Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting
By constructing a three-dimensional security architecture based on PUF and quantum key distribution on the SIM card, the single point of failure risk in key generation and distribution and the lack of real-time authentication in semantic communication systems are solved, achieving efficient identity authentication and privacy protection, and improving the security and real-time performance of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-25
- Publication Date
- 2026-03-10
AI Technical Summary
Existing semantic communication systems face single-point failure risks in 6G networks due to reliance on third-party CAs or cloud services for key generation and distribution. Their authentication mechanisms are also weak against replay attacks, and blockchain identity authentication schemes suffer from insufficient real-time performance and high storage costs, making it difficult to meet the security requirements of dynamic semantic interactions.
By using a SIM card as the carrier of the Physically Unclonable Function (PUF) and the quantum random key storage terminal, a three-dimensional security architecture of "terminal trusted execution environment - quantum key distribution - semantic differential privacy" is constructed. The SIM card security base module generates the physically unclonable function features and quantum secure keys. Combined with a lightweight authentication protocol, a semantic security enhancement module and a trusted execution environment optimization module, dynamic identity authentication, privacy protection and resistance to quantum attacks are achieved.
It significantly improves the real-time performance and quantum computing resistance of key distribution, reduces computational complexity and storage overhead, enhances the real-time performance of identity authentication and the success rate of replay attack blocking, provides a hardware-level trusted execution environment, and meets the security requirements of semantic communication.
Smart Images

Figure CN121645235A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the technical field of mobile communications, and in particular to a semantic communication security enhancement system based on SIM card quantum key pre-setting. Background Technology
[0002] With the rapid development of mobile communication technology, the capacity of traditional communication systems has gradually approached the limits of Shannon's theory. However, the continuous breakthroughs in artificial intelligence technology and the construction of 6G communication networks have placed higher demands on communication efficiency and intelligence, thus semantic communication has once again become a hot technology.
[0003] Semantic communication is a novel communication paradigm. Breaking away from traditional bitstream transmission, it achieves high-level semantic representation of communication content through semantic parsing, knowledge modeling, and compression coding, significantly improving spectral efficiency and content understanding accuracy. However, with the large-scale application of semantic communication in 5G / 6G networks, such as intelligent customer service, telemedicine, and industrial control, its security protection system is gradually revealing significant shortcomings: traditional communication security architectures focus on link and transport layer protection, making it difficult to cope with emerging threats such as semantic content tampering, knowledge base leakage, and identity forgery.
[0004] The security requirements of semantic communication exhibit distinct characteristics: First, the semantic parsing of communication content relies on the knowledge base on the client side, and the existing cloud storage mode of model parameters is prone to the risk of batch data leakage; Secondly, the semantic encoding and decoding process may involve user privacy data, and the end-to-end encryption mechanism needs to be deeply coupled with semantic processing; Third, dynamic semantic interaction scenarios (such as real-time negotiation and knowledge reasoning) require identity verification mechanisms to be lightweight and resistant to replay attacks.
[0005] Existing semantic communication security solutions mainly include: (1) End-to-end encryption models based on deep learning can solve the risk of knowledge base data leakage to a certain extent, but they have the defect of centralized key lifecycle management; (2) The semantic feature protection technology combined with homomorphic encryption can be used to protect user privacy data involved in the semantic encoding and decoding process, but it faces the engineering bottleneck of excessive computational complexity; (3) For blockchain-based identity authentication protocols, it is necessary to solve the problems of storage capacity limitation and consensus delay on the data chain.
[0006] Finally, and crucially, existing technologies generally neglect the construction of "trust anchors" in semantic communication systems: on the one hand, key generation and distribution rely on third-party CAs or cloud services, posing a single point of failure risk; on the other hand, the trusted execution environment (TEE) on the device side does not fully utilize the inherent security attributes of mobile communication infrastructure. This proposal, based on the native security capabilities of mobile networks, proposes using the SIM card as the carrier of physically unclonable functions and the quantum random key (quantum random number generator) storage terminal to construct a three-dimensional security architecture of "terminal trusted execution environment - quantum key distribution - semantic differential privacy." This aims to address the core deficiencies of existing technologies in key security, identity authenticity, and semantic data privacy, thus building an autonomous and controllable security foundation for 6G semantic communication.
[0007] Semantic communication identity authentication schemes based on blockchain technology have the following three key shortcomings: Insufficient real-time performance: As the scale of the blockchain expands, the time required for nodes within the chain to complete cross-domain authentication will continue to increase, and may eventually fail to meet business performance requirements. High storage costs: The blockchain distributed ledger storage model is not suitable for storing large amounts of data in semantic communication knowledge bases. In addition, chained data storage does not offer the same degree of freedom in data manipulation as traditional centralized storage models, which increases the difficulty of data model design.
[0008] Weak resistance to replay attacks: The transparent ledger model of blockchain may provide vulnerabilities for replay attacks by unauthorized users. For example, attackers can intercept and repeatedly send expired authentication requests, exploiting the global synchronization delay of the blockchain to bypass the context verification mechanism of dynamic semantic interactions, leading to identity forgery or unauthorized access.
[0009] To address the shortcomings of existing technologies, this disclosure provides a semantic communication security enhancement system based on SIM card quantum key pre-configuration. Summary of the Invention
[0010] To achieve the above objectives, the present disclosure adopts the following technical solution: One aspect of this disclosure provides a semantic communication security enhancement system based on SIM card quantum key pre-configuration, comprising: The SIM card security base module is configured to utilize the hardware characteristics of the SIM card to generate physically unclonable functional features and a pre-set quantum security key; The lightweight authentication protocol module is communicatively connected to the SIM card security base module and is configured to achieve dynamic identity authentication based on physically unclonable features and quantum secure keys. The semantic security enhancement module is configured to perform privacy protection processing on semantic communication data; The Trusted Execution Environment Optimization Module, which is communicatively connected to the SIM card security base module and the lightweight authentication protocol module, is configured to build a hardware-software collaborative trusted execution environment. The quantum security enhancement module, integrated into the SIM card security base module, is configured to provide resistance to quantum attacks and dynamic key management; The system, through the collaborative work of the aforementioned modules, achieves comprehensive enhancement of identity authentication, key management, privacy protection, and data transmission security in the semantic communication process.
