Route-A1" is generated to obtain a routing scheme suitable for the current network environment and ensure smooth data flow.

[0239] Furthermore, the decision algorithm employs a cost function model based on multidimensional weights: Where C represents the congestion level and D represents the delay parameter. and The preset values ​​are 0.6 and 0.4 respectively. When the Cost exceeds the preset security baseline threshold of 0.75, the system generates a new dynamic route identifier through the HMAC algorithm to achieve seamless switching of the transmission path and prevent traffic under fixed paths from being intercepted by quantum computing and subjected to offline brute-force attacks.

[0240] In one possible implementation, the process of obtaining the corresponding routing path information for a dynamic routing identifier requires associating the target encrypted ciphertext sequence with the routing identifier. For example, an identifier tag is added to the sequence's metadata. Then, it's determined whether the sequence meets the requirements of the communication protocol, such as checking if the sequence length is less than the protocol payload limit. If it does, the embedding position is determined to be a specific offset bit in the payload, thus seamlessly integrating the encrypted data and avoiding protocol conflicts. The principle of this association mechanism is to use the routing identifier as a key-value pair to map the sequence position. The specific analysis process includes first parsing the path node list of the identifier, then calculating the hash value of the sequence and the node matching degree. If the matching degree is greater than 0.9, the position is confirmed as legitimate. Furthermore, in business scenarios such as financial transaction networks, where unstable paths lead to data leakage, the consequences could be transaction delays or security risks. Position determination achieved through this method can effectively support the covert transmission of encrypted sequences. The technical goal is to improve network security, thereby reducing packet loss rate by up to 20% under high load environments.

[0241] For example, when embedding an encrypted ciphertext sequence in the application layer payload of a communication protocol, the initial transmission message can be constructed using a serialization method, inserting the ciphertext as a byte stream into the body of an HTTP POST request to obtain a message structure containing encrypted data.

[0242] In one possible implementation, the initial transmitted message is format-validated, such as by verifying the header checksum and length field. If the format is complete, the final encrypted transmitted message is generated.

[0243] For example, after obtaining the verification result of the final encrypted transmission message, a preset transmission control strategy, such as a QoS strategy, is used to send it to the target node, determining that the priority is high and selecting a low-latency path.

[0244] In one possible implementation, feedback data such as packet loss rate is acquired in real time in response to changes in path state during transmission. If congestion exists, the dynamic routing identifier is adjusted to generate a new scheme, thereby optimizing transmission efficiency.

[0245] S7: The application layer service header of the encrypted transmission message is subjected to secondary blinding processing using the algebraic operators of the non-commutative polynomial matrix group. While maintaining the plaintext parsability of the network layer routing header, the final quantum-resistant encrypted network layer data is generated.

[0246] Step 1: Obtain the application layer service header data in encrypted transmission. Using a non-commuting matrix as the basic structure, the data is initially grouped using the mathematical properties of the non-commuting polynomial matrix group to obtain the initially grouped payload header data blocks. Step 2: For the initially grouped payload header data blocks, perform a first blinding operation using algebraic operators. Transform the data blocks using the operational rules of the non-commuting matrix to determine the intermediate data result after the first blinding. Step 3: Starting from the intermediate data result after the first blinding, perform a second blinding process using the same algebraic operators. Combined with the dynamic adjustment mechanism of the non-commuting polynomial matrix group, the intermediate data is re-encrypted to determine the encrypted payload header data after the second blinding. Step 4: Obtain the network layer routing header data. If the routing header data has not been encrypted, it remains in plaintext. Verify its readability using a parsing tool to obtain plaintext parsable routing header data. Step 5: Based on the encrypted payload header data after the second blinding and the plaintext parsable routing header data, use a data reassembly algorithm to integrate the two to determine the reassembled network layer data structure. Step Six: For the recombined network layer data structure, use a quantum-resistant verification algorithm to perform security checks on the overall data. If the check results meet the preset security standards, the final quantum-resistant encrypted network layer data is generated.

