Anti-quantum-attack SM2 key exchange method and anti-quantum-attack SM2 key exchange system
By integrating and optimizing the algorithms for both initiating and responding users, multiple algorithmic sub-strategies are established, and a dual-cryptographic encryption model is constructed. This solves the security problem of SM2 key exchange under quantum attacks and achieves efficient and secure key exchange.
Patent Information
- Application Number
- CN202511501557.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-21
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-10-21
AI Technical Summary
The existing SM2 key exchange method is not secure enough against quantum computer attacks and cannot effectively resist quantum attacks, resulting in the failure of communication confidentiality and identity authenticity.
By integrating the algorithms for initiating and responding users, multiple algorithmic sub-strategies are established. The best strategy is selected based on performance optimization results, and a dual-password encryption model is constructed. Periodic monitoring and early warning are performed, and the algorithmic sub-strategies are modified to improve security and adaptability.
It improves the efficiency and security of SM2 key exchange, reduces the harm of quantum attacks, ensures the security of the communication process, and enhances the ability to adapt to different communication scenarios.
Smart Images

Figure CN120979665A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of key exchange, in particular to an SM2 key exchange method and system resisting quantum attacks. BACKGROUND
[0002] Public key cryptography algorithm is the cornerstone of modern information security system, and is widely used in digital identity authentication, secure data transmission, virtual private network (VPN) and other key fields. With the rapid development of quantum computing technology, such a cryptography system based on traditional number theory problems is facing an unprecedented survival threat.
[0003] A quantum computer can achieve exponential speedup operation on certain mathematical problems by using quantum superposition and entanglement characteristics. Quantum algorithms such as Shor algorithm can effectively solve large integer factorization and discrete logarithm problems, which means that once a large-scale general-purpose quantum computer is successfully developed, the existing widely deployed RSA, ECC and SM2 public key cryptography systems will be completely cracked, resulting in complete failure of the communication confidentiality and identity authenticity guaranteed by these algorithms. SUMMARY
[0004] The purpose of the present application is to solve the above technical problems, and the present application provides an SM2 key exchange method and system resisting quantum attacks, aiming to improve the security of SM2 key exchange and reduce the harm of quantum attacks.
[0005] In some embodiments of the present application, by fusing the algorithms of the initiating user and the responding user, multiple algorithm sub-strategies are established, and the best algorithm sub-strategy is selected according to the performance optimization result, thereby improving the efficiency and security of SM2 key exchange. At the same time, by periodically monitoring the communication state, the quantum attack risk is warned in time, and the algorithm sub-strategy is corrected, thereby reducing the harm of quantum attacks.
[0006] In some embodiments of the present application, by constructing a double encryption model, the security of communication can be ensured when a single type of password is cracked, the risk of intrusion in the communication process is reduced, and different types of quantum algorithms can be added at any time through modular design, thereby improving the adaptability to different communication scenarios.
[0007] In some embodiments of the present application, an SM2 key exchange method resisting quantum attacks is provided, which comprises: The initiating user establishes an algorithm strategy set according to the algorithm feedback parameters of the responding user; A first algorithm strategy is set according to the algorithm strategy set, and an interactive key set of the initiating user and the responding user is constructed according to the first algorithm strategy; Communication monitoring data is obtained, and it is judged whether to correct the first algorithm strategy according to the communication monitoring data.
[0008] In some embodiments of the application, a set of algorithm strategies is established, including: The initiating user constructs a second set of algorithms according to the algorithm feedback parameters of the responding user; Obtain the first set of algorithms of the initiating user; Generate a primary SM2 algorithm and a quantum algorithm sequence A according to the fusion result of the first set of algorithms and the second set of algorithms; A=(a1, a2…a i …a n ), wherein a i is the i-th primary quantum algorithm; n is the number of primary quantum algorithms; Establish a set of algorithm strategies B according to the primary SM2 algorithm and the quantum algorithm sequence A; B=(b1, b2…b i …b n ), wherein b i is the i-th algorithm sub-strategy; n is the number of algorithm sub-strategies; the algorithm sub-strategy b i includes the primary SM2 algorithm and the i-th primary quantum algorithm.