[0011] In one optional implementation, the SIM card security base module includes: The physically unclonable feature extraction unit is configured to generate a unique physical fingerprint by utilizing the manufacturing process deviation of the SIM card chip. The quantum key pre-filling unit is configured to pre-fill a quantum true random key via a quantum random number generator; The security domain isolation unit is configured to divide an independent security zone within the SIM card for storing master key parameters and sensitive configurations.
[0012] In one optional implementation, the quantum key presetting unit further includes a quantum random number generator, which generates quantum random numbers conforming to the NISTSP800-22 standard and uses the quantum random numbers as seed keys to pre-inject into the security domain isolation unit of the SIM card.
[0013] In one optional implementation, the independent security zone capacity of the security domain isolation unit is not less than 512KB, and it supports encrypted storage based on the AES-256-GCM algorithm.
[0014] In one optional implementation, the lightweight authentication protocol module includes: The two-factor authentication unit is configured to generate dynamic identity tags by combining physically unclonable features with pre-filled quantum true random keys. The anti-replay attack unit is configured to generate a one-time challenge value by binding a timestamp with a quantum random number. Zero-knowledge proof units are configured to verify user access permissions without revealing the knowledge base content.
[0015] In one optional implementation, the two-factor authentication unit includes obtaining a physical fingerprint through a physically non-clonable functional feature extraction unit, performing a hash operation with a quantum true random key in a quantum key presetting unit, and generating a dynamic identity tag with a validity period of 500ms locally.
[0016] In one optional implementation, the timestamp accuracy of the anti-replay attack unit is ±50ms, and the challenge values of the most recent 1000 authentication requests are stored through an LRU caching mechanism to achieve fast detection of duplicate requests. The zero-knowledge proof unit is implemented using the Groth16 algorithm, and the verification process takes no more than 10ms with a communication overhead of less than 256 bytes.
[0017] In one optional implementation, the semantic security enhancement module includes: Differential privacy injection unit, used to add Laplace noise to the semantic coding layer; Dynamic confusion unit, which generates semantic feature confusion matrix based on preset quantum key; The key derivation system requests a one-time temporary session key from the quantum key distribution device based on the seed of the quantum random number generator in the SIM card.
[0018] In one optional implementation, the noise intensity ε of the differential privacy injection unit can be dynamically adjusted. When ε=0.5, the semantic model accuracy loss is ≤8.3%, and the ε value can be automatically switched according to the privacy sensitivity level of the communication scenario. The dimension of the confusion matrix of the dynamic confusion unit matches the dimension of the semantic feature vector, and the matrix elements are dynamically generated based on quantum keys using the AES-128 algorithm, with the confusion operation taking ≤5ms.
[0019] In one optional implementation, the lifecycle of the temporary session key applied for by the key derivation system is bound to a single semantic interaction session, and it is automatically destroyed after the session ends. It also supports over-the-air key updates via base station quantum key relay.
[0020] In one optional implementation, the trusted execution environment optimization module includes: The baseband-SIM joint authentication unit is configured to establish a secure channel between the baseband processor and the SIM card via an elliptic curve key exchange protocol; The runtime integrity verification unit is configured to periodically verify the memory image of the trusted execution environment based on the physically unclonable feature. The secure storage expansion unit is configured to expand the encrypted storage capacity of the TEE using the SIM card security domain.
[0021] In one optional implementation, the verification period of the runtime integrity verification unit can be configured to 100ms-1s. When the verification fails, the system is triggered to perform a soft reset and the sensitive data is erased. The secure storage extension unit supports encrypted caching of the semantic communication knowledge base, and the integrity of the cached data is verified by SHA-384 hash value.
[0022] In one optional implementation, the quantum security enhancement module includes: The post-quantum algorithm integration unit implements key encapsulation based on the embedded CRYSTALS-Kyber algorithm; The key destruction unit is configured to automatically erase the quantum key in the SIM card upon detection of physical intrusion or abnormal voltage; The quantum key relay unit enables over-the-air updates of the SIM card's quantum key through the base station's quantum key distribution equipment.
[0023] In one optional implementation, the post-quantum algorithm integration unit supports a key encapsulation / decapsulation rate of ≥1Mbps, and the algorithm code is stored in an independent secure area of the SIM card.
[0024] In one optional implementation, the key destruction unit has a response time of ≤10μs and supports permanently disabling the attacked SIM card through a hardware fuse mechanism.
[0025] In one optional implementation, the physical fingerprint generation success rate of the physically unclonable feature extraction unit is ≥99.99%, the false recognition rate is ≤0.001%, and it supports stable operation in a temperature range of -40℃ to 85℃.
[0026] In one optional implementation, the communication between the key derivation system and the quantum key distribution device adopts a challenge-response mechanism based on quantum random numbers, with a single key application time of ≤20ms and a key generation rate of ≥128 bits / ms.
