Device communication method, apparatus and related device
By dynamically determining the target security level and communication protocol, and using quantum-resistant cryptographic algorithms to enhance the communication of industrial equipment, the problem of equipment computing power limitations is solved, and efficient and secure communication in a quantum computing environment is achieved.
Patent Information
- Application Number
- CN202511061820.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-07-30
AI Technical Summary
Existing industrial equipment is limited by computing power and cannot be adapted to quantum-resistant cryptographic algorithms, resulting in insufficient communication security, especially when facing the threat of quantum computing.
By receiving and parsing the device's computing power level, security level, and quantum-resistant cryptographic algorithm information, the target security level and communication protocol are dynamically determined. The communication protocol is then enhanced using the target quantum-resistant cryptographic algorithm and parameter set to ensure communication security.
It improves the communication security and adaptability of industrial equipment in a quantum computing environment, enhances the compatibility between different devices and the reliability of data transmission, and ensures effective and secure communication even in resource-constrained environments.
Smart Images

Figure CN120567397B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular, to a device communication method, device and related device. BACKGROUND
[0002] With the development of quantum technology, the security of traditional communication has been greatly threatened, especially the industrial communication with higher openness. In order to cope with the challenge of quantum technology, anti-quantum cryptographic algorithms need to be adopted or increased for communication encryption, but for industrial devices, because the computing power of industrial devices is limited, and different anti-quantum cryptographic algorithms require different computing power, how to reasonably adapt anti-quantum cryptographic algorithms for industrial devices is a hot research topic at present. SUMMARY
[0003] The present disclosure provides a device communication method, device and related device, which at least improves the security guarantee of device communication to a certain extent.
[0004] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.
[0005] According to one aspect of the present disclosure, a device communication method is provided, applied to a first device, comprising: receiving initial information from a second device, wherein the initial information of the second device comprises the computing power level, security level, anti-quantum cryptographic algorithm, communication protocol and its category of the second device; determining the target security level, target anti-quantum cryptographic algorithm and target communication protocol from the security level, anti-quantum cryptographic algorithm and communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device; determining the target parameter set used by the target anti-quantum cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol by using the target anti-quantum cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicating with the second device according to the target communication protocol after protocol enhancement.
[0006] In one embodiment of the present disclosure, receiving initial information from a second device comprises: receiving an initial message from a second device; after receiving the initial message from the second device, the method further comprises: parsing the initial message of the second device, and determining the computing power level, security level and anti-quantum cryptographic algorithm, communication protocol and its category of the second device from the first field, second field and third field of the initial message of the second device respectively.
[0007] In one embodiment of the present disclosure, based on the computing power levels of the first device and the second device, the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol are determined from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively, comprising: taking the device with lower computing power level as the target device among the first device and the second device; and taking the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the target device as the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol respectively.
[0008] In one embodiment of the present disclosure, the target parameter set used by the target quantum-resistant cryptographic algorithm is determined based on the target security level, comprising: when the target security level is the first level, determining the target parameter set as the first parameter set; when the target security level is the second level, determining the target parameter set as the second parameter set; when the target security level is the third level, determining the target parameter set as the third parameter set; and when the target security level is the fourth level, determining the target parameter set as the zero parameter set.
[0009] In one embodiment of the present disclosure, the target communication protocol is protocol enhanced by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol, comprising: the category of the target communication protocol includes the target communication protocol with encryption algorithm and the target communication protocol without encryption algorithm; when the target communication protocol is without encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; and when the target communication protocol is with encryption algorithm, the encryption algorithm in the target communication protocol is replaced by the target quantum-resistant cryptographic algorithm using the target parameter set.
[0010] In one embodiment of the present disclosure, before the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol are determined from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device based on the computing power levels of the first device and the second device, the method further comprises: determining the computing power level, the communication protocol and its category of the first device; and determining the security level and the quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.
[0011] In one embodiment of the present disclosure, after the security level and the quantum-resistant cryptographic algorithm of the first device are determined based on the computing power level of the first device, the method further comprises: sending the initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and its category of the first device.
[0012] In one embodiment of the present disclosure, the initial information of the first device is sent to the second device, comprising: encapsulating the computing power level, the security level and the quantum-resistant cryptographic algorithm of the first device into the first field, the second field and the third field of the initial message of the first device respectively, to obtain the initial message of the first device; and sending the initial message of the first device to the second device.
[0013] In one embodiment of the present disclosure, the computing power level of the first device is determined, comprising: performing computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, determining that the computing power level of the first device is a computing power limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, determining that the computing power level of the first device is a regular device; and when the evaluation value is greater than the third threshold, determining that the computing power level of the first device is a strong computing power device.
[0014] In one embodiment of the present disclosure, the security level of the first device is determined based on the computing power level of the first device, comprising: when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining that the security level of the first device is a fourth level; when the computing power level of the first device is a computing power limited device, determining that the security level of the first device is a third level; when the computing power level of the first device is a regular device, determining that the security level of the first device is a second level; and when the computing power level of the first device is a strong computing power device, determining that the security level of the first device is a first level.
[0015] According to another aspect of the present disclosure, a device communication apparatus is provided, applied to a first device, comprising: a receiving module configured to receive initial information from a second device, wherein the initial information of the second device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category thereof of the second device; a first determining module configured to determine a target security level, a target quantum-resistant cryptographic algorithm and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device; a second determining module configured to determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; an enhancing module configured to perform protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and a communication module configured to communicate with the second device according to the protocol enhanced target communication protocol.
[0016] According to still another aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform any of the above methods by executing the executable instructions.
[0017] According to yet another aspect of the present disclosure, a computer readable storage medium is provided, having stored thereon a computer program, which, when executed by a processor, implements any of the above methods.
[0018] According to yet another aspect of the present disclosure, a computer program product is provided, comprising computer instructions stored in a computer readable storage medium, which, when executed by a processor, implement the operational instructions of any of the above methods.
[0019] In the embodiments of the present disclosure, the target parameter set used by the target quantum-resistant cryptographic algorithm is determined based on the target security level, and the target communication protocol is enhanced by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol, thereby solving the problem that industrial equipment is difficult to adapt to quantum-resistant cryptographic algorithms due to the limitation of computing power in the prior art, and further enhancing the security of industrial equipment communication.