[0009] In some embodiments of the application, a primary algorithm strategy is set, including: According to the set of algorithm strategies B, set b i as the target sub-strategy in turn; Generate a performance evaluation value c of the target sub-strategy; c=[ β i ×j i ]; Wherein θ1 is the number of performance indicators; β i is the influence factor of the i-th performance indicator; j i is the expected reference value of the i-th performance indicator in the target sub-strategy; Generate the performance evaluation value of each algorithm sub-strategy in turn; Establish a performance evaluation value sequence C, C=(c1, c2…c i …c n ), wherein c i is the performance evaluation value of the i-th algorithm sub-strategy; Set the algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C as the primary algorithm strategy; Set the primary quantum algorithm in the primary algorithm strategy as an auxiliary quantum algorithm; Generate a synchronization instruction of the primary algorithm strategy; The primary algorithm strategy includes: The auxiliary quantum algorithm, the primary algorithm strategy includes: The first-level SM2 algorithm, the first-level initiating SM2 public key, the first-level responding SM2 public key, the auxiliary quantum algorithm, and the first-level responding quantum public key.
[0010] In some embodiments of the present application, the interaction key set of the initiating user and the responding user is constructed, including: The responding user acquires a first-level algorithm strategy according to the synchronization instruction; The initiating user generates an initial interaction package based on the first-level algorithm strategy and sends the initial interaction package to the responding user; The responding user acquires the initial interaction package and generates a verification value f of the initial interaction package; A preset verification value threshold F1 is set; If f>F1, the responding user generates a feedback interaction package and sends the feedback data package to the initiating user; A first shared secret is acquired according to the initial interaction package; A second shared secret is acquired according to the feedback data package; The first shared secret and the second shared secret are processed An interaction key set is constructed according to the processing result.
[0011] In some embodiments of the present application, the initial interaction package is generated, including: The initiating user generates a first shared secret; The first shared secret is encapsulated based on the first-level responding quantum public key, and a first-level encapsulant is generated; The initiating user generates a second-level initiating SM2 public key, a redundancy label, and a first-level initiating quantum public key; The initial interaction package is generated, and the initial interaction package includes: The first-level encapsulant, the second-level initiating public key, the redundancy label, and the first-level initiating quantum public key; A first-level verification structure of the initial interaction package is set.
[0012] In some embodiments of the present application, the responding user generates the feedback interaction package, including: The responding user generates a second shared secret; The second shared secret is encapsulated based on the first-level initiating quantum public key, and a second-level encapsulant is generated; The responding user generates a second-level responding SM2 public key; The feedback interaction package is generated, and the feedback interaction package includes: The second-level encapsulant, the second-level responding SM2 public key, and the first-level responding quantum public key; A second-level verification structure of the feedback data package is set.
[0013] In some embodiments of the present application, whether to correct the first-level algorithm strategy is judged, including: A plurality of monitoring periods are established, and an end time node of each monitoring period is set as a monitoring time node; The communication monitoring data of the current monitoring time node is acquired; A plurality of time intervals are set in the current monitoring period; A time interval sequence T is established, T=(t1, t2…t i …t m ), wherein t i is the i-th time interval of the current monitoring period; m is the number of time intervals of the current monitoring period; The communication risk value of each time interval is generated; The modified evaluation value d of the current time node is generated according to all the communication risk values; d=[ Y(i)×(k i -k')]; Wherein, ki is the communication risk value of the i-th time interval; k' is the communication risk value threshold; Y(i) is the selection coefficient; if (k i -k')>0; Y(i)=1; if (k i -k')<0; Y(i)=0; m is the number of time intervals in the current monitoring period; A modified evaluation value threshold D1 is preset; If d>D1, a modified instruction of a first-level algorithm strategy is generated.
[0014] In some embodiments of the application, the communication risk value of each time interval is generated, comprising: According to the time interval sequence T, t i is set as a target time interval in turn; The communication risk value k of the target time interval is generated according to the communication monitoring data; k=g×[ η i ×s i ]; g=U×[ β i ×v i ]; Wherein, g is the risk correction coefficient; θ2 is the number of attack risk indicators; η i is the i-th attack risk indicator; s i is the reference value of the i-th attack risk indicator of the target time interval generated based on the communication monitoring data; U is the conversion coefficient; θ1 is the number of performance evaluation indicators; β i is the i-th performance evaluation indicator; v i is the deviation value of the i-th performance evaluation indicator; The communication risk value of each time interval is generated in turn.
[0015] In some embodiments of this application, a quantum-resistant SM2 key exchange system is provided, comprising: The central control unit includes a first processing module and a second processing module; The initiating user obtains the algorithm feedback parameters from the responding user through the first processing module and establishes an algorithm strategy set; The second processing module is used to set the first-level algorithm strategy according to the algorithm strategy set; The second processing module is also used to construct the interaction key set of the initiating user and the responding user according to the first-level algorithm strategy; The monitoring unit is used to acquire communication monitoring data and determine whether to correct the primary algorithm strategy based on the communication monitoring data. The first processing module is also used for: A second algorithm set is constructed based on the algorithm feedback parameters from the responding users; Obtain the first algorithm set of the initiating user; The first-level SM2 algorithm and quantum algorithm sequence A are generated based on the fusion results of the first algorithm set and the second algorithm set; A=(a1, a2…a…) i …a n ), where a i Let be the i-th first-order quantum algorithm; n is the number of first-order quantum algorithms; Establish an algorithm strategy set B based on the first-level SM2 algorithm and the quantum algorithm sequence A; B = (b1, b2, ..., bb) i …b n ), where b i Let be the i-th algorithmic sub-policy; n is the number of algorithmic sub-policies; algorithmic sub-policy b i It includes the first-level SM2 algorithm and the i-th first-level quantum algorithm.