[0027] Another aspect of this disclosure provides a semantic communication security enhancement method based on SIM card quantum key pre-configuration, comprising: S1: Constructing a secure SIM card base, specifically including: Physically unclonable functional features are extracted from SIM card chip manufacturing process deviations to serve as unique hardware fingerprints. A quantum true random key is generated using a quantum random number generator, and the quantum true random key is pre-injected into the independent secure area of the SIM card; An independent secure area is defined within the SIM card to encrypt and store the physical unclonable functional features and the quantum true random key; S2: Implements the lightweight authentication protocol, specifically including: Based on the extracted physically unclonable functional features and the pre-injected quantum true random key, dynamic identity tags are generated through a two-factor authentication mechanism; By combining quantum random numbers and timestamps to generate one-time challenge values, replay attack protection is achieved. Zero-knowledge proof protocol is used to verify the access rights of semantic communication subjects, and identity confirmation is completed without disclosing the knowledge base content; S3: Performs security enhancement processing on semantic communication data, specifically including: Injecting Laplace noise into the semantic coding layer to achieve differential privacy protection; Based on the pre-injected quantum true random key, a semantic feature confusion matrix is dynamically generated, and the semantic feature vector is confused and transformed. A one-time temporary session key is applied for using the quantum key distribution device based on the seed vector of the quantum random number generator in the SIM card through the key derivation system, which is used for semantic data transmission encryption. S4: Optimize the trusted execution environment, specifically including: A secure communication channel between the baseband processor and the SIM card is established using an elliptic curve key exchange protocol. Periodic integrity checks are performed on the TEE memory image based on the extracted physical non-clonable functional characteristics. Expand the encrypted storage capacity of the TEE by dividing it into independent security zones to realize the encrypted caching of the semantic communication knowledge base; S5: Constructing quantum security enhancement mechanisms, specifically including: Integrating a quantum key encapsulation algorithm into the SIM card provides quantum true random keys with protection against quantum attacks; Monitors abnormal physical environment of SIM card, and automatically erases the quantum true random key stored in the independent security area when physical intrusion or abnormal voltage is detected; The over-the-air dynamic update of the quantum true random key of the SIM card is achieved through the base station quantum key relay protocol; Through multi-layered enhancements including hardware security foundation, dynamic authentication, semantic protection, trusted environment, and quantum security, we achieve full-link identity authentication, key management, privacy protection, and data transmission security in semantic communication.
[0028] In another aspect of this disclosure, an electronic device is provided, comprising: At least one memory stores computer-executable instructions non-transiently; At least one processor, configured to run the computer-executable instructions, The computer-executable instructions are executed by the processor to implement the aforementioned semantic communication security enhancement method based on SIM card quantum key pre-setting.
[0029] In another aspect, this disclosure provides a computer-readable storage medium storing computer-executable instructions that, when executed by at least one processor, implement the semantic communication security enhancement method based on SIM card quantum key pre-setting described above.
[0030] The effects of this disclosure: By employing SIM card embedded quantum key pre-setting and Physically Unclonable Function (PUF) technology, local key generation and storage avoid the single point of failure risk of traditional centralized key servers, while supporting millisecond-level dynamic key updates, significantly improving the real-time performance and quantum computing resistance of key distribution.
[0031] By integrating differential privacy noise injection and dynamic confusion matrix into the semantic coding layer, the computational complexity is reduced by about 70% compared to homomorphic encryption schemes. Furthermore, through adaptive noise calibration (accuracy loss ≤ 8.3% when ε=0.5), a balance between privacy protection and model accuracy is achieved.
[0032] By combining quantum random number binding timestamps with local LRU cache detection, compared with blockchain identity authentication schemes, the authentication latency is reduced from seconds to milliseconds, and the success rate of replay attack blocking is increased to 99.99%.
[0033] Based on the Physical Unclonable Feature (PUF) of the SIM card chip and security domain isolation technology, it provides a hardware-level Trusted Execution Environment (TEE). Compared with traditional TEE solutions, the storage capacity is expanded by 512KB, and it supports runtime integrity verification to resist physical side-channel attacks.
[0034] It integrates post-quantum algorithms (CRYSTALS-Kyber) with quantum key relay technology, and also supports an automatic key destruction mechanism to avoid the risk of key leakage caused by physical contact.
[0035] By employing a dynamic obfuscation matrix and a lightweight authentication protocol, storage overhead is reduced by 90% compared to blockchain solutions, and terminal power consumption is reduced to 1 / 5 of that of traditional fully homomorphic encryption solutions, meeting the heat dissipation design threshold for mobile devices. Attached Figure Description
[0036] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the embodiments of the present disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings: Figure 1 This is a framework diagram of a semantic communication security enhancement system based on SIM card quantum key pre-setting provided in Embodiment 1 of this disclosure; Figure 2 This is a flowchart of a semantic communication security enhancement method based on SIM card quantum key pre-setting provided in Embodiment 3 of this disclosure; Figure 3 This is a block diagram of the electronic device provided in Embodiment 4 of this disclosure; Figure 4 This is a block diagram of a computer-readable storage medium provided in Embodiment 4 of this disclosure. Detailed Implementation
[0037] The technical solutions of the present disclosure will be described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments.
[0038] In the following description, the terms "first," "second," etc., are used for descriptive convenience only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this disclosure, unless otherwise stated, "a plurality of" means two or more.
[0039] In this disclosure, unless otherwise expressly specified and limited, the term "connection" should be interpreted broadly. For example, "connection" can be a fixed mechanical connection, a detachable mechanical connection, or an integral part; or, "connection" can be a direct connection or an indirect connection through an intermediate medium. Furthermore, unless otherwise expressly specified and limited, the term "coupling" should be interpreted broadly. For example, "coupling" can be a direct electrical connection, such as physical contact and electrical conduction between two components; it can also be understood as an electrical connection between different components in a circuit structure through physical lines capable of transmitting electrical signals, such as copper foil or wires on a printed circuit board (PCB), to transmit electrical signals; or, "coupling" can be an indirect electrical connection between two components through an intermediate medium; or, "coupling" can be an electrical connection between two components in a non-contact manner, such as an electrical connection between two components using capacitive coupling to transmit electrical signals.
