Key management optimization method based on post quantum cryptography algorithm
By generating noise-resistant post-quantum keys through a lattice-based key generation algorithm and fault-tolerant coding technology, combined with multivariate polynomial encryption and hash chain structure, efficient and secure key management is achieved in a quantum computing environment, solving the security issues and low key management efficiency of traditional algorithms in a quantum computing environment.
Patent Information
- Application Number
- CN202510875979.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-06-27
AI Technical Summary
Traditional cryptographic algorithms are insecure in quantum computing environments. The key generation process lacks randomness and security, key storage and distribution are risky, and updates and revocations are inefficient. Existing post-quantum cryptographic algorithms lack optimization in key management.
A lattice-based key generation algorithm and fault-tolerant coding technology are used to generate noise-resistant post-quantum keys, a multivariate polynomial encryption algorithm and hash chain structure are used for key binding, a distributed hash tree and threshold signature protocol are combined for sharded storage, weights are dynamically adjusted, and key management is performed through revocable ring signatures and quantum secure erase protocols.
It improves the security and generation efficiency of keys, ensures security in quantum computing environments, realizes the security of distributed storage and efficient key management, supports dynamic updates and anonymous revocation, prevents keys from being tampered with or forged, and reduces the risk of centralized storage.
Smart Images

Figure CN120639284A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a key management optimization method based on a post-quantum cryptographic algorithm. Background Art
[0002] In today's digital age, information security is crucial for protecting personal privacy, corporate interests, and national sovereignty. Keys, the core of data encryption and decryption, are crucial for secure and effective management. Traditional cryptographic algorithms have long played an important role in applications, but with the rapid development of quantum computing technology, these algorithms are facing unprecedented challenges.
[0003] The immense computing power of quantum computers makes it theoretically possible to rapidly crack the mathematical problems that traditional cryptographic algorithms rely on, such as the elliptic curve discrete logarithm problem and the shortest vector problem in lattice theory. For example, elliptic curve cryptography relies on the difficulty of the elliptic curve discrete logarithm problem to ensure its security. However, quantum computers can use Shor's algorithm to solve this difficult problem in polynomial time, rendering elliptic curve cryptography insecure in a quantum computing environment. Similarly, the Diffie-Hellman key exchange protocol, which relies on the elliptic curve discrete logarithm problem, faces the same dilemma. Once quantum computers are deployed on a large scale, the security of many existing systems, including encrypted communications, financial transactions, and data storage, will be seriously threatened.
[0004] Traditional key management methods also present numerous challenges. First, during the key generation process, it's difficult to ensure sufficient randomness and security, making them vulnerable to analysis and cracking by attackers. For example, some key generation methods based on pseudo-random number generators may generate key sequences with certain regularities. By studying the generation algorithm and obtaining partial keys, attackers could potentially predict subsequent keys. Second, key storage and distribution present risks. Centralized key storage can compromise all keys if attacked. Distributed storage, on the other hand, presents challenges in ensuring the security of key shards and enabling accurate and rapid retrieval and combination of key shards when needed. Furthermore, traditional methods are often inefficient and insecure when it comes to key updates and revocations. For example, rekeying and regenerating keys can require significant computational and communication overhead, while key revocations can be difficult to ensure that revoked keys will not be reused.
[0005] Post-quantum cryptography offers a new approach to addressing these challenges. It relies on mathematical challenges believed to remain secure in quantum computing environments, such as lattice theory, solving multivariate polynomial equations, and code-based cryptography. However, the application of post-quantum cryptography to key management is still in its exploratory stages, with much room for improvement and refinement. For example, how can we design efficient key generation methods based on post-quantum cryptography to improve key security and efficiency? How can we leverage post-quantum cryptography to implement more secure and reliable key storage and distribution mechanisms? And how can we optimize the key update and revocation process to adapt it to the characteristics of post-quantum cryptography? Therefore, researching a key management optimization method based on post-quantum cryptography is of great practical significance and urgency. Summary of the Invention
[0006] The purpose of the present invention is to provide a key management optimization method based on a post-quantum cryptographic algorithm to solve the problems raised in the above background technology.
