Anti-quantum password encryption method and device, anti-quantum SIM card, equipment and medium
By introducing post-quantum cryptographic hardware accelerator and input and output buffers into SIM cards, the security problems of existing cryptographic algorithms in front of quantum computers are solved, and fast-responsive post-quantum secure encryption is achieved.
Patent Information
- Application Number
- CN202510299298.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-13
AI Technical Summary
Existing cryptographic algorithms based on mathematical problems such as large prime number decomposition and discrete elliptic curves are no longer safe in front of quantum computers, resulting in the communication response delay problem of SIM cards.
The post-quantum cipher hardware accelerator and input and output buffer are introduced into the SIM card, and the encryption request is received through the central processor, converted into instructions, and data encryption instructions are executed through the post-quantum cipher hardware accelerator to optimize memory access and accelerate data encryption.
It reduces the communication response delay caused by long-term anti-quantum cryptographic calculation time, realizes the support of post-quantum secure encryption in SIM cards, and improves the speed of data encryption and memory access speed.
Smart Images

Figure CN120150940A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of anti - quantum cryptography technology, and in particular, to an anti - quantum cryptography encryption method, device, anti - quantum SIM card, device and medium. Background Art
[0002] A SIM (Subscriber Identity Module) card is an IC card held by a mobile user in the GSM system, called a user identification card. The current technology of SIM cards is becoming increasingly mature. It not only has the function of mobile communication, but also extends many applications on this basis, such as applets like SIM shield and bus cards, which is a technology of super SIM cards. With the increasing demand for daily financial services, people pay more and more attention to the security on SIM cards. At present, operators such as China Mobile have launched super SIM cards with national cryptographic algorithm security chips, and this kind of SIM card uses national cryptographic security algorithms to ensure the security of user payment transactions. However, with the development of quantum computers in recent years, the existing cryptographic algorithms based on mathematical problems such as large prime number factorization and discrete elliptic curves are no longer secure. Summary of the Invention
[0003] Embodiments of the present application provide an anti - quantum cryptography encryption method, device, anti - quantum SIM card, device and medium, which can reduce the communication response delay caused by the relatively long calculation time of the anti - quantum cryptography itself, and realize the support of post - quantum security encryption in the SIM card.
[0004] In a first aspect of the embodiments of the present application, an anti - quantum cryptography encryption method is provided, which is applied to a terminal including a SIM card. The SIM card includes a central processing unit, a post - quantum cryptography hardware accelerator, an input - output buffer and a bus. The central processing unit includes an instruction cache unit. The method includes:
[0005] The central processing unit receives an encryption request sent by an upper - layer application through the instruction cache unit, and converts the encryption request into a set of instructions. The set of instructions includes a data loading instruction and a data encryption instruction;
[0006] The central processing unit executes the data loading instruction to transmit data to the input - output buffer through the bus;
[0007] The central processing unit executes the data encryption instruction through the post - quantum cryptography hardware accelerator to encrypt the data in the input - output buffer.
[0008] Optionally, the SIM card further includes a dedicated static random access memory, a general static random access memory, and a flash memory. The data includes a key stored in the general static random access memory. Before the central processing unit executes the data loading instruction to transmit the data to the input / output buffer through the bus, the method further includes:
[0009] The central processing unit periodically detects the number of times the key is used;
[0010] If the number of times the key is used exceeds a first threshold, the central processing unit moves the key to the dedicated static random access memory, and the dedicated static random access memory is directly connected to the input / output buffer through hardware mapping;
[0011] If the number of times the key is used is lower than a second threshold, the central processing unit moves the key to the flash memory, and the second threshold is less than the first threshold.
[0012] Optionally, the SIM card further includes a direct memory access controller. The data loading instruction includes a key loading instruction. When the central processing unit executes the data loading instruction to transmit the data to the input / output buffer through the bus, it includes:
[0013] If the key is stored in the dedicated static random access memory, the central processing unit directly executes the key loading instruction to transmit the key from the dedicated static random access memory to the input / output buffer through the bus;
[0014] If the key is stored in the general static random access memory, the central processing unit executes the key loading instruction through the direct memory access controller to transmit the key from the general static random access memory to the input / output buffer through the bus.
