Method, device and medium for determining and security evaluating update period of quantum key

By constructing an objective function that distinguishes the advantage function, the security level of the quantum key is quantified, solving the problem of unreasonable quantum key update cycle in existing technologies. This enables accurate determination of quantum key security assessment and update cycle, optimizing the security and cost-effectiveness of the encryption system.

CN121508856BActive Publication Date: 2026-03-27CAS QUANTUM NETWORK CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-12
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing encrypted communication schemes, when combined with quantum keys and block ciphers, cannot effectively quantify the security level, resulting in unreasonable quantum key update cycles, which may lead to the risk of breaching the key security boundary or an imbalance between cost and benefit.

Method used

By constructing an objective function based on the distinguishing advantage function, the security level of quantum keys is quantified, the maximum number of files that a single quantum key can encrypt is determined, and the update cycle of quantum keys is determined according to security parameters, number of blocks, and security level. Precise quantization is then performed in combination with different block cipher modes.

Benefits of technology

It achieves the quantization of the security level of quantum keys, ensuring that the security of the encryption system is always kept at the lowest permissible level, avoiding the risk of key security boundary breach, and optimizing the cost-effectiveness ratio.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508856B_ABST
    Figure CN121508856B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of quantum keys, and discloses a method and equipment for determining and security evaluating the update period of a quantum key, and a medium. The method comprises the following steps: acquiring a security parameter, a group number, a lower bound of a security level, and a lowest allowed security level; determining a maximum encryptable file quantity of a single quantum key according to the security parameter, the group number, the lower bound of the security level, the lowest allowed security level, and a target function, wherein the target function is a function for describing the correlation between the security level of the quantum key and the encryptable file quantity of the quantum key, and the target function is determined according to a discrimination advantage function under CPA; and determining a quantum key encryptable file quantity that is not greater than the maximum encryptable file quantity of the single quantum key, and taking the quantum key encryptable file quantity as the update period of the quantum key. The method quantifies the security level of the quantum key and the group cipher combined application to encrypted communication, thereby determining a reliable quantum key update period and reliably security evaluating the quantum key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum key technology, and in particular to a quantum key update period determination and security evaluation method, device and medium. BACKGROUND

[0002] A block cipher is a symmetric key cipher system, which divides plaintext into fixed length groups, and each group is encrypted by the same key to generate corresponding ciphertext blocks. In order to further ensure the security of encrypted communication, a quantum key distributed through a quantum key distribution (QKD) network can be used to replace the key negotiated in the traditional way.

[0003] At present, there is an urgent need for a combination of the above block cipher and quantum key encryption communication scheme to provide a corresponding quantification scheme for the security level of the encryption system to guide the implementation and analysis of the encryption system. SUMMARY

[0004] In the present application, a quantum key update period determination and security evaluation method, device and medium are provided, which quantifies the security level of the combination of quantum keys and block ciphers applied to encrypted communication, and further determines a reliable quantum key update period and dynamically evaluates the security of quantum keys.

[0005] The first aspect of the present application provides a quantum key update period determination method, comprising: obtaining a security parameter, a block number, a lower bound of a security level and a minimum allowed security level; determining a maximum encryptable file quantity of a single quantum key according to the security parameter, the block number, the lower bound of the security level, the minimum allowed security level and a target function, wherein the target function is a function describing the correlation between the security level of the quantum key and the encryptable file quantity of the quantum key according to a distinguishing advantage function under CPA; determining a quantum key encryptable file quantity that is not greater than the maximum encryptable file quantity of the single quantum key as the update period of the quantum key.

[0006] The second aspect of the present application further provides a quantum key security evaluation method, comprising: obtaining a security parameter, a block number, a lower bound of a security level and an update period of a quantum key; determining a security level of the quantum key according to the security parameter, the block number, the lower bound of the security level, the update period of the quantum key and a target function, wherein the update period of the quantum key indicates the encryptable file quantity of a single quantum key, and the target function is a function describing the correlation between the security level of the quantum key and the encryptable file quantity of the quantum key according to a distinguishing advantage function under CPA.

[0007] The third aspect of the present application further provides an electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to the first aspect or the second aspect.

[0008] The fourth aspect of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method according to the first aspect or the second aspect.

[0009] The technical solutions provided in the present application have at least the following advantages:

[0010] By constructing a target function for describing the correlation between the security level of the quantum key distribution system and the quantum key encryption file quantity according to the discrimination advantage function under the CPA, the security level of the quantum key and the block cipher combined application to the encrypted communication can be quantitatively described based on the quantum key encryption file quantity, so that after obtaining the security parameters, the number of blocks and the minimum security level, the maximum encryptable file quantity of a single quantum key of the quantum key distribution system can be determined, and a reliable quantum key update cycle can be determined, or after obtaining the security parameters, the number of blocks and the update cycle of the quantum key, the quantum key can be dynamically evaluated. BRIEF DESCRIPTION OF DRAWINGS

[0011] One or more embodiments are illustrated by way of example in the drawings in which like reference numerals indicate like elements, and in which:

[0012] Figure 1 is a flowchart of a method for determining an update cycle of a quantum key according to an embodiment of the present application;

[0013] Figure 2 is a flowchart of a method for determining an update cycle of a quantum key according to another embodiment of the present application;

[0014] Figure 3 is a flowchart of a method for evaluating the security of a quantum key according to another embodiment of the present application;

[0015] Figure 4 is a schematic diagram of an evaluation analysis scenario according to another embodiment of the present application;

[0016] Figure 5 is a structural schematic diagram of an electronic device according to another embodiment of the present application. DETAILED DESCRIPTION

[0017] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with the accompanying drawings. However, it can be understood by those skilled in the art that, in the embodiments of the present application, many technical details are proposed in order to make the readers better understand the present application. However, the technical solutions claimed by the present application can be implemented even if there are no such technical details and various changes and modifications based on the following embodiments.