[0016] In some embodiments of this application, the second processing module is further configured to: b is set sequentially according to algorithm strategy set B. i For the target sub-strategy; The performance evaluation value c of the generated target sub-strategy; c=[ β i ×j i ]; Where θ1 represents the number of performance indicators; β i Let j be the influencing factor of the i-th performance index; i This is the expected reference value for the i-th performance metric in the target sub-strategy; Generate performance evaluation values for each algorithm sub-strategy in sequence; A performance evaluation value sequence C, C=(c1, c2…c i …c n ), is established, wherein c i is a performance evaluation value of the i-th algorithm sub-strategy; The algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C is set as a primary algorithm strategy; The primary quantum algorithm in the primary algorithm strategy is set as an auxiliary quantum algorithm; Synchronization instructions of the primary algorithm strategy are generated; The primary algorithm strategy comprises: The auxiliary quantum algorithm, the primary algorithm strategy comprises: The primary SM2 algorithm, the primary initiation SM2 public key, the primary response SM2 public key, the auxiliary quantum algorithm, and the primary response quantum public key.
[0017] Compared with the prior art, the SM2 key exchange method and system against quantum attacks according to the embodiments of the present application have the beneficial effects that: By fusing the algorithms of the initiation user and the response user, multiple algorithm sub-strategies are established, and the best algorithm sub-strategy is selected according to the performance optimization result, so that the SM2 key exchange efficiency and security are improved, and at the same time, the quantum attack risk is timely warned by periodically monitoring the communication state, and the algorithm sub-strategy is corrected, so that the harm of quantum attacks is reduced.
[0018] By constructing a double-cipher encryption model, the security of communication can be ensured when a single cipher type is cracked, and the intrusion risk in the communication process is reduced, and by modular design, different types of quantum algorithms can be added at any time, and the adaptability to different communication scenarios is improved. BRIEF DESCRIPTION OF DRAWINGS
[0019] Figure 1 is a flowchart of an SM2 key exchange method against quantum attacks according to a preferred embodiment of the present application. DETAILED DESCRIPTION
[0020] The specific embodiments of the present application will be further described in detail below in combination with the drawings and embodiments. The following embodiments are used to illustrate the present application, but not to limit the scope of the present application.
[0021] In the description of the present application, it needs to be understood that the terms "center", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.
[0022] The terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise stated, the meaning of "a plurality of" is two or more.
[0023] In the description of the present application, it needs to be explained that unless otherwise explicitly specified and limited, the terms "mounting", "connection", "connection" should be understood broadly, for example, it can be fixed connection, or detachable connection, or integrally connected; it can be mechanical connection, or electrical connection; it can be directly connected, or indirectly connected through intermediate medium, or the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0024] As Figure 1 shown, the anti-quantum attack SM2 key exchange method of the preferred embodiment of the present application comprises: S101: The initiator establishes an algorithm strategy set according to the algorithm feedback parameters of the responder; S102: Set the first algorithm strategy according to the algorithm strategy set, and construct the interactive key set of the initiator and the responder according to the first algorithm strategy; S103: Obtain communication monitoring data, and determine whether to modify the first algorithm strategy according to the communication monitoring data.
[0025] Specifically, the initiator refers to the initiator of communication, and the responder refers to the receiver of communication. The number of the initiator and the responder in the single communication process is preferably one.
[0026] Specifically, the algorithm strategy set is established, including: The initiator constructs a second algorithm set according to the algorithm feedback parameters of the responder; Obtain the first algorithm set of the initiator; Generate a first SM2 algorithm and a quantum algorithm sequence A according to the fusion result of the first algorithm set and the second algorithm set; A=(a1, a2…a…) i …a n ), where a i Let be the i-th first-order quantum algorithm; n is the number of first-order quantum algorithms; Establish an algorithm strategy set B based on the first-level SM2 algorithm and the quantum algorithm sequence A; B = (b1, b2, ..., bb) i …b n ), where b i Let be the i-th algorithmic sub-policy; n is the number of algorithmic sub-policies; algorithmic sub-policy b i It includes the first-level SM2 algorithm and the i-th first-level quantum algorithm.
