Key distribution method and electronic equipment
By using quantum cryptographic algorithm to encrypt the key during the key distribution process, the problem of low security in key distribution in quantum computing scenarios is solved, and high security and flexible key distribution in the quantum computing environment is achieved.
Patent Information
- Application Number
- CN202510639256.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-08-12
AI Technical Summary
The existing key distribution methods are less secure in quantum computing scenarios and are easily cracked by quantum computers. Traditional encryption algorithms are no longer effective.
The key is encrypted by the anti-quantum cryptography algorithm, and the key is encrypted and decrypted through dynamic negotiation between the anti-quantum security platform and the business system to ensure the anti-quantum computing characteristics of the key.
It improves the security of key distribution, can effectively resist attacks from quantum computers, achieve dynamic adaptation and flexible security matching, and ensure the continuous and secure operation of the business system.
Smart Images

Figure CN120474699A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a key distribution method and electronic device. Background Art
[0002] Keys are the key to secure communication in business systems. They are generated by a dedicated trusted organization, such as a key distribution center, and distributed to business systems.
[0003] At present, key distribution is mostly achieved through key encapsulation mechanisms. For example, encryption algorithms such as asymmetric algorithms are used to encrypt and encapsulate keys. However, traditional encryption algorithms are no longer secure in the context of quantum computing. If the key distribution message is intercepted, the key can be easily cracked by a quantum computer, resulting in low security of key distribution. Summary of the Invention
[0004] The embodiments of the present application provide a key distribution method and an electronic device to achieve the effect of improving the security of key distribution.
[0005] In a first aspect, an embodiment of the present application provides a key distribution method, which is applied to a quantum-resistant security platform; comprising:
[0006] In response to an algorithm negotiation request sent by the business system, determining a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement according to the security algorithm requirement carried in the algorithm negotiation request, and sending the target quantum-resistant cryptographic algorithm to the business system;
[0007] In response to a key acquisition request from the business system, determining a target key required for the target business based on key identification information of the target business indicated in the key acquisition request; encrypting the target key according to the target quantum-resistant cryptographic algorithm to obtain a key with quantum-resistant computing characteristics;
[0008] Sending the key with quantum computing resistance characteristics to the business system.
[0009] In a second aspect, an embodiment of the present application provides a key distribution method, which is applied to a business system that is deployed with a quantum-resistant dynamic security component; comprising:
[0010] Based on the quantum-resistant dynamic security component, obtain the security algorithm requirements required by the target business; and generate an algorithm negotiation request based on the security algorithm requirements, and send the algorithm negotiation request to the quantum-resistant security platform;
[0011] Based on the quantum-resistant dynamic security component, receive the target quantum-resistant cryptographic algorithm returned by the quantum-resistant security platform, and obtain key identification information of the target service; generate a key acquisition request based on the target quantum-resistant cryptographic algorithm and the key identification information, and send the key acquisition request to the quantum-resistant security platform;
[0012] Based on the quantum-resistant dynamic security component, the key with quantum-resistant computing characteristics returned by the quantum-resistant security platform is received; and according to the target quantum-resistant cryptographic algorithm, the key with quantum-resistant computing characteristics is decrypted to obtain the key of the target business.
[0013] In a third aspect, an embodiment of the present application provides a key distribution device, which is applied to a quantum-resistant security platform; comprising:
[0014] a determination module, configured to respond to an algorithm negotiation request sent by a business system, determine a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement according to the security algorithm requirement carried in the algorithm negotiation request, and send the target quantum-resistant cryptographic algorithm to the business system;
[0015] an encryption module, configured to respond to a key acquisition request from the business system, determine a target key required for the target business based on key identification information of the target business indicated in the key acquisition request, and encrypt the target key according to the target quantum-resistant cryptographic algorithm to obtain a key with quantum computing resistance;
[0016] A sending module is used to send the key with anti-quantum computing characteristics to the business system.
[0017] In a fourth aspect, an embodiment of the present application provides a key distribution device, which is applied to a business system, wherein the business system is deployed with a quantum-resistant dynamic security component; comprising:
[0018] A first acquisition module is configured to acquire security algorithm requirements required for a target service based on the quantum-resistant dynamic security component; generate an algorithm negotiation request based on the security algorithm requirements, and send the algorithm negotiation request to the quantum-resistant security platform;
[0019] A second acquisition module is configured to receive, based on the quantum-resistant dynamic security component, a target quantum-resistant cryptographic algorithm returned by the quantum-resistant security platform, and obtain key identification information of the target service; generate a key acquisition request based on the target quantum-resistant cryptographic algorithm and the key identification information, and send the key acquisition request to the quantum-resistant security platform;
[0020] A decryption module is configured to receive, based on the quantum-resistant dynamic security component, a key with quantum-resistant computing characteristics returned by the quantum-resistant security platform; and decrypt the key with quantum-resistant computing characteristics according to the target quantum-resistant cryptographic algorithm to obtain a key for the target business.
[0021] In a fifth aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;
[0022] The memory stores computer-executable instructions;
[0023] The processor executes the computer-executable instructions stored in the memory, so that the processor executes various possible implementations of the first aspect or the second aspect as described above.
[0024] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement various possible implementations of the first or second aspect above.
[0025] In a seventh aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements various possible implementation methods of the first or second aspect above.
