Equipment communication method and device and related equipment

By receiving the computing power level and security level information of the equipment, dynamically adjusting the target security level and communication protocol, and using the anti-quantum cryptographic algorithm to enhance the communication of industrial equipment, solving the problem that industrial equipment is difficult to adapt to the anti-quantum cryptographic algorithm due to computing power limitations, achieving higher communication security and system adaptability.

CN120567397AActive Publication Date: 2025-08-29CHINA TELECOM CORP LTD +1

Patent Information

Application Number
CN202511061820.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-08-29
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

Due to computing power limitations, industrial equipment is difficult to adapt to quantum cryptographic algorithms, resulting in insufficient communication security.

Method used

By receiving the computing power level, security level and quantum cryptographic algorithm information of the device, dynamically adjust the target security level and communication protocol, and enhance the communication protocol using the target quantum cryptographic algorithm and parameter set.

Benefits of technology

It improves the communication security and system adaptability of industrial equipment in resource-constrained environments, and enhances the protection ability to combat quantum computing threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567397A_ABST
    Figure CN120567397A_ABST
Patent Text Reader

Abstract

The invention provides an equipment communication method and device and related equipment, and relates to the technical field of communication. The method comprises the following steps: respectively determining a target security level, a target anti-quantum cryptography algorithm and a target communication protocol from security levels, anti-quantum cryptography algorithms and communication protocols of a first device and a second device based on computing power levels of the first device and the second device; determining a target parameter set used by the target anti-quantum cryptography algorithm based on the target security level; according to the category of the target communication protocol, performing protocol enhancement on the target communication protocol by using the target anti-quantum cryptography algorithm and the target parameter set; and communicating with the second equipment according to the target communication protocol after protocol enhancement. Through the technical means, the problem that industrial equipment is difficult to adapt to the anti-quantum cryptography algorithm due to the limitation of computing power in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technology, and in particular to a device communication method, apparatus, and related equipment. Background Art

[0002] The development of quantum technology poses a significant threat to the security of traditional communications, especially in highly open industrial communications. To address the challenges posed by quantum technology, it is necessary to adopt or add quantum-resistant cryptographic algorithms for communication encryption. However, for industrial equipment, the computing power itself is limited, and different quantum-resistant cryptographic algorithms require different computing power. Therefore, how to properly adapt quantum-resistant cryptographic algorithms for industrial equipment is a major research hotspot. Summary of the Invention

[0003] The present disclosure provides a device communication method, apparatus, and related equipment, which improve the security of device communication at least to a certain extent.

[0004] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0005] According to one aspect of the present disclosure, a device communication method is provided, which is applied to a first device, and includes: receiving initial information from a second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and category of the second device; determining a target security level, a target quantum-resistant cryptographic algorithm and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms and communication protocols of the first and second devices, respectively, based on the computing power levels of the first and second devices; determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicating with the second device according to the enhanced target communication protocol.

[0006] In one embodiment of the present disclosure, receiving initial information from a second device includes: receiving an initial message from the second device; after receiving the initial message from the second device, the method further includes: parsing the initial message from the second device, and determining the computing power level, security level and quantum-resistant cryptographic algorithm, communication protocol and category of the second device from the first field, second field and third field of the initial message of the second device, respectively.

[0007] In one embodiment of the present disclosure, based on the computing power levels of the first device and the second device, the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol are determined from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively, including: taking the device with the lower computing power level of the first device and the second device as the target device; and taking the security level, quantum-resistant cryptographic algorithm, and communication protocol of the target device as the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol, respectively.

[0008] In one embodiment of the present disclosure, a target parameter set used by a target quantum-resistant cryptographic algorithm is determined based on a target security level, including: when the target security level is a first level, determining the target parameter set to be a first parameter set; when the target security level is a second level, determining the target parameter set to be a second parameter set; when the target security level is a third level, determining the target parameter set to be a third parameter set; when the target security level is a fourth level, determining the target parameter set to be a zero parameter set.

[0009] In one embodiment of the present disclosure, according to the category of the target communication protocol, the target communication protocol is enhanced using a target quantum-resistant cryptographic algorithm and a target parameter set, including: the category of the target communication protocol includes a target communication protocol with an encryption algorithm and a target communication protocol without an encryption algorithm; when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; when the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced by the target quantum-resistant cryptographic algorithm using the target parameter set.

[0010] In one embodiment of the present disclosure, before determining the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first and second devices, respectively, based on the computing power levels of the first device and the second device, the method further includes: determining the computing power level, communication protocol, and category of the first device; and determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.

[0011] In one embodiment of the present disclosure, after determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device, the method further includes: sending initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device.

[0012] In one embodiment of the present disclosure, sending initial information of a first device to a second device includes: encapsulating the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and category of the first device into the first field, second field, and third field of the initial message of the first device, respectively, to obtain the initial message of the first device; and sending the initial message of the first device to the second device.

[0013] In one embodiment of the present disclosure, determining the computing power level of a first device includes: performing a computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, determining that the computing power level of the first device is a computing power-limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, determining that the computing power level of the first device is a conventional device; and when the evaluation value is greater than the third threshold, determining that the computing power level of the first device is a high-computing power device.

[0014] In one embodiment of the present disclosure, the security level of the first device is determined based on the computing power level of the first device, including: when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining the security level of the first device to be the fourth level; when the computing power level of the first device is a computing power-limited device, determining the security level of the first device to be the third level; when the computing power level of the first device is a conventional device, determining the security level of the first device to be the second level; when the computing power level of the first device is a strong computing power device, determining the security level of the first device to be the first level.