[0020] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0022] Figure 1 A schematic diagram of a device communication system in an embodiment of the present disclosure is shown.
[0023] Figure 2 A flowchart of a device communication method in an embodiment of the present disclosure is shown.
[0024] Figure 3 A flowchart of a device computing power level division method in an embodiment of the present disclosure is shown.
[0025] Figure 4 A flowchart of a device security level division method in an embodiment of the present disclosure is shown.
[0026] Figure 5 A structural schematic diagram of a quantum security component in an embodiment of the present disclosure is shown.
[0027] Figure 6 A schematic diagram of a device communication apparatus in an embodiment of the present disclosure is shown.
[0028] Figure 7A schematic diagram of an electronic device provided in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0029] Example implementations are now described with reference to the following drawings. Example implementations can, however, be implemented in many different forms and should not be construed as limited to the examples set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of example implementations to those skilled in the art. The described features, structures, or characteristics can be combined in one or more implementations.
[0030] In addition, the drawings are merely schematic and are not drawn to scale. Identical or similar components are denoted by the same reference numerals throughout the drawings, and a repeated description thereof will be omitted. Some of the block diagrams in the drawings are functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0031] It should be understood that each step recited in the method implementations of the present disclosure can be executed in different orders, and / or in parallel. In addition, the method implementations can include additional steps and / or omit the execution of the steps shown. The scope of the present disclosure is not limited in this respect.
[0032] It should be noted that the concepts of "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0033] It should be noted that the modification of "one" or "multiple" mentioned in the present disclosure is illustrative and not limiting, and those skilled in the art should understand that, unless otherwise explicitly indicated in the context, it should be understood as "one or more".
[0034] It should be noted that the embodiments of the present disclosure and the technical features in the embodiments can be combined with each other without conflict.
[0035] For ease of understanding, the following first explains several terms related to the present disclosure as follows:
[0036] Industrial communication refers to a communication technology used for data transmission and control between devices and systems in an industrial environment, with characteristics of high reliability, real-time and security, and is the cornerstone of industrial automation and intelligent manufacturing. Its core function is to realize efficient interconnection of sensors, controllers, actuators and other devices, support real-time monitoring, automation control and data-driven decision-making.
[0037] Post Quantum Cryptography (PQC), also known as "quantum-resistant cryptography", is a new generation of cryptographic algorithms that resist attacks by quantum computers on existing cryptographic algorithms. It is a key technology for maintaining network security in the quantum information era and an important part of countering the threat of quantum computers.
[0038] PROFIBUS (Process Field Bus) is another widely used fieldbus standard, suitable for factory automation and process automation. The protocol has no encryption algorithm.
[0039] OPC-UA (OPC Unified Architecture) is a cross-platform service-oriented architecture designed to provide secure and reliable industrial automation data exchange. It is a major upgrade to the traditional OPC standard, addressing issues such as interoperability and security. The protocol has an encryption algorithm.
[0040] CRYSTALS-KYBER (Key Encapsulation Mechanism, KEM) is a quantum-resistant cryptographic algorithm. It is based on the Module-Learning With Errors (MLWE) problem, which is considered to be difficult to solve in the quantum computing era. KYBER was proposed as part of the NIST post-quantum cryptography standard and has attracted attention for its performance and security.
[0041] CRYSTALS-Dilithium is a lattice-based cryptography quantum-resistant cryptographic algorithm designed to provide protection against quantum computing attacks. It was developed as part of the National Institute of Standards and Technology (NIST) post-quantum cryptography standardization process and was selected as one of the final candidates in the third round. Dilithium was developed by a group of well-known researchers to provide an efficient and secure post-quantum digital signature scheme.
[0042] The specific implementation of the embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings.
[0043] Figure 1 shows a schematic diagram of a device communication system in an embodiment of the present disclosure,
[0044] The first device 101 and the second device 102 can be industrial devices such as intelligent sensors, intelligent electricity meters, industrial gateways, edge computing devices, and industrial robots, or the first device 101 and the second device 102 can also be mobile devices such as mobile phones, game consoles, tablet computers, e-book readers, smart glasses, MP4 (Moving Picture Experts Group Audio Layer IV) players, smart home devices, AR (Augmented Reality) devices, VR (Virtual Reality) devices, and the like.
[0045] The first device 101 can be installed with an application program to perform the following: receiving initial information from the second device, wherein the initial information of the second device includes the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the second device; determining the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the first device and the second device based on the computing power level of the first device and the second device; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and performing communication with the second device according to the target communication protocol after the protocol enhancement.
[0046] The second device 102 can be installed with an application program to perform the following: receiving initial information from the first device, wherein the initial information of the first device includes the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the first device; determining the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the second device and the first device based on the computing power level of the second device and the first device; determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and performing communication with the first device according to the target communication protocol after the protocol enhancement.
[0047] The first device 101 and the second device 102 are connected through a communication network. Optionally, the communication network is a wired network or a wireless network.
[0048] Optionally, the wireless or wired networks described above use standard communications technologies and / or protocols. The networks typically carry Internet traffic, but can also include, for example, a local area network (LAN), metropolitan area network (MAN), wide area network (WAN), wireless area network, wired or wireless network, private network, or a virtual private network (VPN), any combination thereof, etc. In some embodiments, data exchanged over the one or more networks is represented using technologies and / or formats including, but not limited to, Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc. In addition, all or some links can be encrypted using conventional encryption technologies, such as, for example, Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec), etc. In other embodiments, custom and / or proprietary data communications technologies and / or formats can be employed.
[0049] Figure 2 A flowchart of a method for device communication is shown in the embodiments of the present disclosure, which is applied to a first device, such as a device shown in FIG. 1, and includes the following steps: Figure 2 As shown, the method includes the following steps:
[0050] S201, receiving initial information from a second device, wherein the initial information of the second device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a category thereof of the second device.
[0051] The second device is another device for communication with the first device. The computing power level is an index for measuring the computing power of a device, which affects the ability of the device to execute complex algorithms. The security level represents the strength level of the device in protecting data and communication security. The quantum-resistant cryptographic algorithm is a PQC algorithm. The communication protocol specifies a set of rules for how different devices exchange information, including its category such as a transport layer protocol, an application layer protocol, etc. According to the standard of whether there is an encryption algorithm, the category of the target communication protocol can be divided into target communication protocol with encryption algorithm and target communication protocol without encryption algorithm.
