Anti-quantum-attack message processing method and system, electronic equipment and storage medium

By combining quantum-resistant cryptographic algorithms and updatable encryption technology with symmetric key encryption and digital signatures, the problem that existing technologies cannot resist quantum attacks has been solved, and the security and integrity of data in a quantum environment has been achieved.

CN121217331APending Publication Date: 2025-12-26中电信量子信息科技集团有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511392358.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing updatable encryption technologies cannot withstand attacks from quantum computing; even updated keys remain at risk of being cracked, and data security cannot be guaranteed.

Method used

A quantum-resistant cryptographic algorithm is used to generate symmetric key encapsulated ciphertext, and an updatable encryption technology is combined to dynamically update the key pair by updating the token, ensuring the security of the key in a quantum computing environment. At the same time, digital signature verification is introduced to ensure the integrity and authenticity of the data.

Benefits of technology

It achieves comprehensive protection of data confidentiality, integrity, and authentication in a quantum computing environment, ensuring that data can be securely transferred to a new key in a timely manner in the event of key leakage, reducing the risk of data leakage and improving system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121217331A_ABST
    Figure CN121217331A_ABST
Patent Text Reader

Abstract

The invention provides an anti-quantum-attack message processing method and system, electronic equipment and a storage medium, and relates to the technical field of information security. In the message encryption process, a symmetric key encryption algorithm based on an anti-quantum cryptographic algorithm is introduced to encrypt the message, and the anti-quantum technology is effectively fused into the encryption technology, so that the encryption process has the anti-quantum characteristic, and the message can be prevented from being cracked due to the fact that the symmetric key cannot be attacked. And when the secret key leaks, the secret key pair can be dynamically updated to update the digital signature information in the ciphertext information, so that the message data can be timely and safely converted to a new secret key when the secret key leaks or needs to be updated. And the digital signature information is carried in the ciphertext information, and the digital signature information is updated in time after the secret key is leaked, so that the digital signature information can be verified based on the updated secret key information when the message is decrypted, and the integrity and authenticity of the message are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and more specifically, to a message processing method, system, electronic device, and storage medium resistant to quantum attacks. Background Technology

[0002] With the rapid development of cloud storage and network technologies, the secure storage and transmission of data has become a key challenge in today's digital age. The widespread adoption of cloud storage services allows users to easily upload data to the cloud, achieving efficient data storage and sharing. However, this convenience also brings hidden risks to data security, especially in key management. Once a key is leaked, all encrypted data is at risk of being decrypted, potentially leading to a serious data breach. Based on this, updatable encryption technology has emerged. Updatable encryption technology allows for the dynamic updating of keys for encrypted data; even if the old key is leaked, the new key ensures data security.

[0003] Currently, while existing updatable encryption technologies support key updates, these updates rely on traditional cryptographic algorithms, which are vulnerable to quantum computing attacks. The updated keys still face the risk of being cracked, and data security cannot be guaranteed. Summary of the Invention

[0004] The purpose of this application is to address the shortcomings of the prior art by providing a message processing method, system, electronic device, and storage medium resistant to quantum attacks, so as to achieve comprehensive protection of data confidentiality, integrity, and identity authentication.

[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of this application are as follows:

[0006] In a first aspect, embodiments of this application provide a quantum-resistant message processing method applied to a cloud server, the method comprising:

[0007] Receive initial ciphertext information sent by the sending terminal, the ciphertext information including: encapsulated ciphertext, message ciphertext, and digital signature information;

[0008] In the current round, the receiving terminal sends a first update token and a second update token. The first update token includes a first update ratio and an updated first public key. The first update ratio is generated based on the updated first private key and the first private key before the update. The second update token includes a second update ratio and an updated second public key. The second update ratio is generated based on the updated second private key and the second private key before the update.

[0009] Obtain the current encrypted information, and update the digital signature information in the current encrypted information according to the first update token and the second update token to obtain the current new encrypted information.

[0010] Optionally, updating the digital signature information in the current ciphertext information based on the first update token and the second update token to obtain the new ciphertext information includes:

[0011] Based on the first update ratio, the second update ratio, and the digital signature information in the current encrypted information, generate the current new digital signature information;

[0012] Based on the new digital signature information, update the digital signature information in the current ciphertext information to obtain the new ciphertext information.

[0013] Optionally, updating the digital signature information in the current ciphertext information based on the new digital signature information to obtain the new ciphertext information includes:

[0014] The digital signature information in the current encrypted information is replaced with the new digital signature information to obtain the current new encrypted information.

[0015] Secondly, embodiments of this application also provide a quantum-resistant message processing method, applied to a sending terminal, the method comprising:

[0016] Receive the second initial public key from the receiving terminal, and generate a ciphertext encapsulated with a symmetric key based on the second initial public key;

[0017] Based on the symmetric key, a quantum-resistant data encapsulation algorithm is used to encrypt the target message and generate message ciphertext.

[0018] Based on the first initial private key of the sending terminal, the encapsulated ciphertext and the message ciphertext are signed to obtain digital signature information;

[0019] Based on the encapsulated ciphertext, the message ciphertext, and the digital signature information, the initial ciphertext information is obtained and sent to the cloud server.

[0020] In the current round, a first update token is generated based on the first key pair before the update and the first key pair after the update, and the first update token is sent to the cloud server.

[0021] Optionally, generating the ciphertext encapsulated with the symmetric key based on the second initial public key includes:

[0022] Based on the second initial public key, the symmetric key is encapsulated using a quantum-resistant key encapsulation algorithm to obtain the encapsulated ciphertext of the symmetric key.

[0023] Optionally, generating the first update token based on the first key pair before the update and the first key pair after the update includes:

[0024] The first update ratio is determined based on the first private key in the first key pair before the update and the first private key in the first key pair after the update;

[0025] The first update token is generated based on the first update ratio and the first public key in the updated first key pair.

[0026] Optionally, determining the first update ratio based on the first private key in the first key pair before the update and the first private key in the first key pair after the update includes:

[0027] The ratio of the first private key in the updated first key pair to the first private key in the original first key pair is used as the first update ratio.

[0028] Optionally, before signing the encapsulated ciphertext and the message ciphertext according to the first initial private key of the sending terminal to obtain digital signature information, the method further includes:

[0029] Based on a preset data field, the first initial private key is randomly selected;

[0030] Based on the first initial private key, determine the first initial public key;

[0031] The first initial key pair of the sending terminal is obtained based on the first initial private key and the first initial public key;

[0032] The first initial public key is sent to the receiving terminal.

[0033] Optionally, it also includes:

[0034] If the preset interval has elapsed since the last round, or if a key pair leak is detected, then proceed to the current round.

[0035] Thirdly, this application also provides a quantum-resistant message processing method applied to a receiving terminal. The method includes: in the current round, generating a second update token based on the second key pair before the update and the second key pair after the update of the receiving terminal.

[0036] Send the second update token to the cloud server.

[0037] Optionally, the receiving terminal generates a second update token from the pre-update second key pair and the post-update second key pair, including:

[0038] A second update ratio is generated based on the second private key in the second key pair before the update and the second private key in the second key pair after the update;

[0039] The second update token is generated based on the second update ratio and the second public key in the updated second key pair.

[0040] Optionally, generating a second update ratio based on the second private key in the second key pair before the update and the second private key in the second key pair after the update includes:

[0041] A hash operation is performed on the second private key in the updated second key pair to obtain a first hash result;

[0042] Perform a hash operation on the second private key in the second key pair before the update to obtain a second hash result;

[0043] The ratio of the first hash result to the second hash result is used as the second update ratio.

[0044] Optionally, it also includes:

[0045] Based on preset global security parameters, a lattice-based post-quantum key algorithm is used to generate an initial second key pair for the receiving terminal; the initial second key pair includes: a second initial private key and a second initial public key;

[0046] Send the second initial public key from the initial second key pair to the sending terminal.

