Anti-quantum enhancement method and device for stock password equipment system

By introducing a combination architecture of anti-quantum FPGA chips and classic cryptographic chips into existing classic cryptographic devices, the problems of insufficient security and high replacement costs of classic cryptographic devices in the quantum computer era are solved, and the smooth anti-quantum migration and security upgrade of the device is achieved, ensuring forward security and backward compatibility.

CN120200746AInactive Publication Date: 2025-06-24FUDAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510390704.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing classic cryptographic devices face problems of insufficient security and high replacement costs in the era of quantum computers, which has led to the urgent need for the industry and academia to upgrade resistant to quantum security without destroying the hardware architecture.

Method used

The architecture based on anti-quantum FPGA chip combined with classic cryptographic chips is adopted to provide anti-quantum cryptographic cards and doorman-style anti-quantum security enhancement devices, which are used for existing classic cryptographic devices with PCIe interfaces and without PCIe interfaces, respectively, to achieve smooth anti-quantum migration and security upgrades to existing classic cryptographic devices.

Benefits of technology

Without changing the original hardware architecture, forward security and backward compatibility of existing classic cryptographic devices are achieved, extending the service life of the equipment and reducing migration costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200746A_ABST
    Figure CN120200746A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum enhancement method and an anti-quantum enhancement device for a stock password equipment system. According to the method, an anti-quantum cryptographic card or doorkeeper type anti-quantum security enhancement device is connected with the anti-quantum cryptographic card or doorkeeper type anti-quantum security enhancement device on the premise that the hardware architecture of the stock classical cryptographic device is not changed, and anti-quantum security enhancement is provided; the stock classical cryptographic equipment system refers to a cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, a software system and the like deployed with a classical cryptographic algorithm incapable of resisting quantum attacks; the anti-quantum cryptographic card is a cryptographic card supporting a classical cryptographic algorithm and an anti-quantum cryptographic algorithm, a classical cryptographic chip, an anti-quantum FPGA chip and other components are arranged on the anti-quantum cryptographic card, and the anti-quantum cryptographic card is connected with stock classical cryptographic equipment through a PCIe interface. The entrance guard type anti-quantum security enhancement equipment is electronic equipment which is deployed between classical cryptographic equipment and a public network and is used for carrying out anti-quantum security protection on a Diffie-Hellman type cryptographic protocol or a digital envelope key exchange process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of anti-quantum cryptography and information security technology, and in particular to an anti-quantum enhancement method, device and equipment for an existing classical cryptographic device system. Background Art

[0002] Most of the currently deployed public-key cryptosystems are based on the problems of large integer factorization, discrete logarithm, and discrete logarithm on elliptic curves. However, the above difficult problems are considered to be solvable in polynomial time on a quantum computer. Currently, the engineering construction of quantum computers has continuously achieved breakthroughs, and its super computing power poses a potential risk of breaking the current public-key cryptosystem. Therefore, academia and industry have successively carried out cryptographic research that can resist quantum computing attacks, namely post-quantum cryptography (PQC), also known as quantum-safe cryptography, which mainly includes hash-based, code-based, multivariate-based, lattice-based and other routes. Among many technical routes, lattice-based cryptography has achieved good performance in terms of security, bandwidth size, and computing efficiency, and can construct various cryptographic algorithms and protocols, such as public-key encryption, digital signature, key agreement cipher, etc., and is called one of the most promising technical routes.

[0003] In the transitional stage from classical cryptography to anti-quantum cryptography, the currently used classical cryptographic devices face the problems of insufficient security and high replacement costs. For example, only some cryptographic algorithms in the existing classical cryptographic chips and devices are affected by quantum computing. If all the existing cryptographic chips and devices are scrapped due to anti-quantum migration, it will inevitably cause a huge waste of economic resources. How to ensure the system compatibility and stability of the existing cryptographic device hardware architecture, and perform anti-quantum security upgrades on the existing classical cryptographic devices in a lower-cost and smoother migration manner, and extend the application of the existing classical cryptographic devices and chips in the quantum computing era has become a realistic problem that needs to be solved urgently by the industrial and academic communities. Summary of the Invention

[0004] In view of this, the present invention provides a quantum-resistant enhancement method, device, and equipment for an existing classical cryptographic device system, which can enhance quantum-resistant security without changing its hardware structure. In the context of the present invention, the existing classical cryptographic device system may include multiple existing classical cryptographic devices. Generally speaking, the existing classical cryptographic device system includes one or more of a classical cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, and a software system. The present invention realizes the smooth quantum-resistant migration of existing classical cryptographic chips and devices, ensures the forward security and backward compatibility of the communication link, and extends the service life of existing classical cryptographic chips and devices. It ensures that the existing classical cryptographic chips can continue to be applied in the post-quantum era based on the board card architecture of the present invention, and the existing classical cryptographic device system can use the doorman device of the present invention in a black box manner for quantum-resistant upgrade. The specific solutions are as follows:

[0005] In a first aspect, the present invention discloses a quantum-resistant enhancement method for an existing classical cryptographic device system. The method specifically includes:

[0006] For existing classical cryptographic devices with a PCIe interface, a quantum-resistant cryptographic card based on a quantum-resistant FPGA chip combined with a classical cryptographic chip architecture is used and built into the device as a sub-module. At this time, the existing classical cryptographic device serves as the host computer, and the quantum-resistant cryptographic card serves as the slave computer. The two communicate with each other through PCIe. The host computer application layer calls the quantum-resistant cryptographic card SDK to complete classical cryptographic functions and quantum-resistant cryptographic functions.

[0007] For existing classical cryptographic devices that do not have a PCIe interface or do not allow the chassis to be opened, a doorman-style quantum-resistant security enhancement device is used and placed outside between the classical cryptographic device and the public network. The two communicate with each other through a network port. At this time, the doorman-style quantum-resistant security enhancement device only provides quantum-resistant security protection for the key information in the Diffie-Hellman type cryptographic protocol or the digital envelope key exchange process, without changing its system interaction process.