[0247] In one possible implementation, the application layer service header data from the encrypted transmission is first obtained. For example, in a network communication system, this data includes fields such as protocol identifiers and sequence numbers. This data is then processed using a non-commutative matrix as the underlying structure. A non-commutative matrix is ​​a matrix form that does not satisfy the commutative law, where element operations such as A*B do not equal B*A, thus providing higher security.

[0248] Specifically, the mathematical properties of non-commutative polynomial matrix groups are used to initially group the data. For example, the load header data is divided into multiple blocks, each block corresponding to a polynomial coefficient. Grouping is achieved through group operations such as addition and multiplication modulo polynomial rings to obtain the initially grouped load header data blocks, thereby ensuring the independence of the data in subsequent transformations.

[0249] For example, in actual business operations, the first blinding operation is performed on these initially grouped payload header data blocks using algebraic operators. Algebraic operators here refer to linear transformation rules based on non-commutative matrices, such as multiplying the data block vector by a matrix. The transformation process involves element-wise calculations like v' = M * v, where M is the non-commutative matrix and v is the data vector. This operational rule is used to transform the data blocks and determine the intermediate data result after the first blinding. This blinding operation aims to hide the original data characteristics and reduce the risk of interception during network transmission. The application layer business header data includes file metadata, permission identifiers, and decryption fingerprints. During the second blinding process, the system extracts the FrameHeader of a preset communication protocol (such as HTTP / 2) and only performs non-commutative transformation on the business-customized header after the Payload length field, while retaining the standard Type and Flags fields. This 'partial masking' strategy allows intermediate network nodes (such as load balancers) to still perform forwarding based on plaintext routing headers, while attackers, even if they parse the protocol layer, cannot obtain the security level and category of the circulating files by analyzing the business headers. Starting from the intermediate data results after the first blinding, the same algebraic operators are used for the second blinding process. The intermediate data is then re-encrypted by combining the dynamic adjustment mechanism of the non-commutative polynomial matrix group. For example, the polynomial coefficients are dynamically adjusted according to the changes in network latency parameters to achieve re-encryption and determine the encrypted data of the load header after the second blinding, thereby enhancing the anti-reverse engineering capability in multiple rounds of processing.

[0250] The technical effect of this "partial masking" strategy is that by hiding sensitive business information (such as document classification and public official identification tags) in a custom header after secondary blinding, the statistical characteristics of collaborative office data flow at the network transmission layer are completely eliminated. Even if attackers use quantum computers to monitor the traffic in real time, they will not be able to infer the specific business logic of the internal transmission by analyzing the message length or header structure.

[0251] In one possible implementation, network layer routing header data is obtained. If unencrypted, it remains in plaintext. Its readability is verified using parsing tools such as a protocol analyzer, for example, by checking the integrity of IP address and port fields, resulting in plaintext parsable routing header data. Based on the encrypted payload header data after secondary blinding and the plaintext parsable routing header data, a data reassembly algorithm is used to integrate them. For example, byte-level concatenation places the encrypted portion in the payload area and the plaintext routing header in the header, determining the reassembled network layer data structure. The specific execution logic of the data reassembly algorithm is as follows: the encrypted payload header data after secondary blinding is inserted as a "padding" or "custom option field" in the communication protocol extension header. During the integration process, the system uses Cyclic Redundancy Check (CRC-32) to perform byte alignment and verification on the reassembled message. Because the network layer routing header remains in plaintext, intermediate nodes in the government intranet can quickly forward packets by parsing the flow identifier in the header without performing decryption, achieving decoupling between quantum-resistant encryption depth and the distribution efficiency of existing network infrastructure.