[0018] The division of the following embodiments is for the convenience of description, and should not constitute any limitation on the specific implementation modes of the present application. The embodiments can be combined and referenced with each other on the premise of no contradiction.

[0019] For the traditional encryption scheme, that is, the scheme of encryption by the key determined through negotiation of the classic communication network (such as the 5th Generation Mobile Communication Technology (5G) communication network, etc.), the security evaluation scheme is mainly provided from two technical routes of asymptotic security and specific security. The following will illustrate these two technical ideas.

[0020] For asymptotic security, the security evaluation of the encryption scheme is characterized by the probability of the success of the enemy in destroying the system under a specific attack model. Taking the adopted Chosen-Plaintext Attack (CPA) as an example, it is assumed that the enemy can access the encryption machine without the key, and if the number of times of accessing the encryption machine by the enemy is , the probability of the success of the attack can be represented by the function of the security parameter and , that is, the probability of the success of the enemy in breaking the system within queries. Under this technical idea, it is considered that: for any natural number (an auxiliary parameter for generalization expression) and (a polynomial amplification of the computing resources of the enemy), there exists (a critical value of the security length), when the security parameter and , there is . That is, if the security parameter of an encryption scheme is sufficiently large, and the computing resources of the enemy are limited to the polynomial time of , the scheme can achieve the target security requirement, wherein represents a polynomial about .

[0021] For specific security, it is required to give the probability of the success of the attack of the enemy Instead of relying on the limit property of the function, the explicit expression of the function is used. After obtaining the explicit expression of the function, the quantization design of the security parameter can be performed. Generally, the maximum resource used by the enemy and the maximum probability of success allowed are set first. The minimum is the security parameter that should be deployed by the system.

[0022] As can be seen, asymptotic security describes the qualitative security guarantee of the encryption system (by proving that there is a large enough security parameter so that the attack probability can be ignored), and the goal is to solve the existence problem of the secure encryption scheme; and the specific security provides a quantitative analysis method of security strength (by explicit calculation of the function ), aiming to solve the problem of setting the security parameter λ in actual deployment.

[0023] However, when quantum keys are combined with block ciphers and applied to encrypted communication, the more urgent needs are the setting of the update period of the quantum key, and the dynamic benefit description of the security level. The above two schemes cannot meet the needs.

[0024] However, through analysis of the above needs, it is found that the core problem is how to quantify the security level of the quantum key to guide the determination of the update period of the quantum key and the dynamic evaluation of the security level. Thus, the risk of breaking the security boundary of the key due to too low rotation frequency and the problem of unbalanced cost-benefit ratio due to too frequent rotation can be avoided. At the same time, through reliable security evaluation, a more suitable encryption system can be designed through the balance between security and operation benefit.

[0025] Further, the embodiment of the present application proposes a key update period determination method, a security evaluation method, equipment and medium, based on the security boundary determination (such as the collision resistance strength of AES (Advanced Encryption Standard)-256, the linear analysis threshold of SM4 (a kind of national secret algorithm), etc.) of the block cipher system. Target function to quantify the security level of the quantum key, and through the equivalent random key length (equivalent entropy value) of the session key and other quantum keys generated by the AKE (Authenticated Key Exchange) mode, the security level of the quantum key can be accurately defined and quantified. Under ideal conditions, the quantum key can realize information theory security, that is, the equivalent random key length of the key itself, to guide the key replacement period and security evaluation.

[0026] In the block cipher scheme, the basic cryptographic function module (such as a block cipher algorithm, a pseudo-random number generator or a pseudo-random function) is a predefined and theoretically verified component, and its security indicators (usually defined as the advantage of distinguishing under some oracle attack (padding oracle attack)) have been widely accepted by the cryptography community. In order to expand the function to process long files and multi-file streams, different working modes (such as CBC (Cipher-block chaining, password block chaining) mode or CTR (Counter, counter) mode, etc.) need to be used, and the expansion will cause the security strength to decay, that is, when the working mode is repeatedly encrypted under a single key, the theoretical security boundary will significantly decrease with the increase of the number of processed files and the increase of the file length. In addition, if a quantum key is introduced, changing the key every file or every block during encryption can keep the security at a high level, but this method is limited by the quantum key distribution rate and lacks practicality. Therefore, in the embodiments of the present application, the decay of security is inhibited by periodically updating the working key, that is, there is a relationship between the update period and the security, and the security level of the quantum key is quantified by providing an objective function to describe the relationship.

[0027] Based on this, the embodiments of the present application provide a quantum key security evaluation method, which is applied to any electronic device, device, etc. with computing power, such as servers, user terminals, etc. The following will be described in conjunction with the flowchart shown in Figures 1-5 .

[0028] In some embodiments, as shown in Figure 1 , the method for determining the update period of the quantum key comprises the following steps:

[0029] Step 101, obtaining security parameters, block numbers, lower bounds of security levels, and allowed minimum security levels.

[0030] Step 102, determining the maximum number of encrypted files of a single quantum key according to the security parameters, the block numbers, the lower bounds of the security levels, the allowed minimum security levels, and an objective function, wherein the objective function is a function that describes the correlation between the security level of the quantum key and the number of encrypted files of the quantum key according to the advantage function under CPA.

[0031] Step 103, determining a number of encrypted files of the quantum key that is not greater than the maximum number of encrypted files of a single quantum key as the update period of the quantum key.