[0008] In a second aspect, the present invention discloses a quantum-resistant enhancement device for an existing classical cryptographic device system, which provides a low-cost quantum-resistant hybrid working mode for existing classical cryptographic chips and provides a solution for their full-cycle application in the pre-quantum and post-quantum eras. It has two hardware architectures, specifically including:

[0009] A quantum-resistant FPGA chip, which is used to deploy quantum-resistant cryptographic algorithms, communicate with the host computer, and manage keys. It has a configurable and parallel architecture and can quickly configure multiple quantum-resistant cryptographic standards;

[0010] Classical cryptographic chips are used to provide classical cryptographic algorithms, communicate data with the host computer, and manage keys. They can be divided into two categories from the chip architecture: Soc classical cryptographic chips and non-Soc classical cryptographic chips. In terms of chip form, they exist in two forms. The first is a single-chip structure, which integrates classical cryptographic chips with non-open-source algorithms, such as one or more of SM1 and SM7. The second is a two-chip structure, one of which supports non-open-source classical cryptographic algorithms and the other supports open-source classical cryptographic algorithms.

[0011] The random number module is used to generate physically noisy source random numbers and simultaneously support access by quantum-resistant FPGA chips and classical cryptographic chips.

[0012] The storage module is used to save calculation programs, user configuration information, and key information, and simultaneously support access by quantum-resistant FPGA chips and classical cryptographic chips.

[0013] The PCIe module is used for data communication and on-board power supply.

[0014] In the first hardware architecture, the Soc classical cryptographic chip is used as the main chip and is directly connected to the PCIe module, responsible for protocol parsing, data forwarding, and key management functions. The quantum-resistant FPGA chip is used as the slave chip 1, responsible for quantum-resistant cryptographic algorithm functions, and is connected to the main chip through one or more of the AXI, AHB, and APB bus protocols. The non-open-source classical cryptographic chip is used as the slave chip 2, responsible for non-open-source domain-specific classical cryptographic algorithm functions, and is connected to the main chip through one or more of the SPI, IIC, and UART protocols. The host computer can directly interact with the slave chip 1 for data.

[0015] In the second hardware architecture, the quantum-resistant FPGA is used as the main chip and is directly connected to the PCIe module, responsible for protocol parsing, data forwarding, and key management functions. The non-Soc classical cryptographic chip is used as the slave chip 1, responsible for classical cryptographic algorithm functions. The non-open-source classical cryptographic chip is used as the slave chip 2, responsible for non-open-source domain-specific cryptographic algorithm functions. The main chip uses one or more of the SPI, IIC, and UART protocols to interact with the slave chip 1 and the slave chip 2 for data.

[0016] Thirdly, the present invention discloses a quantum-resistant enhancement device for an existing classical cryptographic device system, providing a solution for the application of existing classical cryptographic devices in the pre-quantum and post-quantum eras, specifically including:

[0017] For the existing classical cryptographic device sender A and receiver B, the Diffie-Hellman-like cryptographic protocol is adopted, and the session key between the two parties is K = KDF(g xy ,r A ,r B, aux) is obtained, where KDF is a key derivation function, and g xy = CDH(g x , g y ), r A is the random nonce of sender A, r B is the random nonce of receiver B, aux is other public information exchanged between the two parties, and g x , g y are the ephemeral public key information publicly transmitted in the original protocol; The guard-style quantum-resistant security enhancement devices GA and GB are respectively connected in series between sender A, receiver B and the public network, and perform quantum-resistant security protection on any non-empty subset of the set {[g x , [g y , [r A , [r B , [aux]}, where GA performs quantum-resistant encryption on any non-empty subset of {[g x , [g y , [r A , [r B , [aux]}, and GB performs corresponding quantum-resistant decryption;

[0018] For the existing classical cryptographic devices sender A and receiver B, the classical key encapsulation digital envelope protocol is adopted, and the session key of both parties is obtained by K = KDF(K, c A , pk B , auxK), where K is the key encrypted or encapsulated by the ciphertext c A , c A is the ciphertext encrypted by sender A using the public key pk B of receiver B, and auxK is other public information exchanged between the two parties; For this case, the guard-style quantum-resistant security enhancement devices GA and GB perform quantum-resistant security protection on any non-empty subset of the set {[c A , [auxK]}, where GA performs quantum-resistant encryption on any non-empty subset of {[c A , [auxK]}, and GB performs corresponding quantum-resistant decryption.

[0019] A memory for storing computer programs, configuration information, and key information of the quantum-resistant FPGA and classical cryptographic chips;

[0020] A data communication module for connecting classical cryptographic devices and the public network;

[0021] A processor for executing the computer program to implement the quantum-resistant security enhancement method as described above. Description of the Drawings

[0022] To more clearly illustrate the technical solutions in the present invention, the accompanying drawings required for the description of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0023] Figure 1 Schematic diagram of an anti - quantum cryptographic card provided by an embodiment of the present invention Figure 1 ;

[0024] Figure 2 Schematic diagram of an anti - quantum cryptographic card provided by an embodiment of the present invention Figure 2 ;

[0025] Figure 3 Schematic diagram of the working process of a doorman - style anti - quantum security enhancement device provided by an embodiment of the present invention. Detailed implementation manners

[0026] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0027] Existing classical cryptographic devices and chips have the following problems: First, quantum computers only affect the security of some classical cryptographic algorithms in the existing classical cryptographic chips, devices, and systems. Completely replacing them as a whole will cause huge economic waste; Second, quantum computers continue to make breakthroughs, and the current working mode is difficult to guarantee the forward security of the cryptographic system; Third, when the era of quantum computing fully arrives, the existing application architecture still needs to be replaced, lacking backward compatibility. To solve the above - mentioned technical problems, the present invention discloses an anti - quantum enhancement method, device, and equipment for classical cryptographic device systems, which can perform anti - quantum security enhancement on them in a low - cost and smoother manner, having forward security and backward compatibility without changing the original device hardware architecture, effectively maintaining the original interaction framework, and providing a solution for the full - cycle application of existing classical cryptographic devices and chips.

