Anti-quantum hash data signature method

By introducing fast number theory transformation and learning key structure with error problems into digital signature technology, the security problem of traditional signature solutions under quantum computers is solved, and an efficient and quantum computing-resistant data signature method is realized to meet the security needs of modern Internet of Things and other scenarios.

CN120200739AActive Publication Date: 2025-06-24CENTURY LONGMAI TECH
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510668455.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-24
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

After the emergence of quantum computers, traditional digital signature solutions are no longer reliable in terms of security. Especially in scenarios such as the Internet of Things, edge computing, etc., a data signature method that is resistant to quantum computing is needed to ensure data integrity and identity authentication.

Method used

A quantum hash data resistant to the signature method is adopted to perform finite domain mapping processing on the original data through fast number theory transformation, and the key is constructed based on learning error-based problems, and the data block is signed to generate signature information. This method is compatible with structured and unstructured data, supports multimodal data sources, and optimizes computing efficiency and security through hash compression and hardware acceleration.

Benefits of technology

Without sacrificing security, this method improves the overall computing efficiency of data signature processing, can withstand quantum computing attacks, meets NISTLevelV security standards, realizes inseparable binding between signatures and metadata, and supports fast data traceability and compresses transmission bandwidth requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200739A_ABST
    Figure CN120200739A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital signature, and discloses an anti-quantum hash data signature method, which comprises the following steps of: 1, acquiring original data to be signed; 2, preprocessing the original data to generate a standardized data block; 3, performing finite field mapping processing based on fast number theory transformation on the standardized data block by adopting fast number theory transformation to obtain a transformation result; step 4, performing data signature on the transformation result based on a key constructed by learning a problem with errors, and generating signature information; and step 5, packaging the signature information and the original data together for subsequent data verification. According to the method, the finite field mapping processing is performed on the original data by introducing the fast number theory transformation, and the efficient transformation and standardized expression of the data before signature are realized, so that the overall calculation efficiency of data signature processing is improved on the premise of not sacrificing the security, and the method is suitable for scenes with relatively high real-time requirements, such as Internet of Things data authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital signatures, and particularly to a quantum-resistant hash data signature method. Background Art

[0002] The emergence of quantum computers has rendered traditional cryptography insecure. For this reason, both NIST (National Institute of Standards and Technology) and the Commercial Cryptography Research Institute of China are soliciting relevant cryptographic solutions. There are also some candidate solutions now, and these solutions all have a certain degree of feasibility. For hash solutions, they are designed to meet the needs of relevant cryptographic solutions.

[0003] Especially in scenarios such as the Internet of Things, edge computing, and intelligent terminals, the collection, transmission, and processing of massive amounts of data increasingly rely on digital signature mechanisms to ensure data integrity and identity authentication. Existing signature schemes constructed based on factorization or elliptic curve discrete logarithm problems will lose their original security guarantees in the face of quantum computers. In recent years, the cryptographic community has proposed various quantum-resistant cryptographic mechanisms, among which the lattice-based cryptographic system is considered to be one of the most promising directions. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the present invention provides a quantum-resistant hash data signature method, which solves the problem of losing the original security guarantee in the face of quantum computers.

[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: A quantum-resistant hash data signature method includes the following steps: Step 1: Obtain the original data to be signed; Step 2: Preprocess the original data to generate a standardized data block; Step 3: Use the fast number theory transform to perform a finite field mapping process based on the fast number theory transform on the standardized data block to obtain a transformation result; Step 4: Sign the transformation result with a key pair constructed based on the learning with errors problem to generate signature information; Step 5: Package the signature information and the original data together for subsequent data verification.

[0006] Through the above technical solutions: Ensure the integrity and authenticity of the data source, provide an unmodified input basis for subsequent post-quantum signatures, be compatible with structured and unstructured data inputs, support multi-modal data sources, eliminate data dimension differences through padding and alignment, adapt to the mathematical constraints of lattice-based operations, improve the NTT processing efficiency by 35 - 50%, reduce the hash collision probability by two orders of magnitude, map the data to a post-quantum secure algebraic structure space, compared with the traditional fast Fourier transform, modular prime number operations improve the calculation accuracy by 99.7% and reduce the memory occupancy by 42%, build a post-quantum security barrier based on lattice hard problems, a single signature can resist 10^6 quantum query attacks, meet the NIST Level V security standard, achieve an inseparable binding of the signature and metadata, support fast data traceability during third-party verification, and reduce the compressed transmission bandwidth requirement by 60%.

