System and method for verifying data transmission integrity based on whole ring
Through the complete loop operation and the random key design of the symmetric key store, the security threat of artificial intelligence and quantum computing to data transmission is solved, and unconditional and secure data integrity verification is achieved.
Patent Information
- Application Number
- CN202510784888.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-12
AI Technical Summary
The existing technology is difficult to withstand the threat of cryptographic analysis brought by artificial intelligence and quantum computing, especially the cracking of classic cryptographic systems, resulting in a decline in data transmission security.
The data transmission integrity verification method based on the whole loop is used to verify data integrity through random keys and whole loop operations in the symmetric key store, and the integrity verification mechanism is designed using mathematical principles to resist attacks from artificial intelligence and quantum computing.
It realizes unconditional and secure data transmission integrity verification, can effectively resist password attacks from artificial intelligence and quantum computing, and improve the security of data transmission.
Smart Images

Figure CN120281480A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data transmission integrity verification system and method based on an integral domain, belonging to the technical field of data security. Background Art
[0002] The waves of artificial intelligence and quantum computing, as the core forces of the new generation of technological revolution, are profoundly changing human society. While promoting social progress, artificial intelligence and quantum computing have also had a profound impact on the field of network security. Artificial intelligence has enhanced the automated defense level of information systems, and quantum computing has promoted the computing revolution and achieved the secure distribution of encryption keys. However, while artificial intelligence and quantum computing facilitate the development of network security, they also pose huge challenges to network security. Especially in the field of cryptography, artificial intelligence and quantum computing will reshape the pattern of cryptanalysis. Artificial intelligence breaks through the limits of cryptanalysis through deep learning, enabling the autonomous identification of encryption mechanisms and the automated discovery of vulnerabilities in cryptographic protocols. Quantum computing has severely reduced the security level of classical cryptographic systems. The quantum Shor algorithm can directly break RSA and Elliptic Curve Cryptography (ECC) through the parallelism and superposition state characteristics of quantum computing. The quantum Grover algorithm can directly halve the security strength of symmetric encryption and hash algorithms. Currently, a global wave of Post-Quantum Cryptography (PQC) has emerged. The United States will fully replace it with PQC by 2035. The Commercial Cryptography Standards Research Institute of China officially launched the solicitation for a new generation of quantum-resistant cryptographic algorithms in February 2025.
[0003] Currently, the country is making all-out efforts to develop a trusted data space. Trusted data transmission is the basis for ensuring data security and constructing a trusted data space. Since data faces many security threats such as impersonation, forgery, and tampering during transmission, it is of great significance to establish a highly trusted integrity verification algorithm for data transmission to verify the trustworthiness of transmitted data in real time.
[0004] In view of the huge threats of artificial intelligence and quantum computing to cryptographic systems, the present invention proposes a data transmission integrity verification method based on an integral domain, which resists cryptanalysis with random distribution. Its security only depends on mathematical principles and has unconditional security. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to propose a data transmission integrity verification system and method based on an integral domain, which is different from the design of conventional cryptography based on mathematical problems. It resists cryptanalysis with random distribution and designs an integrity verification mechanism only relying on mathematical principles to resist various cryptographic attacks based on artificial intelligence and quantum computing, has unconditional security, and improves the security of data integrity verification to resist security threats from artificial intelligence and quantum computing.
[0006] To solve the above technical problems, the technical solution adopted by the present invention is as follows:
[0007] The system of the present invention includes two entities, user A and user B, which have the same composition structure. For the convenience of description, it is assumed that user A is responsible for sending data and user B is responsible for receiving data. The data involved in this technical solution refers to the data stored in the computing device and the network communication data.
[0008] Both user A and user B consist of a symmetric key library, an integrity verification module, and a data transmission module. Among them, the data transmission module is mainly responsible for receiving the transmitted binary stream data, converting it into an element in the integral ring for subsequent verification by the integrity verification module, and also responsible for converting the verified data into a binary stream and sending it; the integrity verification module is responsible for randomly selecting a key in the symmetric key library and performing integrity verification on the data by means of element modulo operation to ensure that the data is not tampered with.
[0009] Let be the integral ring (set of integers), be the set of natural numbers, and mod be the standard modulo (remainder finding) operation on .
[0010] The symmetric key library stores multiple groups of symmetric keys shared by user A and user B. Each key is stored according to an entry, and the specific structure of each entry is as follows:
[0011] .