[0040] In this embodiment of the disclosure, directional terms such as "up," "down," "left," and "right" may be defined relative to the orientation in which the components are schematically placed in the accompanying drawings. It should be understood that these directional terms can be relative concepts, used for relative description and clarification, and can change accordingly depending on the orientation in which the components are placed in the accompanying drawings.
[0041] Example 1: like Figure 1 As shown, this disclosure provides a semantic communication security enhancement system based on SIM card quantum key pre-configuration, including: The SIM card security base module is configured to utilize the hardware characteristics of the SIM card to generate physically unclonable functional features and a pre-set quantum security key; The lightweight authentication protocol module is communicatively connected to the SIM card security base module and is configured to achieve dynamic identity authentication based on physically unclonable features and quantum secure keys. The semantic security enhancement module is configured to perform privacy protection processing on semantic communication data; The Trusted Execution Environment Optimization Module, which is communicatively connected to the SIM card security base module and the lightweight authentication protocol module, is configured to build a hardware-software collaborative trusted execution environment. The quantum security enhancement module, integrated into the SIM card security base module, is configured to provide resistance to quantum attacks and dynamic key management; The system, through the collaborative work of the aforementioned modules, achieves comprehensive enhancement of identity authentication, key management, privacy protection, and data transmission security in the semantic communication process.
[0042] In the above embodiments, the SIM card security base is constructed, PUF feature extraction is performed: an unclonable physical fingerprint is generated by utilizing the process deviation of the SIM card chip, quantum key pre-setting is performed, and quantum security keys are pre-charged through a quantum random number generator (QRNG), and security domain isolation is performed: an independent security area (Secure Enclave) is divided within the SIM card to store the master key parameters. Lightweight authentication protocol with two-factor authentication mechanism: Combining PUF features with pre-filled quantum true random keys to generate dynamic identity tags locally, ensuring key reliability while solving the key generation efficiency problem; Anti-replay attack design: Introducing quantum random numbers bound to timestamps to resist replay attacks; Zero-knowledge proof (ZKP): Implementing privacy verification of semantic knowledge base access permissions.
[0043] Semantic security enhancement module: Differential privacy injection: Laplace noise is added to the semantic coding layer; Dynamic obfuscation mechanism: A semantic feature obfuscation matrix is generated based on a pre-set key; Key Derivation System (KDS): A one-time temporary session key is requested from the online quantum key distribution device based on the SIM card QRNG seed to ensure communication link security; Trusted execution environment optimization: Baseband-SIM joint authentication: A secure channel is established between the baseband processor and the SIM card; Runtime integrity verification: TEE environment verification is performed based on the SIM card PUF features; Secure storage expansion: The TEE storage capacity is expanded using the SIM card's secure area; Quantum security enhancement; Post-quantum algorithm integration: Post-quantum encryption and decryption algorithms such as the CRYSTALS-Kyber algorithm are embedded in the SIM card; Key destruction mechanism: The quantum key is automatically erased when physical intrusion is detected; Quantum key relay: Over-the-air update of the SIM card quantum key is achieved through the base station; Key distribution performance can be expanded by adding quantum key service nodes.
[0044] Example 2: like Figure 1 As shown, based on Embodiment 1, the system provided in this disclosure embodiment further includes the SIM card security base module, comprising: The physically unclonable feature extraction unit is configured to generate a unique physical fingerprint by utilizing the manufacturing process deviation of the SIM card chip. The quantum key pre-filling unit is configured to pre-fill a quantum true random key via a quantum random number generator; The security domain isolation unit is configured to divide an independent security zone within the SIM card for storing master key parameters and sensitive configurations.
[0045] In one optional implementation, the quantum key presetting unit further includes a quantum random number generator, which generates quantum random numbers conforming to the NISTSP800-22 standard and uses the quantum random numbers as seed keys to pre-inject into the security domain isolation unit of the SIM card.
[0046] In one optional implementation, the independent security zone capacity of the security domain isolation unit is not less than 512KB, and it supports encrypted storage based on the AES-256-GCM algorithm.
[0047] In one optional implementation, the lightweight authentication protocol module includes: The two-factor authentication unit is configured to generate dynamic identity tags by combining physically unclonable features with pre-filled quantum true random keys. The anti-replay attack unit is configured to generate a one-time challenge value by binding a timestamp with a quantum random number. Zero-knowledge proof units are configured to verify user access permissions without revealing the knowledge base content.
[0048] In one optional implementation, the two-factor authentication unit includes obtaining a physical fingerprint through a physically non-clonable functional feature extraction unit, performing a hash operation with a quantum true random key in a quantum key presetting unit, and generating a dynamic identity tag with a validity period of 500ms locally.
[0049] In one optional implementation, the timestamp accuracy of the anti-replay attack unit is ±50ms, and the challenge values of the most recent 1000 authentication requests are stored through an LRU caching mechanism to achieve fast detection of duplicate requests. The zero-knowledge proof unit is implemented using the Groth16 algorithm, and the verification process takes no more than 10ms with a communication overhead of less than 256 bytes.
[0050] In one optional implementation, the semantic security enhancement module includes: Differential privacy injection unit, used to add Laplace noise to the semantic coding layer; Dynamic confusion unit, which generates semantic feature confusion matrix based on preset quantum key; The key derivation system requests a one-time temporary session key from the quantum key distribution device based on the seed of the quantum random number generator in the SIM card.