[0027] Specifically, the second algorithm set includes the types of quantum algorithms that can be run by the responding user and the parameters of the SM2 algorithm to be run.
[0028] Specifically, the first algorithm set includes the types of quantum algorithms that can be run by the initiating user and the parameters of the SM2 algorithm to be run.
[0029] Specifically, quantum algorithm types include, but are not limited to, lattice-based quantum algorithms, hash-based quantum algorithms, encoding-based quantum algorithms, multivariate polynomial-based quantum algorithms, and homologous quantum algorithms.
[0030] And the first-level initiating SM2 public key (i.e., the long-term SM2 public key for initiating user filing).
[0031] Specifically, by fusing the two sets of algorithms, all quantum algorithms that can be run by both the initiating and responding users are extracted, and a first-level quantum algorithm sequence A is constructed. Each first-level quantum algorithm represents a quantum algorithm, and both the initiating and responding users can support the operation of that quantum algorithm.
[0032] Specifically, a first-level SM2 algorithm is generated based on the fusion result of the SM2 algorithm parameters of the initiating user and the responding user. The first-level SM2 algorithm includes a first-level response SM2 public key (i.e., the long-term SM2 public key registered by the responding user) and a first-level initiating SM2 public key (i.e., the long-term SM2 public key registered by the initiating user).
[0033] Specifically, the first-level SM2 algorithm is randomly combined with various first-level quantum algorithms, and multiple algorithm sub-policies are generated based on the combination results.
[0034] Specifically, the first-level algorithm strategy is defined, including: b is set sequentially according to algorithm strategy set B. i For the target sub-strategy; The performance evaluation value c of the generated target sub-strategy; c=[ β i ×j i ]; wherein, θ1 is the number of performance indicators; β i is the influence factor of the i th performance indicator; j i is the expected reference value of the i th performance indicator in the target sub-strategy; generate the performance evaluation value of each algorithm sub-strategy in turn; establish a performance evaluation value sequence C, C=(c1, c2…c i …c n ), wherein c i is the performance evaluation value of the i th algorithm sub-strategy; set the algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C as the first-level algorithm strategy; set the first-level quantum algorithm in the first-level algorithm strategy as the auxiliary quantum algorithm; generate the synchronization instruction of the first-level algorithm strategy; The first-level algorithm strategy includes: The auxiliary quantum algorithm, the first-level algorithm strategy includes: The first-level SM2 algorithm, the first-level initiating SM2 public key, the first-level responding SM2 public key, the auxiliary quantum algorithm and the first-level responding quantum public key.
[0035] Specifically, the performance evaluation indicators include but are not limited to algorithm signature efficiency, key exchange speed, resource occupation, security confidence and other parameters related to communication efficiency and security.
[0036] Specifically, by quantifying each performance evaluation indicator, each performance evaluation indicator is in the same value range. The greater the reference value of each performance evaluation indicator, the greater the advantage corresponding to the performance evaluation indicator.
[0037] Specifically, the influence factor of each performance evaluation indicator is set according to the actual communication demand of the initiating user and the responding user, so as to realize the optimization processing of different communication scenes.
[0038] Specifically, the greater the performance evaluation indicator, the higher the adaptability between the current algorithm sub-strategy and the communication demand of the current initiating user and the responding user.
[0039] Specifically, according to the auxiliary quantum algorithm, a temporary quantum key pair of the initiating user and the responding user is generated, so as to set the first-level responding quantum public key (i.e. the generated temporary quantum public key of the responding user).
[0040] It can be understood that, in the above embodiments, by fusing the algorithms of the initiator and the responder, multiple algorithm sub-strategies are established, and the best algorithm sub-strategy is selected according to the performance optimization result, so as to improve the efficiency and security of the SM2 key exchange.
[0041] In the preferred embodiments of the present application, the interactive key set of the initiator and the responder is constructed, including: The responder obtains a first algorithm strategy according to the synchronization instruction; The initiator generates an initial interactive package based on the first algorithm strategy and sends the initial interactive package to the responder; The responder obtains the initial interactive package and generates a verification value f of the initial interactive package; A preset verification value threshold F1 is set; If f>F1, the responder generates a feedback interactive package and sends the feedback data package to the initiator; A first shared secret is obtained according to the initial interactive package; A second shared secret is obtained according to the feedback data package; The first shared secret and the second shared secret are processed An interactive key set is constructed according to the processing result.
[0042] Specifically, the initiator and the responder perform mixed calculation on the first shared secret and the second shared secret by using the same key derivation function, construct a session master key, and generate multiple categories of temporary sub-keys according to the session demand, which are immediately and securely destroyed after performing the corresponding tasks. The interactive key set is constructed according to the session master key and all temporary sub-keys.
