Quantum token generation method and device and electronic equipment
By generating quantum tokens through quantum state encoding of quantum random numbers and user behavior trajectories, the shortcomings of existing CSRF defense mechanisms in quantum computing environments are solved, and efficient identity authentication and security protection are achieved.
Patent Information
- Application Number
- CN202510970235.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-09-19
AI Technical Summary
Existing CSRF defense mechanisms are difficult to effectively defend against automated attacks in a quantum computing environment, and tokens are easily cracked and attacked by timing prediction, resulting in insufficient network security.
By obtaining quantum random number sequences and user behavior trajectories, quantum state encoding is performed, and a quantum token is generated using a post-quantum encryption algorithm. Combined with the quantum coding characteristics and preset timestamp, a quantum token for identity authentication is generated.
It significantly improves the defense level against CSRF attacks, provides a high-level authentication mechanism, ensures the security and stability of web applications in the era of quantum computing, and effectively resists automated attacks and token cracking.
Smart Images

Figure CN120675797A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum information technology, and in particular to a method, device and electronic device for generating a quantum token. Background Art
[0002] Against the backdrop of the rapid development of information technology, network security has become a critical concern across all industries. In particular, in the field of web development, with the increasing popularity of internet applications, CSRF (Cross-Site Request Forgery) attacks, as a common security threat, have attracted widespread attention. CSRF attacks exploit a user's logged-in status and, by forging requests, allow the victim to unknowingly execute malicious commands or operations, thereby compromising user data or permissions. While existing CSRF defense mechanisms provide a certain degree of protection, their effectiveness is facing unprecedented challenges in the face of the impending quantum computing era.
[0003] Defense strategies for CSRF attacks include request source restrictions, user operation restrictions, additional verification mechanisms, and security device-level protection. However, these strategies exhibit the following limitations in the face of quantum computing:
[0004] 1. Request source restriction: Use the HTTP Referer field to verify the legitimacy and credibility of the request source. While simple and low-cost to implement, this method is highly dependent on correct browser implementation. Furthermore, differences in how different browsers handle the Referer field can lead to compatibility issues. Furthermore, some browsers allow users to manually disable the sending of Referer fields, which directly weakens the effectiveness of this method. In a quantum computing environment, if an attacker can manipulate the underlying logic of the user's browser, verifying the legitimacy of the request source becomes ineffective.
[0005] 2. User Operation Restrictions: Introducing graphical verification codes or complex human-machine verification mechanisms makes it more difficult for attackers to forge requests. While these methods perform well in traditional computing environments, in the face of quantum computing, the complexity and speed of automated programs will significantly increase, and traditional graphic recognition technology may no longer be an effective barrier. Furthermore, the frequent appearance of verification codes may degrade the user experience, especially on mobile devices, where screen size limitations make entering verification codes more cumbersome.
[0006] 3. Additional Verification Mechanism: Tokens are used for authentication, ensuring that every request carries valid credentials. However, the token generation and verification process relies on traditional encryption technologies such as RSA and ECC. These encryption algorithms are vulnerable to quantum computing's Shor algorithm and are easily cracked. Therefore, even if the token mechanism is effective in traditional computing environments, its security will be significantly compromised in the quantum era.
[0007] 4. Security Equipment Protection: Build a secure network architecture and employ physical security measures to protect servers and network devices. While this protection strategy can provide some physical-layer security, at the network level, especially given the threat of quantum computing, these measures alone are unlikely to effectively combat remotely launched CSRF attacks. The emergence of quantum computers means that data transmitted over networks may be subject to unprecedented cracking risks. Even if the physical layer is secure, data security issues during transmission cannot be avoided.
[0008] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0009] The embodiments of the present application provide a method, device, and electronic device for generating a quantum token to at least solve the technical problems that the CSRF defense mechanism in the related art cannot effectively resist automated attacks supported by quantum computing, and the token is easy to crack and timing prediction attacks.
[0010] According to one aspect of an embodiment of the present application, a method for generating a quantum token is provided, including: obtaining a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent a pointer movement path corresponding to a user operation on a client interface; performing quantum state encoding on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory; and using a post-quantum encryption algorithm to generate a quantum token based on the quantum random number sequence, the quantized coding feature, and a preset timestamp, wherein the quantum token is the information required for user identity authentication in a cross-site request forgery attack scenario.
[0011] Optionally, obtaining a quantum random number sequence includes: when a user logs in to a client system and the client system interface is in a blank loading state, starting a quantum random number generator; obtaining quantum random data from physical quantum effects through the quantum random number generator, and initializing an entropy pool, wherein the entropy pool is used to store quantum random data, and the entropy value of the entropy pool is greater than 2.8 bits / ns, and the quantum random number generator updates the quantum random data once every preset time period; obtaining a preset amount of quantum random data from the entropy pool to obtain a quantum random number sequence.
[0012] Optionally, after obtaining the user behavior trajectory, the method also includes: determining the pointer coordinate data in the user behavior trajectory; performing a quantum Fourier transform on the pointer coordinate data to convert the pointer movement path in the time domain into quantum amplitude and phase information in the frequency domain to obtain a quantum bit feature corresponding to the user behavior trajectory; using the learning error algorithm in the lattice code to determine the error tolerance for noise filtering of the quantum bit feature, and filtering the noise signal in the quantum bit feature that is greater than the error tolerance.
[0013] Optionally, quantum state encoding is performed on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory, including: determining a quantum gate operation for quantum state encoding of the user behavior trajectory based on quantum amplitude and phase information; and converting the quantum bit feature into a quantized coding feature based on the quantum gate operation, wherein the quantized coding feature is an 8×8 quantum gate operation sequence, and each quantum gate represents an operation on the quantum bit feature.
[0014] Optionally, a post-quantum encryption algorithm is used to generate a quantum token based on a quantum random number sequence, a quantized coding feature, and a preset timestamp, including: generating a quantum key based on a quantum random number sequence and a preset timestamp through a post-quantum encryption algorithm; generating an intermediate token based on the quantized coding feature; and signing the quantum key and the intermediate token using a post-quantum digital signature algorithm to obtain a quantum token.