[0015] Optionally, the data further includes data to be encrypted, and the data to be encrypted is stored in the flash memory. The data loading instruction further includes a data loading instruction. When the central processing unit executes the key loading instruction through the direct memory access controller to transmit the key from the general static random access memory to the input / output buffer through the bus, the method further includes:
[0016] The central processing unit executes the data loading instruction through the direct memory access controller to transmit the data to be encrypted from the flash memory to the input / output buffer through the bus. The direct memory access controller includes multiple channels, and the channel for executing the key loading instruction is different from the channel for executing the data loading instruction.
[0017] Optionally, the SIM card further includes a register, and the method further includes:
[0018] The central processing unit adjusts the execution order of the set of instructions through the instruction cache unit according to at least one of the read address, type, and application priority of the instruction; wherein, the instruction with the read address of the flash memory has a higher priority than the instruction with the read address of the general static random access memory and the dedicated static random access memory, and the instruction with the read address of the register has a lower priority. The instruction with the type of read / write has a higher priority than the instruction with the type of calculation, and the instruction with a higher application priority has a higher priority.
[0019] Optionally, the set of instructions further includes a result storage instruction. After the central processing unit executes the data encryption instruction through the post-quantum cryptography hardware accelerator, the method further includes:
[0020] Receiving the interrupt information returned by the post-quantum cryptography hardware accelerator, the central processing unit sends a result storage instruction to the direct access memory controller. The result storage instruction carries a source address and a destination address, so that the direct access memory controller extracts the encrypted data from the input / output buffer according to the source address and transmits it to the destination address of the flash memory through the bus.
[0021] A second aspect of the embodiments of the present application provides a post-quantum cryptography encryption device, which is applied to a terminal including a SIM card. The SIM card includes a central processing unit, a post-quantum cryptography hardware accelerator, a static random access memory, an input / output buffer, and a bus. The central processing unit includes an instruction cache unit. The device includes:
[0022] An instruction translation unit, configured to receive an encryption request sent by an upper-layer application through the instruction cache unit and convert the encryption request into a set of instructions, where the set of instructions includes a data loading instruction and a data encryption instruction;
[0023] A data transmission unit, configured to execute the data loading instruction to transmit data to the input / output buffer through the bus;
[0024] A data encryption unit, configured to execute the data encryption instruction through the post-quantum cryptography hardware accelerator to encrypt the data in the input / output buffer.
[0025] A third aspect of the embodiments of the present application provides a post-quantum SIM card. The SIM card includes a central processing unit, a post-quantum cryptography hardware accelerator, an input / output buffer, a bus, a dedicated static random access memory, a general static random access memory, a flash memory, and a direct access memory controller. The central processing unit includes an instruction cache unit; wherein:
[0026] The instruction cache unit is configured to receive an encryption request sent by an upper-layer application, convert the encryption request into a set of instructions, and adjust the priorities of the set of instructions;
[0027] The central processing unit is configured to directly or indirectly execute the set of instructions with adjusted priorities;
[0028] The input / output buffer is configured to cache data to be encrypted and keys;
[0029] The post-quantum cryptography hardware accelerator is configured to encrypt the data to be encrypted according to the key;
[0030] The dedicated static random access memory is configured to store the keys whose usage times exceed a first threshold; the general static random access memory is configured to store the keys whose usage times are lower than the first threshold and higher than a second threshold; the flash memory is configured to store the keys whose usage times are lower than the second threshold and the data to be encrypted, where the second threshold is less than the first threshold;
[0031] The direct memory access controller is configured to transmit at least one of the data to be encrypted, the key, and the encrypted data through a bus.