[0051] In one optional implementation, the noise intensity ε of the differential privacy injection unit can be dynamically adjusted. When ε=0.5, the semantic model accuracy loss is ≤8.3%, and the ε value can be automatically switched according to the privacy sensitivity level of the communication scenario. The dimension of the confusion matrix of the dynamic confusion unit matches the dimension of the semantic feature vector, and the matrix elements are dynamically generated based on quantum keys using the AES-128 algorithm, with the confusion operation taking ≤5ms.
[0052] In one optional implementation, the lifecycle of the temporary session key applied for by the key derivation system is bound to a single semantic interaction session, and it is automatically destroyed after the session ends. It also supports over-the-air key updates via base station quantum key relay.
[0053] In one optional implementation, the trusted execution environment optimization module includes: The baseband-SIM joint authentication unit is configured to establish a secure channel between the baseband processor and the SIM card via an elliptic curve key exchange protocol; The runtime integrity verification unit is configured to periodically verify the memory image of the trusted execution environment based on the physically unclonable feature. The secure storage expansion unit is configured to expand the encrypted storage capacity of the TEE using the SIM card security domain.
[0054] In one optional implementation, the verification period of the runtime integrity verification unit can be configured to 100ms-1s. When the verification fails, the system is triggered to perform a soft reset and the sensitive data is erased. The secure storage extension unit supports encrypted caching of the semantic communication knowledge base, and the integrity of the cached data is verified by SHA-384 hash value.
[0055] In one optional implementation, the quantum security enhancement module includes: The post-quantum algorithm integration unit implements key encapsulation based on the embedded CRYSTALS-Kyber algorithm; The key destruction unit is configured to automatically erase the quantum key in the SIM card upon detection of physical intrusion or abnormal voltage; The quantum key relay unit enables over-the-air updates of the SIM card's quantum key through the base station's quantum key distribution equipment.
[0056] In one optional implementation, the post-quantum algorithm integration unit supports a key encapsulation / decapsulation rate of ≥1Mbps, and the algorithm code is stored in an independent secure area of the SIM card.
[0057] In one optional implementation, the key destruction unit has a response time of ≤10μs and supports permanently disabling the attacked SIM card through a hardware fuse mechanism.
[0058] In one optional implementation, the physical fingerprint generation success rate of the physically unclonable feature extraction unit is ≥99.99%, the false recognition rate is ≤0.001%, and it supports stable operation in a temperature range of -40℃ to 85℃.
[0059] In one optional implementation, the communication between the key derivation system and the quantum key distribution device adopts a challenge-response mechanism based on quantum random numbers, with a single key application time of ≤20ms and a key generation rate of ≥128 bits / ms.
[0060] In the above embodiments, the security chip is based on the physical fingerprint generation mechanism of the physical circuit. A high-frequency signal is applied to the internal circuit of the security chip, multiple voltage fluctuation data are collected, noise interference in the data is removed, and an initial data sequence is generated. The SIM card generates a unique physical fingerprint based on the delay difference of the internal circuit path. The response value is corrected using a BCH error correction code to ensure stability under different environmental conditions. Taking a PUF based on XOR offset as an example, the specific steps are as follows: Physical fingerprint acquisition: Apply a 500MHz clock excitation to the 128 arbitrator links of the SIM card chip and acquire voltage fluctuation signals (a total of 2048 samples).
[0061] Noise filtering: Apply medium filtering (window size 3×3) to remove glitch noise and generate an initial response vector Rraw∈{0,1}2048.
[0062] Feature compression: Dimensionality is reduced to 256 bits using the LFSR linear feedback shift register (polynomial x11+x2+1): RPUF=LFSR(Rraw,256); Error correction coding: Hamming (256,224) code is used to generate the error correction table TEC, which supports single-bit error correction.
[0063] Quantum key storage management, the following are quantum key storage management modes: Key generation: A high-entropy true random number is generated using a quantum random number generator to ensure the unpredictability of the key and is physically injected into the SIM as the initial key.
[0064] Storage structure: Master key area: A two-layer encryption strategy is adopted. First, the PUF response value is used to encrypt the key, and then it is written into the tamper-proof security area of the SIM card. Temporary key pool: Pre-stores session keys for short-term use (the validity period of the temporary key can be adjusted through algorithm parameters); Temporary session key request: Based on the standard key derivation algorithm, a request message is generated using the master key pre-filled in the SIM card to request the generation of a temporary session key from the quantum key distribution node.
[0065] This technology addresses the issues of insufficient real-time performance in identity authentication and vulnerabilities in defending against replay attacks. It employs a two-factor dynamic tag generation system, combining hardware fingerprints and quantum keys to achieve rapid dynamic authentication.
[0066] Implementation steps: Input parameters: integrate PUF response value, preset quantum key and timestamp accurate to milliseconds.
[0067] Dynamic key generation: A temporary key is generated by binding the quantum key to a timestamp using a hash algorithm.
[0068] Tag generation: A unique authentication tag is generated by encrypting a random number and a timestamp using a temporary key.
[0069] Interaction flow: Client: Generates an authentication tag with a timestamp and sends it to the server.
[0070] Server-side: Check the validity of the timestamp (window period is ±50ms), and reject the request if it times out.
[0071] The tag is recalculated and compared with the received value; if they match, a session token is issued.
[0072] The semantic security enhancement module defends against the leakage of semantic feature reverse reconstruction and knowledge base association.
[0073] Differential privacy injection mechanism; Implementation steps: Feature extraction: Extracting feature data from communication content (such as numerical sequences converted from text); Sensitivity calculation: Analyze the maximum difference value of semantic features to determine the range of noise addition; Noise injection: Adding controllable random noise during semantic encoding to ensure that attackers cannot recover the original data; Accuracy calibration: Dynamically adjusts noise intensity to balance privacy protection and model accuracy.