[0015] Optionally, generating an intermediate token based on the quantized coding features includes: determining a user ID and a quantum time standard deviation, wherein the quantum time standard deviation is used to represent the degree of fluctuation between quantum time marks during user operation; and integrating the user ID, the quantum time standard deviation, and the quantized coding features using a post-quantum resistant hash algorithm to obtain the intermediate token.
[0016] Optionally, the preset timestamp is determined by: obtaining a quantum entangled photon pair; monitoring the photon decay process in the quantum entangled photon pair, and determining the decay time of the photon decay process, wherein the decay time is the time for the first photon in the quantum entangled photon pair to transition from an excited state to a ground state; and generating a preset timestamp based on the decay time and the system time reference.
[0017] Optionally, the method also includes: determining the quantum curvature of the user behavior trajectory through a trajectory curvature quantization algorithm, wherein the quantum curvature is used to represent the curvature of the surface of the user behavior trajectory; when the quantum curvature is within a first preset range, determining that the user behavior trajectory is a real user operation; when the quantum curvature is within a second preset range, determining that the user behavior trajectory is a potential automated attack behavior, wherein the second preset range is larger than the first preset range.
[0018] According to another aspect of an embodiment of the present application, a device for generating a quantum token is also provided, including: an acquisition module for acquiring a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent the pointer movement path corresponding to the user operation on the client interface; an encoding module for performing quantum state encoding on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory; a generation module for using a post-quantum encryption algorithm to generate a quantum token based on the quantum random number sequence, the quantized coding feature and a preset timestamp, wherein the quantum token is the information required for user identity authentication in a cross-site request forgery attack scenario.
[0019] According to another aspect of the embodiments of the present application, an electronic device is also provided, including: a memory and a processor, wherein the memory is used to store program instructions; the processor is connected to the memory and is used to execute the above-mentioned method for generating a quantum token.
[0020] According to another aspect of the embodiments of the present application, a non-volatile storage medium is also provided, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-mentioned method for generating a quantum token by running the computer program.
[0021] According to another aspect of the embodiments of the present application, a computer program product is also provided, including computer instructions, which implement the above-mentioned method for generating a quantum token when executed by a processor.
[0022] In an embodiment of the present application, by obtaining a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent the pointer movement path corresponding to the user operation on the client interface; quantum state encoding is performed on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory; a post-quantum encryption algorithm is used to generate a quantum token based on the quantum random number sequence, the quantized coding feature and a preset timestamp, wherein the quantum token is the information required for user authentication in a cross-site request forgery attack scenario, thereby achieving the purpose of significantly improving the CSRF attack defense level in the post-quantum computing era, thereby realizing a high-level authentication mechanism, effectively ensuring the security and stability of Web applications in the face of advanced attack technologies, and thus solving the technical problems that the CSRF defense mechanism in related technologies cannot effectively resist automated attacks supported by quantum computing, tokens are easily cracked and timing prediction attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0024] Figure 1 This is a hardware structure diagram of a computer terminal for implementing a method for generating a quantum token according to an embodiment of the present application;
[0025] Figure 2 is a flow chart of a method for generating a quantum token according to an embodiment of the present application;
[0026] Figure 3 This is a schematic diagram of a quantum token verification process according to an embodiment of the present application;
[0027] Figure 4 This is a structural diagram of a device for generating a quantum token according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] First, some nouns or terms that appear in the process of explaining the embodiments of this application are subject to the following explanations:
[0031] CSRF (Cross-Site Request Forgery): A network attack in which an attacker exploits a victim's logged-in status to initiate unauthorized requests to the website they are visiting. This exploit allows the attacker to perform malicious actions on the target website, such as changing user account information, submitting transactions, or posting messages. CSRF attacks typically occur in the background, where the victim is unknowingly subjected to the attacker's intended actions.
[0032] QRNG (Quantum Random Number Generator): A device that generates truly random numbers using quantum phenomena such as quantum entanglement and the random collapse of quantum states. Unlike traditional software-based random number generators, this type of generator provides a truly unpredictable stream of random numbers, making it suitable for high-strength encryption and security authentication, and particularly valuable in the post-quantum security era.
[0033] MLWE (Module Learning with Errors): An extension of the LWE (Learning with Errors) algorithm, it belongs to the field of lattice cryptography. Compared to LWE, MLWE uses higher-dimensional lattices and allows the use of moduli, which enables the encryption algorithm to process large data sets more efficiently. MLWE is considered one of the most promising encryption algorithms in the post-quantum era because it is resistant to cracking attempts using quantum computing.
[0034] QHF (Quantum Hash Function): A hash function designed using quantum computing principles. Compared to traditional hash functions, QHF is more resistant to attacks from quantum computers, particularly quantum algorithms like Grover's search. The design of quantum hash functions typically combines the non-cloning nature of quantum information with the complexity of quantum computing to ensure data integrity verification.
[0035] CRYSTALS-Kyber: A post-quantum encryption algorithm based on lattice cryptography, selected by NIST as a standard public key encryption algorithm in the third round of the post-quantum encryption standardization competition. CRYSTALS-Kyber leverages the difficulty of lattices to provide an efficient and secure encryption solution that seamlessly integrates with existing network security and encryption infrastructure.
[0036] Dilithium: A post-quantum digital signature algorithm based on lattice cryptography, also selected by NIST in a standardization competition. Known for its high security and low overhead, Dilithium provides quantum computing-level security for data signing and entity authentication. In this application, Dilithium is used to issue and verify quantum cryptographic tokens, ensuring their robustness against forgery and verification in a post-quantum computing environment.
[0037] In order to solve the problem of low CSRF attack defense level in related technologies, the present invention provides a method for generating a quantum token, which can be run on Figure 1 Among the computer terminals shown, the computer terminal will be described below.
