Lightweight quantum-resistant key agreement protocol method and system for edge computing

By generating identity-binding public keys and lightweight session keys using lattice cryptography, the quantum computing threat and resource constraints of key negotiation protocols in edge computing environments are resolved, achieving secure and efficient key negotiation.

CN121485935BActive Publication Date: 2026-04-21BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING CATHAY INTERNET INFORMATION TECH CO LTD
Filing Date
2026-01-06
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In edge computing environments, existing key negotiation protocols face challenges such as quantum computing threats, limited computing power, and resource constraints, making it difficult to establish secure and efficient key negotiation mechanisms.

Method used

Short vector private keys are generated using lattice cryptography, public key multinomial matrices are generated through modular arithmetic, identity binding public keys are generated by combining the hardware physical address of edge nodes and collision-resistant hashing, and lightweight session keys are generated using dynamic lattice base chains and resource weight vectors, achieving quantum resistance and efficient key negotiation.

Benefits of technology

It improves the security and efficiency of the key negotiation process, reduces the computational burden and communication overhead of resource-constrained devices, and is suitable for edge computing scenarios with limited computing resources and network bandwidth.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121485935B_ABST
    Figure CN121485935B_ABST
Patent Text Reader

Abstract

This invention provides a lightweight quantum-resistant key negotiation protocol method and system for edge computing, relating to the field of edge computing security technology. The method includes generating a short vector private key and a public key multinomial matrix based on lattice cryptographic parameters, embedding an identity digest vector into the public key to form an identity-binding public key, generating a dynamic lattice basis chain through recursive reconstruction, and adaptively sparsifying the session parameters using a resource weight vector to finally generate a lightweight session key. This method is resistant to quantum attacks and can be dynamically adjusted according to the computing performance and communication bandwidth of edge nodes, reducing resource consumption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of edge computing security technology, and in particular to a lightweight quantum-resistant key negotiation protocol method and system for edge computing. Background Technology

[0002] With the rapid development of the Internet of Things (IoT) and edge computing, a large number of data processing and computing tasks are shifting from the cloud to edge nodes, highlighting the increasing importance of secure communication in edge computing environments. Particularly on resource-constrained edge devices, establishing a secure and efficient key negotiation mechanism has become a key challenge for ensuring edge computing security. Traditional key negotiation protocols are mostly based on classical cryptographic algorithms such as RSA and ECC, which face security threats in the context of the rapid development of quantum computing technology. At the same time, the limited computing power and energy constraints of edge devices place higher demands on the lightweight and efficiency of key negotiation protocols. Summary of the Invention

[0003] The embodiments of the present invention provide a lightweight quantum-resistant key negotiation protocol method and system for edge computing, which can solve the problems in the prior art.

[0004] A first aspect of the present invention provides a lightweight quantum-resistant key negotiation protocol method for edge computing, comprising:

[0005] Obtain the identity information and cipher parameters of the edge nodes;

[0006] Based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations, and a public key polynomial matrix is ​​generated on the modular arithmetic ring using the short vector private key.

[0007] Extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain the identity digest vector. Embed the identity digest vector bitwise into the public key multinomial matrix, fuse them through modular addition to generate the identity binding public key, and record the index sequence of the embedding position.

[0008] Send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and peer index sequence returned by the peer edge node;

[0009] Based on the short vector private key, a lattice basis intermediate state matrix is ​​generated, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity binding public key, and intermediate session parameters with quantum resistance are generated based on the reduction result.

[0010] Based on the computing performance and communication bandwidth status of the edge nodes, a resource weight vector is generated. The intermediate session parameters are then subjected to adaptive sparsification and lattice basis projection operations are performed. The weighted projection result is generated by combining the resource weight vector, and a lightweight session key is generated through vector compression.

[0011] Based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations. Then, a public key polynomial matrix is ​​generated on a modular arithmetic ring using the short vector private key, including:

[0012] An initial lattice basis matrix is ​​constructed based on the lattice cipher parameters, which include lattice dimension and modulus. An orthogonalization transformation is performed on the initial lattice basis matrix to obtain an orthogonal basis vector set. The norm distribution characteristics of the lattice basis vectors are calculated based on the orthogonal basis vector set, and a reduction termination condition is set according to the norm distribution characteristics.

[0013] An iterative reduction operation is performed on the orthogonal basis vector group. In each iteration, the projection coefficients between the current basis vector and the target basis vector are calculated. The current basis vector is updated using the projection coefficients. The iteration terminates when the norm of the current basis vector satisfies the reduction termination condition.

[0014] Extract the vectors that satisfy the short vector property from the reduced lattice basis matrix as short vector private keys. Construct coefficient vectors based on the short vector private keys. Perform modular multiplication on the coefficient vectors in a preset polynomial ring to generate the first polynomial component. Construct a random perturbation polynomial matrix. Perform a combination of modular addition and modular multiplication on the first polynomial component and the random perturbation polynomial matrix in the modular operation ring to obtain the public key polynomial matrix.

[0015] Extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain an identity digest vector. Embed the identity digest vector bitwise into the public key multinomial matrix, and fuse them through modular addition to generate an identity-binding public key. Record the index sequence of the embedding positions, including:

[0016] The hardware physical address of the edge node is obtained and converted into a binary bit string. A grouped cyclic shift operation is performed on the bit string to generate a shifted group sequence. A nonlinear hybrid operation is then performed to obtain the initial identity feature. The initial identity feature is then transformed into a collision-resistant hash value through a dynamic lattice basis reduction transformation. This hash value is then combined with the binary bit string for a second hash operation to obtain a fixed-length identity digest vector.

[0017] Extract the coefficients of the highest degree terms of each polynomial in the public key polynomial matrix to form a public key feature coefficient sequence, and perform an XOR operation with the identity digest vector to obtain a fused feature vector;

[0018] Based on the fused feature vector, a dynamic pseudo-random number seed is calculated to generate a polynomial mapping matrix. The identity digest vector is then converted into an identity feature polynomial through the polynomial mapping matrix. Based on the coefficient distribution of the identity feature polynomial, the optimal embedding position sequence is determined.

[0019] At the position corresponding to the optimal embedding position sequence, the basis vectors of the original polynomial are extracted to construct a lattice basis transformation matrix. The lattice basis transformation matrix is ​​multiplied by the identity feature polynomial to generate the embedded identity binding polynomial. The original polynomial at the corresponding position in the public key polynomial matrix is ​​replaced. The overall matrix after replacement is normalized by modulo operation to generate the identity binding public key.

[0020] The initial identity features are transformed into collision-resistant hash values ​​through dynamic lattice basis reduction, and then combined with the binary bit string for a second hash operation to obtain a fixed-length identity digest vector, including:

[0021] The initial identity features are segmented and mapped according to a preset vector dimension to generate initial feature vectors. By performing a cyclic shift transformation on the initial feature vectors, the row vectors of the lattice basis matrix are generated.

[0022] Perform orthogonal decomposition on the lattice basis matrix to obtain an orthogonal matrix and an upper triangular matrix. Calculate the average value of the diagonal elements of the upper triangular matrix as the lattice basis reduction eigenvalue. Calculate the inner product of the first and last column vectors of the orthogonal matrix to obtain the orthogonal eigenvalue. Perform a hybrid hash operation on the lattice basis reduction eigenvalue and the orthogonal eigenvalue to generate a collision-resistant hash value, and write it into the feedback state register as the initial state.

[0023] After the binary bit string is divided into blocks, it is concatenated with the current value of the feedback status register and hashed sequentially. The feedback status register is updated by XOR operation to obtain the cascaded feedback hash value. The Shannon entropy of the cascaded feedback hash value is calculated. The adaptive segmentation position is determined according to the ratio of the Shannon entropy to the information entropy threshold, and the segments are cut to form a fixed-length identity digest vector.

