Decentralization point-to-point encryption communication and anti-attack method based on quantum computing

By implementing the decentralized point-to-point encrypted communication protocol on the blockchain, the problem of trusting single point and quantum computing threats in the existing communication protocols is solved, and a highly secure and attack-resistant encrypted communication system is realized, which is suitable for scenarios with high security requirements.

CN120017264APending Publication Date: 2025-05-16CHENGDU EXEL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510186902.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing communication protocol relies on a centralized CA certificate system, which poses the risk of trusting single point of risk and traffic analysis attacks. Quantum computing poses a threat to traditional public key encryption, making it difficult to achieve decentralized, quantum-resistant, and trustless encrypted communications of third parties.

Method used

The blockchain-based decentralized point-to-point encryption communication protocol is adopted to generate decentralized identities by users, complete identity verification with revocable anonymous credentials, conduct blockchain-based key negotiation and storage, adopt dual-layer encryption and decentralized storage, and prevent traffic analysis through obfuscating transactions.

Benefits of technology

A highly secure and attack-resistant encrypted communication system has been built, which is suitable for scenarios with high security needs, such as decentralized social networking, financial transactions, government communications, etc., and has realized decentralized and quantum computing-resistant encrypted communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017264A_ABST
    Figure CN120017264A_ABST
Patent Text Reader

Abstract

The invention provides a decentralized point-to-point encryption communication and anti-attack method based on quantum computing, and belongs to the technical field of information security, and the method comprises the steps: user identity registration: a user generates a decentralized identity; the user uses the revocable anonymous voucher to complete identity verification; secure key exchange: carrying out key negotiation; storing the public key based on the block chain; message encryption transmission: double-layer encryption is used; decentralized storage is adopted; and flow analysis is prevented. Through the technologies of DID identity authentication, post-quantum key exchange, intelligent contract trust anchor, decentralized storage, privacy protection and the like, a highly-safe and anti-attack encryption communication system is constructed. The protocol is suitable for scenes with high security requirements, such as decentralized social contact, financial transaction, government communication and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a decentralized point-to-point encrypted communication and anti-attack method based on quantum computing. Background Art

[0002] The current mainstream communication protocols (such as TLS and HTTPS) rely on a centralized CA certificate system, which poses a single point of trust risk and is vulnerable to MITM attacks. In addition, the development of quantum computing technology poses a threat to traditional public key encryption (such as RSA and ECC). Although point-to-point encrypted communications (such as the Signal protocol) provide end-to-end encryption, they still rely on servers for key exchange and pose a risk of traffic analysis attacks.

[0003] Therefore, there is an urgent need for a decentralized, quantum-resistant, and third-party-free encrypted communication protocol in this field.

[0004] The information disclosed in this background technology section is only intended to enhance the understanding of the overall background of the invention and should not be regarded as an acknowledgment or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the invention

[0005] The purpose of the present invention is to provide a decentralized peer-to-peer encrypted communication protocol based on blockchain.

[0006] To achieve the above object, the present invention provides the following solutions:

[0007] A decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing, comprising:

[0008] User identity registration: users generate decentralized identities; users complete identity authentication using revocable anonymous credentials;

[0009] Secure key exchange: perform key negotiation; store public keys based on blockchain;

[0010] Encrypted message transmission: use double-layer encryption; adopt decentralized storage; prevent traffic analysis.

[0011] Optionally, the user generating a decentralized identity includes:

[0012] Use zero-knowledge proof to generate identity credentials, without the need for a centralized CA;

[0013] The identity public key hash is stored on the blockchain, and the private key is managed locally by the user.

[0014] Optionally, the performing key negotiation includes:

[0015] A shared key is generated using a lattice-based post-quantum key exchange algorithm, which is authenticated by a DID plus smart contract.

[0016] Optionally, the blockchain-based storage of public keys includes:

[0017] Store public key hash values ​​in smart contracts; use zk-SNARK to prove the correctness of key exchange and prevent replay attacks.