[0052] In one embodiment of the present disclosure, receiving initial information from the second device includes: receiving an initial message from the second device; and after receiving the initial message from the second device, parsing the initial message of the second device to determine the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the second device from the first field, the second field, and the third field of the initial message of the second device, respectively.
[0053] In this embodiment, after receiving the initial message sent by the second device, the initial message of the second device is parsed. Because the first field, the second field, and the third field of the initial message of the second device encapsulate the computing power level, the security level, and the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the second device, respectively, the computing power level, the security level, and the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the second device can be obtained by parsing the initial message of the second device. By means of the above technical means, the key information is obtained by parsing the fields in the initial message, which ensures that the secure communication configuration between devices can be dynamically adjusted based on the actual capabilities and needs of both parties, thereby enhancing the adaptability and security of the entire system. In addition, the above technical means also improve the possibility of optimizing the encryption scheme for a specific hardware environment, further enhancing the security protection level of data transmission.
[0054] In some embodiments of the present disclosure, receiving initial information from the second device includes: receiving an initial message from the second device; and after receiving the initial message from the second device, parsing the initial message of the second device according to a preset message rule to determine the computing power level, the security level, and the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the communication protocol of the second device.
[0055] S202, based on the computing power level of the first device and the second device, determining the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the first device and the second device, respectively.
[0056] Based on the computing power level of the first device and the computing power level of the second device, the target security level is determined from the security level of the first device and the security level of the second device, the target quantum-resistant cryptographic algorithm is determined from the quantum-resistant cryptographic algorithm of the first device and the quantum-resistant cryptographic algorithm of the second device, and the target communication protocol is determined from the communication protocol of the first device and the communication protocol of the second device.
[0057] In one embodiment of the present disclosure, based on the computing power levels of the first device and the second device, the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol are determined from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the first device and the second device, respectively, comprising: taking the device with a lower computing power level as the target device among the first device and the second device; and taking the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the target device as the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol, respectively.
[0058] The computing power levels of the first device and the second device are compared, and the device with a lower computing power level is identified as the target device. Then, the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the target device are used to determine the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol used when communicating. This technical means directly considers the difference in computing power between devices, selects a security configuration and technical parameters suitable for a low-computing-power device, improves the compatibility and adaptability of the overall system, and enhances the ability of secure communication between different devices. Through this technical means, not only the support capability of the system for diversified hardware environments is improved, but also the security and reliability in the data transmission process are guaranteed.
[0059] For example, in an intelligent transportation system, assume that a roadside unit (as the first device) and a vehicle-mounted unit (as the second device) need to communicate securely. If the computing power level of the vehicle-mounted unit is lower than that of the roadside unit, the vehicle-mounted unit is regarded as the target device, and the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol used when communicating are set according to the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the vehicle-mounted unit. In this way, even if the vehicle-mounted unit cannot support high-complexity encryption algorithms due to hardware limitations, efficient and secure data exchange can still be achieved, enhancing the security of the intelligent transportation system and improving the safety level of road users.
[0060] In one embodiment of the present disclosure, before determining the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the first device and the second device based on the computing power levels of the first device and the second device, the method further comprises: determining the computing power level, the communication protocol, and the category of the first device; and determining the security level and the quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.
[0061] The currently used communication protocol of the first device is determined, and the category of the target communication protocol is divided into target communication protocol with encryption algorithm or target communication protocol without encryption algorithm according to the standard of whether there is an encryption algorithm.
[0062] In one embodiment of the present disclosure, determining the computing power level of the first device includes: performing a computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold but less than or equal to a second threshold, determining that the computing power level of the first device is a computing power limited device; when the evaluation value is greater than the second threshold but less than or equal to a third threshold, determining that the computing power level of the first device is a regular device; and when the evaluation value is greater than the third threshold, determining that the computing power level of the first device is a strong computing power device.
[0063] A comprehensive consideration of the computing power of the first device is made to reflect its ability to execute complex algorithms in the form of quantitative indicators. The first device's score (similar to a mobile phone or computer processor score) or the chip evaluation result of the first device can be directly used as the evaluation value of the first device.
[0064] When the evaluation value is less than or equal to the first threshold, it indicates that the computing resources of the first device are extremely limited and cannot meet the basic requirements of running quantum-resistant cryptographic algorithms, so the first device is classified as a device that does not support any quantum-resistant cryptographic algorithm. When the evaluation value is greater than the first threshold but less than or equal to the second threshold, it means that the first device has certain computing power, but is not sufficient to efficiently run complex quantum-resistant cryptographic algorithms, so the first device is classified as a computing power limited device. When the evaluation value is greater than the second threshold but less than or equal to the third threshold, it indicates that the first device has sufficient computing resources to support general quantum-resistant cryptographic algorithm operations, so the first device is classified as a regular device. When the evaluation value is greater than the third threshold, it means that the first device has strong computing power and can efficiently handle complex encryption tasks, so the first device is classified as a strong computing power device. Through the above technical means, the goal of dynamically adjusting security strategies according to the actual computing power of the device is achieved, ensuring effective secure communication even in resource-limited environments.
[0065] For example, in a cloud computing environment, there are multiple types of servers (as the first device), from old models to the latest high-performance models. By evaluating the computing power of these servers and classifying them as devices that do not support any quantum-resistant cryptographic algorithm, computing power limited devices, regular devices, or strong computing power devices according to the evaluation results, cloud service providers can assign appropriate tasks and security measures based on the characteristics of different types of servers. For example, for computing power limited devices, lightweight quantum-resistant cryptographic algorithms can be selected; while for strong computing power devices, more advanced encryption schemes can be deployed to enhance the security and stability of the entire cloud environment.
[0066] In an embodiment of the present disclosure, determining the security level of the first device based on the computing power level of the first device comprises: when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining the security level of the first device as the fourth level; when the computing power level of the first device is a computing power limited device, determining the security level of the first device as the third level; when the computing power level of the first device is a regular device, determining the security level of the first device as the second level; and when the computing power level of the first device is a strong computing power device, determining the security level of the first device as the first level.