[0032] A fourth aspect of the embodiments of the present application provides an electronic device, including: a processor and a memory;
[0033] The processor is connected to the memory. The memory is configured to store a computer program, and the processor is configured to call the computer program to execute the method in the first aspect of the embodiments of the present application.
[0034] A fifth aspect of the embodiments of the present application provides a computer-readable storage medium storing a computer program, where the computer program includes program instructions that, when executed by a processor, execute the method in the first aspect of the embodiments of the present application.
[0035] In this application, by setting a post-quantum cryptography hardware accelerator and an input / output buffer in the SIM card, data is transmitted to the input / output buffer through the bus. The post-quantum cryptography hardware accelerator can execute data encryption instructions to encrypt the data in the input / output buffer. The setting of the input / output buffer enables the data to be used for encryption without going through cumbersome conversions internally, optimizing the memory access setting and improving the memory access speed. At the same time, the setting of the post-quantum cryptography hardware accelerator allows the central processing unit to offload the encryption instructions to this dedicated processor, the post-quantum cryptography hardware accelerator, for processing, thereby increasing the data encryption speed. It can be seen that the embodiments of the application can reduce the communication response delay caused by the relatively long calculation time of the anti-quantum cryptography itself by improving the memory access speed and accelerating the data encryption speed, and realize the support for post-quantum secure encryption in the SIM card. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0037] Figure 1 FIG. shows a schematic structural diagram of an anti-quantum SIM card provided by an embodiment of the present application;
[0038] Figure 2 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by an embodiment of the present application;
[0039] Figure 3 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by another embodiment of the present application;
[0040] Figure 4 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by another embodiment of the present application;
[0041] Figure 5 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by another embodiment of the present application;
[0042] Figure 6 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by another embodiment of the present application;
[0043] Figure 7 FIG. shows a schematic flowchart of an anti-quantum cryptography encryption method provided by another embodiment of the present application;
[0044] Figure 8Shows the structural schematic diagram of an anti-quantum cryptographic encryption device provided by an embodiment of the present application;
[0045] Figure 9 Shows the structural schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0046] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0047] Please refer to Figure 1 , which shows the structural schematic diagram of an anti-quantum SIM card provided by an embodiment of the present application. The SIM card 100 includes a Central Processing Unit (CPU) 110, a PostQuantum Cryptography (PQC) hardware accelerator 120, an input / output buffer 130, a bus 140, a dedicated Static Random-Access Memory (SRAM) 150, a general static random access memory 160, a Flash 170, and a Direct Memory Access (DMA) 180. The central processor 110 includes an Instruction Cache Unit (I-Cache) 111; where:
[0048] The instruction cache unit 111 is configured to receive an encryption request sent by an upper-layer application, convert the encryption request into a set of instructions, and adjust the priorities of the set of instructions;
[0049] The central processor 110 is configured to directly or indirectly execute the set of instructions with adjusted priorities;
[0050] The input / output buffer 130 is configured to cache data to be encrypted and keys;
[0051] The post-quantum cryptography hardware accelerator 120 is configured to encrypt the data to be encrypted according to the key;
[0052] The dedicated static random access memory 150 is used to store the keys whose usage times exceed the first threshold; the general static random access memory 160 is used to store the keys whose usage times are lower than the first threshold and higher than the second threshold; the flash memory 170 is used to store the keys and the data to be encrypted whose usage times are lower than the second threshold, and the second threshold is less than the first threshold;
[0053] The direct access memory controller 180 is used to transmit at least one of the data to be encrypted, the key, and the encrypted data through the bus 140.
[0054] Furthermore, the SIM card 100 may further include a true random number generator 190. The true random number generator 190 is used to generate true random numbers through physical processes (such as thermal noise, photon behavior), and the true random numbers are used for the generation of keys in the PQC algorithm.