[0012] is the key tag, is the key, is the base used to calculate the verification value. Among them, and have the same length of , and both are randomly selected from Z. is the number of key library data entries. Note that each key entry in the symmetric key library is used only once and then moves one entry backward in sequence. The key is only used by the integrity verification module and is stored in a confidential manner.
[0013] The function of the integrity verification module is divided into two parts:
[0014] Integrity verification module (as the data sender):
[0015] 1) Convert the input data into an element in the integral ring . Let the input data be , where is the data tag of this data, is the length of the data, and the data content The data encoding module will Convert to Medium Element . At this time, the element group .
[0016] 2) Calculate the checksum. Sequentially retrieve the next key entry from the symmetric key library. , for Calculate the checksum
[0017]
[0018] 3) Convert to bit binary data stream MAC. Sent to the transport module.
[0019] Integrity check module (as data receiver):
[0020] Assume the input data is , take out the label from the symmetric key library Key entry for . Decrypt to get the data content Convert it into a full ring The elements in ; let the converted integer be , If it is 0, then output T=1, indicating that the data has not been tampered with during the transmission process, otherwise output T=0, indicating that the data has been tampered with during the transmission process
[0021] Transport Module:
[0022] 1) As the data sender, send data through the public network Send to the data recipient.
[0023] 2) As a data receiver, receiving data through the public network , and sent to the integrity verification module.
[0024] The method of the present invention comprises the following steps:
[0025] Initialization phase: The symmetric key libraries of user A and user B share N key entries. The initial key label KID=0.
[0026] Step 1: Input data. User A's integrity check module converts the data content of the input data into a complete loop. The elements in and generate element groups;
[0027] Step 2: The integrity verification module of user A selects key entries in the symmetric key library in order;
[0028] Step 3: The integrity verification module of User A uses the element to take the modulus of the base, converts the obtained verification value into a binary stream, encrypts it with the secret key, and then splices it with the original data, and sends it to the transmission module of User A;
[0029] Step 4: The transmission module of User A sends the data to User B through the public network;
[0030] Step 5: The transmission module of User B receives the data and forwards it to the integrity verification module of User B;
[0031] Step 6: The integrity verification module of User B retrieves the key entry from the symmetric key library according to the secret key label and decrypts the integrity verification value;
[0032] Step 7: The integrity verification module of User B converts the decrypted data content into an element in the integral ring ;
[0033] Step 8: User B uses the element to take the modulus of the base. If the result is 0, output T = 1, indicating that the data has not been tampered with during the transmission process; otherwise, output T = 0, indicating that the data has been tampered with during the transmission process.
[0034] The beneficial effects of the present invention are:
[0035] 1. Different from the conventional cipher designed based on mathematical problems and difficult to resist cipher analysis based on artificial intelligence and quantum computing, the present invention only relies on mathematical principles to design the integrity verification mechanism, and conducts data integrity verification based on the random selection of the base of the integral ring to resist various cipher attacks based on artificial intelligence and quantum computing.
[0036] 2. The security of the present invention only depends on mathematical principles and does not rely on any mathematical problems, having the property of unconditional security. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is a schematic diagram of the data transmission integrity verification system based on the integral ring;
[0038] Figure 2 is a flowchart of the operation of the data transmission integrity verification system based on the integral ring. DETAILED DESCRIPTION OF THE INVENTION
[0039] The framework diagram of the system of the present invention is as shown in Figure 1 shown, and the flowchart of the operation of the data transmission integrity verification system based on the integral ring is as shown in Figure 2 shown.
[0040] The technical solution of the present invention will be described in detail below with reference to two specific embodiments.
[0041] Example 1: Integrity Check of Data Transmission in Cloud Storage Scenario
[0042] User A (file uploader) uploads a file to the cloud storage service provider (User B) through a client application. To ensure that the file is not tampered with during the upload process, the cloud storage service uses the integrity check method proposed in the present invention.
[0043] Initialization phase: The client application of User A and the cloud storage server of User B pre-share N key entries through an out-of-band secure channel (for example, during user registration or through a secure key exchange protocol). These key entries are stored in the respective symmetric key libraries of User A and User B. Each key entry contains a key label KID, a key Key, and a base . KID is the label of this key entry, used to identify the key entry used during subsequent data transmission. The initial secret key label KID = 0, and the base space A is the set of all prime numbers in the interval ( ). The base is randomly selected uniformly in the base space A, and the secret key space is the set of 256-bit binary numbers. The secret key Key is randomly selected uniformly in the secret key space (using a random number generator to generate prime numbers). The generated base and the secret key Key form a key entry. This key entry is shared between User A and User B.
