Key exchange method capable of resisting quantum attack based on ring error learning

By employing a key exchange method based on on-ring error learning, combined with lattice cryptography and error coordination mechanisms, the problems of high computational overhead and vulnerability to quantum attacks in IoT devices are solved. This achieves lightweight, quantum-resistant key exchange, suitable for secure communication in low-power devices.

CN121000415APending Publication Date: 2025-11-21SHAANXI NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511058133.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing key exchange protocols have high computational overhead in IoT devices, are not suitable for low-power devices, and are vulnerable to quantum attacks, making it difficult to guarantee security and integrity under low latency and low power consumption.

Method used

A key exchange method based on on-ring error learning is adopted, which utilizes lattice cryptography and error coordination mechanism. The system parameters and private key are generated by the authorization center, and the user terminal and IoT device calculate temporary public key and message authentication code to achieve lightweight and quantum attack resistant key exchange.

Benefits of technology

It ensures security in the face of quantum attacks, reduces computational load, is suitable for resource-constrained IoT devices, has the ability to resist replay attacks and man-in-the-middle attacks, and meets the requirements of low power consumption and high-efficiency communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000415A_ABST
    Figure CN121000415A_ABST
Patent Text Reader

Abstract

The invention provides a key exchange method capable of resisting quantum attacks based on ring error learning. The key exchange method comprises the steps that an authorization center generates system parameters, a user private key and an Internet of Things private key and distributes the system parameters, the user private key and the Internet of Things private key to a user side and Internet of Things equipment; the user side calculates a user temporary public key, a first message authentication code and an encrypted first intermediate value and sends the same to the Internet of Things equipment; the Internet of Things equipment verifies the validity of the first message authentication code and the user temporary public key, generates an Internet of Things temporary public key, decrypts the encrypted first intermediate value, calculates a first session key, a second message authentication code and an encrypted second intermediate value, and sends the first session key, the second message authentication code and the encrypted second intermediate value to the user side; and the user side verifies the validity of the second message authentication code and the temporary public key of the Internet of Things, and calculates a second session key equal to the first session key, thereby completing the session. According to the method, the quantum attack can be resisted, meanwhile, the forward security and the man-in-the-middle attack resistance are ensured, and the key exchange efficiency and security are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer information security technology, specifically to a key exchange method based on on-ring error learning that is resistant to quantum attacks. Background Technology

[0002] Key exchange protocols, as a core technology ensuring that communicating parties share secure keys, not only prevent information theft during communication but also ensure the legitimacy of device identities and the integrity of data, thus guaranteeing the security of user privacy data. This technology provides the theoretical basis for establishing a shared secret key between communicating parties, avoiding the risks of transmitting keys over open channels.

[0003] Existing key exchange protocols are divided into symmetric key exchange protocols and asymmetric key exchange protocols. However, traditional key exchange protocols have some problems in today's Internet of Things (IoT) applications. Currently, IoT devices are usually limited by computing power and storage resources, and traditional protocols often require high computational overhead and memory consumption, which contradicts the low power consumption and low performance characteristics of IoT devices. In reality, not all IoT devices meet the requirements of the protocol. A practical solution should be able to meet the communication needs of low-power devices. Taking portable transportation as an example, a large amount of data is generated every day, and data exchange is particularly frequent during peak periods. Therefore, it is necessary to consider achieving fast and accurate data exchange based on user needs.

[0004] Furthermore, while traditional key exchange protocols are widely used and have achieved good results in classical computing environments, their security still faces many challenges:

[0005] (1) First, many traditional protocols rely on computational assumptions in classical complexity theory, such as the large number factorization problem and the discrete logarithm problem. However, with the development of quantum computing, quantum algorithms can efficiently solve these problems in polynomial time, fundamentally threatening their security foundation;

[0006] (2) Secondly, traditional protocols are mostly general designs and lack targeted optimization for communication scenarios of resource-constrained devices (such as IoT terminals). Their computing and communication overhead may be unbearable for low-power devices.

[0007] (3) Third, traditional protocols often assume a relatively stable and reliable communication environment, making it difficult to cope with the high-frequency dynamic access, node failures, and vulnerability to physical attacks in the IoT environment. This can easily lead to information leakage or session hijacking during key negotiation. These problems are further amplified in scenarios where users exchange data with IoT devices. The wide variety of devices, limited computing power, and extensive distribution make the communication process more susceptible to malicious attackers.