[0067] The device with the fourth level of security does not use any quantum-resistant cryptographic algorithm. The computing power levels from low to high are a device that does not support any quantum-resistant cryptographic algorithm, a computing power limited device, a regular device, and a strong computing power device. The security levels from low to high are the fourth level, the third level, the second level, and the first level. The device that does not support any quantum-resistant cryptographic algorithm, the computing power limited device, the regular device, and the strong computing power device correspond to the fourth level, the third level, the second level, and the first level, respectively. Through the above technical means, the goal of dynamically adjusting the security level of the device according to the actual computing power of the device is achieved, ensuring effective secure communication even in a resource-limited environment, so that devices of different performance levels can find a suitable security configuration scheme, thereby enhancing the security and stability of the entire network environment.
[0068] For example, in an Internet of Things application scenario, assume that there are multiple types of sensors (as the first device), from low-power, limited-computing-power simple sensors to high-performance, strong-computing-power intelligent sensors. By evaluating the computing power of these sensors and setting their security levels as the fourth level, the third level, the second level, or the first level according to their computing power levels, appropriate tasks and security measures can be assigned to different types of sensors according to their characteristics. For example, for sensors with extremely limited computing power, only basic data protection measures can be selected; and for intelligent sensors with strong computing power, high-level encryption and authentication mechanisms can be deployed to enhance the security and reliability of the entire Internet of Things.
[0069] In an embodiment of the present disclosure, after determining the security level and quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device, the method further comprises: sending initial information of the first device to a second device, wherein the initial information of the first device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol, and the category of the first device.
[0070] In one embodiment of the present disclosure, sending initial information of the first device to the second device comprises: encapsulating the computing power level, the security level, and the anti-quantum cryptographic algorithm, the communication protocol and the category thereof of the first device into a first field, a second field and a third field of an initial message of the first device respectively to obtain an initial message of the first device; and sending the initial message of the first device to the second device.
[0071] In some embodiments of the present disclosure, sending initial information of the first device to the second device comprises: assembling the computing power level, the security level, and the anti-quantum cryptographic algorithm, the communication protocol and the category thereof of the first device to obtain an initial message of the first device; and sending the initial message of the first device to the second device.
[0072] S203, determining a target parameter set used by the target anti-quantum cryptographic algorithm based on the target security level.
[0073] The target parameter set is a set of optimal parameters selected for the anti-quantum cryptographic algorithm to ensure optimal performance at a given security level. Given the limited computing resources of many current industrial devices, these systems face significant challenges when integrating and running anti-quantum cryptographic algorithms. Anti-quantum cryptographic algorithms generally have high requirements for computing power and memory, while the hardware configuration of existing industrial devices often fails to meet the needs of such advanced encryption technologies, thereby limiting their application potential in resisting future quantum computing threats. Embodiments of the present disclosure determine the target security level based on the computing power level, and determine the target parameter set used by the target anti-quantum cryptographic algorithm based on the target security level, thereby adapting appropriate encryption algorithms for the first device and the second device.
[0074] In one embodiment of the present disclosure, determining a target parameter set used by the target anti-quantum cryptographic algorithm based on the target security level comprises: when the target security level is a first level, determining the target parameter set as a first parameter set; when the target security level is a second level, determining the target parameter set as a second parameter set; when the target security level is a third level, determining the target parameter set as a third parameter set; and when the target security level is a fourth level, determining the target parameter set as a zero parameter set.
[0075] The sizes of the first parameter set, the second parameter set, the third parameter set and the zero parameter set decrease in turn, and the zero parameter set is actually not using the target anti-quantum cryptographic algorithm. Through the above technical means, multiple parameter sets are set to achieve the purpose of dynamically adjusting the anti-quantum cryptographic algorithm parameter set according to the actual security requirements and computing power of the device, thereby ensuring effective secure communication even in a resource-limited environment.
[0076] For example, CRYSTALS-KYBER provides different parameter sets to accommodate different security requirements and application scenarios, each of which defines different public key sizes, ciphertext sizes, and key generation, encryption, and decryption speeds, etc. Kyber512 (third parameter set): provides about 128-bit classical security strength, suitable for most applications. Kyber768 (second parameter set): provides higher security strength, approximately equivalent to 192-bit classical security strength. Kyber1024 (first parameter set): provides the highest security level, about 256-bit classical security strength.
[0077] S204, according to the category of the target communication protocol, using the target quantum-resistant cryptographic algorithm and the target parameter set to perform protocol enhancement on the target communication protocol;
[0078] In an embodiment of the present disclosure, according to the category of the target communication protocol, using the target quantum-resistant cryptographic algorithm and the target parameter set to perform protocol enhancement on the target communication protocol, including: the category of the target communication protocol includes the target communication protocol with encryption algorithm and the target communication protocol without encryption algorithm; when the target communication protocol has no encryption algorithm, the target quantum-resistant cryptographic algorithm using the target parameter set is added to the target communication protocol; when the target communication protocol has an encryption algorithm, the encryption algorithm in the target communication protocol is replaced by the target quantum-resistant cryptographic algorithm using the target parameter set.
[0079] For communication protocols that originally have no encryption algorithm, a layer of security protection is added by introducing the selected target quantum-resistant cryptographic algorithm and its corresponding parameter set. Through this technical means, the security of data transmission is enhanced, ensuring that effective security protection can be achieved even in communication protocols that originally lack encryption measures. For communication protocols that originally have encryption algorithms, the original encryption algorithm will be replaced by a quantum-resistant cryptographic algorithm that is more suitable for the current device computing power level and security requirements. This replacement not only improves the security of the communication protocol, but also ensures that it can resist future quantum computing attack threats, improving the overall system security and forward-looking. Through the above technical means, the purpose of dynamically adjusting the encryption strategy according to the specific circumstances of different target communication protocols is achieved, ensuring that whether the original communication protocol has encryption function or not, the security can be further enhanced on the existing basis.
[0080] For example, in an intelligent city application scenario, there are multiple types of intelligent traffic lights (as second devices) communicating with a central control system (as a first device). Assume that some old models of traffic lights use a traditional communication protocol without encryption algorithm, while new models may have integrated a certain level of encryption algorithm. For those old model traffic lights without encryption algorithm, a target quantum-resistant cryptographic algorithm based on a target parameter set can be added to their communication protocol to enhance its security; while for new model devices that already have some form of encryption algorithm, a more advanced target quantum-resistant cryptographic algorithm that is more suitable for current security needs can be used to replace the original encryption algorithm, ensuring that all data exchanges between devices are fully secured, and improving the overall security and reliability of the intelligent city traffic management system.
