Adaptive key generation method and system based on prime-order cyclic group
Through the adaptive key generation method based on prime-order loop groups, traditional key generation technology is solved, and the problem that traditional key generation technology is difficult to meet complex application scenarios and faces threats of computing power and attack means is achieved, and the key is highly secure, adaptable and efficient generation is achieved. It is suitable for a variety of application scenarios and operates efficiently under different computing resource conditions.
Patent Information
- Application Number
- CN202510373960.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-01
AI Technical Summary
Traditional key generation technology is difficult to meet the diverse needs of keys in complex and changing application scenarios, and faces the threat of growing computing power and new attack methods. Especially in the era of quantum computing, the security of traditional algorithms is challenged, and the computing complexity in resource-constrained environments is high, affecting system performance.
Adopt key generation method based on prime-order loop groups is adopted, and the appropriate prime-order loop groups are selected, and the hash value is used as an exponent for exponential operation, and targeted adjustments are made in combination with the computing resource status to achieve flexible adaptation of the keys, and the real-time monitoring mechanism ensures that the keys are always adapted to the current environment.
It realizes high security, adaptability and efficient generation of keys, can operate efficiently under different computing resources conditions, adapt to a variety of application scenarios, and significantly improves the security, stability and operation efficiency of the information system.
Smart Images

Figure CN120238300A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key generation, and particularly relates to an adaptive key generation method and system based on a cyclic group of prime order. Background Art
[0002] In the digital age, the importance of information security has become increasingly prominent. With the rapid development of network technology, data faces many security threats during transmission and storage, such as data being stolen, tampered with, or forged. As the core element to ensure information security, the security, adaptability, and performance of key generation technology are directly related to the secure and stable operation of the entire information system.
[0003] Traditional key generation technologies have some limitations. On the one hand, many traditional algorithms are difficult to meet the diverse requirements for keys in complex and changing application scenarios. For example, under different encryption strength requirements, some algorithms cannot flexibly adjust key generation strategies, resulting in poor encryption effects or waste of computing resources. On the other hand, in the face of the increasing computing power and emerging new attack methods, the security of traditional key generation methods faces severe challenges. For example, with the development of quantum computing technology, key generation algorithms based on certain traditional mathematical problems are at risk of being quickly cracked. In addition, in resource-constrained environments, such as mobile devices or Internet of Things terminals, traditional key generation technologies may not be able to operate effectively due to high computational complexity, affecting system performance.
[0004] Therefore, developing a key generation technology that can adapt to various application scenarios, has high security, and can operate efficiently under different computing resource conditions has become an urgent problem to be solved in the current field of cryptography. Summary of the Invention
[0005] In view of the above problems, the object of the present invention is to provide an adaptive key generation method and system based on a cyclic group of prime order. By utilizing the unique mathematical properties of the cyclic group of prime order, key generation is realized, and it can be flexibly adapted according to different encryption requirements, user identities, and computing resource conditions, thereby significantly improving the security, stability, and operating efficiency of the information system.
[0006] To achieve the above object, the present invention adopts the following technical solutions:
[0007] An adaptive key generation method based on a cyclic group of prime order, comprising the following steps:
[0008] Step 101, select a suitable cyclic group of prime order according to the specific application scenario and security requirements, construct an additive group of integers modulo p, such as Z p , determine the large prime number p to initialize the base group, and provide a stable mathematical structure for subsequent key generation;
[0009] Step 102: Collect user identity information, encryption requirement parameters, and computing resource status data. Hash the user identity information and encryption requirement parameters to obtain a hash value. Use this hash value as an exponent to perform an exponentiation operation in a selected cyclic group of prime order, such as calculating g h mod p, where g is a generator of Z p , and obtain an intermediate result.
[0010] Step 103: According to the obtained computing resource status, make targeted adjustments to the above intermediate result, and generate a final key that adapts to the encryption requirements of different scenarios by considering various factors.
[0011] Step 104: Set the threshold of the monitoring parameter, and use the key adaptation mechanism to monitor the changes in the encryption requirements of the application scenario and the dynamics of the computing resources in real time. Once the monitoring parameter exceeds the preset threshold, immediately start the key regeneration process to ensure that the key always adapts to the current environment.
[0012] Furthermore, in Step 101, according to the security level, select a cyclic group of prime order with a larger scale for fields with extremely high security requirements such as military and finance. Select a cyclic group of prime order with a medium scale for general commercial applications. Take the construction of the additive group of integers modulo p, Z p as an example. Through strict screening of appropriate large prime numbers p, complete the initialization work of the basic group, laying a solid mathematical foundation for the subsequent key generation process.