[0026] An embodiment of the present application provides a key distribution method and electronic device. Before a quantum-resistant security platform distributes keys to a business system, the business system first obtains the security algorithm requirements required by the target business, and generates and sends an algorithm negotiation request based on the security algorithm requirements. The quantum-resistant security platform responds to the algorithm negotiation request, determines a target quantum-resistant cryptographic algorithm that matches the security algorithm requirements of the target business, and returns it to the business system. After receiving the target quantum-resistant cryptographic algorithm, the business system obtains key identification information of the target business based on a quantum-resistant dynamic security component, and uses the target quantum-resistant cryptographic algorithm and the key identification information to generate a key acquisition request, which is sent to the quantum-resistant security platform. The quantum-resistant security platform responds to the key acquisition request, determines a target key of the target business based on the key identification information, and uses the target quantum-resistant cryptographic algorithm to encrypt the target key to obtain a key with quantum-resistant computing characteristics, and distributes it to the business system. After receiving the key with quantum-resistant computing characteristics, the business system uses the target quantum-resistant cryptographic algorithm to decrypt it to obtain the target key of the target business. In this way, in the process of distributing keys from the quantum-resistant security platform to the business system, the keys are encrypted using quantum-resistant cryptographic algorithms, which can effectively resist attacks from quantum computers, prevent traditional encryption algorithms from being cracked, and improve the security of key distribution; moreover, the business system and the quantum-resistant security platform can dynamically negotiate based on the security algorithm requirements required by the business to determine the quantum-resistant cryptographic algorithm that meets the business needs, so that the business system can select the most appropriate quantum-resistant cryptographic algorithm according to different business scenarios and security requirements, thereby improving security and flexibility; at the same time, the target quantum-resistant cryptographic algorithm is dynamically negotiated and matched according to the security algorithm requirements of the business system. When the algorithm security is threatened, dynamic and seamless switching can be achieved to ensure the continuous and safe operation of the business. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0028] Figure 1 A schematic diagram of the application scenario provided for this application;
[0029] Figure 2 A schematic diagram of the structure of a quantum-resistant security platform provided in this application;
[0030] Figure 3 A schematic diagram of the structure of a quantum-resistant dynamic security component provided in this application;
[0031] Figure 4 Schematic diagram of the key distribution method provided in this application Figure 1 ;
[0032] Figure 5Schematic diagram of the key distribution method provided in this application Figure 2 ;
[0033] Figure 6 A schematic diagram of the structure of the key distribution device provided in this application;
[0034] Figure 7 A schematic diagram of the structure of the key distribution device provided in this application;
[0035] Figure 8 This is a schematic diagram of the structure of the electronic device provided in this application.
[0036] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0037] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0038] First, let’s explain the terms involved in this application:
[0039] Quantum computing: refers to a new type of computing technology that follows the laws of quantum mechanics to perform high-speed mathematical and logical operations, store and process quantum information, and solve various problems.
[0040] Quantum-resistant cryptographic algorithm: a new generation of cryptographic algorithm that can resist attacks by quantum computers on existing cryptographic algorithms.
[0041] Key encapsulation: A mechanism that uses asymmetric cryptography to securely exchange symmetric keys, ensuring secure transmission of symmetric keys between communicating parties. This improves the space limitations associated with using public keys to encrypt plaintext and is an effective solution to key distribution and management issues in large-scale networks.
[0042] Key distribution is mostly achieved through a key encapsulation mechanism, such as using an asymmetric algorithm or other encryption algorithm to encrypt and encapsulate the key. However, traditional encryption algorithms are no longer secure in the context of quantum computing. For example, if the key distribution message is intercepted, the encryption algorithm can be easily cracked by a quantum computer, resulting in low security of key distribution. Therefore, the present application provides a key distribution method. Before key distribution, a quantum-resistant cryptographic algorithm that matches the current business scenario is determined, and the quantum-resistant cryptographic algorithm is used to achieve secure distribution of keys to the business system. In this way, dynamic matching of quantum-resistant cryptographic algorithms can be achieved based on business needs. Not only can the quantum-resistant cryptographic algorithm be used to prevent the encryption algorithm from being cracked by a quantum computer, but it can also be based on dynamic matching of quantum-resistant cryptographic algorithms to achieve dynamic adaptation to business needs, thereby improving system security and flexibility.
[0043] Figure 1 A schematic diagram of the application scenario provided for this application, such as Figure 1 As shown, the specific application scenario of this application is that the quantum-resistant security platform can distribute keys for multiple business systems. Figure 1 The following is an example of three business systems.
[0044] The quantum-resistant security platform is used to provide security services such as quantum-resistant encryption and decryption, as well as key management, for multiple business systems. This quantum-resistant security platform can be in the form of a server or server cluster. It should be noted that the embodiments of this application do not limit the deployment method of the quantum-resistant security platform; it can be deployed entirely in the cloud or in a distributed manner.
[0045] In some embodiments, Figure 2 A schematic diagram of the structure of a quantum-resistant security platform provided in this application is shown as follows: Figure 2 As shown, the quantum-resistant security platform includes: a key storage unit, a key distribution unit, a quantum-resistant encryption and decryption operation unit, a transaction receiving unit, a transaction response unit, a security algorithm negotiation unit, and an algorithm management unit.
[0046] Key storage unit: used to provide key storage and query functions.
[0047] Key distribution unit: used to receive key acquisition requests from quantum-resistant dynamic security components, query the key from the key storage unit, and send it to the quantum-resistant dynamic security components in a secure manner.
[0048] Quantum-resistant encryption and decryption operation unit: responsible for quantum-resistant encryption and decryption operations.
[0049] Transaction receiving unit: responsible for receiving and parsing transaction messages.
[0050] Transaction response unit: responsible for assembling and returning transaction messages.
[0051] Security algorithm negotiation unit: responsible for negotiating the communication security algorithm.