[0028] See Figure 1 As shown, the present invention discloses an anti - quantum security enhancement device for existing classical cryptographic devices, adopting an anti - quantum FPGA + Soc classical cryptographic chip architecture, including:

[0029] The Soc classical cryptographic chip serves as the main chip and has an on-chip operating system to handle functions such as protocol parsing, request scheduling, key management, and open-source classical cryptographic algorithms; the quantum-resistant FPGA chip serves as slave chip 1 to deploy quantum-resistant cryptographic algorithms and has scalability; the non-open-source classical cryptographic chip serves as slave chip 2 to deploy non-open-source classical cryptographic algorithms; the TRNG module is a random number module that provides physical noise source random numbers for the quantum-resistant cryptographic card. The main chip has multi-channel PCIe protocol interfaces, communicates with the host computer through the PCIe protocol, and uses one or more of the AXI, AHB, and APB bus protocols to interact with slave chip 1, and the data packets are arranged according to the communication protocol fields; it uses one or more of the SPI, IIC, and UART protocols to interact with slave chip 2.

[0030] When the host computer requests classical cryptographic functions, the main chip and slave chip 2 perform response processing; when the host computer requests quantum-resistant cryptographic functions, there are two working modes: The first: the main chip forwards the requirements to slave chip 1, and slave chip 1 performs response processing, and the result is returned to the host computer through the main chip; The second: through the main chip transparent transmission mode, slave chip 1 directly performs response processing, and the result is directly returned to the host computer.

[0031] See Figure 2 As shown, the present invention discloses a quantum-resistant security enhancement device for existing classical cryptographic devices, adopting a quantum-resistant FPGA + non-Soc classical cryptographic chip architecture, including:

[0032] The quantum-resistant FPGA chip serves as the main chip to handle functions such as protocol parsing, request scheduling, key management, and quantum-resistant cryptographic algorithms, communicates with the host computer through PCIe, and the data packets are arranged according to the communication protocol; the non-Soc classical cryptographic chip serves as slave chip 1 to provide open-source classical cryptographic algorithm functions. The non-open-source classical cryptographic chip serves as slave chip 2 to provide non-open-source classical cryptographic algorithm functions. The main chip uses one or more of the SPI, IIC, and UART protocols to interact with slave chip 1 and slave chip 2.

[0033] When the host computer requests classical cryptographic functions, the main chip forwards the requirements to slave chip 1 and slave chip 2 respectively for processing according to the cryptographic identifier, and the result is returned to the host computer through the main chip; when the host computer requests quantum-resistant cryptographic functions, the main chip performs response processing.

[0034] The functions of each segment of the quantum-resistant FPGA chip communication protocol are shown in Table 1. The data packet consists of three parts: a packet header, a packet body, and a packet tail:

[0035] Table 1 Quantum-resistant FPGA data communication protocol

[0036]

[0037]

[0038] For the function numbers in Table 1, Table 2 gives the specific implementation manners, covering anti-quantum key encapsulation algorithms and digital signature algorithms, including:

[0039] Table 2 Function Instruction Table

[0040]

[0041] See Figure 3 As shown, the present invention discloses a doorman-style anti-quantum security enhancement device, including:

[0042] The sender A and the receiver B of the existing classical cryptographic devices are two users using a public key cryptosystem. The multi-channel doorman-style anti-quantum security enhancement device GA is deployed between the existing classical cryptographic device A and the public network, and the multi-channel doorman-style anti-quantum security enhancement device GB is deployed between the existing classical cryptographic device B and the public network. Without changing the protocol interaction process of the existing devices, anti-quantum security protection is carried out on the Diffie-Hellman type cryptographic protocol or the digital envelope key exchange process. The specific implementation steps are as follows:

[0043] Step 1: The sender A sends a data frame containing the key information g x to the doorman-style anti-quantum security enhancement device GA;

[0044] Step 2: After receiving the data frame, the doorman-style anti-quantum security enhancement device GA parses out the key information g x and then performs anti-quantum security protection using the anti-quantum encryption public key pk GB of the multi-channel doorman-style anti-quantum security enhancement device GB;

[0045] Step 3: Package and send the anti-quantum ciphertext ct1 and the original data frame;

[0046] Step 4: After receiving the ciphertext, the multi-channel doorman-style anti-quantum security enhancement device GB uses the anti-quantum encryption private key sk GB to decrypt the key information g x ;

[0047] Step 5: The multi-channel doorman-style anti-quantum security enhancement device GB sends g x to the receiver B;

[0048] Step 6: The receiver B sends the key information g y to the multi-channel doorman-style anti-quantum security enhancement device GB;

[0049] Step 7: After receiving the data frame, the multi-channel guard-style quantum-resistant security enhancement device GB parses out the key information g y and then uses the quantum-resistant encryption public key pk GA of the guard-style quantum-resistant security enhancement device GA for quantum-resistant security protection;

[0050] Step 8: Package and send the quantum-resistant ciphertext ct2 and the original data frame;

[0051] Step 9: After receiving the ciphertext, the guard-style quantum-resistant security enhancement device GA uses the quantum-resistant encryption private key sk GA to decrypt the key information g y ;

[0052] Step 10: The guard-style quantum-resistant security enhancement device GA sends g y to the sender A.

[0053] For Diffie-Hellman-like cryptographic protocols, the key information g x , g y in the figure can be replaced by any non-empty subset of the set {[g x , [g y , [r A , [r B , [aux]}, and the session key is obtained by K = KDF(g xy , r A , r B , aux), where KDF is a key derivation function, g xy = CDH(g x , g y ), r A is the random nonce of the sender A, r B is the random nonce of the receiver B, and aux is other public information exchanged between the two parties. g x , g y are the temporarily public key information publicly transmitted in the original protocol; for classical key encapsulation digital envelope protocols, the key information g x , g y in the figure can be replaced by any non-empty subset of the set {[c A , [auxK]}, and the session key is obtained by K = KDF(K, c A , pk B , auxK), where K is the key encrypted or encapsulated by the ciphertext c A , c A is the ciphertext encrypted by the sender A using the public key pk B of the receiver B, and auxK is other public information exchanged between the two parties.

[0054] The anti-quantum security enhancement method, device, and equipment proposed by the present invention adopt a pluggable design. The host computer can dynamically select anti-quantum cryptographic algorithms according to parameter configuration. The anti-quantum cryptographic card does not change the device's hardware circuit and can replace the existing classical cryptographic card. The anti-quantum FPGA chip on the board retains the algorithm scalability, and the host computer can complete the software upgrade only by adding anti-quantum cryptographic instructions. The guard-style anti-quantum cryptographic device does not change the existing protocol interaction process and is independent of the existing classical cryptographic devices. The present invention can enhance the anti-quantum security of existing classical cryptographic devices and chips in a low-cost and loosely coupled manner, ensuring the forward security and backward compatibility of the cryptographic system.

