Anti-quantum enhancement method and device for stock password equipment system
By introducing gatekeeper-style quantum-resistant security enhancement devices and quantum-resistant FPGA chips into existing classical cryptographic devices, and combining them with the architecture of classical cryptographic chips, the security and compatibility issues of existing devices in quantum computing environments are solved, achieving low-cost quantum-resistant security upgrades and smooth migrations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2026-03-13
AI Technical Summary
Existing classical cryptographic devices suffer from insufficient security and high replacement costs when facing the threat of quantum computers, and it is difficult to achieve smooth quantum-resistant migration without changing the hardware architecture.
It adopts an architecture that combines gatekeeper-style quantum-resistant security enhancement devices and quantum-resistant FPGA chips with classical cryptographic chips. It enhances the quantum-resistant security of existing classical cryptographic devices through external or internal means, supports a hybrid working mode of classical cryptographic algorithms and quantum-resistant cryptographic algorithms, and ensures forward security and backward compatibility.
It enables cost-effective quantum-resistant upgrades to existing classical cryptographic devices without altering their hardware structure, ensuring forward security and backward compatibility of communication links and extending device lifespan.
Smart Images

Figure CN121664409A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of quantum-resistant cryptography and information security technology, and in particular to a quantum-resistant enhancement method, apparatus, and device for existing classical cryptographic systems. Background Technology
[0002] Most currently deployed public-key cryptosystems are based on problems such as large integer factorization, discrete logarithms, and discrete logarithms on elliptic curves. However, these difficult problems are believed to be solvable in polynomial time on quantum computers. Currently, breakthroughs are being made in the engineering of quantum computers, and their immense computing power poses a potential risk of decryption to current public-key cryptosystems. Therefore, academia and industry are actively researching cryptography resistant to quantum computing attacks, known as post-quantum cryptography (PQC), or quantum-safe cryptography. This includes hash-based, encoding-based, multivariate-based, and lattice-based approaches. Among these, lattice-based cryptography has achieved good performance in terms of security, bandwidth, and computational efficiency, and can construct various cryptographic algorithms and protocols, such as public-key encryption, digital signatures, and key-negotiation cryptography, making it one of the most promising approaches.
[0003] During the transition from classical cryptography to quantum-resistant cryptography, currently used classical cryptographic devices face challenges such as insufficient security and high replacement costs. For example, only some cryptographic algorithms in existing classical cryptographic chips and devices are affected by quantum computing. Discarding all existing chips and devices for quantum-resistant migration would inevitably lead to a huge waste of economic resources. How to upgrade existing classical cryptographic devices to quantum-resistant security without disrupting their hardware architecture, while ensuring system compatibility and stability, and through a lower-cost and smoother migration method, thus extending their application in the quantum computing era, has become a pressing practical problem for industry and academia. Summary of the Invention
[0004] In view of this, the present invention provides a method, apparatus, and device for quantum-resistant enhancement of existing classical cryptographic device systems, which can enhance quantum security without changing their hardware structure. In the context of this invention, an existing classical cryptographic device system may include multiple existing classical cryptographic devices. Generally, an existing classical cryptographic device system includes one or more of a classical cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, and a software system. This invention achieves smooth quantum-resistant migration of existing classical cryptographic chips and devices, ensuring forward security and backward compatibility of communication links, and extending the lifespan of existing classical cryptographic chips and devices. It ensures that existing classical cryptographic chips based on the board architecture of this invention can continue to be used in the post-quantum era, and that existing classical cryptographic device systems can be upgraded to quantum-resistant systems in a black-box manner using the gatekeeper device of this invention. The specific solution is as follows:
[0005] In a first aspect, the present invention discloses a quantum-resistant enhancement method for existing classical cryptographic device systems, the method specifically comprising:
[0006] For existing classical cryptographic devices, a gatekeeper-style quantum-resistant security enhancement device is adopted. This device is placed externally between the classical cryptographic device and the public network or integrated into the existing cryptographic system and devices, with both parties communicating via a network port. In this case, the gatekeeper-style quantum-resistant security enhancement device only provides quantum-resistant protection for critical information during key exchange based on Diffie-Hellman-type cryptographic protocols or digital envelopes, without altering the system's interaction flow.