[0007] To achieve the above objectives, the present invention provides the following technical solution: a key management optimization method based on a post-quantum cryptography algorithm, the method comprising: Step S1: performing lattice-based construction processing on the initial security parameters using a lattice-based key generation algorithm to obtain a post-quantum key generation base; and performing fault-tolerant processing on the post-quantum key generation base using a fault-tolerant coding technique to obtain a noise-resistant post-quantum key; Step S2: performing dynamic polynomial mapping processing on the noise-resistant post-quantum key using a multivariate polynomial encryption algorithm to obtain a multivariate encryption key; performing hierarchical binding processing on the multivariate encryption key using a hash chain structure to obtain a hierarchical verification key; Step S3: Using a distributed hash tree technology to perform shard storage processing on the hierarchical verification key to obtain distributed key shards; and performing dynamic threshold signature processing on the distributed key shards based on a threshold signature protocol to obtain threshold signature key shards; Step S4: using a dynamic weight update algorithm to periodically adjust the weight of the threshold signature key shard to obtain an updated weight key shard; performing a non-interactive verification process on the updated weight key shard using a zero-knowledge proof protocol to obtain a verified key shard; Step S5: anonymously revoke the verified key shard using a revocable ring signature algorithm to obtain a revocation identification key; and perform quantum secure destruction on the revocation identification key through a secure erase protocol to obtain a final key management result.
[0008] Preferably, step S1 includes the following steps: Step S11: performing lattice construction processing on the initial security parameters using a lattice generation function, wherein the initial security parameters include a modulus, a dimension, and an error distribution; Step S12: Based on the lattice basis output by the lattice basis generation function, the lattice basis is subjected to fault-tolerant coding processing by using a fault-tolerant coding technique to obtain a noise-resistant post-quantum key; Step S13: extracting basic key components from the noise-resistant post-quantum key using a random sampling algorithm to obtain a basic key set; Step S14: performing linear superposition processing on the basic key set through a linear combination algorithm to generate a final noise-resistant post-quantum key.
[0009] Preferably, step S2 includes the following steps: Step S21: construct a multivariate polynomial equation system, where the degree of each polynomial is and the number of variables is, and use a random coefficient generation algorithm to generate a polynomial coefficient matrix; Step S22: mapping the noise-resistant post-quantum key to input variables of the multivariate polynomial equation system, and obtaining the multivariate encryption key by solving the equation system; Step S23: performing layer-by-layer hash binding processing on the multivariate encryption key using a hash chain structure to generate a layered verification key; Step S24: performing chain signature processing on the hierarchical verification key through a verification chain generation algorithm to obtain a verifiable key hash chain.
[0010] Preferably, the generation function of the hash chain structure in step S23 is as follows: in, is the hash value of the i-th layer, is the multivariate encryption key component of the i-th layer, represents the XOR operation, and H is the collision-resistant hash function.
[0011] Preferably, step S3 includes the following steps: Step S31: using distributed hash tree technology to split the hierarchical authentication key into m key shards, where m≥2; Step S32: Based on the threshold signature protocol, a minimum signature threshold t is defined, requiring at least t key shards to jointly generate a valid signature; Step S33: Perform polynomial reconstruction processing on the m key shards using the Lagrange interpolation algorithm to obtain threshold signature key shards; Step S34: Perform independent validity verification on each threshold signature key shard through the shard verification function.
[0012] Preferably, the formula of the shard verification function in step S34 is as follows: in, is the verification value of the j-th shard, is the signature component of the i-th fragment, is the value of the Lagrange basis polynomial at 0, and p is a large prime number.
[0013] Preferably, step S4 includes the following steps: Step S41: construct a dynamic weight update function to calculate the weight value of each key shard based on the historical usage frequency and shard trust; Step S42: normalizing the weight values using a weighted average algorithm to obtain an updated weight distribution scheme; Step S43: Generate a verification proof for each key shard based on a non-interactive zero-knowledge proof protocol; Step S44: Aggregate all verification certificates into a global verification result through the certificate aggregation algorithm to generate a post-verification key shard.
