A Method and System for Switching Quantum-Resistant Dual-Mode Cryptographic Algorithms Based on Dynamic Scheduling

By collecting key lifecycle stages and quantum computing capability evolution evaluation values, a dynamic scheduling mechanism is established to identify decay inflection points and algorithm failure time boundaries, enabling a smooth transition between national cryptographic algorithms and quantum-resistant cryptographic algorithms. This solves the problem of inaccurate algorithm switching timing in existing technologies and improves the forward-looking protection capability of cryptographic systems.

CN121441499BActive Publication Date: 2026-04-03BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies lack a mechanism for analyzing the correlation between the evolution of quantum computing capabilities and the key lifecycle, which leads to inaccurate timing of cryptographic algorithm switching, resulting in wasted resources or security risks, and failing to reserve sufficient response time for a smooth transition before the rise of quantum threats.

Method used

By collecting the operational characteristics of cryptographic communication sessions, including key lifecycle stages and quantum computing capability evolution evaluation values, a dynamic scheduling mechanism is established to identify decay inflection points and algorithm failure time boundaries. A dual-mode collaborative switching decision mechanism is constructed to achieve a smooth transition between national cryptographic algorithms and quantum-resistant cryptographic algorithms.

Benefits of technology

Accurately predicting the time window of quantum threats and providing scientific timing for algorithm switching enables continuous improvement in communication security and reasonable consumption of system resources, solving the technical challenge of balancing security and performance during algorithm switching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121441499B_ABST
    Figure CN121441499B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for switching quantum-resistant dual-mode cryptographic algorithms based on dynamic scheduling, belonging to the field of dynamic scheduling technology. The method includes: collecting operational characteristics of cryptographic communication sessions and analyzing the results to obtain evaluation results containing decay inflection points and algorithm failure time boundaries; determining a set of candidate switching algorithms from a heterogeneous algorithm pool based on the evaluation results, and calculating the expected resource overhead and security gain of each candidate algorithm; establishing a dual-mode collaborative switching decision mechanism, mapping resource overhead and security gain to Pareto front solution sets within a reserved response interval before the algorithm failure time boundary, and determining the switching scheme in conjunction with semantic fragmentation boundaries; executing algorithm switching by inserting control frames at the semantic fragmentation boundaries, and using scheduling execution feedback for iterative correction. This invention achieves a smooth switching between national cryptographic algorithms and quantum-resistant algorithms, balancing security and resource efficiency, and ensuring the long-term security of the cryptographic system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to dynamic scheduling technology, and more particularly to a method and system for switching quantum-resistant dual-mode cryptographic algorithms based on dynamic scheduling. Background Technology

[0002] With the rapid development of quantum computing technology, traditional cryptographic algorithms are facing unprecedented security threats. Quantum computers, utilizing properties such as quantum superposition and quantum entanglement, can break classical cryptographic algorithms based on mathematical problems like large number factorization and discrete logarithms within polynomial time, including the widely used national cryptographic algorithms. To address this challenge, the industry has proposed quantum-resistant cryptographic algorithms. These algorithms are built upon mathematical problems considered resistant to quantum computing attacks, such as lattices, encoding, multivariables, or hash functions. However, quantum-resistant cryptographic algorithms are often significantly more computationally efficient, have higher storage overhead, and consume more bandwidth than traditional national cryptographic algorithms. A direct and complete replacement would place enormous performance pressure on existing cryptographic communication systems.

[0003] In practical applications, cryptographic communication systems need to balance system performance and resource consumption while ensuring security. The development of quantum computing capabilities is a gradual process, and the level of quantum threats varies at different times. Furthermore, the sensitivity and value of the data protected by a key differ at different stages of its lifecycle. Therefore, dynamically selecting an appropriate cryptographic algorithm based on the real-time quantum threat situation and session security requirements becomes an ideal solution. This dynamic switching mechanism can use efficient national cryptographic algorithms to ensure system performance when the quantum threat is low, and can promptly switch to quantum-resistant cryptographic algorithms to ensure security when the quantum threat increases or when protecting highly sensitive data.

[0004] Current technologies lack a mechanism for analyzing the correlation between the evolution of quantum computing capabilities and the key lifecycle. Current cryptographic algorithm selection often employs static configuration, failing to accurately assess the actual development of quantum computing technology and the specific lifecycle stage of the key. This leads to inaccurate timing of algorithm switching; premature switching wastes resources, while delayed switching introduces security risks, and insufficient response time is not allowed for a smooth transition before the algorithm fails. Summary of the Invention

[0005] This invention provides a method and system for switching quantum-resistant dual-mode cryptographic algorithms based on dynamic scheduling, which can solve the problems in the prior art.

[0006] A first aspect of this invention provides a method for switching between quantum-resistant dual-mode cryptographic algorithms based on dynamic scheduling, comprising:

[0007] The operational characteristics of cryptographic communication sessions are collected, including key lifecycle stages and quantum computing capability evolution evaluation values. Based on the correspondence between the quantum computing capability evolution evaluation values ​​and the key lifecycle stages, an evaluation result including decay inflection points and algorithm failure time boundaries is obtained.

[0008] Based on the evaluation results, a set of candidate switching algorithms is determined from the heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms, and the expected value of resource overhead and security gain of each candidate algorithm is calculated.

[0009] A dual-mode collaborative switching decision mechanism is established. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism.

[0010] By inserting a control frame carrying the algorithm negotiation payload at the semantic segment boundary, the cryptographic algorithm is switched, the degree of session continuity disruption and the algorithm migration integrity verification results are collected, and the scheduling execution feedback is formed. The scheduling execution feedback is used to iteratively correct the prediction parameters and the length of the reserved response interval.

[0011] An analysis based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage yields evaluation results including decay inflection points and algorithm failure time boundaries, including:

[0012] Establish a time-series correspondence matrix between the quantum computing capability evolution assessment value and the key life cycle stage. By mapping the growth trend of the quantum computing capability evolution assessment value in the time dimension to the advancement status of the key life cycle stage in the usage dimension on a time-by-time basis, a coupled evolution sequence of quantum threat intensity and key exposure degree is formed.

[0013] Based on the coupled evolution sequence, the security margin value of the cryptographic algorithm at each moment is calculated. The gradient change rate analysis is performed on the time series curve formed by the security margin value. The turning point when the gradient change rate in the time series curve changes from a gradual change to a steep change is identified as the decay inflection point. The moment when the security margin value drops to the preset security boundary is identified as the algorithm failure time boundary. The decay inflection point and the algorithm failure time boundary are jointly included in the evaluation result.

[0014] By mapping the growth trend of the quantum computing capability evolution assessment value over time to the advancement status of the key lifecycle stage in the usage dimension on a time-by-time basis, a coupled evolutionary sequence of quantum threat strength and key exposure degree is formed, including:

[0015] The quantum computing capability evolution assessment value is sampled over time to obtain the numerical change trajectory of the quantum computing capability evolution assessment value on a continuous time scale, and a trend fitting operation is performed on the numerical change trajectory to obtain the slope characteristics and acceleration characteristics of the growth trend.

[0016] The key lifecycle stage is quantified by usage dimension, and the key lifecycle stage is divided into multiple evolution sub-stages associated with the number of times the key is used. Each evolution sub-stage is assigned a state weight value that represents the degree of accumulation of key exposure risk.

[0017] A dual-axis mapping space of time scale and usage dimension is established. In the dual-axis mapping space, the time nodes corresponding to the slope feature and the acceleration feature are associated with the state weight value corresponding to each evolution sub-stage on a time-by-time basis. Based on the quantum computing capability at the time node, the state weight value is analyzed in a hierarchical and progressive manner and the historical cumulative influence is superimposed. Through multi-dimensional cross-validation and dynamic calibration, the coupling value at each time moment in the coupled evolution sequence is generated. The coupling values ​​at each time moment are arranged in chronological order to form the coupled evolution sequence.

[0018] Based on the evaluation results, a set of candidate switching algorithms is determined from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms. The expected resource overhead and expected security gain of each candidate algorithm are calculated, including:

[0019] The time window length between the decay inflection point and the algorithm failure time boundary is extracted from the evaluation results. Combined with the system operation trajectory, historical security event distribution characteristics and potential risk evolution patterns within the time window, a multi-dimensional comprehensive analysis is conducted to establish an urgency assessment standard and dynamically evaluate the current urgency level and security status of the system.

[0020] Based on the urgency level and the security situation, candidate algorithms are selected from the heterogeneous algorithm pool. The effectiveness and limitations of various protective measures in historical security incidents under different urgency levels are analyzed in a targeted manner. Combined with the evolution law of potential risks, differentiated security protection requirements are determined to form a set of candidate switching algorithms.

[0021] For each candidate algorithm in the candidate switching algorithm set, based on its resource utilization characteristics under different urgency levels and different load conditions, combined with the time window length and historical switching experience and lessons learned, the applicability of each candidate algorithm under the current security situation is comprehensively evaluated, and the expected value of resource overhead is determined.

[0022] For each candidate algorithm in the candidate switching algorithm set, and in conjunction with the urgency level and security situation, we conduct an in-depth analysis of the dynamic changes in its security improvement effect under the current risk evolution pattern. We verify the actual protection capability of each candidate algorithm through historical switching effect evaluation data and determine the expected value of security gain.

[0023] A dual-mode collaborative switching decision mechanism is established. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to a Pareto front solution set in a multi-objective constraint space, including:

[0024] A reserved response interval is set before the algorithm failure time boundary. The system status within the reserved response interval is continuously monitored. Based on the system load fluctuation pattern and historical switching experience, the system resource utilization characteristics are extracted. The system operation status is evaluated by combining the business peak distribution and security event occurrence pattern.

[0025] Based on the system operation status analysis, the execution effect of switching decisions under different response intervals is analyzed. The optimal response interval length is determined by combining historical data verification. The execution sequence and resource scheduling strategy of switching decisions are determined according to the optimal response interval length and the system resource utilization characteristics.

[0026] Within the reserved response interval, a multi-objective constraint space is constructed based on the execution sequence and the resource scheduling strategy. Based on the system operation status, the expected value of resource overhead and the expected value of security gain for each candidate algorithm under different system load conditions and different security threat levels are calculated respectively. The calculation results are mapped to feature points in the multi-objective constraint space.

[0027] By analyzing the distribution pattern of the feature points in the multi-objective constraint space, switching nodes are identified. The actual execution cost and protection effect of the switching scheme corresponding to each feature point are evaluated in combination with the system resource utilization characteristics. The set of non-dominated solutions that simultaneously satisfies the minimization of resource overhead and the maximization of security gain is selected to form the Pareto front solution set.

[0028] Cryptographic algorithm switching is performed by inserting control frames carrying algorithm negotiation payloads at the semantic segmentation boundaries, collecting verification results of session continuity disruption and algorithm migration integrity, and forming scheduling execution feedback including:

[0029] A control frame is constructed at the semantic segment boundary. The timing and position of the cut-in are determined by analyzing the data flow characteristics between the semantic segment boundary and the next semantic self-contained unit. The control frame is dynamically injected into the data flow based on the timing and position of the cut-in to trigger the switching of the cryptographic algorithm.

[0030] During the switching execution of the cryptographic algorithm, the continuity characteristics of the data stream are tracked based on the timing of the switch. By comparing and analyzing the data stream integrity and latency change trends at the switch position, and combining historical switching experience, the impact of the timing and position of the switch on the data stream is evaluated.

[0031] The migration integrity verification is performed on the switched cryptographic algorithm. A verification path is established based on the continuity characteristics of the data flow. By analyzing the verification effect of the verification path under different levels of influence, the rationality of the timing and location of the entry is continuously evaluated.

[0032] A thorough analysis of the correlation between the degree of impact and the verification effect is conducted, and scheduling execution feedback is generated by combining the evaluation results of the timing and location of the intervention.

[0033] Perform migration integrity verification on the switched cryptographic algorithm, establish a verification path based on the data flow continuity characteristics, and continuously evaluate the rationality of the timing and location of the intervention by analyzing the verification effect of the verification path under different levels of influence.

[0034] The switched cryptographic algorithm is subjected to migration integrity verification. Temporal stability indicators and data integrity parameters are extracted based on the continuity characteristics of the data stream. A hierarchical verification mechanism with adaptive verification depth is constructed. The hierarchical verification mechanism determines the dynamic distribution strategy of verification nodes by analyzing the fluctuation characteristics, mutation patterns and evolution trends of the data stream during the switching process, combined with historical verification experience and discrete time series analysis.