[0081] In some embodiments of the present disclosure, according to the category of the target communication protocol, the target communication protocol is enhanced using the target quantum-resistant cryptographic algorithm and the target parameter set, including: when the target communication protocol has no encryption algorithm, adding the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol, and using the target quantum-resistant cryptographic algorithm using the target parameter set for encryption and decryption in communication; when the target communication protocol has an encryption algorithm, adding the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol, and using the target quantum-resistant cryptographic algorithm using the target parameter set and the encryption algorithm in the target communication protocol for encryption and decryption in communication.
[0082] Using the encryption algorithm in the target communication protocol for encryption first can obtain a first encryption result. Then the target quantum-resistant cryptographic algorithm using the target parameter set is used to encrypt the first encryption result to obtain a second encryption result.
[0083] S205, communicate with the second device according to the target communication protocol after protocol enhancement.
[0084] The target quantum-resistant cryptographic algorithm using the target parameter set can be used for encryption and decryption in communication, and other communication standards follow the original provisions of the target communication protocol. Through the above technical means, the problem that industrial devices are difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations in the prior art is solved, and the security of industrial device communication is further enhanced.
[0085] In some embodiments, the second device: determines the computing power level, communication protocol and its category of the second device; determines the security level and quantum-resistant cryptographic algorithm of the second device based on the computing power level of the second device.
[0086] Figure 3A flowchart of a device computing power level classification method in an embodiment of the present disclosure is shown, which is applied to a second device, as shown in Figure 3 includes the following steps:
[0087] S301, performing computing power evaluation on the second device to obtain an evaluation value;
[0088] S302, when the evaluation value is less than or equal to a first threshold value, determining that the computing power level of the second device is a device that does not support any quantum-resistant cryptographic algorithm;
[0089] S303, when the evaluation value is greater than the first threshold value but less than or equal to a second threshold value, determining that the computing power level of the second device is a computing power limited device;
[0090] S304, when the evaluation value is greater than the second threshold value but less than or equal to a third threshold value, determining that the computing power level of the second device is a regular device;
[0091] S305, when the evaluation value is greater than the third threshold value, determining that the computing power level of the second device is a strong computing power device.
[0092] The first threshold value, the second threshold value and the third threshold value increase in turn. Through the above technical means, the goal of dynamically adjusting the security strategy according to the actual computing power of the device is achieved, ensuring that effective security communication can be achieved even in a resource-limited environment.
[0093] The computing power level and the security level each have multiple levels, and each computing power level has a corresponding security level.
[0094] In some embodiments, the second device can also be classified in more detail according to the evaluation value: when the evaluation value is less than or equal to a fourth threshold value, the computing power level of the second device is determined to be a first computing power level device; when the evaluation value is greater than the fourth threshold value but less than or equal to a fifth threshold value, the computing power level of the second device is determined to be a second computing power level device; when the evaluation value is greater than the fifth threshold value but less than or equal to a sixth threshold value, the computing power level of the second device is determined to be a third computing power level device; when the evaluation value is greater than the sixth threshold value but less than or equal to a seventh threshold value, the computing power level of the second device is determined to be a fourth computing power level device; and when the evaluation value is greater than the seventh threshold value, the computing power level of the second device is determined to be a fifth computing power level device.
[0095] Figure 4 A flowchart of a device security level classification method in an embodiment of the present disclosure is shown, which is applied to a second device, as shown in Figure 4 includes the following steps:
[0096] S401, when the computing power level of the second device is a device that does not support any quantum-resistant cryptographic algorithm, determining that the security level of the second device is the fourth level;
[0097] S402, when the computing power level of the second device is a computing power limited device, determining that the security level of the second device is a third level;
[0098] S403, when the computing power level of the second device is a regular device, determining that the security level of the second device is a second level;
[0099] S404, when the computing power level of the second device is a strong computing power device, determining that the security level of the second device is a first level.
[0100] Through the above technical means, the target of dynamically adjusting the security level according to the actual computing power of the device is realized, which ensures that effective security communication can be realized even in a resource limited environment, so that devices of different performance levels can find a suitable security configuration scheme, thereby enhancing the security and stability of the entire network environment.
[0101] In some embodiments, when the computing power level of the second device is a first computing power level device, the security level of the second device is determined to be a fourth level; when the computing power level of the second device is a second computing power level device, the security level of the second device is determined to be a third level; when the computing power level of the second device is a third computing power level device or a fourth computing power level device, the security level of the second device is determined to be a second level; when the computing power level of the second device is a fifth computing power level device, the security level of the second device is determined to be a first level.
[0102] In some embodiments, the target parameter set used by the target quantum-resistant cryptographic algorithm is determined based on the category of the target communication protocol, the target security level, and the data category of the first device and the second device.
[0103] Specifically: determine the scores corresponding to the category of the target communication protocol, the target security level and the data category, and determine the target parameter set used according to the scores corresponding to the category of the target communication protocol, the target security level and the data category. The parameter set used by the target quantum-resistant cryptographic algorithm has multiple sizes, and the target parameter set is one of them.
[0104] For example: for the category of the target communication protocol: the target communication protocol without encryption algorithm is 0 points, and the target communication protocol with encryption algorithm is 50 points; the target security level has four levels, from high to low corresponding to 100 points, 75 points, 50 points and 25 points; the data category of the first device and the second device represents the category of the data interacted by the first device and the second device, and the data category has control instruction related data, device collected data and device itself data, etc., and the control instruction related data, device itself data and device collected data correspond to 50 points, 30 points and 20 points respectively. The total score of the category of the target communication protocol, the target security level and the data category corresponds to three sizes of parameter sets according to the set threshold.
[0105] In some embodiments, a device communication method applied to a second device includes: receiving initial information from a first device, wherein the initial information of the first device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a category of the communication protocol of the first device; determining a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the second device and the first device respectively based on the computing power levels of the second device and the first device; determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicating with the first device according to the target communication protocol after the protocol enhancement.