[0014] Preferably, the formula of the dynamic weight update function in step S41 is as follows: in, is the weight of the i-th shard, is the historical usage frequency, Score the trustworthiness. and is the dynamic adjustment coefficient.
[0015] Preferably, step S5 includes the following steps: Step S51: Generate a ring signature including a revocation tag using a revocable ring signature algorithm, where the number of ring members is n; Step S52: using an anonymous revocation function to identify the key shard to be destroyed according to the revocation tag; Step S53: Overwriting and randomizing the identification fragment multiple times based on the quantum secure erase protocol to ensure that the information is irrecoverable; Step S54: Use the erase verification function to perform entropy value detection on the destroyed storage area to confirm the destruction integrity.
[0016] Preferably, the execution steps of the quantum secure erase protocol in step S53 include: Step S531: overwrite the key storage medium with random data at least three times; Step S532: Generate a true random number sequence using a quantum random number generator to replace the original stored content; Step S533: Verify whether the medium meets a preset entropy threshold through a physical damage detection algorithm.
[0017] Compared with the prior art, the present invention has the following beneficial effects: The present invention is based on a post-quantum cryptographic algorithm and utilizes a lattice-based key generation algorithm and fault-tolerant coding technology to generate noise-resistant post-quantum keys from initial security parameters. The lattice problem on which the lattice-based algorithm relies has high security in a quantum computing environment and is difficult to be cracked by a quantum computer. Fault-tolerant coding technology further enhances the key's resistance to noise and errors, ensuring the integrity and availability of the key in complex communication and storage environments. In the presence of noise interference in the quantum channel, traditional keys may have errors, resulting in the inability to correctly decrypt data. The noise-resistant post-quantum keys generated by the present invention can effectively resist the influence of noise and ensure the secure transmission and storage of data.
[0018] By dynamically mapping keys to polynomials using a multivariate polynomial encryption algorithm, combined with a hash chain structure and verification chain generation algorithm, we achieve the generation and verification of multivariate encryption keys and hierarchical verification keys. The complexity of the multivariate polynomial encryption algorithm enhances the security of the encrypted keys, while the hash chain structure and verification chain provide a reliable method for key verification. During data transmission, the recipient can quickly and accurately verify the authenticity and integrity of the key using the verification chain, preventing key tampering or forgery.
[0019] Utilizing distributed hash tree technology and a threshold signature protocol, hierarchical verification keys are sharded and dynamically signed. Distributed hash tree technology stores key shards on different nodes, reducing the risk of centralized key storage. The threshold signature protocol specifies that only a certain number of key shards must be combined to generate a valid signature, enhancing the security of key signatures. In a distributed storage system, even if the key shards of some nodes are stolen, an attacker cannot generate a valid signature, thus ensuring system security.
[0020] The dynamic weight update algorithm periodically adjusts the weights of threshold signature key shards based on historical usage frequency and shard trust, while a zero-knowledge proof protocol implements non-interactive verification. This dynamic management approach optimizes the weight distribution of key shards based on actual key usage and node trust, improving the efficiency and security of key usage. In a network environment where node trust fluctuates dynamically, the dynamic weight update algorithm can promptly adjust the weights of key shards, ensuring that key shards from highly trusted nodes play a greater role in key usage.
[0021] The revocable ring signature algorithm enables anonymous revocation, while the quantum-secure erase protocol ensures the secure destruction of revocation identification keys. Anonymous revocation protects user privacy, while the quantum-secure erase protocol ensures that key information is irrecoverable through multiple overwrites and randomization. When a user needs to revoke a key, the revocable ring signature algorithm enables the revocation without revealing the user's identity. The quantum-secure erase protocol prevents attackers from recovering and exploiting residual data from revoked keys, further enhancing key management security. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a working principle diagram of the key management optimization method of the present invention; Figure 2 A workflow diagram for key generation and processing; Figure 3 Workflow diagram for key sharding storage and signature verification; Figure 4 Workflow diagram for key weight adjustment. DETAILED DESCRIPTION
[0023] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0024] See also Figure 1-4 The present invention provides a key management optimization method based on a post-quantum cryptographic algorithm, and its overall implementation scheme is as follows: Step S1: Using a lattice-based key generation algorithm to perform lattice construction processing on the initial security parameters to obtain a post-quantum key generation base; and using fault-tolerant coding technology to perform fault-tolerant processing on the post-quantum key generation base to obtain a noise-resistant post-quantum key.
