Quantum cryptographic operation method, storage medium and PQC password card
By configuring the working mode and security level in the cryptographic card, the quantum cryptographic operation method solves the problem of the single operating mode in the existing technology, realizes quantum cryptographic operation applicable to multiple scenarios, and improves system efficiency and security.
Patent Information
- Application Number
- CN202411033692.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-30
- Publication Date
- 2026-02-06
AI Technical Summary
Existing cryptographic card products have a single operating mode and limited application scenarios, making them unable to effectively resist cracking by quantum computers.
A quantum cryptography method is provided, which receives configuration instructions from the data processing module through a register, configures the working mode and security level, reads a random number sequence from DDR to generate a key, and stores it in DDR. This method supports quantum cryptography operations in various application scenarios.
It enables the configuration of working modes and security levels according to user needs, meeting the quantum cryptography operation requirements of various application scenarios and improving system efficiency and security.
Smart Images

Figure CN121485906A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cryptographic card technology, and in particular to a quantum cryptography method, a storage medium, and a PQC cryptographic card. Background Technology
[0002] Information security is a comprehensive interdisciplinary field, broadly encompassing mathematics, cryptography, computer science, communications, control engineering, artificial intelligence, security engineering, and the humanities, among others. It has been a rapidly developing and popular area of study in recent years. With the advancement of information technology, while enjoying the immense benefits of information resources, people also face the severe challenge of information security. Information security issues are becoming increasingly prominent, and various security applications based on cryptographic principles are becoming more widespread. Data encryption has penetrated every corner of information applications. To date, cryptographic technology remains the most effective method for achieving information security and is a core technology of information security. Through data encryption, people can effectively ensure that the content on communication lines is not leaked and can also verify the integrity of transmitted information.
[0003] However, with the rapid development of quantum computing technology, traditional cryptographic techniques will no longer be unbreakable, as quantum computers can easily crack traditional passwords. To address this crisis, a new research direction has emerged in cryptography: Post-Quantum Cryptography (PQC). As the name suggests, this refers to cryptography used after quantum computers are introduced, a type of cryptography that can resist being cracked by quantum computers. Currently, there are many cryptographic card products on the market, but their operating modes are relatively simple, and their application scenarios are limited.
[0004] Therefore, proposing a cryptographic operation method that can be applied to various application scenarios and resisted by quantum computers has become an urgent problem to be solved in this field. Summary of the Invention
[0005] The purpose of this invention is to provide a quantum cryptography operation method, storage medium, and PQC cryptographic card to solve the problems of limited operation mode and application scenarios of existing cryptographic card products. This application can meet the needs of different users.
[0006] The first aspect of this application provides a quantum cryptography method applied to a cryptographic core group in a PQC cryptographic card, wherein the PQC cryptographic card further includes a DDR and a data processing module communicatively connected to the cryptographic core group, and the method includes:
[0007] The configuration instructions sent by the data processing module are received through the register;
[0008] Configure the operating mode and security level in response to the configuration instructions;
[0009] After configuration, in response to the running command sent by the data processing module, the system reads a random number sequence from the DDR, performs quantum cryptography to generate a key, and stores the key in the DDR.
[0010] Optionally, before receiving the configuration instruction sent by the data processing module through the register, the method described above may further include:
[0011] The working status of the cryptographic operation core group is obtained and the working status is sent to the data processing module.
[0012] Optionally, the configuration instructions sent by the data processing module can be received via a register, as described above:
[0013] The data processing module obtains the working status of each of the cryptographic operation core groups;
[0014] When the cryptographic operation core group is in an idle state, the data processing module sends the configuration instruction through the register.
[0015] The cryptographic operation core group receives configuration instructions sent by the data processing module through a register.
[0016] Optionally, in the method described above, the cryptographic core group and the DDR are connected via a DMA controller for communication. The method further includes:
[0017] The data processing module determines whether the DMA controller is enabled.
