Data security transmission method and system with anti-quantum security
Through the combination of ML-DSA and DKE algorithms combined with SM4 encryption, a data transmission method that is resistant to quantum security is constructed, which solves the security risks in the quantum computing environment, and realizes the full-process quantum security and efficient data transmission, which is suitable for key infrastructure such as electricity, finance, and medical care.
Patent Information
- Application Number
- CN202510633978.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-05-16
AI Technical Summary
The existing encryption algorithms have serious security risks in the quantum computing environment and cannot effectively resist quantum computing attacks, especially in data transmission scenarios of multi-source nodes and multi-target nodes. The existing methods only provide quantum protection for some encryption processes, which fail to comprehensively improve security.
The ML-DSA signature algorithm is used to generate public and private keys, combined with DKE algorithm and SM4 algorithm, and through certificate verification and temporary shared key generation module, data transmission is achieved using quantum cryptographic algorithm, including obtaining identity identifiers, temporary public keys and validity requirements, generating X.509 certificates, encrypting and decrypting data, and extending the key length through key derivation functions to enhance security.
It provides full-process quantum security resistance, reduces system upgrade costs, is suitable for critical infrastructure scenarios, ensures data confidentiality and integrity, has flexible deployment capabilities and high-performance operation, and is suitable for power, finance, medical and other fields.
Smart Images

Figure CN120263410A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and in particular, to a data security transmission method and system with quantum-resistant security. Background Art
[0002] In recent years, the development of quantum computers has advanced by leaps and bounds, gradually shifting from theoretical research to practical applications. Based on the exploration of medium-scale noisy quantum processors and dedicated quantum computers, extensive research has been carried out at home and abroad, covering multiple industries such as chemistry, finance, artificial intelligence, transportation, aviation, and meteorology. Although some application cases have demonstrated the acceleration advantages of quantum computing, there is still a certain gap from achieving the expected exponential computing acceleration and computing power leap in the industry.
[0003] In 2020, in the paper "A Novel Secure Data Transmission Scheme in Industrial Internet of Things", the authors Hongwen Hui et al. proposed a new chaotic secure communication scheme to solve the security problem of data transmission. The authors first proposed using fractional-order chaotic systems with different structures and different orders to enhance the security of data transmission, combined the characteristics of fog computing and used timestamps for encryption, which not only improved the real-time performance of data transmission but also increased security. Although it was aimed at the industrial Internet environment, it mainly focused on the data transmission from a single source node to a single target node, without covering the cases of multiple source nodes and multiple target nodes, and there is a potential threat of quantum computing attacks to this method.
[0004] In 2024, in the paper "QPASE: Quantum-Resistant Password-Authenticated Searchable Encryption for Cloud Storage", the authors Jingwei Jiang et al. proposed a lattice-based quantum-resistant password-authenticated searchable encryption scheme that can resist the security threats brought by quantum computing. In this scheme, users use easy-to-remember passwords to encrypt and search for data stored in the cloud, avoiding complex key management to ensure the secure transmission of data. The authors analyzed the security of QPASE through a formal security model, using the Bellare-Pointcheval-Rogaway model to analyze the authentication security of QPASE, and at the same time using the indistinguishability against chosen-keyword attack model to prove the privacy security of keywords. QPASE has been proven to be robust and secure under both classical and quantum computers. However, its complexity is relatively high, posing a great challenge to resource-limited devices or scenarios.
[0005] In 2022, the patent CN202211114432.6, "A Quantum-Resistant Computing Method and Device Based on National Cryptography Technology", proposed a key protection method applied to the initiating party terminal. By randomly selecting a key and generating a corresponding key ID, performing standard key exchange negotiation, adding a quantum-resistant computing payload PPKi (including the encrypted key ID) to the message, and sending the modified message to the responder. After receiving the message, check whether it contains the quantum-resistant computing payload PPKr. If it exists and its key ID is the same as that in PPKi, generate SKEYID and continue the key exchange negotiation. This method enhances the quantum-resistant computing ability based on national cryptography technology and improves the security of data encryption. However, this method only provides quantum-resistant protection for the key ID, and other parts such as key exchange are not fortified for quantum security.
[0006] In 2023, the patent CN202311832721.4, "An Encryption Method and Decryption Method, Device, and Medium for Resisting Quantum Attacks", proposed to perform multiple XOR operations by combining the national cryptography algorithm with a whitening key to extend the key length and enhance the security during the encryption process. When encrypting, first XOR the information to be encrypted with the whitening key, then perform the national cryptography algorithm encryption, and finally XOR with the whitening key again to obtain the ciphertext. When decrypting, perform the reverse operation. In this way, the complexity of resisting quantum attacks is increased, thereby improving the anti-cracking ability of the national cryptography algorithm. However, this method can only be used to ensure the security of the symmetric encryption stage and cannot ensure the security of the more important asymmetric encryption stage.