[0052] Algorithm management unit: responsible for classifying and managing algorithms of different security levels and performance.
[0053] A business system, deployed with quantum-resistant dynamic security components, is used to provide quantum-resistant security services. This business system refers to an application system that requires the use of security algorithms and keys for data protection, communication encryption, and other security operations, such as a banking transaction system. This business system can be deployed as a server or server cluster. It should be noted that the embodiments of this application do not limit the deployment method of the business system; it can be deployed entirely in the cloud or in a distributed manner.
[0054] In some embodiments, Figure 3 A schematic diagram of the structure of a quantum-resistant dynamic security component provided in this application is shown as follows: Figure 3 As shown, the quantum-resistant dynamic security component includes: a security control unit, a quantum-resistant encryption and decryption unit, and a transaction processing unit.
[0055] Security Control Unit: This includes the Security Algorithm Negotiator and the Algorithm Requirements Manager. The Security Algorithm Negotiator is responsible for initiating communication algorithm negotiation requests; the Algorithm Requirements Manager manages the security level and service performance requirements of the algorithms required for different services.
[0056] Transaction processing unit: includes transaction sender, transaction receiver and transaction responder, which are responsible for sending transactions, receiving call parameters and returning call results respectively.
[0057] Quantum-resistant encryption and decryption unit: This unit includes a key acquirer, a key storage, and a quantum-resistant operator. The key acquirer is responsible for assembling key acquisition requests, sending them to the quantum-resistant security platform, parsing the key information returned by the quantum-resistant security platform, assigning a key index to it, and storing it in the key storage. The quantum-resistant operator is responsible for encryption and decryption operations, generating quantum-resistant public and private keys, and retrieving key information from the key storage based on the key index, using the public and private keys to complete the corresponding encryption and decryption operations.
[0058] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0059] Figure 4 Schematic diagram of the key distribution method provided in this application Figure 1 ,like Figure 4As shown, the method includes:
[0060] S101. The business system obtains the security algorithm requirements required for the target business based on quantum-resistant dynamic security components.
[0061] For example, the target service refers to the service that the service system needs to process, and the embodiments of this application are not limited thereto. The security algorithm requirement represents the specific requirements that the service system puts forward for the communication security algorithm in terms of security and performance to ensure the safe operation of the target service. For example, these requirements may include the level of resistance to quantum attacks, key distribution efficiency, key size, resource usage restrictions, etc.
[0062] In one example, the correspondence between the business and the security algorithm requirements can be preset in the quantum-resistant dynamic security component of the business system. Therefore, based on this correspondence, the security algorithm requirements corresponding to the target business can be determined.
[0063] S102. The business system generates an algorithm negotiation request based on the quantum-resistant dynamic security component and security algorithm requirements.
[0064] Exemplarily, the algorithm negotiation request represents network transmission data generated by the business system after encapsulating the security algorithm requirements in order to obtain a suitable quantum-resistant cryptographic algorithm. The algorithm negotiation request may include information such as the business system identifier and the security algorithm requirements.
[0065] In one example, a business system based on a quantum-resistant dynamic security component can structure security algorithm requirements, add information such as the business system's unique identifier and request timestamp, and use a preset encoding method to encode and generate algorithm negotiation requests.
[0066] S103. The business system sends an algorithm negotiation request to the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0067] Exemplarily, the business system may send an algorithm negotiation request to a designated port of the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0068] Accordingly, the quantum-resistant security platform receives the algorithm negotiation request.
[0069] S104. The quantum-resistant security platform responds to the algorithm negotiation request sent by the business system and determines, based on the security algorithm requirements carried in the algorithm negotiation request, a target quantum-resistant cryptographic algorithm that matches the security algorithm requirements.
[0070] Exemplarily, the target quantum-resistant cryptographic algorithm represents a quantum-resistant cryptographic algorithm used to perform quantum-resistant encryption processing on a key corresponding to a target service.
[0071] In one example, after receiving a request message, the quantum security platform can extract the security algorithm requirements from the message and select a quantum-resistant cryptographic algorithm that meets the security algorithm requirements from a preset algorithm library as the target quantum-resistant cryptographic algorithm. For example, the preset algorithm library includes multiple quantum-resistant cryptographic algorithms and their corresponding security algorithm requirements. The platform then calculates the similarity between the security algorithm requirements carried in the message and the security algorithm requirements corresponding to each quantum-resistant cryptographic algorithm in the library, and selects the quantum-resistant cryptographic algorithm with the highest similarity as the target quantum-resistant cryptographic algorithm.
[0072] S105. The anti-quantum security platform sends the target anti-quantum cryptographic algorithm to the business system.
[0073] For example, the quantum security platform can encapsulate the identifier of the target quantum cryptographic algorithm into a response message and send it to the business system. The identifier of the target quantum cryptographic algorithm is used to uniquely characterize the target quantum cryptographic algorithm and can be the ID of the target quantum cryptographic algorithm or the algorithm name, etc., which is not limited in this embodiment of the present application.
[0074] Optionally, if the anti-quantum security platform updates a new anti-quantum cryptographic algorithm and the business system has not been deployed, the anti-quantum security platform can also compress the code corresponding to the target anti-quantum cryptographic algorithm and send the compressed code to the business system.
[0075] Accordingly, the business system receives the target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component.
[0076] S106. The business system obtains the key identification information of the target business based on the quantum-resistant dynamic security component.
[0077] Exemplarily, the key identification information is used to uniquely identify the key required for the target business. The key identification information may include business ID, key usage, or key ID, etc., which is used to accurately query the corresponding key in the quantum-resistant security platform.