[0074] Dynamic confusion matrix generation.
[0075] Technical process: Matrix generation: Generate a random transformation matrix based on a preset quantum key and session ID.
[0076] Feature obfuscation: Multiplying semantic features with a matrix transforms the feature space, preventing reverse engineering attacks.
[0077] Trusted Execution Environment (TEE) optimization enhances TEE environment security and storage capacity, and includes a baseband-SIM joint authentication protocol.
[0078] Implementation process: Key negotiation: The baseband processor and SIM card generate a shared key through the Elliptic Curve Key Exchange (ECDH) protocol.
[0079] Secure channel: Uses AES-256-GCM to encrypt communication data and supports counter mode to prevent replay attacks.
[0080] Secure storage extended storage solutions: SIM card chip security area (512KB): Encrypted storage of user keys; Trusted memory (2MB): Temporarily stores intermediate data.
[0081] Quantum security enhancement: Post-quantum algorithm integration implementation scheme Key generation: A quantum-resistant algorithm is used to generate public and private keys. The public key contains matrix parameters and error correction codes.
[0082] Encryption and decryption: Random noise is superimposed during encryption, and the plaintext is restored using the private key during decryption, ensuring that quantum computers cannot crack it.
[0083] Quantum key relay process: The terminal SIM card requests a key update from the base station (carrying the PUF hash).
[0084] After the base station verifies the legitimacy of the PUF, it obtains a new key through the quantum key center (quantum encrypted transmission).
[0085] The base station updates the terminal key via the air interface, and the terminal verifies the update via a hash.
[0086] Key destruction protection trigger condition: Physical damage or abnormal operation is detected.
[0087] Protective measures: Clear all stored keys (overwrite and erase multiple times); Send a self-destruct notification (including unique device information and time).
[0088] Hardware layer: Quantum-safe SIM card; Quantum key storage area: The root key is pre-loaded using quantum random number generation through offline injection, and physical no-cloning (PUF) technology is used to prevent key extraction.
[0089] Hardware encryption engine: Integrates national cryptographic algorithms SM2 / SM4, supporting real-time encryption and decryption of semantic data streams.
[0090] Secure Execution Environment (TEE): Based on the isolation technology of SIM card chip, the identity authentication protocol is run to ensure that the key signing process cannot be stolen by external attacks.
[0091] Key Management Layer. Quantum Key Pre-setting System: Generates a truly random key seed using a quantum random number generator (QRNG) and writes it offline via a dedicated device before SIM card activation. Dynamic Key Derivation: Derives temporary keys (such as call keys or knowledge base access keys) from the root key based on the session scenario. Each derivation uses a hash algorithm to generate an irreversible unique identifier. Key Update Protocol: When the remaining preset key amount falls below a threshold, keys are replenished via a quantum key distribution network (QKD) or offline service stations.
[0092] Semantic communication layer semantic encoding encryption: Lightweight encryption is superimposed on the output of the traditional semantic encoder, and the semantic vector is obfuscated using a session key generated by key derivation. Differential privacy engine: Noise is added to access requests to the semantic knowledge base, and a differential privacy parameter ε is generated through quantum key generation to achieve data obfuscation for different user permission levels (e.g., higher-privilege users have lower ε values).
[0093] Authentication Layer, Two-Way Authentication Protocol: Both communicating parties generate zero-knowledge proofs using pre-set keys, completing joint verification of device and user identities within the TEE. Quantum Key Signature: Digitally sign communication metadata (such as IP addresses and timestamps) using pre-set keys to prevent man-in-the-middle attacks.
[0094] Example 3: like Figure 2 As shown, based on Embodiment 1, this disclosure provides a semantic communication security enhancement method based on SIM card quantum key pre-setting, including: S1: Constructing a secure SIM card base, specifically including: Physically unclonable functional features are extracted from SIM card chip manufacturing process deviations to serve as unique hardware fingerprints. A quantum true random key is generated using a quantum random number generator, and the quantum true random key is pre-injected into the independent secure area of the SIM card; An independent secure area is defined within the SIM card to encrypt and store the physical unclonable functional features and the quantum true random key; S2: Implements the lightweight authentication protocol, specifically including: Based on the extracted physically unclonable functional features and the pre-injected quantum true random key, dynamic identity tags are generated through a two-factor authentication mechanism; By combining quantum random numbers and timestamps to generate one-time challenge values, replay attack protection is achieved. Zero-knowledge proof protocol is used to verify the access rights of semantic communication subjects, and identity confirmation is completed without disclosing the knowledge base content; S3: Performs security enhancement processing on semantic communication data, specifically including: Injecting Laplace noise into the semantic coding layer to achieve differential privacy protection; Based on the pre-injected quantum true random key, a semantic feature confusion matrix is dynamically generated, and the semantic feature vector is confused and transformed. A one-time temporary session key is applied for using the quantum key distribution device based on the seed vector of the quantum random number generator in the SIM card through the key derivation system, which is used for semantic data transmission encryption. S4: Optimize the trusted execution environment, specifically including: A secure communication channel between the baseband processor and the SIM card is established using an elliptic curve key exchange protocol. Periodic integrity checks are performed on the TEE memory image based on the extracted physical non-clonable functional characteristics. Expand the encrypted storage capacity of the TEE by dividing it into independent security zones to realize the encrypted caching of the semantic communication knowledge base; S5: Constructing quantum security enhancement mechanisms, specifically including: Integrating a quantum key encapsulation algorithm into the SIM card provides quantum true random keys with protection against quantum attacks; Monitors abnormal physical environment of SIM card, and automatically erases the quantum true random key stored in the independent security area when physical intrusion or abnormal voltage is detected; The over-the-air dynamic update of the quantum true random key of the SIM card is achieved through the base station quantum key relay protocol; Through multi-layered enhancements including hardware security foundation, dynamic authentication, semantic protection, trusted environment, and quantum security, we achieve full-link identity authentication, key management, privacy protection, and data transmission security in semantic communication.