[0025] Step S2: performing dynamic polynomial mapping processing on the noise-resistant post-quantum key using a multivariate polynomial encryption algorithm to obtain a multivariate encryption key; performing hierarchical binding processing on the multivariate encryption key using a hash chain structure to obtain a hierarchical verification key.
[0026] Step S3: Using distributed hash tree technology to perform shard storage processing on the hierarchical verification key to obtain distributed key shards; and performing dynamic threshold signature processing on the distributed key shards based on the threshold signature protocol to obtain threshold signature key shards.
[0027] Step S4: using a dynamic weight update algorithm to perform periodic weight adjustment processing on the threshold signature key shard to obtain an updated weight key shard; performing non-interactive verification processing on the updated weight key shard through a zero-knowledge proof protocol to obtain a verified key shard.
[0028] Step S5: anonymously revoke the verified key shard using a revocable ring signature algorithm to obtain a revocation identification key; and perform quantum secure destruction on the revocation identification key through a secure erase protocol to obtain a final key management result.
[0029] Example 1: In the specific implementation process of step S1, the operation is further refined. First, step S11 is executed using the lattice generation function The initial security parameters are processed by lattice construction. The initial security parameters here are the modulus in the above example. , dimension , the error distribution is Gaussian distribution .pass Function operation to obtain the lattice basis .
[0030] Then proceed to step S12, based on the lattice base output by the lattice base generation function , using fault-tolerant coding technology, such as Hamming code for fault-tolerant coding. The generator matrix of Hamming code is , for Geki Encode and obtain the encoded lattice basis , which is the noise-resistant post-quantum key.
[0031] Step S13, using random sampling algorithm From noise-resistant post-quantum keys Extract the basic key component. Assume that the sampling seed of the random sampling algorithm is ,pass Function, from Randomly select some elements from the to get the basic key component set .
[0032] Finally, step S14 is executed, and the linear combination algorithm is used to Basic key set Perform linear superposition processing. The linear combination coefficient vector is ,pass Function, generates the final noise-resistant post-quantum key .
[0033] Example 2: For step S2, in actual operation, step S21 is performed first. Construct a multivariable polynomial equation system and set the degree of each polynomial to , the number of variables is . Generate polynomial coefficient matrix using random coefficient generation algorithm ,matrix Elements in ( ; ) are randomly generated values within a specific range.
[0034] Then proceed to step S22, the noise-resistant post-quantum key Mapped to the input variables of a multivariate polynomial equation system. Assuming noise-resistant post-quantum key After some transformation, the input variable vector is obtained , substitute it into the equation By solving the system of equations , get the multivariate encryption key .
[0035] Then, in step S23, the multivariate encryption key is encrypted using the hash chain structure. Perform layer-by-layer hash binding processing. The generation function of the hash chain structure is ,in, For the In this embodiment, it is assumed that the hash chain is constructed from the first layer, and the initial value ; For the The multivariate encryption key component of the layer, where the multivariate encryption key Split into multiple components according to certain rules, such as , as each layer ; Represents an exclusive OR operation, which performs a bitwise operation on the previous layer's hash value and the current layer's key component, increasing the complexity of the hash value; For collision-resistant hash functions, such as SHA-256, it can ensure that the probability of different inputs generating different hash values is extremely low, thereby improving security. By calculating layer by layer, a layered verification key is generated. .
[0036] Finally, step S24 is executed to generate the algorithm by verifying the chain Hierarchical Authentication Key Perform chain signature processing. Assume that the signature algorithm is , the private key is ,pass Function to get a verifiable key hash chain .
[0037] Example 3: In the implementation process of step S3, step S31 is first performed. Distributed hash tree technology, such as Merkle tree technology, is used to store the hierarchical verification key. Split into The Merkle tree constructs a tree structure by hashing the data, using the hierarchical verification key as the leaf node data. After layer-by-layer hash calculations, the root node hash value is finally obtained, which also achieves data sharding.