[0008] (4) Meanwhile, the key exchange process needs to be completed under the constraints of low latency and low energy consumption, and traditional schemes struggle to achieve a balance between security and performance. Therefore, against the backdrop of continuous breakthroughs in quantum computing technology, traditional key exchange protocols that rely on number theory problems face unprecedented security risks. Once large-scale, stable quantum computers are realized, existing encryption foundations may be cracked in a short period of time, and the confidentiality and integrity of communication systems will be seriously threatened. Summary of the Invention

[0009] In view of this, the present invention provides a key exchange method resistant to quantum attacks based on on-ring error learning, so as to at least solve the above-mentioned technical problems.

[0010] According to a first aspect of the present invention, a quantum attack-resistant key exchange method based on on-ring error learning is provided, comprising: an authorization center generating system parameters, a user private key, and an IoT private key and distributing them to a user terminal and an IoT device; the user terminal calculating a user temporary public key, a first message authentication code, and an encrypted first intermediate value based on the system parameters and the user private key, and sending them to the IoT device; the IoT device verifying the validity of the first message authentication code and the user temporary public key, and upon successful verification, the IoT device generating an IoT temporary public key based on the system parameters and the IoT private key and decrypting the encrypted first intermediate value to obtain a first intermediate value, calculating a first session key, a second message authentication code, and an encrypted second intermediate value based on the first intermediate value, the user temporary public key, the IoT temporary public key, user identity information, and IoT device identity information, and sending the IoT temporary public key, the second message authentication code, and the encrypted second intermediate value to the user terminal; the user terminal verifying the validity of the second message authentication code and the IoT temporary public key, and upon successful verification, calculating a second session key equal to the first session key based on the IoT temporary public key, the user temporary public key, the encrypted second intermediate value, user identity information, and IoT device identity information, and completing the session.

[0011] Optionally, the system parameters include a hash function, message authentication code parameters, a discrete Gaussian distribution, a modulo multinomial, and fixed elements randomly and uniformly selected from the ring.

[0012] Optionally, the IoT device verifies the validity of the first message authentication code through the following steps: After receiving the encrypted first intermediate value, the user's temporary public key, and the first message authentication code sent by the user terminal, the IoT device recalculates the first message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received first message authentication code; if the recalculated first message authentication code is consistent with the received first message authentication code, the message authentication code verification is successful.

[0013] Optionally, the user terminal verifies the validity of the second message authentication code through the following steps: After receiving the encrypted second intermediate value, the IoT temporary public key, and the second message authentication code sent by the IoT device, the user terminal recalculates the second message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received second message authentication code; if the recalculated second message authentication code is consistent with the received second message authentication code, the message authentication code verification is successful.

[0014] Optionally, the formula for the IoT device to calculate the first session key is as follows:

[0015] K IA =H(A||I||k) A ||k I ||e1||y2)

[0016] Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key. I For Internet of Things (IoT) temporary public keys.

[0017] Optionally, the formula for calculating the first session key by the user terminal is as follows:

[0018] K AI =H(A||I||k) A ||k I ||e2||y1)

[0019] Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key. I For Internet of Things (IoT) temporary public keys.

[0020] According to a second aspect of the present invention, a quantum-resistant key exchange system based on on-ring error learning is provided, comprising an authorization center, a user terminal, and an Internet of Things (IoT) device, connected via a communication connection, wherein: the authorization center generates system parameters, a user private key, and an IoT private key and distributes them to the user terminal and the IoT device; the user terminal calculates a user temporary public key, a first message authentication code, and an encrypted first intermediate value based on the system parameters and the user private key, and sends them to the IoT device; the IoT device verifies the validity of the first message authentication code and the user temporary public key, and upon successful verification, the IoT device generates an IoT temporary public key based on the system parameters and the IoT private key and encrypts the first message authentication code and the first intermediate value; The first intermediate value is decrypted to obtain the first intermediate value. Based on the first intermediate value, the user's temporary public key, the IoT temporary public key, the user's identity information, and the IoT device's identity information, the first session key, the second message authentication code, and the encrypted second intermediate value are calculated. The IoT temporary public key, the second message authentication code, and the encrypted second intermediate value are then sent to the user terminal. The user terminal verifies the validity of the second message authentication code and the IoT temporary public key. After successful verification, the user terminal calculates the second session key, which is equal to the first session key, based on the IoT temporary public key, the user's temporary public key, the encrypted second intermediate value, the user's identity information, and the IoT device's identity information, thus completing the session.

