Encryption and decryption method and system fusing quantum key and secret sharing, and medium
The integration of QKD and Shamir secret sharing with dynamic storage node migration enhances the security and efficiency of electric power system databases against quantum computer threats by ensuring controlled decryption and robust protection.
Patent Information
- Application Number
- CN202510721039.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-15
AI Technical Summary
In the prior art, the threat of quantum computers to traditional encryption algorithms leads to impairing the data security of power systems, and the existing QKD and Shamir secret sharing methods have efficiency bottlenecks in key recovery and shard management, making it difficult to meet the power system's demand for real-time and high availability.
The QKD device is used to generate the master key and data encryption key, combined with the Shamir secret sharing algorithm and the quantum key hash dynamic method, and the master key is divided into multiple encryption shards and dynamic storage node migration is carried out to form hierarchical protection to ensure data security.
It realizes an efficient data encryption and decryption process, ensures the security and reliability of the power system database, can withstand targeted attacks by quantum computers, and has high decryption efficiency and controllable recovery time.
Smart Images

Figure CN120320945A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to an encryption and decryption method, system and medium that integrate quantum key and secret sharing. Background Art
[0002] With the rapid development of information technology, data security and privacy protection have become the focus of global attention. Especially in critical infrastructure fields such as the power system, data leakage and malicious attacks may trigger serious grid accidents and social impacts. The data security requirements in the power system are special, including real-time performance, high availability, and the ability to defend against quantum computing attacks. The development of quantum computers poses a serious threat to traditional encryption algorithms. A quantum computer can quickly break the security of grid data through the Shor algorithm. Since traditional encryption systems usually rely on a single key or a centralized key management mechanism, once the key is leaked or the system is breached, the data security of the entire power grid will be seriously affected. A common method to resist the intrusion of quantum computers is through quantum key distribution (QKD). Based on the principles of quantum mechanics, it can achieve absolutely secure key distribution, preventing eavesdropping and man-in-the-middle attacks. QKD utilizes the non-clonability of quantum states and the uncertainty principle to ensure the unconditional security of key distribution. At the same time, the Shamir secret sharing algorithm is used for further protection. This algorithm slices the key and stores it distributively, ensuring that only multiple slices can cooperate to recover the key, thereby improving the security and reliability of the system. In the prior art, the simultaneous use of the Shamir secret sharing algorithm and the quantum key distribution method has efficiency bottlenecks in key recovery and slice management, lacks a dynamic update mechanism, is difficult to meet the requirements of the power system for real-time performance and high availability, and cannot fully resist future attacks by quantum computers. Summary of the Invention
[0003] In order to overcome the above technical problems, the present invention provides an encryption and decryption method that integrates quantum key and secret sharing. This encryption and decryption method generates a master key and a data encryption key based on a QKD device, encrypts the data encryption key with the master key, encrypts the database with the data encryption key to form a hierarchical protection, sets a combination of the Shamir secret sharing algorithm and the quantum key hash dynamic method, automatically migrates the storage nodes of the encrypted slices, resists targeted attacks, and ensures the data security of the database.
[0004] To achieve the above object, on the one hand, the present invention provides an encryption and decryption method that integrates quantum key and secret sharing, including:
[0005] Generating a master key and a data encryption key by using the QKD method;
[0006] In the case of encryption operations, the main key is used to encrypt the data encryption key, and the data encryption key is used to encrypt the database;
[0007] Based on a first preset threshold value, the main key is split into multiple encrypted shards through the Shamir secret sharing algorithm;
[0008] The quantum key hashing dynamic method is used to determine the storage nodes of the multiple encrypted shards;
[0009] In the case of decryption operations, a second preset number of encrypted shards are obtained, and the second preset number is greater than or equal to the first preset threshold value;
[0010] The main key is restored based on the obtained second preset number of encrypted shards;
[0011] The restored main key is used to decrypt the data encryption key;
[0012] The data encryption key is used to decrypt the power system database.
[0013] Preferably, the QKD method is used to generate the main key and the data encryption key, including:
[0014] The QKD device is used to generate a quantum key, and the main key is obtained from the quantum key through the key derivation function HKDF according to formula (1),
[0015] MK = HKDF(K QKD , salt, info), (1)
[0016] where, MK is the main key, K QKD is the quantum key, salt is the public salt value, and info is the context identifier;
[0017] The AES-GCM encryption mode is used to generate the data encryption key based on the data table according to formula (2),
[0018] enc DEK = AES-GCM(MK, DEK||table ID ), (2)
[0019] where, dEK is the data encryption key, MK is the main key, table ID is the ID of the data table, and enc DEK is the output of the data encryption key.