[0252] When the algebraic operator performs the secondary blinding process, the system captures the dynamic routing identifier generated in step S6 in real time as a seed for the blinding factor. When a network transmission path experiences congestion switching, the algebraic operator dynamically adjusts the transformation matrix of the non-commutative polynomial matrix group based on the asymmetric hash value of the routing identifier. This strong coupling mechanism of "cryptographic item-routing item" ensures that the characteristics of encrypted transmission messages on the physical link evolve dynamically with the transmission path, completely eliminating the fixed statistical characteristics that may be captured by traffic analysis technology during large-scale document circulation, and significantly improving the dynamic anti-eavesdropping capability in the government network environment.

[0253] Specifically, the dynamic routing identifier is obtained through a preset mapping function. The transformation kernel is converted into an algebraic operator, where the mapping function adopts a transformation kernel with algebraic operators. A linear congruential generator for the seed produces a set of polynomial coefficient vectors. This set of vectors directly determines the rotation angle and permutation order of the noncommutative matrix during the quadratic blinding process, thus ensuring that each switch in the physical path corresponds to a completely new set of header encryption logic.

[0254] This process establishes a strong coupling mechanism of "routing item-cryptographic item". When the network transmission path dynamically switches, the transformation kernel of the algebraic operator undergoes nonlinear evolution, causing the message characteristics on the physical link to change in real time, thereby completely eliminating the fixed statistical characteristics that may be captured by traffic analysis technology during large-scale document circulation.

[0255] For example, for the recombined network layer data structure, a quantum-resistant verification algorithm is used to perform security checks on the overall data. This algorithm involves simulating key strength checks under quantum attack scenarios, such as using Grover's algorithm to simulate whether the data resists search attacks. If the detection result meets preset security standards, such as a key length exceeding 256 bits, then the final quantum-resistant encrypted network layer data is generated, thus ensuring transmission security in the quantum computing era. This approach achieves efficient encrypted transmission.

[0256] To form a complete closed loop for encrypted transmission of collaborative office information, the system of this invention is also configured with a quantum-resistant ciphertext decryption and restoration process. When a legitimate receiving node in the collaborative office network captures the above encrypted transmission message, it performs the following decryption operations in sequence: Step 1: Parse the network layer routing header and verify the communication protocol, and strip the application layer payload of the message into a secure sandbox; Step 2: The receiving end uses the locally issued algebraic operator inverse to perform a secondary inverse blinding process on the application layer service header, restoring the original connection state containing encrypted data; Step 3: For the target encrypted ciphertext sequence in the payload, the receiving end extracts the corresponding private key matrix s and performs an inverse conjugate algebraic transformation operation, specifically calculating the matrix. This process removes the obfuscation caused by the public key and the external group transformation applied by the random element. After performing the inverse conjugate algebraic transformation, the receiver constructs a lattice basis matrix on the non-commutative quotient ring Rq, transforming the solved intermediate matrix into a vector representation in the lattice space. Since non-commutative group multiplication is not commutative, the system must strictly adhere to the left-to-right multiplication inversion rule during obfuscation removal, i.e., by calculating... Recover the initial features containing the perturbation.

[0257] Step 4: Introduce the preset Nearest Plane Algorithm to perform modulo reduction and grid alignment operations on the elements containing discrete Gaussian noise in the solved matrix, eliminate the error polynomial and dynamic mask noise accumulated within the legal decryption fault tolerance boundary, and restore the noise-free initial group element sequence.

[0258] Step 5: Finally, the inverse mapping function of the multidimensional tensor is called to reconstruct the decrypted initial group element sequence into a content feature matrix. Combined with the symmetric key derived from the non-commutative polynomial matrix group transformation process, the original ciphertext is decrypted to complete the high-fidelity restoration output of collaborative office heterogeneous data.

[0259] In the grid alignment operation, the receiver uses the private key matrix s to construct the accompanying grid. Treating the noisy element c' obtained by the solution as a continuous point in space, the lattice is found using the nearest plane algorithm. The integer lattice point with the smallest c' norm at mid-range. Since S5 has already limited the noise norm to within a certain range during the encryption phase through a modulus switching mechanism. Within this range, based on the unique decoding distance limit of lattice ciphers, this operation can strip away discrete Gaussian noise with an exponential success rate, thereby obtaining accurate initial polynomial coefficients.