[0013] Furthermore, in Step 102, during the hashing process, use a hashing algorithm such as SHA-256 to process the user identity information and encryption requirement parameters to obtain a hash value of a fixed length. Here, input the user identity information and encryption requirement parameters into a hashing algorithm such as SHA-256 for processing, thereby obtaining a hash value of a fixed length. The hash value integrates the key information of the user and the encryption requirements, and also has characteristics such as uniqueness, irreversibility, and sensitivity, providing a reliable data basis for the subsequent key generation steps.
[0014] Among them, use the obtained hash value as an exponent to perform an exponentiation operation in the selected cyclic group of prime order. For example, if the selected cyclic group of prime order is Z p , the hash value is h, and the generator is g, then calculate g h mod p to obtain an intermediate result. This step makes full use of the mathematical properties of the cyclic group of prime order, making the intermediate result have high security and complexity.
[0015] Further, in step 103, when making targeted adjustments to the intermediate result, if the available memory is small, a simplified transformation method is adopted; if the processor performance is strong, more complex mathematical transformations are performed. Here, based on the obtained computing resource status, targeted adjustments are made to the above intermediate result. If the available memory of the system is small, a simplified transformation method is adopted to reduce the amount of calculation and memory occupation; if the processor performance is strong, more complex mathematical transformations are performed to further improve the security and randomness of the key. By comprehensively considering various factors, a key that finally adapts to the encryption requirements of different scenarios is generated.
[0016] Further, in step 104, the thresholds of the monitoring parameters include the encryption strength change threshold and the computing resource change threshold. For example, the encryption strength change threshold is set such that when the number of encryption bits needs to be increased or decreased by a certain value, the key regeneration is triggered; when the available memory decreases by more than a certain proportion, the key update process is started to trigger the key regeneration. Here, with the help of the key adaptation mechanism, the encryption requirement changes and the computing resource dynamics of the application scenario are monitored in real time. Once the monitoring parameters exceed the preset thresholds, the key regeneration process is immediately started to ensure that the key is always adapted to the current environment and the information security is guaranteed.
[0017] The present invention also provides an adaptation key generation system based on a cyclic group of prime order, including a parameter collection module, a cyclic group of prime order selection module, a key generation module, and a key adaptation monitoring module;
[0018] The parameter collection module is respectively connected to the cyclic group of prime order selection module and the key generation module; the parameter collection module provides user identity information, encryption requirement parameters, and computing resource status data to the cyclic group of prime order selection module to help it select a suitable cyclic group of prime order; the parameter collection module transmits this data to the key generation module for hash processing and adjustment of the intermediate result;
[0019] The cyclic group of prime order selection module is connected to the key generation module. The cyclic group of prime order selection module is used to receive the data from the parameter collection module to select a cyclic group of prime order and transmit the selected information to the key generation module for its exponential operation;
[0020] The key generation module is connected to the key adaptation monitoring module. The key generation module receives the parameters for hash and intermediate result adjustment, and receives the selected cyclic group of prime order information to perform exponential operation to generate a key;
[0021] The key adaptation monitoring module monitors the encryption requirement changes and the computing resource dynamics of the application scenario in real time. When the monitoring parameters exceed the preset thresholds, it triggers the key generation module to regenerate the key.
[0022] By adopting the above technical solutions: This key generation technology breaks through the limitations of traditional key generation technologies by virtue of the special mathematical properties of prime-order cyclic groups, and realizes the deep adaptation of key generation to a variety of complex application scenarios. In the financial transaction scenario, in the face of high-frequency and high-risk fund transfers and sensitive information interactions, this technology can generate high-strength and highly adaptable keys to ensure the confidentiality, integrity, and immutability of transaction data, and build a solid information security defense line for financial institutions and users; in the field of network communication, whether it is daily instant messaging, or enterprise-level remote work and data transmission, this technology can dynamically generate adapted keys according to different communication protocols, bandwidth conditions, and security requirements to ensure that information is not stolen or tampered with during transmission; in terms of data storage, whether it is local hard disk storage or cloud storage services, it can generate matching keys for different data types, storage scales, and access permissions to prevent data leakage and illegal access. In addition, in emerging fields such as Internet of Things device connections, intelligent transportation system data interactions, and medical information security storage, this technology also shows strong application potential, providing solid and reliable technical support for various data encryption scenarios with strict information security requirements.
[0023] Compared with the prior art, the present invention has the following beneficial effects:
[0024] 1. Based on the characteristics of prime-order cyclic groups, the keys generated by the present invention have extremely high security and can effectively resist various traditional cryptographic attack means, such as brute-force cracking, man-in-the-middle attacks, etc. At the same time, the keys generated by combining user identity information and dynamic encryption requirement parameters further increase the complexity and unpredictability of the keys, greatly improving the security of the information system.
[0025] 2. Through a unique key adaptation mechanism, the present invention can flexibly generate adapted keys according to different application scenarios and computing resource conditions. Whether it is on resource-constrained mobile devices, Internet of Things terminals, or in financial transaction systems and military communication fields with extremely high security requirements, the effectiveness and adaptability of the keys can be ensured, greatly expanding the application scope of this technology.