[0018] Optionally, as described above, when the DMA controller is enabled, reading a random number sequence from the DDR to perform quantum cryptography to generate a key, and storing the key in the DDR, includes:
[0019] The DMA controller reads a random number sequence from the DDR and stores it in the RAM of the cryptographic core group;
[0020] The random number sequence is obtained from the RAM, quantum cryptography is performed to generate a key, and the key is stored in the RAM;
[0021] The key is read from the RAM and stored in the DDR via the DMA controller.
[0022] Optionally, prior to reading the random number sequence from the DDR via the DMA controller and storing it in the RAM of the cryptographic core group, and reading the key from the RAM and storing it in the DDR via the DMA controller, the method further includes:
[0023] The data processing module sends the address information of the DDR to the DMA controller;
[0024] The DMA controller responds to the cryptographic core group's reading and storage of the DDR based on the address information.
[0025] As described above, optionally, the number of cryptographic operation core groups is multiple, and the PQC cryptographic card further includes a DMA arbitration module located in the same chip as the cryptographic operation core groups, and each of the cryptographic operation core groups is connected to the DMA controller through the DMA arbitration module;
[0026] Reading a random number sequence from the DDR and storing it in the RAM of the cryptographic core group includes:
[0027] The DMA arbitration module arbitrates the acquisition requests of multiple cryptographic operation core groups, and the cryptographic operation core groups read the random number sequence according to the arbitration result;
[0028] The cryptographic core group reads the key from the RAM and stores it in the DDR, including:
[0029] The DMA arbitration module arbitrates the storage requests of multiple cryptographic operation core groups, and the cryptographic operation core groups store the key in the DDR according to the arbitration result.
[0030] Optionally, the method described above can be used when the DMA controller is off;
[0031] Reading a random number sequence from the DDR, performing quantum cryptography to generate a key, and storing the key in the DDR includes:
[0032] The data processing module reads a random number sequence from the DDR and stores it in the RAM of the cryptographic core group through the register;
[0033] The cryptographic operation core group obtains the random number sequence from the RAM, performs quantum cryptographic operations to generate a key, and stores the key in the RAM;
[0034] The data processing module reads the key from the RAM through the register and stores it in the DDR.
[0035] A second aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in any one of the first aspects above.
[0036] The third aspect of this application provides a PQC cryptographic card, characterized in that it performs quantum cryptographic operations using the method described in any one of the first aspects.
[0037] Compared with the prior art, the cryptographic operation core group and the data processing module of this application are connected through the on-chip register bus. The core group receives the configuration instructions sent by the data processing module and responds to the configuration instructions to configure the working mode and security level. The core group is configured according to different user needs to meet different quantum cryptographic operation requirements. After the configuration is completed, the core group reads the random number sequence from the DDR to perform quantum cryptographic operation to generate the key and stores the key in the DDR. Attached Figure Description
[0038] Figure 1 This embodiment provides a schematic diagram of the composition of a cryptographic operation system. Figure 1 ;
[0039] Figure 2 This is a flowchart illustrating a quantum cryptography operation method provided in this embodiment;
[0040] Figure 3 This embodiment provides a flowchart illustrating how a configuration instruction sent by a data processing module is received via a register.
[0041] Figure 4 This embodiment provides a schematic diagram of the composition of a cryptographic operation system. Figure 2 ;
[0042] Figure 5 This embodiment provides a schematic diagram of the operation flow of the cryptographic operation core group when the DMA controller is enabled;
[0043] Figure 6 This embodiment provides a schematic diagram of the composition of a cryptographic operation system. Figure 3 ;
[0044] Figure 7 This embodiment provides a schematic diagram of the process before a cryptographic core group performs quantum cryptographic operations.
[0045] Figure 8 This embodiment provides a schematic diagram of the operation flow of the cryptographic operation core group when the DMA controller is turned off;
[0046] Figure 9 This is a schematic diagram of the composition of a PQC cryptographic card provided in this embodiment. Detailed Implementation
[0047] The following detailed description is illustrative only and is not intended to limit the embodiments and / or their application or use. Furthermore, it is not intended to be construed as being bound by any express or implied information presented in the preceding "Background Art" or "Summary of the Invention" or "Detailed Description" sections.