[0055] Example 1. An anti-quantum enhancement method for an existing classical cryptographic device system, the method comprising:

[0056] For existing classical cryptographic devices with a PCIe interface, an anti-quantum cryptographic card is adopted in an internal integrated manner. The anti-quantum cryptographic card performs data interaction with the existing classical cryptographic device through the PCIe interface, adopts a hybrid architecture of an anti-quantum FPGA programmable device and a classical cryptographic chip, provides classical cryptographic algorithm and anti-quantum cryptographic algorithm functions, and supports the continued use of existing classical cryptographic chips in the post-quantum era;

[0057] For existing classical cryptographic devices that do not have a PCIe interface or do not allow the chassis to be opened, a guard-style anti-quantum security enhancement device is adopted in an external independent manner. The guard-style anti-quantum security enhancement device performs data interaction with the existing classical cryptographic device through a high-speed interface such as an optical fiber, supports multi-channel access, adopts an anti-quantum encryption algorithm, and performs anti-quantum security protection on the key exchange process and digital envelope key encapsulation process based on Diffie-Hellman type cryptographic protocols and elliptic curve derivative protocols, realizing the black-box anti-quantum security enhancement of the existing classical cryptographic device system.

[0058] Example 2. The anti-quantum enhancement method according to Example 1, wherein the classical cryptographic algorithm refers to a cryptographic algorithm constructed based on the difficult problems of large integer factorization, discrete logarithm / discrete logarithm on an elliptic curve, and the existing classical cryptographic device system is one or more of a cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, and a software system that support the classical cryptographic algorithm;

[0059] Among them, the anti-quantum cryptographic algorithm refers to a cryptographic algorithm that can resist attacks from classical computers and quantum computers and can run on classical computers, including lattice-based, hash-based, code-based, multivariate-based, and isogeny-based.

[0060] Example 3. The quantum-resistant enhancement method according to Example 1 is characterized in that the classical cryptographic chip uses the ASIC form to integrate one or more classical cryptographic algorithms into the chip, including the Soc classical cryptographic chip and the non-Soc classical cryptographic chip, and supports SM1, SM2, SM3, SM4, SM7, SM9, AES, RSA, and EC-DSA algorithms.

[0061] Example 4. The quantum-resistant enhancement method according to Example 1 is characterized in that the quantum-resistant cryptographic card adopts two architectures: the quantum-resistant FPGA combined with the Soc classical cryptographic chip and the quantum-resistant FPGA combined with the non-Soc classical cryptographic chip, and supports both classical cryptographic algorithms and quantum-resistant cryptographic algorithms at the same time, ensuring the full-cycle application of the classical cryptographic chip in the pre-quantum and post-quantum eras;

[0062] Among them, the existing classical cryptographic device serves as the host computer, and the quantum-resistant cryptographic card serves as the slave computer. Data communication is carried out through the PCIe interface. The quantum-resistant cryptographic card includes one or more of a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, a PCIe interface, a network port, a USB3.0, a serial port, and an expansion interface. Quantum-resistant cryptographic algorithms are deployed inside the quantum-resistant FPGA, and multiple quantum-resistant algorithms can be extended.

[0063] Example 5. The quantum-resistant enhancement method according to Example 1 is characterized in that the doorman-style quantum-resistant security enhancement device includes a processor, a memory, and a computing program stored in the memory and capable of running on the processor;

[0064] Among them, the doorman-style quantum-resistant security enhancement devices GA and GB are deployed between the existing classical cryptographic device sender A, receiver B and the public network, and perform quantum-resistant security protection on the key data frames during the system key exchange process of the existing classical cryptographic device. Without changing the original protocol interaction, it ensures the full-cycle application of the classical cryptographic device in the pre-quantum and post-quantum eras;

[0065] Among them, for the Diffie-Hellman type cryptographic protocol, the session keys of the existing classical cryptographic device sender A and receiver B are obtained by K = KDF(g xy ,r A ,r B ,aux), where KDF is the key derivation function, g xy = CDH(g x ,g y ), r A is the random nonce of sender A, r B is the random nonce of receiver B, aux is other public information exchanged between both parties, g x ,g yis the temporary public key information publicly transmitted by the original protocol; for a string str ∈ {0, 1} * , [R] represents any non-empty substring of R and its equivalent variants, and the equivalent variants of a string refer to those that can recover the original string in a pre-agreed manner; let [g x represent any non-empty substring of g x and its equivalent variants, [g y represent any non-empty substring of g y and its equivalent variants, [r A represent any non-empty substring of r A and its equivalent variants, [r B represent any non-empty substring of r B and its equivalent variants, [aux] represent any non-empty substring of aux and its equivalent variants; the guard-style quantum-resistant security enhancement devices GA and GB perform quantum-resistant security protection on any non-empty subset of the set {[g x , [g y , [r A , [r B , [aux]}, where GA performs quantum-resistant encryption on any non-empty subset of {[g x , [g y , [r A , [r B , [aux]}, and GB performs the corresponding quantum-resistant decryption;

[0066] Among them, for the classical key encapsulation digital envelope protocol, the session keys of the legacy classical cryptographic devices sender A and receiver B are obtained by K = KDF(K, c A , pk B , auxK), where K is the key encrypted or encapsulated by the ciphertext c A , c A is the ciphertext encrypted by the sender A using the public key pk B of the receiver B, and auxK is other public information exchanged between the two parties; for this case, the guard-style quantum-resistant security enhancement devices GA and GB perform quantum-resistant security protection on any non-empty subset of the set {[c A , [auxK]}, where GA performs quantum-resistant encryption on any non-empty subset of {[c A , [auxK]}, and GB performs the corresponding quantum-resistant decryption.