[0007] Furthermore, for existing classical cryptographic devices with PCIe interfaces, a quantum-resistant cryptographic card based on a quantum-resistant FPGA chip combined with a classical cryptographic chip architecture is adopted and built into the device as a sub-module. In this case, the existing classical cryptographic device acts as the host computer, and the quantum-resistant cryptographic card acts as the slave computer. The two communicate with each other via PCIe. The application layer of the host computer calls the quantum-resistant cryptographic card SDK to complete both classical cryptographic and quantum-resistant cryptographic functions.
[0008] Secondly, this invention discloses a quantum-resistant enhancement device for existing classical cryptographic devices, providing a low-cost quantum-resistant hybrid operating mode for existing classical cryptographic chips and offering a solution for their full-cycle application in the pre-quantum and post-quantum eras. It comprises two hardware architectures, specifically including:
[0009] Quantum-resistant FPGA chips are used to deploy quantum-resistant cryptographic algorithms, communicate with host computers, and manage keys. They feature a configurable, parallel architecture and can be quickly configured with multiple quantum-resistant cryptographic standards.
[0010] Classic cryptographic chips are used to provide classic cryptographic algorithms, communicate with host computers, and manage keys. They are divided into two categories based on chip architecture: SoC classic cryptographic chips and non-SoC classic cryptographic chips. In terms of chip form, they exist in two forms: the first is a single-chip structure that integrates classic cryptographic chips with non-open source algorithms, such as one or more of SM1 and SM7; the second is a dual-chip structure, one of which supports non-open source classic cryptographic algorithms and the other supports open source classic cryptographic algorithms.
[0011] The random number module is used to generate random numbers from physical noise sources, and also supports access from quantum-resistant FPGA chips and classical cryptographic chips;
[0012] The storage module is used to save the computing program, user configuration information, and key information, and supports access from quantum-resistant FPGA chips and classical cryptographic chips.
[0013] PCIe modules are used for data communication and on-board power supply.
[0014] In the first hardware architecture, a classic SoC cryptographic chip is used as the master chip, directly connected to the PCIe module, responsible for protocol parsing, data forwarding, and key management functions; a quantum-resistant FPGA chip serves as slave chip 1, responsible for quantum-resistant cryptographic algorithms, and connected to the master chip through one or more of the AXI, AHB, and APB bus protocols; a non-open-source classic cryptographic chip serves as slave chip 2, responsible for non-open-source domain-specific classic cryptographic algorithms, and connected to the master chip through one or more of the SPI, IIC, and UART protocols; the host computer can directly interact with slave chip 1.
[0015] In the second hardware architecture, a quantum-resistant FPGA is used as the main chip, which is directly connected to the PCIe module and is responsible for protocol parsing, data forwarding, and key management functions. A non-SoC classical cryptographic chip is used as slave chip 1, which is responsible for classical cryptographic algorithm functions. A non-open-source classical cryptographic chip is used as slave chip 2, which is responsible for non-open-source domain-specific cryptographic algorithm functions. The main chip uses one or more of the SPI, IIC, and UART protocols to interact with slave chip 1 and slave chip 2.
[0016] Thirdly, this invention discloses a quantum-resistant enhancement device for existing classical cryptographic devices, providing a solution for the application of existing classical cryptographic devices in the pre-quantum and post-quantum eras, specifically including:
[0017] For a classic cryptographic device, sender A and receiver B use a Diffie-Hellman cryptographic protocol, with the session key between them provided by [the relevant authority / component]. We obtain, where KDF is the key derivation function. , For sender A's random nonce, For receiver B, the random nonce is denoted by aux, which represents other public information exchanged between the two parties (one party being A and GA, and the other party being GB and B). It is the temporary public key information publicly transmitted according to the original protocol; the gatekeeper-style quantum-resistant security enhancement devices GA and GB are connected in series between sender A, receiver B and the public network, or embedded in the systems and devices of A and B, respectively, for the set Quantum-resistant security is provided for any non-empty subset, where GA is used to... For any non-empty subset of the array, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption.