[0078] In one example, a business system's quantum-resistant dynamic security component can preset a correspondence between services and key identification information. Furthermore, upon receiving a target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component, the business system can determine the key identification information for the target service based on this correspondence.
[0079] S107. The business system generates a key acquisition request based on the quantum-resistant dynamic security component and the target quantum-resistant cryptographic algorithm and key identification information.
[0080] Exemplarily, a key acquisition request represents a data packet in a specific format used to obtain a target service key. It may include key identification information for the target service, enabling the quantum-resistant security platform to determine and return the corresponding key based on this key identification information. The service system may generate a key acquisition request in a predefined message format based on the acquired target quantum-resistant cryptographic algorithm and key identification information, based on the quantum-resistant dynamic security component. For example, the service system may invoke the target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component to generate a quantum-resistant public key and private key, and then generate a key acquisition request using the quantum-resistant public key and key identification information in a predefined message format.
[0081] S108. The business system sends a key acquisition request to the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0082] Exemplarily, the business system may send a key acquisition request to a designated port of the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0083] Accordingly, the quantum-resistant security platform receives the key acquisition request.
[0084] S109. The quantum-resistant security platform responds to the key acquisition request of the business system and determines the target key required for the target business according to the key identification information of the target business indicated in the key acquisition request.
[0085] For example, the target key represents the raw key data required by the business system to implement secure operations for the target business. The quantum-resistant security platform may pre-store a correspondence between key identification information and raw key data. In response to a key acquisition request from the business system, the platform can determine the target key required for the target business based on the key identification information of the target business indicated in the key acquisition request and the correspondence.
[0086] S110. The anti-quantum security platform encrypts the target key according to the target anti-quantum cryptographic algorithm to obtain a key with anti-quantum computing characteristics.
[0087] For example, a key with quantum-resistant properties represents encrypted key data that, after encryption using a target quantum-resistant cryptographic algorithm, is capable of resisting quantum computing attacks. The quantum-resistant security platform can invoke the target quantum-resistant cryptographic algorithm to directly encrypt the target key, resulting in a quantum-resistant key. Alternatively, the quantum-resistant security platform can first generate a session key using a random number, invoke the target quantum-resistant cryptographic algorithm to encrypt the session key, and then encrypt the target key using the encrypted session key to obtain a quantum-resistant key. This multi-layered encryption process enhances key security.
[0088] S111. The quantum-resistant security platform sends a key with quantum-resistant computing properties to the business system.
[0089] Exemplarily, the quantum-resistant security platform assembles keys with quantum computing-resistant properties into messages in a preset format and sends them to a designated port of the business system.
[0090] Correspondingly, the business system receives the key with anti-quantum computing characteristics returned by the anti-quantum security platform based on the anti-quantum dynamic security component.
[0091] S112. The business system decrypts the key with anti-quantum computing characteristics based on the quantum-resistant dynamic security component and the target quantum-resistant cryptographic algorithm to obtain the target key of the target business.
[0092] For example, the service system can invoke a target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component to directly decrypt the quantum-resistant key to obtain the key for the target service. For example, the service system can directly use the aforementioned quantum-resistant private key to decrypt the quantum-resistant key to obtain the target key for the target service. Alternatively, the service system can invoke a target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component to first decrypt the encrypted session key to obtain the plaintext session key, and then use the plaintext session key to decrypt the remaining quantum-resistant key to obtain the target key for the target service.
[0093] The key distribution method provided by the embodiment of the present application is as follows: before the quantum-resistant security platform distributes keys to the business system, the business system first obtains the security algorithm requirements required by the target business, and generates and sends an algorithm negotiation request based on the security algorithm requirements. The quantum-resistant security platform responds to the algorithm negotiation request, determines the target quantum-resistant cryptographic algorithm that matches the security algorithm requirements of the target business, and returns it to the business system; after receiving the target quantum-resistant cryptographic algorithm, the business system obtains the key identification information of the target business based on the quantum-resistant dynamic security component, and uses the target quantum-resistant cryptographic algorithm and the key identification information to generate a key acquisition request, and sends it to the quantum-resistant security platform; the quantum-resistant security platform responds to the key acquisition request, determines the target key of the target business based on the key identification information, and uses the target quantum-resistant cryptographic algorithm to encrypt the target key to obtain a key with quantum computing characteristics, and distributes it to the business system; after receiving the key with quantum computing characteristics, the business system uses the target quantum-resistant cryptographic algorithm to decrypt it to obtain the target key of the target business.
[0094] In this way, in the process of distributing keys from the quantum-resistant security platform to the business system, the keys are encrypted using quantum-resistant cryptographic algorithms, which can effectively resist attacks from quantum computers, prevent traditional encryption algorithms from being cracked, and improve the security of key distribution; moreover, the business system and the quantum-resistant security platform can dynamically negotiate based on the security algorithm requirements required by the business to determine the quantum-resistant cryptographic algorithm that meets the business needs, so that the business system can select the most appropriate quantum-resistant cryptographic algorithm according to different business scenarios and security requirements, thereby improving security and flexibility; at the same time, the target quantum-resistant cryptographic algorithm is dynamically negotiated and matched according to the security algorithm requirements of the business system. When the algorithm security is threatened, dynamic and seamless switching can be achieved to ensure the continuous and safe operation of the business.
[0095] Figure 5 Schematic diagram of the key distribution method provided in this application Figure 2 ,refer to Figure 2 、 Figure 3 and Figure 5 As shown, this embodiment Figure 4 Based on the embodiment, the key distribution method is described in detail, and the method includes:
[0096] S201. The business system obtains the security requirements and business performance requirements required by the target business based on quantum-resistant dynamic security components.