[0021] According to a third aspect of the present invention, an electronic device is provided, including a processor and a memory storing a program. The program includes instructions that, when executed by the processor, cause the processor to perform the steps performed by the method of the first aspect described above.

[0022] According to a fourth aspect of the present invention, a computer storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method of the first aspect described above.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] This invention leverages the intractability of the on-ring learning error problem and incorporates an error coordination mechanism to achieve efficient, lightweight, and quantum-resistant authentication key exchange in the Internet of Things (IoT). This scheme maintains security even against adversaries capable of quantum attacks. It offers enhanced privacy, prevents data misuse, and avoids single points of failure. It possesses forward completeness, resisting attacks such as man-in-the-middle and replay attacks. This lightweight authentication communication method has low computational cost, making it more practically applicable. By combining the advantages of lattice cryptography, this scheme achieves an efficient, low-power, and quantum-resistant key exchange mechanism, meeting the multiple requirements of security, efficiency, and scalability in IoT environments. It is particularly suitable for large-scale device deployments and low-power device communication in IoT environments. In the future, with the continuous growth of the number of IoT devices and the evolution of security threats, this lattice-based key exchange scheme will play a crucial role in ensuring the security of the IoT ecosystem. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0026] Figure 1 This is a framework diagram of the present invention.

[0027] Figure 2 To and Figure 1 The corresponding detailed operation execution flow diagram. Detailed Implementation

[0028] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] To address the unprecedented security risks faced by traditional key exchange protocols that rely on number theory problems, novel key exchange mechanisms based on lattice problems, the common origin hypothesis, or multivariable polynomials are needed. These schemes maintain robust computational difficulty even with current quantum algorithms, providing stronger security guarantees. They are also suitable for resource-constrained IoT applications with frequent access, effectively resisting potential future attack paths and ensuring the persistent security of data exchange.

[0030] Traditional methods for implementing quantum-resistant schemes typically rely on homology-based approaches, which often require significant time and resources. In recent years, lattice-related technologies have emerged as a promising solution. Researching efficient quantum-resistant key exchange for the Internet of Things (IoT) not only has high theoretical value but also significant practical applications, offering advantages such as strong security and wide applicability.

[0031] In practical applications, the user terminal and IoT devices of this invention generate their own key information and negotiate a common session key without revealing the real key. Even if an attacker intercepts the communication content, they cannot recover valid information from it, thus ensuring the privacy and anti-attack capability of the key. At the same time, this method has high computational efficiency and small message size, making it particularly suitable for deployment in resource-constrained IoT environments, balancing security and practicality. By learning the error learning problem on lattice rings, a key exchange protocol resistant to quantum attacks can be established, while reducing the number of communication interactions and improving the efficiency of the entire system. The protocol implements an efficient, low-power, and quantum-resistant key exchange mechanism, meeting the multiple requirements of security, efficiency, and scalability in IoT environments, and is particularly suitable for large-scale device deployment and low-power device communication in IoT environments. It provides a feasible solution for secure communication between user terminals and IoT devices, and has certain reference value and practical significance for promoting the research and application of IoT security protocols.

[0032] See details Figure 1 An embodiment of the present invention provides a quantum-resistant key exchange method based on on-ring error learning, comprising:

[0033] The authorization center generates system parameters, user private keys, and IoT private keys and distributes them to user terminals and IoT devices.

[0034] The user terminal calculates the user's temporary public key, first message authentication code, and encrypted first intermediate value based on system parameters and the user's private key, and sends them to the IoT device.

[0035] The IoT device verifies the validity of the first message authentication code and the user's temporary public key. After successful verification, the IoT device generates an IoT temporary public key based on system parameters and the IoT private key, and decrypts the encrypted first intermediate value to obtain the first intermediate value. Based on the first intermediate value, the user's temporary public key, the IoT temporary public key, the user's identity information, and the IoT device's identity information, the first session key, the second message authentication code, and the encrypted second intermediate value are calculated, and the IoT temporary public key, the second message authentication code, and the encrypted second intermediate value are sent to the user terminal.