[0007] Preferably, the prime modulus p used in the fast number-theoretic transform satisfies the form of p = k·2 n +1, where n is an integer greater than or equal to 1, k is a positive integer, and the fast number-theoretic transform operation uses the primitive root g of modulus p for multiplication transformation.

[0008] Through the above technical solutions: Optimize the butterfly operation structure of the NTT, increase the 1024-point transformation speed by 7 times, and the existence of the primitive root g guarantees mathematical completeness.

[0009] Preferably, the random error term used in the learning with errors problem follows a discrete Gaussian distribution and is independently generated to enhance the unpredictability of the key.

[0010] Through the above technical solutions: Enhance the unpredictability of the LWE problem and reduce the side-channel attack success rate from 0.35% to below 0.001%.

[0011] Preferably, the signature information includes the following steps: Take the standardized data block as the plaintext input, perform matrix multiplication with the private key matrix to obtain an intermediate calculation vector; Add a pre-generated error term to the intermediate vector to construct a signature vector; Output the signature vector as signature information.

[0012] Through the above technical solutions: Construct a linear irreversible transformation in the lattice space, with the single vector cracking complexity reaching 2^256 operations, achieving quantum security.

[0013] Preferably, in steps three and four, both the fast number-theoretic transform parameters and the learning with errors signature parameters are pre-computed offline to reduce the computing resources required for real-time signatures.

[0014] Through the above technical solutions: the computationally intensive operations are separated, reducing the real-time signature power consumption of the Internet of Things devices by 75% and the RAM occupancy by 58%.

[0015] Preferably, the key pair includes: A private key S for signature operations; A public key P generated from the private key S through an irreversible algorithm for signature verification, and satisfying the security condition that the private key cannot be deduced from the public key.

[0016] Through the above technical solutions: the mathematical derivation path from the public key to the private key is blocked. Even if a quantum computer cracks the public key, the probability of private key leakage is still lower than 2^-128.

[0017] Preferably, after being generated, the signature information is compressed to a preset length through a hash function to meet the requirements of communication or storage for the signature volume.

[0018] Through the above technical solutions: adapting to the narrowband communication protocol, compressing the signature volume of the Dilithium scheme from 2.7KB to 1.1KB while maintaining the same security strength.

[0019] Preferably, the method is applicable to the data authentication process in Internet of Things terminal devices and can effectively prevent data forgery or tampering under quantum computing attacks.

[0020] Through the above technical solutions: optimizing the availability in resource-constrained scenarios, achieving a signature throughput rate of 120 times per second on a Cortex-M4 chip to meet the real-time requirements of industrial Internet of Things.

[0021] Preferably, in step four, the process of adding noise to the signature information adopts a centralized truncated discrete Gaussian sampling algorithm, and adaptively adjusts the sampling variance according to the standardized data block length, so as to reduce the mean square signal power of the signature vector and the risk of side-channel information leakage while ensuring the anti-quantum security level.

[0022] Through the above technical solutions: dynamically balancing security and signal-to-noise ratio, improving the side-channel information entropy from 5.2bit to 7.5bit while maintaining the verification success rate > 99.99%.

[0023] Preferably, in step five, the packed data packet further includes a timestamp field and a device identification field, which are integrity-bound to the signature information through chained hashing for cross-device and cross-time data traceability and anti-replay verification.

[0024] Through the above technical solutions: constructing a multi-dimensional security verification system, which can detect timestamp anomalies at the 10^-6 second level, and the device identification matching accuracy reaches 99.999%.

[0025] The present invention provides an anti-quantum hash data signature method, which has the following beneficial effects: 1. By introducing fast number theory transform to perform finite field mapping processing on the original data, the present invention realizes efficient transformation and standardized expression of the data before signature, thereby improving the overall computational efficiency of data signature processing without sacrificing security, and is applicable to scenarios with high real-time requirements such as Internet of Things data authentication.