[0260] See Figure 4 The present invention also provides a quantum-resistant collaborative office encryption system based on non-commutative group transformation and perturbation mapping, which mainly includes:

[0261] The data acquisition and encoding module is used to acquire heterogeneous data to be encrypted in the collaborative office system, extract its content feature matrix using a preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on a preset non-commutative polynomial matrix group through a multidimensional tensor mapping algorithm.

[0262] The statistical analysis and error superposition module is used to calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, the error distribution probability is determined according to the data mode type of the heterogeneous data to be encrypted, and the error polynomial matrix corresponding to the norm limit is generated by sampling from the discrete Gaussian distribution. The error polynomial matrix is ​​superimposed on the initial group element sequence to generate the adjusted group element set.

[0263] The conjugate transformation encryption module is used to perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group using the system public key parameter as the conjugate element, to obtain a sequence of ciphertext polynomial matrices.

[0264] The dynamic noise mask generation module is used to generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and to perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties.

[0265] The blinding processing module is used to perform blinding processing on the ciphertext polynomial matrix sequence based on the random mask matrix using the multiplication operation of the non-commutative group, and output the target encrypted ciphertext sequence, wherein the cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted within the legal decryption fault tolerance boundary of the non-commutative polynomial matrix group.

[0266] The message encapsulation module is used to parse the current network transmission path status parameters and generate a dynamic routing identifier, and encapsulate the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol to construct an encrypted transmission message;

[0267] The secondary blinding and data generation module is used to perform secondary blinding processing on the application layer service header of the encrypted transmission message using the algebraic operators of the non-commutative polynomial matrix group, and generate the final quantum-resistant encrypted network layer data while keeping the plaintext of the network layer routing header parseable.

[0268] The feature extraction model described in this invention employs specific data augmentation techniques during training. By applying random rotations, noise simulation, and layout offsets to the scanned official documents, the feature matrix extracted by the model exhibits topological invariance. This characteristic, combined with a fault-tolerant boundary mechanism for non-commutative groups, solves the vulnerability problem of traditional encryption, which is extremely sensitive to input data and cannot be decrypted even with a single error. This makes it particularly suitable for high-load, noisy government and enterprise network environments.

[0269] This invention addresses the inherent limitations of single-technology approaches by cross-disciplinaryly integrating the "Learning Tolerance Problem (LWE)" of lattice ciphers with the "Conjugate Search Problem (CSP)" of noncommutative groups. It overcomes the bottleneck in office network communication caused by ciphertext expansion in traditional lattice ciphers and solves the shortcoming of traditional noncommutative ciphers in defending against chosen-ciphertext attacks due to the lack of effective perturbations. In the high-frequency heterogeneous data scenario of government and enterprise collaborative office work, it achieves a synergistic leap in security level and processing efficiency.

[0270] The above description is merely a specific implementation of this specification. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the scope of protection of this specification is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this specification, and these modifications or substitutions should all be covered within the scope of protection of this specification.

Claims

1. A quantum-resistant collaborative office encryption method based on noncommutative group transformation and perturbation mapping, characterized in that, The method includes: S1: Obtain heterogeneous data to be encrypted from the collaborative office system, generate a symmetric encryption key using intermediate parameters in the non-commutative polynomial matrix group transformation process, and use the symmetric encryption key to perform stream encryption on the heterogeneous data to be encrypted to obtain the original ciphertext; at the same time, extract its content feature matrix using a preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on the preset non-commutative polynomial matrix group through a multidimensional tensor mapping algorithm; S2: Calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, determine the error distribution probability according to the data mode type of the heterogeneous data to be encrypted, and sample from the discrete Gaussian distribution to generate the error polynomial matrix with the corresponding norm limit. Superimpose the error polynomial matrix into the initial group element sequence to generate the adjusted group element set. S3: Using the system public key parameter as the conjugate element, perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group to obtain a sequence of ciphertext polynomial matrices. S4: Generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties. S5: Based on the random mask matrix, the ciphertext polynomial matrix sequence is blinded using the multiplication operation of the non-commuting group to output the target encrypted ciphertext sequence, wherein the cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted within the legal decryption tolerance boundary of the non-commuting polynomial matrix group.