[0035] A data flow trajectory prediction model is established based on the spatial distribution characteristics and temporal correlation patterns of the verification nodes. The data flow trajectory prediction model analyzes the sensitivity of the data flow continuity characteristics under different system loads and network states by training the historical evolution patterns of the temporal stability index and the data integrity parameter. Combined with the dynamic distribution strategy, the verification effect of the verification path during the switching process under different influence levels and disturbance conditions is evaluated. The prediction results of the data flow trajectory prediction model are used to continuously evaluate the rationality of the entry timing and entry position.

[0036] A second aspect of the present invention provides a quantum-resistant dual-mode cryptographic algorithm switching system based on dynamic scheduling, comprising:

[0037] The acquisition module is used to acquire the operational characteristics of the cryptographic communication session, including the key lifecycle stage and the quantum computing capability evolution evaluation value; based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage, an evaluation result including the decay inflection point and the algorithm failure time boundary is obtained;

[0038] The determination module is used to determine a set of candidate switching algorithms from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms based on the evaluation results, and to calculate the expected value of resource overhead and the expected value of security gain for each candidate algorithm.

[0039] The mapping module is used to establish a dual-mode collaborative switching decision mechanism. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism.

[0040] The iterative module is used to perform cryptographic algorithm switching by inserting control frames carrying algorithm negotiation payloads at the semantic segmentation boundary, collect the verification results of session continuity disruption and algorithm migration integrity, form scheduling execution feedback, and use the scheduling execution feedback to iteratively correct the prediction parameters and the length of the reserved response interval.

[0041] A third aspect of the present invention provides an electronic device, comprising:

[0042] processor;

[0043] Memory used to store processor-executable instructions;

[0044] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0045] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0046] The beneficial effects of this application are as follows:

[0047] This invention collects the operational characteristics of cryptographic communication sessions, including key lifecycle stages and quantum computing capability evolution assessment values, and analyzes the correspondence between the two to obtain assessment results containing decay inflection points and algorithm failure time boundaries. It can accurately predict the time window of quantum threats faced by cryptographic algorithms, providing a scientific basis for timing judgment for algorithm switching. This avoids the problem that traditional static configuration methods cannot cope with the dynamic evolution of quantum computing capabilities, and improves the forward-looking protection capability of cryptographic systems.

[0048] This invention establishes a dual-mode collaborative switching decision mechanism. Within the reserved response interval before the algorithm failure time boundary, it maps the expected value of resource overhead and the expected value of security gain to the Pareto front solution set of the multi-objective constraint space. Combined with the semantic fragmentation boundary of the session data stream, it determines the switching scheme, realizing a smooth transition between the national cryptographic algorithm and the quantum-resistant cryptographic algorithm. This ensures the continuous improvement of communication security while taking into account the rationality of system resource consumption, and solves the technical problem of balancing security and performance during algorithm switching. Attached Figure Description

[0049] Figure 1 This is a flowchart illustrating the quantum-resistant dual-mode cryptographic algorithm switching method based on dynamic scheduling according to an embodiment of the present invention.

[0050] Figure 2 This is a flowchart illustrating the dynamic switching decision generation process based on multiple constraints in an embodiment of the present invention. Detailed Implementation

[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0052] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0053] Figure 1 This is a flowchart illustrating the quantum-resistant dual-mode cryptographic algorithm switching method based on dynamic scheduling according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0054] The operational characteristics of cryptographic communication sessions are collected, including key lifecycle stages and quantum computing capability evolution evaluation values. Based on the correspondence between the quantum computing capability evolution evaluation values ​​and the key lifecycle stages, an evaluation result including decay inflection points and algorithm failure time boundaries is obtained.

[0055] Based on the evaluation results, a set of candidate switching algorithms is determined from the heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms, and the expected value of resource overhead and security gain of each candidate algorithm is calculated.

[0056] A dual-mode collaborative switching decision mechanism is established. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism.

[0057] By inserting a control frame carrying the algorithm negotiation payload at the semantic segment boundary, the cryptographic algorithm is switched, the degree of session continuity disruption and the algorithm migration integrity verification results are collected, and the scheduling execution feedback is formed. The scheduling execution feedback is used to iteratively correct the prediction parameters and the length of the reserved response interval.

[0058] In one optional implementation, an analysis is performed based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage to obtain an evaluation result that includes the decay inflection point and the algorithm failure time boundary, including:

[0059] Establish a time-series correspondence matrix between the quantum computing capability evolution assessment value and the key life cycle stage. By mapping the growth trend of the quantum computing capability evolution assessment value in the time dimension to the advancement status of the key life cycle stage in the usage dimension on a time-by-time basis, a coupled evolution sequence of quantum threat intensity and key exposure degree is formed.

[0060] Based on the coupled evolution sequence, the security margin value of the cryptographic algorithm at each moment is calculated. The gradient change rate analysis is performed on the time series curve formed by the security margin value. The turning point when the gradient change rate in the time series curve changes from a gradual change to a steep change is identified as the decay inflection point. The moment when the security margin value drops to the preset security boundary is identified as the algorithm failure time boundary. The decay inflection point and the algorithm failure time boundary are jointly included in the evaluation result.

[0061] To achieve a correlation assessment between quantum threats and key lifecycle, a multi-dimensional temporal correspondence matrix needs to be constructed. This matrix contains three core dimensions: a time scale dimension, divided into equally spaced observation points according to the natural passage of time, with each observation point corresponding to a specific date and timestamp; a quantum computing capability dimension, recording the number of physical qubits, logical qubits, and quantum gate operation fidelity of the quantum computing system at that moment; and a key lifecycle dimension, marking the state identifiers of the key at each stage from generation, distribution, storage, use, to destruction. During matrix initialization, the time dimension is set to a range from the starting point to the next thirty years, with each time unit corresponding to a three-month observation period. For example, an observation point recorded as timestamp 202401 corresponds to a quantum computing capability assessment value of 85 points, indicating the key is in active use; this data tuple constitutes a basic unit in the matrix.

[0062] After establishing the temporal correspondence, a time-by-time mapping process is performed to analyze the growth trend of quantum computing power. Starting from the first time observation point in the matrix, the quantum computing power assessment value at that moment is extracted. This assessment value reflects the time cost required for the current quantum system to break a specific cryptographic algorithm. Simultaneously, the lifecycle stage of the key at the same moment is extracted. This stage information includes the key's usage time, remaining validity period, and cumulative data transmission volume. These two types of data are associated and bound to form a composite data structure containing time identifier, threat strength, and exposure level. For example, assuming that at time point 202404, the quantum computing power assessment value reaches 92 points, the corresponding key has been used for eighteen months, and the cumulative data transmission volume has reached five million encryption operations, then 92 points is used as the threat strength value. The eighteen-month usage time of the key and the cumulative value of five million operations are converted into an exposure level value of 68 points, forming a coupled data pair (92, 68).

[0063] The construction of the coupled evolution sequence relies on the accumulation of data pairs from all observation points across the entire time span. Threat intensity and exposure data pairs generated at each time point are arranged chronologically to form an ordered sequence structure. This sequence reflects two key trends: quantum threat intensity shows a continuous upward trend with technological advancements, while key exposure shows a cumulative increase with prolonged use. By calculating the increments in threat intensity and exposure between adjacent time points, the rate of their co-evolution can be quantified. For example, from time point 202407 to 202410, the threat intensity increases from 95 points to 98 points, an increment of 3 points; simultaneously, the exposure increases from 72 points to 79 points, an increment of 7 points. This increment pair shows that the rate of key exposure is faster than the rate of quantum threat growth during this time period.

[0064] The security margin is calculated based on the difference between the design strength of a cryptographic algorithm and the actual threats it faces. The design strength of an algorithm represents its theoretically upper limit of resistance to attacks, typically expressed as a standardized score based on parameters such as key length and algorithm complexity. For the AES-256 algorithm, its design strength is rated at 150 points; for the RSA-2048 algorithm, it is rated at 120 points. At each observation time, the algorithm's design strength is subtracted from the current quantum computing power assessment value, and then the key exposure value is subtracted to obtain the security margin value at that moment. For example, at time 202501, the RSA-2048 algorithm has a design strength of 120 points. Facing a quantum computing power assessment value of 100 points and a key exposure value of 75 points, the calculated security margin is -55 points, indicating that the algorithm is insecure. For cases where the security margin value is still positive, a larger value indicates a more sufficient security margin.

[0065] Connecting the security margin values ​​at all observation points in chronological order creates a time-series curve reflecting the evolution of the security state. In the early stages, this curve typically maintains high values ​​and declines slowly, indicating that quantum threats have not yet posed a substantial challenge to traditional cryptographic algorithms. As time progresses, the curve begins to show an accelerated decline, reflecting the significantly enhanced impact on cryptographic security after quantum computing capabilities overcome certain technological bottlenecks. Gradient rate of change analysis is performed on this curve. Specifically, the magnitude of the change in security margin values ​​between adjacent time points is calculated, followed by the rate of change of that magnitude itself. For example, from time point 202601 to 202604, the security margin decreases from 45 points to 40 points, with a gradient of -5 points; from 202604 to 202607, the security margin decreases from 40 points to 28 points, with a gradient of -12 points. The rate of change in these two gradient segments shows that the rate of decline accelerates from 5 points per quarter to 12 points per quarter, an increase of 140%.

[0066] The identification of decay inflection points is based on the abrupt change characteristics of the gradient change rate. A threshold for the gradient change rate is set, and when the increase in the gradient change rate in adjacent time periods exceeds this threshold, that moment is marked as a candidate inflection point. A verification check is performed on the candidate inflection point, requiring that the gradient change rate remain high for three consecutive observation periods after that moment to exclude interference from accidental fluctuations. The confirmed decay inflection point is marked as the turning point where the cryptographic algorithm's security transitions from a stable period to a rapid decline period. For example, assuming that at time point 202610, the gradient change rate jumps from 5 points per quarter to 15 points per quarter, and the gradient change rates for the subsequent three quarters are 17 points, 19 points, and 21 points respectively, this moment is confirmed as a decay inflection point.

[0067] The determination of the algorithm's failure time boundary is based on the breach judgment of a preset safety margin. This preset safety margin is set according to industry standards and risk tolerance, typically using a safety margin value dropping to zero or a negative value as the failure criterion. The system iterates through all observation points on the time series curve to find the moment when the safety margin value first touches the preset boundary. If the safety margin value at a certain observation point is +3 points and the next observation point is -2 points, then linear interpolation is performed between these two time points to estimate the precise time coordinate at which the safety margin value drops to zero. For example, if the safety margin value at time point 202704 is 8 points and the safety margin value at time point 202707 is -4 points, with a three-month interval between the two points, the calculated time when the safety margin value drops to zero is approximately mid-202705, which is the algorithm's failure time boundary.

[0068] The evaluation results output includes two key time points and their related descriptive information. The decay inflection point output includes the specific timestamp of the inflection point, the security margin value at that moment, the gradient change rate value, and security status comparison data for three observation periods before and after the inflection point. The algorithm failure time boundary output includes the timestamp of the failure moment, the remaining key validity period, the quantum computing capability assessment value, and the type of recommended countermeasures. The integration of the two node information forms a complete quantum threat timeline map, providing a decision-making basis for key update strategy formulation. For example, if an evaluation result shows that the decay inflection point occurs in 202610 and the failure time boundary occurs in 202705, it indicates that there is a nine-month warning window from the inflection point to failure, during which the system can complete the key system upgrade and migration.

[0069] In one optional implementation, a coupled evolutionary sequence of quantum threat strength and key exposure is formed by mapping the growth trend of the quantum computing capability evolution assessment value over time with the advancement status of the key lifecycle stage in the usage dimension on a time-by-time basis, including:

[0070] The quantum computing capability evolution assessment value is sampled over time to obtain the numerical change trajectory of the quantum computing capability evolution assessment value on a continuous time scale, and a trend fitting operation is performed on the numerical change trajectory to obtain the slope characteristics and acceleration characteristics of the growth trend.

[0071] The key lifecycle stage is quantified by usage dimension, and the key lifecycle stage is divided into multiple evolution sub-stages associated with the number of times the key is used. Each evolution sub-stage is assigned a state weight value that represents the degree of accumulation of key exposure risk.