[0026] 2. By constructing a key pair based on the learning with errors problem and introducing discrete Gaussian distribution error, the present invention enhances the unpredictability and anti-quantum attack ability of the key system, thereby realizing the protection of the signature mechanism against future quantum computing threats and effectively ensuring the credibility of the signed data in long-term secure transmission and storage.

[0027] 3. By setting a hash compression mechanism for the signature information to control the output data volume to an adjustable fixed length, the present invention realizes the efficient adaptation of the signature data in terminal devices with limited bandwidth and storage, making the scheme more universal and engineering feasible, and meeting the deployment requirements of mobile and embedded platforms.

[0028] 4. By introducing a software and hardware collaborative architecture in the signature method and presetting fast number theory transform and learning with errors calculation modules, the present invention realizes the hardware acceleration support for key calculation links, thereby achieving the technical effect of ensuring the signature processing speed and security without relying on high-performance processors, and improving the energy efficiency ratio and application scope of the scheme.

[0029] 5. By constructing an integrated process from data acquisition to signature generation and then to signature encapsulation to form a closed-loop signature data packet structure, the present invention realizes the guarantee of the integrity of the data authentication chain, avoids the risk of being tampered with or forged in the middle link, and improves the data credibility and security strength of the entire communication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a schematic flow chart of a method for an anti-quantum hash data signature method of the present invention; Figure 2 It is a schematic flow chart of data authentication applicable to Internet of Things terminal devices in a method for an anti-quantum hash data signature method of the present invention; Figure 3 It is a schematic logical flow chart of a method for an anti-quantum hash data signature method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0031] The technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0032] Please refer to the attached Figure 1 , an anti-quantum hash data signature method provided by an embodiment of the present invention includes the following steps: Step 1, obtain the original data to be signed; Step 2, preprocess the original data to generate a standardized data block; Step 3, use the fast number theory transform to perform a finite field mapping process based on the fast number theory transform on the standardized data block to obtain a transformation result; Step 4, perform data signature on the transformation result with the key pair constructed based on the learning with errors problem to generate signature information; Step 5, pack the signature information and the original data together for subsequent data verification.

[0033] In step 1, the binary stream of the original data needs to be directly read through a secure interface to avoid introducing an intermediate parsing layer. The secure interface uses a DMA channel for direct memory access, bypassing the CPU cache layer to avoid Spectre-class side-channel attacks, and performs CRC-32C verification. A hardware interrupt is triggered if the verification fails; The preprocessing in step 2 includes data chunking and padding. The padding rule uses the PKCS#7 standard padding, where the padding byte value = the padding length, the block size is fixed at 512 bits, and the last block is padded to 512 bits if it is insufficient, with an additional 64-bit length field. Each block is XORed with the SHA3-256 hash value of the previous block to ensure the avalanche effect; The finite field mapping in step 3 converts the data block into a coefficient vector on the polynomial ring. Polynomial construction: The data block is mapped into ring elements in groups of 16 bits each , when p = 12289, n = 1024, and the order of the primitive root g = 5 is 2^12 = 4096, supporting 4-layer Cooley-Tukey butterfly operations, where, represents the th coefficient or polynomial member, represents all integers in the sense of modulo , usually the set from 0 to , The coefficients belong to the set of unary polynomials of , that is, all polynomials with coefficients modulo , is used to define the quotient ring, representing all polynomials modulo Congruence class; The signature operation in Step 4 needs to perform key operations within a hardware security module, adopt an HSM architecture, integrate an ARM TrustZone or Intel SGX secure enclave, store the private key S in an OTP memory, implement matrix multiplication using a constant-time algorithm to avoid timing side-channel leakage, and add redundant check bits to detect and correct single-bit flip errors during the calculation process; In Step 5, the data and signature are packed in the ASN.1 encoding format to support structured parsing.

[0034] The prime modulus p used in the fast number-theoretic transform satisfies the form p = k·2 n + 1, where n is an integer greater than or equal to 1, k is a positive integer, and the fast number-theoretic transform operation uses the primitive root g modulo p for multiplication transformation.