[0018] For sender A and receiver B using existing classical cryptographic devices, the classical key encapsulation digital envelope protocol is employed, with the session key between the two parties being... We obtain, where K is the ciphertext Encryption or encapsulation key, It is sender A using receiver B's public key The encrypted ciphertext, auxK, is other-information exchanged between the two parties (one party is A and GA, the other is GB and B); in this case, the gatekeeper-style quantum-resistant security enhancement device GA, GB pair set Quantum-resistant security is provided for any non-empty subset, where GA is used to... For any non-empty subset of the array, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption.
[0019] The memory is used to store computer programs, configuration information, and key information for quantum-resistant FPGAs and classical cryptographic chips.
[0020] The data communication module is used to connect classic cryptographic devices to public networks;
[0021] A processor for executing the computer program to implement the quantum-resistant security enhancement method as described above. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in this invention, the accompanying drawings used in the description of this invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A schematic diagram of a quantum-resistant cryptographic card provided for an embodiment of the present invention. Figure 1 ;
[0024] Figure 2A schematic diagram of a quantum-resistant cryptographic card provided for an embodiment of the present invention. Figure 2 ;
[0025] Figure 3 This is a schematic diagram illustrating the workflow of a gatekeeper-style quantum security enhancement device provided in an embodiment of the present invention. Detailed Implementation
[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0027] Existing classical cryptographic devices and chips suffer from several problems: First, quantum computers only affect the security of some classical cryptographic algorithms in existing classical cryptographic chips, devices, and systems; completely replacing them would result in enormous economic waste. Second, with continuous breakthroughs in quantum computing, the current operating mode cannot guarantee the forward security of cryptographic systems. Third, when the quantum computing era fully arrives, the existing application architecture will still need to be replaced, lacking backward compatibility. To address these technical problems, this invention discloses a quantum-resistant enhancement method, apparatus, and device for classical cryptographic device systems. This method and device can enhance quantum security in a lower cost and more smoothly, without altering the original hardware architecture. It provides forward security and backward compatibility, effectively maintaining the original interaction framework, and offering a solution for the full lifecycle application of existing classical cryptographic devices and chips.
[0028] See Figure 1 As shown, this invention discloses a quantum-resistant security enhancement device for existing classical cryptographic devices, employing a quantum-resistant FPGA + SoC classical cryptographic chip architecture, comprising:
[0029] The SoC (System-on-a-Chip) classical cryptographic chip serves as the master chip, featuring an on-chip operating system for handling protocol parsing, request scheduling, key management, and open-source classical cryptographic algorithms. A quantum-resistant FPGA chip, acting as slave chip 1, is used to deploy quantum-resistant cryptographic algorithms and offers scalability. A non-open-source classical cryptographic chip, acting as slave chip 2, is used to deploy non-open-source classical cryptographic algorithms. The TRNG module is a random number module that provides random numbers from a physical noise source for the quantum-resistant cryptographic card. The master chip has a multi-channel PCIe protocol interface for data communication with the host computer via PCIe. It interacts with slave chip 1 using one or more of the AXI, AHB, and APB bus protocols, with data packets arranged according to the communication protocol fields. It also interacts with slave chip 2 using one or more of the SPI, IIC, and UART protocols.
[0030] When the host computer requests classical cryptography, the main chip and slave chip 2 respond and process the request. When the host computer requests quantum-resistant cryptography, there are two working modes: First, the main chip forwards the request to slave chip 1, which responds and processes the request, and the result is returned to the host computer through the main chip. Second, the slave chip 1 responds and processes the request directly through the main chip, and the result is returned directly to the host computer.
[0031] See Figure 2 As shown, this invention discloses a quantum-resistant security enhancement device for existing classical cryptographic devices, employing a quantum-resistant FPGA + non-SoC classical cryptographic chip architecture, comprising:
[0032] The quantum-resistant FPGA chip serves as the master chip, handling functions such as protocol parsing, request scheduling, key management, and quantum-resistant cryptographic algorithms. It communicates with the host computer via PCIe, with data packets arranged according to the communication protocol. A non-SoC classical cryptographic chip (slave chip 1) provides open-source classical cryptographic algorithm functionality. A non-open-source classical cryptographic chip (slave chip 2) provides non-open-source classical cryptographic algorithm functionality. The master chip interacts with slave chip 1 and slave chip 2 using one or more of the SPI, IIC, and UART protocols.