[0032] In Figure 1In the illustrated embodiment, by constructing a target function describing the correlation between the security level of the quantum key distribution system and the quantum key encrypted file quantity determined according to the advantage function under CPA, the security level of the quantum key and the block cipher combined application to the encrypted communication can be quantitatively described based on the quantum key encrypted file quantity, so that after obtaining the security parameter, the number of blocks and the allowed minimum security level, the maximum encryptable file quantity of a single quantum key of the quantum key distribution system can be determined, and the quantum key encrypted file quantity not greater than the maximum encryptable file quantity of a single quantum key is determined as a reliable quantum key update period, so that through the update of the quantum key, the security level of the encryption system is always not lower than the allowed minimum security level.

[0033] For ease of understanding Figure 1 In the illustrated embodiment, the steps thereof will be described below.

[0034] In step 101, the security parameter is the security parameter of the block cipher algorithm, the number of blocks is the number of blocks required to be divided when data of a preset length is encrypted according to the block length of the block cipher algorithm, the lower bound of the security level is the lower bound of the average security level of the block cipher algorithm, and the allowed minimum security level is the lowest security level required to be met.

[0035] It should be noted that for a certain block cipher algorithm, the security parameter, the number of blocks and the lower bound of the security level are determined values, and the allowed minimum security level can be determined according to application scenarios, user requirements, etc.

[0036] In some embodiments, a data table can be pre-set, in which different block cipher algorithms and their corresponding security parameters, numbers of blocks and lower bounds of security levels are maintained, so that the security parameter, the number of blocks and the lower bound of the security level can be obtained by table lookup, and the allowed minimum security level can be actively input by the user, of course, the allowed minimum security level can also be maintained by the data table, or the security parameter, the number of blocks and the lower bound of the security level are input by the user, which will not be enumerated here.

[0037] In step 102, the target function can be any function capable of determining the correlation between the security level of the quantum key and the quantum key encrypted file quantity according to the advantage function under CPA.

[0038] In some embodiments, the target function is associated with the block mode of the block encryption used by the encryption system. Thus, by providing corresponding target functions for different block modes, the quantification of the security level is more accurate, and the quantum key update period obtained is more accurate.

[0039] In some embodiments, when the quantum key is the key of a block cipher algorithm in CTR mode, the objective function can include:

[0040] ;

[0041] wherein, f is the objective function, Q is the encryptable file volume of a single quantum key, l is the number of blocks, is the lower bound of security level, N = 2^λ, λ is a security parameter.

[0042] In some embodiments, when the quantum key is the key of a block cipher algorithm in CBC mode, the objective function can include:

[0043] ;

[0044] wherein, f is the objective function, Q is the encryptable file volume of a single quantum key, l is the number of blocks, is the lower bound of security level, N = 2^λ, λ is a security parameter.

[0045] In some embodiments, when the quantum key is the key of a block cipher algorithm in ECBC-MAC (Electronic Codebook Message Authentication Code) mode, the objective function can include:

[0046] ;

[0047] wherein, f is the objective function, Q is the encryptable file volume of a single quantum key, l is the number of blocks, is the lower bound of security level, N = 2^λ, λ is a security parameter.

[0048] Of course, the above is only an example, and the expression of the objective function can be different according to different modeling methods and mathematical processing methods, for example, in some embodiments, the objective function can be: and so on, which will not be listed one by one here.

[0049] In order to facilitate the understanding of the execution of step 102, the following will be described by taking the objective function when the quantum key is the key of a block cipher algorithm in CTR mode as an example.

[0050] It is known that the objective function is: ;

[0051] and N = 2A.

[0052] Therefore, after obtaining the security parameter λ, the number of groups l , the lower bound of the security level and the allowed minimum security level f , the maximum encryptable file amount of a single quantum key is determined, that is, to solve the following equation with the unknown number Q .

[0053] In step 103, the embodiments of the present application do not limit the strategy that is not greater than the maximum encryptable file amount of a single quantum key. In some embodiments, the update period of the quantum key can be selected by considering the cost of updating the quantum key, with the cost and the maximum encryptable file amount of a single quantum key as constraints; in some embodiments, the selection can be made by considering the security improvement effect of the quantum key encryptable file amount relative to the maximum encryptable file amount of a single quantum key; in some embodiments, it can be arbitrarily selected to be not greater than the maximum encryptable file amount of a single quantum key; in some embodiments, it can be selected to be 0.7 times the maximum encryptable file amount of a single quantum key, etc.

[0054] In some embodiments, the quantum key encryptable file amount that is not greater than the maximum encryptable file amount of a single quantum key, which is used as the update period of the quantum key, can be realized by the following way: according to the security parameter, the number of groups, the lower bound of the security level, the candidate quantum key encryptable file amount and the objective function, the security level improvement degree of each candidate quantum key encryptable file amount relative to the maximum encryptable file amount of a single quantum key is evaluated, wherein each candidate quantum key encryptable file amount is a quantum key encryptable file amount that is not greater than the maximum encryptable file amount of a single quantum key; according to the security level improvement degree of each candidate quantum key encryptable file amount relative to the maximum encryptable file amount of a single quantum key, the quantum key encryptable file amount that is used as the update period of the quantum key is determined from the candidate quantum key encryptable file amount and the maximum encryptable file amount of a single quantum key.

[0055] Thus, by evaluating the security level improvement degree of the candidate quantum key encryptable file amount that is not greater than the maximum encryptable file amount of a single quantum key relative to the maximum encryptable file amount of a single quantum key, the effect improvement of the candidate quantum key encryptable file amount relative to the maximum encryptable file amount of a single quantum key is quantified, thereby providing reliable guidance for the determination of the update period of the quantum key, which is conducive to more reasonably and accurately determining the update period of the quantum key.