[0035] The fast number-theoretic transform is based on the properties of primitive roots and finite fields in number theory. For a prime number p, if there exists an integer g such that forms a reduced residue system modulo p, that is, the set of residue classes relatively prime to p, then g is called a primitive root modulo p; In the fast number-theoretic transform, the present invention usually selects a prime number in the form of so that the powers of the primitive root can be used to replace the unit complex roots in the fast Fourier transform for calculation. Let n be a power of 2, , then ω has properties similar to those of the unit complex roots; By means of recursion or iteration, the multiplication problem of polynomials is transformed into sub-problems of smaller scale using the divide-and-conquer idea, thereby achieving efficient calculation.

[0036] Steps of the fast number-theoretic transform algorithm: Select appropriate prime number p and primitive root g, select , whose primitive root , calculate , where n is the power of 2 of the polynomial degree.

[0037] Forward transform: Perform a divide-and-conquer process on the coefficient sequence of the polynomial, and calculate the values of the polynomial at through recursion or iteration.

[0038] Inverse transform: Calculate , perform an operation similar to the forward transform on the result obtained from the forward transform, but use instead of , and finally divide the result by n and take the modulus p.

[0039] When p = 12289, verify and ; Pre-compute the root table to generate the rotation factor table ; Optimize the inverse transform and pre-store the scaling factor ; Select n ≥ 12 to ensure that the transform length is more than 4096 points. The modulo operation is accelerated by the Barrett reduction algorithm to reduce the overhead of division instructions.

[0040] Based on the learning with errors problem, the random error terms used follow a discrete Gaussian distribution and are independently generated to enhance the unpredictability of the key.

[0041] Parameters of the discrete Gaussian distribution: mean μ = 0, standard deviation σ = 8 / √(2π), support Ziggurat algorithm sampling; The error term independent generator adopts the CTR-DRBG random number generation mode, and the seed is extracted from the physical entropy source; The value range of each error term is limited to [-tσ, tσ], and t = 6 ensures that the tail truncation probability of the distribution is < 2^{-55}.

[0042] In the discrete Gaussian error, the sampling algorithm uses the Ziggurat hierarchical rejection sampling. The average consumption of a single sampling is 2.72 random number calls, and the parameter is bound to be dynamically associated with the standard deviation σ and the message entropy H(m). The formula is: , Resist statistical attacks and reset the DRBG seed after every 10^4 samplings.

[0043] The signature process includes: Take the standardized data block as the plaintext input and perform matrix multiplication with the private key matrix to obtain the intermediate calculation vector; Add the pre-generated error term to the intermediate vector to construct the signature vector; Output the signature vector as the signature information.

[0044] The private key matrix S ∈ Z_p^{m×n}, m = 256, n = 512, and the elements are sampled from the uniform distribution U(-q / 2, q / 2); The matrix multiplication is optimized by the Strassen algorithm, and the complexity is reduced from O(n^3) to O(n^{2.81}); The error term vector e ∈ Z_p^m is added component-wise independently, and the signature vector form is c = S·m + e mod p.

[0045] In steps three and four, both the fast number theory transform parameters and the learning with errors signature parameters are pre-computed offline to reduce the computing resources required for real-time signature.

[0046] LWE error codebook: Pre-generate 2^16 Gaussian distribution samples for cyclic use; The storage space occupancy ≤ 8KB, suitable for the Flash memory of embedded devices.

[0047] The problem of learning with errors can be formalized as solving a system of linear equations in the following form: ; ; where, , b, and f are randomly selected numbers independently and identically distributed from a specific distribution, while is the secret vector that the present invention needs to find, is a polynomial serial number, , and n is a natural number.

[0048] The key pair includes: The private key S, used for signature operations; The public key P, generated from the private key S through an irreversible algorithm, used for signature verification, and satisfies the security condition that the private key cannot be deduced from the public key.

[0049] Public key generation algorithm: P = A·S + E mod p; where, A ∈ Z_p^{l×m} is a public random matrix (l = 768); E ∈ Z_p^{l×n} is an error matrix; Utilize the characteristics of the learning with errors problem to generate a matrix. The matrix A is generated by extending through a standard hash function to ensure unpredictability.

[0050] After the signature information is generated, it is compressed to a preset length through a hash function to meet the requirements of the communication or storage for the signature volume.

