A control method of a multi-protocol switching quantum security-resistant gateway

By integrating a quantum-resistant cryptographic card and a multi-standard protocol dynamic conversion engine, dynamic quantum attack detection and millisecond-level encryption algorithm switching of the security gateway are realized, solving the problem that existing security gateways cannot adapt to quantum computing threats, and achieving efficient, secure quantum-resistant security conversion and compatibility.

CN121530577BActive Publication Date: 2026-04-07WEIDE GUANGDONG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-14
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing security gateways cannot dynamically adapt to quantum computing threats, cannot seamlessly switch between or mix classical and quantum-resistant algorithms, resulting in security response gaps, incompatibility with multiple cryptographic standards, and affecting the smooth transition from classical security to quantum-resistant security.

Method used

It adopts a layered, three-dimensional protection architecture, integrating a quantum-resistant cryptographic card, a multi-standard protocol dynamic conversion engine, and a quantum-safe authentication mechanism. It can detect quantum attacks in real time, switch encryption algorithms in milliseconds, achieve seamless conversion between traditional and quantum-resistant algorithms, and support compatibility with multiple cryptographic standards.

Benefits of technology

It achieves proactive quantum security protection, dynamically adapts to quantum computing threats, ensures the confidentiality and integrity of information, supports seamless conversion and compatibility of multiple standard protocols, and reduces operational complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530577B_ABST
    Figure CN121530577B_ABST
Patent Text Reader

Abstract

This application relates to a control method for a multi-protocol switching quantum-resistant security gateway. The method includes, after the security gateway powers on, performing a hardware environment security self-test and generating a unique root key based on a physically non-cloning function; continuously collecting and analyzing network traffic characteristics; identifying quantum attack patterns and dynamically deciding on encryption algorithm modes based on a machine learning model; parsing communication data packets; dynamically converting and adapting between traditional and quantum-resistant cryptographic protocols according to instructions and preset rules; calling a quantum-resistant cryptographic engine for encryption or signature operations; dynamically deriving and managing session keys throughout their lifecycle based on the root key; and, based on quantum attack detection results, switching algorithm modes, communication protocols, and keys in a coordinated manner, while also enabling side-channel attack protection and hardware security response. This method achieves proactive protection against quantum attacks, seamless multi-protocol compatibility, and full lifecycle security management of keys for the security gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum key technology, specifically to a control method for a multi-protocol switching quantum-resistant secure gateway. Background Technology

[0002] Traditional security gateways, as core devices for information security, are widely used in critical areas of finance and government. Their cryptographic technology systems are based on classical cryptography, including RSA, ECC, and AES, and rely on specific mathematical problems to ensure security. The rise of quantum computing has fundamentally shaken this foundation. Shor's algorithm can efficiently crack RSA and ECC public-key cryptography, and Grover's algorithm has also significantly weakened the security strength of symmetric cryptography, posing a direct threat to existing systems.

[0003] Existing solutions often achieve compatibility through gateway conversion, which leads to decreased efficiency and increased deployment complexity.

[0004] Due to rigid design, existing security gateways generally lack dynamic adaptability and cannot automatically and seamlessly switch or mix classical and quantum-resistant algorithms when a threat is detected, creating a gap in security response. These problems together constitute the main technical obstacles to a smooth transition from classical security to quantum-resistant security.

[0005] The core innovation of this invention lies in its layered, three-dimensional protection architecture, which integrates a quantum-resistant cryptographic card, a multi-standard protocol dynamic conversion engine, and a quantum-safe authentication mechanism. This security gateway can detect quantum attack threats in real time and intelligently and seamlessly switch between traditional encryption algorithms SM2 or SM4 and quantum-resistant algorithms NIST standard ML-KEM or ML-DSA within milliseconds. At the same time, it ensures full compatibility with existing devices and various cryptographic standards, including Chinese national cryptography, NIST PQC, and QSDC, achieving a balance between security, compatibility, and efficiency. Summary of the Invention

[0006] To address the problems existing in the prior art, this application aims to provide a control method for a multi-protocol switching quantum-resistant security gateway that integrates threat detection, algorithm switching, protocol conversion, and hardware acceleration management into a smart quantum-resistant technology solution.

[0007] The control method for a multi-protocol switching quantum-resistant secure gateway described in this application includes:

[0008] S101 After the security gateway is powered on, it performs a hardware environment security self-test and generates a unique root key for the device based on a physically unclonable function, thus completing the calibration and initialization of the quantum random number generator.

[0009] S102. Continuously collect and analyze network traffic characteristics, identify quantum computing attack patterns based on pre-trained machine learning models, and dynamically decide and output the current encryption algorithm mode instruction based on the identification results. The encryption algorithm modes include traditional encryption algorithm modes and quantum-resistant encryption algorithm modes.

[0010] S103. Perform protocol parsing on communication data packets, and dynamically convert and adapt between traditional cryptographic protocols and quantum-resistant cryptographic protocols according to encryption algorithm mode instructions and preset protocol conversion rules, for seamless communication between heterogeneous encryption systems.

[0011] S104. When in quantum-resistant encryption algorithm mode, call the quantum-resistant cryptographic engine to perform quantum-resistant encryption or signature operations on the data based on pre-computed parameters.

[0012] S105. Based on the root key, dynamically generate session keys according to a preset strategy, and manage the generation, storage, rotation and destruction of keys for full-process security control.

[0013] S106. Based on the real-time detection results of quantum attacks, dynamically switch the encryption algorithm mode, communication protocol and key. At the same time, activate the anti-side-channel attack protection mechanism during the cryptographic operation and trigger security response actions based on the hardware environment monitoring results.

