Quantum security key management method and system based on homomorphic encryption
By employing homomorphic encryption and dynamically adjusting the granularity of key distribution, the problem of balancing security and efficiency in quantum secure key management is solved, enabling efficient and secure key distribution in a quantum computing environment.
Patent Information
- Application Number
- CN202511370963.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-24
- Publication Date
- 2025-12-19
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing quantum-safe key management technologies are ill-equipped to meet the real-time changes in security and efficiency requirements during key distribution. Fixed-granularity key distribution modes cannot be dynamically adjusted, resulting in deficiencies in security or efficiency.
A quantum-secure key management method based on homomorphic encryption is adopted. By obtaining key distribution requirements, the key distribution granularity is dynamically adjusted. Combined with quantum computing threat models and performance evaluation models, the key distribution path is optimized to ensure a balance between security and efficiency in the system.
This approach achieves improved key management security while ensuring high system performance, dynamically adjusts key distribution granularity to address quantum computing threats, optimizes distribution paths, and enhances system flexibility and operational efficiency.
Smart Images

Figure CN121173544A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of key management, in particular to a quantum secure key management method and system based on homomorphic encryption. BACKGROUND
[0002] With the development of quantum computing technology, many traditional cryptography algorithms (such as RSA and ECC) are at risk of being cracked quickly. Quantum computing uses the power of parallel computing to complete decryption tasks that would take millions of years for traditional computers. Therefore, quantum security has become an important research direction in the field of cryptography.
[0003] In existing quantum security key management methods, keys are usually distributed based on fixed granularity, such as quantum-resistant algorithms or quantum key distribution (QKD), using fixed key shunting granularity. Among them, quantum-resistant algorithms usually distribute or manage keys as a whole without an explicit segmentation mechanism. The key granularity used by QKD depends on the bit rate of the quantum channel, and its distribution granularity is fixed at system initialization and cannot be dynamically changed according to network performance or security requirements. This fixed granularity mode is difficult to meet the real-time change requirements of security and efficiency in the key distribution process. If the granularity is too large, the security of key distribution may be reduced, as larger shunting units are more likely to become attack targets. If the granularity is too small, although the security may be improved, it will significantly increase the distribution delay and system resource occupation (such as communication bandwidth and computing power).
[0004] In summary, existing quantum secure key management techniques are difficult to meet the real-time change requirements of security and efficiency in the key distribution process. SUMMARY
[0005] The present application provides a quantum secure key management method and system based on homomorphic encryption, which can improve the security of key management while ensuring high system performance.
[0006] In a first aspect, to solve the above technical problems, the present application provides a quantum secure key management method based on homomorphic encryption, comprising: Obtaining key distribution requirements and determining a first key shunting granularity according to the key distribution requirements; According to the first key shunting granularity, determining a granularity security threshold based on a first homomorphic encryption algorithm and a preset quantum computing threat model; According to the first key shunting granularity and the granularity security threshold, performing security trend monitoring to obtain a second key shunting granularity; According to the second key shunting granularity, adjusting the second key shunting granularity based on a preset performance evaluation model to obtain a third key shunting granularity; obtaining a first encryption key, generating a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key; According to the third key shunting granularity, the shortest distribution path between each node of the system is calculated, and the second encryption key is distributed according to the shortest distribution path to obtain a node key; The node key is encrypted to obtain key data, and the key data is stored in the secure storage area of the node.
[0007] Preferably, the security threshold is determined based on a first homomorphic encryption algorithm and a preset quantum computing threat model according to the first key shunting granularity to obtain a granularity security threshold, including: According to the first key shunting granularity, the region is divided to obtain a key shunting granularity interval; The key shunting granularity interval is evaluated based on the first homomorphic encryption algorithm to obtain an interval encryption strength; Based on the preset quantum computing threat model, the key shunting granularity interval is simulated to obtain a quantum computing cracking threshold; The quantum computing cracking threshold and the interval encryption strength of each key shunting granularity interval are compared in value, and the key shunting granularity interval with an interval encryption strength greater than the quantum computing cracking threshold is determined as a granularity security threshold interval; According to the granularity security threshold interval, the smallest value in the granularity security threshold interval is selected as the granularity security threshold.
[0008] Preferably, the security trend is monitored according to the first key shunting granularity to obtain a second key shunting granularity, including: The first key shunting granularity and the granularity security threshold are compared in size, and when the first key shunting granularity is greater than the granularity security threshold, the first key shunting granularity is reduced based on a preset adjustment algorithm; when the first key shunting granularity is less than the granularity security threshold, the first key shunting granularity is increased based on the preset adjustment algorithm; The adjusted key shunting granularity is determined as the second key shunting granularity.
[0009] Preferably, the second key shunting granularity is adjusted based on a preset performance evaluation model to obtain a third key shunting granularity, including: The second key shunting granularity is evaluated based on the preset performance evaluation model to obtain a performance evaluation value; The performance evaluation value is compared with the preset system performance threshold. When the performance evaluation value is greater than the system performance threshold, the second key splitting granularity is adjusted based on the preset dynamic adjustment mechanism to obtain the third key splitting granularity.