[0047] Optionally, it also includes:

[0048] Access the cloud server to obtain the new encrypted information for the current round and the first public key in the updated first key pair of the sending terminal for the current round;

[0049] The digital signature information in the new ciphertext is verified by using the first public key in the updated first key pair.

[0050] If the verification is successful, the encapsulated ciphertext in the new ciphertext information is decrypted using the second private key in the updated second key pair to obtain the symmetric key;

[0051] The target message is obtained by decrypting the message ciphertext in the new ciphertext information using the symmetric key.

[0052] Fourthly, embodiments of this application also provide a message processing system resistant to quantum attacks, including: a cloud server, a sending terminal, and a receiving terminal;

[0053] The cloud server is used to perform the steps of the method described in any of the first aspects above;

[0054] The transmitting terminal is used to perform the steps of the method described in any of the second aspects above;

[0055] The receiving terminal is used to perform the steps of the method described in any of the third aspects above.

[0056] Fifthly, embodiments of this application also provide a message processing device resistant to quantum attacks, the device comprising: a receiving module and an updating module;

[0057] The receiving module is used to receive initial ciphertext information sent by the sending terminal, the ciphertext information including: encapsulated ciphertext, message ciphertext, and digital signature information;

[0058] In the current round, the receiving terminal sends a first update token and a second update token. The first update token includes a first update ratio and an updated first public key. The first update ratio is generated based on the updated first private key and the first private key before the update. The second update token includes a second update ratio and an updated second public key. The second update ratio is generated based on the updated second private key and the second private key before the update.

[0059] The update module is used to obtain the current ciphertext information and update the digital signature information in the current ciphertext information according to the first update token and the second update token to obtain the new ciphertext information.

[0060] Optionally, the update module is specifically used to generate new digital signature information based on the first update ratio, the second update ratio, and the digital signature information in the current encrypted information;

[0061] Based on the new digital signature information, update the digital signature information in the current ciphertext information to obtain the new ciphertext information.

[0062] Optionally, the update module is specifically used to replace the digital signature information in the current ciphertext information with the new digital signature information to obtain the current new ciphertext information.

[0063] Sixthly, embodiments of this application also provide a message processing device resistant to quantum attacks, the device comprising: a generation module and a processing module;

[0064] The generation module is used to receive the second initial public key of the receiving terminal and generate the ciphertext of the symmetric key based on the second initial public key.

[0065] The processing module is used to encrypt the target message using a quantum-resistant data encapsulation algorithm based on the symmetric key, and generate message ciphertext.

[0066] Based on the first initial private key of the sending terminal, the encapsulated ciphertext and the message ciphertext are signed to obtain digital signature information;

[0067] Based on the encapsulated ciphertext, the message ciphertext, and the digital signature information, the initial ciphertext information is obtained and sent to the cloud server.

[0068] The generation module is used to generate a first update token in the current round based on the first key pair before the update and the first key pair after the update, and send the first update token to the cloud server.

[0069] Optionally, the generation module is specifically used to encapsulate the symmetric key using a quantum-resistant key encapsulation algorithm based on the second initial public key, thereby obtaining the encapsulated ciphertext of the symmetric key.

[0070] Optionally, the generation module is specifically used to determine a first update ratio based on the first private key in the first key pair before the update and the first private key in the first key pair after the update;

[0071] The first update token is generated based on the first update ratio and the first public key in the updated first key pair.

[0072] Optionally, the generation module is specifically used to take the ratio of the first private key in the updated first key pair to the first private key in the unupdated first key pair as the first update ratio.

[0073] Optionally, the generation module is further configured to randomly select the first initial private key based on a preset data domain;

[0074] Based on the first initial private key, determine the first initial public key;

[0075] The first initial key pair of the sending terminal is obtained based on the first initial private key and the first initial public key;

[0076] The first initial public key is sent to the receiving terminal.

[0077] Optionally, if a preset interval has elapsed since the last round, or if a key pair leak is detected, then proceed to the current round.

[0078] In a seventh aspect, embodiments of this application also provide a schematic diagram of a message processing device resistant to quantum attacks, the device comprising: a generation module and a sending module;

[0079] The generation module is used to generate a second update token in the current round based on the second key pair before the update and the second key pair after the update of the receiving terminal.

[0080] The sending module is used to send the second update token to the cloud server.

[0081] Optionally, the generation module is specifically used to generate a second update ratio based on the second private key in the second key pair before the update and the second private key in the second key pair after the update;

[0082] The second update token is generated based on the second update ratio and the second public key in the updated second key pair.

[0083] Optionally, the generation module is specifically used to perform a hash operation on the second private key in the updated second key pair to obtain a first hash result;

[0084] Perform a hash operation on the second private key in the second key pair before the update to obtain a second hash result;

[0085] The ratio of the first hash result to the second hash result is used as the second update ratio.

[0086] Optionally, the generation module is further configured to generate an initial second key pair for the receiving terminal using a lattice-based post-quantum key algorithm based on preset global security parameters; the initial second key pair includes: a second initial private key and a second initial public key;

[0087] Send the second initial public key from the initial second key pair to the sending terminal.

[0088] Optionally, it may also include: a decryption module;

[0089] The decryption module is used to access the cloud server to obtain the new ciphertext information of the current round and the first public key in the updated first key pair of the sending terminal of the current round.

[0090] The digital signature information in the new ciphertext is verified by using the first public key in the updated first key pair.

[0091] If the verification is successful, the encapsulated ciphertext in the new ciphertext information is decrypted using the second private key in the updated second key pair to obtain the symmetric key;

[0092] The target message is obtained by decrypting the message ciphertext in the new ciphertext information using the symmetric key.

[0093] Eighthly, embodiments of this application provide an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the machine-readable instructions to implement the quantum-resistant message processing method provided in the first, second, or third aspects.

[0094] In a ninth aspect, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, performs a quantum-resistant message processing method as provided in the first, second, or third aspect.

[0095] The beneficial effects of this application are:

[0096] This application provides a quantum-resistant message processing method, system, electronic device, and storage medium, comprising: a sending terminal receiving a second initial public key from a receiving terminal, and generating a symmetric key-encapsulated ciphertext based on the second initial public key; the sending terminal encrypting a target message using a quantum-resistant data encapsulation algorithm based on the symmetric key to generate message ciphertext; the sending terminal signing the encapsulated ciphertext and the message ciphertext using a first initial private key to obtain digital signature information; the sending terminal obtaining initial ciphertext information based on the encapsulated ciphertext, the message ciphertext, and the digital signature information, and sending the initial ciphertext information to a cloud server; and the cloud server receiving the initial ciphertext sent by the sending terminal. Information; In the current round, the sending terminal generates a first update token based on the first key pair before and after the update, and sends the first update token to the cloud server; In the current round, the receiving terminal generates a second update token based on the second key pair before and after the update; the receiving terminal sends the second update token to the cloud server; In the current round, the cloud server receives the first update token sent by the sending terminal and the second update token sent by the receiving terminal; the cloud server obtains the current ciphertext information and updates the digital signature information in the current ciphertext information according to the first and second update tokens, thus obtaining the new ciphertext information. During message encryption, a symmetric key encryption algorithm based on quantum-resistant cryptography is introduced to encrypt the message, then encapsulates the symmetric key, and assembles the encapsulated ciphertext, the message ciphertext, and the digital signature information to obtain the ciphertext information. This effectively integrates quantum-resistant technology into the encryption technology, making the encryption process more quantum-resistant, and because the symmetric key cannot be attacked, it can prevent the message from being cracked. When a key is leaked, updatable key technology allows for dynamic updates to the key pair. Based on the updated and original key pairs, the digital signature information in the ciphertext is updated, ensuring that message data can be securely and promptly transferred to the new key when a key leak occurs or the ciphertext needs updating. This is done without downloading and decrypting the encapsulated ciphertext and the original message; only the digital signature information needs updating, allowing for rapid updates. Furthermore, by embedding the digital signature within the ciphertext, and ensuring its timely update after a key leak, message decryption can be performed by verifying the digital signature based on the updated key information, guaranteeing message integrity and authenticity. By combining quantum-resistant cryptography, updatable encryption, and digital signature technologies, a comprehensive, efficient, and secure solution is provided for cloud storage environments, achieving integrated protection for data confidentiality, integrity, and authentication. Attached Figure Description