[0020] Preferably, in the case of encryption operations, using the main key to encrypt the data encryption key and using the data encryption key to encrypt the database includes:
[0021] The data encryption key, the corresponding data table, and the master key are jointly stored in the hardware security module. The master key encrypts and protects the data encryption key, and the data encryption key encrypts and protects the corresponding data table.
[0022] Preferably, the master key is split into multiple encrypted shards based on a first preset threshold value by using the Shamir secret sharing algorithm, including:
[0023] Use the Shamir secret sharing algorithm to construct a polynomial equation according to formula (3),
[0024]
[0025] where f(x) is the polynomial equation, a i is a randomly generated coefficient, x is the independent variable, t is the threshold value, mod p is the modulo operation, and p is a large prime number;
[0026] Generate multiple encrypted shards using the polynomial according to formula (4),
[0027] S i =(x i ,f(x i )),x i ∈{1,2,…,n}, (4)
[0028] where, S i is the i-th encrypted shard, x i is the identifier of the i-th encrypted shard, f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, and n is the total number of split encrypted shards;
[0029] The split encrypted shards are encrypted and stored using an external public key.
[0030] Preferably, the storage nodes of multiple encrypted shards are determined by using the quantum key hash dynamic method, including:
[0031] Use the quantum key hash dynamic method to determine the storage nodes of the encrypted shards according to formula (5),
[0032] Node ID i =Hash(K QKD ||S i )mod M, (5)
[0033] where, Node ID i is the identifier of the storage node of the i-th encrypted shard, Hash is the function operation of the hash dynamic method, mod M is the modulo operation, and M is a large prime number.
[0034] Preferably, restoring the master key according to the obtained second preset number of encrypted shards includes:
[0035] Verifying the obtained second preset number of encrypted shards;
[0036] Interpolating and processing based on the verified encrypted shards using formula (6) to restore the master key,
[0037]
[0038] where x i is the identifier of the i-th encrypted shard, x j is the identifier of the j-th encrypted shard, f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, t is the threshold value, mod p is the modulo operation, and p is a large prime number.
[0039] Preferably, decrypting the data encryption key using the restored master key includes:
[0040] Obtaining the data encryption key from the encryption table using the restored master key.
[0041] The second aspect of the present invention provides an encryption and decryption system integrating quantum key and secret sharing. The encryption and decryption system includes:
[0042] A user interaction module for receiving or inputting encrypted shards;
[0043] An encryption and decryption module connected to the user interaction module for performing the encryption and decryption method as described in any one of the above claims;
[0044] A database connected to the encryption and decryption module for performing data encryption and decryption operations through the encryption and decryption module.
[0045] The third aspect of the present invention provides a computer-readable storage medium. When the computer program stored on the computer-readable storage medium is executed, the encryption and decryption method as described in any one of the above claims is implemented.
[0046] Through the above technical solutions, the encryption and decryption method generates a master key and a data encryption key based on a QKD device, encrypts the data encryption key using the master key, encrypts the database using the data encryption key to form hierarchical protection, sets the combination of the Shamir secret sharing algorithm and the quantum key hashing dynamic method, automatically migrates the storage nodes of the encrypted shards, resists targeted attacks, ensures the data security of the database, obtains sufficient encrypted shards to decrypt and obtain the master key through the Lagrange interpolation method, has high decryption efficiency, and ensures that the recovery time is controllable. Description of the Drawings
[0047] Figure 1 It is a flowchart of an encryption and decryption method that combines quantum key and secret sharing according to an embodiment of the present invention. Specific Embodiment
[0048] The following will describe in detail the specific embodiments of the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for explaining and illustrating the embodiments of the present invention, and are not used to limit the embodiments of the present invention.
[0049] As Figure 1 It is a flowchart of an encryption and decryption method that combines quantum key and secret sharing according to an embodiment of the present invention. In Figure 1 it, the encryption and decryption method may include:
[0050] In step S10, a master key and a data encryption key are generated by using the QKD method;
[0051] In step S11, in the case of performing an encryption operation, the data encryption key is encrypted by using the master key, and the database is encrypted by using the data encryption key;
[0052] In step S12, the master key is divided into multiple encrypted shards based on a first preset threshold value by using the Shamir secret sharing algorithm;
[0053] In step S13, a quantum key hashing dynamic method is used to determine the storage nodes of the multiple encrypted shards;
[0054] In step S14, in the case of performing a decryption operation, a second preset number of encrypted shards are obtained, and the second preset number is greater than or equal to the first preset threshold value;
[0055] In step S15, the master key is restored according to the obtained second preset number of encrypted shards;
[0056] In step S16, the data encryption key is decrypted by using the restored master key;
[0057] In step S17, the power system database is decrypted by using the data encryption key.