[0043] Specifically, the verification value f is generated according to the analysis result of the first verification structure. There is a risk of tampering with a single component, and the verification sub-value of the component is set to zero, and there is no risk of tampering, and the verification sub-value of the component is 1. The verification value f is generated according to the sum of the verification sub-values of all components.
[0044] Specifically, the preset verification value threshold F1 is preferably 3.
[0045] Specifically, the components of the first verification structure include a first encapsulation, a second initiator quantum public key, a redundancy label, and four digital signatures on the first initiator quantum public key.
[0046] Specifically, the initial interactive package is generated, including: The initiator generates a first shared secret; The first shared secret is encapsulated based on the first response quantum public key, and a first encapsulation is generated; The initiator generates a second initiator SM2 public key, a redundancy label, and a first initiator quantum public key; generating an initial interaction package, the initial interaction package comprising: a primary encapsulant, a secondary initiation public key, a redundancy label, and a primary initiation quantum public key; setting a primary verification structure of the initial interaction package.
[0047] Specifically, the first shared secret is a temporary secret randomly generated by the initiating user, which is encapsulated by the primary response quantum public key for processing, thereby generating a primary encapsulant, which can only be unsealed by the corresponding quantum private key of the responding user.
[0048] Specifically, the redundancy label is a random number generated by the responding user based on the demand of this session.
[0049] Specifically, the primary initiation quantum public key is a quantum public key of a temporary quantum key pair of the initiating user generated based on an auxiliary quantum algorithm.
[0050] Specifically, all data in the initial data package is digitally signed by using the long-term SM2 private key of the initiating user on record, thereby constructing a primary verification structure.
[0051] Specifically, the responding user generates a feedback interaction package, comprising: The responding user generates a second shared secret; The second shared secret is encapsulated based on the primary initiation quantum public key, and a secondary encapsulant is generated; The responding user generates a secondary response SM2 public key; generating a feedback interaction package, the feedback interaction package comprising: a secondary encapsulant, a secondary response SM2 public key, and a primary response quantum public key; setting a secondary verification structure of the feedback data package.
[0052] Specifically, the second shared secret is a temporary secret randomly generated by the responding user, which is encapsulated by the primary initiation quantum public key for processing, thereby generating a secondary encapsulant, which can only be unsealed by the corresponding quantum private key of the initiating user.
[0053] Specifically, all data in the initial data package is digitally signed by using the long-term SM2 private key of the responding user on record, thereby constructing a secondary verification structure.
[0054] It can be understood that in the above embodiment, by constructing a double password encryption model, the security of communication can be ensured when a single password type is cracked, and the risk of intrusion in the communication process is reduced.
[0055] In the preferred embodiment of the present application, the method comprises: Establish multiple monitoring cycles and set the end time node of each monitoring cycle as the monitoring time node; Obtain the communication monitoring data at the current monitoring time node; Set multiple time intervals within the current monitoring cycle; Establish a time interval sequence T, T = (t1, t2…t i …t m ), where t i is the i-th time interval of the current monitoring cycle; m is the number of time intervals in the current monitoring cycle; Generate the communication risk value for each time interval; Generate the corrected evaluation value d for the current time node based on all communication risk values; d = Y(i)×(k i - k')]; where ki is the communication risk value of the i-th time interval; k' is the communication risk value threshold; Y(i) is the selection coefficient; if (k i - k') > O; Y(i) = 1; if (k i - k') < O; Y(i) = 0; m is the number of time intervals in the current monitoring cycle; Preset the corrected evaluation value threshold D1; If d > D1, generate a correction instruction for the primary algorithm strategy.
[0056] Specifically, the corrected evaluation value threshold can be set according to historical parameters.
[0057] Specifically, the communication risk value threshold can be set according to historical parameters.
[0058] Specifically, the duration of a single monitoring cycle can be set according to the historical communication attack frequency. The higher the attack frequency, the shorter the duration of the corresponding monitoring cycle.
[0059] Specifically, set the duration of a single time interval according to the corrected evaluation value of the previous monitoring time node. The greater the corrected evaluation value, the shorter the duration of the corresponding time interval. The mapping relationship between the two can be set according to historical parameters.
[0060] Specifically, divide the current monitoring cycle according to the set duration of the time interval to generate multiple time intervals.
[0061] Specifically, the greater the corrected evaluation value, the worse the efficiency and security of the current primary algorithm strategy during key interaction. When the corrected evaluation value is greater than the preset corrected evaluation value threshold, the current primary algorithm strategy needs to be corrected.