[0072] A dual-axis mapping space of time scale and usage dimension is established. In the dual-axis mapping space, the time nodes corresponding to the slope feature and the acceleration feature are associated with the state weight value corresponding to each evolution sub-stage on a time-by-time basis. Based on the quantum computing capability at the time node, the state weight value is analyzed in a hierarchical and progressive manner and the historical cumulative influence is superimposed. Through multi-dimensional cross-validation and dynamic calibration, the coupling value at each time moment in the coupled evolution sequence is generated. The coupling values ​​at each time moment are arranged in chronological order to form the coupled evolution sequence.

[0073] The time-series sampling of quantum computing capability evolution assessment values ​​is achieved through the deployment of distributed monitoring nodes. These nodes sample core indicators such as the number of qubits, gate operation fidelity, and coherence time at fixed time intervals. The sampling interval is set to once per hour, with a sampling precision of four decimal places. Data storage uses a key-value structure of timestamps and numerical pairs. The monitoring module maintains a circular buffer with a capacity of 8760 data points, corresponding to hourly sampling data for one year. When the buffer is full, a first-in-first-out (FIFO) strategy is used to discard historical data. The acquisition of numerical change trajectories relies on a sliding window mechanism. The window size is set to 168 data points corresponding to a one-week time span, and each sliding step is 24 data points corresponding to one day. Trajectory data preprocessing includes outlier detection and smoothing. The outlier threshold is set to three standard deviations. When an outlier is detected, the mean of the nearest neighboring points is used for interpolation and replacement.

[0074] The trend fitting operation is based on the least squares principle. Data points within the fitting window are used to calculate the slope feature through linear regression. The slope value represents the growth rate of quantum computing power, expressed in power values ​​per hour. The acceleration feature is obtained by quadratic fitting of the slope sequence, reflecting the changing trend of the growth rate, expressed in the square of power values ​​per hour. The fitting algorithm uses a recursive update method; when new data points are added, only the affected local intervals are recalculated, avoiding full recalculation and improving computational efficiency. The fitting quality is evaluated using the coefficient of determination index, with a threshold set at 0.85. A value below the threshold triggers refitting or adaptive adjustment of the fitting window. The calculation results of the slope and acceleration features are retained to six decimal places. Intermediate variables during the calculation process are stored as double-precision floating-point numbers to avoid accumulated errors.

[0075] The quantification of key lifecycle phases is based on key usage frequency statistics. A frequency counter increments atomically to ensure concurrency security. The key lifecycle is divided into five evolutionary sub-phases: initial phase, active phase, mature phase, decay phase, and obsolescence phase. These phases are based on the percentage range of cumulative usage relative to the preset total lifetime usage. The initial phase corresponds to a usage ratio of 0-20%, the active phase 20%-50%, the mature phase 50%-75%, the decay phase 75%-95%, and the obsolescence phase 95%-100%. State weights are assigned incrementally: 0.1 for the initial phase, 0.3 for the active phase, 0.6 for the mature phase, 0.9 for the decay phase, and 1.0 for the obsolescence phase. Weight calculation considers the specific distribution of usage within each sub-phase, using linear interpolation to determine precise weight values, maintaining an interpolation accuracy to three decimal places.

[0076] The dual-axis mapping space is established using a two-dimensional coordinate system. The horizontal axis represents time in hours, and the vertical axis represents usage dimensions in cumulative usage counts. The origin of the mapping space is set at the first use of the key. The positive direction of the time axis points to the future, while the positive direction of the usage dimension axis points in the direction of increasing usage counts. An adaptive strategy is used for the coordinate grid division. The grid interval on the time axis is dynamically adjusted according to data density; hourly intervals are used when the density is high, and daily intervals are used when the density is low. The grid interval on the usage dimension axis is determined based on the total number of uses within the key's preset lifecycle. Dividing the total number of uses by 100 yields the basic grid interval, ensuring a moderate grid density for easy data location and visualization.

[0077] The time-by-time association between time nodes and state weight values ​​is achieved through hash mapping. The mapping key is a composite index of timestamp and usage count, and the mapping value contains three fields: slope feature, acceleration feature, and state weight value. The association process first looks up the corresponding slope and acceleration features based on the time node, then determines the evolutionary sub-stage based on the cumulative usage count of that time node, and finally obtains the corresponding state weight value. The storage of associated data adopts a time-sharding strategy, with daily data stored as independent shards. The shard index contains date identifiers and data range information, facilitating historical data querying and archiving management. Concurrency control for association operations employs a read-write lock mechanism. Read operations are allowed to execute concurrently, while write operations are executed mutually exclusively to ensure data consistency.

[0078] The hierarchical progressive analysis is based on the influence of quantum computing capabilities on state weight values, and the degree of influence is assessed using the concept of a threat coefficient. The threat coefficient calculation comprehensively considers the magnitude of both slope and acceleration characteristics, with the slope contributing 70% of the weight and acceleration contributing 30%. This weight allocation is determined based on historical statistical data. The threat coefficient is calculated using a piecewise linear function. When the slope characteristic is less than a preset baseline value, the threat coefficient is 1.0; when it exceeds the baseline value, it increases proportionally, with a growth rate coefficient set to 0.1 per unit slope increase. The threat coefficient calculation for acceleration characteristics is similar, with the baseline value set to the square root of the slope characteristic baseline value, and the growth rate coefficient set to 0.05 per unit acceleration increase.

[0079] The cumulative historical impact is calculated using a decaying cumulative model, where the impact of historical time points decays exponentially over time, with a decay coefficient set to 0.95 per hour. A sequence of impact values ​​is maintained for cumulative calculation, with a sequence length limited to 720 elements corresponding to 30 days of history; historical impact values ​​exceeding this length are automatically discarded. The accumulation process uses a sliding window approach: the impact value of a new time point is added to the beginning of the sequence, and all historical impact values ​​are updated according to the decay coefficient. The cumulative impact value is the weighted sum of all elements in the sequence. The parameters of the decaying cumulative model can be dynamically adjusted at runtime; the decay coefficient can be adjusted within the range of 0.9 to 0.99, and the historical window length can be adjusted within the range of 15 to 60 days.

[0080] Multi-dimensional cross-validation is achieved through independent computational paths. The first path is based on the growth trend of quantum computing power over time, the second on the cumulative degree of key exposure over usage, and the third on an empirical model based on historical statistical data. The results from the three paths are fused using a weighted average, with weights allocated as follows: 40% for time, 35% for usage, and 25% for the empirical model. A difference threshold of 15% is set for cross-validation. When the difference between the results of any two paths exceeds this threshold, an anomaly alarm is triggered, and a detailed diagnostic process is initiated to identify the cause of the difference. The confidence level of the validation results is assessed using analysis of variance. A variance less than 0.01 is considered valid, while a variance exceeding 0.05 is considered a failure requiring recalculation.

[0081] The dynamic calibration mechanism is based on feedback control principles. Calibration trigger conditions include verification failure, changes in the external environment, and updates to configuration parameters. The calibration process is achieved by adjusting key parameters such as threat coefficient calculation parameters, attenuation coefficients, and weight allocation ratios. The adjustment range is controlled within ±10% of the original parameter values ​​to avoid system oscillation. Calibration effectiveness is evaluated using a before-and-after comparison method, with comparison indicators including prediction accuracy, computational stability, and resource consumption. A 5% or greater improvement in indicators after calibration is considered effective. Calibration history is stored for 180 days, including calibration trigger reasons, parameter adjustment details, and effectiveness evaluation results, providing data support for subsequent optimization.

[0082] The coupling value generation employs a weighted fusion algorithm. The fusion input includes three components: the current quantum computing capability value, the key exposure state weight value, and the historical cumulative influence value. The fusion weights are dynamically determined based on the characteristics of each time point. In the early stages of the key lifecycle, the quantum computing capability weight is set to 0.6, while in the mid-to-late stages, the key exposure weight is set to 0.7. The historical cumulative influence weight remains constant at 0.2 throughout the entire lifecycle. The coupling value calculation precision is maintained to five decimal places, and an intermediate result caching strategy is used to avoid redundant calculations and improve performance. The coupling value range is normalized to the interval between 0 and 1, and outliers outside this range are truncated.

[0083] The generation of the coupled evolution sequence is achieved through time sorting and data integration. The sorting algorithm uses merge sort to ensure stability and efficiency, with a time complexity of O(n log n). The sequence data structure includes fields such as timestamp, coupling value, confidence level, and calculation version, with field types of long integer, double-precision floating-point, single-precision floating-point, and string, respectively. Sequence storage employs a compressed format to reduce storage space usage. The LZ4 compression algorithm is chosen to ensure fast compression and decompression, with a compression ratio typically exceeding 60%. The sequence data access interface supports functions such as time range query, value range filtering, and sampling frequency reduction. Query response time is controlled at the millisecond level to meet real-time application requirements.

[0084] In one optional implementation, a set of candidate switching algorithms is determined from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms based on the evaluation results, and the expected resource overhead and expected security gain of each candidate algorithm are calculated, including:

[0085] The time window length between the decay inflection point and the algorithm failure time boundary is extracted from the evaluation results. Combined with the system operation trajectory, historical security event distribution characteristics and potential risk evolution patterns within the time window, a multi-dimensional comprehensive analysis is conducted to establish an urgency assessment standard and dynamically evaluate the current urgency level and security status of the system.

[0086] Based on the urgency level and the security situation, candidate algorithms are selected from the heterogeneous algorithm pool. The effectiveness and limitations of various protective measures in historical security incidents under different urgency levels are analyzed in a targeted manner. Combined with the evolution law of potential risks, differentiated security protection requirements are determined to form a set of candidate switching algorithms.

[0087] For each candidate algorithm in the candidate switching algorithm set, based on its resource utilization characteristics under different urgency levels and different load conditions, combined with the time window length and historical switching experience and lessons learned, the applicability of each candidate algorithm under the current security situation is comprehensively evaluated, and the expected value of resource overhead is determined.

[0088] For each candidate algorithm in the candidate switching algorithm set, and in conjunction with the urgency level and security situation, we conduct an in-depth analysis of the dynamic changes in its security improvement effect under the current risk evolution pattern. We verify the actual protection capability of each candidate algorithm through historical switching effect evaluation data and determine the expected value of security gain.

[0089] The time window length is extracted by parsing the decay inflection point timestamp and the algorithm failure boundary timestamp in the evaluation results. A time difference calculation method is used to obtain the window length value in hours. The extraction module receives the evaluation result data in JSON format, parses the decay inflection point and algorithm failure boundary timestamp fields, performs a subtraction operation, and converts the data to hours, maintaining precision to two decimal places. When the confidence level of the evaluation result confidence field is below 0.85, a safety margin adjustment factor of 0.8 is applied to reduce the time window length. The time window data is stored in a time series database, supporting historical query and trend analysis functions.

[0090] The operation trajectory data collection is implemented based on a distributed monitoring architecture, with monitoring agents deployed on key nodes such as application servers, database servers, and network devices. Collected metrics include operational parameters such as CPU utilization, memory usage, network throughput, disk I / O latency, and process response time. The sampling frequency is set to once every 30 seconds to ensure a balance between data granularity and real-time performance. The trajectory data structure includes fields such as timestamp, node identifier, metric type, value, and unit. A time-sharded storage strategy is adopted, with hourly data forming independent shards for easy querying and archiving. Outlier detection employs statistical methods, setting three times the standard deviation as the outlier threshold. When an outlier is detected, an anomaly log is recorded, and data repair is performed using linear interpolation.

[0091] The analysis of historical security incident distribution characteristics relies on a security incident management database. The database table structure includes core fields such as unique event identifier, event type, occurrence time, end time, impact scope, severity, and handling status. Event type classification adopts a standardized classification system. The primary classification includes four main categories: network attacks, malicious code, unauthorized operations, and system failures. The secondary classification is refined to specific attack methods such as SQL injection, cross-site scripting, denial-of-service attacks, and buffer overflows. The distribution characteristic statistical algorithm uses a sliding time window method. The window size can be configured to different granularities such as 1 hour, 6 hours, 24 hours, and 7 days, statistically analyzing characteristic parameters such as the frequency of occurrence, average duration, and impact scope distribution of different types of events within each time window.