[0048] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, one or more embodiments are now described with reference to the accompanying drawings, wherein similar reference numerals are used throughout the text to refer to similar components. In the following description, numerous specific details are set forth for purposes of explanation in order to provide a more thorough understanding of one or more embodiments. However, it will be apparent that one or more embodiments may be practiced in various circumstances without these specific details, and the various embodiments may be combined with and referenced to each other without contradiction.
[0049] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0050] The cryptographic operation system in this embodiment is applied to a PQC cryptographic card to perform quantum cryptographic operations. The quantum cryptographic operation system uses a chip as the core chip to perform quantum cryptographic operations, such as a ZYNQ chip. Corresponding functional modules are set up within the chip to perform the operations. In addition, a DDR (Double Data Rate) is set up externally for storage. The quantum cryptographic operation includes quantum cryptographic encryption and quantum cryptographic decryption. The user encrypts information using a key during the quantum cryptographic encryption operation, and the quantum cryptographic decryption operation is used to decrypt the encrypted information.
[0051] As attached Figure 1As shown in the illustration, this application provides a cryptographic operation system applied to a PQC cryptographic card. The cryptographic operation system includes a data processing module and a cryptographic operation core group connected within the chip, as well as external DDR. For example, the chip includes a PS (Processing System) section and a PL (Programmable Logic) section. The PS section corresponds to the data processing module and can connect to the user terminal to receive quantum encryption operation requests from the user. The PL section has programmable logic corresponding to the cryptographic operation core group, which can be edited to achieve quantum encryption operations for different needs. Furthermore, the data processing module and the cryptographic operation core group are connected via registers within the chip, and the data processing module accesses and configures the cryptographic operation core group through the registers.
[0052] The data processing module is used to acquire several sets of random number sequences and user-preset operation parameters. The random number sequences are used by the cryptographic operation core group to perform quantum encryption operations, while the preset operation parameters are used to configure the cryptographic operation core group. The corresponding operation parameters are set according to different user needs, and the cryptographic operation core group is configured according to the operation parameters to perform quantum encryption operations that meet the user's needs.
[0053] There can be multiple cryptographic core groups, which can perform quantum cryptographic operations using a single algorithm, or each group can use a different algorithm. For example, the multiple cryptographic core groups include a first cryptographic core group and a second cryptographic core group, which run different algorithms.
[0054] Specifically, the first cryptographic core group is used to process the Kyber algorithm, and the second cryptographic core group is used to process the Dilithium algorithm. Both the Kyber and Dilithium algorithms are post-quantum cryptographic algorithms from NIST, used for key encapsulation and key negotiation, and are used in many network security and encryption applications. Employing two cryptographic core groups to perform quantum cryptographic operations improves the level of security.
[0055] based on Figure 1 cryptographic systems, such as Figure 2 As shown, this embodiment provides a quantum cryptography method applied to a cryptographic core group in a PQC cryptographic card. The PQC cryptographic card also includes a DDR and a data processing module that are communicatively connected to the cryptographic core group. The method includes the following steps.
[0056] Step S10: Receive configuration instructions sent by the data processing module through the register.
[0057] In this embodiment, the cryptographic operation core group needs to be configured with corresponding operating modes and operation security levels according to different user needs when performing quantum cryptographic operations. Specifically, the operation security level is the security level of the operating mode of the cryptographic operation core group, for example, it is divided into three levels (1v2, 1v3, 1v4). The security level affects the amount of input and output data of each unit in the cryptographic operation core group described above, and needs to be configured by the user. Before starting the operating mode of the cryptographic operation core group, the data processing module will send the operation security level to the cryptographic operation core group through the register. The operating mode needs to be configured by the user. The cryptographic operation core group configures its internal units through the register. A data processing module can only be in one mode at a time, and can only be reconfigured after the mode is completed.