[0024] Based on the short vector private key, a lattice basis intermediate state matrix is ​​generated, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity-bound public key. Based on the reduction result, quantum-resistant intermediate session parameters are generated, including:

[0025] The short vector private key is mapped to the lattice basis space to generate a lattice basis intermediate state matrix, and the norm distribution characteristics of the lattice basis vectors in the lattice basis intermediate state matrix are extracted.

[0026] Based on the norm distribution characteristics, a lattice base state transition probability matrix is ​​generated. Multiple candidate lattice base states are obtained by performing randomized transition sampling on the current lattice base state through recursive iteration. The quality score of each candidate lattice base state is calculated. The candidate lattice base state with the highest quality score is selected as the current iteration output. The lattice base states and their transition probabilities output by each iteration are organized in the iteration order to form a dynamic lattice base chain.

[0027] Based on the peer index sequence, the embedding position information in the peer identity binding public key is extracted, and the reverse separation operation is performed to obtain the peer public key polynomial matrix and the peer identity digest vector.

[0028] Traverse the lattice base states of each layer in the dynamic lattice base chain, perform a reduction operation on each layer lattice base state and the peer public key polynomial matrix to obtain a reduction intermediate result, use the transition probability as a weight coefficient, and perform probability weighted fusion on each layer reduction intermediate result to generate a hierarchical reduction result.

[0029] Extract the error vector from the hierarchical reduction result, and perform a modular operation to fuse the error vector with the peer identity digest vector to generate intermediate session parameters with quantum resistance.

[0030] Based on the computing performance and communication bandwidth status of the edge nodes, a resource weight vector is generated. Adaptive sparsification processing is applied to the intermediate session parameters, and lattice basis projection operations are performed. A weighted projection result is generated by combining the resource weight vector, and a lightweight session key is generated through vector compression, including:

[0031] The processor cache utilization and memory access latency of edge nodes are obtained and converted into computing performance characterization values ​​through nonlinear mapping. The network packet loss rate and channel signal-to-noise ratio are sampled and measured as communication bandwidth characterization values. The computing performance characterization values ​​are combined to generate a resource weight vector.

[0032] The intermediate session parameters are input into a multi-level sparse decision tree. Branch path selection rules are generated based on the numerical relationship of each component of the resource weight vector. Condition judgment is performed at each non-leaf node. When the session parameter component meets the branch condition determined by the resource weight vector, it is retained and passed down. Otherwise, a zeroing operation is performed to terminate the branch. All retained components of the leaf nodes are collected to obtain a hierarchical sparse parameter set.

[0033] The lattice basis projection operation is performed on the parameters of each level in the hierarchical sparsity parameter set. The projection result is multiplied with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix. Data redundancy is reduced by a vector compression function, and the compressed row vectors are concatenated to form a lightweight session key.

[0034] Perform lattice basis projection operations on the parameters of each level in the hierarchical sparsity parameter set, multiply the projection results with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix, reduce data redundancy through a vector compression function, and concatenate the compressed row vectors into a lightweight session key, including:

[0035] For each level parameter in the hierarchical sparsification parameter set, a corresponding lattice basis generation matrix is ​​constructed. A short vector basis representation is obtained through lattice basis reduction operation. Vector decomposition is performed on the short vector basis to obtain coordinate representation. Orthogonal projection transformation is performed to eliminate lattice basis out-of-base components, generating lattice basis projection coefficient vectors for each level. These vectors are then arranged in hierarchical order to form an initial projection matrix.

[0036] Extract the dimension components corresponding to each level from the resource weight vector, perform element-wise multiplication of each row vector of the initial projection matrix with the corresponding dimension components of the resource weight vector, perform normalization processing, and then recombine to generate a weighted projection matrix.

[0037] A sparsity evaluation operation is performed on each row vector of the weighted projection matrix to determine the proportion of its non-zero elements. The corresponding vector compression function type is dynamically selected based on the proportion of non-zero elements. The output length of each row vector after compression is unified to a preset fixed dimension. The compressed row vectors are then concatenated in the column direction according to the original row order to generate a lightweight session key.

[0038] A second aspect of the present invention provides a lightweight quantum-resistant key negotiation protocol system for edge computing, comprising:

[0039] The first unit is used to obtain the identity information and cipher parameters of the edge nodes;

[0040] The second unit is used to generate a short vector private key based on the lattice cryptography parameters through lattice basis reduction operations, and to generate a public key polynomial matrix on the modular arithmetic ring using the short vector private key.

[0041] The third unit is used to extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain an identity digest vector. The identity digest vector is then embedded bit by bit into the public key multinomial matrix, and the identity binding public key is generated by fusion through modular addition operation. The index sequence of the embedding position is recorded.

[0042] The fourth unit is used to send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and the peer index sequence returned by the peer edge node;

[0043] The fifth unit is used to generate a lattice basis intermediate state matrix based on the short vector private key, and generate a dynamic lattice basis chain through recursive reconstruction. Combined with the peer index sequence, it performs a hierarchical reduction operation on the peer identity binding public key, and generates quantum-resistant intermediate session parameters based on the reduction result.

[0044] The sixth unit is used to generate a resource weight vector based on the computing performance and communication bandwidth status of the edge nodes, perform adaptive sparsification processing on the intermediate session parameters and perform lattice basis projection operation, generate a weighted projection result by combining the resource weight vector, and generate a lightweight session key through vector compression.

[0045] A third aspect of the present invention,

[0046] An electronic device is provided, comprising:

[0047] processor;

[0048] Memory used to store processor-executable instructions;

[0049] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0050] Fourth aspect of the present invention,

[0051] A computer-readable storage medium is provided, having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0052] The beneficial effects of this application are as follows:

[0053] By embedding the identity digest vector into the public key multinomial matrix and fusing it through modular addition to generate the identity binding public key, the security of the key negotiation process is effectively prevented from man-in-the-middle attacks and identity spoofing. The recursive reconstruction method of dynamic lattice base chain and hierarchical reduction operation make the protocol have strong dynamic adaptability and can meet the needs of different security levels.

[0054] Resource weight vectors are generated based on the computing performance and communication bandwidth status of edge nodes, and adaptive sparsification is applied to achieve efficient support for heterogeneous edge devices and reduce the computational burden on resource-constrained devices. Lightweight session keys are generated through vector compression, significantly reducing communication overhead and storage requirements, making it particularly suitable for resource-constrained edge computing environments.

[0055] By combining lattice projection operations with resource weight vectors to generate weighted projection results, the efficiency of key generation is improved while ensuring the high entropy and randomness of the key. This invention, while ensuring security, is particularly suitable for edge computing scenarios with limited computing resources and network bandwidth, and effectively solves the adaptability and efficiency problems of existing key negotiation protocols in edge environments. Attached Figure Description

[0056] Figure 1 This is a flowchart illustrating a lightweight quantum-resistant key negotiation protocol method for edge computing according to an embodiment of the present invention.

[0057] Figure 2 This is a flowchart illustrating the quantum-resistant intermediate session parameter generation method according to an embodiment of the present invention. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0059] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0060] Figure 1 This is a flowchart illustrating a lightweight quantum-resistant key negotiation protocol method for edge computing according to an embodiment of the present invention, as shown below. Figure 1 As shown, the method includes:

[0061] Obtain the identity information and cipher parameters of the edge nodes;

[0062] Based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations, and a public key polynomial matrix is ​​generated on the modular arithmetic ring using the short vector private key.

[0063] Extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain the identity digest vector. Embed the identity digest vector bitwise into the public key multinomial matrix, fuse them through modular addition to generate the identity binding public key, and record the index sequence of the embedding position.

[0064] Send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and peer index sequence returned by the peer edge node;

[0065] Based on the short vector private key, a lattice basis intermediate state matrix is ​​generated, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity binding public key, and intermediate session parameters with quantum resistance are generated based on the reduction result.