[0038] The quantum token generation method embodiment provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal for implementing a method for generating a quantum token is shown in FIG. Figure 1 As shown, the computer terminal 10 may include one or more (illustrated by 102a, 102b, ..., 102n in the figure) processors (the processor may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission module 106 for communication functions connected via a wired and / or wireless network. In addition, it may also include: a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, and a BUS bus. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0039] It should be noted that the one or more processors and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0040] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method for generating a quantum token in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, realizing the above-mentioned method for generating a quantum token. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0041] The transmission module 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission module 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission module 106 may be a radio frequency (RF) module, which is configured to communicate with the Internet wirelessly.
[0042] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0043] It should be noted that, in some optional embodiments, the above Figure 1 The computer terminal shown may include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of hardware elements and software elements. Figure 1 This is merely one example of a particular embodiment and is intended to illustrate the types of components that may be present in the computer terminal described above.
[0044] In the above-mentioned operating environment, an embodiment of the present application provides an embodiment of a method for generating a quantum token. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0045] Figure 2 This is a flow chart of a method for generating a quantum token according to an embodiment of the present application, such as Figure 2 As shown, the method includes the following steps:
[0046] Step S202: Acquire a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent a pointer movement path corresponding to a user operation on a client interface.
[0047] In the above step S202, the main responsibility is to accumulate sufficient randomness and user behavior characteristics to provide pure and personalized raw data for subsequent quantization coding and token generation. Among them, the quantum random number sequence can be obtained through a random number generator (QRNG), and the quantum random number sequence has a high entropy value (≥2.8bits / ns), ensuring the unpredictability and pure randomness of the data. The user behavior trajectory can be obtained by capturing the dynamic characteristics of the user's interaction with the client system, such as real-time monitoring and recording the movement path of the pointer (such as the cursor corresponding to the mouse) on the system interface during user operation.
[0048] Step S204: quantum state encoding is performed on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory.
[0049] In step S204, the collected user behavior trajectory data is converted into a quantum state representation. Through quantization encoding, the coordinate information in the trajectory is converted into quantum-like amplitude and phase. This process utilizes the principles of quantum mechanics to map the behavior of classical physical space to the space of qubits, increasing the complexity and non-cloning properties of the data.
[0050] Step S206: A post-quantum encryption algorithm is used to generate a quantum token based on the quantum random number sequence, the quantized coding characteristics, and the preset timestamp. The quantum token is the information required for user identity authentication in a cross-site request forgery attack scenario.
[0051] In step S206, a quantum token is generated using a post-quantum encryption algorithm (such as CRYSTALS-Kyber and Dilithium) by combining a quantum random number sequence, quantized encoding features, and a preset timestamp. This algorithm is capable of withstanding attacks from quantum computers, ensuring the security and integrity of the quantum token. The addition of a timestamp further enhances the token's timeliness, keeping it valid for a short period of time and reducing the possibility of replay attacks.
[0052] Through steps S202 to S206, the goal of significantly improving CSRF attack defense in the post-quantum computing era is achieved, thereby implementing a high-level authentication mechanism and effectively ensuring the security and stability of web applications in the face of advanced attack techniques. This resolves the technical issues that CSRF defense mechanisms in related technologies are unable to effectively defend against automated attacks supported by quantum computing, token cracking, and timing prediction attacks. This is explained in detail below.
[0053] In the above step S202, obtaining the quantum random number sequence includes: when the user logs in to the client system and the client system interface is in a blank loading state, starting a quantum random number generator; obtaining quantum random data from physical quantum effects through the quantum random number generator, and initializing an entropy pool, wherein the entropy pool is used to store the quantum random data, and the entropy value of the entropy pool is greater than 2.8 bits / ns, and the quantum random number generator updates the quantum random data once every preset time period; obtaining a preset amount of quantum random data from the entropy pool to obtain a quantum random number sequence.
[0054] In this embodiment of the present application, the acquisition of the quantum random number sequence will be started when the user logs into the client system and is in a blank loading state. The purpose is to ensure that the system environment is as pure as possible and free of any predictable data elements before the quantum token is generated. The specific analysis is as follows:
[0055] 1. Quantum entropy initialization.
[0056] The system first activates a quantum random number generator (QRNG), such as an ID Quantique device, which uses physical quantum effects (for example, quantum noise, uncertainty in quantum states, etc.) to generate quantum random data and form an initial entropy pool. The entropy value of the entropy pool is ≥2.8 bits / ns, which is much higher than the quality achieved by traditional random number generators.
[0057] 2. Obtain quantum random number sequence.
[0058] A predetermined amount of quantum random data is extracted from the entropy pool to form a quantum random number sequence. This sequence not only possesses all the security properties of traditional random numbers, but also incorporates the advantages of quantum randomness, providing a high-quality random seed for subsequent quantum encoding and token generation. Because its entropy value is significantly higher than conventional standards, the quantum random number sequence becomes a key component of the system's generation of quantum tokens that are difficult to copy or predict.
[0059] 3. Dynamic quantum data update.
[0060] It's important to note that the quantum random number generator doesn't operate statically; instead, it automatically updates its quantum random data at periodic intervals (e.g., every 500ms). This mechanism ensures that the data in the entropy pool always remains up-to-date and highly random, further strengthening the system's anti-predictability and anti-attack capabilities. Each update draws a new data sample from physical quantum effects, ensuring that the quantum random number sequence in the entropy pool doesn't repeat or develop patterns over time, maintaining its security and effectiveness in quantum computing environments.
[0061] In the above process, quantum data collection technology is used to ensure that the random number sequence generated from the source has quantum-level unpredictability and security, providing a strong foundation for subsequent quantum encoding of user behavior trajectories and token generation.
[0062] Furthermore, after obtaining the user behavior trajectory, the method also includes: determining the pointer coordinate data in the user behavior trajectory; performing a quantum Fourier transform on the pointer coordinate data to convert the pointer movement path in the time domain into quantum amplitude and phase information in the frequency domain to obtain a quantum bit feature corresponding to the user behavior trajectory; using the learning error algorithm in the lattice code to determine the error tolerance for noise filtering of the quantum bit feature, and filtering the noise signal in the quantum bit feature that is greater than the error tolerance.