[0010] Preferably, the step of obtaining the first encryption key, generating a second encryption key based on a homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key includes: Obtain the first encryption key; The first encryption key is generated based on a random number generation algorithm to obtain the initial encryption key; The initial encryption key is encrypted using a homomorphic encryption algorithm to obtain a second encryption key. The second encryption key replaces the first encryption key based on the atomic transaction mechanism.
[0011] Preferably, before generating the initial encryption key based on the random number generation algorithm for the first encryption key, the method further includes: Data extraction is performed on the first encryption key to obtain key attributes; The key attributes are updated based on a preset key update strategy. When the first encryption key meets the key update trigger condition, the first encryption key is generated based on a random number generation algorithm to obtain an initial encryption key.
[0012] Preferably, before replacing the first encryption key with the second encryption key based on the atomic transaction mechanism, the method further includes: The first encryption key and the second encryption key are encrypted respectively to obtain the third encryption key and the fourth encryption key; The third encryption key and the fourth encryption key are checked for consistency. If the third encryption key and the fourth encryption key are consistent, the second encryption key replaces the first encryption key. If the third encryption key and the fourth encryption key are inconsistent, the first encryption key is restored to the system.
[0013] Secondly, the present invention provides a quantum secure key management system based on homomorphic encryption, comprising: The granularity calculation module is used to obtain the key distribution requirements and determine the first key splitting granularity based on the key distribution requirements. The threshold determination module is used to determine the security threshold based on the first key splitting granularity, the first homomorphic encryption algorithm, and the preset quantum computing threat model to obtain the granular security threshold. The security detection module is used to perform security trend monitoring based on the first key splitting granularity and the granularity security threshold to obtain the second key splitting granularity. The granularity adjustment module is used to adjust the second key splitting granularity based on the second key splitting granularity and a preset performance evaluation model to obtain the third key splitting granularity. The key update module is used to obtain a first encryption key, generate a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replace the first encryption key with the second encryption key. The key distribution module is used to calculate the shortest distribution path between each node in the system according to the third key splitting granularity, and to distribute the second encryption key according to the shortest distribution path to obtain the node key; The key storage module is used to encrypt the node key to obtain key data and store the key data in the node's secure storage area.
[0014] Thirdly, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the quantum secure key management method based on homomorphic encryption as described above.
[0015] Fourthly, the present invention also provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the quantum secure key management method based on homomorphic encryption as described above.
[0016] Compared with existing technologies, the present invention has the following beneficial effects: The embodiments of the present invention provide a quantum-secure key management method and system based on homomorphic encryption. The method includes: obtaining key distribution requirements and determining a first key distribution granularity based on the key distribution requirements; determining a granular security threshold based on the first key distribution granularity, using a first homomorphic encryption algorithm and a preset quantum computing threat model; performing security trend monitoring based on the first key distribution granularity and the granular security threshold to obtain a second key distribution granularity; adjusting the second key distribution granularity based on a preset performance evaluation model to obtain a third key distribution granularity; obtaining a first encryption key, generating a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key; calculating the shortest distribution path between nodes in the system based on the third key distribution granularity, and distributing the second encryption key according to the shortest distribution path to obtain node keys; encrypting the node keys to obtain key data, and storing the key data in the secure storage area of the node.
[0017] In this invention, the method first determines the initial key splitting granularity based on key distribution requirements. Then, it uses homomorphic encryption algorithms to evaluate the security at different granularities and, combined with a quantum computing threat model, determines the security threshold for the key splitting granularity. Based on this granularity security threshold, the system can adjust the key distribution strategy in real time according to changes in the security environment. When a decrease in security is detected, the key splitting granularity is automatically reduced according to preset conditions to improve the ability to resist quantum attacks; conversely, when security is high, the granularity can be increased to improve system efficiency. Furthermore, the method also monitors the system's performance indicators in real time through a preset performance evaluation model. During monitoring, if the current key splitting granularity is found to cause a decrease in system performance, the granularity is automatically adjusted to within the system's performance tolerance range, ensuring that key management maintains high security without significantly burdening system performance. Finally, the method optimizes the key distribution path, calculates the shortest path between nodes within the system, and rationally allocates the key splitting granularity based on the node's processing capacity and network conditions. In summary, by dynamically adjusting the key splitting granularity and optimizing the distribution path, the method can improve the security of key management while ensuring high system performance. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating the quantum secure key management method based on homomorphic encryption provided in the first embodiment of the present invention. Figure 2 This is a schematic diagram of the structure of a quantum secure key management system based on homomorphic encryption provided in the second embodiment of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Reference Figure 1 The first embodiment of the present invention provides a quantum-secure key management method based on homomorphic encryption, comprising the following steps: S11, obtain the key distribution requirements, and determine the first key distribution granularity based on the key distribution requirements.
[0021] S12, based on the first key splitting granularity, a security threshold is determined based on the first homomorphic encryption algorithm and a preset quantum computing threat model to obtain a granular security threshold.