[0097] For example, security requirements refer to security-related requirements for ensuring data security and system security. These requirements may include, for example, data confidentiality levels, identity authentication methods, and access control policies to ensure that data is not stolen or tampered with during transmission. Service performance requirements refer to requirements for system performance. These requirements may include, for example, key distribution response time, system throughput, and resource usage limits.
[0098] In one example, the security control unit in a quantum-resistant dynamic security component deployed in a business system can establish a data interface with the business system's security policy module and performance monitoring module. Based on the algorithm requirements manager within the security control unit in the quantum-resistant dynamic security component, the business system can read security requirements such as data confidentiality level and access control policy from the security policy module, and obtain performance requirements such as system response time and throughput from the performance monitoring module.
[0099] S202. The business system determines the security algorithm requirements of the target business based on the quantum-resistant dynamic security component and according to the security requirements and business performance requirements.
[0100] For example, the correspondence between security requirements, business performance requirements and security algorithm requirements can be preset in the algorithm requirement manager within the security control unit. Then, the business system can determine the security algorithm requirements of the target business based on the correspondence, security requirements and business performance requirements based on the algorithm requirement manager within the security control unit in the quantum-resistant dynamic security component.
[0101] S203. The business system generates an algorithm negotiation request based on the quantum-resistant dynamic security component and security algorithm requirements.
[0102] Exemplarily, the business system configures the security algorithm requirements into the security algorithm negotiator based on the security control unit in the quantum-resistant dynamic security component, and the security algorithm negotiator generates an algorithm negotiation request according to the security algorithm requirements.
[0103] S204. The business system sends an algorithm negotiation request to the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0104] The business system initiates an algorithm negotiation request to the quantum-resistant security platform based on the security algorithm negotiator of the security control unit in the quantum-resistant dynamic security component.
[0105] Accordingly, the quantum-resistant security platform receives the algorithm negotiation request.
[0106] S205. The quantum-resistant security platform responds to the algorithm negotiation request sent by the business system and determines a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement based on the security algorithm requirement and a preset algorithm library.
[0107] For example, the algorithm library includes multiple quantum-resistant cryptographic algorithms. The quantum-resistant security platform can use the algorithm management unit to match the security algorithm requirements in the preset algorithm library, determine the target quantum-resistant cryptographic algorithm that matches the security algorithm requirements, and configure the target quantum-resistant cryptographic algorithm to the security algorithm negotiation unit.
[0108] In some embodiments, the algorithm management unit of the quantum-resistant security platform may obtain the operating data of each quantum-resistant cryptographic algorithm in the algorithm library; determine the unsafe algorithms in the algorithm library based on the operating data of the quantum-resistant cryptographic algorithm; and remove the unsafe algorithms from the algorithm library.
[0109] For example, operational data represents data generated during the actual operation of a quantum-resistant cryptographic algorithm, and may include computing resource utilization, runtime, encryption and decryption success rates, exception error records, attack logs, and security vulnerability reports. Unsafe algorithms represent quantum-resistant cryptographic algorithms that have security vulnerabilities, unstable performance, or are unable to withstand current quantum attack threats. The algorithm management unit of the quantum-resistant security platform can use machine learning algorithms to analyze operational data and extract abnormal features. If the algorithm's abnormal features meet pre-set abnormality determination rules, it is identified as an unsafe algorithm and removed from the algorithm library. Abnormal features are characteristic data indicating abnormal algorithm operation, and may include, for example, abnormal resource utilization peaks, frequent error return codes, and so on.
[0110] Specifically, for each quantum-resistant cryptographic algorithm in the algorithm library, the algorithm management unit of the quantum security platform may analyze the operational data of the quantum-resistant cryptographic algorithm using a machine learning algorithm to extract the abnormal characteristics of the quantum-resistant cryptographic algorithm. Based on the operational data of the quantum-resistant cryptographic algorithm, the algorithm management unit may extract the abnormal characteristics of the quantum-resistant cryptographic algorithm. The algorithm management unit may then determine whether the quantum-resistant cryptographic algorithm has an abnormality based on the machine learning algorithm and the abnormal characteristics. If the abnormality is present, the algorithm is determined to be an unsafe algorithm. If not, the algorithm is determined to be a safe algorithm.
[0111] In this way, before the next business system requests a key, a secure quantum-resistant cryptographic algorithm can be matched during the negotiation of the quantum-resistant cryptographic algorithm, realizing dynamic and seamless algorithm switching for the business system.
[0112] S206. The anti-quantum security platform sends the target anti-quantum cryptographic algorithm to the business system.
[0113] Exemplarily, the quantum-resistant security platform may return the identifier of the target quantum-resistant cryptographic algorithm to the business system through the security algorithm negotiation unit to complete the negotiation process of the quantum-resistant cryptographic algorithm.
[0114] Accordingly, the business system receives the target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component.
[0115] S207. The business system obtains the key identification information of the target business based on the quantum-resistant dynamic security component.
[0116] Exemplarily, the business system obtains the key identification information of the target business based on the key acquirer in the quantum-resistant encryption and decryption unit of the quantum-resistant dynamic security component.
[0117] S208. The business system calls the target quantum-resistant cryptographic algorithm based on the quantum-resistant dynamic security component to generate a pair of public and private keys for quantum-resistant cryptography.
[0118] For example, the business system can call the target quantum-resistant cryptographic algorithm corresponding to the identifier of the target quantum-resistant cryptographic algorithm based on the quantum-resistant operator in the quantum-resistant encryption and decryption unit of the quantum-resistant dynamic security component to generate a pair of quantum-resistant cryptographic public and private keys.