[0007] Therefore, a data security transmission method and system with quantum-resistant security are developed to solve the above problems. Summary of the Invention
[0008] The present invention proposes a data security transmission method and system with quantum-resistant security to solve the problem that existing encryption algorithms have serious security risks in a quantum computing environment.
[0009] The present invention achieves the above object through the following technical solutions:
[0010] On the one hand, the present invention provides a data security transmission method with quantum-resistant security, including:
[0011] Obtain information, where the information includes the identity identifier, temporary public key, temporary secret value, and validity period requirement of the user;
[0012] Generate the public key and private key of the user based on the ML-DSA signature algorithm;
[0013] Send an authentication request to the CA certification center according to the information and the public key of the user and receive the certificate authenticated and issued by the CA certification center;
[0014] Exchange and verify each other's certificates with other users. The certificates are X.509 certificates generated by a CA certification center through private key authentication and issued based on the authentication requests, public keys, and certificates of the corresponding users. The authentication requests include the identity identifiers, temporary public keys, and validity period requirements of the corresponding users. The private key for certificate generation is generated by the CA certification center based on the ML-DSA signature algorithm.
[0015] After the certificate verification passes, respond to the data transmission instruction, call and execute the temporary shared key generation module, and output the temporary shared key. Then, based on the temporary shared key, send data to other users or receive data from other users according to the SM4 algorithm and the ML-DSA signature algorithm. The temporary shared key generation module is used to obtain matrix signals and exchange matrix signals with other users, and is also used to calculate and output the temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signals are generated based on shared values, and the shared values are calculated based on the temporary public keys in the exchanged certificates, the temporary secret values of the corresponding users, and a shared value calculation function. The shared value calculation function is selected from the preset formula library of the corresponding user according to the type of the data transmission instruction. The types of the data transmission instruction include data sending and data receiving.
[0016] Furthermore, generating the public key and private key of the local user based on the ML-DSA signature algorithm includes:
[0017] Using the SHAKE-256 algorithm and a seed to generate a kxl-dimensional matrix G, and each element in G is a polynomial over the quotient ring where , n = 256, the integer ring modulo q, X n +1 is a fixed polynomial, is the structure of the polynomial ring;
[0018] Using the SHAKE-256 algorithm and a seed to generate an l-dimensional vector s1 and a k-dimensional vector s2 respectively, where each element in s1 and s2 is to a random number in, to represents the private key coefficient range;
[0019] Calculate the vector ;
[0020] Based on the vector t, calculate and generate the public key and private key of the local user according to the Power2Round algorithm.
[0021] Further, the X.509 certificate includes the version number, serial number, identity information, validity period, object identifier of the ML-DSA signature algorithm public key, and the ephemeral public key of the corresponding user.
[0022] Further, the steps for obtaining the ephemeral public key include:
[0023] Set three public parameters: a prime number, a random matrix, and a noise parameter;
[0024] Calculate an ephemeral secret value based on the three public parameters using the DKE algorithm;
[0025] Calculate the ephemeral public key from the ephemeral secret value, with the calculation formula as follows: ;
[0026] where p i is the ephemeral public key, M is the random matrix, s i is the ephemeral secret value, e i is the noise, q is the prime number, and mod represents the modulo operation.
[0027] Further, select the shared value calculation function from the formula library preset by the corresponding user according to the type of the data transmission instruction: When the type of the data transmission instruction is data sending, the shared value calculation function is:
[0028] ;
[0029] When the type of the data transmission instruction is data receiving, the shared value calculation function is:
[0030] ;
[0031] where K B , K A both represent the shared value, p j , p j T , s i T are, in sequence, the ephemeral public key in the exchanged certificate, the transpose of the ephemeral public key in the exchanged certificate, and the transpose of the ephemeral secret value of this user.
[0032] Further, the calculation formula for the temporary shared key SK is:
[0033] ;
[0034] K represents the shared value, σ represents the matrix signal, and each element in the matrix signal is used to indicate whether the corresponding element in the shared value is in , where K is KB or K A 。
[0035] Further, according to the temporary shared key, sending data to the other user or receiving data from the other user based on the SM4 algorithm and the ML-DSA signature algorithm includes:
[0036] In response to a data sending instruction, encrypt the data to be sent based on the SM4 algorithm according to the temporary shared key to obtain encrypted data, then sign the digest of the encrypted data based on the ML-DSA signature algorithm using the private key of the local user to obtain encrypted signature data, and receive the verification feedback from the other user after sending the encrypted signature data; or:
[0037] In response to a data receiving instruction, decrypt the received data based on the SM4 algorithm according to the temporary shared key to obtain decrypted data, and then verify the decrypted data based on the ML-DSA signature algorithm.