[0015] According to another aspect of the present disclosure, there is provided a device communication apparatus, which is applied to a first device and is characterized in that it includes: a receiving module, configured to receive initial information from a second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and category of the second device; a first determination module, configured to determine a target security level, a target quantum-resistant cryptographic algorithm and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms and communication protocols of the first device and the second device respectively based on the computing power levels of the first device and the second device; a second determination module, configured to determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; an enhancement module, configured to perform protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and a communication module, configured to communicate with the second device in accordance with the enhanced target communication protocol.

[0016] According to yet another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform any of the above methods by executing the executable instructions.

[0017] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, any of the above methods is implemented.

[0018] According to another aspect of the present disclosure, a computer program product is provided, including computer instructions stored in a computer-readable storage medium, and the computer instructions implement operating instructions of any of the above methods when executed by a processor.

[0019] In the embodiments of the present disclosure, a target parameter set used by a target quantum-resistant cryptographic algorithm is determined based on a target security level. According to the category of the target communication protocol, the target quantum-resistant cryptographic algorithm and the target parameter set are used to enhance the target communication protocol. This solves the problem in the prior art that industrial equipment is difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations, thereby enhancing the security of industrial equipment communications.

[0020] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0022] Figure 1 A schematic diagram of a device communication system in an embodiment of the present disclosure is shown.

[0023] Figure 2 A flow chart of a device communication method in an embodiment of the present disclosure is shown.

[0024] Figure 3 A flowchart of a method for classifying computing power of devices in an embodiment of the present disclosure is shown.

[0025] Figure 4 A flow chart of a method for classifying device security levels in an embodiment of the present disclosure is shown.

[0026] Figure 5 A schematic structural diagram of a quantum security component in an embodiment of the present disclosure is shown.

[0027] Figure 6 A schematic diagram of a device communication apparatus in an embodiment of the present disclosure is shown.

[0028] Figure 7A schematic diagram of an electronic device provided in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0029] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0030] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0031] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0032] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0033] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0034] It should be pointed out that, in the absence of conflict, the embodiments of the present disclosure and the technical features therein may be combined with each other.

[0035] For ease of understanding, several terms involved in this disclosure are explained below: Industrial communications refers to the communication technology used for data transmission and control between devices and systems in industrial environments. Featuring high reliability, real-time performance, and security, it is the cornerstone of industrial automation and intelligent manufacturing. Its core function is to enable efficient interconnection of sensors, controllers, actuators, and other devices, supporting real-time monitoring, automated control, and data-driven decision-making.

[0036] Post-quantum cryptography (PQC), also known as "quantum-resistant cryptography," is a new generation of cryptographic algorithms that can resist attacks by quantum computers on existing cryptographic algorithms. It is a key technology for maintaining network security in the quantum information age and an important part of combating the threat of quantum computers.

[0037] PROFIBUS (Process Field Bus) is another widely used fieldbus standard suitable for factory automation and process automation. This protocol does not have an encryption algorithm.

[0038] OPC-UA (OPC Unified Architecture) is a cross-platform, service-oriented architecture designed to provide secure and reliable data exchange for industrial automation. It is a major upgrade to the traditional OPC standard, addressing issues such as interoperability and security. The protocol also includes encryption algorithms.

[0039] CRYSTALS-KYBER (Key Encapsulation Mechanism, KEM) is a quantum-resistant cryptographic algorithm. It is based on the Module-Learning With Errors (MLWE) problem, a mathematical problem considered intractable in the quantum computing era. KYBER was proposed as part of the NIST post-quantum cryptography standard and has garnered attention for its performance and security.

[0040] CRYSTALS-Dilithium is a quantum-resistant cryptographic algorithm based on lattice-based cryptography, designed to provide protection against quantum computing attacks. It was developed as part of the National Institute of Standards and Technology (NIST)'s post-quantum cryptography standardization process and was selected as a finalist in the third round. Developed by a team of renowned researchers, Dilithium aims to provide an efficient and secure post-quantum digital signature scheme.

[0041] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0042] Figure 1 A schematic diagram of a device communication system according to an embodiment of the present disclosure is shown. Both the first device 101 and the second device 102 can be industrial devices such as smart sensors, smart meters, industrial gateways, edge computing devices and industrial robots. Alternatively, the first device 101 and the second device 102 can also be mobile phones, game consoles, tablets, e-book readers, smart glasses, MP4 (Moving Picture Experts Group Audio Layer IV, Moving Picture Experts Group Audio Layer 4) players, smart home devices, AR (Augmented Reality) devices, VR (Virtual Reality) devices and other mobile devices.

[0043] In which, an application can be installed in the first device 101 to perform: receiving initial information from the second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the second device; based on the computing power levels of the first device and the second device, determining the target security level, target quantum-resistant cryptographic algorithm and target communication protocol from the security level, quantum-resistant cryptographic algorithm and communication protocol of the first device and the second device respectively; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; according to the category of the target communication protocol, using the target quantum-resistant cryptographic algorithm and target parameter set to enhance the target communication protocol; and communicating with the second device according to the enhanced target communication protocol.

[0044] In which, an application can be installed in the second device 102 to perform: receiving initial information from the first device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device; based on the computing power levels of the second device and the first device, determining the target security level, target quantum-resistant cryptographic algorithm and target communication protocol from the security level, quantum-resistant cryptographic algorithm and communication protocol of the second device and the first device respectively; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; according to the category of the target communication protocol, using the target quantum-resistant cryptographic algorithm and target parameter set to enhance the target communication protocol; and communicating with the first device according to the enhanced target communication protocol.

[0045] The first device 101 and the second device 102 are connected via a communication network. Optionally, the communication network is a wired network or a wireless network.

[0046] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or any combination of a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. can be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.

[0047] Figure 2 A flow chart of a device communication method according to an embodiment of the present disclosure is shown, and the method is applied to a first device, such as Figure 2 As shown, the following steps are included: S201, receiving initial information from a second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the second device.