2. The method according to claim 1, characterized in that, Also includes: S6: Obtain the feedback status parameters of the current network transmission path and generate a dynamic routing identifier accordingly. Encapsulate the original ciphertext and the target encrypted ciphertext sequence into the application layer payload of the preset communication protocol to construct an encrypted transmission message.

3. The method according to claim 2, characterized in that, Also includes: S7: The application layer service header of the encrypted transmission message is subjected to secondary blinding processing using the algebraic operators of the non-commutative polynomial matrix group. While maintaining the plaintext parsability of the network layer routing header, the final quantum-resistant encrypted network layer data is generated.

4. The method according to claim 3, characterized in that, S1 includes: Obtain heterogeneous data to be encrypted from the collaborative office system, perform preliminary screening and sorting of the data using a preset classification algorithm, and obtain a classified data set; For the categorized dataset, a pre-defined feature extraction model is used to extract content features for each category of data, generating a corresponding content feature matrix. By dividing the content feature matrix into blocks, each block of data is mapped into a multidimensional tensor form, and the data unit represented by the multidimensional tensor is determined. The data units are encoded using a multidimensional tensor mapping algorithm, which transforms them into initial group elements on a pre-defined non-commutative polynomial matrix group, resulting in an encoded set of elements. If the encoded set of elements satisfies the preset noncommutativity condition, the elements that satisfy the condition are combined into an initial group element sequence; if not, the mapping parameters of the multidimensional tensor mapping algorithm are adjusted and re-encoded until an initial group element sequence that satisfies the condition is obtained. Based on the initial group element sequence, a consistency check is performed on it using a preset sequence verification algorithm to determine whether the sequence meets the preset structural requirements; Once the sequence data that has passed the consistency check is obtained, it is saved to the specified database according to the preset storage strategy, thus completing the preparatory processing before data encryption.

5. The method according to claim 3, characterized in that, S2 includes: By performing a structured decomposition on the adjusted set of group elements, the core distribution patterns are extracted, and the corresponding distribution pattern matrix is ​​constructed to obtain a preliminary distribution pattern matrix. Based on the distribution pattern matrix, a stratified sampling method is used to prioritize the key elements in the matrix and determine the sequence of key elements after prioritization. If the element distribution in the key element sequence meets a preset uniformity threshold, then a corresponding vector mapping result is generated by performing vector mapping on the key element sequence. For the vector mapping result, obtain its matching degree with the initial content feature matrix. If the matching degree reaches the preset matching threshold, determine the appropriate vector mapping set. From the set of vector maps, a new error correction matrix is ​​constructed using a sampling strategy based on discrete Gaussian distribution, resulting in the corrected error correction matrix; The final encryption protection matrix is ​​generated by superimposing the error correction matrix with the adjusted group element set, thus ensuring the integrity of the encryption protection matrix.