[0038] Further, the SM4 algorithm is a multi-level encryption structure, and its algorithm steps are as follows:
[0039] Input the seed key: Use the 256-bit temporary shared key K as the input key seed;
[0040] Key derivation: Use the key derivation function KDF to expand the key seed into 2 independent 128-bit first sub-keys and second sub-keys, and assign a unique salt to each sub-key;
[0041] Three-layer encryption process: In the first layer of encryption, use the first sub-key to encrypt the information to obtain the first ciphertext. In the second layer of decryption, use the second sub-key to decrypt the first ciphertext obtained in the first layer to obtain the second ciphertext. In the third layer of encryption, use the first sub-key again to encrypt the second ciphertext obtained in the second layer to obtain the final ciphertext;
[0042] Decryption process: The decryption process is the reverse of the encryption process.
[0043] Further, among them:
[0044] After responding to the data sending instruction and receiving the verification feedback from the other user, if the other user's verification is successful, the signature is valid. If the other user's signature verification fails, resend the data to the other user according to the other user's request for resending data. If the signature verification fails, abandon this conversation and then re-establish the connection; or:
[0045] After responding to the data receiving instruction, if the decryption fails, reject the data. If the verification of the decrypted data fails, discard the data and request the sender to resend the data.
[0046] On the other hand, the present invention also provides a data security transmission system with quantum-resistant security, including:
[0047] An acquisition module, which is used to acquire information, and the information includes the identity identifier, temporary public key, temporary secret value and validity period requirement of the user;
[0048] A generation module, which is used to generate the public key and private key of the user based on the ML-DSA signature algorithm;
[0049] A receiving module, which is used to send an authentication request to the CA authentication center according to the information and the public key of the user and receive the certificate authenticated and issued by the CA authentication center;
[0050] An exchange module, which is used to exchange and verify the certificates with other users. The certificate is an X.509 certificate authenticated and issued by the CA authentication center based on the private key generated by the authentication request, public key and certificate of the corresponding user. The authentication request includes the identity identifier, temporary public key and validity period requirement of the corresponding user. The certificate generation private key is generated by the CA authentication center based on the ML-DSA signature algorithm;
[0051] A response module, which is used to respond to the data transmission instruction after the certificate verification is passed, call and execute the temporary shared key generation module, output the temporary shared key, and then send data to other users or receive data from other users based on the SM4 algorithm and the ML-DSA signature algorithm according to the temporary shared key. The temporary shared key generation module is used to acquire the matrix signal and exchange the matrix signals with other users, and is also used to calculate and output the temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signal is generated according to the shared value, and the shared value is calculated according to the temporary public key in the exchanged certificate, the temporary secret value of the corresponding user and the shared value calculation function. The shared value calculation function is selected from the preset formula library of the corresponding user according to the type of the data transmission instruction. The type of the data transmission instruction includes data sending and data receiving.
[0052] The beneficial effects of the present invention are as follows:
[0053] A data security transmission method and system with quantum-resistant security proposed by the present invention use quantum-resistant cryptographic algorithms ML-DSA and DKE algorithms, which can effectively prevent quantum computing attacks during data transmission in the quantum computing era. By using a dual-key encryption method, it not only ensures the efficiency of the transmitted data but also enhances the security of the system. Through a hybrid architecture, the system can support traditional cryptographic systems while gradually upgrading to a post-quantum security solution, reducing the cost and risk during system upgrades. It is particularly suitable for critical infrastructure scenarios such as power, finance, and healthcare. It can ensure data confidentiality, integrity, and non-repudiation while having flexible deployment capabilities and high-performance operating efficiency, meeting the data security requirements in the post-quantum era. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is the original flowchart of a data security transmission method with quantum-resistant security of the present application;
[0055] Figure 2 It is the schematic structural diagram of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and illustrated herein generally can be arranged and designed in a variety of different configurations.
[0057] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of the present invention.
[0058] It should be noted that: like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0059] In addition, the terms "first", "second", etc. are only used to distinguish descriptions and should not be understood as indicating or implying relative importance. The term "unique salt" refers to the different and non-repeating random values used to generate each subkey. This is to ensure that even if the same key seed is used multiple times, different subkeys can be generated by different salt values, thereby enhancing security and preventing attackers from deriving other keys through pre-calculation or association attacks. The two independent 128-bit subkeys are processed with salt values to ensure the independence of the keys. Using the same salt and key derivation function by both parties can ensure that the keys of both parties are the same, and there will be no problems with encryption and decryption. The term ML-DSA stands for "Digital Signature Standard Based on Modular Lattice", and DKE stands for "Ding Key Exchange (DKE), a post-quantum key exchange algorithm based on lattice problems."
[0060] The specific implementation modes of the present invention are described in detail below in conjunction with the accompanying drawings.
[0061] like Figure 1 As shown, the present invention provides, on one hand, a data security transmission method with quantum security, comprising:
[0062] S1: Obtain information, including the user's identity identifier, temporary public key, temporary secret value and validity period requirement;
[0063] Identity: includes user name or device ID identifier, so that the identity information of the subject can be reflected in the certificate, and its authenticity and validity can be verified through the certificate during communication.