[0092] The identification of potential risk evolution patterns is achieved through a time series prediction model. The model chosen is the ARIMA autoregressive integral moving average model, with parameters configured as follows: AR term p=2, difference times d=1, and MA term q=2. The model training dataset covers historical security event data from the past 12 months, and the maximum likelihood estimation method is used to optimize the model parameters during training. Evolutionary pattern feature extraction includes three dimensions: seasonality cycle identification, long-term trend analysis, and pattern detection. Seasonal analysis uses Fourier transform to identify major frequency components, trend analysis uses least squares to fit trend lines, and detection uses a change point detection algorithm to identify anomalous abrupt changes. Prediction accuracy is evaluated using the mean absolute percentage error (MASE) metric, with a threshold set at 15%. When the model accuracy falls below the threshold, a parameter re-optimization process is triggered.

[0093] The multi-dimensional comprehensive analysis is built upon a data fusion framework. The fusion algorithm employs a weighted fusion method, with weight allocation determined through a combination of expert evaluation and historical data statistics. The time window length dimension has a weight of 0.25, reflecting the urgency of the switchover response time; the operational trajectory characteristics dimension has a weight of 0.30, reflecting the current operational status of the system; the historical security event distribution dimension has a weight of 0.20, reflecting historical threat patterns; and the potential risk evolution pattern dimension has a weight of 0.25, reflecting future risk trends. Each dimension is scored using a standardized scoring system from 0 to 100, and the scoring calculation process includes three steps: data normalization, weight application, and comprehensive score calculation.

[0094] The urgency assessment criteria employ a tiered system, mapping the overall score to five urgency levels. Low urgency corresponds to a score range of 0-20, indicating normal system operation and low threat risk; low-to-medium urgency corresponds to 21-40, indicating potential risk with limited impact; medium urgency corresponds to 41-60, indicating significant risk requiring attention; medium-to-high urgency corresponds to 61-80, indicating a high threat requiring preventative measures; and high urgency corresponds to 81-100, indicating a severe threat requiring immediate response. The assessment results output includes detailed information such as level codes, specific scores, confidence intervals, and contribution breakdowns for each dimension.

[0095] The dynamic security posture assessment integrates multi-source threat intelligence data, including external intelligence such as vulnerability databases, malware repositories, attack signature databases, and threat reports, as well as internal security monitoring data. The posture assessment model employs a Bayesian network structure, where network nodes contain elements such as threat sources, attack vectors, vulnerabilities, asset value, and protection capabilities, with edges representing causal relationships between elements. Prior probabilities are determined based on historical statistical data, while conditional probabilities are obtained through joint modeling using expert knowledge engineering and machine learning methods. The posture calculation engine periodically updates network parameters and calculates a risk index for the current security posture, ranging from 0 to 1 with precision to three decimal places.

[0096] The heterogeneous algorithm pool encompasses two main categories: Chinese national cryptographic algorithms and quantum-resistant cryptographic algorithms. The Chinese national cryptographic algorithms include core implementations such as the SM2 elliptic curve public key algorithm, the SM3 cryptographic hash algorithm, and the SM4 block cipher algorithm. The quantum-resistant cryptographic algorithms include mainstream quantum-resistant algorithms such as the NTRU algorithm based on lattice theory, the McEliece algorithm based on error correction coding, the Rainbow algorithm based on multivariate public keys, and the SPHINCS signature algorithm based on hash functions. The algorithm pool data structure adopts a hierarchical organization: the first layer groups algorithms by category, the second layer categorizes them by specific algorithms, and the third layer stores attribute information such as algorithm version, parameter configuration, performance indicators, and security strength. The algorithm pool management interface provides functions such as algorithm registration, querying, filtering, and version management.

[0097] The candidate algorithm selection mechanism is implemented based on a rule engine. The rule base defines decision rules that map urgency levels and security postures to candidate algorithms. The rule structure includes a condition section and a conclusion section. The condition section defines selection criteria such as the urgency level range, the security posture risk index range, and system performance constraints. The conclusion section specifies output requirements such as the recommended algorithm category, priority ranking, and quantity limits. The rule engine uses forward reasoning to match corresponding rules based on the input urgency level and security posture parameters, outputting a list of candidate algorithms. The selection process also considers compatibility constraints and mutual exclusion relationships between algorithms to ensure the feasibility of the selection results.

[0098] The effectiveness analysis of historical security incident mitigation measures employs association rule mining, using the Apriori algorithm to identify strong association rules between security incident types and mitigation measure types. The effectiveness quantification index system includes four core indicators: protection success rate, false alarm rate, false negative rate, and average response time. The success rate is defined as the proportion of mitigation measures that successfully prevented or mitigated security incidents out of the total number of mitigation measures executed. Analysis results are stored hierarchically according to urgency levels, with each level recording the effectiveness statistics of different event types and mitigation measure combinations. Limitation identification is achieved through anomaly case analysis, focusing on unusual situations where mitigation measures fail under expected effective scenarios.

[0099] Differentiated security protection requirements are determined based on a threat risk assessment matrix. The matrix's rows represent threat type classifications, columns represent asset importance levels, and matrix elements represent corresponding protection strength requirements. Protection requirements are divided into three strength levels: Basic protection corresponds to a single-algorithm protection scheme, suitable for low-risk scenarios; Enhanced protection corresponds to a dual-algorithm redundancy scheme, suitable for medium-risk scenarios; and Strict protection corresponds to a multi-algorithm combination scheme, suitable for high-risk scenarios. The requirement mapping process involves querying the threat risk assessment matrix to obtain the corresponding protection requirement specifications based on the current threat assessment results and critical asset classifications.

[0100] The candidate switching algorithm set is generated using a multi-objective optimization method, with optimization objectives including maximizing safety gain, minimizing resource overhead, and minimizing switching complexity. A genetic algorithm is selected as the optimization algorithm, with a population size of 100, a crossover probability of 0.8, a mutation probability of 0.1, and 200 iterations. Individual algorithm codes use binary encoding, with each gene representing the selection state of a candidate algorithm. The fitness function is designed as a weighted comprehensive evaluation function, with weight coefficients dynamically adjusted according to the current urgency level. The optimization process generates a Pareto optimal solution set, from which several algorithms with the best overall performance are selected to form the candidate switching algorithm set.

[0101] Resource utilization feature analysis is based on a performance benchmark database, with test data covering combined test scenarios across different hardware platforms, load intensities, and concurrency levels. The quantifiable metrics for resource utilization features include four dimensions: CPU computational overhead, memory storage overhead, network communication overhead, and disk I / O overhead. Test precision requirements are set to milliseconds for CPU overhead, MB for memory overhead, KB / s for network overhead, and times / second for disk overhead. Feature data is stored using a multi-dimensional array structure, supporting fast queries by multiple index dimensions such as algorithm identifier, urgency level, and load type. Load condition classification uses a three-dimensional spatial definition, including dimensions of data processing volume, concurrent connection count, and data packet size.

[0102] Historical handover lessons learned are extracted through handover operation log mining. Log data includes key fields such as handover initiation time, source algorithm identifier, target algorithm identifier, handover execution duration, handover result status, and error messages. The experience extraction algorithm employs a decision tree learning method, using handover success / failure as the target variable and algorithm type, system load, and time window as feature variables to learn the key influencing factors for successful handover. Lessons learned are summarized into a knowledge base, containing common handover failure modes, corresponding preventative measures, and best practice guidelines. The knowledge base supports searching by failure type, algorithm combination, system environment, and other dimensions.

[0103] The comprehensive applicability analysis employs a fuzzy comprehensive evaluation method. The evaluation index system includes five primary indicators: algorithm security strength, computational resource requirements, implementation complexity, system compatibility, and operational stability. Each primary indicator is further subdivided into several secondary indicators for detailed evaluation. The security strength indicator includes sub-indicators such as resistance to classical computing attacks and resistance to quantum computing attacks. Evaluation weights are determined using the analytic hierarchy process (AHP), and a judgment matrix is ​​constructed through expert scoring to calculate the relative importance weights of each indicator. The fuzzy evaluation process converts qualitative evaluation into quantitative scoring, and 0-1 standardization ensures the comparability of evaluation results.

[0104] The expected resource overhead is calculated using Monte Carlo simulation. The simulation process considers the random distribution characteristics of the load conditions, with load parameters including random variables such as data processing volume, concurrent connections, and packet size. Each random variable is fitted with a probability distribution function based on historical statistical data: data processing volume follows a Poisson distribution, concurrent connections follow a normal distribution, and packet size follows an exponential distribution. The simulation executes 10,000 independent trials, with load conditions randomly generated for each trial. The corresponding resource overhead is calculated, and the expected value, variance, confidence interval, and other statistical characteristics of the resource overhead are finally obtained. The calculation process considers the additional overhead of the switching process, including algorithm initialization cost, state transition cost, and data format conversion cost.

[0105] The calculation of the expected security gain comprehensively considers the algorithm's own security strength improvement effect and its adaptability to the current threat environment. This adaptability is quantified using a threat-algorithm matching evaluation model. Security strength is uniformly quantified using the concept of equivalent security levels, mapping the security strength of different algorithm types to equivalent symmetric key lengths for easy horizontal comparison. Dynamic change feature analysis considers the impact of time evolution on security gain, establishing a security strength decay model to describe the changing pattern of algorithm security over time. The gain calculation process incorporates risk evolution prediction to evaluate the algorithm's expected security gain in future time periods.

[0106] Historical switchover effectiveness evaluation data is collected from actual switchover execution records in the production environment. The data includes multi-dimensional effectiveness evaluation information such as comparisons of system security indicators before and after the switchover, changes in performance indicators, and impact on user service quality. Security indicators include quantitative metrics such as security incident frequency, average incident severity, and attack success rate. Performance indicators include operational metrics such as system response time, throughput, and resource utilization. Effectiveness quantification employs a before-and-after comparative analysis method, calculating the percentage improvement of each indicator to generate a switchover effectiveness evaluation report.

[0107] Actual protection capabilities are verified through penetration testing and attack simulation experiments. Test scenarios cover known attack vectors and emerging threat methods, including various attack types such as hacking, side-channel attacks, and quantum algorithm attacks. Test execution utilizes an automated testing framework, supporting batch test task scheduling and result statistical analysis. The quantitative metric for protection capability is the attack blocking success rate, calculated by dividing the number of successfully blocked attacks by the total number of attack attempts. The result is expressed as a percentage and rounded to two decimal places.

[0108] In one optional implementation, a dual-mode cooperative switching decision mechanism is established. Within a reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to a Pareto front solution set of a multi-objective constraint space, including:

[0109] A reserved response interval is set before the algorithm failure time boundary. The system status within the reserved response interval is continuously monitored. Based on the system load fluctuation pattern and historical switching experience, the system resource utilization characteristics are extracted. The system operation status is evaluated by combining the business peak distribution and security event occurrence pattern.

[0110] Based on the system operation status analysis, the execution effect of switching decisions under different response intervals is analyzed. The optimal response interval length is determined by combining historical data verification. The execution sequence and resource scheduling strategy of switching decisions are determined according to the optimal response interval length and the system resource utilization characteristics.

[0111] Within the reserved response interval, a multi-objective constraint space is constructed based on the execution sequence and the resource scheduling strategy. Based on the system operation status, the expected value of resource overhead and the expected value of security gain for each candidate algorithm under different system load conditions and different security threat levels are calculated respectively. The calculation results are mapped to feature points in the multi-objective constraint space.

[0112] By analyzing the distribution pattern of the feature points in the multi-objective constraint space, switching nodes are identified. The actual execution cost and protection effect of the switching scheme corresponding to each feature point are evaluated in combination with the system resource utilization characteristics. The set of non-dominated solutions that simultaneously satisfies the minimization of resource overhead and the maximization of security gain is selected to form the Pareto front solution set.

[0113] like Figure 2 As shown, the method includes:

[0114] The reserved response interval is set within the time period before the algorithm failure time boundary. The interval length is determined by calculating the time window length and the safety margin coefficient. The time window length is extracted from the evaluation results and calculated in hours, keeping two decimal places precise, by comparing the decay inflection point timestamp with the algorithm failure time boundary timestamp. The safety margin coefficient is dynamically adjusted according to the current threat level: 0.3 for low threat levels, 0.5 for medium threat levels, and 0.7 for high threat levels. The reserved response interval length is equal to the time window length multiplied by the safety margin coefficient. The starting point of the interval is set as the algorithm failure time boundary minus the reserved response interval length, ensuring sufficient time for the handover decision to be executed.