[0062] Specifically, a communication risk value of each time interval is generated, including: According to the time interval sequence T, t is set in turn i For the target time interval; According to the communication monitoring data, a communication risk value k of the target time interval is generated; k=g×[ η i ×s i ]; g=U×[ β i ×v i ]; Wherein, g is a risk correction coefficient; θ2 is the number of attack risk indicators; η i is the influence factor of the i th attack risk indicator; s i is the reference value of the i th attack risk indicator of the target time interval generated based on the communication monitoring data; U is a conversion coefficient; θ1 is the number of performance evaluation indicators; β i is the influence factor of the i th performance evaluation indicator; v i is the deviation value of the i th performance evaluation indicator; The communication risk value of each time interval is generated in turn.
[0063] Specifically, through the conversion coefficient, the risk correction coefficient g is within a preset value range, and the greater the value of [ β i ×v i ], the greater the value of the risk correction coefficient g, and the mapping relationship between the two can be set according to historical parameters.
[0064] Specifically, the attack risk indicators include but are not limited to the number of attacks, the number of password cracking, the password cracking range and other parameters related to transmission risk. By quantifying each attack risk indicator, each attack risk indicator is within the same value range, and the greater the reference value of each attack risk indicator, the more transmission risks occur in the target time interval, and the worse the corresponding key interaction efficiency and security.
[0065] Specifically, the influence factor of each attack risk indicator can be set according to its mapping degree to the transmission risk, and the greater the mapping degree, the greater the corresponding influence factor.
[0066] Specifically, the greater the communication risk value, the worse the key interaction efficiency and security in the current time interval.
[0067] It can be understood that in the above embodiment, the communication state is periodically monitored, and the quantum attack risk is timely warned, and the algorithm sub-strategy is corrected, thereby reducing the harm of quantum attack.
[0068] In another preferred embodiment of the quantum-resistant SM2 key exchange method based on any of the above preferred embodiments, this preferred embodiment provides a quantum-resistant SM2 key exchange method, comprising: The central control unit includes a first processing module and a second processing module; The initiating user obtains the algorithm feedback parameters from the responding user through the first processing module and establishes an algorithm strategy set; The second processing module is used to set the first-level algorithm strategy according to the algorithm strategy set; The second processing module is also used to construct the interaction key set between the initiating user and the responding user according to the first-level algorithm strategy; The monitoring unit is used to acquire communication monitoring data and determine whether to correct the primary algorithm strategy based on the communication monitoring data. The first processing module is also used for: A second algorithm set is constructed based on the algorithm feedback parameters from the responding users; Obtain the first algorithm set of the initiating user; The first-level SM2 algorithm and quantum algorithm sequence A are generated based on the fusion results of the first algorithm set and the second algorithm set; A=(a1, a2…a…) i …a n ), where a i Let be the i-th first-order quantum algorithm; n is the number of first-order quantum algorithms; Establish an algorithm strategy set B based on the first-level SM2 algorithm and the quantum algorithm sequence A; B = (b1, b2, ..., bb) i …b n ), where b i Let be the i-th algorithmic sub-policy; n is the number of algorithmic sub-policies; algorithmic sub-policy b i It includes the first-level SM2 algorithm and the i-th first-level quantum algorithm.
[0069] In a preferred embodiment of this application, the second processing module is further configured to: b is set sequentially according to algorithm strategy set B. i For the target sub-strategy; The performance evaluation value c of the generated target sub-strategy; c=[ β i ×j i ]; Where θ1 represents the number of performance indicators; β i Let j be the influencing factor of the i-th performance index; i This is the expected reference value for the i-th performance metric in the target sub-strategy; The performance evaluation values of the respective algorithm sub-strategies are generated in sequence; The performance evaluation value sequence C is established, C=(c1, c2…c i …c n ), wherein c i is the performance evaluation value of the i-th algorithm sub-strategy; The algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C is set as the primary algorithm strategy; The primary quantum algorithm in the primary algorithm strategy is set as the auxiliary quantum algorithm; The synchronization instruction of the primary algorithm strategy is generated; The primary algorithm strategy comprises: The auxiliary quantum algorithm, the primary algorithm strategy comprises: The primary SM2 algorithm, the primary initiating SM2 public key, the primary responding SM2 public key, the auxiliary quantum algorithm, and the primary responding quantum public key.
[0070] According to the first concept of the present application, by fusing the algorithms of the initiating user and the responding user, a plurality of algorithm sub-strategies are established, and the best algorithm sub-strategy is selected according to the performance optimization result, so as to improve the SM2 key exchange efficiency and security, and at the same time, the communication state is periodically monitored, the quantum attack risk is timely warned, and the algorithm sub-strategy is corrected, so as to reduce the harm of quantum attack.