[0056] ​In some embodiments, the degree of security level improvement of each candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key can be evaluated according to the security parameter, the number of groups, the security level lower bound, the candidate quantum key encryption file amount, and the objective function, by determining the security level of each candidate quantum key encryption file amount according to the security parameter, the number of groups, the security level lower bound, the candidate quantum key encryption file amount, and the objective function, and determining the difference between the security level of each candidate quantum key encryption file amount and the security level of the maximum encryptable file amount of a single quantum key as the degree of security level improvement of the corresponding candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key.

[0057] Of course, the above is only an example, and in some embodiments, other strategies can be used to evaluate the degree of security level improvement of the candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key, for example, the difference between the security level of the candidate quantum key encryption file amount and the security level of the maximum encryptable file amount of a single quantum key can be further processed and then used as the degree of security level improvement of the candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key, which will not be listed one by one here.

[0058] In some embodiments, the quantum key encryption file amount serving as the update period of the quantum key can be determined from the candidate quantum key encryption file amount and the maximum encryptable file amount of a single quantum key according to the degree of security level improvement of each candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key, by obtaining the cost parameter of a single quantum key, determining the security benefit of each candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key according to the degree of security level improvement of the candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key and the cost parameter of a single quantum key, and determining the quantum key encryption file amount serving as the update period of the quantum key from the candidate quantum key encryption file amount and the maximum encryptable file amount of a single quantum key according to the security benefit of each candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key.

[0059] Thus, by combining the cost of the quantum key with the security benefit analysis of the quantum key, i.e., the security measurement between the unit key multiplexing and the cost, the setting of the quantum key distribution system can be better guided.

[0060] In some embodiments, the security benefit of each candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key can be determined according to the degree of security level improvement of the candidate quantum key encryption file amount relative to the maximum encryptable file amount of a single quantum key and the cost parameter of a single quantum key, by the following expression:

[0061] Δ y = ( × f) / ( k × m );

[0062] Where, Δ y For the security benefits of quantum key distribution systems, The maximum number of files that can be encrypted with a single quantum key. f The degree of security improvement in the number of files encrypted by a candidate quantum key relative to the maximum number of files that a single quantum key can encrypt. k This refers to the increase in the number of quantum key updates when the number of files encrypted with a candidate quantum key is used as the quantum key update cycle, compared to using the maximum number of files encryptable with a single quantum key as the quantum key update cycle, provided that the number of encrypted files reaches the maximum number of encrypted files with a single quantum key. m The cost of a single quantum key.

[0063] Of course, the above are just examples. In some embodiments, the degree of security improvement and economic cost can be correlated in other ways, which will not be listed here.

[0064] It should be noted that the embodiments of this application do not limit the selection of the number of candidate quantum key encryption files. In some embodiments, the selection can be made by user input, and in some embodiments, it can be made according to a certain strategy.

[0065] In some embodiments, the size of the candidate quantum key encryption file can be determined by the following expression:

[0066] ;

[0067] in, The number of files encrypted using candidate quantum keys. The maximum number of files that can be encrypted with a single quantum key. The range of values ​​for is (0, 1).

[0068] In some embodiments, it is possible to let , =1, 2, 3, ..., T, where T is a preset integer, or T is an integer that satisfies the following conditions: , The minimum allowed quantum key update cycle.

[0069] As mentioned earlier, the objective function can vary depending on the block pattern of the block cipher algorithm. Based on this, in some embodiments, such as...Figure 2 As shown, the method for determining the update period of the quantum key may include the following steps:

[0070] Step 201: Obtain the safety parameters, number of groups, safety level definitive boundary, and minimum permissible safety level.

[0071] Step 202: Obtain the current working mode, which is one of the following modes: CTR mode, CBC mode, or ECBC-MAC mode.

[0072] Step 203: Find the objective function corresponding to the current working mode.

[0073] Step 204: Determine the maximum number of files that a single quantum key can encrypt based on security parameters, number of groups, security level sublimit, minimum allowable security level, and objective function. The objective function is a function that describes the relationship between the quantum key security level and the number of quantum key encrypted files, determined based on the distinguishing advantage function under CPA.

[0074] Step 205: Determine a quantum key encryption file size that is no larger than the maximum number of files that a single quantum key can encrypt, as the quantum key update cycle.

[0075] exist Figure 2 In the illustrated embodiment, based on the ability to quantify the security level of combining quantum keys and block ciphers in encrypted communication according to the number of encrypted files, and to determine the maximum number of encrypted files that a single quantum key in a quantum key distribution system can encrypt, as well as to determine a reliable quantum key update cycle, corresponding objective functions are further provided for different block patterns, making the quantization of the security level more accurate, and thus the obtained quantum key update cycle more accurate.

[0076] It is not hard to see that Figure 2 The illustrated embodiment is similar to... Figure 1 The method embodiments shown correspond to the method embodiments. Figure 2 The illustrated embodiment can be compared with Figure 1 The embodiments shown are implemented in combination. Figure 1 The relevant technical details mentioned in the illustrated embodiments are as follows: Figure 2 The illustrated embodiments are still effective, and will not be repeated here to avoid repetition.

[0077] Accordingly, embodiments of this application also provide a method for security evaluation of quantum keys. In some embodiments, such as Figure 3 As shown, the security assessment method for quantum keys may include the following steps:

[0078] In step 301, the security parameter, the number of groups, the lower bound of the security level, and the update period of the quantum key are obtained.

[0079] In step 302, the security level of the quantum key is determined according to the security parameter, the number of groups, the lower bound of the security level, the update period of the quantum key, and the objective function, wherein the update period of the quantum key indicates the number of encrypted files allowed by a single quantum key, and the objective function is a function describing the correlation between the security level of the quantum key and the number of encrypted files of the quantum key, which is determined according to the discrimination advantage function under CPA.