[0055] In the embodiment of the present application, by setting a post-quantum cryptography hardware accelerator and an input / output buffer in the SIM card, data is transmitted to the input / output buffer through the bus. The post-quantum cryptography hardware accelerator can execute data encryption instructions to encrypt the data in the input / output buffer. The setting of the input / output buffer enables the data to be used for encryption without going through cumbersome conversions inside, optimizing the memory access setting and improving the memory access speed. At the same time, the setting of the post-quantum cryptography hardware accelerator enables the central processing unit to offload the encryption instructions to this dedicated processor, the post-quantum cryptography hardware accelerator, for processing, thereby improving the data encryption speed. It can be seen that the embodiment of the application can reduce the response delay error caused by the relatively long calculation time due to the large key in the quantum-resistant cryptography algorithm by improving the memory access speed and accelerating the data encryption speed, and achieve post-quantum security-level encryption protection for the SIM card.
[0056] Please refer to Figure 2 , which shows a schematic flowchart of a quantum-resistant cryptography encryption method provided by an embodiment of the present application. Applied to a terminal including the SIM card shown above Figure 1 , the method may include the following steps:
[0057] Step 21: The central processing unit receives an encryption request sent by an upper-layer application through the instruction cache unit and converts the encryption request into a set of instructions. The set of instructions includes a data loading instruction and a data encryption instruction.
[0058] Among them, a request is a service requirement put forward by an application program to system resources (such as CPU, memory, etc.), and an encryption request is a service requirement for encrypting data; an instruction is a machine language command that can be directly executed by system resources; at least one request can be converted into at least one instruction, usually a set of instructions, and the instructions can include, for example, data loading instructions, data encryption instructions, data storage instructions, and so on.
[0059] Exemplarily, when the upper-layer application calls the encryption function through the interface unit, it triggers a system call to enter the kernel state. The operating system adds the encryption request to the CPU scheduling queue through the interrupt handler, and the compiler compiles the encryption request and converts it into specific encryption instructions.
[0060] Among them, as Figure 3 shown, after performing step 21, that is, after the central processing unit receives the encryption request sent by the upper-layer application through the instruction cache unit and converts the encryption request into a set of instructions, the method further includes:
[0061] Step 24: The central processing unit adjusts the execution order of the set of instructions through the instruction cache unit according to at least one of the read address, type, and application priority of the instruction; among them, the instruction with the read address of the flash memory has a higher priority than the instruction with the read address of the general static random access memory and the dedicated static random access memory, and the instruction with the read address of the register has the lowest priority. The instruction with the type of read / write has a higher priority than the instruction with the type of calculation, and the instruction with a higher application priority has a higher priority.
[0062] Among them, the read address of the instruction is used to indicate which hardware stores the data indicated by the instruction, and the hardware can be, for example, flash memory, general static random access memory, dedicated static random access memory, memory, register, etc.; in this application, the data to be encrypted is usually stored in the flash memory, and the key is usually stored in the general static random access memory or the dedicated static random access memory. The size of the data to be encrypted is usually larger than the size of the key. The instruction with the read address of the flash memory has a higher priority than the instruction with the read address of the general static random access memory and the dedicated static random access memory, and the instruction with the read address of the register has the lowest priority, so that the data loading instruction is ahead of the key loading instruction, thereby shortening the time-consuming in the loading instruction and achieving the effect of overall operation acceleration.
[0063] Among them, in the encryption operation, the types of instructions are mainly divided into read / write instructions and calculation instructions. The read / write instructions can be further divided into load key instructions, load data instructions (i.e., load the data to be encrypted, and the data to be encrypted can be plaintext or intermediate state data), and result storage instructions; the calculation instructions can be divided into different calculation instructions according to different encryption algorithms, such as row shift instructions, column confusion instructions, round key addition instructions, etc. In this application, the instructions of the read / write type have a higher priority than the instructions of the calculation type. By using the instructions of the read / write type to pre-load the data required for subsequent rounds in advance, it can be ensured that the execution of the instructions of the calculation type does not require excessive waiting time, thus achieving the effect of accelerating the overall operation.
[0064] Among them, the encryption requests received by the instruction cache unit can be sent by multiple upper-layer applications. In this case, the instruction priorities of the instructions corresponding to different applications are determined according to the application priorities of the multiple upper-layer applications.