[0018] Optionally, the using of double-layer encryption includes:

[0019] The first layer: protecting session keys based on post-quantum public key encryption;

[0020] The second layer: symmetric encryption, used for data transmission.

[0021] Optionally, the decentralized storage includes:

[0022] The sender encrypts the message and stores it in IPFS, generating a unique CID;

[0023] The receiver verifies the DID and decrypts the data using proxy re-encryption.

[0024] Optionally, the preventing traffic analysis includes:

[0025] Obfuscated transactions are used to make it impossible for external observers to analyze communication patterns.

[0026] Compared with the prior art, the present invention has the following beneficial effects:

[0027] The present invention proposes a decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing, including: user identity registration: users generate decentralized identities; users use revocable anonymous credentials to complete identity authentication; secure key exchange: key negotiation; public key storage based on blockchain; message encryption transmission: using double-layer encryption; using decentralized storage; preventing traffic analysis. The present invention constructs a highly secure and attack-resistant encrypted communication system through technologies such as DID identity authentication, post-quantum key exchange, smart contract trust anchor, decentralized storage, and privacy protection. The protocol is suitable for scenarios with high security requirements, such as decentralized social networking, financial transactions, and government communications. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0029] Figure 1 A schematic diagram of a method flow chart provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0030] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0031] The purpose of the present invention is to provide a decentralized peer-to-peer encrypted communication protocol based on blockchain.

[0032] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0033] Embodiment 1:

[0034] This embodiment provides a decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing, such as Figure 1 As shown, including:

[0035] 1. User identity registration:

[0036] (1) User-generated decentralized identity (DID):

[0037] Use zero-knowledge proof (ZKP) to generate identity credentials without the need for a centralized CA:

[0038] The identity public key hash is stored on the blockchain, and the private key is managed locally by the user.

[0039] (2) The user completes identity authentication using revocable anonymous credentials:

[0040] Allow users to selectively disclose identity attributes without exposing all identity information.

[0041] 2. Secure key exchange (post-quantum key exchange protocol)

[0042] (1) A and B negotiate a key:

[0043] Generate a shared secret key using a lattice-based post-quantum key exchange algorithm such as KYBER.

[0044] The shared key does not rely on traditional public key infrastructure (PKI), but is authenticated through DID+smart contract.

[0045] (2) Public key storage based on blockchain (trust anchor):

[0046] A and B store public key hashes in the smart contract to prevent MITM attacks.

[0047] zk-SNARK is used to prove the correctness of key exchange and prevent replay attacks.

[0048] 3. Message encryption transmission

[0049] (1) Use double-layer encryption:

[0050] First layer: protecting session keys based on post-quantum public key cryptography (FALCON or KYBER).

[0051] Second layer: Symmetric encryption (AES-GCM or ChaCha20-Poly1305) is used for data transmission.

[0052] (2) Using decentralized storage (IPFS+Proxy Re-encryption):

[0053] The sender encrypts the message and stores it in IPFS, generating a unique CID (content identifier).

[0054] The receiver verifies the DID and decrypts the data using proxy re-encryption.

[0055] (3) Prevent traffic analysis:

[0056] Use Mimblewimble or zk-SNARK to obfuscate transactions, making it impossible for external observers to analyze communication patterns.

[0057] The present invention provides a ZTBP-256 attack-resistant blockchain communication protocol cryptography algorithm.

[0058] This algorithm includes four core modules: identity authentication, key exchange, message encryption, and trust anchor storage. It uses post-quantum cryptography and blockchain smart contracts for anti-attack communication encryption.

[0059] 1. Identity authentication (DID + zero-knowledge proof)

[0060] zk-SNARK is used for identity verification to ensure that users can prove their legitimacy without revealing their specific identity.

[0061] Mathematical model:

[0062] set up:

[0063] User identity is represented by a public-private key pair.

[0064] Use a hash function to generate an identity commitment:

[0065] C_A=H(ID_A||pk_A)

[0066] Code example:

[0067] zk-SNARK proofs using ZoKrates.