[0115] Continuous system status monitoring is achieved through a distributed monitoring agent. This agent is deployed on key nodes to collect operational metrics such as CPU utilization, memory usage, network bandwidth utilization, and disk I / O latency. The monitoring data collection frequency is set to once every 15 seconds, and the data format includes fields such as timestamp, node identifier, metric type, numerical value, and status flag. Monitoring data is transmitted in real-time to a central processing node and stored in a time-series database to support rapid querying and analysis. An anomaly detection module performs real-time analysis of the monitoring data, setting anomaly thresholds as CPU utilization exceeding 85%, memory usage exceeding 90%, and network latency exceeding 100 milliseconds. Upon detecting anomalies, the module immediately records the anomaly event and triggers an alarm notification.

[0116] System resource utilization feature extraction is based on statistical analysis of historical monitoring data, with the analysis time window set to the most recent 30 days of operational data. Load fluctuation patterns are identified by calculating the mean, standard deviation, and coefficient of variation of various monitoring indicators. A coefficient of variation exceeding 0.3 indicates significant load fluctuation, while a coefficient of variation less than 0.1 indicates relatively stable load. Historical switchover experience is extracted from switchover operation logs, which include information such as switchover time, source algorithm, target algorithm, execution time, and success status. Resource utilization features are quantified into three dimensions: peak utilization, average utilization, and fluctuation amplitude. Each dimension uses a standardized scoring system from 0 to 1, where 0 represents the lowest resource utilization and 1 represents the highest.

[0117] The business peak distribution analysis employs a time series decomposition method, breaking down historical business volume data into three components: trend component, seasonal component, and random component. The seasonal component identifies peak business periods within a day, typically 9:00 AM to 11:00 AM, 2:00 PM to 4:00 PM, and 7:00 PM to 9:00 PM. Business volume data is extracted from application server access logs, including metrics such as request count, response time, and concurrent connections. Peak intensity is quantified by calculating the ratio of the peak period to the average level; a ratio exceeding 2.0 is defined as a strong peak, 1.5 to 2.0 as a moderate peak, and less than 1.5 as a weak peak.

[0118] The security incident pattern analysis is based on historical records in the security incident management database. Incident records include information such as occurrence time, incident type, severity, duration, and scope of impact. Incident frequency is statistically analyzed hourly to identify high-risk periods within a day, typically system maintenance from 00:00 to 06:00 and off-peak business from 12:00 to 14:00. Incident type distribution statistics show that network attacks account for 45%, malicious code for 25%, unauthorized operations for 20%, and system failures for 10%. Severity is rated on a scale of 1 to 5, with 5 being the highest severity. Statistical results show that incidents at severity level 3 or higher account for 35% of all incidents.

[0119] The system operational status assessment comprehensively considers the distribution of peak business hours and the patterns of security incidents, establishing a status assessment model to calculate the current operational status index. The status index calculation uses a weighted average method, with business load weighted at 0.4 and security threat weighted at 0.6, reflecting the principle of prioritizing security. The business load score is based on a comparison of the current period's load with historical averages for the same period. A current load exceeding the historical average by more than 20% is considered high load, while a load below the average by more than 20% is considered low load. The security threat score is based on security incident occurrences and threat intelligence updates within the last 24 hours; the threat score increases when a high-severity incident occurs or new threat intelligence is received. The status index ranges from 0 to 1, with 0 indicating a good operational status and 1 indicating a severe operational status.

[0120] The effectiveness analysis of switchover decisions under different response intervals was achieved through simulation calculations. The response interval length was set from 1 hour to 12 hours, with an analysis point set every hour. 100 switchover scenarios were simulated for each response interval length. Scenario parameters included random variables such as system load level, threat intensity level, and business impact period. The effectiveness evaluation metrics included four dimensions: switchover success rate, average execution time, total resource consumption, and business interruption duration. The switchover success rate was required to reach 95% or higher, the average execution time to be controlled within 30 minutes, the total resource consumption to not exceed 20% of the system capacity, and the business interruption duration to be controlled within 5 minutes.

[0121] Historical data verification was conducted using actual switchover records from the past six months, containing detailed data on 83 successful switchovers and 7 failed switchovers. The verification analysis revealed that a 4-hour response interval resulted in the highest switchover success rate (96.7%), a 2-hour response interval resulted in the shortest average execution time (18 minutes), and a 6-hour response interval resulted in the lowest resource consumption (12% of system capacity). A comprehensive evaluation weighted the various metrics as follows: success rate 0.4, execution time 0.3, resource consumption 0.2, and business impact 0.1, calculating the optimal response interval length as 4 hours.

[0122] The execution timing is determined based on the optimal response interval length and system resource utilization characteristics, dividing the 4-hour response interval into three execution phases. The first phase is the preparation phase, lasting 1 hour, primarily involving resource pre-allocation, algorithm initialization, and state backup. The second phase is the switching phase, lasting 2 hours, performing core switching operations such as algorithm replacement, parameter configuration, and functional verification. The third phase is the stabilization phase, lasting 1 hour, performing final tasks such as system stability monitoring, performance tuning, and anomaly handling.

[0123] The resource scheduling strategy employs a tiered scheduling scheme based on system resource utilization characteristics. During low-load periods, a parallel scheduling strategy is used to execute multiple switching tasks simultaneously. During medium-load periods, a serial scheduling strategy is used to execute switching tasks one by one. During high-load periods, a delayed scheduling strategy is used to postpone non-urgent switching tasks. A resource reservation mechanism reserves 20% of CPU resources, 30% of memory resources, and 15% of network bandwidth for switching operations, ensuring that the switching process does not affect normal business operations. Resource isolation is achieved through container technology, allocating an independent computing environment for switching operations to avoid resource contention with business applications.

[0124] The multi-objective constraint space is constructed using a three-dimensional spatial model. The X-axis represents the resource overhead dimension, the Y-axis represents the security gain dimension, and the Z-axis represents the execution complexity dimension. The space range is set to resource overhead from 0 to 1000 units, security gain from 0 to 256-bit equivalent security strength, and execution complexity from 0 to 100 complexity scores. The constraints include three types: upper limit constraints on resources, lower limit constraints on security, and time window constraints. The upper limit constraints on resources limit the maximum resource consumption of a single switch, the lower limit constraints on security ensure the minimum security strength after the switch, and the time window constraints ensure that the switch is completed within the reserved response interval.

[0125] The expected resource cost of candidate algorithms is calculated based on performance test data under different system load conditions, categorized into light, medium, and heavy loads. Light load corresponds to CPU utilization below 30% and memory utilization below 40%; medium load corresponds to CPU utilization between 30% and 70% and memory utilization between 40% and 80%; and heavy load corresponds to CPU utilization above 70% and memory utilization above 80%. Each candidate algorithm is tested 1000 times at each load level, recording resource consumption data such as CPU time, memory usage, network traffic, and disk I / O. The expected value is calculated using a weighted average method, with weights determined based on historical load distribution: 0.2 for light load, 0.5 for medium load, and 0.3 for heavy load.

[0126] The expected security gain is calculated based on the protection effectiveness assessment under different security threat levels, which are divided into three levels: low, medium, and high. Low threat level corresponds to basic threats such as conventional scanning attacks and weak password attacks; medium threat level corresponds to application-layer attacks such as SQL injection and cross-site scripting; and high threat level corresponds to advanced threats such as APT attacks and zero-day exploits. Each candidate algorithm undergoes protection capability testing for each threat level, evaluating metrics such as attack success rate, detection accuracy, and response time. The security gain is quantified as an equivalent security strength improvement value, calculated using the information theory entropy value method, combining the algorithm's theoretical security strength with the actual attack cost assessment.

[0127] The feature point mapping process maps the expected resource cost and expected safety gain of each candidate algorithm as coordinate points to a multi-objective constraint space, forming a set of algorithm feature points. Each feature point contains attribute information such as algorithm identifier, resource cost coordinates, safety gain coordinates, execution complexity coordinates, algorithm type, and priority. Mapping precision is set to retain integer values ​​for resource cost, one decimal place for safety gain, and integer values ​​for execution complexity. Feature point storage employs a multi-dimensional index structure, supporting fast retrieval based on coordinate range, algorithm type, priority, and other criteria.

[0128] Feature point distribution pattern analysis identifies the distribution patterns of algorithm types through clustering algorithms. The K-means clustering algorithm is selected, with five clusters corresponding to different algorithm performance characteristic categories. The first category is high-security, low-overhead, characterized by a security gain greater than 200 bits and resource overhead less than 300 units. The second category is balanced performance, characterized by a security gain of 150 to 200 bits and resource overhead of 300 to 600 units. The third category is high-performance, characterized by resource overhead less than 200 units but relatively low security gain. The fourth category is high-security, characterized by a security gain greater than 220 bits but higher resource overhead. The fifth category is special-purpose algorithms, specifically designed for particular application scenarios.

[0129] Switching node identification is based on the positional relationships of feature points in the constraint space to identify key nodes that satisfy multi-objective optimization conditions. The identification rules include three judgment dimensions: the nearest distance principle, the performance balance principle, and the resource constraint principle. The nearest distance principle calculates the Euclidean distance from the feature point to the ideal point, whose coordinates represent the minimum resource cost, the maximum safety gain, and the minimum execution complexity. The performance balance principle evaluates the trade-offs between the various objective functions to avoid over-optimization of a single objective leading to severe deterioration of other objectives. The resource constraint principle ensures that the identified switching nodes are executable within the system resource constraints.

[0130] The actual implementation cost assessment comprehensively considers both direct and indirect costs of the switchover process. Direct costs include computational, storage, and communication overhead related to algorithm switching, while indirect costs include business interruption losses, increased system risk, and increased operational complexity. Cost quantification employs a cost model, converting various costs into a unified cost unit for comparison. The calculation formula uses a weighted summation method, with direct costs weighted at 0.6 and indirect costs at 0.4. This weighting reflects the controllability and quantifiability of direct costs.

[0131] The protection effectiveness assessment is based on attack simulation test results, with test scenarios including both known attack vectors and unknown attack patterns. Known attack vector tests utilize standard attack suites, including attack steps such as network scanning, vulnerability exploitation, privilege escalation, and data theft. Unknown attack pattern tests employ mutation attack techniques, randomly mutating attack parameters and execution sequences based on known attacks. The quantitative indicators of protection effectiveness include four dimensions: attack blocking rate, false positive rate, false negative rate, and response time. The attack blocking rate is required to reach 98% or higher, the false positive rate to be controlled below 2%, the false negative rate to be controlled below 1%, and the average response time to be controlled below 1 second.

[0132] The selection of non-dominated solutions employs the Pareto dominance relation: solution A dominates solution B if and only if solution A is not inferior to solution B on all objectives and is strictly superior to solution B on at least one objective. The selection process traverses all feature points, identifying solutions not dominated by any other solution as non-dominated solutions. The set of non-dominated solutions forms the Pareto front, with solutions on the front representing the optimal choice for different objective trade-offs. The Pareto front solution set stores attributes including solution coordinates, corresponding algorithm identifiers, performance metrics, and recommendation weights, supporting the sorting and selection of solutions according to different preferences.

[0133] In one optional implementation, cryptographic algorithm switching is performed by inserting a control frame carrying an algorithm negotiation payload at the semantic fragment boundary, collecting the results of session continuity disruption and algorithm migration integrity verification, and forming scheduling execution feedback including:

[0134] A control frame is constructed at the semantic segment boundary. The timing and position of the cut-in are determined by analyzing the data flow characteristics between the semantic segment boundary and the next semantic self-contained unit. The control frame is dynamically injected into the data flow based on the timing and position of the cut-in to trigger the switching of the cryptographic algorithm.

[0135] During the switching execution of the cryptographic algorithm, the continuity characteristics of the data stream are tracked based on the timing of the switch. By comparing and analyzing the data stream integrity and latency change trends at the switch position, and combining historical switching experience, the impact of the timing and position of the switch on the data stream is evaluated.

[0136] The migration integrity verification is performed on the switched cryptographic algorithm. A verification path is established based on the continuity characteristics of the data flow. By analyzing the verification effect of the verification path under different levels of influence, the rationality of the timing and location of the entry is continuously evaluated.

[0137] A thorough analysis of the correlation between the degree of impact and the verification effect is conducted, and scheduling execution feedback is generated by combining the evaluation results of the timing and location of the intervention.