[0033] When the host computer requests classical cryptography, the main chip forwards the request to slave chip 1 and slave chip 2 respectively for processing based on the cryptographic identifier, and the result is returned to the host computer through the main chip; when the host computer requests quantum-resistant cryptography, the main chip performs the response processing.
[0034] The functions of each segment of the quantum-resistant FPGA chip communication protocol are shown in Table 1. The data packet consists of three parts: header, body, and trailer.
[0035] Table 1 Quantum-resistant FPGA data communication protocol
[0036] Table 2 provides specific implementation methods for the function numbers in Table 1, covering quantum-resistant key encapsulation algorithms and digital signature algorithms, including:
[0037] Table 2 Function Instruction Table
[0038] See Figure 3 As shown, this invention discloses a gatekeeper-style quantum security enhancement device, comprising:
[0039] The existing classical cryptographic devices, sender A and receiver B, are two users using a public-key cryptosystem. A multi-channel gatekeeper-type quantum-resistant security enhancement device GA is deployed between the existing classical cryptographic device A and the public network, while a multi-channel gatekeeper-type quantum-resistant security enhancement device GB is deployed between the existing classical cryptographic device B and the public network. Without altering the protocol interaction process of the existing devices, these devices provide quantum-resistant security protection for Diffie-Hellman-type cryptographic protocols or digital envelope key exchange processes. The specific implementation steps are as follows:
[0040] Step 1: Sender A sends a message containing key information. The data frames are sent to the gatekeeper-type quantum-resistant security enhancement device GA;
[0041] Step 2: After receiving the data frame, the gatekeeper-style quantum security enhancement device (GA) will transmit the key information... The data is then parsed and used with the quantum-resistant public key of the multi-channel gatekeeper-style quantum-resistant security enhancement device GB. Provide quantum-resistant security protection;
[0042] Step 3: Quantum-resistant ciphertext Pack it together with the original data frame and send it;
[0043] Step 4: After receiving the ciphertext, the multi-channel gatekeeper-style quantum-resistant security enhancement device GB uses the quantum-resistant encryption private key. Key information Decrypted;
[0044] Step 5: Multi-channel gatekeeper-style quantum-resistant security enhancement device GB will Send to recipient B;
[0045] Step 6: Receiver B delivers key information Send to multi-channel gatekeeper-style quantum-resistant security enhancement device GB;
[0046] Step 7: After receiving the data frame, the multi-channel gatekeeper-style quantum security enhancement device GB will transmit key information. The key is then parsed and used as a quantum-resistant public key for the gatekeeper-style quantum-resistant security enhancement device GA. Provide quantum-resistant security protection;
[0047] Step 8: Quantum-resistant ciphertext Pack it together with the original data frame and send it;
[0048] Step 9: After receiving the ciphertext, the gatekeeper-style quantum-resistant security enhancement device (GA) uses the quantum-resistant encryption private key. Key information Decrypt it;
[0049] Step 10: The gatekeeper-style quantum-resistant security enhancement device GA will Send to sender A.
[0050] Key information in the diagram regarding Diffie-Hellman-type cryptographic protocols Can be replaced with a set For any non-empty subset, the session key is... We obtain, where KDF is the key derivation function. , For sender A's random nonce, For receiver B, randomnonce; aux represents other information exchanged between the two parties (one party is A and GA, the other party is GB and B). This refers to the temporary public key information publicly transmitted under the original protocol; for the classic key encapsulation digital envelope protocol, the key information in the diagram is... Can be replaced with a set For any non-empty subset, the session key is... We obtain, where K is the ciphertext Encryption or encapsulation key, It is sender A using receiver B's public key The encrypted ciphertext, auxK, represents other public information exchanged between the two parties.