[0044] Step 1: The client application of User A splits the file to be uploaded into multiple data blocks. Each data block is processed as a separate input data. The data encoding module converts the data content of each data block into an element in the integral ring . For example, assuming the data content is 300-bit binary data "100...001", the data encoding module converts it into the element , where the data length is required. The data encoding module generates an element group for this data block, representing the ID of the data block, the data length, and the converted element respectively.
[0045] Step 2: The integrity check module of the client application of User A sequentially selects a key entry from its symmetric key library.
[0046] Step 3: The integrity check module of the client application of User A uses the element to perform a modulo operation on the base in the selected key entry to obtain a check value Convert to bit binary data stream MAC. Concatenate the check value MAC with the original data to form a data packet
[0047] Step 4: The transmission module of User A sends the data packet to User B through the public network.
[0048] Step 5: The transmission module of the cloud storage server of User B receives the data packet and forwards it to the integrity verification module of User B.
[0049] Step 6: The integrity verification module of User B sequentially retrieves key entries from the symmetric key library , and parses Convert it to an element in the integral domain in
[0050] Step 7: The integrity verification module of User B will For the basis in the retrieved key entry Judge whether the remainder is 0. If it holds, output T = 1, indicating that the data has not been tampered with during transmission The cloud storage server of User B can continue to process the data block. For example, store it in the storage system. Otherwise, output T = 0, indicating that the data has been tampered with during transmission. The cloud storage server of User B can discard the data block and send an error report to User A, requesting to re-upload the data.
[0051] Embodiment 2: Integrity verification of data transmission in the application update scenario
[0052] The user terminal requests a software package from a trusted software repository. To ensure that the file is not tampered with during the download and transmission process, both the user terminal and the trusted software repository use the integrity verification method proposed by the present invention.
[0053] Initialization phase: The user terminal and the trusted software repository pre-share key entries. These key entries are stored in the symmetric key libraries of the user terminal and the trusted software repository respectively. Each key entry contains a key label , a key and a basis . is the label of this key entry, used to identify the key entry used during subsequent data transmission. The initial secret key label , the basis space is the set composed of all prime numbers in the interval ( ) , the basis is randomly selected uniformly in the basis space . The key space is a set of 256-bit binary numbers. The key is randomly selected uniformly in the key space (using a random number generator to generate elements). The generated basis and the key form a key entry. This key entry is shared between the client and the trusted software repository.
[0054] Step 1: In the stage of generating verification information, the trusted software repository divides the data to be uploaded into multiple data blocks. Each data block is processed as separate input data. The data encoding module converts the data content of each data block into an element in the integral ring . For example, assuming the data content is 300-bit binary data "100...001", the data encoding module converts it into the element , where the data length is required. The data encoding module generates an element group for this data block, which respectively represents the of the data block, the data length, and the converted element.
[0055] Step 2: The integrity verification module of the trusted software repository sequentially selects a key entry from its symmetric key library.
[0056] Step 3: The integrity verification module of the trusted software repository performs a modulo operation on the basis in the selected key entry using the element to obtain the verification value . Convert to a -bit binary data stream MAC. Concatenate the MAC with the original data to form a data packet .
[0057] Step 4: The transmission module of the trusted software repository sends the data packet to the client.
[0058] Step 5: The transmission module of the client receives the data packet and delivers it to the integrity verification module of the client.
[0059] Step 6: The integrity verification module of the client sequentially retrieves the key entry from the symmetric key library and parses out the element group and converts it to an element in the integral ring .
[0060] Step 7: The integrity verification module of User B will perform a modulo operation on the base in the retrieved key entries and determine whether the remainder is 0. If it holds, output T = 1, indicating that the data has not been tampered with during transmission and the data integrity verification passes, and output . The client can continue to process this data block. Otherwise, output T = 0, indicating that the data has been tampered with during transmission. The client can discard this data block and send an error report to a trusted software repository, requesting to resend the data.
[0061] Implement the algorithm of the present invention on Xilinx FPGA 100MHZ and conduct comparative experiments with mainstream algorithms SM3, SHA2-256, and SHA3-256. The results are as follows:
[0062] The present invention SM3 SHA2-256 SHA3-256 Throughput 7Gbps 3.5Gbps 3Gbps 4Gbps Resource occupancy (LUT) 370 600 650 450 Resource occupancy (FF) 260 500 500 380
[0063] It can be seen that the present invention is superior to the existing algorithms in both throughput and resource occupation.