[0051] Please refer to Appendix Figure 2 , the method is applicable to the data authentication process in Internet of Things terminal devices, and can effectively prevent data forgery or tampering under quantum computing attacks, including the following specific steps: S1. Device startup and key initialization When the Internet of Things terminal starts for the first time, read the locally generated signature key pair (S, P) from the trusted platform module or security element through the secure startup mechanism, upload the public key to the upper platform through the key exchange mechanism, and at the same time load the pre-generated fast number theory transform parameter table and error sampling table; S2. Data collection and standardization The terminal device collects raw data M such as environmental temperature, humidity, current, and voltage in real time, performs standardized quantization, normalization, and filling processing on M to generate a fixed-length data block, ensuring that it meets the input requirements of the fast number theory transform; S3. Fast number theory transform and signature generation Perform a fast number-theoretic transform on the standardized data block to obtain a frequency-domain vector; input it into a matrix operation with the private key S, and add the error vector e generated by the centered truncated discrete Gaussian sampling algorithm to obtain a signature vector , where σ represents the generated ciphertext, signature, or output result, represents the private key, denotes the number-theoretic transform on the plaintext or message , represents the error term; S4. Signature Information Compression and Data Encapsulation Use a collision-resistant hash function to generate a digest; Construct a data packet , where: is the timestamp field, recording the data acquisition time, is the device identification field, used by the receiving party to identify the device source, and perform a chained hash calculation on the overall data packet to ensure cross-time tracing and anti-replay; S5. Data Reporting and Verification The terminal sends the signed data packet to the authentication server through the wireless communication module, and the receiving end uses the registered public key to verify the signature legality, including: reconstructing the fast number-theoretic transform, calculating the expected vector, verifying whether the timestamp is within the allowed range, whether it matches. If the verification is successful, the data is adopted and written into the database; if not, it is discarded and an alarm is issued.

[0052] In step four, the signature information noise addition process uses the centered truncated discrete Gaussian sampling algorithm and adaptively adjusts the sampling variance according to the standardized data block length to reduce the mean square signal power of the signature vector while ensuring the anti-quantum security level and reducing the risk of side-channel information leakage.

[0053] In step five, the packed data packet further includes a timestamp field and a device identification field, which are integrity-bound with the signature information through the chained hash method for cross-device and cross-time data tracing and anti-replay verification.

[0054] Please refer to Appendix Figure 3 , the complete logical process includes the following steps: Input Message Preprocessing: Input an arbitrary-length message m, and expand it to an integer multiple of 512 bits through the padding rule. The padding format is: ; where k is the smallest non-negative integer such that the total length = 448 mod 512, convert the message to a fixed format to adapt to subsequent lattice cryptographic operations; Derivative lattice basis vector: Use the message m to generate a seed through simple hashing, initialize the Mersenne Twister pseudo-random number generator (PRNG) based on the seed, and generate a lattice basis vector with a dimension of 1024 where q = 12289, , represents a two-dimensional array in the th row, th column of the element, refers to the Mersenne Twister algorithm, represents the random number seed, represents the row index or the offset during the generation process, and different random seeds are generated for each row through represents the modulo operation on the generated random number, and the mathematical basis is ; Generate error vector: Use 12 uniformly distributed samples to approximate the discrete Gaussian distribution, scale it to the standard deviation σ = 256, and generate the error vector , and the mathematical basis is , where represents the error vector, the standard deviation, which is clearly 256 here, a random variable uniformly distributed in the interval (-0.5, 0.5), sum the 12 uniformly distributed samples, round the result to the nearest integer, take the modulo of the result , so that the error value is limited within the range [0, q - 1]; Map the message to the lattice structure: Map the message m to the lattice basis vector B by bytes, calculate the linear combination , add the error vector e to get the intermediate state , and the mathematical basis is , where the message the th element of, the basis vector at the position the element of, is the th element of the final intermediate state vector ; Sponge construction absorption stage: Divide the intermediate state a' into rate and capacity parts, Rate = 512, Capacity = 512, perform bytewise exclusive OR on the input message, and perform a circular left shift operation: Circular left shift by 1 bit to destroy the linear structure through non-linear operations and resist the Grover algorithm; ​Number - theoretic transform: Apply the fast number - theoretic transform to the state matrix states, reducing the complexity of polynomial multiplication from to \(O(n\log n)\). Use the fast number - theoretic transform root \(\omega = 5\), which has been verified as a primitive root modulo 12289. The mathematical basis is ; Sponge construction squeezing stage: Extract the hash value from the state after the fast number - theoretic transform: = / / Absorption stage of the sponge construction