[0022] S13, based on the first key splitting granularity and the granularity security threshold, perform security trend monitoring to obtain the second key splitting granularity.
[0023] S14, Based on the second key splitting granularity, the second key splitting granularity is adjusted according to a preset performance evaluation model to obtain a third key splitting granularity.
[0024] S15, obtain the first encryption key, generate a key based on the second homomorphic encryption algorithm and the random number generation algorithm to obtain the second encryption key, and replace the first encryption key with the second encryption key.
[0025] S16, calculate the shortest distribution path between each node in the system according to the third key distribution granularity, and distribute the second encryption key according to the shortest distribution path to obtain the node key.
[0026] S17, the node key is encrypted to obtain key data, and the key data is stored in the node's secure storage area.
[0027] It is worth noting that with the development of quantum computing technology, many traditional cryptographic algorithms (such as RSA and ECC) face the risk of being quickly cracked. Quantum computing, utilizing the power of parallel computing, can complete decryption tasks that would take traditional computers millions of years in a very short time. Therefore, quantum security has become an important research direction in the field of cryptography.
[0028] To facilitate understanding of the present invention, some preferred embodiments of the present invention will be described in further detail below.
[0029] In step S11, the key distribution requirements are obtained, and the first key distribution granularity is determined based on the key distribution requirements.
[0030] It's worth noting that the first key splitting granularity refers to the degree of refinement in key management, where the key is divided into smaller segments (e.g., bits, bytes, or key fragments of a specific length). The size of the splitting granularity directly affects the security and efficiency of key distribution: a smaller splitting granularity improves security because attackers need to compromise smaller and more dispersed units; while a larger splitting granularity helps reduce communication and computational overhead during distribution, thus improving system efficiency. Therefore, determining the first key splitting granularity hinges on balancing the needs of security and efficiency.
[0031] Specifically, determining the initial key splitting granularity requires first analyzing the specific requirements of key distribution. This includes assessing the system's network structure, number of nodes, and distribution path complexity, while considering the priority of security requirements and the tolerance for efficiency. For example, in highly sensitive scenarios (such as those requiring defense against quantum computing attacks), security requirements dominate, and the splitting granularity needs to be more refined to reduce the risk of cracking individual key fragments. Conversely, in scenarios with higher efficiency requirements (such as network environments with high real-time requirements), the splitting granularity can be appropriately increased to reduce system resource consumption. By combining these requirements, a preliminary range for the key splitting granularity can be defined. This range will vary depending on the specific application, ranging from the smallest bit granularity to larger byte granularity or other custom unit granularities.
[0032] In step S12, based on the first key splitting granularity, a security threshold is determined using the first homomorphic encryption algorithm and a preset quantum computing threat model to obtain the granular security threshold.
[0033] Preferably, the step of determining the granular security threshold based on the first key splitting granularity, the first homomorphic encryption algorithm, and a preset quantum computing threat model, to obtain the granular security threshold includes: Based on the first key splitting granularity, the region is divided to obtain the key splitting granularity interval; The security assessment of the key splitting granularity interval is performed based on the first homomorphic encryption algorithm to obtain the interval encryption strength. Based on a preset quantum computing threat model, the cracking simulation is performed on the key splitting granularity range to obtain the quantum computing cracking threshold; The quantum computing cracking threshold and the interval encryption strength of each key splitting granularity interval are compared numerically, and the key splitting granularity interval with the interval encryption strength greater than the quantum computing cracking threshold is determined as the granular security threshold interval. Based on the granularity safety threshold range, the smallest granularity value within the granularity safety threshold range is selected as the granularity safety threshold.
[0034] Specifically, based on the first key splitting granularity, a security threshold is determined by combining a first homomorphic encryption algorithm and a preset quantum computing threat model, ultimately yielding a granular security threshold. This process first requires dividing the granularity range into multiple regions based on the first key splitting granularity, with each region corresponding to a key splitting granularity interval. Next, the first homomorphic encryption algorithm is used to assess the security of each key splitting granularity interval. The encryption strength value for each interval is obtained by measuring the strength of the encryption operations within that interval. The encryption strength reflects the key's resistance to cracking at that granularity; a higher value indicates stronger security at that granularity. Simultaneously, combined with the preset quantum computing threat model, a cracking simulation is performed on each splitting granularity interval to quantify the ability of quantum computing to crack the security, calculating the quantum computing cracking threshold for each interval. This threshold represents the maximum security level that quantum computing can overcome under current technological conditions.
[0035] It's worth noting that homomorphic encryption is a cryptographic technique that allows computations to be performed directly on encrypted data in its ciphertext state without decryption. This means that after data is encrypted, mathematical operations can be performed directly on the ciphertext, and the result will still be correct after decryption.
[0036] It is worth noting that the preset quantum computing threat model is a pre-defined model used to simulate and analyze the potential threats posed by quantum computing technology to encryption systems. The model simulates the ability of quantum computing to crack different key lengths, and by calculating key parameters such as the number of qubits and computation time, it predicts which encryption algorithms or granularities may be broken, assigning them a cracking threshold.