[0014] Preferably, in S101, after the security gateway is powered on, the hardware environment starts to perform a security self-test. The self-test process determines the result by scanning the integrity of the internal circuit and comparing it with the pre-stored benchmark data. If the self-test passes, the physical unclonable function is activated, the manufacturing differences of the chip are collected, and the extracted unique feature value is used to generate the unique root key of the device.

[0015] The internal oscillator parameters of the quantum random number generator are encrypted using a key. These parameters are then used to adjust the operating state of the quantum random number generator, thereby obtaining calibration data and driving the quantum random number generator into a stable operating mode, marking the completion of the entire initialization process.

[0016] Preferably, in S102, by continuously collecting and initially classifying network traffic, regular and abnormal traffic datasets are identified, a machine learning model performs in-depth analysis on the abnormal traffic to detect potential quantum computing attack patterns and determine threat categories, and the system queries a preset mapping table.

[0017] If a quantum attack threat is confirmed, the corresponding quantum-resistant encryption algorithm mode is selected. The system generates standardized instructions based on the selected encryption mode and sends them to the target device in real time through a secure channel. By receiving and verifying the status feedback from the target device, the system confirms that it meets the preset standards, thereby completing the switching of the encryption mode.

[0018] Preferably, in S103, the system acquires communication data packets and identifies the cryptographic protocol type. When the comparison reveals that the current protocol is a traditional protocol but the instruction requires a quantum-resistant protocol, a protocol conversion is triggered. The conversion process is based on preset rules, extracting the cryptographic payload from the data packet, re-encapsulating the header according to the new protocol type, adjusting the key negotiation and authentication fields, and obtaining the adapted data packet. After verifying its consistency tag and length field to ensure the conversion is complete, the system outputs the data packet to the heterogeneous encryption system transmission channel to maintain a seamless communication data stream.

[0019] Preferably, in S104, the quantum-resistant cryptographic engine is activated, the payload data to be processed is extracted from the communication data packet, the pre-calculated parameter set is loaded with the corresponding quantum-resistant algorithm key material, and the payload data is encrypted by the activated engine to generate quantum-resistant encrypted ciphertext.

[0020] A quantum-resistant signature algorithm is used to generate a corresponding signature value for the ciphertext. The encrypted ciphertext is combined with the signature value to obtain quantum-resistant protected data with full protection effectiveness. The original payload part in the data packet is replaced with this quantum-resistant protected data to obtain the final data packet processed by the quantum-resistant mode.

[0021] Preferably, in S105, the system loads derivation parameters according to the root key and preset strategy, generates an initial derivation context, performs derivation operations to obtain a session key, generates a unique identifier and timestamp for the session key, and forms a generation record.

[0022] The system determines the storage location and access permissions for the generated records, encrypts the session key using a symmetric encryption algorithm, and stores it. The system monitors the key usage duration through a timed mechanism. If the rotation conditions are met, a new session key is generated based on the root key and the updated policy. The new key will generate a new identifier and timestamp, forming a new record.

[0023] The system acquires and destroys the old encrypted storage session key, updates the key status, adjusts access permissions based on the updated status, and obtains the final security control record.

[0024] Preferably, in S106, the real-time monitoring system generates preliminary threat assessment data by detecting and analyzing quantum attacks, dynamically adjusts the encryption algorithm and communication protocol, selects an appropriate encryption scheme and determines the security configuration, performs key switching, obtains new materials from the key pool to complete key updates, and activates side-channel protection and monitors the computing environment during cryptographic operations.

[0025] If abnormal fluctuations are detected, the frequency is reduced to ensure stability. Hardware operation data is collected through sensors. If parameters exceed the threshold, a security response is triggered. The response instructions are used to adjust protocol priorities, restrict high-risk channels, and determine new communication paths. Under the new scheme, the system continuously monitors attacks and cyclically updates threat assessments to complete a dynamic optimization closed loop for security configuration.

[0026] The control method for a multi-protocol switching quantum-resistant security gateway described in this application has the advantage of achieving proactive and high-strength quantum-resistant security protection, fundamentally solving the vulnerability of traditional systems. The core lies in the integration of a quantum-resistant cryptographic chip and a real-time threat detection mechanism. By continuously analyzing network traffic and identifying quantum attack patterns based on machine learning models, the system can proactively perceive threats. Once a risk is confirmed, it can intelligently and seamlessly switch the encryption operation from the traditional SM2 or SM4 algorithm to the NIST standard ML-KEM or ML-DSA quantum-resistant algorithm within milliseconds. This upgrades security protection from passive and static to proactive and dynamic, fundamentally resisting the decryption threat brought by quantum computing and ensuring the confidentiality and integrity of information in the long-term evolution process.

[0027] Effectively overcoming standardization fragmentation and compatibility barriers, the solution's embedded multi-standard protocol dynamic conversion engine can automatically parse and reconstruct data packets according to algorithm switching instructions without relying on external gateways. It achieves dynamic adaptation between traditional cryptographic protocols and quantum-resistant cryptographic protocols. This not only eliminates the latency and complexity caused by additional conversion equipment, but more importantly, it achieves full-stack compatibility with existing national cryptographic equipment, international PQC standards, and even future QSDC protocols. Security upgrades no longer come at the cost of sacrificing the interconnection or deployment efficiency of existing systems, providing key support for a smooth transition from classical to quantum-resistant cryptography.