[0063] In the embodiment of the present application, after obtaining the user behavior trajectory, a series of quantization processes are performed immediately to convert the coordinate data of the classic pointer (such as the cursor corresponding to the mouse in the client system interface) into quantum information in the frequency domain, thereby extracting more secure behavioral characteristics. The specific process can be as follows:
[0064] 1. Determine the pointer coordinate data in the user behavior trajectory.
[0065] First, all the pointer movement coordinates on the user interface are obtained to form a series of (x, y) point sets, which represent the trajectory records left by the user during the operation.
[0066] 2. Quantum Fourier transform.
[0067] Using the quantum Fourier transform (QFT), the pointer movement path in the time domain is converted into the corresponding quantum amplitude and phase information in the frequency domain to obtain the qubit characteristics. Among them, QFT can reveal the inherent patterns of trajectory data, especially those subtle changes that are difficult to detect at the macro level, and thus convert them into a series of quantum state amplitude and phase values. The specific quantization sampling formula can be as follows:
[0068]
[0069] Where (x, y) represents the coordinates of the pointer movement; e iπx / 1024 represents the quantum state in complex form obtained by transforming the coordinate x; e iπy / 768 represents the quantum state in complex form obtained by transforming the coordinate y; Represents the tensor product, which is used to combine the quantum states after the transformation of coordinates x and y into an overall quantum bit feature Ψ(x, y).
[0070] 3. The learning error algorithm in lattice cryptography filters quantum noise.
[0071] To ensure the purity and accuracy of qubit signatures, the Learning With Error (LWE) algorithm from lattice cryptography can be used to determine the error tolerance for noise filtering. The LWE algorithm effectively distinguishes between signal and noise. By setting a reasonable error threshold (<0.05), the system can filter out noise signals in qubit signatures that exceed this threshold, preserving the true quantum characteristics of user behavior and improving the robustness of the entire defense system.
[0072] Through the above process, not only can the user's unique operating patterns be captured, but these patterns can also be converted into quantum state encoding, effectively integrating the advantages of quantum computing with the secure processing of user behavior data, laying a solid foundation for generating unforgeable quantum tokens.
[0073] In step S204, quantum state encoding is performed on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory, including: determining a quantum gate operation for quantum state encoding of the user behavior trajectory based on quantum amplitude and phase information; and converting the quantum bit feature into a quantized coding feature based on the quantum gate operation. The quantized coding feature is an 8×8 quantum gate operation sequence, and each quantum gate represents an operation on the quantum bit feature.
[0074] In the embodiments of this application, the quantum amplitude and phase information extracted from the user's behavior trajectory can be used to determine the appropriate quantum gate operation. Quantum gates are a fundamental component of quantum circuit design. Each quantum gate represents a specific quantum operation, such as a Hadamard gate, a CNOT gate, or a Phase gate. These gates act together on the quantum bit (qubit) to reproduce the quantized encoding characteristics of the user's behavior trajectory.
[0075] The user's behavior trajectory is then mapped into an 8×8 sequence of quantum gate operations. This means that the system organizes quantum gate operations in a matrix format, with each quantum gate representing a quantum operation on a specific qubit feature. This matrix encoding is not only compact but also enables efficient quantum circuit deployment using open-source quantum computing frameworks such as IBM Qiskit, significantly improving encoding speed and applicability. The position and type of each quantum gate in the sequence are determined by the user's actual behavior, making the encoding characteristics closely tied to the individual user's behavioral patterns and making it more difficult to imitate and replicate.
[0076] Therefore, the generation of quantum coded signatures involves more than simple data conversion; rather, it deeply integrates the physical properties of user behavior with the flexibility and security of quantum information processing. Through carefully designed quantum gate operations, user behavior traces are transformed into a series of quantum state amplitude and phase values, which are then further integrated into the quantum coded signature. This process leverages the unclonability of quantum states and the post-quantum computing security of lattice cryptography to establish a personalized and secure foundation for user authentication.
[0077] In the above step S206, a post-quantum encryption algorithm is used to generate a quantum token based on the quantum random number sequence, the quantized coding feature and the preset timestamp, including: generating a quantum key based on the quantum random number sequence and the preset timestamp through the post-quantum encryption algorithm; generating an intermediate token based on the quantized coding feature; and signing the quantum key and the intermediate token using a post-quantum digital signature algorithm to obtain the quantum token.
[0078] Among them, generating an intermediate token based on the quantized coding characteristics includes: determining the user ID and quantum time standard deviation, where the quantum time standard deviation is used to represent the degree of fluctuation between quantum time marks during user operations; and using a post-quantum resistant hash algorithm to integrate the user ID, quantum time standard deviation and quantized coding characteristics to obtain the intermediate token.
[0079] In the embodiments of this application, a series of sophisticated post-quantum algorithm combinations are used to generate quantum tokens. The core mechanism is to cleverly combine quantum random number sequences, quantized coding features, and preset timestamps to produce quantum tokens with extremely high security and uniqueness. The specific process can be as follows:
[0080] 1. Quantum key generation.
[0081] First, the quantum random number sequence is combined with a preset timestamp accurate to the nanosecond level, and a dynamic quantum key is derived through a post-quantum encryption algorithm (such as CRYSTALS-Kyber). For example:
[0082] K dynamic =Kyber-768(K master ,t n )
[0083] Where K dynamic represents the generated dynamic quantum key; Kyber-768 represents the adopted post-quantum encryption algorithm; K master represents the master key, that is, the above quantum random number sequence; t n Indicates the aforementioned preset timestamp in nanoseconds.
[0084] Optionally, a timestamp t is preset nIt can be determined in the following ways: obtaining a quantum entangled photon pair; monitoring the decay process of the photons in the quantum entangled photon pair, and determining the decay time of the photon decay process, wherein the decay time is the time it takes for the first photon in the quantum entangled photon pair to transition from an excited state to a ground state; and generating a preset timestamp based on the decay time and the system time base.
[0085] In the embodiment of the present application, the preset timestamp t n The generation of quantum time is based on a unique mechanism based on the decay time of quantum entangled photon pairs. Specifically, the system first acquires a pair of entangled photons and then closely monitors the decay of one of the two photons from an excited state to its ground state. The recorded decay instant serves as the quantum time reference point. By comparing this decay time with the system's internal high-precision clock, a timestamp closely correlated with quantum random events can be generated with nanosecond-level accuracy.