[0048] The second device is the other end of the communication chain with the first device. The computing power level is a measure of a device's computing power, affecting its ability to execute complex algorithms. The security level indicates the device's level of strength in protecting data and communication security. Quantum-resistant cryptographic algorithms are PQC algorithms. Communication protocols define a set of rules for exchanging information between different devices, including classifications such as transport layer protocols and application layer protocols. Based on the presence or absence of encryption algorithms, target communication protocols can be categorized as either with or without encryption algorithms.

[0049] In one embodiment of the present disclosure, receiving initial information from a second device includes: receiving an initial message from the second device; after receiving the initial message from the second device, the method further includes: parsing the initial message from the second device, and determining the computing power level, security level and quantum-resistant cryptographic algorithm, communication protocol and category of the second device from the first field, second field and third field of the initial message of the second device, respectively.

[0050] In this embodiment, after receiving the initial message sent by the second device, the initial message of the second device is parsed. Because the first field, the second field, and the third field of the initial message of the second device respectively encapsulate the computing power level, security level, and quantum-resistant cryptographic algorithm, communication protocol, and its category of the second device, the computing power level, security level, and quantum-resistant cryptographic algorithm, communication protocol, and its category of the second device can be obtained by parsing the initial message of the second device. By using the above-mentioned technical means to obtain key information by parsing each field in the initial message, it is ensured that the secure communication configuration between devices can be dynamically adjusted based on the actual capabilities and needs of both parties, thereby enhancing the adaptability and security of the entire system. In addition, the above-mentioned technical means also enhance the possibility of optimizing encryption schemes for specific hardware environments, further strengthening the security protection level of data transmission.

[0051] In some embodiments of the present disclosure, receiving initial information from a second device includes: receiving an initial message from the second device; after receiving the initial message from the second device, the method further includes: parsing the initial message from the second device according to preset message rules to determine the computing power level, security level and quantum-resistant cryptographic algorithm, communication protocol and category of the second device.

[0052] S202 , based on the computing power levels of the first device and the second device, determine a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively.

[0053] Based on the computing power level of the first device and the computing power level of the second device, a target security level is determined from the security level of the first device and the security level of the second device, a target quantum-resistant cryptographic algorithm is determined from the quantum-resistant cryptographic algorithm of the first device and the quantum-resistant cryptographic algorithm of the second device, and a target communication protocol is determined from the communication protocol of the first device and the communication protocol of the second device.

[0054] In one embodiment of the present disclosure, based on the computing power levels of the first device and the second device, the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol are determined from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively, including: taking the device with the lower computing power level of the first device and the second device as the target device; and taking the security level, quantum-resistant cryptographic algorithm, and communication protocol of the target device as the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol, respectively.

[0055] The computing power levels of the first and second devices are compared, and the device with the lower computing power level is identified as the target device. The target device's security level, quantum-resistant cryptographic algorithm, and communication protocol are then used to determine the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol used during communication between the two devices. This technical approach directly accounts for differences in computing power between devices, selecting security configurations and technical parameters suitable for devices with lower computing power. This improves the compatibility and adaptability of the overall system and enhances the ability to securely communicate between different devices. This technical approach not only enhances the system's support for diverse hardware environments but also ensures the security and reliability of data transmission.

[0056] For example, in an intelligent transportation system, suppose a roadside unit (ROU) (the first device) and an onboard unit (OVU) (the second device) need to communicate securely. If the OVU's computing power is lower than that of the RSU, the OVU is considered the target device, and the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol used in communication between the two parties are set based on its security level, target quantum-resistant cryptographic algorithm, and target communication protocol. This allows for efficient and secure data exchange even if the OVU cannot support highly complex encryption algorithms due to hardware limitations, enhancing the security of the intelligent transportation system and improving the safety of road users.

[0057] In one embodiment of the present disclosure, before determining the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first and second devices, respectively, based on the computing power levels of the first device and the second device, the method further includes: determining the computing power level, communication protocol, and category of the first device; and determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.

[0058] The communication protocol currently used by the first device is determined, and the target communication protocol is classified into a target communication protocol with an encryption algorithm or a target communication protocol without an encryption algorithm according to a standard of whether the target communication protocol has an encryption algorithm.

[0059] In one embodiment of the present disclosure, determining the computing power level of a first device includes: performing a computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, determining that the computing power level of the first device is a computing power-limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, determining that the computing power level of the first device is a conventional device; and when the evaluation value is greater than the third threshold, determining that the computing power level of the first device is a high-computing power device.

[0060] A comprehensive assessment of the computing power of the first device, reflecting its ability to execute complex algorithms in the form of quantitative indicators. The first device's benchmark score (similar to a mobile phone or computer processor benchmark) or the chip evaluation results of the first device can be directly used as the evaluation value of the first device.

[0061] When the evaluation value is less than or equal to the first threshold, it indicates that the computing resources of the first device are extremely limited and cannot meet the basic requirements for running quantum-resistant cryptographic algorithms. The first device is classified as a device that does not support any quantum-resistant cryptographic algorithms. When the evaluation value is greater than the first threshold but less than or equal to the second threshold, it means that the first device has some computing power, but not enough to efficiently run complex quantum-resistant cryptographic algorithms. The first device is classified as a device with limited computing power. When the evaluation value is greater than the second threshold but less than or equal to the third threshold, it indicates that the first device has sufficient computing resources to support general quantum-resistant cryptographic algorithm operations. The first device is classified as a conventional device. When the evaluation value is greater than the third threshold, it indicates that the first device has strong computing power and can efficiently handle complex encryption tasks. The first device is classified as a high-computing device. Through the above technical means, the goal of dynamically adjusting security policies based on the actual computing power of the device is achieved, ensuring effective secure communication even in resource-constrained environments.