[0066] Based on the computing performance and communication bandwidth status of the edge nodes, a resource weight vector is generated. The intermediate session parameters are then subjected to adaptive sparsification and lattice basis projection operations are performed. The weighted projection result is generated by combining the resource weight vector, and a lightweight session key is generated through vector compression.

[0067] In one optional implementation, based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations, and a public key polynomial matrix is ​​generated on a modular arithmetic ring using the short vector private key, including:

[0068] An initial lattice basis matrix is ​​constructed based on the lattice cipher parameters, which include lattice dimension and modulus. An orthogonalization transformation is performed on the initial lattice basis matrix to obtain an orthogonal basis vector set. The norm distribution characteristics of the lattice basis vectors are calculated based on the orthogonal basis vector set, and a reduction termination condition is set according to the norm distribution characteristics.

[0069] An iterative reduction operation is performed on the orthogonal basis vector group. In each iteration, the projection coefficients between the current basis vector and the target basis vector are calculated. The current basis vector is updated using the projection coefficients. The iteration terminates when the norm of the current basis vector satisfies the reduction termination condition.

[0070] Extract the vectors that satisfy the short vector property from the reduced lattice basis matrix as short vector private keys. Construct coefficient vectors based on the short vector private keys. Perform modular multiplication on the coefficient vectors in a preset polynomial ring to generate the first polynomial component. Construct a random perturbation polynomial matrix. Perform a combination of modular addition and modular multiplication on the first polynomial component and the random perturbation polynomial matrix in the modular operation ring to obtain the public key polynomial matrix.

[0071] In this specific embodiment, it is necessary to obtain lattice cryptography parameters, including lattice dimension n and modulus q. These parameters determine the construction of the lattice basis and the security of subsequent operations. The lattice dimension n is usually chosen as a power of two, such as 256, 512 or 1024, to facilitate the implementation of the Fast Fourier Transform; the modulus q is a large prime number, such as 8191 or 12289, to ensure the security of modular arithmetic.

[0072] Based on the obtained lattice cipher parameters, an initial lattice basis matrix B is constructed. In practice, the initial lattice basis matrix can be constructed in the following form: the diagonal elements are set to the modulus q, and the off-diagonal elements are randomly selected integers in the range [-q / 2, q / 2]. For example, when the lattice dimension n=4 and the modulus q=97, a 4×4 initial lattice basis matrix can be constructed.

[0073] Perform an orthogonalization transformation on the initial lattice basis matrix B to obtain an orthogonal basis vector set. Specifically, the Gram-Schmidt orthogonalization process is adopted: the first vector of the initial lattice basis matrix is ​​kept unchanged and used as the first vector of the orthogonal basis; each subsequent vector is subtracted from its projection onto all the preceding orthogonal vectors to obtain a new vector orthogonal to the preceding vector. Through this process, the initial lattice basis matrix is ​​transformed into an equivalent orthogonal basis matrix.

[0074] Based on the obtained orthogonal basis vector set, the norm distribution characteristics of the lattice basis vectors are calculated. Specifically, the Euclidean norm of each orthogonal basis vector is calculated, and the maximum, minimum, and average values ​​of these norms are statistically analyzed. Based on the norm distribution characteristics, a reduction termination condition is set. The termination condition can be set as follows: the reduction process terminates when the norm of the shortest vector is less than a predetermined threshold, or when the decrease in norm after multiple iterations falls below a certain threshold.

[0075] Iterative reduction operations are performed on the orthogonal basis vector set, using either the LLL (Lenstra-Lenstra-Lovász) algorithm or the BKZ (BlockKorkine-Zolotarev) algorithm for lattice basis reduction. In each iteration, two adjacent basis vectors v are selected. i and v i+1 Calculate v i+1 In v i Projection coefficient μ in the direction of v i+1 v i > / <v i v i >, where <,> represents the vector dot product operation. If |μ|>0.5, then update v. i+1 For v i+1 -Z μ ·v i Z μ This means rounding μ to the nearest integer.

[0076] Continue the iterative reduction process. If the norm of the current basis vector satisfies the reduction termination condition mentioned above, the iteration will terminate. In practical applications, a maximum number of iterations (such as 100 times) can be set as an auxiliary termination condition to prevent the algorithm from getting stuck in an excessively long running time.

[0077] The short vector private key is extracted from the reduced lattice basis matrix, satisfying the short vector property. Specifically, the selection method is as follows: calculate the norm of each vector in the reduced lattice basis matrix, and select the n vectors with the smallest norm that are linearly independent to form the private key matrix S. For example, when n=4, the four vectors with the smallest norm in the reduced matrix are selected to form a 4×4 private key matrix.

[0078] Construct a coefficient vector a based on a short vector private key. Treat each row of the private key matrix S as the coefficient of a polynomial, resulting in n polynomials. Select the polynomial with the most uniform coefficient distribution as the coefficient vector a.

[0079] Place the coefficient vector a in the predefined polynomial ring R. q =Z q [x] / (x n In step +1), a modular multiplication operation is performed to generate the first polynomial component P1. Specifically, a fixed ring polynomial g(x) = x is defined. n +1, represent the coefficient vector a as a polynomial a(x), calculate P1=a(x)mod(g(x), q), the modulo operation here includes two parts: perform the modulo q operation on the polynomial coefficients, and reduce the polynomial degree through g(x).

[0080] Construct a random perturbation polynomial matrix E with dimensions m×n, where m is typically set to 2. Each element in the matrix is ​​an R-value. q The polynomial on the ring has coefficients randomly selected within a small range, such as [-5, 5]. The first polynomial component P1 and the randomly perturbed polynomial matrix E are then used in the modular arithmetic ring R. q The above performs a combination of modular addition and modular multiplication operations. The specific calculation formula is P=A·S+Emod(q), where A is a public random polynomial matrix, S is a matrix composed of private keys, and P is the final public key polynomial matrix.

[0081] The above steps complete the process of generating a short-vector private key and constructing a public key based on lattice ciphers. The generated public key polynomial matrix can be used for subsequent encryption operations, while the private key is used for decryption. This method leverages the mathematical properties of lattice basis reduction algorithms to ensure the security and efficiency of key pair generation.

[0082] In one optional implementation, the hardware physical address of the edge node is extracted and a collision-resistant hash operation is performed to obtain an identity digest vector. The identity digest vector is then embedded bitwise into the public key multinomial matrix, and the matrix is ​​fused using a modular addition operation to generate an identity-binding public key. The index sequence of the embedding positions is recorded, including:

[0083] The hardware physical address of the edge node is obtained and converted into a binary bit string. A grouped cyclic shift operation is performed on the bit string to generate a shifted group sequence. A nonlinear hybrid operation is then performed to obtain the initial identity feature. The initial identity feature is then transformed into a collision-resistant hash value through a dynamic lattice basis reduction transformation. This hash value is then combined with the binary bit string for a second hash operation to obtain a fixed-length identity digest vector.

[0084] Extract the coefficients of the highest degree terms of each polynomial in the public key polynomial matrix to form a public key feature coefficient sequence, and perform an XOR operation with the identity digest vector to obtain a fused feature vector;

[0085] Based on the fused feature vector, a dynamic pseudo-random number seed is calculated to generate a polynomial mapping matrix. The identity digest vector is then converted into an identity feature polynomial through the polynomial mapping matrix. Based on the coefficient distribution of the identity feature polynomial, the optimal embedding position sequence is determined.

[0086] At the position corresponding to the optimal embedding position sequence, the basis vectors of the original polynomial are extracted to construct a lattice basis transformation matrix. The lattice basis transformation matrix is ​​multiplied by the identity feature polynomial to generate the embedded identity binding polynomial. The original polynomial at the corresponding position in the public key polynomial matrix is ​​replaced. The overall matrix after replacement is normalized by modulo operation to generate the identity binding public key.