[0058] In the method as Figure 1 shown, step S10 may generate a master key by using a QKD device, and generate a data encryption key based on the master key by using a key derivation function. The key derivation process is completed in a trusted execution environment to ensure the reliability of key generation.
[0059] Step S11 can encrypt the data encryption key using the master key and encrypt the database using the data encryption key under the condition of performing the encryption operation, and perform hierarchical encryption protection to ensure that the master key does not come into contact with the data and guarantee independence.
[0060] Step S12 can split the master key into multiple encrypted shards through the Shamir secret sharing algorithm based on a first preset threshold value, and the generated encrypted shards are greater than the preset threshold value.
[0061] Step S13 uses the quantum key hash dynamic method to determine the storage nodes of multiple encrypted shards, enabling the storage nodes of the encrypted shards to have the ability of autonomous drift. Each time the key of QKD is updated, the encrypted shards automatically migrate to new storage nodes according to the new hash value, and the old storage nodes are securely erased. This mechanism ensures that attackers cannot locate the key shards through long-term observation;
[0062] Step S14, under the condition of performing the decryption operation, obtains a second preset number of encrypted shards, and the second preset number is greater than or equal to the first preset threshold value. Only when at least the threshold number of encrypted shards are obtained can the decryption operation be performed;
[0063] Step S15 can recover the master key based on the obtained second preset number of encrypted shards and perform Lagrange interpolation in the finite field to make the recovery time controllable;
[0064] Step S16 decrypts the data encryption key using the recovered master key and obtains the required data encryption key through the encryption table;
[0065] Step S17 decrypts the power system database using the data encryption key and records the decryption operation while obtaining the data to ensure security and reliability.
[0066] This encryption and decryption method generates the master key and the data encryption key based on the QKD device, encrypts the data encryption key using the master key, and encrypts the database using the data encryption key to form hierarchical protection. It sets the combination of the Shamir secret sharing algorithm and the quantum key hash dynamic method, and the storage nodes of the encrypted shards migrate automatically to resist targeted attacks and ensure the data security of the database.
[0067] Considering the dynamic characteristics of the generation of the master key and the data encryption key and implementing hierarchical encryption, in an embodiment of the present invention, generating the master key and the data encryption key using the QKD method may include:
[0068] Generate a quantum key using the QKD device, and obtain the master key according to the key derivation function HKDF through the formula (1) for the quantum key,
[0069] MK = HKDF(KQKD , salt, info), (1)
[0070] Among them, MK is the master key, K QKD is the quantum key, salt is the public salt value, and info is the context identifier;
[0071] Use the AES - GCM encryption mode to generate a data encryption key based on the data table according to formula (2),
[0072] enc DEK = AES - GCM(MK, DEK||table ID ), (2)
[0073] Among them, DEK is the data encryption key, MK is the master key, and table ID is the ID of the data table, and enc DEK is the output of the data encryption key.
[0074] First, generate a quantum key based on the QKD device, obtain the required master key through the quantum key according to the key derivation function HKDF, which is used to carry the encryption core system, and store the master key in the hardware security module; then, dynamically generate the required data encryption key according to the data table level through the AES - GCM encryption mode, so as to achieve corresponding precise encryption protection according to the data table.
[0075] In order to implement hierarchical encryption and ensure the reliability of data encryption; in an embodiment of the present invention, when performing an encryption operation, the master key is used to encrypt the data encryption key, and the data encryption key is used to encrypt the database, including storing the data encryption key together with the corresponding data table and the master key in the hardware security module, the master key encrypts and protects the data encryption key, and the data encryption key encrypts and protects the corresponding data table. Hierarchical encryption brings double protection, ensuring that the master key does not touch the data and further protecting the data in the database.