[0062] For example, in a cloud computing environment, consider a variety of server types (as the primary device), ranging from older models to the latest high-performance models. By evaluating the computing power of these servers and categorizing them as devices that do not support any quantum-resistant cryptographic algorithms, devices with limited computing power, devices with standard computing power, or devices with high computing power, cloud service providers can assign appropriate tasks and security measures based on the characteristics of different server types. For example, for devices with limited computing power, lightweight quantum-resistant cryptographic algorithms can be selected; for devices with high computing power, higher-level encryption schemes can be deployed, thereby enhancing the security and stability of the entire cloud environment.

[0063] In one embodiment of the present disclosure, the security level of the first device is determined based on the computing power level of the first device, including: when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining the security level of the first device to be the fourth level; when the computing power level of the first device is a computing power-limited device, determining the security level of the first device to be the third level; when the computing power level of the first device is a conventional device, determining the security level of the first device to be the second level; when the computing power level of the first device is a strong computing power device, determining the security level of the first device to be the first level.

[0064] Devices with a security level of 4 do not use any quantum-resistant cryptographic algorithms. The order of computing power, from low to high, is as follows: no support for quantum-resistant cryptographic algorithms, limited computing power devices, conventional devices, and high computing power devices. The security levels, from low to high, are level 4, level 3, level 2, and level 1. Devices that do not support quantum-resistant cryptographic algorithms, limited computing power devices, conventional devices, and high computing power devices correspond to levels 4, 3, 2, and 1, respectively. Through these technical measures, the goal of dynamically adjusting a device's security level based on its actual computing power is achieved, ensuring effective secure communication even in resource-constrained environments. This allows devices of different performance levels to find a security configuration solution that suits them, thereby enhancing the security and stability of the entire network environment.

[0065] For example, in an IoT application scenario, consider a variety of sensor types (as primary devices), ranging from simple sensors with low power consumption and limited computing power to high-performance, intelligent sensors with strong computing capabilities. By evaluating the computing power of these sensors and assigning security levels of Level 4, Level 3, Level 2, or Level 1 based on their computing power, appropriate tasks and security measures can be assigned to each sensor type. For example, for sensors with extremely limited computing power, only basic data protection measures can be implemented; whereas for intelligent sensors with strong computing power, advanced encryption and authentication mechanisms can be deployed, thereby enhancing the security and reliability of the entire IoT.

[0066] In one embodiment of the present disclosure, after determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device, the method further includes: sending initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device.

[0067] In one embodiment of the present disclosure, sending initial information of a first device to a second device includes: encapsulating the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and category of the first device into the first field, second field, and third field of the initial message of the first device, respectively, to obtain the initial message of the first device; and sending the initial message of the first device to the second device.

[0068] In some embodiments of the present disclosure, sending initial information of a first device to a second device includes: assembling the computing power level, security level and quantum-resistant cryptographic algorithm, communication protocol and its category of the first device to obtain the initial message of the first device; and sending the initial message of the first device to the second device.

[0069] S203: Determine a target parameter set used by a target quantum-resistant cryptographic algorithm based on a target security level.

[0070] The target parameter set is a set of optimal parameters selected for a quantum-resistant cryptographic algorithm to ensure optimal performance at a given security level. Given that many current industrial devices have limited computing resources, these systems face significant challenges in integrating and running quantum-resistant cryptographic algorithms. Quantum-resistant cryptographic algorithms generally have high requirements for computing power and memory, and the hardware configuration of existing industrial equipment often cannot meet the needs of such advanced encryption technologies, thereby limiting their application potential in resisting future quantum computing threats. The disclosed embodiment determines the target security level based on the computing power level, and determines the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level, thereby adapting appropriate encryption algorithms to the first device and the second device.

[0071] In one embodiment of the present disclosure, a target parameter set used by a target quantum-resistant cryptographic algorithm is determined based on a target security level, including: when the target security level is a first level, determining the target parameter set to be a first parameter set; when the target security level is a second level, determining the target parameter set to be a second parameter set; when the target security level is a third level, determining the target parameter set to be a third parameter set; when the target security level is a fourth level, determining the target parameter set to be a zero parameter set.

[0072] The first, second, third, and zero parameter sets decrease in size, with the zero parameter set effectively not using the target quantum-resistant cryptographic algorithm. By setting multiple parameter sets through the aforementioned technical means, the quantum-resistant cryptographic algorithm parameter set can be dynamically adjusted based on the device's actual security requirements and computing power, ensuring effective secure communication even in resource-constrained environments.

[0073] For example, CRYSTALS-KYBER offers different parameter sets to suit different security requirements and application scenarios. Each parameter set defines different characteristics, such as public key size, ciphertext size, and key generation, encryption, and decryption speed. Kyber512 (third parameter set): provides approximately 128-bit classical security strength, suitable for most applications. Kyber768 (second parameter set): provides higher security strength, approximately equivalent to 192-bit classical security strength. Kyber1024 (first parameter set): provides the highest security level, approximately 256-bit classical security strength.

[0074] S204, performing protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the type of the target communication protocol; In one embodiment of the present disclosure, according to the category of the target communication protocol, the target communication protocol is enhanced using a target quantum-resistant cryptographic algorithm and a target parameter set, including: the category of the target communication protocol includes a target communication protocol with an encryption algorithm and a target communication protocol without an encryption algorithm; when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; when the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced by the target quantum-resistant cryptographic algorithm using the target parameter set.