[0028] The solution establishes a trusted starting point by starting with hardware power-on self-test and generating an unclonable root key based on PUF. Then, it can dynamically distribute and manage session keys based on the root key and real-time threat situation, realizing full lifecycle security control of keys. At the same time, the cryptographic operation process enables protection against side-channel attacks and combines hardware environment monitoring to trigger security responses. This three-dimensional control that deeply integrates threat detection, algorithm switching, protocol conversion, key management and hardware acceleration provides an ultra-high level of security while significantly reducing the complexity of operation and maintenance through automation and intelligence. Attached Figure Description

[0029] Figure 1 This application describes the flow chart of a control method for a multi-protocol switching quantum-resistant secure gateway. Figure 1 ;

[0030] Figure 2This application describes the flow chart of a control method for a multi-protocol switching quantum-resistant secure gateway. Figure 2 ;

[0031] Figure 3 This application describes the flow chart of a control method for a multi-protocol switching quantum-resistant secure gateway. Figure 3 . Detailed Implementation

[0032] like Figures 1-3 As shown in this application, a control method for a multi-protocol switching quantum-resistant secure gateway is described.

[0033] like Figures 1-3 As shown, after S101 and the security gateway are powered on, they perform a hardware environment security self-test and generate a unique root key for the device based on a physically unclonable function to complete the calibration and initialization of the quantum random number generator.

[0034] Further, in step S101, the security gateway electrical signal is obtained to trigger the hardware environment startup;

[0035] The safety self-test results are determined by comparing the scanned internal circuit integrity with pre-stored reference data.

[0036] If the safety self-test results match the pre-stored baseline data, then activate the physically unclonable function to collect chip manufacturing differences;

[0037] Extract unique feature values ​​from chip manufacturing differences to generate a unique root key for the device;

[0038] The parameters of the internal oscillator of the quantum random number generator are encrypted using the device's unique root key.

[0039] The calibration data is obtained by adjusting the working state of the quantum random number generator according to the encrypted oscillator parameters;

[0040] The initialization completion flag is determined by driving the quantum random number generator into a stable mode using calibration data.

[0041] Specifically, in step S101, after the security gateway is powered on, the built-in power management module monitors the voltage to ensure it is stable within the range of 3.3V±0.1V and checks whether the clock frequency is locked at 100MHz±50ppm. If the threshold is exceeded, a hardware reset is triggered to prevent side-channel attacks.

[0042] Entering the hardware environment security self-test phase, the SHA-256 algorithm is used to verify the integrity of key registers, Flash firmware and SRAM randomness. The expected hash value is calculated and compared with the actual value. If the error exceeds 1 bit, it is judged as a tampering risk and the device is locked. At the same time, the abnormal counter is recorded for subsequent risk assessment.

[0043] When generating a unique root key for a device based on a physically unclonable function, an entropy source is generated by manufacturing process deviations of 256 ring oscillator units. After removing the bias through a VonNeumann corrector, the key is input into the health test recommended by NISTSP800-90B, where the entropy rate must reach 0.98 or higher. Then, a 256-bit root key RK is constructed using HMAC-DRBG with the device's factory serial number as the seed, ensuring that the average Hamming distance between keys from different devices is greater than 128 bits, thus achieving unpredictability and cloning resistance.

[0044] Immediately after the root key is generated, the quantum random number generator is calibrated and initialized. A reverse bias voltage of 8.5V is applied to the avalanche noise diode, the raw bit stream is collected, and autocorrelation analysis is performed. The first-order autocorrelation coefficient is required to be less than 0.05.

[0045] Conditional entropy extraction was performed using AES-256 in CTR mode, ensuring that the output random numbers passed all items of the Dieharder test suite, with the entropy extraction rate remaining stable above 0.85.

[0046] The TRNG output buffer is initialized to 512 bytes, and the initial seed is stored in encrypted form with the root key RK. This enables a fully automated process from power-on to security readiness, ensuring that all subsequent encryption operations are based on an unforgeable hardware root of trust.

[0047] In one embodiment, the hardware security self-test and the entropy source assessment of the physically unclonable function (PUF) for root key generation are specifically as follows:

[0048] Acquire the SRAM power-on initial value sequence S={s1,s2,…,s n}, calculate the variance of its Hamming distance:

[0049]

[0050] Where, σ 2 The Hamming distance variance measures the randomness of the entropy source, d. H This represents the Hamming distance, where μ is a reference value. For the average Hamming distance, when σ 2 When the entropy source is greater than θ (θ=50), it is considered that the entropy source is sufficient.

[0051] In root key generation, a unique root key RK is generated based on the entropy source using a key derivation function (KDF):

[0052]

[0053] Where H( ) is the hash function (SHA-256), salt is the device serial number, and RK is the root key, the device's unique base key.

[0054] like Figures 1-3 As shown, S102 continuously collects and analyzes network traffic characteristics, identifies quantum computing attack patterns based on a pre-trained machine learning model, and dynamically decides and outputs the current encryption algorithm mode instruction based on the identification results. The encryption algorithm modes include traditional encryption algorithm modes and quantum-resistant encryption algorithm modes.

[0055] Furthermore, in step S102, network traffic data is continuously collected, and the data is initially classified according to preset filtering rules to separate regular traffic from abnormal traffic, thereby obtaining a classified traffic dataset.

[0056] For the categorized traffic dataset, a machine learning model is used to perform in-depth analysis of abnormal traffic, identify possible hidden quantum computing attack patterns, and determine potential threat categories;

[0057] Based on the potential threat category, obtain the pre-established threat-encryption mode mapping table. If the threat category belongs to quantum computing attack, select the quantum-resistant encryption algorithm mode and determine the appropriate encryption mode.

[0058] By adapting to the encryption mode, corresponding mode instruction data is generated, and then standardized by combining it with the preset instruction format to obtain standardized instruction content.

[0059] For standardized instruction content, a secure transmission channel is used to distribute the instructions, which are sent to the target device in real time to confirm that the instructions have been received.

[0060] Obtain the status feedback from the target device after receiving the instruction. By comparing the feedback data with the preset execution standard, if the feedback data meets the standard, the encryption mode switch is confirmed to be complete.