[0076] Considering that the master key needs to be split into multiple parts for protection, in an embodiment of the present invention, the master key is split into multiple encrypted shards based on a first preset threshold value through the Shamir secret sharing algorithm, including constructing a polynomial equation according to formula (3) using the Shamir secret sharing algorithm,
[0077]
[0078] Among them, f(x) is the polynomial equation, a i is a randomly generated coefficient, X is the independent variable, t is the threshold value, modp is the modulo operation, and p is a large prime number;
[0079] Generate multiple encrypted shards using a polynomial according to formula (4).
[0080] S i =(x i , f(x i ))), x i ∈{1, 2, …, n}, (4)
[0081] Where S i is the i-th encrypted shard, x i is the identifier of the i-th encrypted shard, f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, and n is the total number of divided encrypted shards;
[0082] Store the divided encrypted shards encrypted with an external public key in the database. Construct the required polynomial according to the Shamir secret sharing algorithm, divide the master key according to the polynomial to generate the encrypted shards we need, and store the encrypted shards encrypted with an external public key, which further protects the encrypted shards and ensures the security of the encryption protection.
[0083] To realize the dynamic migration of the storage nodes of the encrypted shards and protect the security of the storage nodes; in an embodiment of the present invention, the storage nodes of multiple encrypted shards are determined by the quantum key hashing dynamic method, including determining the storage nodes of the encrypted shards by the quantum key hashing dynamic method according to formula (5).
[0084] Node ID i =Hash(K QKD ||S i ) mod M, (5)
[0085] Where Node ID i is the identifier of the storage node of the i-th encrypted shard, Hash is the function operation of the hashing dynamic method, mod M is the modulo operation, and M is a large prime number.
[0086] The quantum key hashing dynamic method enables the storage nodes of the encrypted shards to be automatically migrated according to the new hash value, and at the same time the storage nodes of the old encrypted shards are securely erased, so that external attackers cannot locate the key shards through long-term observation, ensuring the security of the encryption.
[0087] To realize the secure decryption of the encrypted content and improve the decryption efficiency at the same time, in an embodiment of the present invention, the master key is restored based on the obtained second preset number of encrypted shards, including verifying the obtained second preset number of encrypted shards;
[0088] Interpolate the recovered master key using Equation (6) based on the verified encrypted shards.
[0089]
[0090] where x i is the identifier of the i-th encrypted shard, x j is the identifier of the j-th encrypted shard, f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, t is the threshold value, mod p is the modulo operation, and p is a large prime number. Obtain the required number of verified encrypted shards to ensure the reliability of the encrypted shards. Perform Lagrange interpolation on the verified encrypted shards. The entire process is completed in an isolated environment. The interpolation calculation is accelerated using a precompiled finite field arithmetic library to ensure that the recovery time is controllable, thereby ensuring the decryption efficiency.
[0091] To achieve hierarchical decryption, in an embodiment of the present invention, the recovered master key is used to decrypt the data encryption key, including obtaining the data encryption key from the encryption table using the recovered master key. The encryption table is not easily accessible to external attackers. The acquisition of the data encryption key further increases the difficulty of decryption and further protects the data.
[0092] A second aspect of the present invention provides an encryption and decryption system that integrates quantum key and secret sharing. The encryption and decryption system includes a user interaction module, an encryption and decryption module, and a database. The user interaction module is used to receive or input encrypted shards. The encryption and decryption module is connected to the user interaction module and is used to execute the encryption and decryption method described in any one of the above claims. The database is connected to the encryption and decryption module to perform data encryption and decryption operations through the encryption and decryption module.
[0093] A third aspect of the present invention provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program on the computer-readable storage medium is executed, the encryption and decryption method described in any one of the above claims is implemented.
[0094] Through the above technical solutions, the encryption and decryption method generates a master key and a data encryption key based on a QKD device, encrypts the data encryption key using the master key, encrypts the database using the data encryption key to form hierarchical protection, combines the Shamir secret sharing algorithm with the quantum key hashing dynamic method, automatically migrates the storage nodes of the encrypted shards, resists targeted attacks, ensures the data security of the database, obtains sufficient encrypted shards to decrypt and obtain the master key using the Lagrange interpolation method, has high decryption efficiency, and ensures that the recovery time is controllable.
[0095] The preferred embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solutions of the present invention, and these simple modifications all fall within the protection scope of the present invention. In addition, it should be noted that, in the various specific technical features described in the above specific embodiments, without contradiction, they can be combined in any suitable way. To avoid unnecessary repetition, the present invention will not separately describe various possible combination methods.
[0096] In addition, any combination can be made between various different embodiments of the present invention, as long as it does not violate the idea of the present invention, it should also be regarded as the content disclosed by the present invention.