[0138] Semantic fragmentation boundary identification is implemented through a data flow parsing module. This module is built on a layered protocol stack architecture and supports semantic analysis of multiple protocols, including HTTP, HTTPS, TCP, and UDP. A semantic fragmentation boundary is defined as the end position of a complete business logic unit. In HTTP, this corresponds to the end marker of a response message; in TCP, it corresponds to the boundary marker of a data segment; and in database protocols, it corresponds to the transaction commit point. The boundary identification algorithm uses a state machine pattern, maintaining three state variables: protocol parsing state, buffer management state, and boundary detection state. The protocol parsing state tracks the protocol type and parsing progress of the current data packet; the buffer management state controls the temporary storage and release of data; and the boundary detection state indicates whether the semantic fragmentation boundary has been reached.

[0139] The control frame is constructed using a standard frame format. The control frame header contains four basic fields: frame type, sequence number, payload length, and checksum. The frame type field occupies 2 bytes, with values ​​of 0x8001 indicating an algorithm switching control frame, 0x8002 indicating an algorithm negotiation request frame, and 0x8003 indicating an algorithm negotiation response frame. The sequence number field occupies 4 bytes and uses an incrementing sequence to ensure the order and uniqueness of the control frames. The payload length field occupies 2 bytes and indicates the number of bytes in the algorithm negotiation payload, ranging from 64 to 1024 bytes. The checksum field occupies 4 bytes and uses the CRC32 algorithm to calculate the checksum of the entire control frame.

[0140] The algorithm negotiation payload includes fields such as the current algorithm identifier, target algorithm identifier, switching timestamp, negotiation parameter set, and verification code. The current algorithm identifier occupies 4 bytes and uses a standard algorithm number: 0x0001 for AES-256, 0x0002 for SM4, and 0x0101 for RSA-2048. The target algorithm identifier occupies 4 bytes: 0x0201 for NTRU, 0x0202 for McEliece, and 0x0203 for Dilithium. The switching timestamp occupies 8 bytes and uses a UNIX timestamp format accurate to milliseconds. The negotiation parameter set uses TLV encoding format, with a 1-byte type field, a 2-byte length field, and a variable-length value field, supporting flexible configuration of parameters such as key length, encryption mode, and padding method. The verification code occupies 32 bytes and is generated using the HMAC-SHA256 algorithm to ensure the integrity and authenticity of the payload.

[0141] Data flow characteristic analysis is based on a sliding window statistical method, with the window size set to the most recent 100 data packets and the sliding step size set to 10 data packets. Characteristic indicators include four dimensions: data packet arrival interval, data packet size distribution, data flow rate variation, and protocol field characteristics. Data packet arrival intervals are statistically analyzed using four metrics: mean, standard deviation, maximum, and minimum. An average interval less than 10 milliseconds indicates a high-frequency data flow, while an average interval greater than 100 milliseconds indicates a low-frequency data flow. Data packet size distribution is analyzed using a histogram, divided into three intervals: small packets (below 128 bytes), medium packets (128 to 1024 bytes), and large packets (above 1024 bytes). Data flow rate is obtained by calculating the number of bytes transmitted per unit time; a rate change exceeding 50% indicates a sudden change in traffic.

[0142] The timing of the handover is determined based on data flow characteristic analysis and business logic constraints. The timing selection algorithm employs a multi-objective decision-making method. The objective function includes three optimization goals: minimizing business interruption, maximizing handover success rate, and minimizing resource consumption. Minimizing business interruption is achieved by analyzing the current business activity level, prioritizing time windows where activity is below a threshold of 0.3. The handover success rate is based on historical handover statistics, achieving a success rate as high as 95.8% during stable data flow periods, while dropping to 82.3% during periods of data flow fluctuation. Resource consumption assessment considers three resource dimensions: CPU utilization, memory usage, and network bandwidth usage, prioritizing handovers where the overall consumption is below 60% of system capacity.

[0143] The cutoff location is selected within the data stream gaps after the semantic fragmentation boundary. The gap detection algorithm analyzes the time intervals and protocol state transitions between consecutive data packets. Locations with time intervals exceeding 50 milliseconds and in an idle protocol state are marked as candidate cutoff locations. Location evaluation metrics include three aspects: data integrity risk, latency impact, and recovery difficulty. Data integrity risk is assessed by analyzing data dependencies before and after the cutoff location; locations with strong dependencies receive higher risk scores. Latency impact is calculated based on the expected execution time of the cutoff operation and the business's latency sensitivity. Recovery difficulty assessment considers the rollback complexity and data recovery cost after a switchover failure.

[0144] Dynamic control frame injection employs data stream injection technology. The injection module is deployed on critical nodes of the network link and possesses packet interception, modification, and forwarding capabilities. The injection process includes four steps: packet interception, control frame insertion, packet reassembly, and integrity verification. Packet interception is based on network filtering rules, which match fields such as source IP address, destination IP address, protocol type, and port number. Control frame insertion inserts the constructed control frame into the data stream at a determined cutoff point, using packet segmentation and reassembly techniques. Packet reassembly ensures that the data stream remains valid at the protocol level after the control frame is inserted. Integrity verification verifies the correctness of the data stream by recalculating protocol checksums.

[0145] The cryptographic algorithm switching trigger mechanism is based on the parsing and processing of control frames. Upon detecting an algorithm switching control frame, the receiving end initiates the switching process. The switching process comprises four stages: algorithm negotiation, key update, state transition, and functional verification. In the algorithm negotiation stage, the target algorithm identifier and negotiation parameters in the control frame payload are parsed, and the integrity and legitimacy of the payload are verified. In the key update stage, new key materials are generated or negotiated according to the requirements of the new algorithm. A secure random number generator is used for key generation, and the key length is determined according to the algorithm requirements. In the state transition stage, the operating state of the old algorithm is converted into a state format recognizable by the new algorithm. In the functional verification stage, encryption and decryption tests are performed to confirm that the new algorithm is working correctly.

[0146] Data flow continuity tracking is achieved through a real-time monitoring module deployed at key monitoring points of the data flow, collecting information such as packet sequence numbers, timestamps, sizes, and protocol status. Quantitative metrics for continuity characteristics include four aspects: packet loss rate, out-of-order rate, duplication rate, and latency jitter. The packet loss rate is calculated by dividing the number of lost packets by the total number of transmitted packets; under normal circumstances, the loss rate should be below 0.1%. The out-of-order rate is the proportion of packets arriving in a different order than they were sent; an out-of-order rate exceeding 1% indicates network transmission abnormalities. The duplication rate identifies repeated reception of packets with the same sequence number. Latency jitter is calculated as the standard deviation of the latency of consecutive data packets; jitter exceeding 10 milliseconds negatively impacts the real-time service experience.

[0147] The data flow integrity analysis at the ingress point employs packet-level integrity checks, covering 50 packets before and after the ingress point. Integrity checks include three levels: protocol field verification, data payload verification, and sequence continuity checks. Protocol field verification verifies protocol integrity fields such as IP header checksums, TCP header checksums, and UDP header checksums. Data payload verification performs CRC or hash checks on application layer data. Sequence continuity checks verify the continuity and increasing relationship of packet sequence numbers. Integrity scoring uses a 100-point scale, with protocol field verification accounting for 40 points, data payload verification for 35 points, and sequence continuity checks for 25 points. A total score of 90 or above indicates good integrity.

[0148] The latency trend analysis is based on time series analysis, with the analysis window set to a 5-minute time range before and after the cutoff point. Latency measurement employs end-to-end RTT measurement technology, achieving microsecond-level accuracy. The trend analysis algorithm uses the least squares method to fit a linear trend in latency changes; a positive slope indicates an increasing latency trend, while a negative slope indicates a decreasing latency trend. Trend strength is assessed by calculating the correlation coefficient of the fitted straight line; an absolute correlation coefficient greater than 0.8 indicates a significant trend. The latency variation magnitude is obtained by calculating the difference between the maximum and minimum latency; a variation exceeding 20% ​​of the average latency indicates significant latency fluctuation.

[0149] Historical handover experience extraction is based on statistical analysis of a handover operation database, which records key information such as handover time, entry location, impact level, and success status. The experience extraction algorithm employs association rule mining to identify the impact patterns of entry timing and location on handover success rate. Mining results show that the success rate of handovers during periods of low data flow activity is 12.5% ​​higher than during periods of high activity, and the success rate of handovers in protocol idle states is 8.3% higher than in data transmission states. The experience base includes three knowledge types: best practice patterns, failure case analysis, and parameter optimization suggestions. Best practice patterns summarize common characteristics of successful handovers, failure case analysis identifies the root causes of handover failures, and parameter optimization suggestions provide parameter tuning solutions for different scenarios.

[0150] The impact assessment employs a multi-dimensional comprehensive evaluation method, encompassing four dimensions: business continuity impact, data integrity impact, performance metric impact, and user experience impact. Business continuity impact is quantified by statistically analyzing the duration of business interruptions and error rates during the switchover process; interruptions exceeding 30 seconds or error rates exceeding 5% are considered high-impact. Data integrity impact is assessed based on the amount of data lost, the extent of data corruption, and the difficulty of data recovery. Performance metric impact considers indicators such as changes in response time, throughput reduction, and fluctuations in resource utilization. User experience impact is measured through indicators such as user access success rate, page load time, and interaction response latency.

[0151] Migration integrity verification establishes a multi-layered verification mechanism, encompassing four levels: algorithm functionality verification, data consistency verification, performance benchmark verification, and security strength verification. Algorithm functionality verification executes standard test vectors to verify the correctness of the new algorithm's encryption and decryption functions. Data consistency verification compares the data content before and after the switchover to ensure no data corruption or loss has occurred. Performance benchmark verification tests whether the new algorithm's performance under current load conditions meets business requirements. Security strength verification evaluates whether the security protection level provided by the new algorithm meets the expected strength.

[0152] The verification path is constructed based on the analysis results of the data flow continuity characteristics. The path design includes two types: forward verification paths and reverse verification paths. The forward verification path traces from the data source to the data endpoint, verifying the integrity of the entire data transmission link. The reverse verification path traces back from the data endpoint to the data source, confirming the correctness of the data processing process. Verification path nodes include key nodes such as data generation points, algorithm processing points, transmission relay points, and data consumption points. Each node has a verification checkpoint, which performs verification operations such as data validation, status verification, and timing checks.

[0153] The validation effectiveness analysis under different impact levels was conducted using a controlled experimental method. The experimental design included validation scenarios with three impact levels: low impact, medium impact, and high impact. Low impact scenarios corresponded to business interruption time of less than 10 seconds and a data integrity score of 95 or higher. Medium impact scenarios corresponded to interruption time of 10 to 30 seconds and an integrity score of 80 to 95. High impact scenarios corresponded to interruption time exceeding 30 seconds and an integrity score below 80. 100 validation tests were performed in each scenario, and performance indicators such as validation success rate, validation time, and validation accuracy were statistically analyzed.

[0154] The assessment of the timing and location of the handover is based on a comprehensive scoring method. The scoring model includes a weighting of success rate (0.4), impact level (0.3), resource consumption (0.2), and recovery difficulty (0.1). The success rate score is based on historical statistics of successful handovers, with a success rate of 95% or higher earning a perfect score of 100. The impact level score uses a reverse scoring method, with lower impact levels receiving higher scores. The resource consumption score considers the combined usage of CPU, memory, and network resources. The recovery difficulty score assesses the complexity and time cost of rolling back after a handover failure.

[0155] The correlation analysis combined correlation and regression analysis to examine the quantitative relationship between the degree of influence and the validation effect. Correlation analysis calculated the Pearson correlation coefficient between the two variables; a coefficient absolute value greater than 0.7 indicated a strong correlation. Regression analysis established a predictive model from the degree of influence to the validation effect. The model employed multiple linear regression, including three independent variables: degree of influence, timing of intervention, and location of intervention. Model training used 800 switching records from the most recent six months, and model validation employed a 10-fold cross-validation method, achieving an average prediction accuracy of 87.3%.

[0156] The scheduling execution feedback generates a comprehensive analysis based on the evaluation results of the switching timing and location. The feedback includes four parts: an execution status report, a summary of performance metrics, anomaly records, and optimization suggestions. The execution status report records key time points, execution results, and verification results during the switchover process. The performance metric summary provides statistical comparisons of performance before and after the switchover, including changes in response time, throughput, and error rate. The anomaly records detail any abnormal events that occurred during the switchover, their causes, and the corresponding handling measures. The optimization suggestions, based on the analysis of the current switchover effect, propose improvements such as timing optimization, location optimization, and parameter adjustment optimization.