[0064] Temporary public key, temporary secret value: When initializing the DKE algorithm, you need to set the prime number q and random matrix And three common parameters of noise parameter α, Indicates that all elements belong to nxn matrix, generating the temporary secret value s used to negotiate the symmetric encryption key i . Pass the temporary secret value s i Calculate the temporary public key , P i is a temporary public key, M is a random matrix, s i is a temporary secret value, e i is noise, q is a prime number, and mod represents modular operation.
[0065] S2: Generate the user's public key and private key based on the ML-DSA signature algorithm;
[0066] There are four main steps:
[0067] (1) Use the SHAKE-256 algorithm and a seed to generate a kxl-dimensional matrix G, where each element in G is a polynomial over the quotient ring and , n = 256, is the ring of integers modulo q, X n + 1 is a fixed polynomial, is the structure of the polynomial ring;
[0068] (2) Use the SHAKE-256 algorithm and a seed to generate an l-dimensional vector s1 and a k-dimensional vector s2 respectively, where each element in s1 and s2 is to a random number in, to represents the range of private key coefficients;
[0069] (3) Calculate the vector .
[0070] (4) Use the Power2Round algorithm to decompose the high and low bits to reduce the key size, pack the key and output, output the public and private keys of this user and .
[0071] The key pair of the ML-DSA signature algorithm and are locally generated and independently stored by each participating party. The temporary secret value of the key exchange DKE algorithm is dynamically generated at each session, encrypted and temporarily stored in the local secure memory, and immediately destroyed after the session ends.
[0072] S3: Send an authentication request to the CA authentication center according to the information and the public key of this user and receive the certificate authenticated and issued by the CA authentication center;
[0073] S4: Exchange and verify the certificates with other users. The certificates are X.509 certificates authenticated and issued by the CA authentication center based on the authentication request, public key and certificate of the corresponding user. The authentication request includes the identity identifier, temporary public key and validity period requirement of the corresponding user. The certificate generation private key is generated by the CA authentication center based on the ML-DSA signature algorithm;
[0074] Exchange and verify the certificates, thereby enabling the authentication of both communication parties, ensuring that both parties of the data transmission are trustworthy, and preventing man-in-the-middle attacks and identity forgery. During authentication, both communication parties exchange certificates and use the ML-DSA algorithm to verify the certificate signature. After verification, both parties are confirmed as trustworthy entities and a secure communication channel is established.
[0075] The certificate generation public and private key pair PK for certificate generation based on the ML-DSA signature algorithm is generated by the certificate authority CA CA and SK CA The CA authentication center reviews and verifies the user's identity, confirms the legitimacy of the user's identity, and uses the private key SK generated by the certificate generation of the ML-DSA signature algorithm CA to sign the main body part of the certificate. The content of the main body part of the certificate includes the user's version number, serial number, identity information, validity period, object identifier of the public key of the ML-DSA signature algorithm, and the user's temporary public key P i etc. Finally, the signature value is encapsulated into the X.509 certificate structure. The user applies to the certificate authority CA to authenticate the temporary public key P i and the public key upk based on the ML-DSA signature algorithm and issue a certificate
[0076] S5: After the certificate verification passes, respond to the data transmission instruction, call and execute the temporary shared key generation module, call and execute the temporary shared key generation module, output the temporary shared key, and then based on the temporary shared key, send data to other users or receive data from other users based on the SM4 algorithm and the ML-DSA signature algorithm, where the temporary shared key generation module is used to obtain matrix signals and exchange matrix signals with other users, and calculate and output the temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signals are generated according to the shared value, and the shared value is calculated according to the temporary public key in the exchanged certificate, the corresponding user's temporary secret value, and the shared value calculation function. The shared value calculation function is selected from the preset formula library of the corresponding user according to the type of the data transmission instruction, and the type of the data transmission instruction includes data sending and data receiving
[0077] The beneficial effects of the present invention are as follows
[0078] 1. The present invention can provide quantum security assurance. Through the "trinity" design of ML-DSA + DKE + enhanced SM4, a quantum-resistant security system covering the entire processes of authentication, negotiation, and transmission is constructed. Among them, the ML-DSA algorithm is based on the Lattice problem, and DKE is based on the Ring-LWE problem, both of which are post-quantum cryptographic algorithms recognized by NIST. The enhanced SM4 can also effectively resist Grover quantum algorithm attacks, achieving the dual goals of "quantum-resistant security" and "domestic compliance".
[0079] 2. The present invention provides flexible certificate management. The strict hierarchical structure model adopted can provide efficient certificate management and good scalability, is suitable for quickly implementing update and revocation operations, reduces potential risks, and meets the requirements of high security, high real-time performance, and long-term stable operation
[0080] 3. The present invention can perform efficient key management. The dynamic temporary key completely eliminates the risk of long-term key residence, ensures the security of the key life cycle, effectively reduces the complexity of key management, and at the same time ensures the security of the system.