[0095] Example 4: Figure 3 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown.
[0096] The electronic device may include a central processing unit / microprocessor / main control chip, etc. 4; and a storage medium 5, coupled to the central processing unit / microprocessor / main control chip, etc. 4, and storing computer-executable instructions therein for performing the steps of the various methods of the embodiments of this disclosure when executed by the processor.
[0097] The central processing unit / microprocessor / main control chip, etc., can include, but are not limited to, one or more processors or microprocessors.
[0098] Storage medium 5 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (e.g., hard disk, floppy disk, solid-state drive, removable disk, CD-ROM, DVD-ROM, Blu-ray disc, etc.).
[0099] In addition, the electronic device may also include (but is not limited to) a data bus 6, an input / output bus / external bus / device bus 7, a display 8, and input / output devices 9 (e.g., keyboard, mouse, speaker, etc.).
[0100] The central processing unit / microprocessor / main control chip, etc. 4 can communicate with external devices (8, 9, etc.) via I / O bus 7 through wired or wireless network (not shown).
[0101] The storage medium 5 may also store at least one computer-executable instruction for performing the steps of various functions and / or methods in the embodiments described herein when the central processing unit / microprocessor / main control chip, etc., 4 is running.
[0102] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.
[0103] Figure 4 A schematic diagram of a computer-readable storage medium according to an embodiment of the present disclosure is shown.
[0104] like Figure 4 As shown, the non-transitory computer-readable storage medium 11 stores instructions, such as computer-readable instructions 10. When the computer-readable instructions 10 are executed by a processor, the various methods described above can be performed. The non-transitory computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-transitory non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, the non-transitory computer-readable storage medium 11 can be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions 10 stored on the computer-readable storage medium 11, the various methods described above can be performed.
[0105] In the several embodiments provided in this disclosure, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0106] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0107] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0108] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the methods of the various embodiments of this disclosure through a computer device (which may be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.
[0109] The above embodiments are only used to illustrate the technical solutions of this disclosure, and are not intended to limit it. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this disclosure.
Claims
1. A semantic communication security enhancement system based on SIM card quantum key presetting, characterized in that, The application relates to a SIM card security base module configured to generate a physically unclonable function feature and a preset quantum secure key by utilizing a SIM card hardware feature; a lightweight authentication protocol module in communication connection with the SIM card security base module and configured to realize dynamic identity authentication based on the physically unclonable function feature and the quantum secure key; a semantic security enhancement module configured to perform privacy protection processing on semantic communication data; a trusted execution environment optimization module in communication connection with the SIM card security base module and the lightweight authentication protocol module and configured to construct a hardware-software cooperative trusted execution environment; and a quantum security enhancement module integrated in the SIM card security base module and configured to provide quantum attack resistance and dynamic key management. The SIM card security base module comprises a physically unclonable function feature extraction unit configured to generate a unique physical fingerprint by utilizing a process deviation of a SIM card chip; a quantum key preset unit configured to pre-charge a quantum true random key by a quantum random number generator; and a security domain isolation unit configured to divide independent security zones in the SIM card for storing master key parameters and sensitive configurations. The quantum key preset unit further comprises a quantum random number generator configured to generate quantum random numbers meeting the NIST SP800-22 standard and pre-charge the quantum random numbers as seed keys into the security domain isolation unit of the SIM card. The independent security zones divided by the security domain isolation unit have a capacity not less than 512 KB and support encrypted storage based on an AES-256-GCM algorithm. The lightweight authentication protocol module comprises a two-factor authentication unit configured to generate a dynamic identity label by combining the physically unclonable function feature and the pre-charged quantum true random key; an anti-replay attack unit configured to generate a one-time challenge value by binding a timestamp with a quantum random number; and a zero-knowledge proof unit configured to verify user access authority without leaking contents of a knowledge base. The two-factor authentication unit comprises a physically unclonable function feature extraction unit configured to acquire a physical fingerprint, a quantum key preset unit configured to perform a hash operation on the quantum true random key to generate a dynamic identity label with a time limit of 500 ms. The timestamp accuracy of the anti-replay attack unit is + / - 50 ms, and the challenge values of the last 1000 authentication requests are stored by an LRU cache mechanism to realize rapid detection of repeated requests; the zero-knowledge proof unit is realized by using a Groth16 algorithm, and the verification process takes no more than 10 ms and has a communication overhead of less than 256 bytes.
2. The semantic communication security enhancement system of claim 1, wherein, The semantic security enhancement module comprises a differential privacy injection unit configured to add Laplace noise at a semantic coding layer; a dynamic confusion unit configured to generate a semantic feature confusion matrix based on a preset quantum key; and a key derivation system configured to apply a one-time temporary session key to a quantum key distribution device according to a seed vector of a quantum random number generator in the SIM card. 3. The semantic communication security enhancement system of claim 2, wherein, 4. The semantic communication security enhancement system of claim 3, wherein, 5. The semantic communication security enhancement system of claim 1, wherein, 6. The semantic communication security enhancement system of claim 1, wherein, 7. The semantic communication security enhancement system of claim 5, wherein, 8. The semantic communication security enhancement system of claim 1, wherein, 9. The semantic communication security enhancement system of claim 8, wherein, The noise intensity of the differential privacy injection unit can be dynamically adjusted, and when the noise intensity is 0.5, the semantic model accuracy loss is less than or equal to 8.3%, and the noise intensity can be automatically switched according to the privacy sensitivity level of the communication scene; The confusion matrix dimension of the dynamic confusion unit matches the semantic feature vector dimension, and the matrix elements are dynamically generated based on the quantum key through the AES-128 algorithm, and the confusion operation time is less than or equal to 5 ms.