[0065] Step 22: The central processing unit executes the data loading instruction to transmit the data to the input / output buffer through the bus.
[0066] Among them, the data includes the key stored in the general static random access memory, such as Figure 4 As shown, before executing step 22, that is, before the central processing unit executes the data loading instruction to transmit the data to the input / output buffer through the bus, the method further includes:
[0067] Step 25: The central processing unit periodically detects the usage times of the key;
[0068] Step 26: If the usage times of the key exceed the first threshold, the central processing unit moves the key to the dedicated static random access memory, and the dedicated static random access memory is directly connected to the input / output buffer through hardware mapping;
[0069] Step 27: If the usage times of the key are lower than the second threshold, the central processing unit moves the key to the flash memory, and the second threshold is less than the first threshold.
[0070] Further, the usage times of the key can be the usage times statistically within a certain time interval, such as 3 months, half a year, one year, etc. The time interval is not limited here. The first threshold can be, for example, 10 times, 15 times, 20 times, and the second threshold can be 5 times, 10 times, 15 times. The specific values of the first threshold and the second threshold are not limited here, but it should be noted that the second threshold is less than the first threshold.
[0071] In the embodiment of the present application, hierarchical management of keys is performed according to the access frequency of the keys. Keys with different access frequencies are stored in different memories, and more frequently used keys can be accessed more quickly through the corresponding stored keys, ensuring that the overall response time of key loading is shorter when the encryption operation is executed, thereby improving the overall efficiency of the encryption operation.
[0072] Among them, the data loading instruction includes a key loading instruction. As Figure 5 shown, when performing step 22, that is, when the central processing unit executes the data loading instruction to transmit data to the input / output buffer through the bus, it includes:
[0073] Step 221: Determine whether the key is stored in the dedicated static random access memory or the general static random access memory;
[0074] Step 222: If the key is stored in the dedicated static random access memory, the central processing unit directly executes the key loading instruction to transmit the key from the dedicated static random access memory to the input / output buffer through the bus;
[0075] Step 223: If the key is stored in the general static random access memory, the central processing unit executes the key loading instruction through the direct memory access controller to transmit the key from the general static random access memory to the input / output buffer through the bus.
[0076] Further, the method further includes: if the key is stored in the flash memory, the central processing unit first decrypts and loads it into the general static random access memory through the bus, and then executes step 223.
[0077] In an embodiment of the present application, if the key is stored in a dedicated static random access memory, it indicates that the access frequency of the key is relatively high. The central processing unit directly executes the key loading instruction and directly docks the dedicated static random access memory to the input / output buffer of the PQC hardware accelerator through hardware mapping. If the key is stored in a general static random access memory, it indicates that the access frequency of the key is medium and can be dynamically managed by the operating system. The central processing unit executes the key loading instruction by directly accessing the memory controller to transfer the key from the general static random access memory to the input / output buffer through the bus. If the key is stored in a flash memory, it indicates that the access frequency of the key is relatively low. The central processing unit first decrypts and loads it into the general static random access memory through the bus, and then performs the reading operation when the key is stored in the general static random access memory. The multi-level key storage and loading mechanism provided by the present application can enable faster access to the key, ensure a shorter overall response time for key loading during encryption operations, and thus improve the overall efficiency of encryption operations.
[0078] Wherein, the data further includes data to be encrypted, the data to be encrypted is stored in the flash memory, and the data loading instruction further includes a data loading instruction. As Figure 6 shown, while performing step 222, that is, while the central processing unit executes the key loading instruction through the direct access memory controller to transfer the key from the general static random access memory to the input / output buffer through the bus, the method further includes:
[0079] Step 224: The central processing unit executes the data loading instruction through the direct access memory controller to transfer the data to be encrypted from the flash memory to the input / output buffer through the bus. The direct access memory controller includes multiple channels, and the channel for executing the key loading instruction is different from the channel for executing the data loading instruction.