[0075] For communication protocols that originally lack encryption algorithms, an additional layer of security is added by introducing a selected target quantum-resistant cryptographic algorithm and its corresponding parameter set. This technical approach enhances the security of data transmission, ensuring effective security even in communication protocols that originally lacked encryption measures. For communication protocols that originally had encryption algorithms, the original encryption algorithms will be replaced with quantum-resistant cryptographic algorithms that are more suitable for the current device computing power level and security requirements. This replacement not only improves the security of the communication protocol, but also ensures its ability to withstand future quantum computing attack threats, improving the security and forward-looking nature of the overall system. Through the above technical means, the goal of dynamically adjusting encryption strategies based on the specific circumstances of different target communication protocols is achieved, thereby ensuring that regardless of whether the original communication protocol has encryption capabilities, security can be further enhanced on the existing basis.

[0076] For example, in a smart city application scenario, there are multiple types of smart traffic lights (as the second device) communicating with a central control system (as the first device). Suppose that some older traffic lights use a traditional communication protocol without an encryption algorithm, while newer models may already have a certain level of encryption integrated into them. For those older traffic lights without encryption algorithms, a targeted quantum-resistant cryptographic algorithm based on a target parameter set can be added to their communication protocol to enhance their security. For newer devices that already have some form of encryption algorithm, the original encryption algorithm can be replaced with a more advanced targeted quantum-resistant cryptographic algorithm that is more suitable for current security requirements. This ensures that data exchange between all devices is fully secure, improving the overall security and reliability of the smart city traffic management system.

[0077] In some embodiments of the present disclosure, according to the category of the target communication protocol, the target communication protocol is enhanced using the target quantum-resistant cryptographic algorithm and the target parameter set, including: when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol, and the target quantum-resistant cryptographic algorithm using the target parameter set is used to perform encryption and decryption in communication; when the target communication protocol has an encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol, and the target quantum-resistant cryptographic algorithm using the target parameter set and the encryption algorithm in the target communication protocol are used to perform encryption and decryption in communication.

[0078] Encryption is performed during communication using a target quantum-resistant cryptographic algorithm using a target parameter set and an encryption algorithm in a target communication protocol. The encryption algorithm in the target communication protocol is first used to encrypt to obtain a first encryption result. The first encryption result is then encrypted using the target quantum-resistant cryptographic algorithm using the target parameter set to obtain a second encryption result.

[0079] S205: Communicate with the second device according to the enhanced target communication protocol.

[0080] The target quantum-resistant cryptographic algorithm using the target parameter set can be used for encryption and decryption during communications, while other communication standards follow the original provisions of the target communication protocol. This technical approach solves the problem of industrial equipment being unable to adapt to quantum-resistant cryptographic algorithms due to computing power limitations, thereby enhancing the security of industrial equipment communications.

[0081] In some embodiments, the second device: determines the computing power level, communication protocol and category of the second device; and determines the security level and quantum-resistant cryptographic algorithm of the second device based on the computing power level of the second device.

[0082] Figure 3A flow chart of a method for classifying computing power of a device according to an embodiment of the present disclosure is shown. The method is applied to a second device, such as Figure 3 As shown, the following steps are included: S301, evaluating the computing power of the second device to obtain an evaluation value; S302: When the evaluation value is less than or equal to the first threshold, determining that the computing power level of the second device is a device that does not support any quantum-resistant cryptographic algorithm; S303: When the evaluation value is greater than the first threshold but less than or equal to the second threshold, determine that the computing power level of the second device is a computing power-limited device; S304: When the evaluation value is greater than the second threshold but less than or equal to the third threshold, determine that the computing power level of the second device is a regular device; S305: When the evaluation value is greater than the third threshold, determine that the computing power level of the second device is a high computing power device.

[0083] The first threshold, the second threshold, and the third threshold increase in sequence. Through the above technical means, the goal of dynamically adjusting the security policy according to the actual computing power of the device is achieved, ensuring effective secure communication even in a resource-constrained environment.

[0084] There are multiple levels of computing power and security, and each computing power level has a corresponding security level.

[0085] In some embodiments, the second device can also be divided into more detailed categories according to the evaluation value: when the evaluation value is less than or equal to the fourth threshold, the computing power level of the second device is determined to be a first computing power level device; when the evaluation value is greater than the fourth threshold but less than or equal to the fifth threshold, the computing power level of the second device is determined to be a second computing power level device; when the evaluation value is greater than the fifth threshold but less than or equal to the sixth threshold, the computing power level of the second device is determined to be a third computing power level device; when the evaluation value is greater than the sixth threshold but less than or equal to the seventh threshold, the computing power level of the second device is determined to be a fourth computing power level device; when the evaluation value is greater than the seventh threshold, the computing power level of the second device is determined to be a fifth computing power level device.

[0086] Figure 4 A flow chart of a method for classifying device security levels in an embodiment of the present disclosure is shown. The method is applied to a second device, such as Figure 4 As shown, the following steps are included: S401, when the computing power level of the second device is a device that does not support any quantum-resistant cryptographic algorithm, determining that the security level of the second device is level 4; S402: When the computing power level of the second device is a computing power-limited device, determine that the security level of the second device is a third level; S403, when the computing power level of the second device is a conventional device, determining that the security level of the second device is a second level; S404: When the computing power level of the second device is a high computing power device, determine that the security level of the second device is the first level.

[0087] Through the above-mentioned technical means, the goal of dynamically adjusting the security level of the device according to its actual computing power is achieved, ensuring effective secure communication even in resource-constrained environments, and enabling devices of different performance levels to find a security configuration solution that suits them, thereby enhancing the security and stability of the entire network environment.

[0088] In some embodiments, when the computing power level of the second device is a first computing power level device, the security level of the second device is determined to be the fourth level; when the computing power level of the second device is a second computing power level device, the security level of the second device is determined to be the third level; when the computing power level of the second device is a third computing power level device or a fourth computing power level device, the security level of the second device is determined to be the second level; when the computing power level of the second device is a fifth computing power level device, the security level of the second device is determined to be the first level.