[0097] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0098] Figure 1 A schematic diagram of the architecture of a quantum-resistant message processing system provided in this application embodiment;

[0099] Figure 2 A schematic diagram of the interaction flow of a message processing method resistant to quantum attacks provided in an embodiment of this application;

[0100] Figure 3 A flowchart illustrating a quantum-resistant message processing method provided in this application embodiment;

[0101] Figure 4 A flowchart illustrating another quantum-resistant message processing method provided in this application embodiment;

[0102] Figure 5 A flowchart illustrating another quantum-resistant message processing method provided in this application embodiment;

[0103] Figure 6 A flowchart illustrating a quantum-resistant message processing method provided in this application embodiment;

[0104] Figure 7 A flowchart illustrating a quantum-resistant message processing method provided in this application embodiment;

[0105] Figure 8 A flowchart illustrating another quantum-resistant message processing method provided in this application embodiment;

[0106] Figure 9 A flowchart illustrating another quantum-resistant message processing method provided in this application embodiment;

[0107] Figure 10 A schematic diagram of a quantum-resistant message processing device provided in an embodiment of this application;

[0108] Figure 11 A schematic diagram of another quantum-resistant message processing device provided in the embodiments of this application;

[0109] Figure 12 A schematic diagram of yet another quantum-resistant message processing device provided in an embodiment of this application;

[0110] Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0111] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0112] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0113] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0114] First, the relevant nouns and terms will be explained:

[0115] Post-Quantum Cryptography (PQC): PQC is a class of cryptographic techniques designed to resist attacks from quantum computing. With the development of quantum computing, traditional cryptographic algorithms such as RSA (Rivest-Shamir-Adleman encryption algorithm) and ECC (Elliptic Curve Cryptography) face the risk of being cracked. PQC utilizes mathematical problems, such as lattice-based, multivariable polynomial equation systems, and encoding problems, to construct encryption and signature schemes. Even with the powerful computing capabilities of quantum computers, it can guarantee the confidentiality, integrity, and authentication of information, providing long-term protection for information security.

[0116] Updatable Encryption (UE): Updatable encryption is an encryption technique that allows ciphertext to be updated using an update token without decryption, thus assigning a new key to the ciphertext. In scenarios involving long-term data storage or key leaks, it effectively solves the key update problem, ensuring that even if the key is leaked or expired, previously encrypted data can still be securely decrypted using the new key. This avoids the overhead of re-encrypting large amounts of data, improving system security and efficiency.

[0117] Digital Signature (DS): A digital signature is a technology used to verify the authenticity and integrity of digital information. It generates a signature by encrypting the information with a private key, and the recipient can decrypt and verify the signature using the corresponding public key. Digital signatures ensure that information truly originates from the signer and has not been tampered with, while also possessing non-repudiation—meaning the signer cannot deny having signed the information. It is widely used in e-government, e-commerce, and other fields, providing security for the secure transmission and trusted interaction of information.

[0118] With the rapid development of cloud storage and network technologies, the secure storage and transmission of data has become a key challenge in today's digital age. The widespread adoption of cloud storage services allows users to easily upload data to the cloud, achieving efficient data storage and sharing. However, this convenience also brings hidden risks to data security, especially in key management. In traditional encryption methods, once a key is leaked, all encrypted data is at risk of being decrypted, potentially leading to serious data breaches. To address this issue, updatable encryption technology has emerged. Updatable encryption allows for dynamic updates to the keys of encrypted data; even if the old key is leaked, the new key ensures data security. This ability to dynamically manage keys not only reduces the risk of key leaks but also provides stronger security for data protection in cloud storage environments.

[0119] In the process of data transmission and storage, in addition to ensuring data confidentiality, data integrity and authentication are equally crucial. Digital signature technology, as an effective security mechanism, can ensure that data is not tampered with during transmission and verify the identity of the data sender. Digital signatures generate unique signature information by encrypting data, and the recipient can verify the signature to confirm the authenticity and integrity of the data. In cloud storage environments, digital signatures can be used to verify whether data uploaded to the cloud has been tampered with and to confirm the identity of the data uploader, thus providing additional protection for data security.

[0120] However, current encryption and digital signature technologies are facing new challenges brought about by quantum computing. The emergence of quantum computers has seriously threatened the security of traditional encryption and digital signature algorithms, and many existing cryptographic systems have become extremely vulnerable to quantum computing. Therefore, researching and developing quantum-resistant encryption and digital signature technologies has become an urgent task. In the field of updatable encryption, although some research results have been achieved, most existing updatable encryption schemes do not simultaneously consider the requirements of quantum resistance, data integrity, and authentication.

[0121] Based on this, this solution provides a quantum-resistant message processing method. By integrating quantum-resistant cryptography with updatable encryption technology, it constructs a signature encryption system that supports dynamic key updates, achieving quantum-resistant security, dynamic key updates, and efficient authentication confidentiality. This effectively prevents quantum computers from cracking encrypted data, ensuring that data can be securely and promptly transferred to the new key in case of key leakage or when an update is needed. It also guarantees data integrity and authenticity, making it suitable for long-term security protection of sensitive data in environments such as cloud storage, including scenarios requiring frequent key rotation such as medical records and financial transaction records. This ensures forward and backward security, reduces the risk of data leakage, and improves the overall security and reliability of the system.

[0122] Figure 1 This application provides an embodiment of a quantum-resistant message processing system architecture. The system includes a sending terminal, a receiving terminal, and a cloud server. The sending terminal is primarily used to: generate an initial key pair; encapsulate a symmetric key using the receiving terminal's public key to obtain encapsulated ciphertext; encrypt a message using the symmetric key to obtain message ciphertext; sign the message using its own private key to obtain digital signature information; and finally assemble the encapsulated ciphertext, message ciphertext, and digital signature information to obtain ciphertext information. The sending terminal is also used to generate a new key and an update token and send them to the cloud server in case of key leakage. The receiving terminal is primarily used to: generate an initial key pair using a quantum-resistant cryptographic algorithm; verify the digital signature information using the sending terminal's public key; after successful verification, decrypt the encapsulated ciphertext using its own private key to obtain a symmetric key; and decrypt the message ciphertext using the symmetric key to obtain the message. The receiving terminal is also used to generate a new key and an update token and send them to the cloud server in case of key leakage. The cloud server is primarily used to securely store the ciphertext information and update the digital signature information in the ciphertext information after receiving the update token, achieving key evolution without requiring downloading the ciphertext.

[0123] Figure 2 This is a schematic diagram of the interaction flow of a message processing method resistant to quantum attacks provided in an embodiment of this application; this interaction flow can be applied to the above. Figure 1 The system shown specifically involves the interaction process between the sending terminal, the receiving terminal, and the cloud server. For example... Figure 1 As shown, the method includes:

[0124] S101, The receiving terminal sends the second initial public key to the sending terminal.

[0125] Accordingly, the sending terminal receives the second initial public key.

[0126] S102. The sending terminal generates a ciphertext encapsulated with a symmetric key based on the second initial public key.

[0127] The sending terminal is the terminal used by the message sender, and the receiving terminal is the terminal used by the message receiver.

[0128] After generating the initial key pair, the receiving terminal can send its initial public key to the sending terminal. Similarly, the sending terminal can also send its initial public key to the receiving terminal; that is, the public keys of both parties can be shared. Here, "first" and "second" are used to distinguish the initial public keys of the sending and receiving terminals.