[0086] The core of this mechanism is to utilize the uncertainty of quantum decay to ensure the essential randomness and unpredictability of the timestamp, thereby greatly enhancing the random factor in the token generation process and improving the security and anti-attack capabilities of the entire system.
[0087] 2. Intermediate token construction.
[0088] In the process of generating intermediate tokens, not only the quantum coding features are incorporated, but also the user ID and quantum time standard deviation are added. Among them, the quantum time standard deviation reflects the fluctuation of the quantum time mark during user operation, further enhancing the personalization and timeliness of the token.
[0089] By combining the user ID, quantum time standard deviation, and quantized coding features using a post-quantum-resistant hash algorithm (such as SHA3-512), an intermediate token is generated. This token not only contains the quantum characteristics of the user's behavior but is also closely linked to the user's identity and the time of the operation, forming a composite identifier that is difficult to predict or copy.
[0090] It should be noted that in this application, a post-quantum resistant hash algorithm (such as SHA3-512 quantum resistant hash) is used to replace the traditional hash algorithm (such as MD5 or SHA-256 hash algorithm). It complies with the NIST SP 800-208 standard and takes into account the possibility of quantum attacks. Through a more complex mathematical structure and a longer output length, it can resist the acceleration effect brought by the Grover search algorithm executed by a quantum computer, thereby greatly increasing the difficulty of the hash inverse operation and ensuring the security and integrity of the data summary.
[0091] 3. Quantum token generation.
[0092] The intermediate token and quantum key are signed using a post-quantum digital signature algorithm (such as CRYSTALS-Dilithium) to generate the final quantum token. For example:
[0093] Token=CRYSTALS-Dilithium(UID||QFT track||t n )
[0094] In the formula, Token represents the final quantum token generated, CRYSTALS-Dilithium represents the adopted post-quantum digital signature algorithm, UID represents the user ID, and QFT trajectory represents the quantized encoding feature.
[0095] Since the signature algorithm is also based on post-quantum standards such as lattice cryptography, the generated quantum token is not only difficult to imitate, but also can resist future quantum computer attacks, ensuring the long-term security and effectiveness of the entire token verification process.
[0096] In an embodiment of the present application, after the quantum token is generated, quantum token verification can be performed on the server to ensure the security of the Web system.
[0097] Specifically, first, the quantum secure hash function QHF can be used to process the quantum token (Token_client) provided by the client, and the result can be accurately compared with the expected token hash value (QHF(Token_server)) automatically generated by the server. This process is based on the quantum-resistant algorithm of lattice theory. Even in the face of the accelerated computing power of quantum computers, it can ensure the one-way nature of the hash function, thereby effectively preventing the forgery or illegal use of tokens. Secondly, taking into account the uncertainty of quantum states in actual operations, a quantum tolerance verification mechanism is introduced to allow quantum state amplitude phase deviations within a certain range, specifically limited to less than π / 18 (approximately equal to 10°). This tolerance setting takes into account the errors of quantum measurements in the real world, while ensuring the strictness and credibility of the verification process, avoiding the erroneous rejection of legitimate tokens due to tiny quantum fluctuations.
[0098] In the above process, not only the quantum-resistant characteristics of quantum hashing are used to enhance the reliability of the verification link, but also a balance is achieved between security and user experience through reasonable quantum state tolerance settings, ensuring that user identities can be accurately identified and verified even in uncertain environments where quantum fluctuations exist, providing quantum-level security protection for CSRF defense of web applications.
[0099] In the embodiments of this application, an innovative defense system against CSRF attacks is also introduced. By quantifying the curvature of user behavior, accurately capturing the operation rhythm, and generating dynamic tokens at the quantum level, the system not only significantly improves the recognition and interception rate of automated attacks, but also enhances the security of the token itself, making it resistant to quantum cracking. This series of technical features work together to form a multi-dimensional, multi-layered quantum encryption defense system, providing unprecedented security protection for web applications. The specific analysis is as follows:
[0100] 1. Curvature dynamic calculation model and trajectory curvature quantification algorithm.
[0101] The specific steps may include: determining the quantum curvature of the user behavior trajectory through a trajectory curvature quantization algorithm, wherein the quantum curvature is used to represent the curvature of the surface of the user behavior trajectory; when the quantum curvature is within a first preset range, determining that the user behavior trajectory is a real user operation; when the quantum curvature is within a second preset range, determining that the user behavior trajectory is a potential automated attack behavior, wherein the second preset range is larger than the first preset range.
[0102] The purpose of this algorithm is to accurately distinguish between natural human operations and counterfeit behaviors of automated scripts, especially for automated requests commonly seen in CSRF attacks. By constructing a quantum instantaneous curvature formula, the system can effectively capture quantum behavior patterns unique to human operations, such as subtle changes and nonlinear characteristics in the pointer movement path. Based on the calculated quantum curvature, that is, the degree of curvature of the surface of the user's operation trajectory, two different preset ranges are set: the first preset range corresponds to the quantum curvature fluctuation range of normal human operations, such as 0.12±0.03; and the second preset range covers larger quantum curvature changes, such as >0.28, which are usually associated with non-human automated operations. The specific expression can be as follows:
[0103]
[0104] Where K p Represents the quantum curvature of the user's behavior trajectory, Δt 2 represents the time interval, <ψ i-1 |ψ i+1 > represents the inner product within the quantum state at time points i-1 and i+1.
[0105] When the curvature of the monitored user behavior trajectory falls within the first preset range, the system determines that these operations are derived from real user interactions and allows them to continue normal business processes. Conversely, if the trajectory curvature falls into the second preset range, this indicates that the operation may be abnormal, perhaps an automated script or malware attempting to imitate human behavior. In this case, the system will trigger a warning mechanism and take defensive measures as appropriate, such as requiring secondary verification, restricting account activity, or directly blocking suspicious operations.
[0106] This technical feature corresponds to the in-depth analysis and refined identification of user behavior in the CSRF defense system, greatly improving the accuracy of attack identification, jumping from 98.6% to 99.92%, effectively curbing the intrusion of automated scripts.