[0068] 2. Post-quantum key exchange (Kyber-1024)

[0069] Kyber-1024 (NIST standard post-quantum public key encryption algorithm) is used for secure key exchange.

[0070] Mathematical model:

[0071] Kyber-1024 uses lattice cryptography to calculate the shared secret key:

[0072]

[0073] K_{shared}=H(s_A\cdots_B)

[0074] Code example:

[0075] Use pqc_kyber for Kyber key exchange: from py_ecc.bn128 import add,multiply,G1

[0076] from hashlib import sha256

[0077] #Generate identity hash commitment

[0078] def hash_identity(identity,public_key):return sha256(identity.encode()+

[0079] public_key).hexdigest()

[0080] #Generate zero-knowledge proof (simulation)

[0081] def zk_proof(private_key,public_key):assert multiply(G1,private_key)==

[0082] public key, "Invalid proof" return "ZK PROOF VALID"

[0083] # Example User

[0084] identity="user123"

[0085] #Private Key

[0086] private key = 123456789 public key = multiply (G1, private_key) # calculate the public key

[0087] # Calculate the identity hash

[0088] commitment=hash_identity(identity,

[0089] public_key)

[0090] proof=zk_proof(private_key public_key)

[0091] print("Identity commitment:", commitment)

[0092] print("Zero-knowledge proof:", proof)

[0093] from pqcrypto.kem.kyber1024 import

[0094] generate_keypair,encrypt,decrypt

[0095] #Generate a key pair

[0096] pk_A, sk_A=generate_keypair()

[0097] pk B, sk_B=generate_keypair()

[0098] #A sends a key request, B generates a key and encrypts it

[0099] ciphertext, shared secretB=

[0100] encrypt(pk_A)

[0101] #A decrypts to obtain the shared key

[0102] shared secret_A=decrypt(ciphertext

[0103] sk_A)

[0104] print("Shared key A:"

[0105] shared secret_A.hex())

[0106] print("Shared Key B:"

[0107] shared secret B.hex())

[0108] assert shared secret A==

[0109] shared secret B, "key exchange failed"

[0110] 3. Message encryption (FALCON-1024+AES-GCM-256)

[0111] The session key is encrypted using FALCON-1024 (post-quantum public key encryption), and the communication data is encrypted using AES-GCM-256.

[0112] Mathematical model:

[0113] 1. Generate FALCON-1024 key pair:

[0114] (pk_F,sk_F)=\text{FALCON.KeyGen()}

[0115] Enc_K=\text{FALCON.Enc}(pk_F,K)

[0116] C=\text{AES-GCM}(K,M)

[0117] Code example:

[0118] from pqcrypto.sign.falcon1024 import generate_keypair,sign,verifyfrom cryptography.hazmat.primitives.ciphers.aead import AESGCM import os

[0119] #Generate FALCON-1024 key pair

[0120] pk_F,sk_F=generate_keypair()

[0121] #Generate a symmetric key

[0122] session_key=os.urandom(32)#256-bit AES key

[0123] #FALCON-1024 Encrypted Session Key

[0124] signature=sign(session_key,sk_F)

[0125] #AES-GCM-256 encrypted data

[0126] aesgcm=AESGCM(session_key)

[0127] nonce = os.urandom(12)

[0128] message=b"Secure Message"

[0129] ciphertext=aesgcm.encrypt(nonce,message,None)

[0130] print("Signature:",signature.hex())

[0131] print("Encrypted message:",ciphertext.hex())

[0132] #The receiver verifies the signature and decrypts

[0133] assert verify(session_key,signature,pk_F),"Invalid signature"decrypted_message=aesgcm.decrypt(nonce,ciphertext,None)print("Decrypted message:",decrypted_message.decode())

[0134] 4. Trust Anchor (smart contract stores public key)

[0135] Use Solidity smart contracts to store public key hashes to prevent MITM attacks.