[0067] Example 6. According to the quantum-resistant enhancement method described in Example 4, it is characterized in that the top-level module of the quantum-resistant FPGA for implementing functions includes an algorithm module, a communication module, and a management module;

[0068] The algorithm module is configured to complete quantum-resistant public key encryption algorithms and digital signature algorithms, and includes six sub-modules:

[0069] The key generation module is configured to generate public and private keys for public key encryption and digital signature algorithms;

[0070] The encryption module is configured to perform encryption calculations or key encapsulation calculations;

[0071] The decryption module is configured to perform decryption calculations or key decapsulation calculations;

[0072] The signature module is configured to perform signature calculations on messages;

[0073] The signature verification module is configured to perform signature verification calculations;

[0074] The hash module is configured to perform hash calculations and random bit stream generation calculations;

[0075] The communication module is configured to complete the interaction between the quantum-resistant FPGA and external data. When the host computer and the classical cryptographic chip of the Soc send data to the quantum-resistant FPGA, it is a request data packet, and when the quantum-resistant FPGA sends data to the host computer and the classical cryptographic chip of the Soc, it is a response data packet. Among them, the data packets are arranged according to the communication protocol fields and consist of three parts: a packet header, a packet body, and a packet tail:

[0076] The packet header is used to indicate the function category of the data packet, the packet destination, version information, algorithm parameters, etc. The specific fields include: function number, request / response, sequence number, version number, transaction number, cryptographic identifier, data packet number, whether it is the last packet, public key length, private key length, plaintext length, signature / ciphertext length, encapsulated key length, and other data lengths;

[0077] The packet body is used to place the data corresponding to each field of the packet header, including public key, private key, plaintext, signature, ciphertext, encapsulated key, sequence number, and version number corresponding data;

[0078] The packet tail is used to verify the correctness of data packet transmission and uses a CRC checksum;

[0079] The communication module instructions include two types: service instructions and algorithm instructions, including:

[0080] The factory configuration instruction is a service instruction. The host computer and the classical cryptographic chip of the Soc send a request data packet, and the packet header fields include the sequence number, version number, and function code. Among them, the quantum-resistant FPGA returns an execution result response data packet;

[0081] The power-on self-check instruction is a service instruction. The host computer and the classical cryptographic chip of the Soc send a request data packet to start the self-check function. Among them, the quantum-resistant FPGA returns a self-check result response data packet;

[0082] The key generation instruction is an algorithm instruction used to generate a public key and a private key. The host computer and the Soc classical cryptographic chip send a request data packet, and start the corresponding key generation calculation according to the cryptographic identifier. The anti-quantum FPGA returns a response data packet, and the packet body fields include the public key and private key data;

[0083] The encryption instruction is an algorithm instruction used to perform encryption calculation and key encapsulation calculation. The host computer and the Soc classical cryptographic chip send a request data packet, and start the corresponding calculation according to the cryptographic identifier. The packet body fields include the public key data and the optional data to be encrypted. The anti-quantum FPGA returns a response data packet, and the packet body fields include the ciphertext and the encapsulated key data;

[0084] The decryption instruction is an algorithm instruction used to perform decryption calculation and decapsulation calculation. The host computer and the Soc classical cryptographic chip send a request data packet, and start the corresponding calculation according to the cryptographic identifier. The packet body fields include the private key and ciphertext data. The anti-quantum FPGA returns a response data packet, and the packet body fields include the plaintext and the encapsulated key data;

[0085] The signature instruction is an algorithm instruction used to perform signature calculation. The host computer and the Soc classical cryptographic chip send a request data packet, and start the signature calculation according to the cryptographic identifier. The packet body fields include the private key and message data. The anti-quantum FPGA returns a response data packet, and the packet body fields include the signature data;

[0086] The signature verification instruction is an algorithm instruction used to perform signature verification calculation. The host computer and the Soc classical cryptographic chip send a request data packet, and start the decryption calculation according to the cryptographic identifier. The packet body fields include the public key, message, signature, and string data. The anti-quantum FPGA sends a response data packet, and the packet body field is the signature verification result data;

[0087] The management module is configured to complete the board timing planning, request scheduling, and key management functions.

[0088] Example 7. According to the anti-quantum enhancement method described in Example 4, it is characterized in that the anti-quantum FPGA combined with the Soc classical cryptographic chip architecture includes three types of cryptographic chips and has two working modes;

[0089] Among them, the classic cryptographic chip of Soc is the main chip, which is used to complete classic cryptographic algorithms, host computer data communication, data forwarding, and key management functions; the quantum-resistant FPGA chip is the slave chip 1, which is used to complete quantum-resistant cryptographic algorithm functions; the dedicated non-open-source cryptographic chip is the slave chip 2, which is used to complete non-open-source domain-specific classic cryptographic algorithm functions, and the slave chip 2 is an optional configuration; the main chip and the slave chip 1 use one or more of the AXI, AHB, and APB bus protocols to complete quantum-resistant cryptographic data communication; the main chip and the slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete non-open-source domain-specific classic cryptographic data communication;

[0090] Among them, in the first working mode: both the quantum-resistant cryptographic and classic cryptographic requests sent by the host computer are processed by the main chip; in the second working mode: the quantum-resistant cryptographic request sent by the host computer is directly processed by the slave chip 1, the data packets are arranged according to the communication protocol fields, and the classic cryptographic requests are processed by the main chip and the slave chip 2 respectively according to the cryptographic identifiers.

[0091] Example 8. The quantum-resistant enhancement method according to Example 4, characterized in that the quantum-resistant FPGA combines a non-Soc classic cryptographic chip architecture, including three types of cryptographic chips, where the quantum-resistant FPGA chip is the main chip, which is used to complete quantum-resistant cryptographic algorithms, host computer data communication, data forwarding, and key management functions; the non-Soc classic cryptographic chip is the slave chip 1, which is used to complete classic cryptographic algorithm functions; the dedicated non-open-source cryptographic chip is the slave chip 2, which is used to complete non-open-source domain-specific classic cryptographic algorithm functions, and the slave chip 2 is an optional configuration; the main chip and the slave chips 1 and 2 use one or more of the SPI, IIC, and UART protocols to complete classic cryptographic data communication;

[0092] Among them, the quantum-resistant cryptographic request sent by the host computer is processed by the main chip, the data packets are arranged according to the communication protocol fields, and the classic cryptographic request sent by the host computer is forwarded by the main chip to the slave chips 1 and 2 respectively according to the cryptographic identifiers for processing.