[0080] In Figure 3 In the embodiment shown, by constructing the objective function describing the correlation between the security level of the quantum key distribution system and the number of encrypted files of the quantum key, which is determined according to the discrimination advantage function under CPA, the security level of the quantum key combined with the block cipher applied to the encrypted communication can be quantitatively described based on the number of encrypted files of the quantum key, so that the security of the quantum key can be dynamically evaluated after the security parameter, the number of groups, and the update period of the quantum key are obtained.

[0081] It can be found that, Figure 3 The embodiment shown is a method embodiment corresponding to the method embodiment shown in Figure 1 The embodiment shown can be implemented in cooperation with the embodiment shown in Figure 3 The embodiment shown can be implemented in cooperation with the embodiment shown in Figure 1 The embodiment shown can be implemented in cooperation with the embodiment shown in Figure 1 The related technical details mentioned in the embodiment shown are still valid in the embodiment shown, and in order to reduce repetition, they will not be described here. Figure 3

[0082] In order to facilitate the understanding of the above-mentioned embodiments, the derivation of the objective function will be explained and the application example of the corresponding objective function in the above-mentioned method flow will be provided.

[0083] In the embodiment of the present application, the security parameter is the discrimination advantage of the cipher module , specifically, in the security evaluation of the encryption system, the cipher module (usually using a standardized block cipher algorithm such as AES or SM4, or a derivative scheme based thereon) as a basic component, its security has been verified through long-term cryptanalysis, and the result is known. For example, by using the current internationally recognized optimal attack algorithm , the discrimination advantage of its pseudo-random function can be quantified as:

[0084] ;

[0085] wherein, is the security parameter (such as the key length), ​The maximum number of queries for an attacker. In the case of block cipher algorithm solicitations The value is determined, as the analysis of the cryptographic community continues to deepen (reflected in the attack algorithm efficiency is improved), The average security level of the widely deployed core algorithm has a clear lower bound (unit: bits), which represents the minimum security strength of the algorithm against unit attack cost.

[0086] In an embodiment of the present application, the minimum security level allowed is determined by the security requirements of users and the like, and can be obtained in the following ways: user customization or negotiation and confirmation by the password system designer and the user.

[0087] In an embodiment of the present application, the number of blocks refers to the maximum number of blocks of a single file , which is used to define the upper limit of the number of encrypted blocks into which a single file is divided, and can be flexibly adjusted according to the actual application scenario.

[0088] In an embodiment of the present application, the advantage function under CPA refers to the advantage function when the encryption scheme is CPA-secure and the authentication scheme is existentially unforgeable under adaptive chosen message attacks (EUF-CMA).

[0089] It should be noted that due to different modeling methods of the encryption system applied after the combination of the quantum key and the block cipher, different target functions will be obtained, and the embodiments of the present application do not limit this, and the following mainly provides exemplary descriptions. The following mainly provides some exemplary descriptions.

[0090] In some embodiments, given an encryption scheme and its security definition under CPA, i.e., the advantage function of the adversary is denoted as CPAadv[ ], and its guessing advantage is defined as:

[0091] CPAadv[ ];

[0092] wherein is a security parameter, is the number of times the adversary accesses the encryption oracle.

[0093] Based on this, the security level of the quantum key is quantified by the following index:

[0094] ​Upper bound of query times: set For the adversary The maximum number of queries to the encryption system;

[0095] Worst-case security strength:

[0096] (unit: bits);

[0097] This value represents the resistance of the system to the optimal attack strategy, that is, the adversary adjusts to find the weakest link of the system.

[0098] Correspondingly, the average-case security strength is:

[0099] (unit: bits);

[0100] This value reflects the robustness of the system under typical attack scenarios, that is, the number of attempts required by the adversary per unit success rate.

[0101] Therefore, based on the above definitions, further modeling can be carried out in combination with the specific use process of quantum keys, and the corresponding objective function can be obtained by bringing the above expressions.

[0102] In some embodiments, in the CTR mode, the objective function includes:

[0103] ;

[0104] wherein, f is the objective function, Q is the encryptable file amount of a single quantum key, l is the number of groups, is the lower bound of the security level, N=2^λ, and λ is the security parameter.

[0105] In some embodiments, in the CBC mode, the objective function includes:

[0106] ;

[0107] wherein, f is the objective function, Q is the encryptable file amount of a single quantum key, l is the number of groups, is the lower bound of the security level, N=2^λ, and λ is the security parameter.

[0108] In some embodiments, in the ECBC-MAC mode, the objective function includes:

[0109] ;

[0110] wherein,f ( ) is a target function, Q is the maximum encryptable file quantity of a single quantum key, l is the number of groups, is the lower bound of the security level, N = 2^λ, and λ is a security parameter.

[0111] In order to facilitate understanding of the above target function, the derivation of the target function will be described below by taking the CTR mode as an example.

[0112] Based on the advantage of differentiation The system is modeled as follows:

[0113] (1).

[0114] Engineering approximation processing:

[0115] For mainstream block cipher algorithms (such as SM4, AES, 3DES (Triple Data Encryption Algorithm), or pseudo-random functions constructed therefrom, when is not too large, the average security lower bound is a known constant, and satisfies (that is, of the same order of magnitude as ). At this time, we have:

[0116] ;

[0117] That is, .

[0118] Substituting the above formula into expression (1) gives:

[0119] .

[0120] Therefore, in order to determine the maximum encryptable file quantity of a single quantum key, it is necessary to solve , that is, to solve the positive integer root of At this time, it will be obtained that: the average security lower bound of the block cipher module is , and in order to ensure that the CTR mode encryption system reaches the preset security strength (that is, the expected security level), the maximum encryptable file quantity of a single quantum key is about .