[0037] Subsequently, the encryption strength value of each key splitting granularity interval is compared one by one with the quantum computing cracking threshold, and intervals with encryption strength higher than the quantum computing cracking threshold are selected. These selected intervals can be used as secure key splitting granularity intervals, i.e., granular security threshold intervals. This selection process ensures that the selected granularity can maintain sufficient resistance to attacks under current quantum computing threats.
[0038] Finally, the smallest granularity value is selected from these granularity security threshold ranges as the final granularity security threshold. This selection method can further refine the splitting granularity while ensuring security, thereby minimizing the risk during key distribution and storage, and providing additional redundancy for system security.
[0039] In step S13, security trend monitoring is performed based on the first key splitting granularity and the granularity security threshold to obtain the second key splitting granularity.
[0040] Preferably, the step of performing security trend monitoring based on the first key splitting granularity to obtain the second key splitting granularity includes: The first key splitting granularity and the granularity security threshold are compared. If the first key splitting granularity is greater than the granularity security threshold, the first key splitting granularity is reduced based on a preset adjustment algorithm. If the first key splitting granularity is less than the granularity security threshold, the first key splitting granularity is increased based on the preset adjustment algorithm. The adjusted key splitting granularity is determined as the second key splitting granularity.
[0041] Specifically, based on the first key splitting granularity and granularity security threshold, the core of security trend monitoring is to dynamically adjust the key splitting granularity through a preset adjustment algorithm, thereby optimizing system performance while meeting security requirements. It is worth noting that the preset adjustment algorithm is a rule-based adjustment mechanism whose goal is to find a balance between different security and performance requirements.
[0042] Specifically, firstly, the system compares the granularity of the first key split with a granularity security threshold. If the granularity of the first key split is greater than the granularity security threshold, it indicates a security vulnerability in the current splitting granularity, as a larger granularity increases the risk of key fragments being cracked. In this case, a preset adjustment algorithm triggers a granularity reduction mechanism. In one feasible implementation, the preset adjustment algorithm can be an exponential decay algorithm, and the adjusted granularity can be expressed by the formula: To calculate, where, For the current splitting granularity, As the attenuation factor, To adjust the number of steps, this algorithm can quickly reduce the splitting granularity to near the granularity safety threshold while avoiding excessively large drops that could impact the system. On the other hand, when the first key splitting granularity is smaller than the granularity safety threshold, it indicates that the current splitting granularity is too small. While this provides higher security, it can lead to system performance issues, such as increased communication latency and excessive consumption of computing resources. In this case, the preset adjustment algorithm increases the splitting granularity to improve performance. In one feasible approach, a linear growth algorithm can be used, with the adjustment formula as follows: ,in, As a growth factor, the shunt granularity is gradually increased until it approaches a safe threshold, while ensuring that system performance is not negatively impacted by excessive increases. Alternatively, feedback control-based algorithms, such as proportional-integral-derivative (PID) controllers, can be employed.
[0043] Ultimately, the adjusted key distribution granularity was determined as the second key distribution granularity. This adjusted granularity not only meets the requirements of the current security environment but also maintains optimized performance. By applying the aforementioned adjustment algorithm, the key distribution strategy can be ensured to dynamically adapt to real-time changes in security and efficiency, enhancing the system's ability to respond to quantum computing threats and improving overall operational efficiency.
[0044] In step S14, the second key splitting granularity is adjusted based on a preset performance evaluation model according to the second key splitting granularity to obtain the third key splitting granularity.
[0045] Preferably, the step of adjusting the second key splitting granularity based on the second key splitting granularity and a preset performance evaluation model to obtain the third key splitting granularity includes: The second key splitting granularity is evaluated based on a preset performance evaluation model to obtain performance evaluation values; The performance evaluation value is compared with the preset system performance threshold. When the performance evaluation value is greater than the system performance threshold, the second key splitting granularity is adjusted based on the preset dynamic adjustment mechanism to obtain the third key splitting granularity.
[0046] Specifically, the purpose of adjusting the second key splitting granularity based on a preset performance evaluation model is to further improve the system's operating efficiency by optimizing the splitting granularity while ensuring that security requirements are met. This process first performs a performance evaluation on the second key splitting granularity to quantify its key performance indicators such as resource utilization, response speed, and computational load in the current system environment. It is worth noting that the performance evaluation model is a preset analysis tool that generates corresponding performance evaluation values based on the key splitting granularity's performance in the system, reflecting the overall operating efficiency and resource consumption of the system at the current splitting granularity.
[0047] Specifically, the performance evaluation model can include multiple metrics, such as computation processing latency, communication bandwidth usage, and inter-node transmission latency. Through comprehensive analysis of these metrics, the system can generate a performance evaluation value, which serves as the basis for granularity adjustment. A high performance evaluation value indicates that the current traffic splitting granularity has a significant negative impact on system performance, such as excessive communication or resource consumption due to overly fine granularity. Conversely, a low performance evaluation value indicates that the current traffic splitting granularity has a smaller impact on system performance, leaving room for further optimization.