[0089] In some embodiments, a target parameter set used by a target quantum-resistant cryptographic algorithm is determined based on the type of the target communication protocol, the target security level, and the data types of the first device and the second device.

[0090] Specifically, the target communication protocol type, target security level, and corresponding scores for the data type are determined. The target parameter set to be used is determined based on the target communication protocol type, target security level, and corresponding scores for the data type. The target parameter set is one of several sizes of parameter sets used by the target quantum-resistant cryptographic algorithm.

[0091] For example, for the target communication protocol category, a target communication protocol without an encryption algorithm receives a score of 0, while a target communication protocol with an encryption algorithm receives a score of 50. There are four target security levels: 100, 75, 50, and 25 points, from high to low. The data categories of the first and second devices represent the categories of data exchanged between the first and second devices. These data categories include control instruction-related data, device-collected data, and device-specific data. Control instruction-related data, device-specific data, and device-collected data are assigned 50, 30, and 20 points, respectively. The total score for the target communication protocol category, target security level, and data category corresponds to three parameter sets of varying sizes, based on the set thresholds.

[0092] In some embodiments, a device communication method, applied to a second device, includes: receiving initial information from a first device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device; based on the computing power levels of the second device and the first device, determining the target security level, target quantum-resistant cryptographic algorithm and target communication protocol from the security level, quantum-resistant cryptographic algorithm and communication protocol of the second device and the first device respectively; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; according to the category of the target communication protocol, enhancing the target communication protocol using the target quantum-resistant cryptographic algorithm and target parameter set; and communicating with the first device according to the enhanced target communication protocol.

[0093] The disclosed embodiment receives initial information from a first device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and its category of the first device; based on the computing power levels of the second device and the first device, determines the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security level, quantum-resistant cryptographic algorithm, and communication protocol of the second device and the first device, respectively; determines the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; enhances the target communication protocol using the target quantum-resistant cryptographic algorithm and target parameter set according to the category of the target communication protocol; and communicates with the first device according to the enhanced target communication protocol. The above technical means solve the problem in the prior art that industrial equipment is difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations, thereby enhancing the security of industrial equipment communications.

[0094] In some embodiments, based on the computing power levels of the second device and the first device, the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol are determined from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the second device and the first device, respectively, including: taking the device with the lower computing power level between the second device and the first device as the target device; and taking the security level, quantum-resistant cryptographic algorithm, and communication protocol of the target device as the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol, respectively.

[0095] The above-mentioned technical means directly take into account the differences in computing power between devices, select security configurations and technical parameters suitable for low-computing power devices, improve the compatibility and adaptability of the overall system, and enhance the ability of secure communication between different devices.

[0096] In some embodiments, determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level includes: when the target security level is the second level, determining the target parameter set to be the second parameter set; when the target security level is the first level, determining the target parameter set to be the first parameter set; when the target security level is the first level, determining the target parameter set to be the first parameter set; when the target security level is the fourth level, determining the target parameter set to be the zero parameter set.

[0097] Through the above-mentioned technical means, multiple parameter sets are set to achieve the purpose of dynamically adjusting the parameter sets of quantum-resistant cryptographic algorithms according to the actual security requirements and computing capabilities of the equipment, thereby ensuring effective and secure communication even in resource-constrained environments.

[0098] In some embodiments, based on the category of the target communication protocol, the target communication protocol is enhanced using the target quantum-resistant cryptographic algorithm and the target parameter set, including: the category of the target communication protocol includes the target communication protocol with an encryption algorithm and the target communication protocol without an encryption algorithm; when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; when the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced with the target quantum-resistant cryptographic algorithm using the target parameter set.

[0099] Through the above technical means, the purpose of dynamically adjusting the encryption strategy according to the specific circumstances of different target communication protocols is achieved, thereby ensuring that regardless of whether the original communication protocol has encryption function, security can be further enhanced on the existing basis.

[0100] Based on the same inventive concept, the present disclosure also provides a device communication apparatus, such as the following embodiment. Since the principle of solving the problem in the apparatus embodiment is similar to that in the above method embodiment, the implementation of the apparatus embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0101] Figure 5 A schematic diagram of the structure of a quantum security component in an embodiment of the present disclosure is shown, which is applied to a first device, such as Figure 5 As shown, the quantum security component may include: The resource management module is used to evaluate the computing power of the first device and obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, the computing power level of the first device is determined to be a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, the computing power level of the first device is determined to be a computing power-limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, the computing power level of the first device is determined to be a conventional device; when the evaluation value is greater than the third threshold, the computing power level of the first device is determined to be a high-computing power device.

[0102] The quantum-safe algorithm library is used to support the current mainstream quantum-resistant cryptographic algorithms at home and abroad and various parameter sets that can be selected for various quantum-resistant cryptographic algorithms, and can achieve flexible iterative updates.

[0103] An algorithm selection module is used to determine that the security level of the first device is the fourth level when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; to determine that the security level of the first device is the third level when the computing power level of the first device is a computing power-limited device; to determine that the security level of the first device is the second level when the computing power level of the first device is a conventional device; and to determine that the security level of the first device is the first level when the computing power level of the first device is a strong computing power device; and based on the computing power levels of the first device and the second device, to determine the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively.

[0104] The protocol enhancement module is used to enhance the target communication protocol according to the category of the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set, including: when the target communication protocol has no encryption algorithm, adding the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol; when the target communication protocol has an encryption algorithm, replacing the encryption algorithm in the target communication protocol with the target quantum-resistant cryptographic algorithm using the target parameter set.

[0105] The disclosed embodiment receives initial information from a second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and its category of the second device; based on the computing power levels of the first device and the second device, determines the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security level, quantum-resistant cryptographic algorithm, and communication protocol of the first device and the second device, respectively; determines the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; enhances the target communication protocol using the target quantum-resistant cryptographic algorithm and target parameter set according to the category of the target communication protocol; and communicates with the second device according to the enhanced target communication protocol. The above technical means solve the problem in the prior art that industrial equipment is difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations, thereby enhancing the security of industrial equipment communications.