[0129] Based on the received second initial public key, the sending terminal can encapsulate it into a symmetric key to obtain encapsulated ciphertext. The symmetric key can be generated using quantum-resistant cryptography techniques, such as Kyber.KEM generation. Kyber is a widely accepted quantum-resistant key exchange protocol. Even in the presence of a quantum computer, attackers cannot crack the symmetric key.

[0130] In some embodiments, the sending terminal may use the receiving terminal's second initial public key to execute Kyber.KEM.Encaps to encapsulate the symmetric key. After encapsulation, the resulting key is (c kem ,K), where c kem K represents the ciphertext encapsulation, and K represents the symmetric key.

[0131] S103. The sending terminal encrypts the target message using a quantum-resistant data encapsulation algorithm based on the symmetric key, generating message ciphertext.

[0132] The target message can refer to the message data that the sending terminal wants to send to the receiving terminal. The sending terminal can encrypt the target message based on the aforementioned symmetric key to obtain the ciphertext message. That is, unlike existing message encryption technologies, this scheme integrates a quantum-resistant symmetric key encryption method into the message encryption process. It encrypts the message using a symmetric key, and simultaneously invokes a quantum-resistant data encapsulation algorithm when encrypting the message with the symmetric key, making the encryption process resistant to quantum attacks.

[0133] The quantum-resistant data encapsulation algorithm can be the DEM.Enc algorithm. Assuming the target message is m, the encrypted ciphertext can be c. dem .

[0134] S104. The sending terminal performs signature processing on the encapsulated ciphertext and the message ciphertext according to the first initial private key of the sending terminal to obtain digital signature information.

[0135] The sending terminal can also calculate digital signature information based on its own initial private key, assuming the initial private key is sk. S,0 Then we can calculate Obtain digital signature information σ e .

[0136] Here, e is defined as a bilinear mapping that transforms a pair of data into a single element belonging to a specific data domain. In other words, it "mixes" elements from two groups to obtain a value in a new domain, and this mixing satisfies the property of being linear with respect to each input. H is a quantum-resistant hash function.

[0137] The reason for using bilinear mappings for digital signatures is that the receiving terminal can verify the signature's validity using only the sending terminal's public key and hash value, without needing to know the original private key. Combined with quantum-resistant hash functions, bilinear mappings do not rely on the security of traditional RSA or ECC, thus maintaining a certain level of security under quantum computing (although some elliptic curve-based mappings may be insecure under quantum attacks, this scheme uses a quantum-resistant hash-based construction). Furthermore, the signature is bound to the sending terminal's public key, the message content, and the encapsulated ciphertext, preventing tampering and forgery. Compared to traditional signature algorithms (such as RSA), bilinear mapping signatures offer shorter signature lengths and faster verification speeds in certain scenarios.

[0138] S105. The sending terminal obtains the initial ciphertext information based on the encapsulated ciphertext, the message ciphertext, and the digital signature information.

[0139] S106. The sending terminal sends the initial encrypted information to the cloud server.

[0140] Accordingly, the cloud server receives the initial encrypted information.

[0141] Next, the sending terminal can assemble the encapsulated ciphertext, message ciphertext, and digital signature information to obtain the initial ciphertext information C. e =(c kem ,c dem ,σ e It will send the initial encrypted information to the cloud server for storage.

[0142] The reason it's called the initial ciphertext is that if the sending terminal's private key is subsequently leaked, the key needs to be updated. Based on the updated key, the initial ciphertext will be dynamically updated. The initial ciphertext is used to distinguish it from the subsequently updated ciphertext.

[0143] It is worth noting that the initial encrypted information is generated based on the initial key pair of the sending terminal and the initial key pair of the receiving terminal. Subsequently, after a key leak is detected, the sending terminal and the receiving terminal will update their own key pairs. The cloud server updates the encrypted information based on the updated key pairs of the sending terminal and the receiving terminal.

[0144] The encrypted information includes: encapsulated ciphertext, message ciphertext, and digital signature information.

[0145] After receiving the initial encrypted information sent by the sending terminal, the cloud server stores it. In subsequent updates to the initial encrypted information, the encapsulated ciphertext and message ciphertext in the initial encrypted information remain unchanged in any update round, and there is no need to download and decrypt them. Only the digital signature information in the encrypted information needs to be dynamically updated.

[0146] S107. In the current round, the sending terminal generates a first update token based on the first key pair before the update and the first key pair after the update.

[0147] S108. The sending terminal sends the first update token to the cloud server.

[0148] Accordingly, the cloud server receives the first update token.

[0149] The current round can refer to any update round. When the update conditions are met, such as when the private key of the sending terminal is leaked, the sending terminal can update its own key pair and generate the first update token in order to ensure the security of the encrypted information.

[0150] The first key pair before the update here can refer to the first key pair in the current round before the update, while the first key pair after the update can refer to the first key pair after the update in the current round.

[0151] Assuming the initial round is the first round and the current round is the second round, then the first key pair before the update in the current round can be the initial first key pair of the sending terminal, and the first key pair after the update in the current round can be the first key pair obtained after updating the initial first key pair.

[0152] If the current round is the third round, then the first key pair before the update in the current round can refer to the first key pair after the update in the second round.

[0153] Optionally, the sending terminal can generate a first update token by using the first key pair before the update and the first key pair after the update. At the same time, the sending terminal will send the first update token to the cloud server.

[0154] S109. In the current round, the receiving terminal generates a second update token based on the second key pair before the update and the second key pair after the update.

[0155] Similarly, when the sending terminal updates the first key pair, the receiving terminal also needs to update its own second key pair to generate the updated second key pair; and generate a second update token based on the second key pair before the update and the second key pair after the update.

[0156] S110, The receiving terminal sends the second update token to the cloud server.

[0157] The receiving terminal also needs to send the second update token to the cloud server.

[0158] Accordingly, the cloud server receives the second update token.

[0159] The first update token includes the first update ratio and the updated first public key. The first update ratio is generated based on the updated first private key and the first private key before the update. The second update token includes the second update ratio and the updated second public key. The second update ratio is generated based on the updated second private key and the second private key before the update.

[0160] The update token obtained by this method is generated based on the key pair before and after the update. The update token is only used for updating the ciphertext information in the current round. After the old key pair becomes invalid, it cannot be used to derive the new key pair, which ensures the forward and backward security in the key evolution process. Even if the old key pair is leaked, it will not affect the security of the new key pair.

[0161] S111. The cloud server obtains the current encrypted information and updates the digital signature information in the current encrypted information according to the first update token and the second update token to obtain the new encrypted information.

[0162] In some embodiments, after receiving the first update token and the second update token, the cloud server first retrieves the current ciphertext information from the stored ciphertext information. The current ciphertext information refers to the latest ciphertext information of the current round stored in order to ensure that the receiving terminal can correctly decrypt the ciphertext information and obtain the accurate message.

[0163] The current ciphertext information is the new ciphertext information updated in the previous round. Assuming the current round is the second round and the initial round is the first round, the ciphertext information generated in the initial round is the initial ciphertext information. Therefore, the current ciphertext information obtained in the current round is the initial ciphertext information. In the current round, the initial ciphertext information needs to be updated to obtain the current new ciphertext information.

[0164] Optionally, when updating encrypted information, the cloud server can update only the digital signature information in the encrypted information, while keeping the encapsulated ciphertext and message ciphertext unchanged. This eliminates the need to download and decapsulate the encapsulated ciphertext and message ciphertext, improving the efficiency of encrypted information updates while ensuring that message data can be securely transferred to the new key, thus guaranteeing data integrity and authenticity.