[0038] Then execute step S32 to define the minimum signature threshold based on the threshold signature protocol , which means that at least two key shards must be combined to generate a valid signature. This is to improve the flexibility of key usage while ensuring security, and to prevent the loss of a single key shard from causing the inability to generate a signature.
[0039] Then proceed to step S33, using the Lagrange interpolation algorithm Perform polynomial reconstruction on these four key shards.
[0040] Assume that the four key shards are ,pass Function to get the threshold signature key shard .
[0041] Finally, step S34 is performed by sharding verification function Perform independent validity verification on each threshold signature key shard. For the The verification value of each fragment, in this embodiment, ; For the The signature component of a shard is the portion of data associated with the key shard during the signing process; is the value of the Lagrange basis polynomial at 0, which is generated according to the coordinates of the key shard; is a large prime number, assuming , which is used to ensure the uniqueness and security of the calculation results and prevent problems such as hash conflicts.,The validity of each threshold signature key shard is determined by calculating the verification value and comparing it with the preset correct value.
[0042] Example 4: In the specific operation of step S4, step S41 is first performed. Construct a dynamic weight update function ,in, For the The weight of each shard, Corresponding to different key shard numbers; The historical usage frequency is calculated by counting the number of times each key shard has been used in past encryption or signing operations and combining it with the total number of operations. To evaluate the trustworthiness of the key shards, the reliability of their source and their stability during use can be used. and is the dynamic adjustment coefficient, assuming , , which are used to adjust the relative importance of historical usage frequency and trust score in weight calculation. The weight value of each key shard is calculated by this function.
[0043] Then execute step S42, using the weighted average algorithm Normalize the weight values. Assume that the weight value vector obtained by the dynamic weight update function is ,pass Function to get the updated weight distribution scheme , so that the sum of all weight values is 1, ensuring the rationality and effectiveness of the weights.
[0044] Then proceed to step S43, based on the non-interactive zero-knowledge proof protocol Generate verification proof for each key shard. Assume the key shard is ,pass Function, generate verification proof ,This proof can prove the validity and legitimacy of the key shard without revealing the specific content of the key shard.
[0045] Finally, step S44 is executed to prove the aggregation algorithm. Aggregate all verification proofs into a global verification result. Assume that the set of all verification proofs is ,pass Function to generate key shards after verification .
[0046] Example 5: In the implementation process of step S5, step S51 is first performed. A revocable ring signature algorithm, such as an identity-based revocable ring signature algorithm, is used to generate a ring signature including a revocation tag. Assume that the number of ring members is , when generating a ring signature, each ring member has its own private key and public key . Through the revocable ring signature algorithm , input the ring member's private key set, public key set and the message to be signed , generate a ring signature containing a revocation tag .
[0047] Then execute step S52, through the anonymous revocation function Identify the key shard to be destroyed based on the revocation tag. Assume the revocation tag is ,pass Function, find the corresponding key shard to be destroyed in the ring signature .
[0048] Then, step S53 is performed to perform multiple overwrites and randomization on the identification fragments based on the quantum secure erase protocol. The execution steps of the protocol are as follows: First, step S531 is performed to overwrite the key storage medium with random data at least three times. Assuming the storage medium is a hard disk, randomly generated data blocks are written to the hard disk, with different data written each time, overwriting the area where the key shards were originally stored. This operation is repeated three times, so that the original key shard data is initially destroyed.
[0049] Then, step S532 is executed to generate a true random number sequence using a quantum random number generator to replace the original stored content. The quantum random number generator generates a completely random digital sequence based on the principles of quantum mechanics. Assume that the generated random number sequence is , writing it to the area where the key shards are stored, further destroying the original data.
[0050] Finally, step S533 is executed to detect the physical damage of the Verify whether the media meets the preset entropy threshold. Assume that the preset entropy threshold is ,pass Function, detects the entropy value of the storage medium. If the entropy value reaches or exceeds the threshold, the medium is considered to meet the requirements and the original key shard information is irrecoverable.