[0121] In the embodiments of the present application, the quantification method of the security level of the quantum key is not limited, and it can be determined according to the scene, demand, actual cost generation, etc. For example, in some embodiments, according to the security level of the quantum key and the cost of the quantum key, the security benefit of the quantum key distribution system is determined, which is realized through the following expression:

[0122] Δ y = ( × f) / ( k × m );

[0123] Where, Δ y For the security benefits of quantum key distribution systems, The maximum number of files that can be encrypted with a single quantum key. f The degree of security improvement in the number of files encrypted by a candidate quantum key relative to the maximum number of files that a single quantum key can encrypt. k This refers to the increase in the number of quantum key updates when the number of files encrypted with a candidate quantum key is used as the quantum key update cycle, compared to using the maximum number of files encryptable with a single quantum key as the quantum key update cycle, provided that the number of encrypted files reaches the maximum number of encrypted files with a single quantum key. m The cost of a single quantum key.

[0124] In other words, in CTR mode, based on the key replacement cycle As a result, the worst-case security level of the encryption system is:

[0125] ;

[0126] in, This indicates the maximum number of files that a single quantum key can encrypt (i.e., the key replacement cycle).

[0127] If two key swaps are performed evenly (i.e., the number of files encrypted with a single quantum key is reduced to...), That is, adopt As a candidate quantum key for encrypting files, the security level improvement is:

[0128] (Unit: bits)

[0129] The above equation can be simplified to:

[0130] (Unit: bits)

[0131] Therefore, halving the key replacement cycle can improve the security level by 1 to 2 bits (strictly greater than 1 bit and less than 2 bits).

[0132] Furthermore, if executed uniformly Subkey replacement (i.e., reducing the number of files encrypted with a single key to...) That is, adopt As a candidate quantum key encryption file quantity, the security level improvement quantity is:

[0133] (unit: bit).

[0134] The above formula can be simplified as:

[0135] (unit: bit).

[0136] It can be seen that the uniform execution of key replacement can improve the security level by . bit.

[0137] Therefore, based on the current supported or expected bit number, the above expression can be used to analyze and guide the setting of the key replacement period.

[0138] As for the determination of the benefit, for an encryption system using a high-security pseudo-random function (or a block cipher algorithm) and a CTR working mode, when the maximum encryption file number of a single key is , the basic security strength guarantee is (unit: bit). When the value of is moderate, the uniform key replacement can obtain a security level improvement of about bit; thus, the security benefit can be modeled as follows:

[0139] .

[0140] The cost of a single quantum key is determined by the quantum cryptography infrastructure operator and the user.

[0141] Of course, the above is only an example, and in some cases, other ways of processing the security level as the gain brought by the security level can also be used.

[0142] Similarly, in the CBC mode, for determining the maximum encryption file quantity of a single quantum key, that is, solving the following expression (positive integer solution) :

[0143] = .

[0144] The worst-case security level is:

[0145] .

[0146] If the key replacement is uniformly executed twice (i.e., the number of encryption files of a single key is reduced to , i.e. using As the candidate quantum key encryption file quantity, the security level improvement is:

[0147] (unit: bit).

[0148] The above formula can be simplified as:

[0149] (unit: bit).

[0150] As can be seen, halving the key update period can improve the security level by 1~2 bits (strictly greater than 1 bit and less than 2 bits).

[0151] Further, if the key is replaced uniformly times (i.e. the number of single-key encrypted files is reduced to , i.e. using as the candidate quantum key encryption file quantity, the security level improvement is:

[0152] .

[0153] The above formula can be simplified as:

[0154] (unit: bit).

[0155] As can be seen, uniformly replacing the key times can improve the security level by ~2 bits.

[0156] The security benefit can be modeled as follows:

[0157] The security improvement benefit is: .

[0158] Similarly, in the ECBC-MAC mode, for determining the maximum number of encrypted files for a single quantum key, i.e. solving the following expression (positive integer solution) :

[0159] = .

[0160] The worst-case security level is:

[0161] .

[0162] If the key is replaced uniformly times (i.e. the number of single-key encrypted files is reduced to , i.e. using as the candidate quantum key encryption file quantity, the security level improvement is:

[0163] ] (unit: bit).

[0164] The above formula can be simplified as:

[0165] (unit: bit).

[0166] Therefore, halving the key replacement period can increase the security level by 1-2 bits (strictly greater than 1 bit and less than 2 bits).

[0167] Further, if the uniform execution key replacement (i.e., the number of single-key encrypted files is reduced to , that is, the number of candidate quantum key encrypted files is , the security level increases by:

[0168] ] (unit: bit).

[0169] The above formula can be simplified as:

[0170] (unit: bit).

[0171] Therefore, uniformly executing key replacement can increase the security level by ~ bits.

[0172] The security benefit can be modeled as follows:

[0173] .

[0174] For ease of understanding, the following will provide specific examples of the determination of the maximum number of files that can be encrypted by a single quantum key, and the security benefit evaluation when using the maximum number of files that can be encrypted by a single quantum key, with respect to the objective function of the above example.

[0175] In the scenario of the CTR mode of the SM4 algorithm combined with a quantum key, there are:

[0176] is an SM4 block cipher algorithm, and the block length and key length are both 128 bits, is the CTR mode of the SM4 block cipher algorithm.

[0177] Therefore, the security parameter is assumed to have a worst security level of 121 bits, i.e., the lower bound of the security level If the maximum length of a single file to be encrypted is 1.5 KB and the security level is guaranteed to be 80 bits, then the number of blocks ​the minimum allowed security level .

[0178] Then determine the maximum number of files that can be encrypted by a single quantum key , that is, solve the following equation:

[0179] .

[0180] At this time, . That is, the maximum number of files that can be encrypted by each quantum key is 1210759, and the maximum encrypted data volume is 1210759 x 1.5KB = 1816138.5KB ≈ 1773.5MB. That is, after each quantum key encrypts 1773.5MB of data, it should be replaced.