[0136] Mathematical model:

[0137] 1. Calculate the public key hash:

[0138] H(pk)=\text{Keccak256}(pk)

[0139] mapping(address=>bytes32)public publicKeys;

[0140] function storePublicKey(bytes32 publicKeyHash)public{

[0141] publicKeys[msg.sender]=publicKeyHash;

[0142] }

[0143] Code example:

[0144] Solidity Smart Contracts:

[0145] / / SPDX-License-Identifier:MIT

[0146] pragma solidity^0.8.0;

[0147] contract TrustAnchor{

[0148] mapping(address=>bytes32)public publicKeys;

[0149] function storePublicKey(bytes32 publicKeyHash)public{

[0150] publicKeys[msg.sender]=publicKeyHash;

[0151] }

[0152] function verifyPublicKey(address user,bytes32 publicKeyHash)publicview returns(bool){

[0153] return publicKeys[user]==publicKeyHash;

[0154] }

[0155] }

[0156] 5. Anti-traffic analysis (zk-SNARK obfuscation)

[0157] Use zk-SNARK to generate zero-knowledge proof and hide communication data.

[0158] Mathematical model:

[0159] \pi = ZK_{SNARK}(\text{communication path})

[0160] \text{Verifier}\rightarrow\text{Blockchain}:\text{verify}(\pi)]

[0161] Code example:

[0162] Generate a zk-SNARK proof using ZoKrates:

[0163] from zokrates_pycrypto import ProofSystem

[0164] #Generate zero-knowledge proof

[0165] proof=ProofSystem.generate_proof("message_hash","secret_nonce")

[0166] #Verify the proof

[0167] valid=ProofSystem.verify_proof(proof)

[0168] print("Zero-knowledge proof:",proof)

[0169] print("Verification result:",valid)

[0170] 6. Conclusion

[0171] ZTBP-256 Pass:

[0172] DID+zk-SNARK for identity authentication;

[0173] Kyber-1024 for quantum-resistant key exchange;

[0174] FALCON-1024+AES-GCM-256 for double-layer encryption;

[0175] Smart contracts store public keys to prevent MITM attacks;

[0176] zk-SNARKs obfuscate traffic to prevent data analysis.

[0177] Suitable for high-security applications such as blockchain, decentralized communications, and quantum-resistant computing.

[0178] The application scenarios of this embodiment include:

[0179] High-security communications (such as government, finance, and military).

[0180] Decentralized social platform (no centralized server is required to manage user data).

[0181] Web3 applications (smart contract-driven anonymous authentication and encrypted communication).

[0182] Quantum-resistant computing environment (ensuring communication security for decades to come).

[0183] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0184] The principles and implementation methods of the present invention are described in this article using specific examples. The description of the above embodiments is only used to help understand the method and core idea of ​​the present invention. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present invention.

Claims

1. A decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing, characterized in that: include: User identity registration: users generate decentralized identities; The user authenticates using revocable anonymous credentials; Secure key exchange: perform key negotiation; Public key storage based on blockchain; Message encryption transmission: using double-layer encryption; Adopt decentralized storage; Prevent traffic analysis.

2. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The user generates a decentralized identity including: Use zero-knowledge proof to generate identity credentials, without the need for a centralized CA; The identity public key hash is stored on the blockchain, and the private key is managed locally by the user.

3. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The key negotiation comprises: A shared key is generated using a lattice-based post-quantum key exchange algorithm, which is authenticated by a DID plus smart contract.

4. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The blockchain-based public key storage includes: Store public key hash values ​​in smart contracts; use zk-SNARK to prove the correctness of key exchange and prevent replay attacks.

5. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The use of double-layer encryption includes: The first layer: protecting session keys based on post-quantum public key encryption; The second layer: symmetric encryption, used for data transmission.

6. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The decentralized storage includes: The sender encrypts the message and stores it in IPFS, generating a unique CID; The receiver verifies the DID and decrypts the data using proxy re-encryption.

7. The decentralized peer-to-peer encrypted communication and anti-attack method based on quantum computing according to claim 1 is characterized in that: The prevention of traffic analysis includes: Obfuscated transactions are used to make it impossible for external observers to analyze communication patterns.