[0061] Specifically, in step S102, the security gateway continuously collects inbound and outbound traffic through the dedicated network interface module during operation, sampling 10,000 data packets per second, and extracting the header features of each data packet, including packet length distribution (calculating mean and variance), time interval sequence (accuracy up to 1 μs), protocol type ratio, and TCP flag statistics, to obtain a 128-dimensional feature vector;

[0062] The feature vector was input into a pre-trained lightweight convolutional neural network model, which was trained using the PyTorch framework. A mixed dataset was used, including Grover's algorithm to simulate quantum search attacks, Shor's algorithm to simulate large integer factorization attacks, and normal traffic. The Adam optimizer was used during training, with a learning rate of 0.001 and a batch size of 256. After 150 epochs, the accuracy was verified to be 98.7%.

[0063] The model inference stage first normalizes the input features, then extracts the spatiotemporal pattern through three layers of convolution, and outputs the probability value P of belonging to the quantum computing attack pattern. qc ;

[0064] If P qc If the value exceeds the 0.85 threshold, it is determined that there is a potential risk of quantum attack, and the confidence enhancement factor is immediately calculated. The judgment is smoothed by the probability mean of 10 consecutive sampling windows to avoid a single false alarm.

[0065] The dynamic decision-making module is based on P qc Value output encryption algorithm mode instruction:

[0066] When P qc When the value is less than 0.35, the traditional encryption algorithm mode is selected, with the instruction code being 0x01. AES-256-GCM is preferred to maintain a high throughput.

[0067] When P qc When the value is between 0.35 and 0.85, it enters mixed mode with the instruction code 0x02, enabling dual encryption of Kyber-1024 and AES-256.

[0068] When P qc When the value is greater than 0.85, switch to the pure quantum-resistant encryption algorithm mode, and the instruction code is 0x03;

[0069] The mandatory use of Dilithium-5 digital signatures combined with Falcon-1024 key exchange ensures that all subsequent session key negotiations and data encryption are resistant to quantum Grover and Shor attacks. The entire process is completed in a hardware accelerator with a latency of less than 50μs, achieving real-time adaptive protection.

[0070] In one embodiment, feature vector construction involves collecting N=10000 data packets per second and extracting a d=128-dimensional feature vector x. i ∈R d ;

[0071] In the attack probability calculation, a pre-trained convolutional neural network model f is used. CNN ( Calculate the probability of a quantum attack:

[0072]

[0073] In the decision threshold, the thresholds are set as τ1=0.35 and τ2=0.85:

[0074]

[0075] Where P qcτ1 and τ2 represent the quantum attack probability and the threat assessment value output by the model, respectively. τ1 and τ2 are decision thresholds used for algorithm mode switching.

[0076] like Figures 1-3 As shown, S103 performs protocol parsing on the communication data packets, and dynamically converts and adapts between traditional cryptographic protocols and quantum-resistant cryptographic protocols according to the encryption algorithm mode instructions and preset protocol conversion rules, for seamless communication between heterogeneous encryption systems.

[0077] Further, in step S103, the communication data packet is acquired, and the current cryptographic protocol type is identified through the protocol header field to determine the protocol category to which the data packet belongs;

[0078] Based on the protocol category of the data packet, compare it with the cryptographic protocol type specified in the encryption algorithm mode instruction. If the instruction requires a quantum-resistant cryptographic protocol but the current one is a traditional cryptographic protocol, then trigger the protocol conversion execution.

[0079] Using preset protocol conversion rules, the encrypted payload is extracted from the data packet to obtain the separated encrypted payload data;

[0080] Based on the separated encrypted payload data, the header fields are re-encapsulated according to the application protocol conversion rules to determine the converted cryptographic protocol type.

[0081] By converting the cryptographic protocol type, the key negotiation field and authentication field in the data packet are adjusted to obtain the adapted protocol data packet;

[0082] For the adapted protocol data packets, verify the protocol consistency tag and length field to determine whether the protocol conversion execution is complete;

[0083] If the protocol conversion is completed successfully, the adapted protocol data packet is output to the heterogeneous encryption system transmission channel to ensure seamless communication data flow.

[0084] Specifically, in step S103, after receiving the encryption algorithm mode instruction, the security gateway performs deep parsing of inbound and outbound communication data packets through the FPGA-accelerated protocol parsing engine, processing up to 50,000 data packets per second, peeling off the Ethernet header, IP header, TCP / UDP header layer by layer until the application layer payload identifier is extracted.

[0085] The parsing process uses a state machine to track session states and records the five-tuple information for each flow. The five-tuple information includes source IP, destination IP, source port, destination port, and protocol type. It also calculates the flow duration and cumulative byte count to obtain a 64-dimensional protocol feature vector.

[0086] According to the preset protocol conversion rule table, the table contains 128 mapping rules. For example, when the mode instruction is 0x01, the ECDHE key exchange in the TLS 1.3 handshake is directly mapped to the X25519 curve parameter negotiation.

[0087] RSA-4096 is used for server certificate verification, while ChaCha20-Poly1305 is kept as a symmetric encryption suite to ensure compatibility with legacy systems.

[0088] When the mode instruction is 0x02, the hybrid conversion logic is started, and the key exchange part of the inbound TLS packet is reconstructed into parallel computation of Kyber-768 and ECDHE;

[0089] The server generates both Kyber and ECDH public keys simultaneously, carrying the dual public keys through an extended TLS extension field. The client selects a matching algorithm based on the received field to complete key negotiation. The symmetric encryption layer alternates between AES-128-GCM and ML-KEM derived keys, and the conversion process achieves a latency of less than 30μs through a lookup table.