[0081] 4. While ensuring security, the present invention can efficiently implement data transmission. During the data transmission process, key encapsulation technology is adopted, which can effectively reduce the security risk during key transmission and ensure the efficiency of the transmission process. The symmetric encryption SM4 algorithm can be accelerated by hardware, ensuring the rapidity of the encryption process, and is particularly suitable for scenarios that need to process a large amount of data.
[0082] 5. The present invention has wide applicability. It is applicable not only to power scenarios but also to critical infrastructure fields such as finance and healthcare. The security requirements of these industries are usually high, and the system design can meet the needs of these industries for data security, reliability, and performance. In addition, its quantum resistance and flexible certificate management ensure that it can still effectively cope with new threats in future technological changes.
[0083] The corresponding user mentioned above refers to the user who sends the authentication request and the user who performs the shared value calculation. For example, if the present user sends the authentication request, the corresponding user is the present user; if other users send the authentication request, the corresponding user is other users. The present invention can be applied to each user who needs data transmission. The present user can act as both the data sender and the data receiver.
[0084] As Figure 2 shown, the following takes the application of the present invention in two data transmission parties as an example to further illustrate the present invention. Hereinafter, A is used to refer to the receiver and B is used to refer to the sender.
[0085] According to the present invention, both the receiver A and the sender B obtain their respective certificates from the CA certification center. After the user successfully applies for a certificate, the CA certification center sends the certificate to the user through the secure channel distribution system. If the user's private key is leaked or the device is lost, it is necessary to immediately notify the CA certification center to revoke the certificate; at the same time, to maintain long-term security, a new certificate can be reapplied before the certificate expires to update the temporary public key P i and the validity period.
[0086] Among them, a strict hierarchical structure model is adopted to build the CA certification center. In this architecture, all CAs are organized in a strict hierarchical structure. The top layer is the root CA, and all other CAs directly or indirectly depend on the root CA. This model has high security, is suitable for medium and large-scale systems and enterprises, and can ensure good management and scalability. This model ensures that the top-level root CA and the issued certificates at the lower layer are mutually verified through a strong authentication mechanism, thereby enhancing the overall security of the system.
[0087] At the beginning of communication, the two parties of data transmission exchange identity information and certificates. The receiving party A verifies the ML-DSA signature certificate of the sending party, and the sending party also verifies the certificate of the receiving party. The two parties use the DKE algorithm to generate a shared 256-bit temporary shared key. The receiving party A uses its own temporary secret value s A and the temporary public key p in the certificate of the sending party B B to calculate the shared value , and the sending party B also uses its own temporary secret value s B and the temporary public key in the certificate of the receiving party A to calculate the shared value . The sending party B first generates a matrix signal σ1 representing the matrix signal according to K through the sign function. Each element in the matrix signal is used to indicate whether the corresponding element in the shared value is in B , and after receiving the matrix signal σ1, the receiving party A calculates the key : . .
[0088] After receiving the matrix signal σ2 in the same way, the sending party B calculates the key : , since the error term satisfies , and , so for all it satisfies , and finally the shared key formed by concatenating SK in order is obtained.
[0089] Data encryption and signature. In the data encryption and signature stage, the main goal is to encrypt the data with the shared key K generated previously and use signature technology to ensure the integrity and authentication of the data. This process ensures that the data is not tampered with during transmission and also ensures the confidentiality of the data. To achieve quantum resistance, the SM4 encryption algorithm and the ML-DSA signature algorithm are used together in this stage to ensure the security of the encryption and signature parts. The SM4 algorithm of the present invention consists of 32 rounds of iteration and 1 reverse transformation.
[0090] (1) 32 rounds of iteration: First, it is necessary to perform 32 rounds of iteration on the 4-word plaintext. Each round of iteration requires a 1-word round key, and a total of 32 round keys are required, denoted (where the round key is used in the th round (counting from 0 here), with a length of 1 word). The process of iteration is to continuously use the round function F to calculate the next word backward. The round function F is , which can receive 4 1-word plaintexts and 1 1-word round key as parameters and finally produce a 1-word result.
[0091] (2) One-time reverse transformation: The second step of the encryption process is a simple reverse transformation. Reverse the four words obtained at the end of the iteration to get the final ciphertext. to obtain the final ciphertext .
[0092] The decryption process of SM4 is exactly the same as the encryption process, also including 32 rounds of iteration and one reverse transformation. The difference is that when performing round iteration in the decryption process, the round keys need to be used in reverse order. For example, for , the first round uses , the second round uses , and so on.
[0093] However, the key length supported by the native SM4 algorithm is 128 bits, which is equivalent to 64-bit security in the future quantum computing environment. Using the native SM4 algorithm may not be sufficient to resist quantum attacks. Therefore, this method uses a key expansion and multi-level encryption structure similar to 3DES, and generates two independent 128-bit keys and through the key derivation function KDF, and adopts the method of "encrypt-decrypt-encrypt" to improve the security of the method. The specific algorithm design is as follows:
[0094] (1) Input the seed key: Use the 256-bit shared key SK as the input key seed.