[0157] In one optional implementation, migration integrity verification is performed on the switched cryptographic algorithm. A verification path is established based on the data flow continuity characteristics. By analyzing the verification effect of the verification path under different levels of influence, the rationality of the timing and location of the intervention is continuously evaluated, including:

[0158] The switched cryptographic algorithm is subjected to migration integrity verification. Temporal stability indicators and data integrity parameters are extracted based on the continuity characteristics of the data stream. A hierarchical verification mechanism with adaptive verification depth is constructed. The hierarchical verification mechanism determines the dynamic distribution strategy of verification nodes by analyzing the fluctuation characteristics, mutation patterns and evolution trends of the data stream during the switching process, combined with historical verification experience and discrete time series analysis.

[0159] A data flow trajectory prediction model is established based on the spatial distribution characteristics and temporal correlation patterns of the verification nodes. The data flow trajectory prediction model analyzes the sensitivity of the data flow continuity characteristics under different system loads and network states by training the historical evolution patterns of the temporal stability index and the data integrity parameter. Combined with the dynamic distribution strategy, the verification effect of the verification path during the switching process under different influence levels and disturbance conditions is evaluated. The prediction results of the data flow trajectory prediction model are used to continuously evaluate the rationality of the entry timing and entry position.

[0160] The integrity verification of the cryptographic algorithm migration is achieved by constructing a multi-layered verification framework, which includes three layers: an algorithm function verification layer, a data consistency verification layer, and a performance indicator verification layer. The algorithm function verification layer uses a standard test vector set to verify the functional correctness of the switched cryptographic algorithm. The test vector set covers core algorithm functions such as encryption / decryption, digital signatures, and hash calculation. The data consistency verification layer compares the integrity of the data content before and after the switch, using techniques such as hash verification, digital digest comparison, and data structure verification. The performance indicator verification layer evaluates the performance of the switched algorithm, including comparative analysis of key indicators such as computational latency, throughput, and resource consumption. The verification result is represented by a combination of Boolean values ​​and confidence levels. The Boolean value indicates whether the verification passed or failed, and the confidence level, ranging from 0 to 1, indicates the credibility of the verification result. A confidence level below 0.85 triggers a repeated verification process.

[0161] Data stream continuity feature extraction is based on real-time monitoring of the data stream's transmission status and content changes. The continuity feature quantification indicators include four dimensions: packet sequence continuity, timestamp increment, payload integrity, and protocol state consistency. Packet sequence continuity is achieved by detecting the incrementing relationship and gaps in sequence numbers. Under normal circumstances, sequence numbers strictly increment; gaps or reversals indicate impaired continuity. Timestamp increment verifies the monotonically increasing characteristic of packet timestamps; timestamp rollback or prolonged pauses indicate timing anomalies. Payload integrity uses CRC checksums or hash verification to ensure that the data content has not been corrupted or tampered with. Protocol state consistency checks the correct transitions of the protocol layer state machine; state jumps or illegal transitions indicate protocol anomalies.

[0162] The time series stability index is extracted based on time series analysis methods and includes four sub-indicators: mean stability, variance stability, trend stability, and periodic stability. Mean stability calculates the magnitude of change in the mean of the data stream within a sliding window; a change exceeding 10% of the baseline value indicates mean instability. Variance stability assesses changes in the dispersion of the data distribution; an increase in variance exceeding 50% indicates increased volatility. Trend stability identifies long-term trends in the data through linear regression analysis; an absolute value of the trend slope exceeding a threshold indicates trend instability. Periodic stability uses Fourier transform to identify the periodic characteristics of the data; a change in the dominant frequency component exceeding 15% indicates periodic instability. The overall time series stability score is calculated using a weighted average, with weights of 0.3, 0.25, 0.25, and 0.2 for the four sub-indicators, respectively.

[0163] Data integrity parameter extraction covers four core parameters: data loss rate, data corruption rate, data duplication rate, and data out-of-order rate. The data loss rate is calculated by dividing the number of lost data packets by the total number of data packets to be received; under normal operation, the loss rate should be below 0.01%. The data corruption rate is the proportion of data packets that fail verification; a corruption rate exceeding 0.001% indicates a degraded transmission quality. The data duplication rate identifies the proportion of repeatedly received data packets; a duplication rate exceeding 0.5% indicates network congestion or protocol anomalies. The data out-of-order rate is the proportion of out-of-order data packets; an out-of-order rate exceeding 1% affects data processing in upper-layer applications. Parameter calculations employ a sliding window statistical method, with a window size set to 1000 data packets and a sliding step size set to 100 data packets to ensure the timeliness and accuracy of the statistical results.

[0164] The layered verification mechanism employs a three-tiered progressive verification structure, comprising a fast verification layer, a standard verification layer, and a deep verification layer. The fast verification layer performs basic algorithm function testing and data format validation, with a verification time controlled within 10 seconds, primarily detecting obvious algorithm errors or data corruption. The standard verification layer performs comprehensive functional testing and performance evaluation, with a verification time controlled within 5 minutes, covering algorithm behavior verification under various input conditions. The deep verification layer performs stress testing and boundary condition verification, with a verification time that can be extended to 30 minutes, focusing on testing the algorithm's stability and security under extreme conditions. The adaptive adjustment of verification depth is based on the degree of data flow fluctuation and historical verification results; fast verification is used when the fluctuation level is low and the historical verification pass rate is high, while deep verification is used when the fluctuation level is high or there are many historical anomalies.

[0165] Data stream fluctuation characteristic analysis is achieved by analyzing the magnitude and frequency of changes in data stream indicators. Fluctuation characteristics are quantified into three dimensions: fluctuation intensity, fluctuation frequency, and fluctuation duration. Fluctuation intensity calculates the maximum deviation of the data stream indicator from the mean; an intensity exceeding 30% of the mean is defined as strong fluctuation, 10% to 30% as moderate fluctuation, and less than 10% as weak fluctuation. Fluctuation frequency counts the number of fluctuation events occurring per unit of time; a frequency exceeding 5 times per minute is considered high-frequency fluctuation. Fluctuation duration records the length of time from the start of a single fluctuation event to its return to normal; fluctuations lasting longer than 30 seconds require close monitoring. Fluctuation characteristics are used to adjust validation strategies; strong or high-frequency fluctuations increase validation frequency and depth.

[0166] The mutation pattern identification employs a change point detection algorithm, which uses the cumulative sum control chart principle to detect mutation points in the data sequence. The mutation detection control limit is set at three standard deviations; data points exceeding this limit are marked as suspected mutation points. Three or more consecutive suspected mutation points are confirmed as actual mutation events. Mutation pattern analysis includes three characteristic parameters: mutation magnitude, mutation direction, and mutation recovery time. Mutation magnitude quantifies the degree of change in data values ​​before and after the mutation; mutation direction indicates the direction of data increase or decrease; and mutation recovery time records the time it takes for the data to return to the normal range. Mutation patterns are used to predict abnormal changes in the data stream, guiding the selection of verification timing and the allocation of verification resources.

[0167] The trend analysis is based on a time series forecasting model, which uses the ARIMA autoregressive integral moving average method to predict the future trend of data stream indicators. The model parameters are configured with 3 autoregressive terms, 1 difference degree, and 2 moving average terms, optimized using the AIC information criterion based on historical data. The trend prediction time window is set to the next hour, and the prediction accuracy requirement is an average absolute percentage error of less than 15%. The prediction results include three output parameters: trend direction, rate of change, and confidence interval. The trend direction indicates whether the data stream indicator is growing or declining, the rate of change quantifies the steepness of the trend, and the confidence interval represents the range of uncertainty in the prediction results.

[0168] Historical verification experience extraction is based on data mining analysis of verification operation logs, which contain key information such as verification time, verification type, verification result, execution duration, and resource consumption. The experience extraction algorithm employs association rule mining to identify the correlation between verification success rate and data flow characteristics, verification configuration, and environmental conditions. The mining results form a verification experience knowledge base, which includes three categories of knowledge: best practice rules, failure mode identification, and parameter optimization suggestions. Best practice rules summarize the common characteristics of high-success-rate verification scenarios, failure mode identification summarizes typical causes of verification failure and preventive measures, and parameter optimization suggestions provide verification parameter configuration schemes for different scenarios.

[0169] Discrete-time series analysis employs digital signal processing techniques to perform frequency and time domain analysis on sampled data. Analysis algorithms include Fast Fourier Transform (FFT), autocorrelation function calculation, and power spectral density estimation. Time-domain analysis extracts statistical, trend, and periodic characteristics of the data, while frequency-domain analysis identifies the frequency components and spectral characteristics. Autocorrelation analysis assesses the intrinsic correlation and periodicity of the data sequence, and power spectral density analysis reveals the energy distribution characteristics of the data. The analysis results are used to identify regularities and anomalies in the data stream, guiding the placement of verification nodes and the formulation of verification strategies.

[0170] The dynamic distribution strategy for verification nodes is formulated based on data flow characteristic analysis results and historical verification experience. The strategy includes three aspects: node density adjustment, node location optimization, and node type selection. Node density is dynamically adjusted according to the volatility of the data flow; node density is increased in high-volatility areas to ensure sufficient verification, while node density is reduced in low-volatility areas to lower verification overhead. Node location optimization selects key change points in the data flow, protocol state transition points, and business logic boundary points as verification node locations. Node types are selected according to verification requirements, such as functional verification nodes, performance verification nodes, and security verification nodes. The distribution strategy employs a dynamic adjustment mechanism, continuously optimizing node configuration based on real-time data flow characteristics and verification performance feedback.

[0171] The data flow trajectory prediction model is built using machine learning methods. The model architecture employs a recurrent neural network (RNN) structure, consisting of an input layer, hidden layers, and an output layer. The input layer receives historical sequence data containing time-series stability indicators and data integrity parameters, with the input dimension set to a multivariate time series with 10 time steps. The hidden layer uses Long Short-Term Memory (LSTM) units, with 128 units, and the tanh activation function. The output layer predicts the data flow trajectory at future time points, with the output dimension corresponding to the predicted indicator values. Model training utilizes the backpropagation algorithm, with mean squared error as the loss function, the Adam algorithm as the optimizer, and a learning rate of 0.001.

[0172] The model training dataset is constructed based on historical data stream monitoring records, covering the most recent 6 months of operational data, with over 1 million records. Data preprocessing includes three steps: missing value imputation, outlier detection, and data normalization. Missing values ​​are imputed using linear interpolation, and outliers are identified using the 3-standard-deviation principle and replaced with the median. Data normalization uses maximum-minimum normalization to map the data to the 0-1 interval. The training and test sets are divided in an 8:2 ratio. An early stopping strategy is employed during training to prevent overfitting; training stops when the validation set loss does not decrease for 10 consecutive epochs.

[0173] Spatial distribution feature analysis identifies the distribution patterns of verification nodes in the data flow space using a clustering algorithm. The K-means clustering algorithm is employed, with a maximum of 5 clusters. Each cluster represents a set of verification nodes with similar characteristics, including node location, verification type, and historical performance. The clustering results are used to optimize the configuration and scheduling of verification nodes, allowing nodes with similar characteristics to share verification resources and experiential knowledge. Distribution features also include the connections and dependencies between nodes. Connections represent the execution order of the verification process, while dependencies represent the logical dependencies between verification results.

[0174] Temporal correlation analysis identifies the relationships between validation results at different time points using correlation analysis. The correlation is calculated using the Pearson correlation coefficient, with an absolute value greater than 0.7 indicating a strong correlation. Temporal correlation analysis includes two types: synchronous and asynchronous. Synchronous correlation represents the correlation between results from different validation nodes at the same time point, while asynchronous correlation represents the time-delayed correlation between validation results at different time points. Time-delayed correlation analysis uses the cross-correlation function to calculate the correlation coefficient under different time delays and identify the optimal time delay parameters. Correlation patterns are used to predict the propagation effect and cascading impact of validation results, guiding the temporal arrangement of validation strategies.

[0175] Sensitivity analysis assesses the responsiveness of data flow continuity to changes in load and network status. Sensitivity is quantified as a resilience coefficient, calculated as the percentage change in characteristic divided by the percentage change in load. A resilience coefficient greater than 1 indicates high sensitivity, where the magnitude of characteristic change is greater than the magnitude of load change. A resilience coefficient less than 1 indicates low sensitivity, where the characteristic is relatively stable. Sensitivity analysis includes four dimensions: CPU load sensitivity, memory load sensitivity, network bandwidth sensitivity, and network latency sensitivity. Different load levels are set for each dimension for sensitivity testing, including low load (20%), medium load (50%), and high load (80%).