[0051] Finally, step S54 is executed to use the erase verification function Perform entropy value detection on the storage area after destruction to confirm the integrity of destruction. Assume that the storage area after destruction is ,pass The function calculates the entropy value of the area and compares it with the preset ideal entropy value. If the two are close, the destruction integrity is confirmed and the final key management result is obtained.
[0052] Example 6: Further elaborate on the relevant content of step S11 in step S1. When the lattice generation function is used to perform lattice construction processing on the initial security parameters, the lattice generation function can be implemented based on the Gaussian sampling algorithm. For example, it is based on the given modulus , Dimension and error distribution Perform sampling operation. Assume that the error distribution The standard deviation is Gaussian distribution, in each sampling process, randomly extract elements from the probability space that conforms to the Gaussian distribution to construct the lattice basis vector. Through multiple sampling, generate The required lattice basis vector group, thus obtaining the lattice basis The modulus here is It determines the value range of the sampling result. In the subsequent encryption and calculation process, all numerical operations involved are performed in the model. The calculation is carried out in a finite domain to ensure the closedness and security of the calculation; the dimension The length of the lattice basis vector is determined. Different dimensions will affect the strength and computational complexity of the key; error distribution The randomness and noise characteristics of the sampling are controlled, and the appropriate error distribution can improve the algorithm's anti-attack ability while ensuring the security of the key.
[0053] Example 7: The specific implementation of the random coefficient generation algorithm in step S21 in step S2 is described in detail. The random coefficient generation algorithm can be implemented based on the linear congruential method. The linear congruential formula is set as ,in is the currently generated random number, is the next random number generated, 、 、 is a pre-set parameter. When , assuming the matrix The size of ( , ), first select a suitable initial value ,For example ,parameter , , Generate random numbers in sequence through the linear congruential formula, and fill these random numbers into the polynomial coefficient matrix in the order of rows and columns of the matrix The random coefficients generated in this way possess a certain degree of randomness and unpredictability, meeting the coefficient randomness requirements of multivariate polynomial encryption algorithms and enhancing encryption security. During the subsequent multivariate polynomial encryption process, these random coefficients interact with the input variables, making the encryption result more complex and difficult to crack.
[0054] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0055] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A key management optimization method based on post-quantum cryptography algorithm, characterized in that: The following steps are involved: Step S1: performing lattice-based construction processing on the initial security parameters using a lattice-based key generation algorithm to obtain a post-quantum key generation base; and performing fault-tolerant processing on the post-quantum key generation base using a fault-tolerant coding technique to obtain a noise-resistant post-quantum key; Step S2: performing dynamic polynomial mapping processing on the noise-resistant post-quantum key using a multivariate polynomial encryption algorithm to obtain a multivariate encryption key; Performing hierarchical binding processing on the multivariate encryption key through a hash chain structure to obtain a hierarchical verification key; Step S3: Using a distributed hash tree technology to perform shard storage processing on the hierarchical verification key to obtain distributed key shards; and performing dynamic threshold signature processing on the distributed key shards based on a threshold signature protocol to obtain threshold signature key shards; Step S4: using a dynamic weight update algorithm to periodically adjust the weight of the threshold signature key shard to obtain an updated weight key shard; performing a non-interactive verification process on the updated weight key shard using a zero-knowledge proof protocol to obtain a verified key shard; Step S5: anonymously revoke the verified key shard using a revocable ring signature algorithm to obtain a revocation identification key; and perform quantum secure destruction on the revocation identification key through a secure erase protocol to obtain a final key management result.
2. The key management optimization method based on the post-quantum cryptography algorithm according to claim 1 is characterized in that: Step S1 includes the following steps: Step S11: performing lattice construction processing on the initial security parameters using a lattice generation function, wherein the initial security parameters include a modulus, a dimension, and an error distribution; Step S12: Based on the lattice basis output by the lattice basis generation function, the lattice basis is subjected to fault-tolerant coding processing by using a fault-tolerant coding technique to obtain a noise-resistant post-quantum key; Step S13: extracting basic key components from the noise-resistant post-quantum key using a random sampling algorithm to obtain a basic key set; Step S14: performing linear superposition processing on the basic key set through a linear combination algorithm to generate a final noise-resistant post-quantum key.