[0036] The user terminal verifies the validity of the second message authentication code and the IoT temporary public key. After successful verification, the user terminal calculates a second session key that is equal to the first session key based on the IoT temporary public key, the user's temporary public key, the encrypted second intermediate value, the user's identity information, and the IoT device's identity information, thus completing the session.

[0037] Optionally, the system parameters include a hash function, message authentication code parameters, a discrete Gaussian distribution, a modulo multinomial, and fixed elements randomly and uniformly selected from the ring.

[0038] Optionally, the IoT device verifies the validity of the first message authentication code through the following steps: After receiving the encrypted first intermediate value, the user's temporary public key, and the first message authentication code sent by the user terminal, the IoT device recalculates the first message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received first message authentication code; if the recalculated first message authentication code is consistent with the received first message authentication code, the message authentication code verification is successful.

[0039] Optionally, the user terminal verifies the validity of the second message authentication code through the following steps: After receiving the encrypted second intermediate value, the IoT temporary public key, and the second message authentication code sent by the IoT device, the user terminal recalculates the second message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received second message authentication code; if the recalculated second message authentication code is consistent with the received second message authentication code, the message authentication code verification is successful.

[0040] Optionally, the formula for the IoT device to calculate the first session key is as follows:

[0041] K IA =H(A||I||k) A ||k I ||e1||y2)

[0042] Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key. I For Internet of Things (IoT) temporary public keys.

[0043] Optionally, the formula for calculating the first session key by the user terminal is as follows:

[0044] K AI =H(A||I||k) A ||k I ||e2||y1)

[0045] Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key.I For Internet of Things (IoT) temporary public keys.

[0046] For example, this invention addresses the shortcomings of existing key exchange protocols in the Internet of Things (IoT), such as insufficient efficiency, vulnerability to attacks, high computational and memory consumption, unsuitability for large-scale network deployments, and inability to guarantee security against participants capable of quantum attacks. Based on the error learning problem on rings within lattices, utilizing error coordination mechanisms, hash functions, and message authentication codes, this invention proposes a quantum-resistant key exchange protocol for the IoT, namely, a quantum-resistant key exchange method based on error learning on rings, comprising:

[0047] I. Safety Model Design:

[0048] 1. Authorization Center: Provides long-term public and private keys for users and IoT devices participating in the communication. The public key contains identity information. A corresponding static private key is generated using the master private key, public parameters, and user identity information, and is securely distributed to each user through the authentication channel. Therefore, each user's static private key is uniquely associated with its identity information.

[0049] 2. Internet of Things (IoT) devices: These devices sense and collect information from specific environments and complete authentication and session key generation.

[0050] 3. Malicious Participants: These entities possess complete control over communication between participants, including intercepting, modifying, replaying, or delaying messages, as well as manipulating the order of message delivery. They can indirectly obtain private information by querying specific oracles. They cannot interfere with secure communication between users / IoT terminals and the authorization center, nor can they directly obtain any participant's private information.

[0051] II. Cryptographic Scheme Design:

[0052] 1. Initialization phase:

[0053] (1) KGC is a completely trustworthy authority center, let H represent the hash function {0, 1}. * →R q The hash function is simulated as a random oracle. MAC represents the message verification code, l represents the length of the session key, and χ... β Let represent a discrete Gaussian distribution, where β represents a positive real number. α represents the distribution from R0. q A fixed element is randomly and uniformly selected and assigned to all users and IoT devices. A represents user identity information, and I represents IoT device identity information.

[0054] (2) a is R q The modular polynomial, generated during the protocol initialization phase, is shared by all participants. i =H1(ID) i) is a ring R q The elements in the array are s, which is a randomly selected private key, and sk. i =h i ·s+v,v←χ β .

[0055] 2. The user calculates the temporary public key and sends the encrypted intermediate value:

[0056] (1) From the discrete Gaussian distribution χ β Randomly sample α and δ, and calculate the temporary public key k. A =a·α+δ∈R q Calculate the intermediate value ω1 = h I ·sk A +a·α, Message authentication code

[0057] (2) Cross-round ω1 to get c1, and modulo round ω1 to get y1.