[0176] The verification effectiveness evaluation is based on three core indicators: verification accuracy, verification completeness, and verification timeliness. Accuracy is calculated by dividing the number of correct verification results by the total number of verifications; completeness is calculated by dividing the number of nodes performing verifications by the planned number of verification nodes; and timeliness is calculated by dividing the number of verifications completed on time by the total number of verifications. The evaluation also considers performance differences under different levels of impact and disturbance conditions. Impact levels are categorized into three levels: minor, moderate, and severe. Disturbance conditions include external interference factors such as network jitter, sudden load changes, and resource contention.

[0177] The evaluation of the rationality of the entry timing and entry position is based on a comparative analysis of the prediction results of the data flow trajectory prediction model and the actual verification results. Rationality is quantified as a comprehensive score of prediction accuracy and verification success rate. Prediction accuracy is calculated as the average absolute percentage error between the predicted and actual values; an error of less than 10% is considered high accuracy. Verification success rate is calculated as the percentage of successful verifications; a success rate higher than 95% is considered high success rate. The comprehensive score is calculated using a weighted average, with prediction accuracy weighted at 0.4 and verification success rate weighted at 0.6. The evaluation results are used to continuously optimize the strategy for selecting entry timing and the algorithm for determining entry position.

[0178] A second aspect of the present invention provides a quantum-resistant dual-mode cryptographic algorithm switching system based on dynamic scheduling, comprising:

[0179] The acquisition module is used to acquire the operational characteristics of the cryptographic communication session, including the key lifecycle stage and the quantum computing capability evolution evaluation value; based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage, an evaluation result including the decay inflection point and the algorithm failure time boundary is obtained;

[0180] The determination module is used to determine a set of candidate switching algorithms from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms based on the evaluation results, and to calculate the expected value of resource overhead and the expected value of security gain for each candidate algorithm.

[0181] The mapping module is used to establish a dual-mode collaborative switching decision mechanism. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism.

[0182] The iterative module is used to perform cryptographic algorithm switching by inserting control frames carrying algorithm negotiation payloads at the semantic segmentation boundary, collect the verification results of session continuity disruption and algorithm migration integrity, form scheduling execution feedback, and use the scheduling execution feedback to iteratively correct the prediction parameters and the length of the reserved response interval.

[0183] A third aspect of the present invention provides an electronic device, comprising:

[0184] processor;

[0185] Memory used to store processor-executable instructions;

[0186] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0187] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0188] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0189] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for switching between quantum-resistant dual-mode cryptographic algorithms based on dynamic scheduling, characterized in that: include: The operational characteristics of cryptographic communication sessions are collected, including key lifecycle stages and quantum computing capability evolution assessment values. An analysis based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage yields an evaluation result that includes the decay inflection point and the algorithm failure time boundary, including: Establish a time-series correspondence matrix between the quantum computing capability evolution assessment value and the key life cycle stage. By mapping the growth trend of the quantum computing capability evolution assessment value in the time dimension to the advancement status of the key life cycle stage in the usage dimension on a time-by-time basis, a coupled evolution sequence of quantum threat intensity and key exposure degree is formed. Based on the coupled evolution sequence, the security margin value of the cryptographic algorithm at each time step is calculated. The gradient change rate analysis is performed on the time series curve formed by the security margin value. The turning point when the gradient change rate in the time series curve changes from a gradual change to a steep change is identified as the decay inflection point. The moment when the security margin value drops to the preset security boundary is identified as the algorithm failure time boundary. The decay inflection point and the algorithm failure time boundary are both included in the evaluation result. Based on the evaluation results, a set of candidate switching algorithms is determined from the heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms, and the expected value of resource overhead and security gain of each candidate algorithm is calculated. A dual-mode collaborative switching decision mechanism is established. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism. By inserting a control frame carrying the algorithm negotiation payload at the semantic segment boundary, the cryptographic algorithm is switched, the degree of session continuity disruption and the algorithm migration integrity verification results are collected, and the scheduling execution feedback is formed. The scheduling execution feedback is used to iteratively correct the prediction parameters and the length of the reserved response interval.

2. The method according to claim 1, characterized in that, By mapping the growth trend of the quantum computing capability evolution assessment value over time to the advancement status of the key lifecycle stage in the usage dimension on a time-by-time basis, a coupled evolutionary sequence of quantum threat strength and key exposure degree is formed, including: The quantum computing capability evolution assessment value is sampled over time to obtain the numerical change trajectory of the quantum computing capability evolution assessment value on a continuous time scale, and a trend fitting operation is performed on the numerical change trajectory to obtain the slope characteristics and acceleration characteristics of the growth trend. The key lifecycle stage is quantified by usage dimension, and the key lifecycle stage is divided into multiple evolution sub-stages associated with the number of times the key is used. Each evolution sub-stage is assigned a state weight value that represents the degree of accumulation of key exposure risk. A dual-axis mapping space of time scale and usage dimension is established. In the dual-axis mapping space, the time nodes corresponding to the slope feature and the acceleration feature are associated with the state weight value corresponding to each evolution sub-stage on a time-by-time basis. Based on the quantum computing capability at the time node, the state weight value is analyzed in a hierarchical and progressive manner and the historical cumulative influence is superimposed. Through multi-dimensional cross-validation and dynamic calibration, the coupling value at each time moment in the coupled evolution sequence is generated. The coupling values ​​at each time moment are arranged in chronological order to form the coupled evolution sequence.

3. The method according to claim 1, characterized in that, Based on the evaluation results, a set of candidate switching algorithms is determined from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms. The expected resource overhead and expected security gain of each candidate algorithm are calculated, including: The time window length between the decay inflection point and the algorithm failure time boundary is extracted from the evaluation results. Combined with the system operation trajectory, historical security event distribution characteristics and potential risk evolution patterns within the time window, a multi-dimensional comprehensive analysis is conducted to establish an urgency assessment standard and dynamically evaluate the current urgency level and security status of the system. Based on the urgency level and the security situation, candidate algorithms are selected from the heterogeneous algorithm pool. The effectiveness and limitations of various protective measures in historical security incidents under different urgency levels are analyzed in a targeted manner. Combined with the evolution law of potential risks, differentiated security protection requirements are determined to form a set of candidate switching algorithms. For each candidate algorithm in the candidate switching algorithm set, based on its resource utilization characteristics under different urgency levels and different load conditions, combined with the time window length and historical switching experience and lessons learned, the applicability of each candidate algorithm under the current security situation is comprehensively evaluated, and the expected value of resource overhead is determined. For each candidate algorithm in the candidate switching algorithm set, and in conjunction with the urgency level and security situation, we conduct an in-depth analysis of the dynamic changes in its security improvement effect under the current risk evolution pattern. We verify the actual protection capability of each candidate algorithm through historical switching effect evaluation data and determine the expected value of security gain.

4. The method according to claim 1, characterized in that, A dual-mode collaborative switching decision mechanism is established. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to a Pareto front solution set in a multi-objective constraint space, including: A reserved response interval is set before the algorithm failure time boundary. The system status within the reserved response interval is continuously monitored. Based on the system load fluctuation pattern and historical switching experience, the system resource utilization characteristics are extracted. The system operation status is evaluated by combining the business peak distribution and security event occurrence pattern. Based on the system operation status analysis, the execution effect of switching decisions under different response intervals is analyzed. The optimal response interval length is determined by combining historical data verification. The execution sequence and resource scheduling strategy of switching decisions are determined according to the optimal response interval length and the system resource utilization characteristics. Within the reserved response interval, a multi-objective constraint space is constructed based on the execution sequence and the resource scheduling strategy. Based on the system operation status, the expected value of resource overhead and the expected value of security gain for each candidate algorithm under different system load conditions and different security threat levels are calculated respectively. The calculation results are mapped to feature points in the multi-objective constraint space. By analyzing the distribution pattern of the feature points in the multi-objective constraint space, switching nodes are identified. The actual execution cost and protection effect of the switching scheme corresponding to each feature point are evaluated in combination with the system resource utilization characteristics. The set of non-dominated solutions that simultaneously satisfies the minimization of resource overhead and the maximization of security gain is selected to form the Pareto front solution set.

5. The method according to claim 1, characterized in that, Cryptographic algorithm switching is performed by inserting control frames carrying algorithm negotiation payloads at the semantic segmentation boundaries, collecting verification results of session continuity disruption and algorithm migration integrity, and forming scheduling execution feedback including: A control frame is constructed at the semantic segment boundary. The timing and position of the cut-in are determined by analyzing the data flow characteristics between the semantic segment boundary and the next semantic self-contained unit. The control frame is dynamically injected into the data flow based on the timing and position of the cut-in to trigger the switching of the cryptographic algorithm. During the switching execution of the cryptographic algorithm, the continuity characteristics of the data stream are tracked based on the timing of the switch. By comparing and analyzing the data stream integrity and latency change trends at the switch position, and combining historical switching experience, the impact of the timing and position of the switch on the data stream is evaluated. The migration integrity verification is performed on the switched cryptographic algorithm. A verification path is established based on the continuity characteristics of the data flow. By analyzing the verification effect of the verification path under different levels of influence, the rationality of the timing and location of the entry is continuously evaluated. A thorough analysis of the correlation between the degree of impact and the verification effect is conducted, and scheduling execution feedback is generated by combining the evaluation results of the timing and location of the intervention.

6. The method according to claim 5, characterized in that, Perform migration integrity verification on the switched cryptographic algorithm, establish a verification path based on the data flow continuity characteristics, and continuously evaluate the rationality of the timing and location of the intervention by analyzing the verification effect of the verification path under different levels of influence. The switched cryptographic algorithm is subjected to migration integrity verification. Temporal stability indicators and data integrity parameters are extracted based on the continuity characteristics of the data stream. A hierarchical verification mechanism with adaptive verification depth is constructed. The hierarchical verification mechanism determines the dynamic distribution strategy of verification nodes by analyzing the fluctuation characteristics, mutation patterns and evolution trends of the data stream during the switching process, combined with historical verification experience and discrete time series analysis. A data flow trajectory prediction model is established based on the spatial distribution characteristics and temporal correlation patterns of the verification nodes. The data flow trajectory prediction model analyzes the sensitivity of the data flow continuity characteristics under different system loads and network states by training the historical evolution patterns of the temporal stability index and the data integrity parameter. Combined with the dynamic distribution strategy, the verification effect of the verification path during the switching process under different influence levels and disturbance conditions is evaluated. The prediction results of the data flow trajectory prediction model are used to continuously evaluate the rationality of the entry timing and entry position.

7. A quantum-resistant dual-mode cryptographic algorithm switching system based on dynamic scheduling, used to implement the method of any one of claims 1-6, characterized in that, include: The acquisition module is used to acquire the operational characteristics of cryptographic communication sessions, including key lifecycle stages and quantum computing capability evolution evaluation values. An analysis was conducted based on the correspondence between the quantum computing capability evolution evaluation value and the key lifecycle stage to obtain an evaluation result that includes the decay inflection point and the algorithm failure time boundary. The determination module is used to determine a set of candidate switching algorithms from a heterogeneous algorithm pool consisting of national cryptographic algorithms and quantum-resistant cryptographic algorithms based on the evaluation results, and to calculate the expected value of resource overhead and the expected value of security gain for each candidate algorithm. The mapping module is used to establish a dual-mode collaborative switching decision mechanism. Within the reserved response interval before the algorithm failure time boundary, the expected value of resource overhead and the expected value of security gain are mapped to the Pareto front solution set of the multi-objective constraint space. The switching scheme is determined by combining the semantic fragmentation boundary of the session data stream, and a scheduling decision is generated based on the dual-mode collaborative switching decision mechanism. The iterative module is used to perform cryptographic algorithm switching by inserting control frames carrying algorithm negotiation payloads at the semantic segmentation boundary, collect the verification results of session continuity disruption and algorithm migration integrity, form scheduling execution feedback, and use the scheduling execution feedback to iteratively correct the prediction parameters and the length of the reserved response interval.

8. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data link security management and control system and method based on dynamic encryption

    CN120165965A

  • Anti-quantum cryptography migration method and system for power system

    CN121173467A