6. The method according to claim 3, characterized in that, S3 includes: Obtain the system public key parameters and the adjusted set of group elements, define conjugate elements for the public key parameters, and determine the initial conjugate transformation rules through mapping processing on the non-commutative polynomial matrix group; According to the initial conjugate transformation rule, the conjugate operation is performed on each element in the group element set to obtain the matrix data sequence after the initial transformation. By performing a structure check on the matrix data sequence after the initial transformation, if the check result shows that the matrix sequence does not meet the non-commutativity requirement, the matrix data sequence is adjusted a second time to obtain an intermediate matrix sequence that meets the requirements. Using the intermediate matrix sequence as the basic data, the conjugate operation within the polynomial group is performed on each matrix element to determine the final target encrypted ciphertext sequence. Based on the final target encrypted ciphertext sequence, and combined with the system public key parameters, a standardized ciphertext polynomial matrix sequence is generated. By performing integrity checks on the standardized ciphertext polynomial matrix sequence, if data is found to be missing or abnormal, a supplementary calculation process is triggered to obtain the complete ciphertext output sequence.

7. The method according to claim 3, characterized in that, S5 includes: A random mask matrix is ​​constructed using a preset random generation algorithm, an initial mask data structure is generated, and the mask matrix result is output. The mathematical definition of a non-commutative group is used to constrain the multiplication rules of the generated mask matrix result, thereby determining the intermediate matrix data after the operation. Blinding is performed on the intermediate matrix data and the input ciphertext polynomial matrix sequence to obtain the blinded ciphertext data sequence; Obtain the blinded ciphertext data sequence, combine it with the error polynomial data, calculate the accumulated noise value, and output the noise calculation result; If the noise calculation result exceeds the preset fault tolerance range, the blinded ciphertext data sequence is adjusted, the noise value is recalculated, and it is determined whether the adjusted noise meets the requirements. Based on the comparison between the adjusted noise value and the fault tolerance range, the final target encrypted ciphertext sequence is generated, and the data output after encryption processing is determined.

8. A quantum-resistant collaborative office encryption system based on non-commutative group transformation and perturbation mapping, characterized in that, The system includes: The data acquisition and encoding module is used to acquire heterogeneous data to be encrypted in the collaborative office system, extract its content feature matrix using a preset feature extraction model and divide it into blocks, and encode each data block into an initial group element sequence on a preset non-commutative polynomial matrix group through a multidimensional tensor mapping algorithm. The statistical analysis and error superposition module is used to calculate the sparsity and information entropy of the content feature matrix as statistical distribution parameters. When the statistical distribution parameters meet the preset security baseline threshold, the error distribution probability is determined according to the data mode type of the heterogeneous data to be encrypted, and the error polynomial matrix corresponding to the norm limit is generated by sampling from the discrete Gaussian distribution. The error polynomial matrix is ​​superimposed on the initial group element sequence to generate the adjusted group element set. The conjugate transformation encryption module is used to perform a conjugate transformation operation on the adjusted group element set on the non-commutative polynomial matrix group using the system public key parameter as the conjugate element, to obtain a sequence of ciphertext polynomial matrices. The dynamic noise mask generation module is used to generate a dynamic noise vector sequence containing nonlinear features using a chaotic sequence generation algorithm, and to perform a one-way hash mapping between the dynamic noise vector sequence and the preset generator matrix of the non-commutative polynomial matrix group to obtain a random mask matrix with embedded group transformation properties. The blinding processing module is used to perform blinding processing on the ciphertext polynomial matrix sequence based on the random mask matrix using the multiplication operation of the non-commutative group, and output the target encrypted ciphertext sequence, wherein the cumulative noise norm of the error polynomial matrix and the random mask matrix is ​​restricted within the legal decryption fault tolerance boundary of the non-commutative polynomial matrix group. The message encapsulation module is used to parse the current network transmission path status parameters and generate a dynamic routing identifier, and encapsulate the target encrypted ciphertext sequence into the application layer payload of a preset communication protocol to construct an encrypted transmission message; The secondary blinding and data generation module is used to perform secondary blinding processing on the application layer service header of the encrypted transmission message using the algebraic operators of the non-commutative polynomial matrix group, and generate the final quantum-resistant encrypted network layer data while keeping the plaintext of the network layer routing header parseable.

9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program for performing the method described in any one of claims 1-8.

10. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of claims 1-8.