[0090] When the mode instruction is 0x03, a pure quantum-resistant protocol conversion is forced, intercepting all inbound traditional TLS packets and repackaging them into PQ-TLS frame structures;

[0091] Dilithium-4 is used for certificate signing and verification, and Falcon-512 is used for the key encapsulation mechanism KEM. The CRYSTALS-Dilithium signature value and ML-KEM shared key are embedded in the handshake message.

[0092] The entire conversion is executed in parallel in a dedicated ASIC module to ensure seamless integration with heterogeneous quantum-resistant systems. Outbound data packets are also repackaged according to the reverse mapping rules to achieve bidirectional dynamic adaptation. The entire protocol conversion process is completed through a hardware pipeline, with the total overhead controlled within 80μs, ensuring uninterrupted communication and maintaining the original throughput of over 95%.

[0093] In one embodiment, protocol type identification is achieved by parsing the packet header and extracting the protocol field (CipherSuites in TLS 1.3).

[0094] In key format conversion, the bilinear mapping e:G1×G2→G is used. T Convert the elliptic curve public key Q∈G1 into a quantum-resistant public key generation seed:

[0095]

[0096] Where P pub ∈G2 are system-preset common parameters.

[0097] like Figures 1-3 As shown in S104, when in quantum-resistant encryption algorithm mode, the quantum-resistant cryptographic engine is invoked to perform quantum-resistant encryption or signature operations on the data based on pre-computed parameters.

[0098] Furthermore, in step S104, the quantum-resistant cryptographic engine is activated;

[0099] Extract the payload data to be processed from communication data packets;

[0100] Load quantum-resistant key material based on a pre-calculated parameter set;

[0101] The payload data is encrypted using a quantum-resistant cryptographic engine to obtain quantum-resistant ciphertext.

[0102] A quantum-resistant signature algorithm is used to generate a signature value from the encrypted ciphertext;

[0103] Combine encrypted ciphertext with signature values ​​to form quantum-resistant protected data;

[0104] The original payload portion of the data packet is replaced with quantum-resistant protected data to obtain a quantum-resistant mode-processed data packet.

[0105] Specifically, in step S104, when the security gateway detects that the encryption algorithm mode instruction is 0x03, i.e., pure quantum-resistant encryption mode, it immediately calls the dedicated quantum-resistant cryptographic engine, which integrates multiple parallel processing CRYSTALS-Kyber-1024 modules and CRYSTALS-Dilithium-5 modules.

[0106] Load the pre-computed basis matrix and error vector from the pre-stored 512KB parameter buffer. For example, the Kyber-1024 public key matrix A is pre-computed through the NTT field, and the 4×4×256 ring polynomial coefficients have been quantized to 16-bit integers.

[0107] After receiving the application layer load, the engine starts the key encapsulation process, generating 1024 bytes of Kyber ciphertext and 32 bytes of shared key, with the encapsulation delay controlled within 45μs.

[0108] Simultaneously, the Dilithium-5 signature operation is started in parallel. Utilizing the challenge polynomial seed pre-computed by the hash chain, only 8 rounds of Fiat-Shamir transformation are required to expand the signature value to 4592 bytes and embed it into the reconstructed PQ-TLS server certificate message.

[0109] For inbound quantum-resistant data packets that need to be decrypted, the engine first extracts the Kyber-1024 ciphertext, performs an inverse transformation and error correction in the NTT domain using the preloaded private key polynomial s, and recovers the same 32-byte shared key.

[0110] The decapsulation process employs a pipelined design, consisting of three stages: sampling, decoding, and reassembly, with a total time of less than 52 μs. This shared key drives the AES-256-GCM symmetric encryption module derived from ML-KEM to decrypt the payload data. The GCM authentication tag verification failure rate is less than 10%. -12 ;

[0111] For signature verification scenarios, after the engine loads the sender's Dilithium-5 public key pk, it first calculates the Keccak-512 hash value of the message, and then verifies whether the norm of the signature z satisfies the bound 2 by replaying the challenge response. 23 ;

[0112] To ensure unforgeability under quantum attacks, the entire quantum-resistant computation process is accelerated by a 256-bit wide vector processor, which processes 16 NTT butterfly units per cycle, achieving a single packet throughput of 32,000 packets / second. All intermediate states are refreshed through a side-channel protection mask to prevent power analysis from leaking key information, thereby completing seamless encryption or signature computation from traditional loads to pure quantum-resistant secure transmission.

[0113] In one embodiment, the ML-KEM encryption core operation is represented as:

[0114]

[0115] in, This represents the public key matrix, whose inverse matrix table has been pre-computed;

[0116] Represents a random vector;

[0117] Represents the small error vector;

[0118] q represents the modulus (12289);

[0119] Decryption is performed by looking up table T. A 1. Accelerate matrix operations, reducing complexity from O(n^2) 2 The value drops to nearly O(n).

[0120] like Figures 1-3 As shown, S105, based on the root key, dynamically generate session keys according to a preset strategy, and manage the generation, storage, rotation and destruction of keys for full-process security control.

[0121] Further, in step S105, the derivation parameters are loaded according to the root key and the preset strategy to obtain the initial derivation context;

[0122] The session key is obtained by performing derivation operations through the initial derivation context;

[0123] A unique identifier and timestamp are generated for the session key to obtain the generated record;

[0124] Obtain the session key and identifier from the generated record to determine the storage location and access permissions;

[0125] The session key is encrypted using a symmetric encryption algorithm and then stored in a designated storage location to obtain the encrypted storage session key;

[0126] The usage duration of the encrypted storage session key is monitored through a timed mechanism to determine whether the rotation conditions have been met.