[0058] (3) Transfer user information k A c1 is sent to IoT devices.

[0059] 3. The IoT device decrypts the session key and sends its own temporary public key:

[0060] (1) From the discrete Gaussian distribution χ β Randomly sample λ and θ, and compute the temporary public key k. I =a·λ+θ∈R q Verify k A Is it valid? Check if k1 is equal to... match.

[0061] (2) Calculate ω2=h A ·sk I +a·λ, cross-round ω2 to get c2, modulo round ω2 to get y2, e1=rec(2ω2,c1).

[0062] (3) Calculate the session key K IA =H(A||I||k) A ||k I ||e1||y2), Message authentication code

[0063] (4) K I c2 is sent to the user.

[0064] 4. The user calculates the session key:

[0065] (1) Verify k I To determine if it is valid, check if k2 is equal to... match.

[0066] (2) Calculate ω3=h I ·sk A +k I e2 = rec(2ω3, c2).

[0067] (3) Calculate the session key K AI =H(A||I||k) A ||k I ||e2||y1), complete the session.

[0068] The following provides verification of the correctness and safety of this invention:

[0069] Correctness:

[0070] If the participants in this invention protocol can honestly operate the protocol, and the parameters satisfy:

[0071] (1) The variance parameter β of the discrete Gaussian distribution satisfies (where n is the degree of the polynomial)

[0072] (2) The modulus q is a prime number and is large enough.

[0073] Then both parties will have a significant probability of obtaining the same session key.

[0074] The formulas for users and IoT devices to calculate session keys are as follows:

[0075] K AI =H(A||I||k) A ||k I ||e2||y1)

[0076] K IA =H(A||I||k) A ||k I ||e1||y2)

[0077] Therefore, to prove key consistency, it is only necessary to prove e1 = y1 and e2 = y2. First, calculate the difference between ω and ω2.

[0078] ω1=h I ·sk A +α·α=h I ·h A ·s+h I ·v+α·α

[0079] ω2=h A ·sk I +α·λ=h A ·h I ·s+h A ·v+α·λ

[0080] Therefore, ω1 - ω2 = v·(h) I -h A )-a·(α-λ), where v is the noise term of the static private key sampled from a Gaussian distribution, and α, λ are the sampled values ​​of the temporary public key. According to the properties of the Gaussian distribution, ||v||<2β, ||α||<2β, ||λ||<2β. A h I For the output of hash function H1, ||h A -h I ||≤γ (protocol security parameter). According to the harmonics on the ring, ||ω1-ω2||≤q / 4, thus the same bit string can be successfully decoded, i.e., y1=e1, y2=e2, so both parties can obtain the same session key.

[0081] Security:

[0082] Proposition 1: If the RLWE problem with parameters (n,k,q,η) is difficult, then the key exchange protocol of this invention, i.e., the key exchange method of this invention, is secure.

[0083] Proof: Let ∏ be the protocol of this invention, and let adversary A be a polynomial adversary with a running time less than t. The advantage of adversary A is... in This is the opponent's advantage in Game 1. Let pr(ε) represent the opponent's advantage in game 2, where pr(ε) is a negligible probability. i For opponent A in game G i The probability of guessing the correct bit b. This indicates an advantage in dealing with decision-type RLWE problems.

[0084] G0: This game simulated a real attack using a random oracle model, targeting the AKE protocol mentioned in the text.

[0085] G1: In this game, the temporary public key K of user UA will be used. A Change to random uniform sampling, i.e., K A ←U(R q The rest of the protocol remains unchanged. At this point, in G0, (a, k) A ) is an RLWE sample, in G1, (a, k A G0 is a uniformly random pair. If the adversary can distinguish between G0 and G1, then there exists an algorithm B1 that can break the decision-type RLWE problem, i.e.