[0080] Wherein, the data to be encrypted can be plaintext or intermediate state data during the encryption process, which is not limited herein. In an embodiment of the present application, through the multi-channel mechanism of the direct access memory controller, the data loading instruction and the key loading instruction are executed simultaneously, enabling the key and the data to be loaded into the specified area at the same time. Both belong to the loading instructions, which can reduce the overall execution time of the loading instructions.
[0081] Step 23: The central processing unit executes the data encryption instruction through the post-quantum cryptography hardware accelerator to encrypt the data in the input / output buffer.
[0082] Among them, a dedicated circuit is provided in the post-quantum cryptography hardware accelerator, such as a polynomial multiplier, a hash engine, etc., which can perform efficient operations on the data in the input / output buffer. The data in the input / output buffer includes not only the above-mentioned keys (public keys or ephemeral keys, etc.), the data to be encrypted (plaintext, intermediate data, etc.), but also other data determined according to the selected post-quantum cryptography algorithm, such as random numbers generated by a true random number generator.
[0083] Among them, the set of instructions further includes a result storage instruction, such as Figure 7 As shown, after executing step 23, that is, after the central processing unit executes the data encryption instruction through the post-quantum cryptography hardware accelerator, the method further includes:
[0084] Step 28: Receive the interrupt information returned by the post-quantum cryptography hardware accelerator, and the central processing unit sends a result storage instruction to the direct access memory controller. The result storage instruction carries a source address and a destination address, so that the direct access memory controller extracts the encrypted data from the input / output buffer according to the source address and transmits it to the destination address of the flash memory through the bus.
[0085] Exemplarily, the interrupt information can be an interrupt signal, which is sent by the post-quantum cryptography hardware accelerator to the central processing unit through an interrupt controller, and the encryption status is marked through a status register; the central processing unit pauses the current task, jumps to the interrupt service program, reads the status register of the post-quantum cryptography hardware accelerator, confirms that the operation is successful, and clears the interrupt flag. The central processing unit constructs a storage instruction for the direct access memory controller according to the position and storage requirements of the encryption result. The storage instruction carries the following information: a source address and a destination address, and may also include a transfer length and a transfer mode. The source address is used to represent the starting physical address of the encrypted data in the input / output buffer of the post-quantum cryptography hardware accelerator. The destination address is used to represent the target storage address of the flash memory. The transfer length is used to represent the total size of the encrypted data. The transfer mode can be divided into single burst transfer (Burst Mode) or block transfer (Block Transfer). The central processing unit writes the above parameters into the direct access memory controller through a memory mapping register or a dedicated instruction port, and the direct access memory controller performs the transfer to achieve the storage of the encryption result.
[0086] In the embodiment of the present application, by setting a post-quantum cryptography hardware accelerator and an input / output buffer in the SIM card, data is transmitted to the input / output buffer through the bus. The post-quantum cryptography hardware accelerator can execute data encryption instructions to encrypt the data in the input / output buffer. The setting of the input / output buffer enables the data to be used for encryption without cumbersome conversion inside, optimizing the memory access setting and improving the memory access speed. At the same time, the setting of the post-quantum cryptography hardware accelerator enables the central processing unit to offload the encryption instructions to this dedicated processor, the post-quantum cryptography hardware accelerator, for processing, thereby improving the data encryption speed. It can be seen that the embodiment of the application can reduce the communication response delay caused by the long calculation time of the post-quantum cryptography itself by improving the memory access speed and accelerating the data encryption speed, and realizes supporting post-quantum secure encryption in the SIM card.
[0087] Figure 8 FIG. shows a schematic structural diagram of a post-quantum cryptography encryption device provided by an embodiment of the present application. Applied to a terminal including a SIM card, the SIM card includes a central processing unit, a post-quantum cryptography hardware accelerator, a static random access memory, an input / output buffer, and a bus. The central processing unit includes an instruction cache unit. The device includes:
[0088] An instruction translation unit 801, configured to receive an encryption request sent by an upper-layer application through the instruction cache unit, and convert the encryption request into a set of instructions, where the set of instructions includes a data loading instruction and a data encryption instruction;
[0089] A data transmission unit 802, configured to execute the data loading instruction to transmit data to the input / output buffer through the bus;
[0090] A data encryption unit 803, configured to execute the data encryption instruction through the post-quantum cryptography hardware accelerator to encrypt the data in the input / output buffer.