[0106] Figure 6 A schematic diagram of a device communication apparatus according to an embodiment of the present disclosure is shown, which is applied to a first device, such as Figure 6 As shown, the device communication device may include: a receiving module 601 configured to receive initial information from a second device, wherein the initial information of the second device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a type thereof; A first determining module 602 is configured to determine a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first and second devices, respectively, based on the computing power levels of the first and second devices; A second determination module 603 is configured to determine a target parameter set used by a target quantum-resistant cryptographic algorithm based on a target security level; The enhancement module 604 is configured to perform protocol enhancement on the target communication protocol using a target quantum-resistant cryptographic algorithm and a target parameter set according to the category of the target communication protocol; The communication module 605 is configured to communicate with the second device according to the target communication protocol after the protocol enhancement.

[0107] The disclosed embodiment receives initial information from a second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and its category of the second device; based on the computing power levels of the first device and the second device, determines the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security level, quantum-resistant cryptographic algorithm, and communication protocol of the first device and the second device, respectively; determines the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; enhances the target communication protocol using the target quantum-resistant cryptographic algorithm and target parameter set according to the category of the target communication protocol; and communicates with the second device according to the enhanced target communication protocol. The above technical means solve the problem in the prior art that industrial equipment is difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations, thereby enhancing the security of industrial equipment communications.

[0108] In some embodiments, the receiving module 601 is further configured to receive an initial message from a second device; parse the initial message of the second device, and determine the computing power level, security level, and quantum-resistant cryptographic algorithm, communication protocol, and category of the second device from the first field, second field, and third field of the initial message of the second device, respectively.

[0109] In some embodiments, the first determination module 602 is further configured to use the device with the lower computing power level between the first device and the second device as the target device; and use the security level, quantum-resistant cryptographic algorithm and communication protocol of the target device as the target security level, target quantum-resistant cryptographic algorithm and target communication protocol, respectively.

[0110] In some embodiments, the second determination module 603 is further configured to, when the target security level is the first level, determine the target parameter set as the first parameter set; when the target security level is the second level, determine the target parameter set as the second parameter set; when the target security level is the third level, determine the target parameter set as the third parameter set; when the target security level is the fourth level, determine the target parameter set as the zero parameter set.

[0111] In some embodiments, the enhancement module 604 is further configured to classify the target communication protocol as including a target communication protocol with an encryption algorithm and a target communication protocol without an encryption algorithm; when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; when the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced with the target quantum-resistant cryptographic algorithm using the target parameter set.

[0112] In some embodiments, the first determination module 602 is further configured to determine the computing power level, communication protocol and category of the first device; and determine the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.

[0113] In some embodiments, the first determination module 602 is further configured to send the initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device.

[0114] In some embodiments, the first determination module 602 is further configured to encapsulate the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and category of the first device into the first field, second field, and third field of the initial message of the first device, respectively, to obtain the initial message of the first device; and send the initial message of the first device to the second device.

[0115] In some embodiments, the first determination module 602 is further configured to perform a computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, the computing power level of the first device is determined to be a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, the computing power level of the first device is determined to be a computing power-limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, the computing power level of the first device is determined to be a conventional device; when the evaluation value is greater than the third threshold, the computing power level of the first device is determined to be a strong computing power device.

[0116] In some embodiments, the first determination module 602 is further configured to determine that the security level of the first device is the fourth level when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; determine that the security level of the first device is the third level when the computing power level of the first device is a computing power-limited device; determine that the security level of the first device is the second level when the computing power level of the first device is a conventional device; and determine that the security level of the first device is the first level when the computing power level of the first device is a strong computing power device.

[0117] In some embodiments, the second determination module 603 is further configured to determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the type of the target communication protocol, the target security level, and the data types of the first device and the second device.

[0118] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods, or program products. Therefore, various aspects of the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as "circuits," "modules," or "systems."

[0119] Refer to the following Figure 7 700 according to this embodiment of the present disclosure will be described. Figure 7 The electronic device 700 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0120] like Figure 7 As shown, electronic device 700 is implemented as a general-purpose computing device. Components of electronic device 700 may include, but are not limited to, the aforementioned at least one processing unit 710, the aforementioned at least one storage unit 720, and a bus 730 connecting various system components (including storage unit 720 and processing unit 710).

[0121] The storage unit stores a program code, and the program code can be executed by the processing unit 710, so that the processing unit 710 performs the steps described in the "Exemplary Method" section of this specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 710 can perform the following steps of the above-mentioned method embodiment: receiving initial information from the second device, wherein the initial information of the second device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the second device; based on the computing power levels of the first device and the second device, determining the target security level, target quantum-resistant cryptographic algorithm and target communication protocol from the security level, quantum-resistant cryptographic algorithm and communication protocol of the first device and the second device respectively; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; according to the category of the target communication protocol, performing protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set; and communicating with the second device according to the target communication protocol after protocol enhancement.

[0122] The storage unit 720 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 7201 and / or a cache memory unit 7202 , and may further include a read-only memory unit (ROM) 7203 .

[0123] The storage unit 720 may also include a program / utility 7204 having a set (at least one) of program modules 7205, such program modules 7205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0124] Bus 730 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0125] The electronic device 700 can also communicate with one or more external devices 740 (e.g., a keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with the electronic device 700, and / or any device that enables the electronic device 700 to communicate with one or more other computing devices (e.g., a router, modem, etc.). This communication can occur via an input / output (I / O) interface 750. Furthermore, the electronic device 700 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 760. As shown, the network adapter 760 communicates with other modules of the electronic device 700 via a bus 730. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 700, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0126] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, terminal device, or network device) to execute the methods according to the embodiments of the present disclosure.