[0106] The embodiments of the present disclosure receive initial information from a first device, wherein the initial information of the first device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol, and a category of the communication protocol of the first device; determine a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the second device and the first device respectively based on the computing power levels of the second device and the first device; determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; perform protocol enhancement on the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicate with the first device according to the target communication protocol after the protocol enhancement. Through the above technical means, the problem that industrial devices are difficult to adapt to quantum-resistant cryptographic algorithms due to computing power limitations in the prior art is solved, and the security of industrial device communication is enhanced.
[0107] In some embodiments, determining a target security level, a target quantum-resistant cryptographic algorithm, and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the second device and the first device respectively based on the computing power levels of the second device and the first device includes: taking a device with a lower computing power level as a target device from the second device and the first device; and taking the security level, the quantum-resistant cryptographic algorithm, and the communication protocol of the target device as the target security level, the target quantum-resistant cryptographic algorithm, and the target communication protocol respectively.
[0108] The above technical means directly considers the difference in computing power between devices, selects security configurations and technical parameters suitable for low-computing-power devices, improves the compatibility and adaptability of the overall system, and enhances the ability of secure communication between different devices.
[0109] In some embodiments, determining the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level comprises: when the target security level is the second level, determining the target parameter set as the second parameter set; when the target security level is the first level, determining the target parameter set as the first parameter set; when the target security level is the first level, determining the target parameter set as the first parameter set; and when the target security level is the fourth level, determining the target parameter set as the zero parameter set.
[0110] Through the above technical means, multiple parameter sets are set, and the purpose of dynamically adjusting the quantum-resistant cryptographic algorithm parameter set according to the actual security demand and computing power of the device is achieved, thereby ensuring that effective secure communication can be achieved even in a resource-limited environment.
[0111] In some embodiments, performing protocol enhancement on the target communication protocol according to the category of the target communication protocol using the target quantum-resistant cryptographic algorithm and the target parameter set comprises: the category of the target communication protocol comprises that the target communication protocol has an encryption algorithm and the target communication protocol has no encryption algorithm; when the target communication protocol has no encryption algorithm, adding the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol; and when the target communication protocol has an encryption algorithm, replacing the encryption algorithm in the target communication protocol with the target quantum-resistant cryptographic algorithm using the target parameter set.
[0112] Through the above technical means, the purpose of dynamically adjusting the encryption strategy according to the specific circumstances of different target communication protocols is achieved, thereby ensuring that the security can be further enhanced on the basis of the original communication protocol whether it has an encryption function or not.
[0113] Based on the same inventive concept, the disclosure embodiments also provide a device communication device, as follows. Since the principles of the device embodiments solve problems similar to the above-mentioned method embodiments, the implementation of the device embodiments can be referred to the implementation of the above-mentioned method embodiments, and the repeated parts will not be described here.
[0114] Figure 5 A structure schematic diagram of a quantum security component in the embodiments of the disclosure is shown, which is applied to a first device, as shown in the figure, the quantum security component can comprise: Figure 5
[0115] The resource management module is configured to perform computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold value, determine that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold value but less than or equal to a second threshold value, determine that the computing power level of the first device is a computing power limited device; when the evaluation value is greater than the second threshold value but less than or equal to a third threshold value, determine that the computing power level of the first device is a regular device; and when the evaluation value is greater than the third threshold value, determine that the computing power level of the first device is a strong computing power device.
[0116] The quantum security algorithm library is used to support current mainstream anti-quantum cryptographic algorithms at home and abroad and various parameter sets that can be selected by the anti-quantum cryptographic algorithms, and flexible iteration updating can be implemented.
[0117] The algorithm selection module is configured to determine that the security level of the first device is the fourth level when the computing power level of the first device is a device that does not support any anti-quantum cryptographic algorithm, determine that the security level of the first device is the third level when the computing power level of the first device is a computing power limited device, determine that the security level of the first device is the second level when the computing power level of the first device is a regular device, determine that the security level of the first device is the first level when the computing power level of the first device is a strong computing power device, and determine the target security level, the target anti-quantum cryptographic algorithm and the target communication protocol from the security level, the anti-quantum cryptographic algorithm and the communication protocol of the first device and the second device based on the computing power levels of the first device and the second device.
[0118] The protocol enhancement module is configured to perform protocol enhancement on the target communication protocol by using the target anti-quantum cryptographic algorithm and the target parameter set according to the category of the target communication protocol, including: when the target communication protocol has no encryption algorithm, adding the target anti-quantum cryptographic algorithm using the target parameter set to the target communication protocol; and when the target communication protocol has an encryption algorithm, replacing the encryption algorithm in the target communication protocol by using the target anti-quantum cryptographic algorithm using the target parameter set.
[0119] The second device, wherein the initial information of the second device includes the computing power level, the security level, the anti-quantum cryptographic algorithm and the communication protocol and the category of the second device; the target security level, the target anti-quantum cryptographic algorithm and the target communication protocol are determined from the security level, the anti-quantum cryptographic algorithm and the communication protocol of the first device and the second device based on the computing power levels of the first device and the second device; the target parameter set used by the target anti-quantum cryptographic algorithm is determined based on the target security level; the target communication protocol is enhanced by using the target anti-quantum cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and the first device communicates with the second device according to the target communication protocol after the protocol enhancement. Through the above technical means, the problem that industrial devices are difficult to adapt to anti-quantum cryptographic algorithms due to computing power limitations in the prior art is solved, and the security of industrial device communication is further enhanced.
[0120] Figure 6 A schematic diagram of a device communication apparatus in an embodiment of the present disclosure is shown, which is applied to a first device, as shown in the figure, the device communication apparatus can include: Figure 6
[0121] The receiving module 601 is configured to receive initial information from the second device, wherein the initial information of the second device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the communication protocol of the second device.
[0122] The first determining module 602 is configured to determine the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device.
[0123] The second determining module 603 is configured to determine the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level.
[0124] The enhancing module 604 is configured to perform protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol.
[0125] The communication module 605 is configured to communicate with the second device according to the target communication protocol after the protocol enhancement.