[0127] If the rotation conditions are met, the derivation operation is re-executed based on the root key and the updated preset policy to obtain a new session key;

[0128] A new identifier and timestamp are generated for the new session key to obtain a newly generated record. At the same time, the old encrypted storage session key is retrieved from the storage location and destroyed to obtain the updated key status.

[0129] Adjust access permissions based on the updated key status to obtain security control records.

[0130] Specifically, in step S105, based on the root key, the security gateway uses the HKDF-SHA3-512 extraction function to derive the initial key seed SKS from the 256-bit root key RK. The input salt value is formed by concatenating the 128-bit hardware ID that is the unique identifier of the device with the Keccak-512 hash of the current timestamp, ensuring that each derivation is unpredictable.

[0131] The HMAC-DRBG pseudo-random number generator based on SHA3-512 is used, and rotation is triggered according to a preset strategy when the session period is 1800 seconds or the data volume reaches 4GB.

[0132] A 256-bit session key WK is generated iteratively from SKS. After incrementing by 1 through counter mode CTR, HMAC-SHA3-512(RK||CTR||ContextInfo) is calculated, where ContextInfo contains a 32-byte identifier of protocol version 0x02 and session ID.

[0133] The generated WK is immediately stored in the tamper-proof Ferroelectric RAM area and is saved only in AES-256 encrypted form. The encryption key is a storage-specific subkey extended by the root key RK through KDF. Access requires two-factor hardware lock verification.

[0134] During rotation, after a new WK is generated, the old WK is zeroed out and overwritten three times, triggering a flash erase command to ensure that the probability of residual data being cleared is less than 10%. -15 At the same time, the rotation log is recorded in the audit buffer, including timestamp, rotation reason code and hash chain verification value for subsequent audit tracing;

[0135] During the destruction phase, when more than 5 abnormal access attempts are detected or the device is powered down, an emergency erase protocol is executed. A dedicated hardware fuse is used to permanently destroy the area where the root key RK is located. All derived WK memory pages are zeroed and then random data is overwritten for 7 rounds. The entire key lifecycle is strictly controlled by a state machine to achieve a seamless and secure closed loop from derivation to destruction.

[0136] In one embodiment, session key derivation is performed by deriving session key SK using HKDF based on root key RK:

[0137]

[0138] Where info is the derived context information, L is the key length, and SK is the session key, used for encryption of a single communication;

[0139] In the rotation condition detection, it is triggered by the policy function P(t,D), where t is the time and D is the cumulative amount of encrypted data.

[0140] like Figures 1-3 As shown in S106, based on the results of real-time quantum attack detection, the encryption algorithm mode, communication protocol and key are dynamically switched in conjunction. During the cryptographic operation, the anti-side channel attack protection mechanism is enabled, and the security response action is triggered based on the hardware environment monitoring results.

[0141] Furthermore, in step S106, the detection results of quantum attacks are obtained through a real-time monitoring system, the attack characteristics are analyzed and classified and stored, and preliminary threat assessment data is obtained.

[0142] Based on threat assessment data, the encryption algorithm and communication protocol are adjusted in a pattern, and an appropriate encryption scheme is dynamically selected to determine the current applicable security configuration.

[0143] For a given security configuration, perform a key switching operation, retrieve new key materials from a preset key pool, and complete the key update process;

[0144] During cryptographic operations, a protection mechanism against side-channel attacks is activated, a preset protection module is loaded, and abnormal fluctuations in the computing environment are detected. If abnormal fluctuations are detected, the computing frequency is reduced to obtain a stable computing state.

[0145] By collecting and monitoring data through hardware environment sensors, the changing trends of hardware operating parameters are analyzed. If the parameters exceed the preset threshold, the corresponding safety response process is triggered, and an environment-adaptive response command is obtained.

[0146] Based on the response instructions, adjust the priority configuration of the communication protocol, restrict data transmission on high-risk channels, and determine a new communication path allocation scheme;

[0147] In response to the new communication path allocation scheme, we continuously monitor the detection results of quantum attacks, cyclically update threat assessment data, and dynamically optimize security configurations.

[0148] Specifically, in step S106, regarding the linkage response and protection mechanism for real-time detection results of quantum attacks, the system uses a quantum randomness analysis module deployed at the network edge node to collect the entropy fluctuation in the communication data stream in real time, and sets a threshold of 0.85.

[0149] If the entropy value is detected to be lower than this value for more than 5 consecutive seconds, it is determined that there may be a risk of quantum attack.

[0150] The automatic triggering encryption algorithm was switched from AES-192 to the post-quantum encryption algorithm CRYSTALS-Kyber.

[0151] The handover process takes less than 50 milliseconds. At the same time, the communication protocol is upgraded from TLS1.2 to TLS1.3, the forward security parameter is enabled, and a 512-bit temporary key is used to ensure that the handshake process uses a 512-bit temporary key. The changes in packet delay before and after the handover are analyzed. If the delay increases by more than 20%, the protocol stack buffer is optimized to 64KB to balance performance.

[0152] During cryptographic operations, the system enables protection against side-channel attacks. Specifically, time constant quantization is introduced into the hardware accelerator to fix the encryption operation time at 3.2 milliseconds, regardless of the size of the input data. At the same time, random noise with an intensity of 15% of the signal is injected into the computing unit to interfere with power analysis attacks. The system performs a uniformity check on the noise distribution every 30 minutes to ensure the effectiveness of the protection.

[0153] Based on hardware environment monitoring results, including detecting chip temperature exceeding 85 degrees Celsius or voltage fluctuation exceeding 0.5V, the system automatically triggers a safety response action, reducing the operation frequency to 70% of the original and migrating sensitive operations to the backup safety core;

[0154] The core switching time is controlled within 10 milliseconds. At the same time, the timestamps of abnormal events and environmental parameters are recorded to the tamper-proof log area. The logs are protected by SHA-384 hash to ensure traceability for subsequent analysis. All the above processes are automatically executed through embedded control logic, forming a closed-loop mechanism from detection to response.