[0093] Example 9. The quantum-resistant enhancement method according to Example 4, characterized in that the key transmission and storage methods of the quantum-resistant cryptographic card include:

[0094] For the quantum-resistant FPGA combined with the Soc classic cryptographic chip architecture, the key data is transmitted between the quantum-resistant FPGA and the Soc classic cryptographic chip through one or more of the AXI, AHB, and APB bus protocols; the Soc classic cryptographic chip uses a symmetric encryption algorithm to store the quantum-resistant cryptographic private key in the on-board memory in ciphertext form;

[0095] For the anti-quantum FPGA combined with the non-Soc classical cryptographic chip architecture, key data is transmitted between the anti-quantum FPGA and the classical cryptographic chip through one or more of the SPI, IIC, and UART protocols; the anti-quantum FPGA chip stores the anti-quantum cryptographic private key in the on-board memory.

[0096] Example 10. The anti-quantum enhancement method according to Example 4, characterized in that the anti-quantum cryptographic card uses a cryptographic identifier and a user identifier, supports multi-user key storage under multiple cryptographic algorithms; when a cryptographic algorithm request is made, it is judged whether there is corresponding key data on the board according to the identifier; if not, the corresponding information needs to be transmitted; if so, there is no need to resend, saving communication bandwidth.

[0097] Among them, for the anti-quantum FPGA combined with the Soc classical cryptographic chip architecture: when an error is reported due to the loss of anti-quantum key data inside the anti-quantum FPGA, it can actively send an error code to the Soc classical cryptographic chip and request to resend the key data under this identifier; when an error is reported due to the loss of anti-quantum key data in the Soc classical cryptographic chip, it can actively send an error code to the anti-quantum FPGA and request to resend the anti-quantum key data under this identifier; when an error is reported due to the loss of anti-quantum key data inside the anti-quantum cryptographic card, it can actively send an error code to the host computer and request to restart the session; when an error is reported due to the loss of classical key data inside the anti-quantum cryptographic card, it can actively send an error code to the host computer and request to restart the session.

[0098] For the anti-quantum FPGA combined with the non-Soc classical cryptographic chip architecture: when an error is reported due to the loss of anti-quantum key data inside the anti-quantum cryptographic card, it can actively send an error code to the host computer and request to restart the session; when an error is reported due to the loss of classical key data in the non-Soc classical cryptographic chip, it can actively send an error code to the anti-quantum FPGA and request to resend the key data under this identifier; when an error is reported due to the loss of classical key data inside the anti-quantum cryptographic card, it can actively send an error code to the host computer and request to restart the session.

[0099] Example 11. The anti-quantum enhancement method according to Example 4, characterized in that the random number generator generates physical noise source random numbers, which comply with the national commercial cryptography authentication standard, and uses one or more of the SPI, IIC, and UART protocols to perform data interaction with the anti-quantum FPGA and the Soc classical cryptographic chip respectively.

[0100] Example 12. The anti-quantum enhancement method according to Example 4, characterized in that through the memory, the anti-quantum FPGA chip and the Soc classical cryptographic chip can respectively access the programs, key information, and user configuration information they use.

[0101] Example 13. A quantum-resistant security enhancement device for an existing classical cryptographic device system, comprising a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, and a computing program stored in the memory and running on the quantum-resistant FPGA or the classical cryptographic chip, characterized in that the quantum-resistant FPGA or the classical cryptographic chip executes the computer program to implement the quantum-resistant enhancement method described in any one of Examples 1-12 above.

[0102] Example 14. An electronic device, comprising a memory, a processor, and a computing program stored in the memory and capable of running on the processor, characterized in that the processor executes the computer program to implement the quantum-resistant enhancement method described in any one of Examples 1-12 above.

[0103] Example 15. A computer-readable storage medium, on which a computer program is stored, characterized in that when the program is executed by a processor, it implements the quantum-resistant enhancement method described in any one of Examples 1-12 above.

[0104] Example 16. A computer program product, comprising a computer program / instructions, characterized in that when the computer program / instructions are executed by a processor, they implement the quantum-resistant enhancement method described in any one of Examples 1-12 above.

[0105] Those skilled in the art should understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A quantum resistance enhancement method for existing classical cryptographic device systems, the method comprising: For existing classical cryptographic devices with PCIe interfaces, quantum-resistant cryptographic cards are used in an internally integrated manner. The quantum-resistant cryptographic cards interact with existing classical cryptographic devices through PCIe interfaces, and adopt a hybrid architecture of quantum-resistant FPGA programmable devices and classical cryptographic chips, providing classical cryptographic algorithms and quantum-resistant cryptographic algorithm functions, supporting the continued use of existing classical cryptographic chips in the post-quantum era. For existing classical cryptographic devices that do not have a PCIe interface or are not allowed to open the chassis, a gatekeeper-type anti-quantum security enhancement device is used in an external independent manner. The gatekeeper-type anti-quantum security enhancement device interacts with the existing classical cryptographic devices through a high-speed interface, supports multi-channel access, and uses an anti-quantum encryption algorithm to perform anti-quantum security protection on the key exchange process and digital envelope key encapsulation process based on the Diffie-Hellman type cryptographic protocol and the elliptic curve derivative protocol, thereby realizing black box anti-quantum security enhancement of the existing classical cryptographic device system.

2. The quantum resistance enhancement method according to claim 1, characterized in that: The classical cryptographic algorithm refers to a cryptographic algorithm constructed based on large integer decomposition, discrete logarithm / discrete logarithm difficulty problem on elliptic curve, and the existing classical cryptographic device system is one or more of a cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, and a software system that supports the classical cryptographic algorithm; Among them, quantum-resistant cryptographic algorithms refer to cryptographic algorithms that can resist attacks from classical computers and quantum computers and can run on classical computers, including lattice-based, hash-based, coding-based, multivariate-based, and homology-based.

3. The quantum resistance enhancement method according to claim 1, characterized in that: The classic cryptographic chip uses ASIC form to solidify one or more classic cryptographic algorithms, including Soc classic cryptographic chips and non-Soc classic cryptographic chips, supporting SM1, SM2, SM3, SM4, SM7, SM9, AES, RSA, and EC-DSA algorithms.