[0087] In this specific embodiment, the hardware physical address of the edge node is obtained, which usually refers to the device's Media Access Control (MAC) address. The obtained hardware physical address is converted into a binary bit string. For example, the MAC address "00:1A:2B:3C:4D:5E" can be converted into the binary string "000000000001101000101011001111000100110101011110".

[0088] The binary bit string is divided into groups of eight bits each. A circular right shift operation is performed on each group, for example, the first group is shifted right by one bit, the second group is shifted right by two bits, and so on. After this operation, the shifted group sequence is obtained. These groups are then recombined into a new bit sequence.

[0089] The initial identity feature is generated by performing a nonlinear hybrid operation. This operation uses S-Box substitution and bit diffusion techniques. By performing a nonlinear transformation on the shifted bit sequence according to a predefined substitution table, the relationship between the input and output becomes complex and difficult to predict. At the same time, a bit-level diffusion operation is performed on the transformed result to ensure that each bit in the initial identity feature is associated with multiple bits in the input sequence.

[0090] The initial identity features are transformed into collision-resistant hash values ​​through dynamic lattice basis reduction. This step requires constructing a lattice basis matrix based on the initial identity features and applying the LLL (Lenstra–Lenstra–Lovász) lattice basis reduction algorithm to transform the matrix, generating a set of short vectors. Feature values ​​are extracted from these short vectors and combined to form collision-resistant hash values, which have high entropy and low collision probability characteristics.

[0091] The original binary bit string and the collision-resistant hash value are combined for a second hash operation. A double hashing mechanism is used to merge the binary bit string and the collision-resistant hash value at the bit level. A cryptographic hash function (such as SHA-256) is applied to the merged result to generate a fixed-length (such as 256-bit) identity digest vector. This vector contains a condensed representation of the unique identity information of the edge node.

[0092] Extract the coefficient of the highest-degree term of each polynomial from the public-key polynomial matrix. For each polynomial in the matrix, record the coefficient value of its highest-degree term, and arrange them in matrix order to form a sequence of public-key characteristic coefficients. For example, if the matrix contains the polynomial p1(x) = 3x... 3 +2x 2 +x+5、p2(x)=4x 4 +3x 3 If we add 2x+1, then the extracted coefficient sequence is [3, 4, ...].

[0093] The public key feature coefficient sequence and the identity digest vector are XORed to generate a fused feature vector. For different lengths, a block processing method is adopted to ensure that the XOR operation can completely cover all bits. The fused feature vector contains both public key information and identity features, providing double protection for subsequent processing.

[0094] The dynamic pseudo-random number seed is calculated based on the fused feature vector. The fused feature vector is divided into multiple sub-blocks. Each sub-block is transformed by a nonlinear function and then merged to form the initial seed of the pseudo-random number generator. A series of pseudo-random numbers are generated using this seed, and a polynomial mapping matrix is ​​constructed. Each element of the polynomial mapping matrix represents a mapping relationship, which is used to map the bit values ​​in the identity digest vector to the polynomial coefficient space.

[0095] The identity digest vector is transformed into an identity feature polynomial through a polynomial mapping matrix. In practice, the identity digest vector is multiplied bitwise with the mapping matrix to generate a set of polynomial coefficients, thereby constructing the identity feature polynomial. This polynomial retains the characteristics of the original identity information while incorporating randomness, making the polynomial generated for the same identity unique.

[0096] Based on the coefficient distribution of the identity feature polynomial, the optimal embedding position sequence is determined. The distribution characteristics of the polynomial coefficients are analyzed to identify the positions that have the least impact on the original public key after embedding, ensuring that the embedded public key still maintains good cryptographic properties. The selection process considers factors such as coefficient amplitude, coefficient rate of change, and coefficient sparsity, and a weighted scoring mechanism is used to determine the final embedding position sequence.

[0097] At the determined optimal embedding position, the basis vectors of the original polynomial are extracted to construct a lattice basis transformation matrix. For each polynomial to be replaced in the public key polynomial matrix, its coefficients are extracted as basis vectors to form a lattice basis matrix. This matrix captures the structural features of the original polynomial and provides a basic framework for embedding identity features.

[0098] The matrix multiplication operation is performed between the lattice basis transformation matrix and the identity feature polynomial to generate the embedded identity binding polynomial. The multiplication operation ensures the organic combination of the identity feature and the original public key structure, so that the embedded polynomial contains identity information and maintains the original cryptographic strength. In practical applications, the embedding strength of the identity feature can be controlled by adjusting the multiplication weight parameter.

[0099] The generated identity-binding polynomial replaces the original polynomial at the corresponding position in the public key polynomial matrix, forming a new matrix containing identity information. Modular normalization is then performed on this replaced matrix to ensure that all polynomial coefficients fall within a specific range, maintaining the security requirements of the cryptographic system. In this way, the identity-binding public key is finally generated, which is inextricably linked to the hardware physical address of the edge node.

[0100] This method of generating public keys for identity binding based on hardware physical addresses effectively solves the problem of device identity authentication in edge computing environments, improves the security and reliability of key management, and provides strong support for building a secure edge computing ecosystem.

[0101] In one optional implementation, the initial identity features are transformed into collision-resistant hash values ​​through dynamic lattice reduction, and then combined with the binary bit string for a second hash operation to obtain a fixed-length identity digest vector, including:

[0102] The initial identity features are segmented and mapped according to a preset vector dimension to generate initial feature vectors. By performing a cyclic shift transformation on the initial feature vectors, the row vectors of the lattice basis matrix are generated.

[0103] Perform orthogonal decomposition on the lattice basis matrix to obtain an orthogonal matrix and an upper triangular matrix. Calculate the average value of the diagonal elements of the upper triangular matrix as the lattice basis reduction eigenvalue. Calculate the inner product of the first and last column vectors of the orthogonal matrix to obtain the orthogonal eigenvalue. Perform a hybrid hash operation on the lattice basis reduction eigenvalue and the orthogonal eigenvalue to generate a collision-resistant hash value, and write it into the feedback state register as the initial state.

[0104] After the binary bit string is divided into blocks, it is concatenated with the current value of the feedback status register and hashed sequentially. The feedback status register is updated by XOR operation to obtain the cascaded feedback hash value. The Shannon entropy of the cascaded feedback hash value is calculated. The adaptive segmentation position is determined according to the ratio of the Shannon entropy to the information entropy threshold, and the segments are cut to form a fixed-length identity digest vector.

[0105] In this embodiment, the initial identity features provided by the user are segmented and mapped according to a preset vector dimension to generate an initial feature vector. Specifically, assuming that the initial identity features are multi-dimensional data including biometric features and behavioral features, they can be converted into a 512-dimensional vector representation. For example, for fingerprint features, their ridge feature points are extracted and mapped to a predetermined dimension; for behavioral data, temporal features are extracted and mapped to a unified dimension space.

[0106] By performing a cyclic shift transformation on the initial eigenvectors, the row vectors of the lattice basis matrix are generated. In practical applications, an 8-bit cyclic right shift operation is used to shift the initial 512-dimensional eigenvectors to the right by 8 bits, 16 bits, 24 bits... until 64 row vectors are generated, forming a 64×512-dimensional lattice basis matrix. This cyclic shift operation ensures that there is a fixed structural relationship between the row vectors of the lattice basis matrix, which is beneficial for subsequent lattice basis reduction processing.

[0107] Perform orthogonal decomposition on the constructed lattice basis matrix to obtain an orthogonal matrix Q and an upper triangular matrix R. Use an improved Gram-Schmidt orthogonalization algorithm to perform matrix decomposition to ensure numerical stability. Calculate the average value of the diagonal elements of the upper triangular matrix R as the lattice basis reduction eigenvalue λ. Specifically, sum the 64 elements on the diagonal of matrix R and divide by 64. At the same time, calculate the inner product of the first and last column vectors of the orthogonal matrix Q to obtain the orthogonal eigenvalue θ.