Claims
1. A method for encryption and decryption integrating quantum key and secret sharing, characterized in that, Including: Using the QKD method to generate the master key and the data encryption key; In the case of encryption operation, using the master key to encrypt the data encryption key and using the data encryption key to encrypt the database; Based on a first preset threshold value, splitting the master key into multiple encrypted shards through the Shamir secret sharing algorithm; Using the quantum key hash dynamic method to determine the storage nodes of the multiple encrypted shards; In the case of decryption operation, obtaining a second preset number of encrypted shards, and the second preset number is greater than or equal to the first preset threshold value; Restoring the master key according to the obtained second preset number of encrypted shards; Using the restored master key to decrypt the data encryption key; Using the data encryption key to decrypt the power system database.
2. The encryption and decryption method according to claim 1, characterized in that, Using the QKD method to generate the master key and the data encryption key, including: Using a QKD device to generate a quantum key, and obtaining the master key from the quantum key according to the key derivation function HKDF through formula (1); MK = HKDF(K QKD , salt, info), (1) Among them, MK is the master key, K QKD is the quantum key, salt is the public salt value, and info is the context identifier; Using the AES-GCM encryption mode to generate a data encryption key based on the data table according to formula (2); enc DEK = AES-GCM(MK, DEK || table ID ), (2) Among them, DEK is the data encryption key, MK is the master key, and table ID is the ID of the data table, and enc DEK is the output of the data encryption key.
3. The encryption and decryption method according to claim 2, characterized in that, In the case of encryption operation, using the master key to encrypt the data encryption key and using the data encryption key to encrypt the database, including: Storing the data encryption key together with the corresponding data table and the master key in the hardware security module, using the master key to encrypt and protect the data encryption key, and using the data encryption key to encrypt and protect the corresponding data table.
4. The encryption and decryption method according to claim 1, characterized in that, Based on a first preset threshold value, splitting the master key into multiple encrypted shards through the Shamir secret sharing algorithm, including: Using the Shamir secret sharing algorithm to construct a polynomial equation according to formula (3); where f(x) is a polynomial equation, a i is a randomly generated coefficient, x is the independent variable, t is the threshold value, mod p is the modulo operation, and p is a large prime number; Using the polynomial to generate multiple encrypted shards according to formula (4); S i = (x i , f(x i )),x i ∈ {1, 2, …, n}, (4) Among them, S i is the i-th encrypted shard, x i is the identifier of the i-th encrypted shard, f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, and n is the total number of divided encrypted shards; Encrypting and storing the split encrypted shards using an external public key.
5. The encryption and decryption method according to claim 1, characterized in that, Determining the storage nodes of the multiple encrypted shards using the quantum key hash dynamic method, including: Using the quantum key hash dynamic method to determine the storage nodes of the encrypted shards according to formula (5); Node ID i = Hash(K QKD || S i ) mod M, (5) Among them, Node ID i is the identifier of the storage node of the i-th encrypted shard, Hash is the function operation of the hash dynamic method, mod M is the modulo operation, and M is a large prime number.
6. The encryption and decryption method according to claim 1, wherein Restoring the master key according to the obtained second preset number of encrypted shards, including: Verifying the obtained second preset number of encrypted shards; Performing interpolation processing based on the verified encrypted shards to restore the master key according to formula (6); Among them, x i is the identifier of the i-th encrypted shard, and x j is the identifier of the j-th encrypted shard. f(x i ) is the function value of the identifier of the i-th encrypted shard in the polynomial, t is the threshold value, mod p is the modulo operation, and p is a large prime number.
7. The encryption and decryption method according to claim 1, characterized in that Using the restored master key to decrypt the data encryption key, including: Using the restored master key to obtain the data encryption key from the encrypted table.
8. An encryption and decryption system integrating quantum key and secret sharing, characterized in that, The encryption and decryption system includes: A user interaction module for receiving or inputting encrypted shards; An encryption and decryption module connected to the user interaction module for executing the encryption and decryption method as described in any one of claims 1-7; A database connected to the encryption and decryption module for performing data encryption and decryption operations through the encryption and decryption module.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program on the computer-readable storage medium is executed, the encryption and decryption method as described in any one of claims 1-7 is implemented.
Citation Information
Cited By
Block chain data security storage method based on verifiable secret sharing
CN120785533A
QKD remote key distribution method, system and device based on PQC channel and medium
CN121923817A