4. The quantum resistance enhancement method according to claim 1, characterized in that: The quantum-resistant cryptographic card adopts two architectures: quantum-resistant FPGA combined with Soc classic cryptographic chip, and quantum-resistant FPGA combined with non-Soc classic cryptographic chip. It supports both classic cryptographic algorithms and quantum-resistant cryptographic algorithms, ensuring the full-cycle application of classic cryptographic chips in the pre-quantum and post-quantum eras. Among them, the existing classical cryptographic equipment serves as the host computer, and the anti-quantum cryptographic card serves as the slave computer, and data communication is carried out through the PCIe interface. The anti-quantum cryptographic card includes one or more of the anti-quantum FPGA chip, classical cryptographic chip, random number generator, memory, PCIe interface, network port, USB3.0, serial port and expansion interface. The anti-quantum cryptographic algorithm is deployed in the anti-quantum FPGA, which can expand a variety of anti-quantum algorithms.

5. The quantum resistance enhancement method according to claim 1, characterized in that: The gatekeeper quantum security-enhanced device includes a processor, a memory, and a computing program stored on the memory and capable of running on the processor; Among them, the gatekeeper-type quantum security enhancement devices GA and GB are deployed between the sender A and receiver B of the existing classical cryptographic devices and the public network to provide quantum security protection for key data frames in the key exchange process of the existing classical cryptographic devices. Without changing the original protocol interaction, it ensures the full-cycle application of classical cryptographic devices in the pre-quantum and post-quantum eras. Among them, for the Diffie-Hellman type cryptographic protocol, the session key of the sender A and the receiver B of the existing classic cryptographic device is K = KDF (g xy ,r A ,r B ,aux) where KDF is the key derivation function, g xy =CDH(g x ,g y ), r A is the random nonce of sender A, r B is the random nonce of the receiver B, aux is other public information exchanged between the two parties, g x ,g y It is the temporary public key information publicly transmitted by the original protocol; for a string str∈{0,1} * , [R] represents any non-empty substring of R and its equivalent variant. An equivalent variant of a string means that the original string can be restored in an agreed manner; let [g x ] means g x Any non-empty substring of and its equivalent variants, [g y ] means g y Any non-empty substring of and its equivalent variants, [r A ] indicates r A Any non-empty substring of and its equivalent variants, [r B ] indicates r B Any non-empty substring of aux and its equivalent variants, [aux] represents any non-empty substring of aux and its equivalent variants; the gatekeeper-type quantum security enhancement device GA, GB pairs {[g x ],[g y ],[r A ],[r B ],[aux]}, where GA performs quantum security protection on {[g x ],[g y ],[r A ],[r B ],[aux]} any non-empty subset performs quantum-resistant encryption, and GB performs corresponding quantum-resistant decryption; Among them, for the classic key encapsulation digital envelope protocol, the session key of the sender A and the receiver B of the existing classic cryptographic device is K = KDF (K, c A ,pk B ,auxK), where K is the ciphertext c A The encrypted or wrapped key, c A The sender A uses the receiver B's public key pk B The encrypted ciphertext, auxK is other public information exchanged between the two parties; for this case, the gatekeeper-type quantum security enhancement device GA, GB pairs {[c A ],[auxK]}, where GA performs quantum security protection on {[c A ],[auxK]} performs quantum-resistant encryption, and GB performs corresponding quantum-resistant decryption.

6. The quantum resistance enhancement method according to claim 4, characterized in that: The top-level modules for implementing functions of quantum-resistant FPGA include algorithm module, communication module, and management module; The algorithm module is configured to complete quantum-resistant public key encryption algorithm and digital signature algorithm, and contains six submodules: A key generation module, configured to generate public keys and private keys for public key encryption and digital signature algorithms; An encryption module configured to be used for encryption calculation or key encapsulation calculation; A decryption module, configured to perform decryption calculation or key decapsulation calculation; A signature module, configured to calculate a signature for a message; A signature verification module, configured to perform signature verification calculations; A hash module, configured to be used for hash calculation and random bit stream generation calculation; The communication module is configured to complete the interaction between the quantum-resistant FPGA and external data. The host computer and the Soc classic cryptographic chip send data to the quantum-resistant FPGA as a request data packet, and the quantum-resistant FPGA sends data to the host computer and the Soc classic cryptographic chip as a response data packet. The data packets are arranged according to the communication protocol fields and consist of three parts: the header, the body, and the tail: The packet header is used to indicate the data packet function category, data packet direction, version information, and algorithm parameters. The specific fields include: function number, request / response, sequence number, version number, transaction number, cryptographic identifier, data packet number, whether it is the last packet, public key length, private key length, plaintext length, signature / ciphertext length, encapsulation key length, and other data length; The package body is used to store the data corresponding to each field of the package header, including the public key, private key, plain text, signature, ciphertext, encapsulation key, serial number, and version number; The packet tail is used to verify the correctness of data packet transmission, using CRC checksum; Communication module instructions include business instructions and algorithm instructions, including: Factory configuration instructions are business instructions. The host computer and Soc classic cryptographic chip send request data packets. The header field contains the serial number, version number and function code. The quantum-resistant FPGA returns the execution result response data packet. The power-on self-test instruction is a business instruction. The host computer and the Soc classic cryptographic chip send a request data packet to start the self-test function, and the quantum-resistant FPGA returns a self-test result response data packet; The key generation instruction is an algorithm instruction used to generate public and private keys. The host computer and the Soc classic cryptographic chip send a request data packet and start the corresponding key generation calculation according to the cryptographic identifier. The quantum-resistant FPGA returns a response data packet, and the packet body field includes the public and private key data. The encryption instruction is an algorithm instruction used for encryption calculation and key encapsulation calculation. The host computer and the Soc classic cryptographic chip send a request data packet and start the corresponding calculation according to the cryptographic identifier. The packet body field includes the public key data and the optional data to be encrypted. The quantum-resistant FPGA returns a response data packet, and the packet body field includes the ciphertext and the encapsulation key data. Decryption instructions are algorithm instructions used to perform decryption and decapsulation calculations. The host computer and the Soc classic cryptographic chip send a request data packet and start the corresponding calculation according to the cryptographic identifier. The packet body field includes the private key and ciphertext data. The quantum-resistant FPGA returns a response data packet, and the packet body field includes the plaintext and encapsulation key data. The signature instruction is an algorithm instruction used for signature calculation, in which the host computer and the Soc classic cryptographic chip send a request data packet and start the signature calculation according to the cryptographic identifier. The packet body field includes the private key and message data. The quantum-resistant FPGA returns a response data packet, and the packet body field includes the signature data. The signature verification instruction is an algorithm instruction used to perform signature verification calculations. The host computer and the Soc classic cryptographic chip send a request data packet and start decryption calculations according to the cryptographic identifier. The packet body field includes the public key, message, signature, and string data. The quantum-resistant FPGA sends a response data packet, and the packet body field is the signature verification result data. The management module is configured to complete board timing planning, request scheduling, and key management functions.