[0048] After obtaining the performance evaluation value, the system compares it with a preset system performance threshold. This performance threshold is a reference value set based on the system's performance requirements and operational goals, used to determine whether the current traffic splitting granularity needs adjustment. When the performance evaluation value exceeds the performance threshold, it means that the current traffic splitting granularity is too fine, placing a significant burden on system resources. In this case, the system will activate a preset dynamic adjustment mechanism to expand the traffic splitting granularity. In one feasible approach, the dynamic adjustment mechanism can employ a progressive expansion algorithm, for example, by incrementally adjusting the granularity, as shown in the formula: ,in, The adjusted granularity, For the current splitting granularity, To adjust the step size, This represents the current performance evaluation value and performance threshold. This mechanism can gradually reduce the system's resource pressure while avoiding instability caused by overly rapid granularity adjustments. On the other hand, if the performance evaluation value is less than the performance threshold, it indicates that the current granularity of traffic splitting still has room for optimization, being too coarse and not fully utilizing the system's computing power and communication bandwidth. In this case, the dynamic adjustment mechanism will trigger a granularity refinement operation. One optional approach is to use a proportional reduction algorithm, with the formula: , To reduce the scaling factor, this algorithm can further refine the splitting granularity while ensuring that system performance is not significantly affected, thereby improving security.
[0049] After the above adjustments, the final key splitting granularity was determined to be the third key splitting granularity. Compared to the second key splitting granularity, the third key splitting granularity achieves a better balance between performance and security. Through the combination of a performance evaluation model and a dynamic adjustment mechanism, the system can not only optimize the key splitting strategy based on real-time performance feedback, but also ensure adaptability under different operating environments, further improving the flexibility and efficiency of key management.
[0050] In step S15, a first encryption key is obtained, a second encryption key is generated based on a second homomorphic encryption algorithm and a random number generation algorithm, and the second encryption key replaces the first encryption key.
[0051] Preferably, the step of obtaining the first encryption key, generating a second encryption key based on a homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key includes: Obtain the first encryption key; The first encryption key is generated based on a random number generation algorithm to obtain the initial encryption key; The initial encryption key is encrypted using a homomorphic encryption algorithm to obtain a second encryption key. The second encryption key replaces the first encryption key based on the atomic transaction mechanism.
[0052] Specifically, by obtaining a first encryption key and generating a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, the first encryption key is then replaced with the second encryption key. The purpose is to achieve secure key updates and further enhance the system's ability to resist potential quantum computing threats.
[0053] Preferably, before generating the initial encryption key based on the random number generation algorithm for the first encryption key, the method further includes: Data extraction is performed on the first encryption key to obtain key attributes; The key attributes are updated based on a preset key update strategy. When the first encryption key meets the key update trigger condition, the first encryption key is generated based on a random number generation algorithm to obtain an initial encryption key.
[0054] Preferably, before replacing the first encryption key with the second encryption key based on the atomic transaction mechanism, the method further includes: The first encryption key and the second encryption key are encrypted respectively to obtain the third encryption key and the fourth encryption key; The third encryption key and the fourth encryption key are checked for consistency. If the third encryption key and the fourth encryption key are consistent, the second encryption key replaces the first encryption key. If the third encryption key and the fourth encryption key are inconsistent, the first encryption key is restored to the system.
[0055] Specifically, the entire process of obtaining the first encryption key and generating the second encryption key based on the second homomorphic encryption algorithm and the random number generation algorithm is to address the key security risks in the quantum computing environment while ensuring the security and consistency of the system.
[0056] First, by acquiring the first encryption key, the system extracts the currently used key and its related attribute information. For example, these attributes may include the key's generation time, usage count, and encryption strength; this information provides a basis for determining whether the key needs to be updated. Subsequently, the system judges these attributes according to a preset key update strategy. For example, the update strategy may include triggering conditions such as the key being used more than a certain number of times, the key's lifespan nearing its end, or the detection of a potential security threat. When these conditions are met, the system updates the first encryption key by generating a new initial encryption key using a random number generation algorithm. The goal of the random number generation algorithm is to generate high-entropy, unpredictable random numbers, thereby ensuring the security of the new key. For example, commonly used algorithms may include hardware random number generators (based on physical phenomena) or pseudo-random number generators (based on algorithmic calculations). This random number will serve as the initial encryption key, replacing the old key.
[0057] Specifically, after generating the initial encryption key, the system encrypts it using a second homomorphic encryption algorithm to obtain the final second encryption key. Homomorphic encryption allows direct computation of the ciphertext without decryption, ensuring the key remains encrypted throughout generation and storage, thus reducing the risk of exposure.