[0165] In summary, the quantum-resistant message processing method provided in this embodiment, during message encryption, introduces a symmetric-key encryption algorithm based on quantum-resistant cryptography to encrypt the message, then encapsulates the symmetric key, and assembles the encapsulated ciphertext, the message ciphertext, and the digital signature information to obtain the ciphertext information. This effectively integrates quantum-resistant technology into the encryption technology, making the encryption process more quantum-resistant, and because the symmetric key cannot be attacked, it prevents the message from being cracked. When the key is leaked, an updatable key technology can be used to dynamically update the key pair, and based on the updated key pair and the original key pair, the digital signature information in the ciphertext information is updated. This ensures that when the key is leaked or the ciphertext information needs to be updated, the message data can be securely and promptly converted to the new key, without needing to download and decapsulate the encapsulated ciphertext and the message ciphertext; only the digital signature information needs to be updated to quickly complete the ciphertext information update. By embedding digital signature information within the encrypted message, and ensuring that the digital signature is promptly updated after a key leak, message decryption can be performed using the updated key information to verify the digital signature, thus guaranteeing message integrity and authenticity. By combining quantum-resistant cryptography, updatable encryption, and digital signature technologies, a comprehensive, efficient, and secure solution is provided for cloud storage environments, achieving integrated protection of data confidentiality, integrity, and authentication.

[0166] Next, the above Figure 1 The implementation methods of each step in the process will be explained in detail.

[0167] Figure 3 This is a flowchart illustrating a quantum-resistant message processing method provided in an embodiment of this application; in step S111, the digital signature information in the current ciphertext is updated according to the first update token and the second update token to obtain the new ciphertext information, including:

[0168] S201. Generate new digital signature information based on the first update ratio, the second update ratio, and the digital signature information in the current ciphertext.

[0169] In some embodiments, it is assumed that the current round is e+1 and the previous round is e; the updated digital signature information from the previous round is σ. e Then the digital signature information in the current ciphertext is σ. e The first update ratio is δ. S The second update ratio is δ R .

[0170] Therefore, the new digital signature information can be calculated (that is, the updated digital signature information for the current round):

[0171] S202. Update the digital signature information in the current ciphertext information according to the new digital signature information to obtain the current new ciphertext information.

[0172] Optionally, the digital signature information in the current encrypted information can be replaced with new digital signature information to obtain the new encrypted information.

[0173] That is, the old digital signature information is replaced with the new digital signature information to obtain the current new ciphertext information.

[0174] This section only updates the digital signature information in the ciphertext, without updating the encapsulated ciphertext and the message ciphertext. This is because key leakage usually refers to the leakage of the signature private key, while the encapsulated symmetric key itself is not leaked, since the symmetric key is encapsulated using a quantum-resistant algorithm and is securely held by the receiving terminal. Updating the digital signature information binds the new digital signature information to the sending terminal's new public key, which ensures identity authentication and integrity verification when decrypting the ciphertext information later, while avoiding unnecessary overhead of symmetric key re-encapsulation and message re-encryption.

[0175] In step S102, generating the ciphertext of the symmetric key based on the second initial public key includes: encapsulating the symmetric key using a quantum-resistant key encapsulation algorithm based on the second initial public key to obtain the ciphertext of the symmetric key.

[0176] In some embodiments, after receiving the second initial public key sent by the receiving terminal, the sending terminal can use the second initial public key to execute a quantum-resistant key encapsulation algorithm to encapsulate the symmetric key. This can be achieved by executing Kyber.KEM.Encaps to encapsulate the symmetric key, resulting in (c kem ,K), where c kem K is the symmetric key used to encapsulate the ciphertext.

[0177] Encapsulating symmetric keys using quantum-resistant key encapsulation algorithms can prevent quantum attacks on the symmetric keys, thus preventing message decryption. Since the symmetric key is encapsulated using the receiving terminal's public key, the receiving terminal can decapsulate it using its own private key, ensuring the symmetric key is securely held by the receiving terminal.

[0178] Figure 4 This is a flowchart illustrating another quantum-resistant message processing method provided in an embodiment of this application; optionally, in step S107, generating a first update token based on the first key pair before the update and the first key pair after the update includes:

[0179] S301. Determine the first update ratio based on the first private key in the first key pair before the update and the first private key in the first key pair after the update.

[0180] In the current round, the sending terminal can first generate the updated first key pair based on the first key pair before the update. Here, "based on" does not mean that the updated first key pair is calculated from the first key pair before the update, but rather that the updated first key pair must not be the same as the first key pair before the update.

[0181] In one implementation, the ratio of the first private key in the updated first key pair to the first private key in the original first key pair is used as the first update ratio.

[0182] Assuming the current round is e+1, the first key pair after the update in the current round is (sk S,e+1 ,pk S,e+1 The first key pair before the update in the current round is (sk) S,e ,pk S,e Therefore, the first private key in the first key pair before the update is sk. S,e After the update, the first private key in the first key pair is sk. S,e+1 .

[0183] Then the first update ratio

[0184] S302. Generate a first update token based on the first update ratio and the first public key in the updated first key pair.

[0185] By assembling the first update ratio and the first public key from the updated first key pair, the first update token can be obtained. The first update token is Δ. S,e+1 =(δ S ,pk S,e+1 ).

[0186] Figure 5This is a flowchart illustrating another quantum-resistant message processing method provided in an embodiment of this application; optionally, in step S104, before signing the encapsulated ciphertext and the message ciphertext according to the first initial private key of the sending terminal to obtain digital signature information, the method further includes:

[0187] S401. Based on the preset data field, randomly select the first initial private key.

[0188] Since updating ciphertext involves updating the digital signature within the ciphertext, while the encapsulated ciphertext and message ciphertext remain unchanged from their initial state, the digital signature information is continuously updated based on the initial digital signature information. Therefore, it is necessary to first generate the initial ciphertext information.

[0189] The initial encrypted information needs to be generated based on the first initial private key of the sending terminal and the first initial public key of the receiving terminal. Therefore, both the sending terminal and the receiving terminal need to generate their own initial key pairs.

[0190] During system initialization, global security parameters can be set and a cyclic group can be generated, quantum-resistant hash functions and bilinear mappings can be defined, and system parameters and components can be configured.

[0191] Optionally, a global security parameter λ is set, and G is generated as a cyclic group of order p, where p is a large prime number and g is its generator. Then e is defined as: G × G → G T This is a bilinear mapping. H is chosen as a quantum-resistant hash function, mapping any string of 0s and 1s to Z. p Chinese elements.

[0192] Define quantum-resistant components: Kyber.KEM is a lattice-based post-quantum key encapsulation mechanism, and DEM is a symmetric encryption component (such as AES-GCM).

[0193] λ is a system security parameter, usually an integer, used to control the overall security strength of the system. For example, λ = 128 means the system has a 128-bit security strength, meaning an attacker would need approximately 2... 128 It takes several operations to crack the system. The choice of λ determines the scale of the mathematical problem used in the system, the key length, the output length of the hash function, etc., which directly affects the security and efficiency of the system.

[0194] G is a mathematical construct, specifically a cyclic group of order p, consisting of a large prime number. A generator g is an element in G, and all elements in G can be generated by exponentiation of g. For example, G can be a group of points on an elliptic curve or a multiplicative group in a finite field. The cyclic group G is the fundamental construct for implementing bilinear mappings. The choice of a large prime number p ensures that the Discrete Logarithm Problem (DLP) or its variants (such as the bilinear Diffie-Hellman problem) are computationally difficult in G, thus guaranteeing the security of cryptographic schemes.

[0195] e is an element from two groups G to another group G. T The mapping function satisfies the bilinear property. The bilinear property states that for any a, b ∈ Z... p , has e(g a ,g b )=e(g,g) {ab} Bilinear mappings are used to construct efficient signature and verification mechanisms, such as in signcrypt generation and designification, enabling simpler identity binding and integrity verification. They allow signature verification or signcrypt conversion to be performed without exposing the private key, making them an important mathematical tool for implementing "signcryption" functionality.