[0119] S209. The business system generates a key acquisition request based on the quantum-resistant dynamic security component and the key identification information and the public key of the quantum-resistant cryptography.
[0120] Exemplarily, the business system generates a key acquisition request based on the key identification information of the target business and the public key of the quantum-resistant cryptography in a preset format using a key acquirer in the quantum-resistant encryption and decryption unit of the quantum-resistant dynamic security component.
[0121] S210. The business system sends a key acquisition request to the quantum-resistant security platform based on the quantum-resistant dynamic security component.
[0122] Exemplarily, the business system sends a key acquisition request to the quantum-resistant security platform based on the key acquirer in the quantum-resistant encryption and decryption unit of the quantum-resistant dynamic security component.
[0123] In response, the quantum-resistant security platform receives the key acquisition request. For example, the quantum-resistant security platform may receive the key acquisition request based on the transaction receiving unit. Optionally, the quantum-resistant security platform may verify the identity of the business system based on the transaction receiving unit to ensure the reliability of the key acquisition request.
[0124] S211. The quantum-resistant security platform responds to the key acquisition request of the business system and determines the target key required for the target business according to the key identification information of the target business indicated in the key acquisition request.
[0125] Exemplarily, the key storage unit of the quantum-resistant security platform stores a correspondence between key identification information and the original key. Therefore, based on the key storage unit, in response to a key acquisition request from a business system, the target key required for the target business can be determined based on the key identification information of the target business indicated in the key acquisition request and the corresponding relationship.
[0126] S212. The quantum-resistant security platform determines the session key.
[0127] For example, a session key is a temporarily generated key used to encrypt a target key and is used within a key distribution session to enhance the security of key transmission. The quantum-resistant security platform can generate a temporary session key based on a cryptographic random number generation function using the key distribution unit.
[0128] S213. The quantum-resistant security platform encrypts the session key based on the target quantum-resistant cryptographic algorithm to obtain an encrypted session key.
[0129] Exemplarily, the quantum-resistant security platform can call the target quantum-resistant cryptographic algorithm based on the quantum-resistant encryption and decryption operation unit, use the pre-stored public key of the algorithm to encrypt the generated session key, and obtain the encrypted session key.
[0130] S214. The quantum-resistant security platform encrypts the target key according to the encrypted session key to obtain an encrypted target key.
[0131] Exemplarily, the quantum-resistant security platform can be based on the quantum-resistant encryption and decryption operation unit, and according to the encrypted session key, use a preset encryption algorithm to encrypt the target key to obtain the encrypted target key.
[0132] S215. The quantum-resistant security platform obtains a key with quantum computing resistance according to the encrypted session key and the encrypted target key.
[0133] Exemplarily, the quantum-resistant security platform can combine the encrypted session key and the encrypted target key based on the key distribution unit, and encapsulate them in an easily preset data structure format to form a key with quantum computing resistance.
[0134] S216. The quantum-resistant security platform sends a key with quantum-resistant computing characteristics to the business system.
[0135] Exemplarily, the quantum-resistant security platform may assemble a key with quantum-resistant computing properties into a transaction message through a transaction response unit and send the message to the business system.
[0136] Correspondingly, the business system receives the key with anti-quantum computing characteristics returned by the anti-quantum security platform.
[0137] S217. The business system decrypts the encrypted session key based on the quantum-resistant dynamic security component and the target quantum-resistant cryptographic algorithm to obtain the plaintext session key.
[0138] For example, as mentioned above, the quantum-resistant key includes an encrypted session key and an encrypted target key. The plaintext session key represents the original session key obtained by decrypting the encrypted session key using the quantum-resistant private key.
[0139] In one example, the business system can use the private key previously generated by the target quantum-resistant cryptographic algorithm based on the quantum-resistant operator of the quantum-resistant dynamic security component to call the target quantum-resistant cryptographic algorithm to decrypt the encrypted session key, obtain the plaintext session key, and store it in the secure memory area.
[0140] S218. The business system decrypts the encrypted target key according to the plaintext session key based on the quantum-resistant dynamic security component to obtain the target key for the target business.
[0141] Exemplarily, the business system can use the plaintext session key based on the quantum-resistant operator of the quantum-resistant dynamic security component to decrypt the encrypted target key to obtain the target key of the target business; and assign a key index to the target key and place it in the memory of the key storage for subsequent use by the business system.
[0142] The key distribution method provided by the embodiment of the present application is that before the quantum security platform distributes keys to the business system, the business system first obtains the security requirements and business performance requirements required by the target business, and determines the security algorithm requirements required by the target business based on the security requirements and business performance requirements, and generates and sends an algorithm negotiation request based on the security algorithm requirements; the quantum security platform responds to the algorithm negotiation request, determines the target quantum cryptographic algorithm that matches the security algorithm requirements of the target business from a preset algorithm library, and returns it to the business system; after receiving the target quantum cryptographic algorithm, the business system obtains the key identification information of the target business based on the quantum dynamic security component, and uses the target quantum cryptographic algorithm and the key to negotiate the algorithm. The key identification information generates a key acquisition request and sends it to the quantum-resistant security platform; the quantum-resistant security platform responds to the key acquisition request, determines the target key and session key of the target business based on the key identification information, and first encrypts the session key using the target quantum-resistant cryptographic algorithm, and then uses the encrypted session key to encrypt the target key to obtain a key with quantum computing resistance, and distributes it to the business system; after receiving the key with quantum computing resistance, the business system first uses the target quantum-resistant cryptographic algorithm to decrypt the encrypted session key to obtain a plaintext session key, and then uses the plaintext session key to decrypt the encrypted target key to obtain the target key of the target business.