[0026] 3. In the process of key generation, the present invention fully considers the utilization efficiency of computing resources. Through reasonable algorithm design and optimization, unnecessary calculation steps are reduced, significantly improving the speed and efficiency of key generation, reducing the burden on the system, and enabling this technology to operate efficiently under various computing resource conditions. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a flowchart of the method of the present invention;
[0028] Figure 2 is a key generation flowchart based on prime-order cyclic groups in the present invention;
[0029] Figure 3 This is the flowchart of the key adaptation mechanism in the present invention;
[0030] Figure 4 This is the adaptation key generated based on the key technology in the embodiments of the present invention.
[0031] Figure 5 This is the block diagram of the system of the present invention. Detailed implementation manners
[0032] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present invention fall within the scope of protection of the present invention.
[0033] Embodiment
[0034] Refer to Figures 1-5 , an adaptation key generation method based on a cyclic group of prime order, includes the following steps:
[0035] Initialization of the cyclic group of prime order: In practical applications, first, a suitable cyclic group of prime order needs to be selected according to the specific security level and application scenario. For example, for general commercial applications, a medium-sized cyclic group of prime order can be selected; for fields with extremely high security requirements such as military and finance, a larger-sized cyclic group of prime order is required. Taking the additive group Z p of integers modulo p as an example, a large prime number p is selected, and the relevant group operation rules and parameters are initialized. When selecting a large prime number, a deterministic prime number generation method such as the Maurer method can be used to ensure that the generated prime number has high reliability and security.
[0036] Key generation process:
[0037] Obtaining input parameters: Through the system interface or user input, the identity information of the user, such as the user name, user ID, etc., is accurately obtained; at the same time, the encryption requirement parameters are collected, including the encryption strength requirements (such as the encryption bit number, encryption algorithm type, etc.) and the current computing resource status information, such as the available memory size, the operation speed of the processor, etc. These information will be used as the basic data for key generation.
[0038] Hashing Process: Input the user identity information and encryption requirement parameters into the SHA-256 hashing algorithm for processing to obtain a 256-bit hash value. The selection of the hashing algorithm undergoes strict security and performance evaluations to ensure the uniqueness, irreversibility, and sensitivity of the hash value, providing a reliable input for subsequent exponentiation operations.
[0039] Exponentiation Operation: Use the hash value as the exponent and perform exponentiation operations in a cyclic group of a selected prime order. Assume the cyclic group of prime order is Z p , and the hash value is h, then calculate g h mod p, where g is a generator of Z p , to obtain an intermediate result. When performing exponentiation operations, efficient algorithms are used to optimize the calculation process and reduce the calculation time.
[0040] Combined with Computing Resource Adjustment: According to the obtained computing resource status information, further adjust the intermediate result. For example, if the available memory is small, a simplified transformation method is adopted, such as reducing complex mathematical operation steps, to reduce memory occupancy; if the processor performance is strong, more complex mathematical transformations can be performed, such as introducing additional random number operations, to further improve the security and randomness of the key. In this way, the final adapted key is generated.
[0041] Key Adaptation Process:
[0042] Monitoring Parameter Setting: Preset a series of monitoring parameter thresholds, such as encryption strength change threshold, computing resource change threshold, etc. For example, set the encryption strength change threshold to trigger key regeneration when the number of encryption bits needs to be increased or decreased by a certain number of bits; set the key regeneration to be triggered when the available memory decreases by more than a certain percentage. The setting of these thresholds is based on a large number of experiments and practical application experiences to ensure that changes in application scenarios and computing resources can be responded to in a timely and accurate manner.
[0043] Real-time Monitoring: Through the system monitoring module, real-time monitor the changes in encryption requirements of the application scenario and the dynamic situation of computing resources. For example, use system performance monitoring tools to obtain information such as the upgrade requirements of the encryption algorithm and the real-time size of the system available memory in real time. The monitoring module adopts efficient data collection and processing algorithms to ensure the accuracy and timeliness of the monitoring data.
[0044] Key Regeneration: When the monitored parameters exceed or are lower than the preset thresholds, trigger the key regeneration process. Re-obtain the user identity information, encryption requirement parameters, and computing resource status information, and regenerate the adapted key according to the above key generation process. During the key regeneration process, make full use of the previous calculation results and optimization strategies to improve the generation efficiency and reduce the impact on system performance.