[0058] After generating the second encryption key, the system needs to use it to replace the first encryption key. An atomic transaction mechanism is introduced to ensure the integrity and consistency of the replacement process. It's worth noting that atomic transaction mechanisms are a concept from databases and distributed systems. Their core principle is to ensure that a set of operations either all succeed or all roll back, avoiding intermediate states. For example, during key replacement, if the operation is interrupted for any reason (such as system failure or network problems), the transaction mechanism will automatically roll back, restoring the system to its state before the replacement, ensuring that key inconsistencies do not occur. Furthermore, after the replacement is complete, the transaction mechanism ensures that the replacement result takes effect immediately; the entire operation is atomic to the system, meaning it is indivisible.
[0059] Specifically, before key replacement, to further ensure key consistency and reliability, the first and second encryption keys need to be encrypted separately to obtain the third and fourth encryption keys. It's worth noting that symmetric encryption algorithms, such as AES or DES, can be used to encrypt the first and second encryption keys respectively. Next, the system performs a consistency check on these two keys, for example, through hash value comparison or checksum verification, to ensure their integrity during the replacement operation. If the check results show inconsistency, the key replacement operation is considered abnormal, and the system will automatically roll back, restoring the first encryption key to its original state. Only if the consistency check passes will the replacement operation continue, ultimately completing the replacement of the first encryption key with the second encryption key.
[0060] In step S16, the shortest distribution path between each node in the system is calculated according to the third key distribution granularity, and the second encryption key is distributed according to the shortest distribution path to obtain the node key.
[0061] Specifically, based on the third key distribution granularity, the shortest distribution path between each node in the system is calculated, and the path is used for key distribution, aiming to ensure the efficiency and security of key distribution, thereby generating a unique key for each node, namely the node key.
[0062] First, determining the third key splitting granularity provides the foundation for key distribution, specifying the size of the key fragments. It's worth noting that during distribution, the splitting granularity directly impacts both efficiency and security. Smaller splitting granularity results in the key being divided into more fragments during transmission, increasing distribution complexity but also improving security, as attackers need to crack more key fragments to recover the complete key. Larger splitting granularity, on the other hand, simplifies the distribution process but exposes the key to a higher risk of single-point attacks. Therefore, the setting of the third key splitting granularity before key distribution has already balanced the needs of efficiency and security through the preceding steps.
[0063] After determining the splitting granularity, the system needs to calculate the shortest distribution path between each node. This process involves the application of path optimization algorithms. In one feasible approach, Dijkstra's algorithm is used to quickly calculate the shortest path from the source node to each target node. Specifically, the system models the connectivity between nodes based on the network topology, generating a weighted graph where nodes represent devices or servers participating in key distribution, and edge weights represent the transmission costs between nodes, such as communication latency, bandwidth consumption, or security risks. In this invention, using Dijkstra's algorithm as an example, the system starts from the source node and gradually expands to other nodes, selecting the shortest path to unvisited nodes at each step. This iterative calculation method can efficiently determine the optimal distribution path from the source node to all target nodes.
[0064] Specifically, after obtaining the shortest paths, the system distributes the second encryption key according to these paths. During key distribution, intermediate nodes on each path need to receive and forward key fragments according to the specified splitting granularity to ensure the integrity and security of key distribution. To further enhance the reliability of distribution, the system can adopt a distributed key distribution strategy or a multi-path distribution strategy. Specifically, the distributed key distribution strategy allocates key fragments to multiple paths, ensuring that even if a single path is attacked or interrupted, the entire key distribution will not fail. The multi-path distribution strategy, on the other hand, transmits fragments of the same key simultaneously through different paths, improving attack resistance and fault tolerance.
[0065] During the distribution process, the system needs to assign a unique node key to each node. The node key can be generated by combining a second encryption key and a node identifier; for example, by calculating a unique key using a hash function or encryption algorithm on the key and node information. After the node keys are distributed, each node can only decrypt its own key fragment, thus ensuring the security of the key during distribution and use. Simultaneously, the use of node keys ensures that each node remains independent when participating in subsequent communication or encryption tasks, reducing the cascading risks caused by single points of failure or key leakage.
[0066] In step S17, the node key is encrypted to obtain key data, and the key data is stored in the node's secure storage area.
[0067] Specifically, the encryption and storage of node keys is the final step in the entire key management process. Its goal is to generate key data and store it in the secure storage area of the node by further encrypting the node keys, thereby ensuring the confidentiality, integrity and availability of the keys during the storage stage and resisting the risks of eavesdropping, tampering and loss.
[0068] Specifically, firstly, encrypting the node key enhances its security. While the node key itself already possesses some security features, encrypting it before storage further reduces the likelihood of unauthorized access or leakage during storage. One feasible approach is to employ both symmetric and asymmetric encryption techniques. In this stage, an efficient symmetric encryption algorithm, such as AES (Advanced Encryption Standard), can be used. During encryption, the node key is input as plaintext and processed by the encryption algorithm to generate ciphertext, which is the key data. The key data includes not only the encrypted node key information but also other auxiliary information, such as the node identifier, encryption algorithm version number, and timestamp. This information can be structured and stored in a specific format (e.g., ASN.1 encoding or JSON format) for subsequent parsing and use.