[0126] The embodiments of the present disclosure receive initial information from the second device, wherein the initial information of the second device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the communication protocol of the second device; determine the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device; determine the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; perform protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicate with the second device according to the target communication protocol after the protocol enhancement. Through the above technical means, the problem that the industrial device is difficult to adapt to the quantum-resistant cryptographic algorithm due to the computing power limitation in the prior art is solved, and the security of the communication of the industrial device is enhanced.
[0127] In some embodiments, the receiving module 601 is further configured to receive an initial message from the second device; and analyze the initial message of the second device to determine the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the communication protocol of the second device from a first field, a second field and a third field of the initial message of the second device respectively.
[0128] In some embodiments, the first determining module 602 is further configured to take the device with a lower computing power level as the target device from the first device and the second device; and take the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the target device as the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol respectively.
[0129] In some embodiments, the second determining module 603 is further configured to determine the target parameter set as the first parameter set when the target security level is the first level; determine the target parameter set as the second parameter set when the target security level is the second level; determine the target parameter set as the third parameter set when the target security level is the third level; and determine the target parameter set as the zero parameter set when the target security level is the fourth level.
[0130] In some embodiments, the enhancing module 604 is further configured to determine that the category of the target communication protocol includes target communication protocols with encryption algorithms and target communication protocols without encryption algorithms; add the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol when the target communication protocol is without encryption algorithms; and replace the encryption algorithm in the target communication protocol with the target quantum-resistant cryptographic algorithm using the target parameter set when the target communication protocol is with encryption algorithms.
[0131] In some embodiments, the first determining module 602 is further configured to determine the computing power level, the security level, and the quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.
[0132] In some embodiments, the first determining module 602 is further configured to send the initial information of the first device to the second device, wherein the initial information of the first device includes the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol, and the category thereof of the first device.
[0133] In some embodiments, the first determining module 602 is further configured to encapsulate the computing power level, the security level, and the quantum-resistant cryptographic algorithm, the communication protocol, and the category thereof of the first device into a first field, a second field, and a third field of an initial message of the first device, respectively, to obtain the initial message of the first device; and send the initial message of the first device to the second device.
[0134] In some embodiments, the first determining module 602 is further configured to perform computing power evaluation on the first device to obtain an evaluation value; determine that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm when the evaluation value is less than or equal to a first threshold value; determine that the computing power level of the first device is a computing power limited device when the evaluation value is greater than the first threshold value but less than or equal to a second threshold value; determine that the computing power level of the first device is a regular device when the evaluation value is greater than the second threshold value but less than or equal to a third threshold value; and determine that the computing power level of the first device is a strong computing power device when the evaluation value is greater than the third threshold value.
[0135] In some embodiments, the first determining module 602 is further configured to determine the security level of the first device as the fourth level when the computing power level of the first device is any anti-quantum cryptography algorithm unsupported device, determine the security level of the first device as the third level when the computing power level of the first device is a computing power limited device, determine the security level of the first device as the second level when the computing power level of the first device is a regular device, and determine the security level of the first device as the first level when the computing power level of the first device is a strong computing power device.
[0136] In some embodiments, the second determining module 603 is further configured to determine a target parameter set used by a target anti-quantum cryptography algorithm based on the category of the target communication protocol, the target security level, and the data category of the first device and the second device.
[0137] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method or a program product. Therefore, various aspects of the present disclosure can be embodied as a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" herein.
[0138] The electronic device 700 according to this embodiment of the present disclosure will be described below with reference to Figure 7 Figure 7 The electronic device 700 shown is merely an example and should not impose any limitation on the function and scope of use of the embodiments of the present disclosure.
[0139] As shown in Figure 7 The electronic device 700 is in the form of a general computing device. The components of the electronic device 700 can include, but are not limited to, the at least one processing unit 710 described above, the at least one storage unit 720 described above, and a bus 730 connecting different system components, including the storage unit 720 and the processing unit 710.
[0140] The storage unit stores program codes, which can be executed by the processing unit 710, so that the processing unit 710 performs steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Methods” section of the present specification. For example, the processing unit 710 can perform the following steps of the above method embodiments: receiving initial information from a second device, wherein the initial information of the second device includes a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol and a category thereof of the second device; determining a target security level, a target quantum-resistant cryptographic algorithm and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power levels of the first device and the second device; determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicating with the second device according to the target communication protocol after the protocol enhancement.
[0141] The storage unit 720 can include a readable medium in the form of volatile storage unit, such as a random access memory (RAM) 7201 and / or a cache memory 7202, and can further include a read-only memory (ROM) 7203.
[0142] The storage unit 720 can further include a program / utility 7204 having a set of program modules 7205, including but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or a combination thereof can include implementation of a network environment.
[0143] The bus 730 can represent one or more of several types of bus structures, including a storage unit bus or bus controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of a variety of bus architectures.
[0144] The electronic device 700 can also communicate with one or more external devices 740 such as a keyboard or pointing device, a Bluetooth device, or a database, etc.; and / or one or more devices that enable a user to interact with the electronic device 700; and / or any devices (e.g., routers, modems, or other devices) that enable the electronic device 700 to communicate with one or more other computing devices. Such communication can occur via an input / output (I / O) interface 750. Still yet, the electronic device 700 can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the Internet, through a network adapter 760. As depicted, the network adapter 760 communicates with the other components of the electronic device 700 via the bus 730. It should be appreciated that the bus 730 can be one of any suitable type and that the components of the electronic device 700 can be implemented using one or more of any suitable type of architecture and / or platform.
[0145] Those skilled in the art will readily understand that the example embodiments described herein can be implemented by software and / or by hardware coupled with software, as described above. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or a network, and includes a number of instructions to enable a computing device (such as a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.
[0146] In the disclosed example embodiments, a computer-readable storage medium is also provided, which can be a readable signal medium or a readable storage medium.
[0147] In some possible embodiments, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program codes for causing an end device to perform the steps described in the above “specific embodiments” section of the present specification according to various example embodiments of the present disclosure when the program product is run on the end device.
[0148] More specific examples of the computer-readable storage medium in the present disclosure can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0149] In this disclosure, a computer readable storage medium can include a data signal transporting or broadcasting computer readable program code embodied in the data signal. The data signal can also be transmitted over a network including the Internet. Additionally, the computer readable storage medium can also be any tangible storage medium which can be used to store and / or carry the program codes.