[0107] 2. Quantum time lock and operation rhythm feature extraction.
[0108] The concept of "quantum time lock" is introduced in the operation rhythm feature extraction technology, aiming to significantly improve the CSRF defense mechanism's resistance to automated attacks through precise control of quantum secure timestamps. The accuracy of the above-mentioned preset timestamps reaches the nanosecond level (t n =10 -9 ) seconds), which far exceeds the conventional timing unit, making it almost impossible for attackers to imitate or predict the precise moment of user operations through traditional time prediction or synchronization techniques, thereby building effective quantum anti-prediction.
[0109] At the same time, the quantum decoherence time comparison (threshold <3ns) in the technical characteristics, as an advanced form of time standard deviation, can not only detect tiny fluctuations in the time series, but also identify whether these fluctuations are caused by the natural decay of quantum physics effects or are affected by malicious behavior.
[0110] The specific expression can be as follows:
[0111]
[0112] Where, represents the quantum time standard deviation, t k represents the value of the kth timestamp, represents the sum of all timestamps, Indicates the average value of timestamps.
[0113] This technical feature corresponds to the protection requirements against timing attacks in CSRF defense, especially in high-risk scenarios such as payment verification. It can effectively block up to 99.7% of automated attack attempts, improving the overall security of the system.
[0114] 3. Post-quantum key derivation and quantum composite encryption.
[0115] 1) Dynamic token generation technology:
[0116] In the embodiment of the present application, post-quantum key derivation is based on the MLWE problem, and its quantum cracking resistance requires the completion of ≥2 143 Sub-lattice operations significantly exceed the computational feasibility of current and even future quantum computers, ensuring the quantum unbreakable nature of the key and reaching the SLH-128 security level established by NIST.
[0117] The specific expression can be as follows:
[0118]
[0119] Where K dynamic represents the generated dynamic quantum key; Kyber-768 represents the adopted post-quantum encryption algorithm; K master represents the master key, that is, the above quantum random number sequence; t n Indicates the aforementioned preset timestamp in nanoseconds.
[0120] This upgrade reduces the risk window for key leakage from 24 hours to 3 seconds, greatly compressing the potential exploitation time of attackers, while also proving that its anti-cracking strength reaches the 128-bit security standard.
[0121] 2) Quantum composite encryption:
[0122] In terms of quantum composite encryption, quantum signatures are generated mainly by constructing intermediate tokens and applying the CRYSTALS-Dilithium signature algorithm.
[0123] The specific expression can be as follows:
[0124]
[0125] Token final =CRYSTALS-Dilithium(Token mid ||K dynamic )
[0126] Where, Token mid Indicates the intermediate token, Token final represents the final generated quantum token, ∑ψ traj The sum of quantum state sequences representing user behavior trajectories.
[0127] This process is not only highly efficient, taking only 1.2ms to complete in the Intel SGX environment, but also has made a significant breakthrough in resisting quantum man-in-the-middle attacks, reducing the attack success rate from 0.0007% to 10%. -9In cross-border payment systems, this improvement significantly reduces the success rate of man-in-the-middle attacks by 95.3% (from 0.15% to 0.0007%), while ensuring extremely high system availability (99.99%). This nearly exponential reduction means that dynamic tokens can maintain extremely high reliability and security even in complex attack scenarios in a quantum computing environment.
[0128] Figure 3 This is a schematic diagram of a quantum token verification process according to an embodiment of the present application. Figure 3 As shown, the overall process includes the following steps:
[0129] S1: The user starts using the system.
[0130] S2: The user logs into the system, and the interface is in a blank loading state.
[0131] S3: The client sends a request to the server to obtain a token. At this point, the client starts the QRNG and initializes the entropy pool to ensure the security of the request.
[0132] S4: The client receives the token returned by the server, starts loading the page and sends a data request to the server.
[0133] S5: Server verification token.
[0134] S6: If the server fails to verify the token (e.g. the token is invalid, expired, or tampered with), the user is forced to log out of the system to prevent unauthorized access.
[0135] S7: If the server successfully verifies the token, continue with the following operations.
[0136] S8: The client receives the data and renders the page. When the user operates the page, the user's activity (user behavior) trajectory (i.e., the pointer movement path) is recorded, combined with the preset timestamp, to generate an encrypted token and send it to the server.
[0137] S9: The server verifies the token again.
[0138] S10: If the server fails to verify the token, the user is also forced to log out of the system.
[0139] S11: If the server successfully verifies the token, the page renders normally and the user can use the system functions normally.
[0140] Overall, this application has implemented a comprehensive quantum technology upgrade for web application CSRF defense strategies. Its features and advantages are reflected in the following key technical points, which form a sharp contrast with related technologies:
[0141] 1. Data Collection
[0142] Advantages: When collecting user behavior data, a quantum random number generator (QRNG), such as the IDQ chip, is used to generate 128 bits of true random quantum coordinate code per second, making the behavior trajectory unpredictable at the physical level.
[0143] Comparison: Compared to traditional systems that rely on the JavaScript Math.random() function, which has an entropy limit of only 53 bits and is easily predictable and impersonable, the quantum random number generation proposed in this application significantly improves the randomness and security of data, increasing its anti-prediction capabilities by over 300 times.
[0144] 2. Token generation:
[0145] Advantages: Uses the CRYSTALS-Dilithium post-quantum signature algorithm, combined with SHA3-512 quantum hashing and a dynamic 500ms time window to generate tokens, and implements lightweight quantum signatures with the support of the Web Crypto API.
[0146] Comparison: Traditional hash algorithms such as RSA / SHA256 are vulnerable to quantum computers. Shor's algorithm can crack 2048-bit RSA in a few hours. In contrast, the token generation technology of this application is highly resistant to quantum cracking. According to the NIST Level 3 standard, it is estimated that it will take 10 34 years of computing time, demonstrating strong defense against quantum computing attacks.