[0058] Therefore, when the cryptographic operation system performs quantum cryptographic operations, the data processing module first receives the user's quantum cryptographic operation request, then determines the working mode and security level of each operation performed by the cryptographic operation core group according to the request, and sends the configuration instructions to the cryptographic operation core group through the register.
[0059] Step S20: Response configuration command to configure working mode and security level.
[0060] After the data processing module sends the configuration instructions to the cryptographic operation core group through the register, the cryptographic operation core group is configured according to the working mode and security level in the configuration instructions, and can then perform specific quantum cryptographic operations based on the received input data after the configuration is completed.
[0061] Step S30: After configuration, respond to the run command sent by the data processing module, read the random number sequence from DDR, perform quantum cryptography operation, and store the key in DDR.
[0062] In addition, several sets of random number sequences and the keys of the cryptographic operation core group are stored in DDR. When the data processing module receives several sets of random number sequences required for a quantum cryptographic operation task, it stores the random number sequences in DDR. When the cryptographic operation core group is configured according to the configuration instructions, it will respond to the run instructions sent by the data processing module, read the random number sequences from DDR and perform quantum cryptographic operations to generate keys; the keys of the cryptographic operation core group are also stored in DDR.
[0063] Furthermore, the cryptographic operation system also includes an external random number sequence generation module for generating several sets of random number sequences. For example, in the embodiments of this application, the random number sequence generation module employs a quantum random number sequence generator, which not only occupies on-chip storage memory but is also applicable to the quantum realm.
[0064] Quantum random number sequence generators are mainly divided into two categories based on the random source: discrete and continuous. The earliest research focused on discrete quantum random number sequence generators, which primarily utilize (quasi-)single-photon sources, entangled photon pairs, and other signals as carriers of random variables. This approach is simple and clear in principle and exhibits significant quantum randomness. In contrast, continuous quantum random number sequence generators often employ laser phase noise, amplified spontaneous emission noise, and vacuum shot noise as random sources. The quantum random number sequence generator used in this application is a continuous quantum random number sequence generator, specifically the QRNG10SPI.
[0065] In this application, the cryptographic operation core group and the data processing module are connected via an on-chip register bus. The core group receives configuration instructions sent by the data processing module and responds to the configuration instructions to configure the working mode and security level. It performs corresponding configurations according to different user needs to meet different quantum cryptographic operation requirements. After the configuration is completed, it reads a random number sequence from the DDR to perform quantum cryptographic operations to generate a key and stores the key in the DDR.
[0066] Before receiving configuration instructions from the data processing module via the register, the method further includes: obtaining the working status of the cryptographic operation core group and sending the working status to the data processing module. Specifically, such as... Figure 3 As shown, receiving configuration instructions sent by the data processing module through the register includes the following steps.
[0067] Step S101: The data processing module obtains the working status of each cryptographic operation core group.
[0068] Step S102: When the cryptographic operation core group is in an idle state, the data processing module sends a configuration instruction through the register.
[0069] Step S103: Each cryptographic operation core group receives the configuration instructions sent by the data processing module through the register.
[0070] In this embodiment, there can be multiple cryptographic operation core groups. Multiple cryptographic operation core groups can execute multiple quantum cryptographic operation tasks in parallel. Before the data processing module receives the quantum cryptographic operation task to be executed and sends it to the cryptographic operation core group, it obtains the working status of the cryptographic operation core group and sends the working status to the data processing module so that the data processing module can know whether each cryptographic operation core group is currently in a working state or an idle state. When the working state of the cryptographic operation core group is an idle state, it sends a configuration instruction through the register.
[0071] The cryptographic operation core group operates in two states: one where it reads random number sequences from the DDR and performs quantum cryptographic operations; and another where it is idle and ready to execute the next quantum cryptographic operation task, either when it is not performing any quantum cryptographic operations or when the quantum cryptographic operation has been completed and the key has been stored in the DDR. Configuration commands are sent based on the obtained operating state to control the cryptographic operation core group in executing quantum cryptographic operations, thus avoiding quantum cryptographic task conflicts and improving execution efficiency.