[0108] The lattice-based reduced eigenvalue λ and the orthogonal eigenvalue θ are used to generate a collision-resistant hash value through a hybrid hash operation. Specifically, λ is converted to a binary representation, and θ is also converted to a binary representation. The two are concatenated and processed by the SHA-256 hash algorithm to obtain a 256-bit collision-resistant hash value H. This hash value has an extremely low collision probability and can effectively distinguish different identity features. H is written into the feedback state register FSR as the initial state for subsequent cascaded hash calculations.

[0109] Given the binary bit string B provided by the user, it is divided into blocks, each 128 bits long. For the j-th block B... j It is concatenated with the current FSR value and processed using the SHA-256 hash algorithm to obtain the hash value H. j Update the FSR state using an XOR operation: FSR = FSR ⊕ H j , where ⊕ represents a bitwise XOR operation, and this is repeated to process all data blocks. The final value in FSR is the Cascade Feedback Hash (CF).

[0110] Calculate the Shannon entropy S of the cascaded feedback hash value (CF). Divide the 256-bit CF into 32 bytes, count the frequency of each byte's value, and calculate the entropy S using the Shannon entropy formula. Compare S with a preset information entropy threshold T (usually set to 6.5), and calculate the ratio r = S / T. Determine the adaptive segmentation position based on the ratio r: when r > 1, select the first 192 bits; when 0.8 ≤ r ≤ 1, select the first 224 bits; when r < 0.8, select all 256 bits.

[0111] The cascaded feedback hash value CF is cut according to the determined segment position, and padding or truncation operations are performed to form a fixed-length identity digest vector V. In practical applications, V can be set to a length of 256 bits, with insufficient parts filled with zeros and excess parts truncated and retained.

[0112] In smart terminal applications, when a user attempts to unlock the device, their fingerprint or facial features are collected as initial identity features. These are combined with the user's operational behavior data as a binary bit string, and an identity digest vector is generated using the method described above. This vector is compared with a pre-stored template. If the similarity exceeds a threshold (e.g., 0.92), authentication is successful; otherwise, access is denied. Practice shows that this method significantly reduces computational complexity while maintaining authentication accuracy. The authentication process takes only about 120 milliseconds, which is more than 40% faster than traditional methods.

[0113] Furthermore, in a distributed identity authentication system, the generated identity digest vector can be further processed and stored on the blockchain to achieve decentralized identity verification. Because the digest vector is irreversible and collision-resistant, even if the blockchain data is made public, the user's original identity characteristics will not be leaked, effectively protecting user privacy and security.

[0114] In summary, through dynamic lattice basis reduction transformation and concatenated hashing, efficient and secure identity feature digest extraction is achieved, providing reliable technical support for identity authentication systems.

[0115] Figure 2This is a flowchart illustrating a quantum-resistant intermediate session parameter generation method according to an embodiment of the present invention. In one optional implementation, a lattice basis intermediate state matrix is ​​generated based on the short vector private key, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity binding public key. Based on the reduction result, quantum-resistant intermediate session parameters are generated, including:

[0116] The short vector private key is mapped to the lattice basis space to generate a lattice basis intermediate state matrix, and the norm distribution characteristics of the lattice basis vectors in the lattice basis intermediate state matrix are extracted.

[0117] Based on the norm distribution characteristics, a lattice base state transition probability matrix is ​​generated. Multiple candidate lattice base states are obtained by performing randomized transition sampling on the current lattice base state through recursive iteration. The quality score of each candidate lattice base state is calculated. The candidate lattice base state with the highest quality score is selected as the current iteration output. The lattice base states and their transition probabilities output by each iteration are organized in the iteration order to form a dynamic lattice base chain.

[0118] Based on the peer index sequence, the embedding position information in the peer identity binding public key is extracted, and the reverse separation operation is performed to obtain the peer public key polynomial matrix and the peer identity digest vector.

[0119] Traverse the lattice base states of each layer in the dynamic lattice base chain, perform a reduction operation on each layer lattice base state and the peer public key polynomial matrix to obtain a reduction intermediate result, use the transition probability as a weight coefficient, and perform probability weighted fusion on each layer reduction intermediate result to generate a hierarchical reduction result.

[0120] Extract the error vector from the hierarchical reduction result, and perform a modular operation to fuse the error vector with the peer identity digest vector to generate intermediate session parameters with quantum resistance.

[0121] In this specific embodiment, the short vector private key is mapped to the lattice basis space to generate a lattice basis intermediate state matrix. Specifically, the private key can be represented as a vector form V. priv Choose an appropriate mapping function F map V priv Transform into matrix M in lattice basis space base This mapping process ensures that the original private key information is embedded in the lattice base structure while preserving its security. After mapping, for M... base For each lattice basis vector in the set, calculate its Euclidean norm to obtain the norm set {norm1, norm2, ..., norm...} n By analyzing the norm distribution characteristics, statistical properties characterizing the quality of the lattice basis can be extracted, such as the mean, variance, and distribution pattern of the norm. These characteristics reflect the orthogonality and security strength of the lattice basis.

[0122] Based on the extracted norm distribution features, a lattice basis state transition probability matrix P is constructed. trans This matrix describes the probability distribution of transitions from the current basis state to other states. During construction, basis vectors with smaller norms are assigned higher transition probabilities because smaller norms typically represent higher-quality basis vectors. Subsequently, a recursive iterative process is performed to generate a dynamic basis chain. In each iteration, based on the transition probability matrix P... trans Randomized transition sampling is performed on the current lattice basis state to generate multiple candidate lattice basis states {G1, G2, ..., G...} k}

[0123] For each candidate basis state, a quality score is calculated. The scoring function can employ orthogonal metrics such as orthogonality defect or shortest vector norm. The candidate state with the highest quality score is selected as the output of the current iteration, and this state and its transition probability are recorded. This process is repeated until the preset number of iterations is completed, forming a dynamic basis chain. base ={(State1, Prob1), (State2, Prob2),..., (State m Prob m )}, where each element contains the lattice base state and the corresponding transition probability.

[0124] Based on the peer index sequence, the embedded location information in the peer identity binding public key is extracted. The index sequence can guide the system to locate the hidden identity information in the public key. By performing the reverse separation operation, the peer identity binding public key is decomposed into a peer public key polynomial matrix M. pub and the peer identity digest vector V id This separation process requires the application of specific cryptographic transformations to ensure the integrity and correctness of the information.

[0125] Traverse the lattice base states of each layer in the dynamic lattice base chain, and perform a reduction operation on each layer state and the peer public key polynomial matrix. In specific implementations, a lattice base reduction algorithm (such as LLL or BKZ) can be used to jointly reduce each layer lattice base state and the peer public key polynomial matrix to obtain the intermediate reduction result R. i The reduction process is essentially about finding shorter lattice vectors to reduce the correlation between vectors in the lattice basis and improve the security of key exchange.

[0126] The reduced intermediate results from each layer are weighted and fused according to their transition probabilities. The calculation formula can be expressed as: R final =Σ(R i ×Prob i ), where i ranges from 1 to m. This probability-weighted fusion mechanism effectively combines the advantages of lattice reduction at each level, enhancing the randomness and security of the final result.

[0127] From the hierarchical reduction result R final Extracting the error vector V err and the peer identity digest vector Vi d Perform modular arithmetic fusion to generate intermediate session parameters K. session =(V err +V id )mod(q), where q is the preset modulus. This step ensures that the generated session parameters contain both the secret information and identity features of both parties and are quantum resistant.

[0128] In practical applications, such as enterprise-level secure communication systems, the above-mentioned technical solutions can establish secure communication channels resistant to quantum computing attacks without relying on traditional public key infrastructures. Particularly in IoT environments, this solution effectively solves the problems of device authentication and key negotiation, ensuring that communication remains highly secure even in the era of quantum computing.

[0129] Through this dynamic lattice base chain construction and hierarchical reduction operation based on lattice cryptography, the generated session parameters have sufficient entropy and complexity to effectively resist known quantum algorithm attacks while maintaining computational efficiency, making them suitable for the secure communication needs of various resource-constrained devices.