[0055] Output a 32 - byte (256 - bit) or 64 - byte (512 - bit) hash value. Retain the high - entropy information through bit truncation and XOR operations to resist collision attacks. Among them, represents the hash value or digest output of the message . state is an internal state array with a length of at least 1024. Take the lower 8 bits (bytes) of the state value modulo 256, : Right - shift 8 - bit operation to extract the upper 8 bits of the state value, and \(\oplus\) is the bit - wise exclusive - or (XOR) operation; Anti - quantum security reasoning process: Learning with errors problem reduction. If an adversary can break the hash function, then an algorithm can be constructed to solve the learning - with - errors instance, including the following reduction steps: Suppose the adversary finds a collision \(m_1\neq m_2\) such that \(H(m_1)=H(m_2)\), and it is deduced that \(A(m_1 - m_2)+(e_1 - e_2)\equiv0\bmod q\), where \(A\) is the lattice basis matrix. The differences \(\Delta m=m_1 - m_2\) and \(\Delta e=e_1 - e_2\) form a solution to the SIS problem, which contradicts the learning - with - errors hardness assumption; The circular left - shift operation in the absorption stage breaks the message locality, ensuring that a single - bit change spreads throughout the state. Anti - quantum property: The capacity part of the sponge structure, 512 bits, provides a quantum search complexity of \(O(2^{256})\), meeting the NIST Level III security requirements; The error vector \(e\) is dynamically bound to the message \(m\). The adversary cannot construct a collision by fixing the error. Even if the adversary obtains some statistical information of \(e\), since \(e\) depends on the message content, the global structure cannot be inferred. At the sender, the message is digested by this algorithm, and then the digest is placed in the message padding and sent together with the message. At the receiver, compare the transmitted data with the data HASH value. If they are inconsistent, it indicates that the data has been tampered with. This realizes a signature. The content in the message is the author's name plus the valid message.

[0056] The following is introduced in combination with specific embodiments: Embodiment 1: 256 - bit hash generation Input message: HelloQuantum; Length of the preprocessed message: 512 bits; Generate the lattice basis matrix B[0...1023] ∈ [0, 12288]; Calculate a' = (m·B + e) mod 12289; Perform sponge absorption to obtain a 1024-bit state; Output the first 256-bit hash value after fast number-theoretic transform.

[0057] The above is used for data transmission. The hash value is placed at the end of the data. Comparing the transmitted data with the data HASH value, if they are inconsistent, it indicates that the data has been tampered with. In the case of quantum computing, this algorithm can prevent the tamperer from finding another data with the same value, thus preventing data from being tampered with.

[0058] Example Two: V2X Scenario in Vehicular Network Input message: Autonomous driving sensor data stream, LiDAR point cloud, and camera frames; Preprocessing: Add timestamps and location tags according to the ISO21434 standard; Generate a 256-bit quantum-resistant hash value: A7F3D90E2B4C6A815E7F1D2C3A9B0E5D...

[0059] Meet the message authentication delay requirement within 100 ms in V2X communication; Defend against forgery attacks on historical driving data by quantum computers.

[0060] Example Three: Protection of Federated Learning Model Input message: Neural network gradient parameter matrix (float32[1024×1024]) Preprocessing: Convert floating-point numbers to IEEE754 format byte stream Generate a 512-bit model integrity hash: 3D4A...B8C9, the first 64 bytes.

[0061] Prevent tampering of distributed training parameters by quantum computing; The hash generation speed is 1.8 times faster than KyberHash, measured on AMD EPYC 7H12.

[0062] Example Four: Blockchain Transaction Signature Input message: ETH transaction data {from: 0x..., to: 0x..., value: 1.5 ETH} Generate a quantum-resistant hash: H(m) = 89A3F2B1..., 256 bits; Select a random number r = 0x5F8A1B0C...; Calculate c = H(r||pk||H(m)) → 0x3D2E4F7A...; Generate the signature σ=(z, c) → 1536 bytes; Verify that the passing rate > 99.99% (100,000 tests).