[0051] The quantum-resistant security enhancement method, device, and equipment proposed in this invention adopt a pluggable design. The host computer can dynamically select the quantum-resistant cryptographic algorithm according to parameter configuration. The quantum-resistant cryptographic card does not change the hardware circuit of the device and can replace the existing classical cryptographic card. The quantum-resistant FPGA chip on the board retains the algorithm scalability, and the host computer can complete the software upgrade simply by adding quantum-resistant cryptographic instructions. The gatekeeper-style quantum-resistant cryptographic device does not change the existing protocol interaction process and is independent of existing classical cryptographic devices. This invention can enhance the quantum-resistant security of existing classical cryptographic devices and chips in a low-cost and loosely coupled manner, ensuring the forward security and backward compatibility of the cryptographic system.
[0052] Example 1. A quantum-resistant enhancement method for existing classical cryptographic device systems, the method comprising:
[0053] For existing classical cryptographic devices with PCIe interfaces, quantum-resistant cryptographic cards are used in an internally integrated manner. The quantum-resistant cryptographic cards interact with existing classical cryptographic devices through the PCIe interface and adopt a hybrid architecture of quantum-resistant FPGA programmable devices and classical cryptographic chips. They provide classical cryptographic algorithms and quantum-resistant cryptographic algorithms, supporting the continued use of existing classical cryptographic chips in the post-quantum era.
[0054] For existing classical cryptographic devices that lack a PCIe interface or whose chassis cannot be opened, an external, stand-alone gatekeeper-style quantum security enhancement device is used. This gatekeeper-style quantum security enhancement device interacts with the existing classical cryptographic device via high-speed interfaces such as fiber optic cables, supports multi-channel access, and employs quantum-resistant encryption algorithms to provide quantum-resistant security protection for the key exchange process and digital envelope key encapsulation process based on Diffie-Hellman type cryptographic protocols and elliptic curve derivation protocols, thereby achieving black-box quantum security enhancement for the existing classical cryptographic device system.
[0055] Example 2. The quantum-resistant enhancement method according to Example 1 is characterized in that the classical cryptographic algorithm refers to a cryptographic algorithm constructed based on the large integer factorization and the discrete logarithm / discrete logarithm on elliptic curves problem, and the existing classical cryptographic device system is one or more of the cryptographic chip, cryptographic machine, signature verification machine, gateway, and software system that support the classical cryptographic algorithm.
[0056] Among them, quantum-resistant cryptographic algorithms refer to cryptographic algorithms that can resist attacks from both classical and quantum computers and can run on classical computers, including lattice-based, hash-based, encoding-based, multivariate-based, and homology-based algorithms.
[0057] Example 3. The quantum-resistant enhancement method according to Example 1 is characterized in that the classical cryptographic chip adopts the form of ASIC to fabricate and solidify one or more classical cryptographic algorithms, including SoC classical cryptographic chips and non-SoC classical cryptographic chips, supporting SM1, SM2, SM3, SM4, SM7, SM9, AES, RSA, and EC-DSA algorithms.
[0058] Example 4. According to the quantum-resistant enhancement method described in Example 1, the quantum-resistant cryptographic card adopts two architectures: a quantum-resistant FPGA combined with a classical cryptographic chip of the SoC and a quantum-resistant FPGA combined with a non-classical cryptographic chip of the SoC. It supports both classical cryptographic algorithms and quantum-resistant cryptographic algorithms, ensuring the full-cycle application of classical cryptographic chips in the pre-quantum and post-quantum eras.
[0059] In this system, existing classical cryptographic devices serve as the host computer, while quantum-resistant cryptographic cards serve as the slave computer. Data communication is conducted through a PCIe interface. A quantum-resistant cryptographic card includes one or more of the following: a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, a PCIe interface, a network port, a USB 3.0 port, a serial port, and an expansion interface. Quantum-resistant cryptographic algorithms are deployed within the quantum-resistant FPGA, enabling the expansion of various quantum-resistant algorithms.
[0060] Example 5. The quantum-resistant enhancement method according to Example 1, characterized in that the gatekeeper-type quantum-resistant security enhancement device includes a processor, a memory, and a computing program stored in the memory and capable of running on the processor;
[0061] Among them, the gatekeeper-style quantum security enhancement devices GA and GB are deployed between the sender A and receiver B of the existing classical cryptographic devices and the public network. They provide quantum security protection for key data frames during the key exchange process of the existing classical cryptographic devices system, ensuring the full-cycle application of classical cryptographic devices in the pre-quantum and post-quantum eras without changing the original protocol interaction.