[0095] (2) Key derivation: Use the key derivation function KDF to expand the seed key into 2 independent 128-bit subkeys and , and at the same time assign a unique salt to each subkey to ensure the independence of the two keys.
[0096] (3) Three-layer encryption process: The first layer of encryption uses the key to encrypt the information M to obtain the ciphertext C1, that is, ; the second layer of decryption uses the key to decrypt the C1 obtained in the first layer to obtain the ciphertext C2, that is, ; the third layer of encryption uses the key again to encrypt the C2 obtained in the second layer to obtain the ciphertext C, that is, .
[0097] (4) Decryption process: The decryption process executes the encryption process in reverse, and obtains M through the key and the ciphertext C, where:
[0098]
[0099] The multi-level encryption structure increases the difficulty of cracking. The attacker needs to crack all the keys at the same time to restore the plaintext. If the keys can be independent of each other, the difficulty of cracking will be greatly increased, which in turn realizes the key length extension of the SM4 algorithm.
[0100] In order to ensure the integrity of the data and prevent the data from being tampered with during transmission, the summary of the encrypted data is used as input and signed using the ML-DSA algorithm to generate a digital signature. The signing process uses the private key usk of the sender B. B Signatures are performed to ensure that data cannot be tampered with or denied. Finally, the signature and encrypted data are transmitted together to ensure that the data recipient can verify the integrity of the data and perform decryption operations at the same time.
[0101] Decryption and verification. The data decryption of the present invention adopts the SM4 algorithm, and the key can be processed by the reverse process. Verification adopts the ML-DSA algorithm, and signature verification is mainly divided into the following steps:
[0102] Generate a polynomial shielding vector y with coefficients less than the security parameter γ1. The parameter γ1 needs to be set within a certain range so that the final signature does not leak the key and the signature is not easily forged.
[0103] calculate and use The high and low bit decomposition algorithm is used to obtain The high bit and the low bit .
[0104] Generate a challenge value for the signature information m , c is The polynomial in has coefficients and 0, H0 represents a hash function.
[0105] Calculate potential signatures , since direct output may lead to the leakage of the key, rejection sampling is used, and the parameter β is the maximum possible coefficient of cs1. , then reject and restart the signing process. Similarly, if Any coefficient of the low-order bit is greater than , you need to restart the signature calculation.
[0106] If the signature verification fails, the receiver needs to discard the data packet and request the sender to resend the data. If multiple signature verification failures are detected, the conversation is abandoned and the connection is reestablished. If the decryption fails due to key mismatch, ciphertext damage, etc., the receiver should reject the data packet, trigger error handling and re-request data. After the verification is passed, both parties are confirmed as trusted entities and a secure communication channel is established.
[0107] The symmetric key of SM4 is dynamically generated during key negotiation, used only in a single session, and immediately destroyed after the session ends, without being stored by default. Each participating party needs to record metadata information such as the purpose, validity period, and owner of the key by itself, and use security means such as encrypted storage and digital signatures to ensure the integrity and authenticity of these metadata. According to the system security level requirements and security policies, the key is updated regularly to avoid the risk of long-term attacks on the key. When the key is destroyed, the key data must be completely deleted to ensure its irrecoverability, and the relevant certificates are updated synchronously, and the destruction log is recorded to meet the security compliance requirements.
[0108] The embodiment of the present invention also provides a data security transmission system with quantum-resistant security, including:
[0109] An acquisition module, which is used to acquire information, and the information includes the identity identifier, temporary public key, temporary secret value, and validity period requirement of the user;
[0110] A generation module, which is used to generate the public key and private key of the user based on the ML-DSA signature algorithm;
[0111] A receiving module, which is used to send an authentication request to the CA authentication center according to the information and the public key of the user and receive the certificate authenticated and issued by the CA authentication center;
[0112] An exchange module, which is used to exchange and verify the certificates with other users. The certificate is an X.509 certificate authenticated and issued by the CA authentication center based on the private key generated from the authentication request, public key, and certificate of the corresponding user. The authentication request includes the identity identifier, temporary public key, and validity period requirement of the corresponding user, and the certificate generation private key is generated by the CA authentication center based on the ML-DSA signature algorithm;
[0113] A response module, which is used to respond to the data transmission instruction after successful certificate verification, call and execute the temporary shared key generation module, output a temporary shared key, and then send data to other users or receive data from other users based on the SM4 algorithm and the ML-DSA signature algorithm using the temporary shared key. The temporary shared key generation module is used to obtain matrix signals and exchange matrix signals with other users, calculate and output a temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signals are generated according to a shared value, and the shared value is calculated based on the temporary public key in the exchanged certificate, the temporary secret value of the corresponding user, and a shared value calculation function. The shared value calculation function is selected from a preset formula library of the corresponding user according to the type of the data transmission instruction, and the types of the data transmission instruction include data sending and data receiving.