[0147] 3. Data processing:
[0148] Advantages: Utilizes the Quantum Fourier Transform (QFT) to analyze the quantum frequency domain characteristics of trajectories in real time. With WebGL acceleration, it can process tens of thousands of trajectory points per second and filter out automated attack noise.
[0149] In contrast, traditional mean filtering can only eliminate basic mechanical noise and is ineffective against quantum simulation attacks. The quantum feature extraction algorithm in this application can effectively detect phase deviations (>0.1 radians) caused by non-human manipulation, with a false alarm rate of <0.01%, significantly enhancing data processing accuracy and anti-attack performance.
[0150] 4. Token Verification:
[0151] Advantages: The server has a built-in quantum security verification module that can complete the decryption and trajectory restoration of quantum tokens within 300ms. The dynamic nanosecond timestamp resists replay attacks and is compatible with the HTTP / 2 protocol for instant verification.
[0152] In contrast, during traditional JWT verification, full token decoding exposes potential security vulnerabilities, particularly the risk of timing attacks. This application's quantum signature verification only requires comparing hash quantum states, significantly increasing verification speed by 5 times without leaking sensitive information, setting a new benchmark for real-time security verification.
[0153] 5. Data encoding:
[0154] Advantages: Encoding quantized trajectory data into a 128-bit quantum-resistant string using Kyber-768 encoding greatly improves transmission efficiency.
[0155] Comparison: Compared with the 33% data expansion problem of Base64 encoding, the data encoding method of this application reduces the network transmission load by 62% while maintaining the same security strength, greatly optimizing data transmission efficiency, especially in weak network environments on mobile terminals, where its advantages are more obvious.
[0156] In summary, this application fundamentally changes the landscape of CSRF defense by integrating a series of quantum technology means, including quantum random number generation, post-quantum algorithm encryption, quantum frequency domain feature analysis, quantum-level verification, and efficient quantum coding. It provides a security barrier for Web applications in the quantum computing era, significantly improves data security and user experience quality, and demonstrates an important development direction for future network security defense.
[0157] According to an embodiment of the present application, a device for generating a quantum token is provided. It should be noted that the device for generating a quantum token in the embodiment of the present application can be used to execute the method for generating a quantum token provided in the embodiment of the present application. The following describes the device for generating a quantum token provided in the embodiment of the present application.
[0158] Figure 4 This is a structural diagram of a quantum token generation device provided according to an embodiment of the present application. Figure 4 As shown, the device includes:
[0159] An acquisition module 40 is used to acquire a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent a pointer movement path corresponding to a user operation on a client interface;
[0160] The encoding module 42 is used to perform quantum state encoding on the user behavior trajectory to obtain a quantized encoding feature corresponding to the user behavior trajectory;
[0161] The generation module 44 is used to generate a quantum token based on a quantum random number sequence, quantized coding characteristics and a preset timestamp using a post-quantum encryption algorithm, wherein the quantum token is the information required for user authentication in a cross-site request forgery attack scenario.
[0162] Through the acquisition module, encoding module and generation module in the above-mentioned quantum token generation device, the goal of significantly improving the CSRF attack defense level in the post-quantum computing era is achieved, thereby realizing a high-level identity authentication mechanism, effectively ensuring the security and stability of Web applications in the face of advanced attack technologies, and thus solving the technical problems that the CSRF defense mechanism in related technologies cannot effectively resist automated attacks supported by quantum computing, tokens are easy to crack and timing prediction attacks.
[0163] In the quantum token generation device provided in an embodiment of the present application, the acquisition module is also used to start the quantum random number generator when the user logs in to the client system and the client system interface is in a blank loading state; obtain quantum random data from physical quantum effects through the quantum random number generator, and initialize the entropy pool, wherein the entropy pool is used to store quantum random data, and the entropy value of the entropy pool is greater than 2.8 bits / ns, and the quantum random number generator updates the quantum random data once every preset time period; obtain a preset amount of quantum random data from the entropy pool to obtain a quantum random number sequence.
[0164] In the quantum token generation device provided in the embodiment of the present application, the acquisition module is also used to determine the pointer coordinate data in the user behavior trajectory; perform quantum Fourier transform on the pointer coordinate data, convert the pointer movement path in the time domain into quantum amplitude and phase information in the frequency domain, and obtain the quantum bit characteristics corresponding to the user behavior trajectory; use the learning error algorithm in the lattice code to determine the error tolerance for noise filtering of the quantum bit characteristics, and filter the noise signals in the quantum bit characteristics that are greater than the error tolerance.
[0165] In the quantum token generation device provided in the embodiment of the present application, the encoding module is also used to determine the quantum gate operation for quantum state encoding of the user behavior trajectory based on the quantum amplitude and phase information; based on the quantum gate operation, the quantum bit feature is converted into a quantized coding feature, wherein the quantized coding feature is an 8×8 quantum gate operation sequence, and each quantum gate represents an operation on the quantum bit feature.
[0166] In the quantum token generation device provided in the embodiment of the present application, the generation module is also used to generate a quantum key based on a quantum random number sequence and a preset timestamp through a post-quantum encryption algorithm; generate an intermediate token based on the quantized coding characteristics; and sign the quantum key and the intermediate token using a post-quantum digital signature algorithm to obtain a quantum token.
[0167] In the quantum token generation device provided in the embodiment of the present application, the generation module is also used to determine the user ID and quantum time standard deviation, where the quantum time standard deviation is used to indicate the degree of fluctuation between quantum time marks during user operation; the user ID, quantum time standard deviation and quantized coding features are integrated using a post-quantum resistant hash algorithm to obtain an intermediate token.
[0168] In the quantum token generation device provided in the embodiment of the present application, the generation module is also used to obtain quantum entangled photon pairs; monitor the photon decay process in the quantum entangled photon pairs, and determine the decay time of the photon decay process, wherein the decay time is the time for the first photon in the quantum entangled photon pair to transition from an excited state to a ground state; and generate a preset timestamp based on the decay time and the system time reference.