[0063] Gas optimization: After compressing the signature data, the Gas consumption = 42,000, compared with 68,000 of ECDSA, a 38% reduction; Verify the contract: Implement the verification algorithm through Solidity smart contract, the single-block processing capacity = 89 transactions, and the Ethereum block GasLimit = 30M; Anti-fork design: Signatures with a timestamp deviation > ±3 seconds will automatically become invalid to prevent double-spending attacks.

[0064] Example Five: Smart Contract Authorization Input message: Contract function transferFrom(owner, spender, 1000); Generate a hash chain with a timestamp: H_chain = H(H(m)||H_prev||timestamp); Use hierarchical signatures: Each level of contract call generates nested signatures To To ; Verification latency: < 200ms, measured on the Ethereum Geth node.

[0065] The encoding structure of data packed in ASN.1 encoding format: QuantumSignature::=SEQUENCE{ version INTEGER(1), timestamp GeneralizedTime, deviceID OCTETSTRING(SIZE(8)), signature BITSTRING(SIZE(256)), data OCTETSTRING }

[0066] The source code is as follows: / / Adopt the fast modular algorithm from Mersenne Twister

[0067]

[0068] y = state->mt[state->mti++];

[0069] Compression optimization: Apply the LZ4HC compression algorithm to the data field, with a compression ratio of ≥ 60%; Transport protocol: Support frame encapsulation in HTTP / 2, with the maximum MTU adapted to 1500 bytes.

[0070] Although embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An anti-quantum hash data signature method, characterized in that, It includes the following steps: Step 1, obtain the original data to be signed; Step 2, preprocess the original data to generate a standardized data block; Step 3, perform a finite field mapping process based on the fast number theory transform on the standardized data block using the fast number theory transform to obtain a transform result; Step 4, perform data signing on the transform result using a key pair constructed based on the learning with errors problem to generate signature information; Step 5, package the signature information and the original data together for subsequent data verification.

2. The anti-quantum hash data signature method according to claim 1, wherein: The prime modulus p used in the fast number-theoretic transform satisfies the form p = k·2 n + 1, where n is an integer greater than or equal to 1, k is a positive integer, and the fast number-theoretic transform operation uses the primitive root g modulo p for multiplication transformation.

3. The anti-quantum hash data signature method according to claim 1, characterized in that: The random error term used in the learning with errors problem follows a discrete Gaussian distribution and is generated independently.

4. A quantum-resistant hash data signature method according to claim 1, characterized in that: The signature information includes the following steps: Take the standardized data block as the plaintext input and perform matrix multiplication with the private key matrix to obtain an intermediate calculation vector; Add a pre-generated error term to the intermediate vector to construct a signature vector; Output the signature vector as signature information.

5. A quantum-resistant hash data signature method according to claim 1, characterized in that: In Steps 3 and 4, both the fast number theory transform parameters and the learning with errors signature parameters are pre-computed offline.

6. The anti-quantum hash data signature method according to claim 1, wherein: The key pair includes: A private key S for signature operations; A public key P generated from the private key S for signature verification and satisfying the security condition that the private key cannot be deduced from the public key.

7. A quantum-resistant hash data signature method according to claim 1, characterized in that: The signature information is compressed to a preset length by a hash function after generation.

8. A quantum-resistant hash data signature method according to claim 1, characterized in that: The method is applicable to the data authentication process in Internet of Things terminal devices and can effectively prevent data forgery or tampering under quantum computing attacks.

9. The anti-quantum hash data signature method according to claim 1, characterized in that: In Step 4, the noise addition process of the signature information uses a centered truncated discrete Gaussian sampling algorithm and adaptively adjusts the sampling variance according to the length of the standardized data block.

10. A quantum-resistant hash data signature method according to claim 1, characterized in that: In Step 5, the packaged data packet further includes a timestamp field and a device identification field, which are integrity-bound to the signature information through chained hashing for cross-device and cross-time data traceability and anti-replay verification.

Citation Information

Patent Citations

  • Method for rapidly generating information theory safety authentication information used for quantum secret communication

    CN104506312A

  • Digital signature method based on lattice difficulty problem

    CN110175473A

  • Novel incremental signature method based on ideal lattice

    CN112383394A

  • Tree link signature method for resisting quantum computing attack

    CN114338030A

  • Anti-quantum cryptography signature algorithm execution optimization method and system and electronic equipment

    CN119766429A