3. The key management optimization method based on the post-quantum cryptography algorithm according to claim 1 is characterized in that: Step S2 includes the following steps: Step S21: construct a multivariate polynomial equation system, where the degree of each polynomial is and the number of variables is, and generate a polynomial coefficient matrix using a random coefficient generation algorithm; Step S22: Mapping the noise-resistant post-quantum key to input variables of the multivariate polynomial equation system, and obtaining the multivariate encryption key by solving the equation system; Step S23: performing layer-by-layer hash binding processing on the multivariate encryption key using a hash chain structure to generate a layered verification key; Step S24: performing chain signature processing on the hierarchical verification key through a verification chain generation algorithm to obtain a verifiable key hash chain.
4. The key management optimization method based on the post-quantum cryptography algorithm according to claim 3 is characterized in that: The generation function of the hash chain structure in step S23 is as follows: in, is the hash value of the i-th layer, is the multivariate encryption key component of the i-th layer, represents the XOR operation, and H is the collision-resistant hash function.
5. The key management optimization method based on the post-quantum cryptography algorithm according to claim 1 is characterized in that: Step S3 includes the following steps: Step S31: using distributed hash tree technology to split the hierarchical authentication key into m key shards, where m≥2; Step S32: Based on the threshold signature protocol, a minimum signature threshold t is defined, requiring at least t key shards to jointly generate a valid signature; Step S33: Perform polynomial reconstruction processing on the m key shards using the Lagrange interpolation algorithm to obtain threshold signature key shards; Step S34: Perform independent validity verification on each threshold signature key shard through the shard verification function.
6. The key management optimization method based on the post-quantum cryptography algorithm according to claim 5 is characterized in that: The formula of the shard verification function in step S34 is as follows: in, is the verification value of the j-th shard, is the signature component of the i-th fragment, is the value of the Lagrange basis polynomial at 0, and p is a large prime number.
7. The key management optimization method based on the post-quantum cryptography algorithm according to claim 1 is characterized in that: Step S4 includes the following steps: Step S41: construct a dynamic weight update function to calculate the weight value of each key shard based on the historical usage frequency and shard trust; Step S42: normalizing the weight values using a weighted average algorithm to obtain an updated weight distribution scheme; Step S43: Generate a verification proof for each key shard based on a non-interactive zero-knowledge proof protocol; Step S44: Aggregate all verification certificates into a global verification result through the certificate aggregation algorithm to generate a post-verification key shard.
8. The key management optimization method based on the post-quantum cryptography algorithm according to claim 7 is characterized in that: The formula of the dynamic weight update function in step S41 is as follows: in, is the weight of the i-th shard, is the historical usage frequency, Score the trustworthiness. and is the dynamic adjustment coefficient.
9. The key management optimization method based on the post-quantum cryptography algorithm according to claim 1 is characterized in that: Step S5 includes the following steps: Step S51: Generate a ring signature including a revocation tag using a revocable ring signature algorithm, where the number of ring members is n; Step S52: using an anonymous revocation function to identify the key shard to be destroyed according to the revocation tag; Step S53: Overwriting and randomizing the identification fragment multiple times based on the quantum secure erase protocol to ensure that the information is irrecoverable; Step S54: Use the erase verification function to perform entropy value detection on the destroyed storage area to confirm the destruction integrity.
10. The key management optimization method based on the post-quantum cryptography algorithm according to claim 9 is characterized in that: The execution steps of the quantum secure erase protocol in step S53 include: Step S531: overwrite the key storage medium with random data at least three times; Step S532: Generate a true random number sequence using a quantum random number generator to replace the original stored content; Step S533: Verify whether the medium meets a preset entropy threshold through a physical damage detection algorithm.
Citation Information
Patent Citations
On-grid certificateless signcryption method with post quantum security
CN110176995A
Method for using multiple passwords in distributed mode and related device
CN117394992A
Certificate chain driven edge computing gateway trusted asymmetric encryption communication protocol
CN119628841A
Block chain driven distributed private data storage and access control method and system
CN119783138A
Lattice-based threshold signature method and threshold decryption method
GB2629664A