[0150] Optionally, program code embodied on a computer readable storage medium can also be transmitted by any data transmission techniques, including but not limited to radio frequency, wireless, cable, satellite, etc., or any suitable combination of the above.
[0151] In an implementation, the program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++, etc., and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider. The present disclosure can also be implemented as a computer program product, which can be executed on a computing device.
[0152] The embodiments of the present disclosure provide a computer program product or computer program, which comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the device communication method provided in any of the various optional manners in the embodiments of the present disclosure.
[0153] It should be noted that although several modules or units of the device for action execution are mentioned in the foregoing detailed description, the division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into a plurality of modules or units.
[0154] Moreover, although individual steps of the methods in the present disclosure are described in a particular order in the drawings, this is not required or implied as to the order of execution of the steps, nor is it required that all of the steps be executed to achieve the desired result. Additionally or alternatively, certain steps can be omitted, combined into a single step, broken into multiple steps, and / or the like.
[0155] Through the above description of the embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or on a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0156] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure following the general principles thereof and including such departures from the present disclosure that come within known use or custom in the art to which the present disclosure pertains. The specification and examples are to be regarded as illustrative only, and the true scope of the present disclosure is indicated by the appended claims.
Claims
1. A device communication method applied to a first device, comprising: The method comprises the following steps: receiving initial information from a second device, wherein the initial information of the second device comprises a computing power level, a security level, a quantum-resistant cryptographic algorithm, a communication protocol and a category of the second device; determining a target security level, a target quantum-resistant cryptographic algorithm and a target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device; determining a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; performing protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol; and communicating with the second device according to the target communication protocol after the protocol enhancement.
2. The method of claim 1, wherein, The receiving of the initial information from the second device comprises receiving an initial message from the second device. After the receiving of the initial message from the second device, the method further comprises the following steps:
3. The method of claim 1, wherein, parsing the initial message of the second device to determine the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the second device from a first field, a second field and a third field of the initial message of the second device respectively. The determining of the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power level of the first device and the second device comprises the following steps: taking a device with a lower computing power level as a target device from the first device and the second device; and 4. The method of claim 1, wherein, taking the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the target device as the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol respectively. The determining of the target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level comprises the following steps: when the target security level is a first level, determining the target parameter set as a first parameter set; when the target security level is a second level, determining the target parameter set as a second parameter set; when the target security level is a third level, determining the target parameter set as a third parameter set; 5. The method of claim 1, wherein, when the target security level is a fourth level, determining the target parameter set as a zero parameter set. The performing of the protocol enhancement on the target communication protocol by using the target quantum-resistant cryptographic algorithm and the target parameter set according to the category of the target communication protocol comprises the following steps: the category of the target communication protocol comprises whether the target communication protocol has an encryption algorithm or not; when the target communication protocol does not have an encryption algorithm, adding the target quantum-resistant cryptographic algorithm using the target parameter set to the target communication protocol; when the target communication protocol has an encryption algorithm, replacing the encryption algorithm in the target communication protocol by using the target quantum-resistant cryptographic algorithm using the target parameter set.
6. The method of claim 1, wherein, Before the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol are determined from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power levels of the first device and the second device, the method further comprises: determining the computing power level, the communication protocol and the category of the first device; determining the security level and the quantum-resistant cryptographic algorithm of the first device based on the computing power level of the first device.
7. The method of claim 6, wherein, After the security level and the quantum-resistant cryptographic algorithm of the first device are determined based on the computing power level of the first device, the method further comprises: sending the initial information of the first device to the second device, wherein the initial information of the first device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the first device.
8. The method of claim 7, wherein, The sending of the initial information of the first device to the second device comprises: encapsulating the computing power level, the security level and the quantum-resistant cryptographic algorithm, the communication protocol and the category of the first device into the first field, the second field and the third field of the initial message of the first device respectively to obtain the initial message of the first device; sending the initial message of the first device to the second device.
9. The method of claim 6, wherein, The determination of the computing power level of the first device comprises: performing computing power evaluation on the first device to obtain an evaluation value; when the evaluation value is less than or equal to a first threshold value, determining that the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm; when the evaluation value is greater than the first threshold value but less than or equal to a second threshold value, determining that the computing power level of the first device is a computing power limited device; when the evaluation value is greater than the second threshold value but less than or equal to a third threshold value, determining that the computing power level of the first device is a regular device; when the evaluation value is greater than the third threshold value, determining that the computing power level of the first device is a strong computing power device.
10. The method of claim 6, wherein, The determination of the security level of the first device based on the computing power level of the first device comprises: when the computing power level of the first device is a device that does not support any quantum-resistant cryptographic algorithm, determining that the security level of the first device is a fourth level; when the computing power level of the first device is a computing power limited device, determining that the security level of the first device is a third level; when the computing power level of the first device is a regular device, determining that the security level of the first device is a second level; when the computing power level of the first device is a strong computing power device, determining that the security level of the first device is a first level.
11. A device communication apparatus applied to a first device, characterized in that, comprises: a receiving module configured to receive initial information from a second device, wherein the initial information of the second device comprises the computing power level, the security level, the quantum-resistant cryptographic algorithm, the communication protocol and the category of the second device; a first determining module configured to determine the target security level, the target quantum-resistant cryptographic algorithm and the target communication protocol from the security level, the quantum-resistant cryptographic algorithm and the communication protocol of the first device and the second device respectively based on the computing power levels of the first device and the second device; The second determining module is configured to determine a target parameter set used by the target quantum-resistant cryptographic algorithm based on the target security level; The enhancing module is configured to perform protocol enhancement on the target communication protocol according to a category of the target communication protocol, by using the target quantum-resistant cryptographic algorithm and the target parameter set; The communication module is configured to communicate with the second device according to the protocol-enhanced target communication protocol.
12. An electronic device, comprising: comprise: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the method of any one of claims 1-10 via executing the executable instructions.
13. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-10.
14. A computer program product comprising computer instructions stored in a computer readable storage medium, the computer instructions being executable by a processor to implement the operational instructions of the method of any one of claims 1-10.
Citation Information
Patent Citations
Internet of Things test platform adaptation method, system and device based on post quantum cryptography
CN120342587A
Systems and methods for measuring one or more metrics of a cryptographic algorithm in a post-quantum cryptography system
US12200116B1