[0196] H is a cryptographic hash function that takes a bit string of arbitrary length (i.e., data) as input and outputs a hash function in Z. p The elements are in the integer ring (mod p). This hash function is "quantum-resistant," meaning it remains secure against quantum attacks. Hash functions can map arbitrary data (such as messages, keys, signatures) to numerical values ​​in a mathematical field, facilitating subsequent cryptographic operations. In signature and ciphertext generation, H is used to bind data to a private or public key for data integrity verification.

[0197] The above series of definitions form the mathematical foundation for constructing a quantum-resistant cryptographic system.

[0198] For the sending terminal, it can randomly select a first initial private key. The aforementioned preset data field can refer to Z. p The data field, the first initial private key can be from Z p It is randomly selected from the remaining class ring Z modulo p. p The first initial private key is randomly selected from the data.

[0199] It is worth noting that when updating the private key later, it can still be obtained from the remaining class ring Z of modulo p. p A new private key, different from the previously selected private key, is randomly selected.

[0200] S402. Determine the first initial public key based on the first initial private key.

[0201] Based on the initial private key, the initial public key sk corresponding to the initial private key can be calculated using a key algorithm. S,0 .

[0202] Optionally, the first initial public key pk S,0 It can be via g's sk S,0 The exponentiation operation is generated in the cyclic group G; therefore, the first initial public key belongs to G.

[0203] S403. Based on the first initial private key and the first initial public key, obtain the first initial key pair of the sending terminal.

[0204] Therefore, the first initial key pair obtained by the sending terminal is (sk S,0 ,pk S,0 ).

[0205] S404. Send the first initial public key to the receiving terminal.

[0206] The sending terminal can also send the first initial public key to the receiving terminal, so that the receiving terminal can subsequently verify the digital signature based on the first initial public key.

[0207] Optionally, it also includes: if a preset interval has been reached since the last round; or if a key pair leak is detected, then proceed to the current round.

[0208] In some embodiments, the current round can be entered when a condition is met. This condition could be the detection of a key pair leak, specifically the leakage of the private key transmission of the sending terminal. That is, whenever a private key transmission leak of the sending terminal is detected, a new round can be triggered to dynamically update the key pair and the ciphertext information.

[0209] Alternatively, an update interval can be set, and a new round can be automatically triggered at each preset interval to perform dynamic updates of the key pair and ciphertext information.

[0210] Figure 6 A flowchart illustrating a quantum-resistant message processing method provided in this application embodiment; the execution steps of the receiving terminal further include:

[0211] S501. In the current round, a second update token is generated based on the second key pair before the update and the second key pair after the update from the receiving terminal.

[0212] Similar to the method for generating update tokens by the sending terminal, the receiving terminal also generates a second update token based on the second key pair before and after the update in the current round.

[0213] S502, Send the second update token to the cloud server.

[0214] The generated second update token is sent to the cloud server, so that the cloud server can combine the first update token and the second update token to update the encrypted information.

[0215] Figure 7 This is a flowchart illustrating a quantum-resistant message processing method provided in an embodiment of this application; in step S109, the receiving terminal generates a second update token based on the second key pair before and after the update, including:

[0216] S601. Generate a second update ratio based on the second private key in the second key pair before the update and the second private key in the second key pair after the update.

[0217] In one feasible approach, the second private key in the updated second key pair can be hashed first to obtain a first hash result; then the second private key in the unupdated second key pair can be hashed to obtain a second hash result; finally, the ratio of the first hash result to the second hash result can be used as the second update ratio.

[0218] Assuming the second key pair (pk) before the update R,e ,sk R,e After the update, the second key pair is (pk R,e+1 ,sk R,e+1 ), where the second private key in the second key pair before the update is sk R,e After the update, the second private key in the second key pair is sk. R,e+1 .

[0219] Therefore, the second update ratio can be

[0220] Wherein, H(sk) R,e+1 H(sk) represents the second hash result. S,e ) represents the first hash result.

[0221] S602. Generate a second update token based on the second update ratio and the second public key in the updated second key pair.

[0222] A second update token can be generated by assembling the second update ratio and the second public key in the updated second key pair. The second update token can be Δ. R,e+1 =(δ R ,pk R,e+1 ).

[0223] Figure 8This is a flowchart illustrating another quantum-resistant message processing method provided in an embodiment of this application; the method executed by the receiving terminal further includes:

[0224] S701. Based on the preset global security parameters, the initial second key pair for the receiving terminal is generated using a lattice-based post-quantum key algorithm.

[0225] The initial second key pair includes: a second initial private key and a second initial public key.

[0226] Similarly, the receiving terminal also needs to generate an initial second key pair. For the receiving terminal, it can run a key generation algorithm to generate the initial second key pair.

[0227] For example, the receiving terminal may run the Kyber key generation algorithm (sk R,0 ,pk R,0 )←Kyber.KEM.KeyGen(1 λ Output the initial second key pair (sk) R,0 ,pk R,0 ).

[0228] S702. Send the second initial public key from the initial second key pair to the sending terminal.

[0229] The receiving terminal will use the second initial public key pk from the generated initial second key pair. R,0 The data is sent to the sending terminal so that the sending terminal can encapsulate the symmetric key based on the second initial public key, and the receiving terminal can subsequently decrypt the symmetric key based on its own second initial private key.

[0230] It is worth noting that in the current round, when the receiving terminal updates the key pair, it can also be based on the key generation algorithm (sk). R,0 ,pk R,0 )←Kyber.KEM.KeyGen(1 λ This generates an updated second key pair. The updated key pair does not duplicate the data of the existing old key pair.

[0231] When generating key pairs, based on the calculation principle of the algorithm Kyber.KEM.KeyGen itself, the generation of key pairs is also related to some random parameters such as the current time and device encoding, thus ensuring that each generated key pair is unique.

[0232] Figure 9 This is a flowchart illustrating another quantum-resistant message processing method provided in an embodiment of this application; the method executed by the receiving terminal further includes:

[0233] S801. Access the cloud server to obtain the new ciphertext information for the current round and the first public key in the updated first key pair of the sending terminal for the current round.

[0234] For the receiving terminal, when it needs to obtain the target message sent by the sending terminal, it can access the cloud server to obtain the new encrypted information of the current round.

[0235] In some embodiments, since the first update token sent by the sending terminal carries the first public key of the updated first key pair of the sending terminal in the current round, the receiving terminal can simultaneously obtain the first public key of the updated first key pair of the sending terminal in the current round from the cloud server when accessing the cloud server.

[0236] In some embodiments, after generating the first public key in the updated first key pair for the current round, the sending terminal can send it to the receiving terminal, so that the receiving terminal can hold the first public key in the updated first key pair.

[0237] S802. Verify the digital signature information in the new ciphertext information by using the first public key in the updated first key pair.

[0238] Taking the current round as e+1 as an example, the new ciphertext information obtained by the receiving terminal for the current round is (c kem ,c dem ,σ e+1 The receiving terminal can first pk based on the first public key in the updated first key pair. S,e+1 Calculate the bilinear mapping value To check whether the calculation result matches the bilinear mapping value e(σ) e+1 If the two ciphertexts are equal, it proves that the digital signature information has been successfully verified. Successful verification indicates that the current new ciphertext information is the latest in this stage and proves that the ciphertext information was sent by the sending terminal. If the verification fails, it proves that the ciphertext information has been intercepted or tampered with.

[0239] S803. If the verification is successful, the ciphertext in the new ciphertext information is decrypted using the second private key in the updated second key pair to obtain the symmetric key.

[0240] After successful verification, the receiving terminal can decrypt the encapsulated ciphertext using its own second private key in the current round, which is also the second private key in the updated second key pair, to obtain the symmetric key. That is, Dec(c kem ,sk R,e+1 ) = K.

[0241] S804. Decrypt the message ciphertext in the new ciphertext information using the symmetric key to obtain the target message.