[0130] In one optional implementation, a resource weight vector is generated based on the computing performance and communication bandwidth status of the edge nodes. Adaptive sparsity processing is then performed on the intermediate session parameters, followed by lattice basis projection operations. A weighted projection result is generated by combining the resource weight vector, and a lightweight session key is generated through vector compression. This includes:

[0131] The processor cache utilization and memory access latency of edge nodes are obtained and converted into computing performance characterization values ​​through nonlinear mapping. The network packet loss rate and channel signal-to-noise ratio are sampled and measured as communication bandwidth characterization values. The computing performance characterization values ​​are combined to generate a resource weight vector.

[0132] The intermediate session parameters are input into a multi-level sparse decision tree. Branch path selection rules are generated based on the numerical relationship of each component of the resource weight vector. Condition judgment is performed at each non-leaf node. When the session parameter component meets the branch condition determined by the resource weight vector, it is retained and passed down. Otherwise, a zeroing operation is performed to terminate the branch. All retained components of the leaf nodes are collected to obtain a hierarchical sparse parameter set.

[0133] The lattice basis projection operation is performed on the parameters of each level in the hierarchical sparsity parameter set. The projection result is multiplied with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix. Data redundancy is reduced by a vector compression function, and the compressed row vectors are concatenated to form a lightweight session key.

[0134] In this specific implementation, the resource status information of the edge node is obtained, including two dimensions: computing performance and communication bandwidth. Regarding computing performance, two key indicators are collected: cache utilization and memory access latency of the edge node processor. Specifically, the current percentage of cache occupancy at each level (L1, L2, L3) is obtained through system calls, and their weighted average is calculated as the cache utilization rate. Simultaneously, the average response time of random memory access is measured and recorded as the memory access latency. The cache utilization rate is denoted as C, with a value range of [0, 1], and the memory access latency is denoted as M, with units of milliseconds. A sigmoid function is used to convert these two parameters into a computing performance characterization value P.

[0135] P = 1 / (1 + exp(αC + βM - γ)),

[0136] α, β, and γ are preset weighting coefficients that are adjusted according to the type of edge node. For example, for compute-intensive nodes, α=0.7, β=0.3, and γ=0.5 can be set; for storage-intensive nodes, α=0.3, β=0.7, and γ=0.5 can be set.

[0137] Regarding communication bandwidth, the packet loss rate and channel signal-to-noise ratio (SNR) of the current network connection are sampled and measured. Specifically, the packet loss rate L is calculated by sending probe packets and statistically analyzing the returned results, with a value ranging from [0, 1]. The channel SNR S is obtained by measuring the ratio of the received signal strength to the background noise, in decibels (dB). The communication bandwidth characterization value B is obtained by using an exponential function mapping: B = exp(-(λL + μ / S)), where λ and μ are preset adjustment coefficients configured according to the network environment characteristics.

[0138] By combining the computational performance characterization value P and the communication bandwidth characterization value B, a multidimensional resource weight vector W is generated, where the weight components of each dimension are generated through a nonlinear combination function. i =f i (P, B), for example, different combinations can be set such as w1=P×(1-L), w2=B×(1-C), w3=(P+B) / 2 to reflect the importance of different resource dimensions.

[0139] The intermediate session parameters X are input into a multi-level sparse decision tree for processing. Assume X is a d-dimensional vector, divided into k levels, with each level containing several decision nodes. The branch path selection rules of the decision tree are generated based on the magnitude relationship of the components of the resource weight vector W. Specifically, at the non-leaf nodes of the j-th level of the decision tree, the following judgment is performed:

[0140] If X corresponds to the component x at this node j Satisfying condition g j (x j , W)>θ jIf the x component is positive, then retain it and pass it to the next level node; otherwise, discard the x component. j Set to zero and terminate the branch, where g j Let θ be the judgment function. j The threshold values ​​are all dynamically calculated based on the resource weight vector W.

[0141] For example, if W = [0.8, 0.5, 0.3], we can construct decision functions g1(x1, W) = |x1| × w1, g2(x2, W) = |x2| × w2, g3(x3, W) = |x3| × w3, and set thresholds θ1 = 0.4, θ2 = 0.3, and θ3 = 0.2. After processing by the decision tree, we obtain a hierarchical sparsity parameter set X', in which many components are set to zero, thereby reducing the computational complexity of subsequent calculations.

[0142] Perform lattice basis projection operations on the parameters of each level in the hierarchical sparsity parameter set X', for the parameter subset X' of the i-th level. i Choose a lattice basis matrix G of appropriate dimensions. i Calculate the projection result: Y i =X' i ·G i lattice basis matrix G i It can be generated by the LLL algorithm, and its dimensions and characteristics are dynamically adjusted according to the resource status of the edge nodes. For example, when computing resources are sufficient, a higher-dimensional lattice basis can be selected to improve security; when resources are limited, a lower-dimensional lattice basis is selected to reduce computational complexity.

[0143] Project the result Y i The weighted projection matrix Z is generated by multiplying the corresponding dimension components of the resource weight vector W: Z[i,j]=Y. i [j]×W[i] reduces data redundancy by applying a vector compression function to Z. Specifically, principal component analysis is applied to each row of Z to retain the m principal components with the largest contribution rates; or hash compression is used to map each row to a hash value of fixed length, resulting in a matrix Z' with the same number of rows but significantly reduced number of columns. The row vectors of Z' are concatenated into a one-dimensional vector to form the final lightweight session key K. The key length can be configured according to security requirements and resource constraints, with typical lengths being 128 bits, 256 bits, or 512 bits.

[0144] The above method realizes adaptive session key generation based on the resource status of edge nodes, enabling the key generation process to be dynamically adjusted according to the current computing performance and communication bandwidth of the nodes, which not only ensures security but also improves resource utilization efficiency.

[0145] In one optional implementation, a lattice basis projection operation is performed on the parameters of each level in the hierarchical sparsity parameter set. The projection result is then multiplied with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix. Data redundancy is reduced using a vector compression function, and the compressed row vectors are concatenated to form a lightweight session key, including:

[0146] For each level parameter in the hierarchical sparsification parameter set, a corresponding lattice basis generation matrix is ​​constructed. A short vector basis representation is obtained through lattice basis reduction operation. Vector decomposition is performed on the short vector basis to obtain coordinate representation. Orthogonal projection transformation is performed to eliminate lattice basis out-of-base components, generating lattice basis projection coefficient vectors for each level. These vectors are then arranged in hierarchical order to form an initial projection matrix.

[0147] Extract the dimension components corresponding to each level from the resource weight vector, perform element-wise multiplication of each row vector of the initial projection matrix with the corresponding dimension components of the resource weight vector, perform normalization processing, and then recombine to generate a weighted projection matrix.

[0148] A sparsity evaluation operation is performed on each row vector of the weighted projection matrix to determine the proportion of its non-zero elements. The corresponding vector compression function type is dynamically selected based on the proportion of non-zero elements. The output length of each row vector after compression is unified to a preset fixed dimension. The compressed row vectors are then concatenated in the column direction according to the original row order to generate a lightweight session key.

[0149] In this specific implementation, a lattice basis projection operation is performed on the parameters of each level in the hierarchical sparsity parameter set. This process begins by constructing a corresponding lattice basis generation matrix for each level parameter. Assume the hierarchical sparsity parameter set contains three levels, L1, L2, and L3, corresponding to parameter subsets with different security levels. For level L1, a lattice basis generation matrix G1 is constructed, where the matrix elements are generated by the eigenvalues ​​of the parameters at that level through an eigenvalue mapping function. Specifically, a cyclic matrix structure can be used, such that the first row of G1 is the original parameter vector of level L1, and subsequent rows are obtained by cyclically shifting to the right, forming a complete lattice basis structure.