[0155] In one implementation, side-channel protection employs a constant-time algorithm, including modular exponentiation m. e The number of iterations mod n is always k (where k is the maximum bit width of the exponent).

[0156] In power consumption balance control, the operating current is stabilized at I through current mirror feedback. ref ±δI, where I ref δI represents the reference operating current and its allowable fluctuation range;

[0157] In environmental anomaly detection, temperature T is monitored in real time. If T>T is satisfied M times consecutively... th (T) th If the temperature reaches 85℃, the key destruction process is triggered, where T, T th This refers to the real-time temperature and the safe temperature threshold.

[0158] In one embodiment, the security gateway is deployed at the network egress point to provide secure access, encrypted communication, and dynamic security protection against quantum computing attacks. Specifically, this is achieved as follows:

[0159] The security gateway in this embodiment adopts a hardware architecture based on FPGA or ASIC, and its core hardware includes:

[0160] Quantum-resistant cryptographic cards that support NIST post-quantum cryptography standard algorithms such as ML-KEM and ML-DSA;

[0161] Traditional cryptographic algorithm accelerator, supporting SM2, SM4, and AES;

[0162] Physically Unclonable Function (PUF) module;

[0163] Quantum Random Number Generator (QRNG);

[0164] Secure storage area and dedicated processing unit for protocol parsing and conversion;

[0165] Ethernet and other network interfaces are used for traffic acquisition;

[0166] The specific control method is implemented as follows:

[0167] After the security gateway is powered on, it first performs a hardware security self-test. If the self-test passes, the PUF module is activated.

[0168] A sequence of initial power-on values ​​S={s1,s2,...,s2} is acquired from an SRAM cell. n}, calculate its Hamming distance variance σ 2 ;

[0169] When σ 2When the value is greater than θ (θ is a preset threshold, set to 50), the entropy source is considered sufficient. Using this entropy source, a unique 256-bit root key RK is generated through the key derivation function, expressed as RK=KDF(H(S),salt,256), where H( ) is the hash function, and salt is the device serial number;

[0170] The QRNG is calibrated to ensure that its output random number sequence {r i It meets all statistical property requirements by passing the NIST SP 800-90B test kit;

[0171] The security gateway continuously collects network traffic, extracting the d-dimensional feature vector x of N (N=10000) data packets per second. i ∈R d ;

[0172] Input the feature vector into the pre-trained lightweight convolutional neural network model f CNN ( To reason;

[0173] The model outputs the quantum attack probability value P. qc =f CNN (x i )∈[0,1];

[0174] The system sets decision thresholds τ1 and τ2, with τ1=0.35 and τ2=0.85.

[0175] If P qc <τ1, using the traditional algorithm mode;

[0176] If τ1≤P qc ≤τ2, using a hybrid algorithm mode;

[0177] If P qc >τ2, switch to pure quantum-resistant algorithm mode;

[0178] The system outputs the algorithm mode instruction CMD∈{0x01,0x02,0x03} based on the above decision.

[0179] Meanwhile, the protocol parsing engine performs deep parsing of data packets to identify the current protocol type and parameters, such as parsing the CipherSuites list from the TLS1.3 ClientHello message;

[0180] Based on the instruction CMD and the pre-defined protocol conversion mapping rule table M, the protocol conversion engine performs the conversion. When the rule requires a conversion from Elliptic Curve Key Exchange (ECDHE) to Lattice-based Key Encapsulation (ML-KEM), the core computations involved include:

[0181] Using the bilinear mapping e: G1×G2→G T Map the elliptic curve public key Q∈G1 to a seed for generating a quantum-resistant public key: seed=Hash(e(Q,P)). pub )), where P pub ∈G2 are system preset parameters. This process can be completed within a limited time T with hardware acceleration. max Completed within 80ms;

[0182] In quantum-resistant encryption mode, the ML-KEM-1024 encryption engine is invoked, and the core computation of the encryption process is as follows:

[0183]

[0184] in, Let T be the public key matrix, and its associated inverse matrix table has been pre-computed. A 1. To accelerate;

[0185] It is a random vector. For small error vectors, the modulus q is a specific prime number (12289).

[0186] By looking up table T A 1. It can effectively reduce the computational complexity of matrix-vector multiplication;

[0187] In terms of key management, the session key SK is derived from the root key RK: SK=HKDF(RK,info,L), where info is additional information and L is the key length;

[0188] Key rotation is triggered by the policy function P(t,D), where t is time and D is the cumulative data volume;

[0189] The system uses real-time detection results P qc Linked switching of algorithms, protocols, and keys;

[0190] In cryptographic operations, side-channel protection is enabled: constant-time algorithms ensure that the execution path takes a constant amount of time, such as modular exponentiation m. e The number of iterations mod n is always k (where k is the maximum bit width of the exponent).

[0191] The power balancing unit stabilizes the operating current at I through feedback control. ref ±δI;

[0192] The hardware environment monitoring unit samples the temperature T in real time. If M consecutive samples satisfy T>T, th (T) th If the temperature reaches 85℃, a security response will be triggered, and the key destruction process will be initiated.

[0193] This embodiment clearly and completely demonstrates the implementation details of the quantum-resistant security gateway control method through the above-described hardware and software collaborative process and standardized mathematical expression. The introduced explicit calculation model, threshold judgment and function expression enable those skilled in the art to fully understand and reproduce the invention, ensuring the sufficiency of the disclosure in the specification. This solution achieves active dynamic protection against quantum attacks, seamless compatibility with multiple protocols and full-cycle security management of keys.