[0143] Through this method, on the one hand, in the process of distributing keys from the quantum security platform to the business system, the quantum cryptographic algorithm is used to encrypt the keys, which can effectively resist the attack of quantum computers, prevent the traditional encryption algorithm from being cracked, and improve the security of key distribution; on the other hand, the business system and the quantum security platform can dynamically negotiate based on the security algorithm requirements required by the business to determine the quantum cryptographic algorithm that meets the business needs, so that the business system can select the most appropriate quantum cryptographic algorithm according to different business scenarios and security requirements, which can not only meet the business security requirements, but also ensure the efficient operation of the business and avoid waste of resources; on the other hand, according to the security algorithm requirements of the business system, dynamic negotiation is carried out to match the target quantum cryptographic algorithm When the security of the algorithm is threatened, the algorithm library can be updated to ensure the use of secure quantum-resistant cryptographic algorithms for encryption processing, realize automatic identification and elimination of unsafe algorithms, reduce manual intervention, and improve the timeliness and accuracy of algorithm management; on the other hand, the target key is encrypted through the session key to achieve a one-time-one-pad method to ensure the confidentiality, integrity and non-repudiation of data during transmission and processing; on the other hand, the quantum-resistant dynamic security component is decoupled from the business system, and the business system does not need to pay attention to the underlying technical details, which is convenient for integration into various existing business systems; and the design of the algorithm library supports the addition and updating of algorithms, which can flexibly respond to the ever-evolving quantum attack technology and changes in business needs without the need to improve the business system.
[0144] Figure 6 This is a schematic diagram of the structure of the key distribution device provided by this application, such as Figure 6 As shown, the key distribution device 300 provided in this embodiment can be applied to a quantum-resistant security platform. The key distribution device 300 includes:
[0145] Determination module 301 is configured to respond to an algorithm negotiation request sent by a business system, determine a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement according to the security algorithm requirement carried in the algorithm negotiation request, and send the target quantum-resistant cryptographic algorithm to the business system;
[0146] The encryption module 302 is configured to respond to the key acquisition request of the business system, determine the target key required for the target business based on the key identification information of the target business indicated in the key acquisition request, and encrypt the target key according to the target quantum-resistant cryptographic algorithm to obtain a key with quantum computing resistance characteristics;
[0147] The sending module 303 is used to send the key with anti-quantum computing characteristics to the business system.
[0148] In some possible implementations, the encryption module 302 is specifically configured to:
[0149] Determine the session key;
[0150] encrypting the session key based on the target quantum-resistant cryptographic algorithm to obtain an encrypted session key;
[0151] encrypting the target key according to the encrypted session key to obtain an encrypted target key;
[0152] A key with quantum computing resistance is obtained according to the encrypted session key and the encrypted target key.
[0153] In some possible implementations, the determining module 301 is specifically configured to:
[0154] According to the security algorithm requirement and a preset algorithm library, a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement is determined; wherein the algorithm library includes multiple quantum-resistant cryptographic algorithms.
[0155] In some possible implementations, the device further includes a management module configured to:
[0156] Obtaining the operating data of each quantum-resistant cryptographic algorithm in the algorithm library;
[0157] Determining an unsafe algorithm in the algorithm library according to the operation data of the quantum-resistant cryptographic algorithm;
[0158] The unsafe algorithm is removed from the algorithm library.
[0159] In some possible implementations, the management module is specifically configured to:
[0160] For each quantum-resistant cryptographic algorithm in the algorithm library, extract the abnormal characteristics of the quantum-resistant cryptographic algorithm based on the operation data of the quantum-resistant cryptographic algorithm; if it is determined that the quantum-resistant cryptographic algorithm is abnormal based on the abnormal characteristics, determine that the quantum-resistant cryptographic algorithm is an unsafe algorithm.
[0161] The key distribution device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0162] Figure 7 This is a schematic diagram of the structure of the key distribution device provided by this application, such as Figure 7 As shown, the key distribution device 400 provided in this embodiment can be applied to a business system. The key distribution device 400 includes:
[0163] A first acquisition module 401 is configured to acquire security algorithm requirements for a target service based on the quantum-resistant dynamic security component; generate an algorithm negotiation request based on the security algorithm requirements, and send the algorithm negotiation request to the quantum-resistant security platform;
[0164] A second acquisition module 402 is configured to receive, based on the quantum-resistant dynamic security component, the target quantum-resistant cryptographic algorithm returned by the quantum-resistant security platform, and obtain key identification information of the target service; generate a key acquisition request based on the target quantum-resistant cryptographic algorithm and the key identification information, and send the key acquisition request to the quantum-resistant security platform;
[0165] The decryption module 403 is configured to receive the key with quantum computing resistance characteristics returned by the quantum security platform based on the quantum dynamic security component; and decrypt the key with quantum computing resistance characteristics according to the target quantum cryptographic algorithm to obtain the key for the target business.
[0166] In some possible implementations, the second obtaining module 402 is specifically configured to:
[0167] Based on the quantum-resistant dynamic security component, the target quantum-resistant cryptographic algorithm is called to generate a public key and a private key for quantum-resistant cryptography; and the key acquisition request is generated according to the key identification information and the public key of the quantum-resistant cryptography.
[0168] In some possible implementations, the key with quantum computing resistance includes an encrypted session key and an encrypted target key; the decryption module 403 is specifically configured to:
[0169] Based on the quantum-resistant dynamic security component, the encrypted session key is decrypted according to the target quantum-resistant cryptographic algorithm to obtain a plaintext session key; and the encrypted target key is decrypted according to the plaintext session key to obtain a key for the target business.