[0069] After encryption, the system stores the generated key data in the node's secure storage area. It's important to note that the secure storage area is a strictly protected storage environment designed to prevent unauthorized access and data tampering. Depending on the system's specific needs, the secure storage area can be a Physical Security Module (HSM), a Trusted Platform Module (TPM), a protected memory area, or a software-encrypted virtual storage area. For example, an HSM is a dedicated hardware device that provides multiple functions, including key management, encryption operations, and physical protection. By storing key data in an HSM, physical attacks and side-channel attacks can be effectively prevented. For software environments, the secure storage area can enhance data protection through full-disk encryption (such as BitLocker) or file system encryption (such as eCryptfs in Linux).
[0070] In summary, this invention provides a quantum-secure key management method based on homomorphic encryption, comprising: obtaining key distribution requirements and determining a first key distribution granularity based on the key distribution requirements; determining a granular security threshold based on a first homomorphic encryption algorithm and a preset quantum computing threat model based on the first key distribution granularity; performing security trend monitoring based on the first key distribution granularity and the granular security threshold to obtain a second key distribution granularity; adjusting the second key distribution granularity based on a preset performance evaluation model based on the second key distribution granularity to obtain a third key distribution granularity; obtaining a first encryption key, generating a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key; calculating the shortest distribution path between nodes in the system based on the third key distribution granularity, and distributing the second encryption key according to the shortest distribution path to obtain node keys; encrypting the node keys to obtain key data, and storing the key data in the secure storage area of the node.
[0071] In this invention, the method first determines the initial key splitting granularity based on key distribution requirements. Then, it uses homomorphic encryption algorithms to evaluate the security at different granularities and, combined with a quantum computing threat model, determines the security threshold for the key splitting granularity. Based on this granularity security threshold, the system can adjust the key distribution strategy in real time according to changes in the security environment. When a decrease in security is detected, the key splitting granularity is automatically reduced according to preset conditions to improve the ability to resist quantum attacks; conversely, when security is high, the granularity can be increased to improve system efficiency. Furthermore, the method also monitors the system's performance indicators in real time through a preset performance evaluation model. During monitoring, if the current key splitting granularity is found to cause a decrease in system performance, the granularity is automatically adjusted to within the system's performance tolerance range, ensuring that key management maintains high security without significantly burdening system performance. Finally, the method optimizes the key distribution path, calculates the shortest path between nodes within the system, and rationally allocates the key splitting granularity based on the node's processing capacity and network conditions. In summary, by dynamically adjusting the key splitting granularity and optimizing the distribution path, the method can improve the security of key management while ensuring high system performance.
[0072] Reference Figure 2 The second embodiment of the present invention provides a quantum secure key management system based on homomorphic encryption, comprising: The granularity calculation module is used to obtain the key distribution requirements and determine the first key splitting granularity based on the key distribution requirements. The threshold determination module is used to determine the security threshold based on the first key splitting granularity, the first homomorphic encryption algorithm, and the preset quantum computing threat model to obtain the granular security threshold. The security detection module is used to perform security trend monitoring based on the first key splitting granularity and the granularity security threshold to obtain the second key splitting granularity. The granularity adjustment module is used to adjust the second key splitting granularity based on the second key splitting granularity and a preset performance evaluation model to obtain the third key splitting granularity. The key update module is used to obtain a first encryption key, generate a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replace the first encryption key with the second encryption key. The key distribution module is used to calculate the shortest distribution path between each node in the system according to the third key splitting granularity, and to distribute the second encryption key according to the shortest distribution path to obtain the node key; The key storage module is used to encrypt the node key to obtain key data and store the key data in the node's secure storage area.
[0073] It should be noted that the quantum secure key management system based on homomorphic encryption provided in this embodiment of the invention is used to execute all the process steps of the quantum secure key management method based on homomorphic encryption in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.
[0074] This invention also provides an electronic device. The electronic device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a quantum secure key management method program based on homomorphic encryption. When the processor executes the computer program, it implements the steps in the various embodiments of the quantum secure key management method based on homomorphic encryption described above, for example... Figure 1 The step S11 shown. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above-described device embodiments, such as the key update module.
[0075] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.
[0076] The electronic device may be a desktop computer, laptop, handheld computer, or smart tablet, etc. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. It may include more or fewer components than described above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.
[0077] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device via various interfaces and lines.
[0078] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0079] Wherein, if the modules / units integrated in the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0080] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0081] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A quantum-secure key management method based on homomorphic encryption, characterized in that, include: Obtain the key distribution requirements, and determine the first key splitting granularity based on the key distribution requirements; Based on the first key splitting granularity, a security threshold is determined using the first homomorphic encryption algorithm and a preset quantum computing threat model to obtain the granular security threshold; Based on the first key splitting granularity and the granularity security threshold, security trend monitoring is performed to obtain the second key splitting granularity; Based on the second key splitting granularity, the second key splitting granularity is adjusted according to a preset performance evaluation model to obtain the third key splitting granularity; Obtain the first encryption key, generate a second encryption key based on the second homomorphic encryption algorithm and the random number generation algorithm, and replace the first encryption key with the second encryption key; Based on the third key distribution granularity, the shortest distribution path between each node in the system is calculated, and the second encryption key is distributed according to the shortest distribution path to obtain the node key; The node key is encrypted to obtain key data, and the key data is stored in the node's secure storage area.