[0071] According to the second concept of the present application, by constructing a double password encryption model, the security of communication can be ensured when a single password type is cracked, the intrusion risk in the communication process is reduced, and through modular design, different types of quantum algorithms can be added at any time, so as to improve the adaptability to different communication scenarios.
[0072] The above only describes the preferred embodiments of the present application, and it should be pointed out that for ordinary skilled persons in the technical field, some improvements and replacements can be made without departing from the technical principles of the present application, and these improvements and replacements should also be regarded as the protection scope of the present application.
Claims
1. A quantum-resistant SM2 key exchange method, characterized in that, include: The initiating user establishes an algorithm strategy set based on the algorithm feedback parameters from the responding user; Set a primary algorithm strategy based on the algorithm strategy set, and construct an interaction key set for the initiating user and the responding user based on the primary algorithm strategy; Acquire communication monitoring data and determine whether to adjust the primary algorithm strategy based on the communication monitoring data; The set of algorithm strategies includes: The initiating user constructs a second algorithm set based on the algorithm feedback parameters from the responding user; Obtain the first algorithm set of the initiating user; The first-level SM2 algorithm and quantum algorithm sequence A are generated based on the fusion results of the first algorithm set and the second algorithm set; A=(a1, a2…a…) i …a n ), where a i Let be the i-th first-order quantum algorithm; n is the number of first-order quantum algorithms; Establish an algorithm strategy set B based on the first-level SM2 algorithm and the quantum algorithm sequence A; B = (b1, b2, ..., bb) i …b n ), where b i Let be the i-th algorithmic sub-policy; n is the number of algorithmic sub-policies; algorithmic sub-policy b i It includes the first-level SM2 algorithm and the i-th first-level quantum algorithm.
2. The quantum-resistant SM2 key exchange method as described in claim 1, characterized in that, Define the primary algorithm strategy, including: b is set sequentially according to algorithm strategy set B. i For the target sub-strategy; The performance evaluation value c of the generated target sub-strategy; c=[ b i ×j i ]; Where θ1 represents the number of performance indicators; β i Let j be the influencing factor of the i-th performance index; i This is the expected reference value for the i-th performance metric in the target sub-strategy; Generate performance evaluation values for each algorithm sub-strategy in sequence; Establish a performance evaluation value sequence C, C=(c1, c2…c i …c n ), where c i This represents the performance evaluation value of the i-th algorithm sub-strategy; The algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C is defined as the first-level algorithm strategy; The first-level quantum algorithm in the first-level algorithm strategy is designated as the auxiliary quantum algorithm. Generate synchronization instructions for the primary algorithm strategy; The first-level algorithm strategy includes: The auxiliary quantum algorithm, the first-level algorithm strategy includes: The system consists of a Level 1 SM2 algorithm, a Level 1 initiating SM2 public key, a Level 1 responding SM2 public key, an auxiliary quantum algorithm, and a Level 1 responding quantum public key.
3. The quantum-resistant SM2 key exchange method as described in claim 2, characterized in that, Construct the interaction key set for the initiating user and the responding user, including: The user obtains the primary algorithm strategy according to the synchronization command; The initiating user generates an initial interaction packet based on the first-level algorithm strategy and sends the initial interaction packet to the responding user; Respond to the user's request for the initial interaction packet and generate the verification value f of the initial interaction packet; Preset verification threshold F1; If f > F1, the responding user generates a feedback interaction packet and sends the feedback data packet to the initiating user; Obtain the first shared secret based on the initial interaction packet; Obtain the second shared secret based on the feedback data packet; Processing the first shared secret and the second shared secret Construct an interactive key set based on the processing results.
4. The quantum-resistant SM2 key exchange method as described in claim 3, characterized in that, Generate the initial interactive package, including: Initiate user to generate first shared secret; The first shared secret is encapsulated using a first-level response quantum public key, and a first-level encapsulation is generated. The user initiates the generation of a secondary initiator SM2 public key, a redundant tag, and a primary initiator quantum public key; Generate an initial interaction package, which includes: The first-level encapsulation component, the second-level initiation public key, the redundant tag, and the first-level initiation quantum public key; Set the first-level verification structure for the initial interaction package.
5. The quantum-resistant SM2 key exchange method as described in claim 4, characterized in that, Respond to user-generated feedback interaction packages, including: The user generates a second shared secret in response; The second shared secret is encapsulated using a quantum public key initiated at the first level, and a second-level encapsulation is generated. The user responds by generating a secondary response with the SM2 public key; Generate a feedback interaction package, the feedback interaction package including: A two-level encapsulation component, a two-level response SM2 public key, and a one-level response quantum public key; Configure a two-level verification structure for the feedback data packet.