[0242] Then, the receiving terminal uses the symmetric key to decrypt the ciphertext of the message, obtaining the target message m = DEM.Dec(K,c dem ).

[0243] In summary, this application provides a quantum-resistant message processing method, comprising: a sending terminal receiving a second initial public key from a receiving terminal, and generating a symmetric key encapsulated ciphertext based on the second initial public key; the sending terminal encrypting a target message using a quantum-resistant data encapsulation algorithm based on the symmetric key to generate message ciphertext; the sending terminal signing the encapsulated ciphertext and the message ciphertext using a first initial private key to obtain digital signature information; the sending terminal obtaining initial ciphertext information based on the encapsulated ciphertext, the message ciphertext, and the digital signature information, and sending the initial ciphertext information to a cloud server; and the cloud server receiving the initial ciphertext information sent by the sending terminal. In the current round, the sending terminal generates a first update token based on the first key pair before and after the update, and sends the first update token to the cloud server. In the current round, the receiving terminal generates a second update token based on the second key pair before and after the update, and sends the second update token to the cloud server. In the current round, the cloud server receives the first update token sent by the sending terminal and the second update token sent by the receiving terminal. The cloud server obtains the current ciphertext information and updates the digital signature information in the current ciphertext information according to the first and second update tokens to obtain the new ciphertext information. During message encryption, a symmetric key encryption algorithm based on quantum-resistant cryptography is introduced to encrypt the message, then encapsulates the symmetric key, and assembles the encapsulated ciphertext, the message ciphertext, and the digital signature information to obtain the ciphertext information. This effectively integrates quantum-resistant technology into the encryption technology, making the encryption process more quantum-resistant, and because the symmetric key cannot be attacked, it can prevent the message from being cracked. When a key is leaked, updatable key technology allows for dynamic updates to the key pair. Based on the updated and original key pairs, the digital signature information in the ciphertext is updated, ensuring that message data can be securely and promptly transferred to the new key when a key leak occurs or the ciphertext needs updating. This is done without downloading and decrypting the encapsulated ciphertext and the original message; only the digital signature information needs updating, allowing for rapid updates. Furthermore, by embedding the digital signature within the ciphertext, and ensuring its timely update after a key leak, message decryption can be performed by verifying the digital signature based on the updated key information, guaranteeing message integrity and authenticity. By combining quantum-resistant cryptography, updatable encryption, and digital signature technologies, a comprehensive, efficient, and secure solution is provided for cloud storage environments, achieving integrated protection for data confidentiality, integrity, and authentication.

[0244] The following describes the apparatus, device, and storage medium used to execute the quantum-resistant message processing method provided in this application. The specific implementation process and technical effects are described above and will not be repeated below.

[0245] Figure 10 This is a schematic diagram of a quantum-resistant message processing device provided in an embodiment of this application. The functions implemented by this quantum-resistant message processing device correspond to the method steps executed by the cloud server described above. Figure 10 As shown, the device includes: a receiving module 100 and an updating module 200;

[0246] The receiving module 100 is used to receive the initial ciphertext information sent by the sending terminal. The ciphertext information includes: encapsulated ciphertext, message ciphertext, and digital signature information.

[0247] In the current round, the receiving terminal sends a first update token and a second update token. The first update token includes a first update ratio and an updated first public key. The first update ratio is generated based on the updated first private key and the first private key before the update. The second update token includes a second update ratio and an updated second public key. The second update ratio is generated based on the updated second private key and the second private key before the update.

[0248] The update module 200 is used to obtain the current ciphertext information and update the digital signature information in the current ciphertext information according to the first update token and the second update token to obtain the new ciphertext information.

[0249] Optionally, the update module 200 is specifically used to generate new digital signature information based on the first update ratio, the second update ratio, and the digital signature information in the current ciphertext information.

[0250] Based on the new digital signature information, update the digital signature information in the current ciphertext information to obtain the new ciphertext information.

[0251] Optionally, the update module 200 is specifically used to replace the digital signature information in the current ciphertext information with new digital signature information to obtain the current new ciphertext information.

[0252] Figure 11 This is a schematic diagram of another quantum-resistant message processing device provided in an embodiment of this application. The function implemented by this quantum-resistant message processing device corresponds to the method steps executed by the sending terminal described above. Figure 11 As shown, the device includes: a generation module 300 and a processing module 400;

[0253] The generation module 300 is used to receive the second initial public key of the receiving terminal and generate the ciphertext of the symmetric key based on the second initial public key;

[0254] The processing module 400 is used to encrypt the target message using a quantum-resistant data encapsulation algorithm based on a symmetric key, and generate message ciphertext.

[0255] Based on the first initial private key of the sending terminal, the encapsulated ciphertext and the message ciphertext are signed to obtain digital signature information;

[0256] Based on the encapsulated ciphertext, message ciphertext, and digital signature information, the initial ciphertext information is obtained and sent to the cloud server.

[0257] The generation module 300 is used to generate a first update token in the current round based on the first key pair before the update and the first key pair after the update, and send the first update token to the cloud server.

[0258] Optionally, the generation module 300 is specifically used to encapsulate the symmetric key using a quantum-resistant key encapsulation algorithm based on the second initial public key, thereby obtaining the encapsulated ciphertext of the symmetric key.

[0259] Optionally, the generation module 300 is specifically used to determine the first update ratio based on the first private key in the first key pair before the update and the first private key in the first key pair after the update;

[0260] A first update token is generated based on the first update ratio and the first public key in the updated first key pair.

[0261] Optionally, the generation module 300 is specifically used to take the ratio of the first private key in the updated first key pair to the first private key in the unupdated first key pair as the first update ratio.

[0262] Optionally, the generation module 300 is also used to randomly select a first initial private key based on a preset data field;

[0263] Determine the first initial public key based on the first initial private key;

[0264] Based on the first initial private key and the first initial public key, the first initial key pair of the sending terminal is obtained;

[0265] Send the first initial public key to the receiving terminal.

[0266] Optionally, if a preset interval has elapsed since the last round, or if a key pair leak is detected, then proceed to the current round.

[0267] Figure 12This is a schematic diagram of another quantum-resistant message processing device provided in an embodiment of this application. The function implemented by this quantum-resistant message processing device corresponds to the method steps executed by the receiving terminal described above. Figure 12 As shown, the device includes: a generation module 500 and a transmission module 600;

[0268] The generation module 500 is used to generate a second update token in the current round based on the second key pair before the update and the second key pair after the update from the receiving terminal.

[0269] The sending module 600 is used to send the second update token to the cloud server.

[0270] Optionally, the generation module 500 is specifically used to generate a second update ratio based on the second private key in the second key pair before the update and the second private key in the second key pair after the update;

[0271] A second update token is generated based on the second update ratio and the second public key in the updated second key pair.

[0272] Optionally, the generation module 500 is specifically used to perform a hash operation on the second private key in the updated second key pair to obtain a first hash result;

[0273] Perform a hash operation on the second private key in the second key pair before the update to obtain the second hash result;

[0274] The ratio of the first hash result to the second hash result is used as the second update ratio.

[0275] Optionally, the generation module 500 is further configured to generate an initial second key pair for the receiving terminal based on a lattice-based post-quantum key algorithm according to preset global security parameters; the initial second key pair includes: a second initial private key and a second initial public key;

[0276] Send the second initial public key from the initial second key pair to the sending terminal.

[0277] Optionally, it may also include: a decryption module;

[0278] The decryption module is used to access the cloud server to obtain the new ciphertext information of the current round and the first public key in the updated first key pair of the sending terminal of the current round.

[0279] The digital signature information in the new ciphertext is verified by using the first public key in the updated first key pair.

[0280] If the verification is successful, the ciphertext encapsulated in the new ciphertext information is decrypted using the second private key in the updated second key pair to obtain the symmetric key;

[0281] The target message is obtained by decrypting the ciphertext in the new ciphertext using the symmetric key.