[0114] The innovation of the present invention compared with the prior art lies in:
[0115] 1. Innovation in the certificate system based on post-quantum cryptography. The present invention creatively adopts the core scheme of the ML-DSA international standard to construct a digital signature system, and realizes quantum-resistant security through the ring-LWE problem. This algorithm can resist Shor algorithm attacks, ensure that data is protected from quantum computing threats during transmission, and provides a reliable guarantee for the public key cryptography system in the future quantum computing era; adopts the X.509 certificate bridging technology, embeds the ML-DSA public key in the CA hierarchical model at the same time, supports the progressive upgrade of the existing PKI system to a quantum-resistant system, and realizes a smooth transition from the traditional scheme to the quantum-resistant scheme.
[0116] 2. Dynamic management of the entire life cycle of keys. The present invention designs a hierarchical dynamic key management to realize the collaborative control of quantum-resistant keys and traditional keys. The DKE temporary key adopts the "one-time one-key" mechanism, is encrypted and temporarily stored in the secure memory during the session, and is triggered to be destroyed by the trusted execution environment after the session ends, eliminating the risk of key residue; constructs a three-level key derivation tree based on SM4, binds the device fingerprint and environmental noise through the salt value, and ensures key independence.
[0117] 3. Quantum-resistant enhanced SM4 three-layer encryption. Aiming at the defect that the SM4 algorithm has insufficient quantum-resistant strength, the present invention first creates a "encrypt-decrypt-encrypt" composite encryption mode, uses the key derivation function KDF to split the 256-bit DKE shared key into SK1 and SK2 dual factors, and through salt value injection and round key cross confusion, the equivalent key space is increased from to .
[0118] 4. Simultaneously have secure transmission for both sending data and receiving data.
[0119] The data security transmission method and system with anti-quantum security proposed by the present invention solve
[0120] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A data security transmission method with quantum-resistant security, characterized in that, Including: Obtain information, where the information includes the identity identifier, temporary public key, temporary secret value, and validity period requirement of the user; Generate the public key and private key of the user based on the ML-DSA signature algorithm; Send an authentication request to the CA authentication center according to the information and the public key of the user, and receive the certificate authenticated and issued by the CA authentication center; Exchange and verify the certificates with other users. The certificate is an X.509 certificate authenticated and issued by the CA authentication center based on the private key generated according to the authentication request, public key, and certificate of the corresponding user. The authentication request includes the identity identifier, temporary public key, and validity period requirement of the corresponding user. The private key for certificate generation is generated by the CA authentication center based on the ML-DSA signature algorithm; After the certificate verification passes, respond to the data transmission instruction, call and execute the temporary shared key generation module, and output the temporary shared key. Then, based on the temporary shared key, send data to other users or receive data from other users based on the SM4 algorithm and the ML-DSA signature algorithm. The temporary shared key generation module is used to obtain matrix signals and exchange matrix signals with other users, and is also used to calculate and output the temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signal is generated according to the shared value, and the shared value is calculated according to the temporary public key in the exchanged certificate, the temporary secret value of the corresponding user, and the shared value calculation function. The shared value calculation function is selected from the preset formula library of the corresponding user according to the type of the data transmission instruction. The types of the data transmission instruction include data sending and data receiving.
2. A data security transmission method with anti-quantum security according to claim 1, characterized in that, Generating the public key and private key of the user based on the ML-DSA signature algorithm includes: Generate a matrix \(G\) of dimension \(k\times l\) using the SHAKE - 256 algorithm and a seed, where each element in \(G\) is a polynomial over the quotient ring and where , \(n = 256\), the ring of integers modulo \(q\), \(X\) n + 1 is a fixed polynomial, is the structure of the polynomial ring; Generate an l-dimensional vector s1 and a k-dimensional vector s2 using the SHAKE-256 algorithm and a seed respectively, where each element in s1 and s2 is to a random number in, to representing the private key coefficient range; Calculation vector ; Calculate and generate the public key and private key of the user based on the Power2Round algorithm according to the vector t.
3. A data security transmission method with anti-quantum security according to claim 1, characterized in that, The X.509 certificate includes the version number, serial number, identity information, validity period, object identifier of the public key of the ML-DSA signature algorithm, and the temporary public key of the corresponding user.
4. A data security transmission method with quantum resistance security according to claim 1, characterized in that The steps for obtaining the temporary public key include: Set three public parameters: prime number, random matrix, and noise parameter; Calculate the temporary secret value based on the DKE algorithm according to the three public parameters; Calculate the temporary public key according to the temporary secret value. The calculation formula is as follows: ; where p i is a temporary public key, M is a random matrix, s i is a temporary secret value, e i is noise, q is a prime number, and mod represents modular arithmetic.