[0086] G2: G2 is the same as G1, except that it uses the temporary public key K of the IoT device. IChange to random uniform sampling, i.e., K I ←U(R q At this point in G1, (a,k) I ) is an RLWE sample, in G2, (a, k I Since ) is a uniformly random pair, similarly we can obtain:

[0087] G3: G3 is the same as G2, except that the intermediate values ​​ω1, ω2, ω3 are replaced with random uniform sampling, i.e., ω1←U(Rq), ω2←U(Rq). q ), ω3←U(R q Based on the properties of the Gaussian distribution and the error coordination mechanism, the probability that the coefficient of ω1-ω2 exceeds [-q / 4, q / 4] is negligible, and the adversary cannot distinguish the true ω. i Given random values, therefore pr(S3)-pr(S2)≤pr(ε).

[0088] G4: G4 is the same as G3, except that the session key is replaced with a random string K. AI ←U({0,1} l ),K IA ←U({0,1} l At this point, adversary A is facing a uniformly random key, pr(S4=1 / 2). According to the random oracle property of the hash function and the randomness of the RLWE parameter, we have pr(S4)-pr(S3)≤pr(ε).

[0089] Combining G0 to G4, the advantage of opponent A successfully attacking is: Its value is negligible. The security specification of the final protocol is the difficulty of the PLWE problem on the lattice, while the RLWE problem is still a difficult problem in quantum computing. Therefore, the advantage of adversary A is negligible, and proposition 1 is proved.

[0090] Proposition 2: The solution of this invention also has the ability to resist replay attacks and man-in-the-middle attacks.

[0091] Proof: The protocol and method of this invention can resist replay attacks. The core reason is that each execution of the protocol resamples the random values ​​α, δ, λ, θ, so k A k I All values ​​are unpredictable and fresh, making each MAC and key calculation result unreproducible. Therefore, even if an adversary replays historical communication messages, such as k... A c1 or k IThe verification input calculated by the receiver (c1) also fails to match the original information, leading to verification failure. In summary, this protocol, through randomness and freshness mechanisms, fundamentally prevents attackers from forging messages using historical information, thus possessing inherent resistance to replay attacks in the communication model. The protocol incorporates a key-based message authentication (MAC) mechanism to authenticate the identities of communication participants and protect the integrity of communication content, providing resistance to man-in-the-middle attacks: assuming a man-in-the-middle intercepts the user's message k... A c1, k1, and attempting to communicate with IoT devices, due to the lack of sk A Since the adversary cannot generate the correct ω1, they cannot construct a valid k1. Even if they attempt to forge it, MAC verification will fail, and the IoT device will terminate the session. Similarly, the adversary cannot forge k2 to deceive the user. Therefore, a man-in-the-middle attack cannot forge valid input; even if it forwards part of the message, it cannot obtain the session key.

[0092] Furthermore, the solution of the present invention is further described with reference to the following examples:

[0093] Figure 2 The specific execution flow of the quantum-resistant key exchange method based on on-ring error learning proposed in this invention is shown, and its main steps are as follows:

[0094] 1. Initialization Phase: The Authorization Center (KGC) generates parameters α, δ, λ, θ based on the user attribute set U, and generates the user's private key sk based on the public parameters. A IoT private key sk I .

[0095] 2. The user calculates the temporary public key and sends the encrypted intermediate value: The user calculates the temporary public key k. A Used for subsequent encryption, the intermediate value ω1 is calculated, and the message authentication code k1 is used for subsequent authentication.

[0096] 3. The IoT device decrypts the session key and sends its own temporary public key: Calculate the temporary public key k. I Calculate the intermediate value ω2, message authentication code k2, and session key K. IA .

[0097] 4. The user calculates the session key: Calculate the session key K. AI The session is complete once both parties have the same session key.

[0098] In summary, this invention proposes a key exchange protocol for information interaction between users and the Internet of Things (IoT) by utilizing lattice-hard problems, error coordination mechanisms, hash functions, and message authentication codes. In this protocol, the authorization center is completely trusted and responsible for the initialization of the entire system, generating and distributing public keys and public parameters, effectively preventing dishonest behavior from other malicious participants. Key negotiation and authentication between users and IoT devices require only two rounds of interaction, adapting to the low latency and fast wake-up requirements of IoT devices. All secret parameters and randomness are regenerated in each interaction, facilitating stateless deployment and supporting key synchronization after power failure and restart. This protocol significantly reduces computational and communication overhead while ensuring communication security, making it more suitable for resource-constrained IoT devices. This scheme is resistant to quantum attacks while ensuring forward security and resistance to man-in-the-middle attacks, improving the efficiency and security of key exchange. Through theoretical security analysis and performance evaluation, it provides a feasible solution for secure communication between users and IoT devices.