2. The quantum secure key management method based on homomorphic encryption according to claim 1, characterized in that, The step of determining a granular security threshold based on the first key splitting granularity, the first homomorphic encryption algorithm, and a preset quantum computing threat model, to obtain a granular security threshold includes: Based on the first key splitting granularity, the region is divided to obtain the key splitting granularity interval; The security assessment of the key splitting granularity interval is performed based on the first homomorphic encryption algorithm to obtain the interval encryption strength. Based on a preset quantum computing threat model, the cracking simulation is performed on the key splitting granularity range to obtain the quantum computing cracking threshold; The quantum computing cracking threshold and the interval encryption strength of each key splitting granularity interval are compared numerically, and the key splitting granularity interval with the interval encryption strength greater than the quantum computing cracking threshold is determined as the granular security threshold interval. Based on the granularity safety threshold range, the smallest granularity value within the granularity safety threshold range is selected as the granularity safety threshold.
3. The quantum secure key management method based on homomorphic encryption according to claim 1, characterized in that, The step of performing security trend monitoring based on the first key splitting granularity to obtain the second key splitting granularity includes: The first key splitting granularity and the granularity security threshold are compared. If the first key splitting granularity is greater than the granularity security threshold, the first key splitting granularity is reduced based on a preset adjustment algorithm. If the first key splitting granularity is less than the granularity security threshold, the first key splitting granularity is increased based on the preset adjustment algorithm. The adjusted key splitting granularity is determined as the second key splitting granularity.
4. The quantum-secure key management method based on homomorphic encryption according to claim 1, characterized in that, The step of adjusting the second key splitting granularity based on the second key splitting granularity and a preset performance evaluation model to obtain the third key splitting granularity includes: The second key splitting granularity is evaluated based on a preset performance evaluation model to obtain performance evaluation values; The performance evaluation value is compared with the preset system performance threshold. When the performance evaluation value is greater than the system performance threshold, the second key splitting granularity is adjusted based on the preset dynamic adjustment mechanism to obtain the third key splitting granularity.
5. The quantum secure key management method based on homomorphic encryption according to claim 1, characterized in that, The process of obtaining a first encryption key, generating a second encryption key based on a homomorphic encryption algorithm and a random number generation algorithm, and replacing the first encryption key with the second encryption key includes: Obtain the first encryption key; The first encryption key is generated based on a random number generation algorithm to obtain the initial encryption key; The initial encryption key is encrypted using a homomorphic encryption algorithm to obtain a second encryption key. The second encryption key replaces the first encryption key based on the atomic transaction mechanism.
6. The quantum secure key management method based on homomorphic encryption according to claim 5, characterized in that, Before generating the initial encryption key based on the random number generation algorithm for the first encryption key, the method further includes: Data extraction is performed on the first encryption key to obtain key attributes; The key attributes are updated based on a preset key update strategy. When the first encryption key meets the key update trigger condition, the first encryption key is generated based on a random number generation algorithm to obtain an initial encryption key.
7. The quantum secure key management method based on homomorphic encryption according to claim 5, characterized in that, Before replacing the first encryption key with the second encryption key based on the atomic transaction mechanism, the method further includes: The first encryption key and the second encryption key are encrypted respectively to obtain the third encryption key and the fourth encryption key; The third encryption key and the fourth encryption key are checked for consistency. If the third encryption key and the fourth encryption key are consistent, the second encryption key replaces the first encryption key. If the third encryption key and the fourth encryption key are inconsistent, the first encryption key is restored to the system.
8. A quantum-secure key management system based on homomorphic encryption, characterized in that, include: The granularity calculation module is used to obtain the key distribution requirements and determine the first key splitting granularity based on the key distribution requirements. The threshold determination module is used to determine the security threshold based on the first key splitting granularity, the first homomorphic encryption algorithm, and the preset quantum computing threat model to obtain the granular security threshold. The security detection module is used to perform security trend monitoring based on the first key splitting granularity and the granularity security threshold to obtain the second key splitting granularity. The granularity adjustment module is used to adjust the second key splitting granularity based on the second key splitting granularity and a preset performance evaluation model to obtain the third key splitting granularity. The key update module is used to obtain a first encryption key, generate a second encryption key based on a second homomorphic encryption algorithm and a random number generation algorithm, and replace the first encryption key with the second encryption key. The key distribution module is used to calculate the shortest distribution path between each node in the system according to the third key splitting granularity, and to distribute the second encryption key according to the shortest distribution path to obtain the node key; The key storage module is used to encrypt the node key to obtain key data and store the key data in the node's secure storage area.
9. An electronic device, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the quantum secure key management method based on homomorphic encryption as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform the quantum secure key management method based on homomorphic encryption as described in any one of claims 1 to 7.