[0072] like Figure 4 The cryptographic operation system shown communicates with the DDR via a DMA controller. The DMA controller is a functional module within the ZYNQ chip. DMA is a control method where grouped information transfer is entirely handled by the chip's soft core, offering advantages over interrupt-driven methods. During the data preparation phase, the CPU (the chip's data processing module) and peripherals (such as the DDR) work in parallel. DMA establishes a "direct data path" between the DDR and the cryptographic operation core, eliminating the need for data transfer through the data processing module and thus avoiding cumbersome operations such as protecting and restoring the CPU's context.
[0073] As mentioned above, DMA controllers are characterized by program interrupts. Therefore, the aforementioned quantum cryptography method also includes: the data processing module determining whether the DMA controller is enabled. Since DMA data transfer does not require CPU intervention, it avoids interrupting the current program. I / O and host operations run in parallel, and program and data transfer operations run concurrently, making it suitable for high-speed devices transferring large amounts of data, although the hardware overhead is relatively high. Using a DMA controller can accelerate data transfer between the DDR and the data processing module, improving system efficiency. DMA requires preprocessing via a program before transfer begins and post-processing via an interrupt after transfer.
[0074] like Figure 5 As shown, when the DMA controller is enabled, a random number sequence is read from the DDR to perform quantum cryptography to generate a key, and the key is stored in the DDR, including the following steps.
[0075] Step S310: Read the random number sequence from DDR through the DMA controller and store it into the RAM of the cryptographic operation core group.
[0076] Step S320: Obtain a random number sequence from RAM, perform quantum cryptography to generate a key, and store the key in RAM.
[0077] Step S330: Read the key from RAM and store it in DDR via the DMA controller.
[0078] like Figure 6As shown, the top layer of the cryptographic operation core group includes several cryptographic operation core groups and RAM connected by communication. The cryptographic operation core groups are used to perform quantum cryptographic operation tasks according to the random number sequence, while the RAM is used to store data or information. In this embodiment, the RAM is used not only to store the random number sequence required for each quantum cryptographic operation task, but also to store the key for each quantum cryptographic operation.
[0079] When an algorithm core in the cryptographic core group needs to perform a quantum cryptographic operation task, it reads the corresponding random number sequence from DDR and loads it into RAM via the DMA controller. After loading, the algorithm core reads the corresponding random number sequence from RAM via the DMA bus and then executes the corresponding quantum cryptographic operation task according to the configured working mode and operation security level. After the algorithm core completes the operation, it writes the key into RAM, and then writes the key from RAM into DDR via the DMA controller, thus realizing the reading and writing of input data (random number sequence) and output result (key) of the cryptographic core group.
[0080] Specifically, the data read from DDR is collectively referred to as the input data required for the operation of the cryptographic operation core. This input data depends on the stage of the algorithm core's operation and is not limited to random number sequences, but also includes public keys, private keys, plaintext, challenge codes, etc. The data written to DDR is collectively referred to as the output results of the algorithm core's operation. This also depends on the stage of the algorithm core's operation and is not limited to keys, but also includes public keys, private keys, encapsulated keys, decapsulated keys, etc.
[0081] like Figure 7 As shown, before reading the random number sequence from the DDR via the DMA controller and storing it in the RAM of the cryptographic core group, and before reading the key from the RAM and storing it in the DDR via the DMA controller, the method further includes the following steps.
[0082] Step S301: The data processing module sends the DDR address information to the DMA controller.
[0083] Step S302: The DMA controller responds to the cryptographic operation core group's reading and storage of DDR based on the address information.
[0084] The DDR contains address information, with each address storing corresponding data. When the cryptographic core group transmits data to the DDR through the DMA controller, it needs to determine the starting address and data size information in the DDR. This information is sent to the DMA controller by the data processing module according to different quantum cryptography tasks. When the cryptographic core group needs to read a random number sequence or store a key from the DDR through the DMA controller, the DMA controller responds to the cryptographic core group's read and store operations on the DDR based on the address information.