10. The semantic communication security enhancement system of claim 9, wherein, The temporary session key life cycle of the key derivation system application is bound to a single semantic interaction session, and the session is automatically destroyed after the session ends, and the key can be updated over the air through the base station quantum key relay.
11. The semantic communication security enhancement system of claim 1, wherein, The trusted execution environment optimization module comprises: A baseband-SIM joint authentication unit configured to establish a secure channel between the baseband processor and the SIM card through an elliptic curve key exchange protocol; A runtime integrity verification unit configured to periodically verify the memory image of the trusted execution environment based on the physical unclonable function feature; A secure storage expansion unit configured to expand the encryption storage capacity of the TEE using the SIM card security domain.
12. The semantic communication security enhancement system of claim 11, wherein, The verification period of the runtime integrity verification unit can be configured to be 100 ms to 1 s, and the system soft reset is triggered and the sensitive data is erased when the verification fails, and the secure storage expansion unit supports encryption caching of the semantic communication knowledge base, and the integrity of the cached data is verified by the SHA-384 hash value.
13. The semantic communication security enhancement system of claim 1, wherein, The quantum security enhancement module comprises: A post-quantum algorithm integration unit that implements key encapsulation based on the embedded CRYSTALS-Kyber algorithm; A key destruction unit configured to automatically erase the quantum key in the SIM card when physical intrusion or abnormal voltage is detected; A quantum key relay unit that updates the SIM card quantum key over the air through the base station quantum key distribution device.
14. The semantic communication security enhancement system of claim 13, wherein, The post-quantum algorithm integration unit supports a key encapsulation / decapsulation rate of greater than or equal to 1 Mbps, and the algorithm code is stored in a separate secure area of the SIM card.
15. The semantic communication security enhancement system of claim 13, wherein, The key destruction unit has a response time of less than or equal to 10 microseconds, and supports permanently disabling the attacked SIM card through a hardware fuse mechanism.
16. The semantic communication security enhancement system of claim 1, wherein, The physical fingerprint generation success rate of the physical unclonable function feature extraction unit is greater than or equal to 99.99%, the false recognition rate is less than or equal to 0.001%, and stable operation is supported in a temperature range of -40°C to 85°C.
17. The semantic communication security enhancement system of claim 10, wherein, The communication between the key derivation system and the quantum key distribution device uses a challenge-response mechanism based on quantum random numbers, and the time consumption for a single key application is less than or equal to 20 ms, and the key generation rate is greater than or equal to 128 bits / ms.
18. A method for enhancing semantic communication security based on SIM card quantum key presetting, characterized in that, Comprise: S1: Constructing a SIM card security base, Extracting a physical unclonable function feature as a unique hardware fingerprint using a SIM card chip process bias; Generating a quantum true random key through a quantum random number generator, and pre-injecting the quantum true random key into a separate secure area of the SIM card; Dividing a separate secure area in the SIM card, and encrypting the physical unclonable function feature and the quantum true random key; S2: Executing a lightweight authentication protocol, Based on the extracted physical unclonable function feature and the pre-injected quantum true random key, a dynamic identity tag is generated through a two-factor authentication mechanism; The quantum random number is combined with the timestamp to generate a one-time challenge value, and the anti-replay attack protection is realized. The access permission of the semantic communication subject is verified by using the zero-knowledge proof protocol, and the identity authentication is completed without leaking the content of the knowledge base. S3: performing security enhancement processing on the semantic communication data, Laplace noise is injected at the semantic encoding layer to realize differential privacy protection. Based on the pre-injected quantum true random key, a semantic feature confusion matrix is dynamically generated to perform confusion transformation on the semantic feature vector. Through the key derivation system, a one-time temporary session key is applied to the quantum key distribution device from the SIM card based on the quantum random number generator seed, which is used for semantic data transmission encryption. S4: optimizing the trusted execution environment, The secure communication channel between the baseband processor and the SIM card is established by using the elliptic curve key exchange protocol. The TEE memory image is periodically integrity-verified based on the extracted physical unclonable function features. The encrypted storage capacity of the TEE is expanded by using the divided independent security area, and the encrypted cache of the semantic communication knowledge base is realized. S5: constructing a quantum security enhancement mechanism, The post-quantum key encapsulation algorithm is integrated in the SIM card to protect the quantum true random key from quantum attack; The quantum true random key stored in the independent security area is automatically erased when physical intrusion or abnormal voltage is detected; The base station quantum key relay protocol is used to realize the over-the-air dynamic update of the quantum true random key of the SIM card. Through the multi-level enhancement of hardware security base, dynamic authentication, semantic protection, trusted environment and quantum security, the identity authentication, key management, privacy protection and data transmission security of the whole link of the semantic communication are realized. 19.An electronic device comprising: at least one memory that non-transitorily stores computer-executable instructions; at least one processor configured to execute the computer-executable instructions, wherein the computer-executable instructions, when executed by the processor, implement a semantic communication security enhancement method based on SIM card quantum key preset according to claim 18.
20. A computer readable storage medium, wherein, The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions, when executed by at least one processor, implement a semantic communication security enhancement method based on SIM card quantum key preset according to claim 18.
Citation Information
Patent Citations
Key protection method and device
CN115174080A
Communication authentication method and device, computer equipment and storage medium
CN117041956A
Key processing method
CN119544199A
Driving vehicle road cloud cooperative safety control method and system based on trusted computing
CN120301643A
Semantic communication system and method
CN120498591A
Cited By
Data encryption method, data decryption method and data processing method
CN122093793A