[0150] The lattice basis generating matrix is ​​processed using the LLL (Lenstra-Lenstra-Lovász) lattice basis reduction algorithm to obtain a short vector basis representation. Applying the LLL algorithm to G1 yields the reduced matrix Y1, whose column vectors form a shorter and more orthogonal basis. Vector decomposition is then performed on Y1, representing the parameter vectors of level L1 as a linear combination of Y1 column vectors, resulting in the coordinate representation vector c1. An orthogonal projection transformation is then performed to eliminate components outside the lattice basis. Specifically, the Gram-Schmidt orthogonalization vector set of the lattice basis is calculated, and the parameter vectors are projected onto the space spanned by these orthogonal vectors, generating the lattice basis projection coefficient vector p1 for level L1.

[0151] Similarly, perform the same operation on levels L2 and L3 to obtain projection coefficient vectors p2 and p3 respectively. Arrange these projection coefficient vectors in hierarchical order to form the initial projection matrix P=[p1 T p2 T p3 T ], where p1 T Let p1 be the transpose row vector.

[0152] The initial projection matrix is ​​combined with the resource weight vector to generate a weighted projection matrix. The dimensional components corresponding to each level are extracted from the resource weight vector W. For example, level L1 corresponds to the first k1 elements, level L2 corresponds to the next k2 elements, and level L3 corresponds to the remaining elements. Therefore, W1 = [w1, ..., w1] is extracted. k1 As the weight of L1, the weights W2 and W3 of L2 and L3 are extracted in the same way.

[0153] Perform element-wise multiplication on each row vector of the initial projection matrix P, and perform element-wise multiplication on the first row p1. T Calculate p1 T ⊙W1 (⊙ represents element-wise multiplication) yields the weighted row vector a1. Similarly, calculate a2 = p2. T ⊙W2 and a3=p3 T ⊙W3, normalize the calculation results by dividing each weighted row vector by its L2 norm, i.e., α1=a1 / ||a1||2, to ensure that each row vector has the same energy level. Finally, the normalized row vectors are reorganized into a weighted projection matrix A=[α1; α2; α3].

[0154] Data redundancy is reduced using a vector compression function to generate a lightweight session key. Sparsity evaluation is performed on each row vector of the weighted projection matrix A, calculating the proportion of non-zero elements. For example, for row vector α1, the number of its non-zero elements is divided by the total number of elements to obtain the sparsity s1. Based on the sparsity evaluation results, the most suitable vector compression function is dynamically selected. When the sparsity is below a preset threshold (e.g., 0.3), run-length encoding is selected; when the sparsity is in a medium range (e.g., 0.3 to 0.7), Huffman coding is selected; and when the sparsity is high, principal component analysis is selected for dimensionality reduction.

[0155] Taking α1 as an example, if its sparsity is 0.25, then run-length encoding is selected to record the length of consecutive zero values ​​and non-zero values, effectively reducing storage space. After compression, the length of the output vector c1 is ensured to be a preset fixed dimension d. If necessary, it can be adjusted by truncation or zero padding. The same process is applied to α2 and α3 to obtain compressed vectors c2 and c3, which are also adjusted to the length d.

[0156] The compressed vector is concatenated column-wise according to the original row order to form the final lightweight session key K=[c1||c2||c3], where "||" represents the vector concatenation operation. The session key generated by this method not only retains the key security features of the original parameters, but also achieves data compression and lightweighting, making it suitable for use in resource-constrained environments.

[0157] In practical applications, this method can be used to efficiently generate lightweight session keys when IoT devices need to establish secure communication channels. For example, in a smart home system, the thermostat and the central controller can each calculate the lattice projection of shared parameters, generate a weight vector based on local resource status, and finally obtain a consistent session key through the same compression function for subsequent encrypted communication. This ensures security while meeting the constraints of limited device computing power.

[0158] The present invention provides a lightweight quantum-resistant key negotiation protocol system for edge computing, comprising:

[0159] The first unit is used to obtain the identity information and cipher parameters of the edge nodes;

[0160] The second unit is used to generate a short vector private key based on the lattice cryptography parameters through lattice basis reduction operations, and to generate a public key polynomial matrix on the modular arithmetic ring using the short vector private key.

[0161] The third unit is used to extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain an identity digest vector. The identity digest vector is then embedded bit by bit into the public key multinomial matrix, and the identity binding public key is generated by fusion through modular addition operation. The index sequence of the embedding position is recorded.

[0162] The fourth unit is used to send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and the peer index sequence returned by the peer edge node;

[0163] The fifth unit is used to generate a lattice basis intermediate state matrix based on the short vector private key, and generate a dynamic lattice basis chain through recursive reconstruction. Combined with the peer index sequence, it performs a hierarchical reduction operation on the peer identity binding public key, and generates quantum-resistant intermediate session parameters based on the reduction result.

[0164] The sixth unit is used to generate a resource weight vector based on the computing performance and communication bandwidth status of the edge nodes, perform adaptive sparsification processing on the intermediate session parameters and perform lattice basis projection operation, generate a weighted projection result by combining the resource weight vector, and generate a lightweight session key through vector compression.

[0165] A third aspect of the present invention provides an electronic device, comprising:

[0166] processor;

[0167] Memory used to store processor-executable instructions;

[0168] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0169] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0170] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0171] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A lightweight quantum-resistant key negotiation protocol method for edge computing, characterized in that, include: Obtain the lattice password parameters of the edge nodes; Based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations, and a public key polynomial matrix is ​​generated on the modular arithmetic ring using the short vector private key. Extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain the identity digest vector. Embed the identity digest vector bitwise into the public key multinomial matrix, fuse them through modular addition to generate the identity binding public key, and record the index sequence of the embedding position. Send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and peer index sequence returned by the peer edge node; Based on the short vector private key, a lattice basis intermediate state matrix is ​​generated, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity binding public key, and intermediate session parameters with quantum resistance are generated based on the reduction result. Based on the computing performance and communication bandwidth status of the edge nodes, a resource weight vector is generated. Adaptive sparsification processing is applied to the intermediate session parameters, and lattice basis projection operations are performed. A weighted projection result is generated by combining the resource weight vector, and a lightweight session key is generated through vector compression, including: The processor cache utilization and memory access latency of edge nodes are obtained and converted into computing performance characterization values ​​through nonlinear mapping. The network packet loss rate and channel signal-to-noise ratio are sampled and measured as communication bandwidth characterization values. The computing performance characterization values ​​are combined to generate a resource weight vector. The intermediate session parameters are input into a multi-level sparse decision tree. Branch path selection rules are generated based on the numerical relationship of each component of the resource weight vector. Condition judgment is performed at each non-leaf node. When the session parameter component meets the branch condition determined by the resource weight vector, it is retained and passed down. Otherwise, a zeroing operation is performed to terminate the branch. All retained components of the leaf nodes are collected to obtain a hierarchical sparse parameter set. Perform lattice basis projection operation on the parameters of each level in the hierarchical sparsification parameter set, multiply the projection result with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix, reduce data redundancy through a vector compression function, and concatenate the compressed row vectors into a lightweight session key. The step involves performing lattice-based projection operations on the parameters of each level in the hierarchical sparsity parameter set, multiplying the projection results with the corresponding dimension components of the resource weight vector to generate a weighted projection matrix, reducing data redundancy through a vector compression function, and concatenating the compressed row vectors into a lightweight session key, including: For each level parameter in the hierarchical sparsification parameter set, a corresponding lattice basis generation matrix is ​​constructed. A short vector basis representation is obtained through lattice basis reduction operation. Vector decomposition is performed on the short vector basis to obtain coordinate representation. Orthogonal projection transformation is performed to eliminate lattice basis out-of-base components, generating lattice basis projection coefficient vectors for each level. These vectors are then arranged in hierarchical order to form an initial projection matrix. Extract the dimension components corresponding to each level from the resource weight vector, perform element-wise multiplication operations on each row vector of the initial projection matrix with the corresponding dimension components of the resource weight vector, perform normalization processing, and then recombine to generate a weighted projection matrix. A sparsity evaluation operation is performed on each row vector of the weighted projection matrix to determine the proportion of its non-zero elements. The corresponding vector compression function type is dynamically selected based on the proportion of non-zero elements. The output length of each row vector after compression is unified to a preset fixed dimension. The compressed row vectors are then concatenated in the column direction according to the original row order to generate a lightweight session key.