[0091] Figure 9 FIG. shows a schematic structural diagram of a computer device provided by an embodiment of the present application, including a memory and a processor. The memory stores a computer program. When the processor executes the computer program, it realizes the functions of the computer system for the post-quantum cryptography encryption method in any of the above embodiments.
[0092] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the computer, the computer realizes the functions of the computer system for the post-quantum cryptography encryption method in any of the above embodiments.
[0093] The embodiments of the present application also provide a computer program product containing instructions, which, when executed by a computer, enable the computer to perform the functions of the computer system for the quantum-resistant cryptographic encryption method in any of the above embodiments.
[0094] It can be understood that the specific examples in the present application are only to help those skilled in the art better understand the embodiments of the present application, rather than limiting the scope of the present invention.
[0095] It can be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the various processes do not mean the order of execution. The order of execution of the various processes should be determined by their functions and internal logics, and should not constitute any limitation on the implementation processes of the embodiments of the present application.
[0096] It can be understood that the various embodiments described in the present application can be implemented alone or in combination, and the embodiments of the present application do not limit this.
[0097] Unless otherwise specified, all technical and scientific terms used in the embodiments of the present application have the same meaning as commonly understood by those skilled in the technical field of the present application. The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the scope of the present application. The term "and / or" used in the embodiments of the present application and the appended claims includes any and all combinations of one or more of the related listed items. The singular forms "a", "above", and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0098] It can be understood that the processor in the implementation manner of the present application can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method implementation manner can be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the implementation manner of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the implementation manner of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0099] It can be understood that the memory in the implementation manner of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0100] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0101] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0102] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0103] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0104] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0105] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0106] The above is only the specific embodiment of the present application, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application and should be covered by the protection scope of the present application. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A quantum-resistant cryptographic encryption method, characterized in that: Applied to a terminal including a SIM card, the SIM card including a central processing unit, a post-quantum cryptography hardware accelerator, an input / output buffer, and a bus, the central processing unit including an instruction cache unit, the method comprising: The central processing unit receives an encryption request sent by an upper layer application through the instruction cache unit, and converts the encryption request into a group of instructions, wherein the group of instructions includes a data loading instruction and a data encryption instruction; The central processing unit executes the data loading instruction to transfer the data to the input / output buffer through the bus; The central processing unit executes the data encryption instruction through the post-quantum cryptography hardware accelerator to encrypt the data in the input and output buffer.
2. The method according to claim 1, characterized in that The SIM card further includes a dedicated static random access memory, a common static random access memory and a flash memory, the data includes a key stored in the common static random access memory, the central processing unit executes the data loading instruction to transfer the data to the input / output buffer through the bus, and the method further includes: The central processing unit periodically detects the number of times the key is used; If the number of times the key is used exceeds a first threshold, the central processing unit moves the key to the dedicated static random access memory, and the dedicated static random access memory is directly connected to the input and output buffer through hardware mapping; If the number of times the key is used is lower than a second threshold, the central processor moves the key to the flash memory, and the second threshold is smaller than the first threshold.
3. The method according to claim 2, characterized in that The SIM card further includes a direct access memory controller, the data loading instruction includes a key loading instruction, and the central processing unit executes the data loading instruction to transmit data to the input / output buffer through the bus, including: If the key is stored in the dedicated static random access memory, the central processing unit directly executes the load key instruction to transfer the key from the dedicated static random access memory to the input / output buffer through the bus; If the key is stored in the common static random access memory, the central processing unit executes the load key instruction through the direct access memory controller to transfer the key from the common static random access memory to the input / output buffer through the bus.