5. A data security transmission method with quantum-resistant security according to claim 4, characterized in that, Select the shared value calculation function from the preset formula library of the corresponding user according to the type of the data transmission instruction: When the type of the data transmission instruction is data sending, the shared value calculation function is: ; When the type of the data transmission instruction is data receiving, the shared value calculation function is: ; Among them, K B and K A both represent shared values, p j and p j T and s i T are, in sequence, the temporary public key in the exchanged certificate, the transpose of the temporary public key in the exchanged certificate, and the transpose of the temporary secret value of this user.
6. A data security transmission method with quantum-resistant security according to claim 5, characterized in that The calculation formula for the temporary shared key SK is: ; K represents a shared value, and σ represents a matrix signal. Each element in the matrix signal is used to indicate whether the corresponding element in the shared value is in , where K is K B or K A .
7. A data security transmission method with anti-quantum security according to claim 6, characterized in that Sending data to the other user or receiving data from the other user based on the SM4 algorithm and the ML-DSA signature algorithm according to the temporary shared key includes: In response to the data sending instruction, based on the temporary shared key, encrypt the data to be sent using the SM4 algorithm to obtain encrypted data. Then, sign the digest of the encrypted data based on the private key of the user using the ML-DSA signature algorithm to obtain encrypted signature data, and receive the verification feedback from other users after sending the encrypted signature data to other users; or: In response to the data receiving instruction, based on the temporary shared key, decrypt the received data using the SM4 algorithm to obtain decrypted data, and then verify the decrypted data based on the ML-DSA signature algorithm.
8. A data security transmission method with anti-quantum security according to claim 7, characterized in that, The SM4 algorithm is a multi-level encryption structure, and its algorithm steps are as follows: Input the seed key: Use the 256-bit temporary shared key K as the input key seed. Key derivation: Use the key derivation function KDF to expand the key seed into 2 independent 128-bit first sub-keys and second sub-keys, and assign a unique salt to each sub-key. Three-layer encryption process: The first layer encrypts the information using the first sub-key to obtain the first ciphertext, the second layer decrypts the first ciphertext obtained in the first layer using the second sub-key to obtain the second ciphertext, and the third layer encrypts the second ciphertext obtained in the second layer again using the first sub-key to obtain the final ciphertext. Decryption process: The decryption process executes the encryption process in reverse.
9. A data security transmission method with anti-quantum security according to claim 7, characterized in that Where: After responding to the data sending instruction and receiving the verification feedback from other users, if the verification by other users is successful, the signature is valid; if the signature verification by other users fails, resend the data to other users according to the re-sending data request of other users. If the signature verification fails, abandon this conversation and then re-establish the connection; or: After responding to the data receiving instruction, if the decryption fails, reject the data; if the verification of the decrypted data fails, discard the data and request the sender to re-send the data.
10. A data security transmission system with quantum-resistant security, characterized in that, Include: An acquisition module, which is used to acquire information, and the information includes the identity identifier, temporary public key, temporary secret value, and validity period requirement of the user. A generation module, which is used to generate the public key and private key of the user based on the ML-DSA signature algorithm. A receiving module, which is used to send an authentication request to the CA certification center according to the information and the public key of the user and receive the certificate authenticated and issued by the CA certification center. An exchange module, which is used to exchange and verify the certificates of each other with other users. The certificate is an X.509 certificate authenticated and issued by the CA certification center based on the authentication request, public key, and certificate of the corresponding user to generate a private key. The authentication request includes the identity identifier, temporary public key, and validity period requirement of the corresponding user, and the certificate generation private key is generated by the CA certification center based on the ML-DSA signature algorithm. Response module, which is used to respond to the data transmission instruction after successful certificate verification, call and execute the temporary shared key generation module, output the temporary shared key, and then send data to other users or receive data from other users based on the SM4 algorithm and the ML-DSA signature algorithm using the temporary shared key. The temporary shared key generation module is used to obtain matrix signals and exchange matrix signals with other users, and is also used to calculate and output the temporary shared key shared with other users based on the DKE algorithm according to the exchanged matrix signals. The matrix signals are generated based on shared values, and the shared values are calculated according to the temporary public key in the exchanged certificate, the corresponding user's temporary secret value, and a shared value calculation function. The shared value calculation function is selected from a preset formula library of the corresponding user according to the type of the data transmission instruction, and the types of the data transmission instruction include data sending and data receiving.
Citation Information
Patent Citations
Digital certificate authentication method and device based on post-quantum algorithm, equipment and medium
CN119603065A
A post-quantum key negotiation system and method based on IKE protocol
CN119788442A
Key exchange based on DSA type certificates
US20040117626A1
Network authentication process
US20250125970A1
Cited By
Intelligent operation and maintenance method and system based on CMDB
CN120934999A
Anti-quantum computing communication system based on post quantum cryptography
CN121077762A
Identity authentication method fusing anti-quantum signature and X.509 format
CN121356868A
Method of combining anti-quantum signature and x.509 format identity authentication method
CN121356868B