[0181] Suppose , that is, perform 2 key replacements uniformly (that is, the number of single-key encrypted files is reduced to ), and the security level is improved to:

[0182] .

[0183] Estimate the benefits of replacing a 128-bit quantum key ( ):

[0184] .

[0185] In the scenario of the CBC mode of the SM4 algorithm combined with quantum keys, we have:

[0186] SM4 is a block cipher algorithm, and the block length and key length are both 128 bits, is the CBC mode of the SM4 block cipher algorithm.

[0187] Therefore, the security parameter , assuming that its average security level is 121 bits, that is, the lower bound of the security level . If the maximum length of a single file to be encrypted is 1.5KB and the security level is guaranteed 80 bits of security level, then the number of blocks , the minimum allowed security level .

[0188] Then determine the maximum number of files that can be encrypted by a single quantum key , that is, solve the following equation:

[0189] .

[0190] At this time, 123575. That is, the maximum number of files that can be encrypted by each quantum key is 123575, and the maximum encrypted data amount is 123575 x 1.5KB = 185362KB ≈ 181MB. That is, after each quantum key encrypts 181MB of data, the key should be replaced.

[0191] Assume , that is, uniformly perform 2 key replacements (that is, the number of encrypted files by a single key is reduced to , the security level is improved to:

[0192] .

[0193] Estimate the benefits of replacing a 128-bit quantum key ( ):

[0194] .

[0195] In the scenario of combining quantum keys with the SM4 algorithm of the State Secret to construct MAC authentication code (that is, in the ECBC-MAC mode), we have:

[0196] is the SM4 block cipher algorithm, and the block length and key length are both 128 bits, is the MAC authentication code constructed by the CBC mode of the SM4 block cipher algorithm.

[0197] Therefore, the security parameter , assuming that its average security level is 121 bits, that is, the lower bound of the security level . If the maximum length of a single file to be encrypted is 1.5KB and the security level is guaranteed , there are 80 bits of security level, that is, the number of blocks , the minimum allowed security level .

[0198] Then determine the maximum number of encrypted files by a single quantum key , that is, solve the following equation:

[0199] .

[0200] At this time, 174700. That is, the maximum number of files that can be encrypted by each quantum key is 174700, and the maximum encrypted data amount is 174700 x 1.5KB = 262050KB ≈ 256MB. That is, after each quantum key encrypts 256MB of data, the key should be replaced.

[0201] Assume , that is, uniformly perform 2 key replacements (that is, the number of encrypted files by a single key is reduced to , the security level is improved to:

[0202] .

[0203] Estimate the benefit of replacing a 128-bit quantum key (QK)

[0204] .

[0205] Of course, the above is only an example, in some embodiments, other ways can also be used to model, so as to obtain other objective function expressions, which are not listed one by one here.

[0206] In order to better understand the application of the method provided by the above embodiment, the following will be described by taking the evaluation analysis scene of an encryption system realized by combining a quantum key and a block cipher as an example.

[0207] As shown in Figure 4 , the security parameters in the above example are determined by the pseudo-random generator adopted by the block cipher, the maximum length of a single file is determined according to the current working mode of the encryption system, so as to further determine the number of blocks. Based on the above security parameters, the number of blocks and the current replacement period of the quantum key, under the attacks of IND-CPA (Indistinguishability under Chosen-Plaintext Attack, Indistinguishability under Chosen-Plaintext Attack), EUF-CMA and the like, the corresponding security level will be generated, if it is detected that the security level is lower than the allowed minimum security level, then the allowed minimum security level is taken as the security index to adjust the update period of the quantum key, and based on the new update period and the allowed minimum security level, the gain of the current encryption system is determined.

[0208] The step division of the above methods is only for clear description, and can be combined into one step or split some steps into multiple steps in implementation, as long as the same logical relationship is included, all are within the protection scope of the present application; adding irrelevant modifications or introducing irrelevant designs in the algorithm or process, but not changing the core design of the algorithm and process are within the protection scope of the present application.

[0209] Correspondingly, the present application also provides an electronic device, as shown in Figure 5 , comprising: at least one processor 501; and a memory 502 communicatively connected with the at least one processor 501; wherein the memory 502 stores instructions executable by the at least one processor 501, and the instructions are executed by the at least one processor 501 to enable the at least one processor 501 to perform the method described in any of the above method embodiments.

[0210] ​The memory 502 and the processor 501 are connected in a bus manner, the bus can include any number of interconnected buses and bridges, the bus connects one or more processors 501 and various circuits of the memory 502 together. The bus can also connect various other circuits such as peripheral devices, voltage stabilizers and power management circuits together, which are well known in the art, therefore, they will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements such as multiple receivers and transmitters, which provide units for communicating with various other devices on the transmission medium. The data processed by the processor 501 is transmitted on the wireless medium through the antenna, further, the antenna also receives data and transmits the data to the processor 501.

[0211] The processor 501 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management and other control functions. And the memory 502 can be used to store the data used by the processor 501 in the execution operation.

[0212] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program. The computer program is executed by the processor to realize the method embodiment.

[0213] That is, those skilled in the art can understand that all or part of the steps of the above-mentioned embodiment methods can be completed by programs instructing relevant hardware, the programs are stored in a storage medium, and the programs include a plurality of instructions for making a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk and various program code storage media.

[0214] Those skilled in the art can understand that the above-mentioned embodiments are specific embodiments for implementing the present application, and in actual application, various changes can be made in form and details without departing from the spirit and scope of the present application.