[0282] The above-described device is used to execute the method provided in the foregoing embodiments, and its implementation principle and technical effect are similar, so they will not be described again here.

[0283] These modules can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more digital signal processors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together as a system-on-a-chip (SOC).

[0284] The modules described above can be connected or communicate with each other via wired or wireless connections. Wired connections can include metal cables, optical fibers, hybrid cables, or any combination thereof. Wireless connections can include connections via LAN, WAN, Bluetooth, ZigBee, or NFC, or any combination thereof. Two or more modules can be combined into a single module, and any module can be divided into two or more units. Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the method embodiments, and will not be repeated here.

[0285] Figure 13 This is a schematic diagram of an electronic device provided in an embodiment of this application. The device can be integrated into a terminal device or a chip within a terminal device, and can be a computing device with data processing capabilities. This electronic device is used to execute the method steps described above by the sending terminal, receiving terminal, or cloud server.

[0286] The device includes: processor 801 and storage medium 802.

[0287] Storage medium 802 is used to store programs, and processor 801 calls the programs stored in storage medium 802 to execute the above method embodiments. The specific implementation and technical effects are similar, and will not be described in detail here.

[0288] The storage medium 802 stores program code, which, when executed by the processor 801, causes the processor 801 to perform various steps in the quantum-resistant message processing method according to various exemplary embodiments of this application as described in the "Exemplary Methods" section above.

[0289] The processor 801 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0290] Storage medium 802, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The storage medium can include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type storage medium, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage medium, magnetic disk, optical disk, etc. The storage medium is any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, storage medium 802 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0291] Optionally, this application also provides a program product, such as a computer-readable storage medium, including a program that, when executed by a processor, performs the above-described method embodiments.

[0292] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0293] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0294] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units.

[0295] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A message processing method resistant to quantum attacks, characterized in that, Applied to cloud servers, the method includes: Receive initial ciphertext information sent by the sending terminal, the ciphertext information including: encapsulated ciphertext, message ciphertext, and digital signature information; In the current round, the receiving terminal sends a first update token and a second update token. The first update token includes a first update ratio and an updated first public key. The first update ratio is generated based on the updated first private key and the first private key before the update. The second update token includes a second update ratio and an updated second public key. The second update ratio is generated based on the updated second private key and the second private key before the update. Obtain the current encrypted information, and update the digital signature information in the current encrypted information according to the first update token and the second update token to obtain the current new encrypted information.

2. The method according to claim 1, characterized in that, The step of updating the digital signature information in the current ciphertext information according to the first update token and the second update token to obtain the new ciphertext information includes: Based on the first update ratio, the second update ratio, and the digital signature information in the current encrypted information, generate the current new digital signature information; Based on the new digital signature information, update the digital signature information in the current ciphertext information to obtain the new ciphertext information.

3. The method according to claim 2, characterized in that, The step of updating the digital signature information in the current ciphertext information according to the new digital signature information to obtain the current new ciphertext information includes: The digital signature information in the current encrypted information is replaced with the new digital signature information to obtain the current new encrypted information.

4. A message processing method resistant to quantum attacks, characterized in that, Applied to a transmitting terminal, the method includes: Receive the second initial public key from the receiving terminal, and generate a ciphertext encapsulated with a symmetric key based on the second initial public key; Based on the symmetric key, a quantum-resistant data encapsulation algorithm is used to encrypt the target message and generate message ciphertext. Based on the first initial private key of the sending terminal, the encapsulated ciphertext and the message ciphertext are signed to obtain digital signature information; Based on the encapsulated ciphertext, the message ciphertext, and the digital signature information, the initial ciphertext information is obtained and sent to the cloud server. In the current round, a first update token is generated based on the first key pair before the update and the first key pair after the update, and the first update token is sent to the cloud server.

5. The method according to claim 4, characterized in that, The step of generating the symmetric key encapsulated ciphertext based on the second initial public key includes: Based on the second initial public key, the symmetric key is encapsulated using a quantum-resistant key encapsulation algorithm to obtain the encapsulated ciphertext of the symmetric key.

6. The method according to claim 4, characterized in that, The step of generating a first update token based on the first key pair before the update and the first key pair after the update includes: The first update ratio is determined based on the first private key in the first key pair before the update and the first private key in the first key pair after the update; The first update token is generated based on the first update ratio and the first public key in the updated first key pair.

7. The method according to claim 6, characterized in that, Determining the first update ratio based on the first private key in the first key pair before the update and the first private key in the first key pair after the update includes: The ratio of the first private key in the updated first key pair to the first private key in the original first key pair is used as the first update ratio.

8. The method according to claim 4, characterized in that, Before obtaining digital signature information by signing the encapsulated ciphertext and the message ciphertext according to the first initial private key of the sending terminal, the process further includes: Based on a preset data field, the first initial private key is randomly selected; Based on the first initial private key, determine the first initial public key; The first initial key pair of the sending terminal is obtained based on the first initial private key and the first initial public key; The first initial public key is sent to the receiving terminal.

9. The method according to claim 4, characterized in that, Also includes: If the preset interval time has been reached since the last round; If a key pair leak is detected, proceed to the current round.

10. A message processing method resistant to quantum attacks, characterized in that, Applied to a receiving terminal, the method includes: In the current round, a second update token is generated based on the second key pair before the update and the second key pair after the update of the receiving terminal; Send the second update token to the cloud server.

11. The method according to claim 10, characterized in that, The receiving terminal uses the pre-update second key pair and the post-update second key pair to generate a second update token, including: A second update ratio is generated based on the second private key in the second key pair before the update and the second private key in the second key pair after the update; The second update token is generated based on the second update ratio and the second public key in the updated second key pair.

12. The method according to claim 11, characterized in that, The step of generating a second update ratio based on the second private key in the second key pair before the update and the second private key in the second key pair after the update includes: A hash operation is performed on the second private key in the updated second key pair to obtain a first hash result; Perform a hash operation on the second private key in the second key pair before the update to obtain a second hash result; The ratio of the first hash result to the second hash result is used as the second update ratio.

13. The method according to claim 10, characterized in that, Also includes: Based on preset global security parameters, an initial second key pair for the receiving terminal is generated using a lattice-based post-quantum key algorithm. The initial second key pair includes: a second initial private key and a second initial public key; Send the second initial public key from the initial second key pair to the sending terminal.

14. The method according to claim 10, characterized in that, Also includes: Access the cloud server to obtain the new encrypted information for the current round and the first public key in the updated first key pair of the sending terminal for the current round; The digital signature information in the new ciphertext is verified by using the first public key in the updated first key pair. If the verification is successful, the encapsulated ciphertext in the new ciphertext information is decrypted using the second private key in the updated second key pair to obtain the symmetric key; The target message is obtained by decrypting the message ciphertext in the new ciphertext information using the symmetric key.

15. A message processing system resistant to quantum attacks, characterized in that, include: Cloud server, sending terminal, and receiving terminal; The cloud server is used to perform the steps of the method according to any one of claims 1-3; The transmitting terminal is used to perform the steps of the method according to any one of claims 4-9; The receiving terminal is used to perform the steps of the method according to any one of claims 10-14.

16. An electronic device, characterized in that, include: The device includes a processor, a storage medium, and a bus, wherein the storage medium stores program instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the program instructions to implement the steps of the method as described in any one of claims 1-3, 4-9, or 10-14.

17. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which is executed by a processor to implement the steps of the method as described in any one of claims 1-3, 4-9, or 10-14.

Citation Information

Patent Citations

  • Certificate cryptography-based secret key updating method and system for quantum-computing-resistant secret communication

    CN110557367A

  • Key management communication method and device, equipment and storage medium

    CN112187450A

  • Identity-based signcryption method for protecting key

    CN115296792A

  • Digital signature method, verification method, device, equipment, storage medium and system

    CN119484164A

  • Key generation apparatus and key update method

    US20200178080A1