[0085] Continue as Figure 6 As shown, there are multiple cryptographic operation core groups. The PQC cryptographic card also includes a DMA arbitration module located in the same chip as the cryptographic operation core groups. All the operation cores are connected to the DMA controller through the DMA arbitration module.
[0086] The process of reading a random number sequence from DDR and storing it in the RAM of the cryptographic operation core group includes: a DMA arbitration module arbitrating multiple requests for access from the cryptographic operation core group, and the cryptographic operation core group reading the random number sequence based on the arbitration result.
[0087] The cryptographic operation core group reads the key from RAM and stores it to DDR via DMA, including: the DMA arbitration module arbitrates the storage requests of multiple cryptographic operation core groups, and the cryptographic operation core group stores the key to DDR according to the arbitration result.
[0088] Specifically, when arbitrating the reading and writing of random number sequences and keys, the DMA arbitration module arbitrates based on the priority of the cryptographic operation core group and the priority of the quantum cryptographic operation tasks performed by the cryptographic operation core group, and determines the algorithm core that communicates with the DMA controller and DDR first, thus avoiding data interaction and conflicts between multiple cryptographic operation core groups.
[0089] Furthermore, during arbitration, the DMA arbitration module arbitrates all input data read from DDR and output results written to DDR as described above, based on the priority of the quantum cryptography task.
[0090] The above embodiments provide a method for reading a random number sequence from DDR to perform quantum cryptographic operations and storing the key in DDR when the DMA controller is working, such as... Figure 8 As shown, as another implementation, when the DMA controller is off, a random number sequence is read from the DDR to perform quantum cryptography to generate a key, and the key is stored in the DDR, including the following steps.
[0091] Step S311: The data processing module reads the random number sequence from DDR and stores it in the RAM of the cryptographic operation core group through a register.
[0092] Step S321: The cryptographic operation core group obtains a random number sequence from RAM, performs quantum cryptographic operations to generate a key, and stores the key in RAM.
[0093] Step S331: The data processing module reads the key from RAM through the register and stores it in DDR by DMA.
[0094] Specifically, the DMA controller is used for data transmission (random number sequence and key) between the cryptographic core group and the DDR. When the DMA controller is not working, the data transmission link between the cryptographic core group and the DDR is interrupted. The data processing module can be used to transmit the input data and output results of the cryptographic core group.
[0095] For example, the data processing module can not only access and configure the cryptographic cores through registers, but also write several sets of random number sequences into several cryptographic cores. The data processing module directly writes the random number sequences into RAM, and then reads and writes them into the cryptographic cores through RAM to perform quantum cryptography operations to generate keys. After the cryptographic cores complete their operations, they store the keys in RAM, and then the data processing module writes them into DDR.
[0096] It should be added that the aforementioned register access operation state when the DMA controller is off serves two purposes: firstly, to verify the normal operation of the cryptographic core's algorithm, and secondly, as an alternative way to access the cryptographic core in case of DDR failure. This register access method of the cryptographic core's RAM is slightly less efficient than transfer via the DMA controller. Therefore, during normal operation of the cryptographic system, the transfer method with the DMA controller on is typically used.
[0097] Based on the same concept, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the methods described above.
[0098] Based on the same concept, this application also provides a PQC cryptographic card, such as... Figure 9 As shown, the system includes an ARM processor for user authentication, key management, and file management; an FPGA communicating with the ARM processor, which contains a data processing module and a cryptographic core group, which performs quantum cryptographic operations using any of the methods described above; and two noise sources communicating with the FPGA to provide random number sequences to the FPGA and the cryptographic algorithm chip.
[0099] In this embodiment, the post-quantum cryptography algorithm is implemented directly using an FPGA. Furthermore, the solution in this application is a pure bare-metal development that does not involve an embedded operating system, resulting in low resource consumption and theoretically faster pipeline operation.