6. The quantum-resistant SM2 key exchange method as described in claim 5, characterized in that, Determining whether to modify the first-level algorithm strategy includes: Establish multiple monitoring cycles and set the end time node of each monitoring cycle as the monitoring time node; Obtain communication monitoring data at the current monitoring time point; Multiple time intervals are set within the current monitoring period; Establish a time interval sequence T, T=(t1, t2, ..., t3). i …t m ), where t i This represents the i-th time interval of the current monitoring period; m represents the number of time intervals in the current monitoring period. Generate communication risk values for each time interval; Generate a revised evaluation value d for the current time point based on all communication risk values; d=[ Y(i)×(k i -k')]; Among them, ki is the communication risk value of the i-th time interval; k' is the communication risk value threshold; Y(i) is the selection coefficient; if (k i - k') > O; Y(i) = 1; if (k i - k') < O; Y(i) = 0; m is the number of time intervals in the current monitoring period; Preset correction evaluation value threshold D1; If d > D1, generate correction instructions for the first-level algorithm strategy.
7. The quantum-resistant SM2 key exchange method as described in claim 6, characterized in that, Generate communication risk values for each time interval, including: Based on the time interval sequence T, t is set sequentially. i The target time interval; A communication risk value k for the target time interval is generated based on communication monitoring data; k=g×[ or i ×s i ]; g=U×[ b i ×v i ]; Where g is the risk correction coefficient; θ2 is the number of attack risk indicators; η i s is the influencing factor of the i-th attack risk indicator; i θ1 is the reference value of the i-th attack risk indicator in the target time interval, generated based on communication monitoring data; U is the conversion coefficient; θ1 is the number of performance evaluation indicators; β i v is the influence factor of the i-th performance evaluation index; i This represents the deviation value of the i-th performance evaluation index; The communication risk values for each time interval are generated sequentially.
8. A quantum-resistant SM2 key exchange system, employing the quantum-resistant SM2 key exchange method according to any one of claims 1-7, characterized in that, include: The central control unit includes a first processing module and a second processing module; The initiating user obtains the algorithm feedback parameters from the responding user through the first processing module and establishes an algorithm strategy set; The second processing module is used to set the first-level algorithm strategy according to the algorithm strategy set; The second processing module is also used to construct the interaction key set of the initiating user and the responding user according to the first-level algorithm strategy; The monitoring unit is used to acquire communication monitoring data and determine whether to correct the primary algorithm strategy based on the communication monitoring data. The first processing module is also used for: A second algorithm set is constructed based on the algorithm feedback parameters from the responding users; Obtain the first algorithm set of the initiating user; The first-level SM2 algorithm and quantum algorithm sequence A are generated based on the fusion results of the first algorithm set and the second algorithm set; A=(a1, a2…a…) i …a n ), where a i Let be the i-th first-order quantum algorithm; n is the number of first-order quantum algorithms; Establish an algorithm strategy set B based on the first-level SM2 algorithm and the quantum algorithm sequence A; B = (b1, b2, ..., bb) i …b n ), where b i Let be the i-th algorithmic sub-policy; n is the number of algorithmic sub-policies; algorithmic sub-policy b i It includes the first-level SM2 algorithm and the i-th first-level quantum algorithm.
9. The quantum-resistant SM2 key exchange system as described in claim 8, characterized in that, The second processing module is also used for: b is set sequentially according to algorithm strategy set B. i For the target sub-strategy; The performance evaluation value c of the generated target sub-strategy; c=[ b i ×j i ]; Where θ1 represents the number of performance indicators; β i Let j be the influencing factor of the i-th performance index; i This is the expected reference value for the i-th performance metric in the target sub-strategy; Generate performance evaluation values for each algorithm sub-strategy in sequence; Establish a performance evaluation value sequence C, C=(c1, c2…c i …c n ), where c i This represents the performance evaluation value of the i-th algorithm sub-strategy; The algorithm sub-strategy corresponding to the maximum value in the performance evaluation value sequence C is defined as the first-level algorithm strategy; The first-level quantum algorithm in the first-level algorithm strategy is designated as the auxiliary quantum algorithm. Generate synchronization instructions for the primary algorithm strategy; The first-level algorithm strategy includes: The auxiliary quantum algorithm, the first-level algorithm strategy includes: The system consists of a Level 1 SM2 algorithm, a Level 1 initiating SM2 public key, a Level 1 responding SM2 public key, an auxiliary quantum algorithm, and a Level 1 responding quantum public key.
Citation Information
Patent Citations
Transmission processing method and system based on TLCP quantum security, and electronic equipment
CN117424761A
TLCP communication method and system for resisting quantum attack
CN118631447A
Multi-algorithm bootstrapping
WO2024134139A1