[0045] An adaptive key generation system based on a cyclic group of prime order, comprising a parameter collection module, a cyclic group of prime order selection module, a key generation module, and a key adaptation monitoring module;
[0046] The parameter collection module is respectively connected to the cyclic group of prime order selection module and the key generation module; the parameter collection module provides user identity information, encryption requirement parameters, and computing resource status data to the cyclic group of prime order selection module to help it select a suitable cyclic group of prime order; the parameter collection module transmits this data to the key generation module for hash processing and adjustment of intermediate results;
[0047] The cyclic group of prime order selection module is connected to the key generation module. The cyclic group of prime order selection module is used to receive the data from the parameter collection module to select a cyclic group of prime order, and transmit the selected information to the key generation module for its exponential operation;
[0048] The key generation module is connected to the key adaptation monitoring module. The key generation module receives parameters for hash and intermediate result adjustment, and receives the selected cyclic group of prime order information for exponential operation to generate a key;
[0049] The key adaptation monitoring module monitors the changes in encryption requirements of the application scenario and the computing resource dynamics in real time. When the monitored parameters exceed the preset threshold, it triggers the key generation module to regenerate the key.
[0050] In summary, the present invention can effectively achieve the secure, efficient, and adaptive generation of keys in practical applications, meeting the information security requirements in different scenarios.
[0051] The above is the preferred implementation manner of the present invention. Of course, the scope of the rights of the present invention cannot be limited by this. It should be pointed out that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and changes can still be made, and these improvements and changes are also regarded as the protection scope of the present invention.
Claims
1. A method for generating an adaptive key based on a prime-order cyclic group, characterized in that: The steps include: Step 101: According to the specific application scenario and security requirements, select a suitable prime order cyclic group and construct an integer modulo p additive group Z. p , determine a large prime number p to initialize the basic group and provide a stable mathematical structure for subsequent key generation; Step 102: collect user identity information, encryption requirement parameters, and computing resource status data, perform hash processing on the user identity information and encryption requirement parameters, and obtain a hash value; Using the hash value as the exponent, perform exponential operations in the selected prime order cyclic group, such as calculating g h modp, where g is Z p Generators of , and get intermediate results; Step 103: According to the obtained computing resource status, the intermediate results are adjusted in a targeted manner, and various factors are comprehensively considered to generate a key that is ultimately adapted to encryption requirements in different scenarios; Step 104: Set the threshold of the monitoring parameter, and use the key adaptation mechanism to monitor the encryption requirement changes and computing resource dynamics of the application scenario in real time. Once the monitoring parameter exceeds the preset threshold, immediately start the key regeneration process to ensure that the key is always adapted to the current environment.
2. The method for generating an adaptive key based on a prime-order cyclic group according to claim 1, characterized in that: In step 101, based on the security level, a medium-sized prime-order cyclic group is selected for general commercial applications, and a large-scale prime-order cyclic group is selected for military and financial fields with extremely high security requirements.
3. The method for generating an adaptive key based on a prime-order cyclic group according to claim 1, characterized in that: In step 102, during the hash processing, a hash algorithm such as SHA-256 is used to process the user identity information and encryption requirement parameters to obtain a hash value of a fixed length.
4. The method for generating an adaptive key based on a prime-order cyclic group according to claim 1, characterized in that: In step 103, when the intermediate results are adjusted in a targeted manner, if the available memory is small, a simplified transformation method is adopted; if the processor performance is strong, a complex mathematical transformation is performed.
5. The method for generating an adaptive key based on a prime-order cyclic group according to claim 1, characterized in that: In step 104, the thresholds of the monitoring parameters include an encryption strength change threshold and a computing resource change threshold. For example, the encryption strength change threshold is set to trigger key regeneration when the number of encryption bits needs to be increased or decreased to a numerical value; and key regeneration is triggered when the available memory decreases by more than a certain ratio.
6. An adaptive key generation system based on prime order cyclic groups, characterized in that: It includes a parameter collection module, a prime order cyclic group selection module, a key generation module and a key adaptation monitoring module; The parameter collection module is connected to the prime order cyclic group selection module and the key generation module respectively; the parameter collection module provides the prime order cyclic group selection module with user identity information, encryption requirement parameters, and computing resource status data to help it select a suitable prime order cyclic group; the parameter collection module transmits this data to the key generation module for hash processing and adjustment of intermediate results; The prime order cyclic group selection module is connected to the key generation module, and is used to receive data from the parameter collection module to select a prime order cyclic group, and pass the selected information to the key generation module for exponential calculation; The key generation module is connected to the key adaptation monitoring module, the key generation module receives parameters for hashing and intermediate result adjustment, receives selected prime order cyclic group information for exponential operation to generate a key; The key adaptation monitoring module monitors the changes in encryption requirements of application scenarios and computing resource dynamics in real time, and triggers the key generation module to regenerate the key when the monitoring parameters exceed a preset threshold.
Citation Information
Cited By
Method for generating, evaluating and controlling prime number IP address security two-factor dynamic short key
CN121396459A
Prime number IP address security double factor dynamic short key generation and evaluation control method
CN121396459B