[0100] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0101] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0102] The above description, based on the embodiments shown in the figures, details the structure, features, and effects of the present invention. The above description is only a preferred embodiment of the present invention, but the present invention is not limited to the scope of implementation shown in the figures. Any changes made in accordance with the concept of the present invention, or equivalent embodiments modified to have equivalent changes, that do not exceed the spirit covered by the specification and figures, should be within the protection scope of the present invention.
Claims
1. A quantum cryptography method applied to a cryptographic core group in a PQC cryptographic card, wherein the PQC cryptographic card further includes a DDR and a data processing module communicatively connected to the cryptographic core group, characterized in that, The method includes: The configuration instructions sent by the data processing module are received through the register; Configure the operating mode and security level in response to the configuration instructions; After configuration, in response to the running command sent by the data processing module, the system reads a random number sequence from the DDR, performs quantum cryptography to generate a key, and stores the key in the DDR.
2. The method as described in claim 1, characterized in that, Before receiving the configuration instructions sent by the data processing module through the register, the method further includes: The working status of the cryptographic operation core group is obtained and the working status is sent to the data processing module.
3. The method as described in claim 2, characterized in that, The configuration instructions sent by the data processing module are received through the register, including: The data processing module obtains the working status of each of the cryptographic operation core groups; When the cryptographic operation core group is in an idle state, the data processing module sends the configuration instruction through the register. The cryptographic operation core group receives configuration instructions sent by the data processing module through a register.
4. The method as described in claim 1, characterized in that, The cryptographic core group and the DDR are connected via a DMA controller for communication, and the method further includes: The data processing module determines whether the DMA controller is enabled.
5. The method as described in claim 4, characterized in that, When the DMA controller is enabled, a random number sequence is read from the DDR to perform quantum cryptography to generate a key, and the key is stored in the DDR, including: The DMA controller reads a random number sequence from the DDR and stores it in the RAM of the cryptographic core group; The random number sequence is obtained from the RAM, quantum cryptography is performed to generate a key, and the key is stored in the RAM; The key is read from the RAM and stored in the DDR via the DMA controller.
6. The method as described in claim 5, characterized in that, Before reading the random number sequence from the DDR via the DMA controller and storing it in the RAM of the cryptographic core group, and before reading the key from the RAM and storing it in the DDR via the DMA controller, the method further includes: The data processing module sends the address information of the DDR to the DMA controller; The DMA controller responds to the cryptographic core group's reading and storage of the DDR based on the address information.
7. The method as described in claim 4, characterized in that, The number of cryptographic operation core groups is multiple, and the PQC cryptographic card also includes a DMA arbitration module located in the same chip as the cryptographic operation core groups. Each cryptographic operation core group is connected to the DMA controller through the DMA arbitration module. Reading a random number sequence from the DDR and storing it in the RAM of the cryptographic core group includes: The DMA arbitration module arbitrates the acquisition requests of multiple cryptographic operation core groups, and the cryptographic operation core groups read the random number sequence according to the arbitration result; The cryptographic core group reads the key from the RAM and stores it in the DDR, including: The DMA arbitration module arbitrates the storage requests of multiple cryptographic operation core groups, and the cryptographic operation core groups store the key in the DDR according to the arbitration result.
8. The method as described in claim 4, characterized in that, When the DMA controller is off; Reading a random number sequence from the DDR, performing quantum cryptography to generate a key, and storing the key in the DDR includes: The data processing module reads a random number sequence from the DDR and stores it in the RAM of the cryptographic core group through the register; The cryptographic operation core group obtains the random number sequence from the RAM, performs quantum cryptographic operations to generate a key, and stores the key in the RAM; The data processing module reads the key from the RAM through the register and stores it in the DDR.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method described in any one of claims 1-8.
10. A PQC cryptographic card, characterized in that, Quantum cryptography is performed using the method described in any one of claims 1-8.