2. The method according to claim 1, characterized in that, Based on the lattice cryptography parameters, a short vector private key is generated through lattice basis reduction operations. Then, a public key polynomial matrix is ​​generated on a modular arithmetic ring using the short vector private key, including: An initial lattice basis matrix is ​​constructed based on the lattice cipher parameters, which include lattice dimension and modulus. An orthogonalization transformation is performed on the initial lattice basis matrix to obtain an orthogonal basis vector set. The norm distribution characteristics of the lattice basis vectors are calculated based on the orthogonal basis vector set, and a reduction termination condition is set according to the norm distribution characteristics. An iterative reduction operation is performed on the orthogonal basis vector group. In each iteration, the projection coefficients between the current basis vector and the target basis vector are calculated. The current basis vector is updated using the projection coefficients. The iteration terminates when the norm of the current basis vector satisfies the reduction termination condition. Extract the vectors that satisfy the short vector property from the reduced lattice basis matrix as short vector private keys. Construct coefficient vectors based on the short vector private keys. Perform modular multiplication on the coefficient vectors in a preset polynomial ring to generate the first polynomial component. Construct a random perturbation polynomial matrix. Perform a combination of modular addition and modular multiplication on the first polynomial component and the random perturbation polynomial matrix in the modular operation ring to obtain the public key polynomial matrix.

3. The method according to claim 1, characterized in that, Extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain an identity digest vector. Embed the identity digest vector bitwise into the public key multinomial matrix, and fuse them through modular addition to generate an identity-binding public key. Record the index sequence of the embedding positions, including: The hardware physical address of the edge node is obtained and converted into a binary bit string. A grouped cyclic shift operation is performed on the bit string to generate a shifted group sequence. A nonlinear hybrid operation is then performed to obtain the initial identity feature. The initial identity feature is then transformed into a collision-resistant hash value through a dynamic lattice basis reduction transformation. This hash value is then combined with the binary bit string for a second hash operation to obtain a fixed-length identity digest vector. Extract the coefficients of the highest degree terms of each polynomial in the public key polynomial matrix to form a public key feature coefficient sequence, and perform an XOR operation with the identity digest vector to obtain a fused feature vector; Based on the fused feature vector, a dynamic pseudo-random number seed is calculated to generate a polynomial mapping matrix. The identity digest vector is then converted into an identity feature polynomial through the polynomial mapping matrix. Based on the coefficient distribution of the identity feature polynomial, the optimal embedding position sequence is determined. At the position corresponding to the optimal embedding position sequence, the basis vectors of the original polynomial are extracted to construct a lattice basis transformation matrix. The lattice basis transformation matrix is ​​multiplied by the identity feature polynomial to generate the embedded identity binding polynomial. The original polynomial at the corresponding position in the public key polynomial matrix is ​​replaced. The overall matrix after replacement is normalized by modulo operation to generate the identity binding public key.

4. The method according to claim 3, characterized in that, The initial identity features are transformed into collision-resistant hash values ​​through dynamic lattice basis reduction, and then combined with the binary bit string for further hashing to obtain a fixed-length identity digest vector, including: The initial identity features are segmented and mapped according to a preset vector dimension to generate initial feature vectors. By performing a cyclic shift transformation on the initial feature vectors, the row vectors of the lattice basis matrix are generated. Perform orthogonal decomposition on the lattice basis matrix to obtain an orthogonal matrix and an upper triangular matrix. Calculate the average value of the diagonal elements of the upper triangular matrix as the lattice basis reduction eigenvalue. Calculate the inner product of the first and last column vectors of the orthogonal matrix to obtain the orthogonal eigenvalue. Perform a hybrid hash operation on the lattice basis reduction eigenvalue and the orthogonal eigenvalue to generate a collision-resistant hash value, and write it into the feedback state register as the initial state. After the binary bit string is divided into blocks, it is concatenated with the current value of the feedback status register and hashed sequentially. The feedback status register is updated by XOR operation to obtain the cascaded feedback hash value. The Shannon entropy of the cascaded feedback hash value is calculated. The adaptive segmentation position is determined according to the ratio of the Shannon entropy to the information entropy threshold, and the segments are cut to form a fixed-length identity digest vector.

5. The method according to claim 1, characterized in that, Based on the short vector private key, a lattice basis intermediate state matrix is ​​generated, and a dynamic lattice basis chain is generated through recursive reconstruction. Combined with the peer index sequence, a hierarchical reduction operation is performed on the peer identity-bound public key. Based on the reduction result, quantum-resistant intermediate session parameters are generated, including: The short vector private key is mapped to the lattice basis space to generate a lattice basis intermediate state matrix, and the norm distribution features of the lattice basis vectors in the lattice basis intermediate state matrix are extracted. Based on the norm distribution characteristics, a lattice base state transition probability matrix is ​​generated. Multiple candidate lattice base states are obtained by performing randomized transition sampling on the current lattice base state through recursive iteration. The quality score of each candidate lattice base state is calculated. The candidate lattice base state with the highest quality score is selected as the current iteration output. The lattice base states and their transition probabilities output by each iteration are organized in the iteration order to form a dynamic lattice base chain. Based on the peer index sequence, the embedding position information in the peer identity binding public key is extracted, and the reverse separation operation is performed to obtain the peer public key polynomial matrix and the peer identity digest vector. Traverse the lattice base states of each layer in the dynamic lattice base chain, perform a reduction operation on each layer lattice base state and the peer public key polynomial matrix to obtain a reduction intermediate result, use the transition probability as a weight coefficient, and perform probability weighted fusion on each layer reduction intermediate result to generate a hierarchical reduction result. Extract the error vector from the hierarchical reduction result, and perform a modular operation to fuse the error vector with the peer identity digest vector to generate intermediate session parameters with quantum resistance.

6. A lightweight quantum-resistant key negotiation protocol system for edge computing, used to implement the method as described in any one of claims 1-5, characterized in that, include: The first unit is used to obtain the lattice password parameters of the edge nodes; The second unit is used to generate a short vector private key based on the lattice cryptography parameters through lattice basis reduction operations, and to generate a public key polynomial matrix on the modular arithmetic ring using the short vector private key. The third unit is used to extract the hardware physical address of the edge node and perform a collision-resistant hash operation to obtain an identity digest vector. The identity digest vector is then embedded bit by bit into the public key polynomial matrix, and the identity binding public key is generated by fusion through modular addition operation. The index sequence of the embedding position is recorded. The fourth unit is used to send the identity binding public key and the index sequence to the peer edge node, and receive the peer identity binding public key and the peer index sequence returned by the peer edge node; The fifth unit is used to generate a lattice basis intermediate state matrix based on the short vector private key, and generate a dynamic lattice basis chain through recursive reconstruction. Combined with the peer index sequence, it performs a hierarchical reduction operation on the peer identity binding public key, and generates quantum-resistant intermediate session parameters based on the reduction result. The sixth unit is used to generate a resource weight vector based on the computing performance and communication bandwidth status of the edge nodes, perform adaptive sparsification processing on the intermediate session parameters and perform lattice basis projection operation, generate a weighted projection result by combining the resource weight vector, and generate a lightweight session key through vector compression.

7. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Lattice encryption-based end-to-end data confidentiality and integrity protection method

    CN113242129A

  • Lightweight hybrid encryption transmission method and system capable of resisting quantum attack

    CN120675692A