[0099] This invention also provides a quantum-resistant key exchange system based on on-ring error learning, comprising an authorization center, a user terminal, and an IoT device, connected via a communication connection, wherein:

[0100] The authorization center generates system parameters, user private keys, and IoT private keys and distributes them to user terminals and IoT devices.

[0101] The user terminal calculates the user's temporary public key, first message authentication code, and encrypted first intermediate value based on system parameters and the user's private key, and sends them to the IoT device.

[0102] The IoT device verifies the validity of the first message authentication code and the user's temporary public key. After successful verification, the IoT device generates an IoT temporary public key based on system parameters and the IoT private key, and decrypts the encrypted first intermediate value to obtain the first intermediate value. Based on the first intermediate value, the user's temporary public key, the IoT temporary public key, the user's identity information, and the IoT device's identity information, the first session key, the second message authentication code, and the encrypted second intermediate value are calculated, and the IoT temporary public key, the second message authentication code, and the encrypted second intermediate value are sent to the user terminal.

[0103] The user terminal verifies the validity of the second message authentication code and the IoT temporary public key. After successful verification, the user terminal calculates a second session key that is equal to the first session key based on the IoT temporary public key, the user's temporary public key, the encrypted second intermediate value, the user's identity information, and the IoT device's identity information, thus completing the session.

[0104] The system in this embodiment is used to implement the corresponding methods in the foregoing multiple method embodiments and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0105] As another example, the present invention also provides an electronic device, which will now be described as an example of a hardware device that can be applied to various aspects of the present invention, serving as a server or client of the invention. The term "electronic device" is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0106] The electronic device may include a processor, a communications interface, memory, and a communication bus.

[0107] The processor, communication interface, and memory communicate with each other via a communication bus. The communication interface is used to communicate with other electronic devices or servers.

[0108] The processor is used to execute programs, specifically the relevant steps in the above method embodiments.

[0109] Specifically, the program may include program code, which includes computer operation instructions.

[0110] The processor may be a CPU, an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The one or more processors included in a smart device may be of the same type, such as one or more CPUs; or they may be of different types, such as one or more CPUs and one or more ASICs.

[0111] The memory is used to store programs. The memory may include high-speed RAM, and may also include non-volatile memory, such as at least one disk drive.

[0112] When executed by a processor, the program enables an electronic device to perform a quantum-resistant key exchange method based on on-ring error learning, as described in this invention.

[0113] Furthermore, the specific implementation of each step in the program can be found in the corresponding descriptions of the steps and units in the above method embodiments, and will not be repeated here. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices and modules described above can be referred to the corresponding process descriptions in the foregoing method embodiments, and will not be repeated here.

[0114] An exemplary embodiment of the present invention also provides a computer storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the methods of the various embodiments of the present invention. The corresponding process descriptions in the foregoing method embodiments can be referred to, and will not be repeated here.

[0115] The methods described above according to embodiments of the present invention can be implemented in hardware, firmware, or as software or computer code that can be stored in a recording medium (such as a CD-ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or as computer code originally stored on a remote recording medium or a non-transitory machine-readable medium and subsequently stored on a local recording medium, downloaded via a network. Thus, the methods described herein can be processed by software stored on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an ASIC or FPGA). It is understood that the computer, processor, microprocessor controller, or programmable hardware includes storage components (e.g., RAM, ROM, flash memory, etc.) capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods described herein. Furthermore, when a general-purpose computer accesses code used to implement the methods shown herein, the execution of the code transforms the general-purpose computer into a dedicated computer for executing the methods shown herein.

[0116] Specific embodiments of the invention have now been described. Other embodiments are within the scope of the appended claims. In some cases, the actions described in the claims can be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing can be advantageous.

[0117] It should be understood that although this specification is described according to various embodiments, not every embodiment contains only one independent technical solution. This way of describing the specification is only for clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.

[0118] Finally, it should be noted that the above embodiments are only used to illustrate the embodiments of the present invention, and are not intended to limit the embodiments of the present invention. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the embodiments of the present invention. Therefore, all equivalent technical solutions also fall within the scope of the embodiments of the present invention, and the patent protection scope of the embodiments of the present invention should be defined by the claims.