4. The method according to claim 3, characterized in that The data further includes data to be encrypted, the data to be encrypted is stored in the flash memory, the data loading instruction further includes a load data instruction, the central processing unit executes the load key instruction through the direct access memory controller to transfer the key from the ordinary static random access memory to the input and output buffer through the bus, and the method further includes: The central processing unit executes the load data instruction through the direct access memory controller to transfer the data to be encrypted from the flash memory to the input and output buffer through the bus. The direct access memory controller includes multiple channels, and the channel used to execute the load key instruction is different from the channel used to execute the load data instruction.
5. The method according to claim 4, characterized in that The SIM card further includes a register, and the method further includes: The central processing unit adjusts the execution order of the group of instructions according to at least one of the read address, type and application priority of the instructions through the instruction cache unit; wherein, the instruction whose read address is the flash memory has a higher priority than the instruction whose read address is the ordinary static random access memory and the dedicated static random access memory, and is higher than the instruction whose read address is the register, the instruction of type read and write has a higher priority than the instruction of type calculation, and the instruction with a high application priority has a high priority.
6. The method according to any one of claims 3 to 5, characterized in that: The set of instructions further includes a result storage instruction, and after the central processor executes the data encryption instruction through the post-quantum cryptography hardware accelerator, the method further includes: After receiving the interrupt information returned by the post-quantum cryptography hardware accelerator, the central processing unit sends a result storage instruction to the direct access memory controller, where the result storage instruction carries a source address and a destination address, so that the direct access memory controller extracts the encrypted data from the input / output buffer according to the source address and transmits it to the destination address of the flash memory through the bus.
7. A quantum-resistant cryptographic encryption device, characterized in that: Applied to a terminal including a SIM card, the SIM card including a central processing unit, a post-quantum cryptography hardware accelerator, a static random access memory, an input and output buffer, and a bus, the central processing unit including an instruction cache unit, the device including: An instruction translation unit, configured to receive an encryption request sent by an upper layer application through the instruction cache unit, and convert the encryption request into a set of instructions, wherein the set of instructions includes a data loading instruction and a data encryption instruction; a data transmission unit, configured to execute the data loading instruction to transmit the data to the input / output buffer through the bus; A data encryption unit is used to execute the data encryption instruction through the post-quantum cryptography hardware accelerator to encrypt the data in the input and output buffer.
8. A quantum-resistant SIM card, characterized in that: The SIM card includes a central processing unit, a post-quantum cryptography hardware accelerator, an input and output buffer, a bus, a dedicated static random access memory, a common static random access memory, a flash memory and a direct access memory controller, and the central processing unit includes an instruction cache unit; wherein: The instruction cache unit is used to receive an encryption request sent by an upper layer application, convert the encryption request into a group of instructions, and adjust the priority of the group of instructions; The central processing unit is used to directly or indirectly execute the set of instructions after the priority is adjusted; The input and output buffer is used to cache the data to be encrypted and the key; The post-quantum cryptography hardware accelerator is used to encrypt the data to be encrypted according to the key; The dedicated static random access memory is used to store the key whose usage times exceed a first threshold; the common static random access memory is used to store the key whose usage times are lower than the first threshold and higher than a second threshold; the flash memory is used to store the key whose usage times are lower than the second threshold and the data to be encrypted, and the second threshold is lower than the first threshold; The direct access memory controller is used to transmit at least one of the data to be encrypted, the key, and the encrypted data through a bus.
9. An electronic device, characterized in that: include: Processor and memory; The processor is connected to a memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the method according to any one of claims 1 to 7 is executed.
Citation Information
Patent Citations
Quantum key encryption method and device based on super SIM card
CN116886277A
Communication network encryption method and system, electronic equipment and storage medium
CN117858081A
Session key generation method and related device
CN119276494A
Quantum-resistant SIM card
US20220240095A1
Technologies for subscriber identity module security
US20250071550A1
Cited By
Communication encryption method based on quantum security SIM card
CN121442321A