[0194] For those skilled in the art, various other corresponding changes and modifications can be made based on the technical solutions and concepts described above, and all such changes and modifications should fall within the protection scope of the claims of this application.

Claims

1. A control method for a multi-protocol switching quantum-resistant secure gateway, characterized in that, include: S101, after the security gateway is powered on, performs a hardware environment security self-test, generates a unique root key for the device based on a physically unclonable function, completes the calibration and initialization of the quantum random number generator, and also includes: After the security gateway is powered on, it triggers the hardware environment to start and perform a security self-test; If the security self-test passes, the physical unclonable function is activated to collect chip manufacturing differences and extract unique feature values ​​to obtain the unique root key of the device. The root key is used to encrypt the internal oscillator parameters of the quantum random number generator, and the working state is adjusted according to the encrypted parameters to obtain calibration data; The calibration data drives the quantum random number generator into a stable working mode, completing the hardware initialization process. S102. Based on the hardware initialization state completed in S101, continuously collect and analyze network traffic characteristics, identify quantum computing attack patterns based on pre-trained machine learning models, and dynamically decide and output the encryption algorithm mode instruction to be used at the current time according to the identification results. The encryption algorithm mode includes traditional encryption algorithm mode and quantum-resistant encryption algorithm mode. S103. According to the encryption algorithm mode instruction output in S102, the communication data packet is parsed, and according to the preset protocol conversion rules, dynamic conversion and adaptation are performed between traditional cryptographic protocols and quantum-resistant cryptographic protocols for seamless communication between heterogeneous encryption systems. S104. In response to the decision in S102 to adopt the quantum-resistant encryption algorithm mode, the quantum-resistant cryptographic engine is invoked to perform quantum-resistant encryption or signature operations on the adapted data packet in S103 based on the pre-computed parameters. S105. Based on the unique root key of the device generated in S101, dynamically derive session keys according to a preset strategy, and perform full-process security control on the generation, storage, rotation and destruction of the session keys. S106. Based on the quantum attack detection results identified in real time in S102, trigger the dynamic switching of encryption algorithm mode, communication protocol and corresponding session key. At the same time, enable the anti-side channel attack protection mechanism during the cryptographic operation process, and trigger security response actions based on the hardware environment monitoring results.

2. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, S102 includes: Continuously collect network traffic data and perform preliminary classification to separate regular traffic from abnormal traffic; A pre-trained machine learning model is used to perform in-depth analysis on the abnormal traffic to identify potential quantum computing attack patterns and determine threat categories; Based on the preset mapping relationship between threat categories and encryption algorithm modes, determine the encryption algorithm mode to be used at the moment; Generate the corresponding encryption algorithm mode instruction and send it to the target device through a secure channel; Receive feedback from the target device to confirm that the encryption algorithm mode switch is complete.

3. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, S103 includes: Acquire communication data packets and identify the type of cryptographic protocol currently in use; The current protocol type is compared with the protocol type required by the encryption algorithm mode instruction; if they do not match, a protocol conversion is triggered. Based on the preset protocol conversion rules, the encrypted payload is extracted from the data packet, and the data packet header is re-encapsulated according to the target protocol type, and the key negotiation and authentication fields are adjusted to obtain the adapted data packet; After verifying the integrity of the adapted data packets, they are output to the heterogeneous encryption system transmission channel.

4. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, S104 includes: Activate the quantum-resistant cryptographic engine to extract the payload data to be processed from the communication data packets; The pre-computed quantum-resistant algorithm parameters and key materials are loaded, and the payload data is encrypted using the quantum-resistant cryptographic engine to obtain quantum-resistant encrypted ciphertext. A quantum-resistant signature algorithm is used to generate a corresponding signature value for the ciphertext. The ciphertext and the signature value are combined to form quantum-resistant protected data, which replaces the original payload in the data packet.

5. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, S105 includes: Based on the root key and the preset derivation strategy, a derivation operation is performed to generate a session key; Create a generation record containing a unique identifier and timestamp for the generated session key; The session key is encrypted using a symmetric encryption algorithm and then stored in a secure storage area. Monitor the usage status of the session key, and when the preset rotation conditions are met, derive a new session key based on the updated policy and the root key; Destroy the old session key and update the key status and access permissions.

6. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, S106 includes: Quantum attack detection results are obtained based on a real-time monitoring system, and threat assessment data is also obtained. Based on the threat assessment data, dynamically adjust the currently used encryption algorithm, communication protocol, and corresponding key; During cryptographic operations, the side-channel attack protection module is activated to monitor and stabilize the computing environment. Operating parameters are collected by hardware environment sensors. When the parameters exceed the preset threshold, a safety response process is triggered to adjust the priority of the communication protocol or restrict high-risk channels.

7. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, The traditional encryption algorithm modes include algorithms based on SM2, SM4, AES, RSA, or ECC; The quantum-resistant encryption algorithm modes include algorithms based on ML-KEM, ML-DSA, Kyber, Dilithium, or Falcon.

8. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 1, characterized in that, The anti-side-channel attack protection mechanism includes performing cryptographic operations using a constant-time algorithm and interfering with side-channel information acquisition by injecting random noise or balancing power consumption.

9. The control method for a multi-protocol switching quantum-resistant secure gateway according to claim 2, characterized in that, The identification of quantum computing attack patterns includes: making mean smoothing judgments based on the detection probabilities of multiple consecutive sampling time windows.

Citation Information

Patent Citations

  • Anti-quantum-attack national secret SSL communication system and anti-quantum-attack national secret SSL communication method

    CN119652507A

  • Anti-quantum cryptographic algorithm FPGA (Field Programmable Gate Array) structure and processing method

    CN119766441A