[0127] In the disclosed exemplary embodiments, a computer-readable storage medium is also provided. The computer-readable storage medium may be a readable signal medium or a readable storage medium.

[0128] In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of various exemplary implementations of the present disclosure described in the above "Specific Implementation Methods" section of this specification.

[0129] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0130] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0131] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0132] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and conventional procedural programming languages ​​such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0133] The present disclosure provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the device communication method provided in any of the various optional embodiments of the present disclosure.

[0134] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0135] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0136] Through the description of the above embodiments, it will be readily understood by those skilled in the art that the example embodiments described herein can be implemented via software or via a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, or mobile hard drive) or on a network and includes several instructions for enabling a computing device (such as a personal computer, server, mobile terminal, or network device) to execute the methods according to the embodiments of the present disclosure.

[0137] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope of the present disclosure being indicated by the appended claims.

Claims

1. A device communication method, applied to a first device, characterized in that: include: Receiving initial information from a second device, wherein the initial information of the second device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a type of the second device; Based on the computing power levels of the first device and the second device, determining a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively; Determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; According to the category of the target communication protocol, performing protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set; Communicate with the second device according to the enhanced target communication protocol.

2. The method according to claim 1, characterized in that The receiving initial information from the second device includes: receiving an initial message from the second device; After receiving the initial message from the second device, the method further includes: parsing the initial message of the second device, and determining the computing power level, security level and quantum-resistant cryptographic algorithm, communication protocol and category of the second device from the first field, second field and third field of the initial message of the second device respectively.

3. The method according to claim 1, characterized in that The determining, based on the computing power levels of the first device and the second device, a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively, includes: The device with the lower computing power level between the first device and the second device is selected as the target device; The security level, quantum-resistant cryptographic algorithm, and communication protocol of the target device are respectively used as the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol.

4. The method according to claim 1, wherein Determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level includes: When the target security level is the first level, determining the target parameter set to be the first parameter set; When the target security level is the second level, determining the target parameter set to be the second parameter set; When the target security level is the third level, determining the target parameter set to be the third parameter set; When the target security level is the fourth level, the target parameter set is determined to be a zero parameter set.

5. The method according to claim 1, wherein The performing protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol includes: The category of the target communication protocol includes the target communication protocol having an encryption algorithm and the target communication protocol having no encryption algorithm; When the target communication protocol does not have an encryption algorithm, adding a target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol; When the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced by a target quantum-resistant cryptographic algorithm using the target parameter set.

6. The method according to claim 1, characterized in that Before determining the target security level, target quantum-resistant cryptographic algorithm, and target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first and second devices, respectively, based on the computing power levels of the first and second devices, the method further includes: Determining the computing power level, communication protocol, and type of the first device; The security level and quantum-resistant cryptographic algorithm of the first device are determined based on the computing power level of the first device.

7. The method according to claim 6, characterized in that After determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device, the method further includes: Sending initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol and its category of the first device.

8. The method according to claim 7, characterized in that The sending the initial information of the first device to the second device includes: Encapsulating the computing power level, security level, quantum-resistant cryptographic algorithm, communication protocol, and type of the first device into the first field, second field, and third field of the initial message of the first device, respectively, to obtain an initial message of the first device; Sending the initial message of the first device to the second device.

9. The method according to claim 6, characterized in that Determining the computing power level of the first device includes: Performing a computing power evaluation on the first device to obtain an evaluation value; When the evaluation value is less than or equal to a first threshold, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; When the evaluation value is greater than the first threshold but less than or equal to a second threshold, determining that the computing power level of the first device is a computing power-limited device; When the evaluation value is greater than the second threshold but less than or equal to a third threshold, determining that the computing power level of the first device is a conventional device; When the evaluation value is greater than the third threshold, it is determined that the computing power level of the first device is a high computing power device.

10. The method according to claim 6, characterized in that The determining a security level of the first device based on the computing power level of the first device includes: When the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining that the security level of the first device is level 4; When the computing power level of the first device is a computing power-limited device, determining that the security level of the first device is level 3; When the computing power level of the first device is a conventional device, determining that the security level of the first device is a second level; When the computing power level of the first device is a strong computing power device, the security level of the first device is determined to be the first level.

11. A device communication apparatus, applied to a first device, characterized in that: include: a receiving module configured to receive initial information from a second device, wherein the initial information of the second device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a type thereof of the second device; a first determining module configured to determine, based on the computing power levels of the first device and the second device, a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security levels, quantum-resistant cryptographic algorithms, and communication protocols of the first device and the second device, respectively; A second determination module is configured to determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; an enhancement module, configured to perform protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; The communication module is configured to communicate with the second device according to the target communication protocol after protocol enhancement.

12. An electronic device, characterized in that: include: processor; as well as a memory for storing executable instructions of the processor; The processor is configured to perform the method according to any one of claims 1 to 10 by executing the executable instructions.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

14. A computer program product, comprising computer instructions, wherein the computer instructions are stored in a computer-readable storage medium, and when the computer instructions are executed by a processor, the computer program product implements the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • A post-quantum key negotiation system and method based on IKE protocol

    CN119788442A

  • Numerical control equipment cooperative scheduling method and system based on heterogeneous computing architecture

    CN120215411A

  • Internet of Things test platform adaptation method, system and device based on post quantum cryptography

    CN120342587A

  • Systems and methods for measuring one or more metrics of a cryptographic algorithm in a post-quantum cryptography system

    US12200116B1

  • Quantum-attack resistant operating system for use in a key management mechanism

    US20210312047A1

Cited By

  • Vehicle and cloud communication method, electronic equipment and vehicle

    CN121547272A