Claims

1. A method for determining a refresh period of a quantum key, characterized by, The method comprises: obtaining a security parameter, a block number, a security lower bound and a minimum allowed security level; determining a single quantum key maximum encryptable file amount according to the security parameter, the block number, the security lower bound, the minimum allowed security level and an objective function, wherein the objective function is a function describing a correlation between a quantum key security level and a quantum key encryptable file amount, which is determined according to a distinguishing advantage function under CPA; determining a quantum key encryptable file amount not greater than the single quantum key maximum encryptable file amount as an update period of the quantum key; wherein, when the quantum key is a key of a block cipher algorithm in a CTR mode, the objective function comprises: ; wherein, f () is the objective function, Q is the number of encipherable files for a single quantum key, l is the number of groups, is the lower bound of the security level, λ is the security parameter; and / or, when the quantum key is a key of a block cipher algorithm in a CBC mode, the objective function comprises: ; wherein, f () is the objective function, Q is the encryptable file quantity of a single quantum key, l is the number of groups, is the lower bound of the security level, N = 2^λ, λ is the security parameter; and / or, when the quantum key is a key of a block cipher algorithm in an ECBC-MAC mode, the objective function comprises: ; wherein, f ( ) is the target function, Q is the number of encrypted files of a single quantum key, l is the number of groups, is the lower bound of the security level, N = 2^λ, λ is the security parameter.

2. The method of claim 1, wherein, The determination of the quantum key encryptable file amount not greater than the single quantum key maximum encryptable file amount as the update period of the quantum key comprises: evaluating a security level improvement degree of each candidate quantum key encryptable file amount relative to the single quantum key maximum encryptable file amount according to the security parameter, the block number, the security lower bound, the candidate quantum key encryptable file amount and the objective function, wherein each candidate quantum key encryptable file amount is a quantum key encryptable file amount not greater than the single quantum key maximum encryptable file amount; determining a quantum key encryptable file amount as the update period of the quantum key from the candidate quantum key encryptable file amount and the single quantum key maximum encryptable file amount according to the security level improvement degree of each candidate quantum key encryptable file amount relative to the single quantum key maximum encryptable file amount.

3. The method of claim 2, wherein, The candidate quantum key encryptable file amount is determined by the following expression: ; wherein, is the candidate quantum key encrypted file amount, is the single quantum key maximum encryptable file amount, the value range of is (0, 1).

4. The method of claim 2, wherein, The evaluation of the security level improvement degree of each candidate quantum key encryptable file amount relative to the single quantum key maximum encryptable file amount according to the security parameter, the block number, the security lower bound, the candidate quantum key encryptable file amount and the objective function comprises: determining a security level of each candidate quantum key encryptable file amount according to the security parameter, the block number, the security lower bound, the candidate quantum key encryptable file amount and the objective function; determining a difference between the security level of each candidate quantum key encryptable file amount and the security level of the single quantum key maximum encryptable file amount as a security level improvement degree of the corresponding candidate quantum key encryptable file amount relative to the single quantum key maximum encryptable file amount.

5. The method of claim 2, wherein, The quantum key encryption file amount as the update period of the quantum key is determined from the candidate quantum key encryption file amounts and the single quantum key maximum encryptable file amount according to the security level improvement degree of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount, comprising: obtaining a cost parameter of the single quantum key; determining the security benefit of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount according to the security level improvement degree of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount and the cost parameter of the single quantum key; determining the quantum key encryption file amount as the update period of the quantum key from the candidate quantum key encryption file amounts and the single quantum key maximum encryptable file amount according to the security benefit of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount.

6. The method of claim 5, wherein, The security benefit of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount is determined according to the security level improvement degree of each of the candidate quantum key encryption file amounts relative to the single quantum key maximum encryptable file amount and the cost parameter of the single quantum key, by the following expression: Δ y = ( × f) / ( 1 k × m ) ; wherein, Δ y is the security benefit of the quantum key distribution system, is the maximum encryptable file quantity of the single quantum key, f is the security level improvement degree of the candidate quantum key encryptable file quantity relative to the maximum encryptable file quantity of the single quantum key, k is the increased quantum key update times of the candidate quantum key encryptable file quantity relative to the maximum encryptable file quantity of the single quantum key as the update period of the quantum key, m is the cost of the single quantum key.

7. A method for security evaluation of quantum keys, characterized by, comprising: obtaining a security parameter, a number of groups, a lower bound of security level, and an update period of a quantum key; determining a security level of the quantum key according to the security parameter, the number of groups, the lower bound of security level, the update period of the quantum key, and an objective function, wherein the update period of the quantum key indicates an encryptable file amount allowed by a single quantum key, and the objective function is a function describing a correlation between the security level of the quantum key and the quantum key encryption file amount determined according to a discrimination advantage function under CPA; wherein when the quantum key is a key of a block cipher algorithm in CTR mode, the objective function comprises: ; wherein, f () is the objective function, Q is the number of encipherable files for a single quantum key, l is the number of groups, is the lower bound of the security level, λ is the security parameter; and / or, when the quantum key is a key of a block cipher algorithm in CBC mode, the objective function comprises: ; wherein, f () is the objective function, Q is the encryptable file quantity of a single quantum key, l is the number of groups, is the lower bound of the security level, N = 2^λ, λ is the security parameter; and / or, when the quantum key is a key of a block cipher algorithm in ECBC-MAC mode, the objective function comprises: ; wherein, f ( ) is the target function, Q is the encryptable file quantity of a single quantum key, l is the number of groups, is the lower bound of the security level, N = 2^λ, and λ is the security parameter.

8. An electronic device, comprising: comprising: at least one processor; and a memory in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 7.

9. A computer readable storage medium storing a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1 to 7. The computer program is executed by the processor to implement the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method, system and related device for adjusting quantum key renewal frequency

    CN109067519A

  • Quantum key fused block encryption method, communication system and evaluation method thereof

    CN120528592A