[0169] The quantum token generation device provided in the embodiment of the present application also includes a determination module 46, which is used to determine the quantum curvature of the user behavior trajectory through a trajectory curvature quantization algorithm, wherein the quantum curvature is used to represent the curvature of the surface of the user behavior trajectory; when the quantum curvature is within a first preset range, the user behavior trajectory is determined to be a real user operation; when the quantum curvature is within a second preset range, the user behavior trajectory is determined to be a potential automated attack behavior, wherein the second preset range is larger than the first preset range.
[0170] An embodiment of the present application also provides an electronic device, including: a memory and a processor, wherein the memory is used to store program instructions; the processor is connected to the memory and is used to execute the above-mentioned method for generating a quantum token.
[0171] It should be noted that the above electronic equipment is used to perform Figure 2 The method for generating a quantum token shown in the figure, therefore the relevant explanations in the above method for generating a quantum token also apply to the electronic device and will not be repeated here.
[0172] An embodiment of the present application also provides a non-volatile storage medium, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-mentioned method for generating a quantum token by running the computer program.
[0173] It should be noted that the above non-volatile storage medium is used to execute Figure 2 The method for generating a quantum token shown in the figure is used. Therefore, the relevant explanations in the above method for generating a quantum token are also applicable to the non-volatile storage medium and will not be repeated here.
[0174] An embodiment of the present application also provides a computer program product, including computer instructions, which, when executed by a processor, implement the above-mentioned method for generating a quantum token.
[0175] It should be noted that the above-mentioned computer program product is used to execute Figure 2 The method for generating a quantum token shown in the figure, therefore the relevant explanations in the above-mentioned method for generating a quantum token also apply to the computer program product and will not be repeated here.
[0176] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0177] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0178] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0179] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0180] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0181] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0182] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for generating a quantum token, characterized in that: include: Obtaining a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent a pointer movement path corresponding to a user operation on a client interface; Performing quantum state encoding on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory; A post-quantum encryption algorithm is used to generate a quantum token based on the quantum random number sequence, the quantized coding characteristics and a preset timestamp, wherein the quantum token is the information required for user identity authentication in a cross-site request forgery attack scenario.
2. The method according to claim 1, characterized in that Get quantum random number sequence, including: When a user logs in to the client system and the client system interface is in a blank loading state, starting the quantum random number generator; Obtaining quantum random data from physical quantum effects through the quantum random number generator and initializing an entropy pool, wherein the entropy pool is used to store the quantum random data, and the entropy value of the entropy pool is greater than 2.8 bits / ns, and the quantum random number generator updates the quantum random data once every preset time period; A preset amount of quantum random data is obtained from the entropy pool to obtain the quantum random number sequence.
3. The method according to claim 1, characterized in that After obtaining the user behavior trajectory, the method further includes: Determining pointer coordinate data in the user behavior trajectory; Performing a quantum Fourier transform on the pointer coordinate data to convert the pointer movement path in the time domain into quantum amplitude and phase information in the frequency domain to obtain a quantum bit feature corresponding to the user behavior trajectory; A learning error algorithm in a lattice code is used to determine an error tolerance for noise filtering of the qubit feature, and noise signals in the qubit feature that are greater than the error tolerance are filtered.
4. The method according to claim 3, characterized in that Performing quantum state encoding on the user behavior trajectory to obtain a quantized coding feature corresponding to the user behavior trajectory includes: Determining a quantum gate operation for quantum state encoding of the user behavior trajectory based on the quantum amplitude and phase information; The qubit feature is converted into the quantized coding feature according to the quantum gate operation, wherein the quantized coding feature is an 8×8 quantum gate operation sequence, and each quantum gate represents an operation on the qubit feature.
5. The method according to claim 1, wherein A post-quantum encryption algorithm is used to generate a quantum token based on the quantum random number sequence, the quantized coding feature and a preset timestamp, including: Generate a quantum key according to the quantum random number sequence and the preset timestamp using the post-quantum encryption algorithm; generating an intermediate token based on the quantized coding feature; The quantum token is obtained by signing using a post-quantum digital signature algorithm based on the quantum key and the intermediate token.
6. The method according to claim 5, characterized in that Generating an intermediate token according to the quantized coding feature, comprising: Determining a user ID and a quantum time standard deviation, wherein the quantum time standard deviation is used to represent the degree of fluctuation between quantum time marks during user operation; A post-quantum resistant hash algorithm is used to integrate the user ID, the quantum time standard deviation and the quantized coding feature to obtain the intermediate token.
7. The method according to claim 1, characterized in that The preset timestamp is determined by: Obtain quantum entangled photon pairs; Monitoring the photon decay process of the quantum entangled photon pair and determining the decay time of the photon decay process, wherein the decay time is the time it takes for the first photon in the quantum entangled photon pair to transition from an excited state to a ground state; The preset timestamp is generated according to the decay time and a system time reference.
8. The method according to claim 1, characterized in that The method further comprises: Determining the quantum curvature of the user behavior trajectory by a trajectory curvature quantization algorithm, wherein the quantum curvature is used to represent the curvature of the surface of the user behavior trajectory; When the quantum curvature is within a first preset range, determining that the user behavior trajectory is a real user operation; When the quantum curvature is within a second preset range, the user behavior trajectory is determined to be a potential automated attack behavior, wherein the second preset range is larger than the first preset range.
9. A device for generating a quantum token, characterized in that: include: An acquisition module, configured to acquire a quantum random number sequence and a user behavior trajectory, wherein the user behavior trajectory is used to represent a pointer movement path corresponding to a user operation on a client interface; An encoding module, configured to perform quantum state encoding on the user behavior trajectory to obtain a quantized encoding feature corresponding to the user behavior trajectory; A generation module is used to generate a quantum token based on the quantum random number sequence, the quantized coding characteristics and a preset timestamp using a post-quantum encryption algorithm, wherein the quantum token is the information required for user authentication in a cross-site request forgery attack scenario.
10. An electronic device, characterized in that: include: A memory and a processor, wherein the memory is used to store program instructions; The processor is connected to the memory and is used to execute the method for generating a quantum token according to any one of claims 1 to 8.
11. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the method for generating a quantum token according to any one of claims 1 to 8 by running the computer program.
12. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the method for generating a quantum token according to any one of claims 1 to 8 is implemented.