[0170] In some possible implementations, the first obtaining module 401 is specifically configured to:
[0171] Based on the quantum-resistant dynamic security component, the security requirements and business performance requirements required by the target business are obtained; and based on the security requirements and business performance requirements, the security algorithm requirements of the target business are determined.
[0172] The key distribution device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0173] Figure 8This is a schematic diagram of the structure of the electronic device provided in this application. Figure 8 As shown, the electronic device 500 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the electronic device 500 also includes a communication component 503. The processor 501, the memory 502, and the communication component 503 are connected via a bus. The electronic device can be the aforementioned quantum-resistant security platform or business system.
[0174] In a specific implementation process, at least one processor 501 executes the computer-executable instructions stored in the memory 502, so that the at least one processor 501 performs the above method.
[0175] The specific implementation process of the processor 501 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0176] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.
[0177] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.
[0178] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0179] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0180] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0181] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0182] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0183] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0184] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0185] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0186] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0187] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0188] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A key distribution method, characterized in that: The method is applied to a quantum-resistant security platform; the method comprises: In response to an algorithm negotiation request sent by the business system, determining a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement according to the security algorithm requirement carried in the algorithm negotiation request, and sending the target quantum-resistant cryptographic algorithm to the business system; In response to a key acquisition request from the business system, determining a target key required for the target business based on key identification information of the target business indicated in the key acquisition request; encrypting the target key according to the target quantum-resistant cryptographic algorithm to obtain a key with quantum-resistant computing characteristics; Sending the key with quantum computing resistance characteristics to the business system.
2. The method according to claim 1, characterized in that The encrypting the target key according to the target quantum-resistant cryptographic algorithm to obtain a key with quantum-resistant computing characteristics includes: Determine the session key; encrypting the session key based on the target quantum-resistant cryptographic algorithm to obtain an encrypted session key; encrypting the target key according to the encrypted session key to obtain an encrypted target key; A key with quantum computing resistance is obtained according to the encrypted session key and the encrypted target key.
3. The method according to claim 1 or 2, characterized in that The determining, according to the security algorithm requirement carried in the algorithm negotiation request, a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement includes: According to the security algorithm requirement and a preset algorithm library, a target quantum-resistant cryptographic algorithm that matches the security algorithm requirement is determined; wherein the algorithm library includes multiple quantum-resistant cryptographic algorithms.
4. The method according to claim 3, characterized in that The method further comprises: Obtaining the operating data of each quantum-resistant cryptographic algorithm in the algorithm library; Determining an unsafe algorithm in the algorithm library according to the operation data of the quantum-resistant cryptographic algorithm; The unsafe algorithm is removed from the algorithm library.
5. The method according to claim 4, characterized in that The step of determining an unsafe algorithm in the algorithm library according to the operation data of the quantum-resistant cryptographic algorithm includes: For each quantum-resistant cryptographic algorithm in the algorithm library, extract the abnormal characteristics of the quantum-resistant cryptographic algorithm based on the operation data of the quantum-resistant cryptographic algorithm; if it is determined that the quantum-resistant cryptographic algorithm is abnormal based on the abnormal characteristics, determine that the quantum-resistant cryptographic algorithm is an unsafe algorithm.
6. A key distribution method, characterized in that: The method is applied to a business system, wherein the business system is deployed with a quantum-resistant dynamic security component; the method comprises: Based on the quantum-resistant dynamic security component, obtain the security algorithm requirements required by the target business; and generate an algorithm negotiation request based on the security algorithm requirements, and send the algorithm negotiation request to the quantum-resistant security platform; Based on the quantum-resistant dynamic security component, receive the target quantum-resistant cryptographic algorithm returned by the quantum-resistant security platform, and obtain key identification information of the target service; generate a key acquisition request based on the target quantum-resistant cryptographic algorithm and the key identification information, and send the key acquisition request to the quantum-resistant security platform; Based on the quantum-resistant dynamic security component, the key with quantum-resistant computing characteristics returned by the quantum-resistant security platform is received; and according to the target quantum-resistant cryptographic algorithm, the key with quantum-resistant computing characteristics is decrypted to obtain the key of the target business.
7. The method according to claim 6, characterized in that The generating a key acquisition request according to the target quantum-resistant cryptographic algorithm and the key identification information includes: Based on the quantum-resistant dynamic security component, the target quantum-resistant cryptographic algorithm is called to generate a public key and a private key for quantum-resistant cryptography; and the key acquisition request is generated according to the key identification information and the public key of the quantum-resistant cryptography.
8. The method according to claim 6, characterized in that The key with quantum computing resistance includes an encrypted session key and an encrypted target key; and decrypting the key with quantum computing resistance according to the target quantum computing resistance cryptographic algorithm to obtain the key for the target service includes: Based on the quantum-resistant dynamic security component, the encrypted session key is decrypted according to the target quantum-resistant cryptographic algorithm to obtain a plaintext session key; and the encrypted target key is decrypted according to the plaintext session key to obtain a key for the target business.
9. The method according to any one of claims 6 to 8, characterized in that: The security algorithm requirements for obtaining the target business include: Based on the quantum-resistant dynamic security component, the security requirements and business performance requirements required by the target business are obtained; and based on the security requirements and business performance requirements, the security algorithm requirements of the target business are determined.
10. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor executes the key distribution method according to any one of claims 1 to 5, or the key distribution method according to any one of claims 6 to 9.