[0064] The data involved in this technical solution refers to any record of information in electronic or other forms, especially the data refers to the data stored in computing devices and network communication data.
Claims
1. A data transmission integrity verification system based on an integral domain, characterized in that It includes two entities, User A and User B. User A is responsible for sending data, and User B is responsible for receiving data. The data involved refers to the data stored in the computing device and the network communication data. Both User A and User B consist of a symmetric key library, an integrity verification module, and a data transmission module. Among them, the data transmission module is responsible for receiving the transmitted binary stream data, converting the binary stream data into elements in the integral ring for subsequent verification by the integrity verification module, and converting the verified binary stream data back into a binary stream and sending it. The binary stream data is information recorded electronically. The integrity verification module is responsible for sequentially selecting keys in the symmetric key library and performing integrity verification on the binary stream data by taking the modulus of integers. The symmetric key library is used to store the symmetric keys shared by User A and User B.
2. The data transmission integrity verification system based on an integral domain according to claim 1, wherein The symmetric keys shared by User A and User B are stored in the symmetric key library according to entries. The specific structure of each entry is as follows: ; is the key label, is the key, is the basis for calculating the check value; where, and are of equal length, both being , and both are randomly selected from Z; is the number of key library data entries; each key entry in the symmetric key library is used only once and then shifted one position backward in sequence; the key is only used by the integrity verification module and is stored in a confidential manner.
3. According to the data transmission integrity verification system based on the integral ring described in claim 1, wherein The working process of the integrity verification module as the data sender is as follows: 1) Convert the input binary stream data into elements in the integral ring ; Let the input binary stream data be , where is the data label of this data, is the data length of this data, is the data content of this data; The data encoding module converts into the element in, and forms an element group ; 2) Calculate the check value; sequentially retrieve the next key entry from the symmetric key repository , For Use To Generate the check value by taking the modulus ; 3) Convert to -bit binary data stream MAC, and send to the transmission module; The working process of the integrity verification module as the data receiver is as follows: Let the input binary stream data be , retrieve the key entry with the label from the symmetric key library , decrypt to obtain the data content of this binary stream data Convert it into an element in the integral domain ; Let the converted integer be , use h to take the modulus of q, determine whether the remainder is 0. If it is 0, output T = 1, indicating that the binary stream data has not been tampered with during transmission. Otherwise, output T = 0, indicating that the binary stream data has been tampered with during transmission.
4. The data transmission integrity verification system based on an integral domain according to claim 1, wherein, The transmission module serves as both the data sender and the data receiver: 1) When the transmission module acts as a data sender, it sends data to the data receiver through a public network ; 2) When the transmission module acts as a data receiver, it receives data through a public network and sends it to the integrity verification module.
5. A data transmission integrity verification method using the system according to any one of claims 1-4, characterized in that It includes the following steps: Initialization stage: The symmetric key libraries of User A and User B share N key entries, and the initial key tag KID = 0. Step 1: Input binary stream data. The integrity verification module of User A converts the data content of the input binary stream data into elements in the integral ring and generates an element group. Step 2: The integrity verification module of User A sequentially selects key entries in the symmetric key library. Step 3: The integrity verification module of User A takes the modulus of the element with respect to the base, converts the obtained verification value into a binary stream, encrypts it with the key, and concatenates it with the binary stream data input in Step 1, and sends it to the transmission module of User A. Step 4: The transmission module of User A sends the concatenated binary stream data to User B through the public network. Step 5: The transmission module of User B receives the concatenated binary data sent by A and forwards this data to the integrity verification module of User B. Step 6: The integrity verification module of User B retrieves the key entry from the symmetric key library according to the key tag and decrypts the integrity verification value. Step 7: The integrity verification module of User B converts the decrypted data content into elements in the ring; Step 8: User B takes the modulus of the element with respect to the base. If the result is 0, then output T = 1, indicating that the binary stream data has not been tampered with during transmission. Otherwise, output T = 0, indicating that the binary stream data has been tampered with during transmission.
Citation Information
Patent Citations
Method for proving integrity of cloud data storage
CN106899406A
Plaintext coding method
CN119094110A
Data integrity verification method and device, electronic equipment and storage medium
CN119129001A
Method and device for auditing data integrity, and storage medium
WO2024088082A1