Claims

1. A quantum-resistant key exchange method based on on-ring error learning, characterized in that, include: The authorization center generates system parameters, user private keys, and IoT private keys and distributes them to user terminals and IoT devices. The user terminal calculates the user's temporary public key, first message authentication code, and encrypted first intermediate value based on system parameters and the user's private key, and sends them to the IoT device. The IoT device verifies the validity of the first message authentication code and the user's temporary public key. After successful verification, the IoT device generates an IoT temporary public key based on system parameters and the IoT private key, and decrypts the encrypted first intermediate value to obtain the first intermediate value. Based on the first intermediate value, the user's temporary public key, the IoT temporary public key, the user's identity information, and the IoT device's identity information, the first session key, the second message authentication code, and the encrypted second intermediate value are calculated, and the IoT temporary public key, the second message authentication code, and the encrypted second intermediate value are sent to the user terminal. The user terminal verifies the validity of the second message authentication code and the IoT temporary public key. After successful verification, the user terminal calculates a second session key that is equal to the first session key based on the IoT temporary public key, the user's temporary public key, the encrypted second intermediate value, the user's identity information, and the IoT device's identity information, thus completing the session.

2. The method according to claim 1, characterized in that, The system parameters include a hash function, message authentication code parameters, a discrete Gaussian distribution, a modulo multinomial, and fixed elements randomly and uniformly selected from the ring.

3. The method according to claim 2, characterized in that, The IoT device verifies the validity of the first message authentication code through the following steps: After receiving the encrypted first intermediate value, the user's temporary public key, and the first message authentication code sent by the user terminal, the IoT device recalculates the first message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received first message authentication code. If the recalculated first message authentication code matches the received first message authentication code, then the message authentication code verification is successful.

4. The method according to claim 2, characterized in that, The user terminal verifies the validity of the second message authentication code through the following steps: After receiving the encrypted second intermediate value, IoT temporary public key and second message authentication code sent by the IoT device, the user terminal recalculates the second message authentication code based on the hash function and message authentication code parameters in the system parameters, and compares it with the received second message authentication code. If the recalculated second message authentication code matches the received second message authentication code, then the message authentication code verification is successful.

5. The method according to claim 1, characterized in that, The formula for calculating the first session key by the IoT device is as follows: K IA =H(A||I||k A ||k I ||e1||y2) Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key. I For Internet of Things (IoT) temporary public keys.

6. The method according to claim 1, characterized in that, The formula for calculating the first session key on the user terminal is as follows: K AI =H(A||I||k A ||k I ||e2||y1) Where A represents user identity information, I represents IoT device identity information, and k A k is the user's temporary public key. I For Internet of Things (IoT) temporary public keys.

7. A quantum-resistant key exchange system based on on-ring error learning, characterized in that, This includes an authorization center, user terminals, and IoT devices, connected via a communication connection, wherein: The authorization center generates system parameters, user private keys, and IoT private keys and distributes them to user terminals and IoT devices. The user terminal calculates the user's temporary public key, first message authentication code, and encrypted first intermediate value based on system parameters and the user's private key, and sends them to the IoT device. The IoT device verifies the validity of the first message authentication code and the user's temporary public key. After successful verification, the IoT device generates an IoT temporary public key based on system parameters and the IoT private key, and decrypts the encrypted first intermediate value to obtain the first intermediate value. Based on the first intermediate value, the user's temporary public key, the IoT temporary public key, the user's identity information, and the IoT device's identity information, the first session key, the second message authentication code, and the encrypted second intermediate value are calculated, and the IoT temporary public key, the second message authentication code, and the encrypted second intermediate value are sent to the user terminal. The user terminal verifies the validity of the second message authentication code and the IoT temporary public key. After successful verification, the user terminal calculates a second session key that is equal to the first session key based on the IoT temporary public key, the user's temporary public key, the encrypted second intermediate value, the user's identity information, and the IoT device's identity information, thus completing the session.

8. An electronic device, characterized in that, include: processor; Memory for stored programs; The program includes instructions that, when executed by the processor, cause the processor to perform the steps of the method as described in any one of claims 1-6.

9. A computer storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1-6.