7. The quantum resistance enhancement method according to claim 4, characterized in that: The quantum-resistant FPGA combined with the Soc classic cryptographic chip architecture includes three types of cryptographic chips with two working modes; Among them, the Soc classic cryptographic chip is the main chip, which is used to complete the classic cryptographic algorithm, host computer data communication, data forwarding, and key management functions; the anti-quantum FPGA chip is the slave chip 1, which is used to complete the anti-quantum cryptographic algorithm function; the dedicated non-open source cryptographic chip is the slave chip 2, which is used to complete the non-open source field-specific classic cryptographic algorithm function, and the slave chip 2 is an optional configuration; the main chip and the slave chip 1 use one or more of the AXI, AHB, and APB bus protocols to complete the anti-quantum cryptographic data communication; the main chip and the slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete the non-open source field-specific classic cryptographic data communication; Among them, in the first working mode: the anti-quantum cryptography and classical cryptography requests sent by the host computer are both processed by the main chip; in the second working mode: the anti-quantum cryptography requests sent by the host computer are directly processed by slave chip 1, the data packets are arranged according to the communication protocol field, and the classical cryptography requests are processed by the main chip and slave chip 2 respectively according to the cryptography identifier.

8. The quantum resistance enhancement method according to claim 4, characterized in that: The quantum-resistant FPGA is combined with the non-Soc classical cryptographic chip architecture, and includes three types of cryptographic chips, among which the quantum-resistant FPGA chip is the master chip, which is used to complete the quantum-resistant cryptographic algorithm, host computer data communication, data forwarding, and key management functions; the non-Soc classical cryptographic chip is the slave chip 1, which is used to complete the classical cryptographic algorithm function; the dedicated non-open source cryptographic chip is the slave chip 2, which is used to complete the non-open source field-specific classical cryptographic algorithm function, and the slave chip 2 is an optional configuration; the master chip and the slave chip 1 and the slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete the classical cryptographic data communication; Among them, the quantum-resistant cryptographic request sent by the host computer is processed by the main chip, and the data packets are arranged according to the communication protocol field. The classical cryptographic request sent by the host computer is forwarded by the main chip to slave chip 1 and slave chip 2 for processing according to the cryptographic identifier.

9. The quantum resistance enhancement method according to claim 4, characterized in that: The key transmission and storage methods of quantum-resistant cryptographic cards include: For the quantum-resistant FPGA combined with the Soc classic cryptographic chip architecture, the key data is transmitted between the quantum-resistant FPGA and the Soc classic cryptographic chip through one or more of the AXI, AHB, and APB bus protocols; the Soc classic cryptographic chip uses a symmetric encryption algorithm to store the quantum-resistant cryptographic private key in the onboard memory in the form of ciphertext; For the quantum-resistant FPGA combined with the non-Soc classical cryptographic chip architecture, the key data is transmitted between the quantum-resistant FPGA and the classical cryptographic chip through one or more of the SPI, IIC, and UART protocols; the quantum-resistant FPGA chip stores the quantum-resistant cryptographic private key in the on-board memory.

10. The quantum resistance enhancement method according to claim 4, characterized in that: The quantum-resistant cryptographic card uses a cryptographic identifier and a user identifier to support multi-user key storage under multiple cryptographic algorithms. When a cryptographic algorithm request is made, the identifier is used to determine whether the corresponding key data is already on the board. If not, the corresponding information needs to be transmitted. If so, there is no need to send it repeatedly, saving communication bandwidth. Among them, for the anti-quantum FPGA combined with the Soc classic cryptographic chip architecture: when the anti-quantum key data inside the anti-quantum FPGA is lost and an error is reported, it can actively send an error code to the Soc classic cryptographic chip to request the key data under the identifier to be resent; when the anti-quantum key data of the Soc classic cryptographic chip is lost and an error is reported, it can actively send an error code to the anti-quantum FPGA to request the anti-quantum key data under the identifier to be resent; when the anti-quantum key data inside the anti-quantum cryptographic card is lost and an error is reported, it can actively send an error code to the host computer to request to restart the session; when the classic key data inside the anti-quantum cryptographic card is lost and an error is reported, it can actively send an error code to the host computer to request to restart the session; For the architecture of anti-quantum FPGA combined with non-Soc classical cryptographic chip: when the anti-quantum key data inside the quantum-resistant cryptographic card is lost and an error is reported, it can actively send an error code to the host computer and request to restart the session; when the classic key data of the non-Soc classical cryptographic chip is lost and an error is reported, it can actively send an error code to the anti-quantum FPGA and request to resend the key data under the identifier; when the classic key data inside the quantum-resistant cryptographic card is lost and an error is reported, it can actively send an error code to the host computer and request to restart the session.

11. The quantum resistance enhancement method according to claim 4, characterized in that: The random number generator generates random numbers from a physical noise source, which complies with the national commercial encryption certification standards. It uses one or more of the SPI, IIC, and UART protocols to interact with the quantum-resistant FPGA and Soc classical cryptographic chip respectively.

12. The quantum resistance enhancement method according to claim 4, characterized in that: Through the memory, the quantum-resistant FPGA chip and the Soc classical cryptographic chip can access the used programs, key information, and user configuration information respectively.

13. A quantum security enhancement device for existing classical cryptographic equipment systems, comprising a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, and a computing program stored in the memory and running on the quantum-resistant FPGA or classical cryptographic chip, characterized in that: The quantum-resistant FPGA or classical cryptographic chip executes the computer program to implement the quantum-resistant enhancement method described in any one of claims 1-12.

14. An electronic device comprising a memory, a processor and a computing program stored in the memory and capable of running on the processor, characterized in that: The processor executes the computer program to implement the quantum-resistant enhancement method described in any one of claims 1-12.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the anti-quantum enhancement method described in any one of claims 1 to 12 is implemented.

16. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the quantum-resistant enhancement method described in any one of claims 1 to 12 is implemented.