[0062] For Diffie-Hellman type cryptographic protocols, the session keys for sender A and receiver B in existing classical cryptographic devices are provided by... We obtain, where KDF is the key derivation function. , For sender A's random nonce, For receiver B, the random nonce is denoted by aux, which represents other information exchanged between the two parties (one party being A and GA, and the other party being GB and B). It is the temporary public key information publicly transmitted under the original protocol; for a string [R] represents any non-empty substring of R and its equivalent variants. An equivalent variant of a string is one that can be reconstructed from the original string in a conventional manner; let [ ]express Any non-empty substring and its equivalent variants, [ ]express Any non-empty substring and its equivalent variants, [ express Any non-empty substring and its equivalent variants, [ ]express Any non-empty substring of aux and its equivalent variants, where [aux] represents any non-empty substring of aux and its equivalent variants; gatekeeper-style quantum security enhancement devices GA and GB for sets Quantum-resistant security is achieved by applying quantum-resistant protection to any non-empty subset of GA and GB, with the following quantum-resistant security objective: even if the information transmitted between GA and GB is intercepted and recorded by an adversary with quantum computing capabilities, K cannot be effectively calculated. Wherein GA... For any non-empty subset of the given set, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption; and / or, where GB performs quantum-resistant decryption on any non-empty subset of the given set. Quantum-resistant encryption is performed on any non-empty subset of the public key, and quantum-resistant decryption is performed accordingly on the GA. The public key for quantum-resistant encryption can be a long-term fixed public key, a quantum-resistant public key that changes periodically, or a quantum-resistant public key that is temporarily generated for each session. Long-term fixed or periodically changed public keys can be pre-set in the GA and / or GB. To enhance authentication, the public key and other information transmitted between the GA and GB can also be authenticated using a digital signature scheme (if signature authentication is used, the gatekeeper device on the server side is given priority for signing, and the gatekeeper device on the client side verifies the signature). In practice, the public key and other transmitted information can reuse some information to save bandwidth or improve computational efficiency; for example, the randm nonce can also be used as a random seed for the public key.
[0063] In the case of the classic key encapsulation digital envelope protocol, the session keys for sender A and receiver B of the existing classic cryptographic devices are provided by... We obtain, where K is the ciphertext Encryption or encapsulation key, It is sender A using receiver B's public key The encrypted ciphertext, auxK, represents other publicly available information exchanged between the two parties; in this case, gatekeeper-style quantum-resistant security enhancement devices GA and GB are used to enhance the set. Quantum-resistant security is provided for any non-empty subset, where GA is used to... For any non-empty subset of the array, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption.
[0064] Example 6. The quantum-resistant enhancement method according to Example 4, characterized in that the top-level module for implementing the quantum-resistant FPGA includes an algorithm module, a communication module, and a management module;
[0065] The algorithm module is configured to implement quantum-resistant public-key encryption algorithms and digital signature algorithms, and contains six sub-modules:
[0066] The key generation module is configured to generate public and private keys for public-key encryption and digital signature algorithms;
[0067] The encryption module is configured for encryption calculations or key encapsulation calculations.
[0068] The decryption module is configured for decryption calculations or key decapsulation calculations;
[0069] The signature module is configured to perform signature calculations on messages;
[0070] The signature verification module is configured for signature verification calculations;
[0071] The hash module is configured for hash calculations and random bitstream generation calculations.
[0072] The communication module is configured to facilitate data interaction between the quantum-resistant FPGA and external systems. The host computer and the classical cryptographic chip of the SoC send data requests to the quantum-resistant FPGA, while the quantum-resistant FPGA sends data responses to the host computer and the classical cryptographic chip of the SoC. These data packets are arranged according to the communication protocol fields and consist of a header, body, and trailer.
[0073] The packet header is used to indicate the data packet function category, data packet target, version information, algorithm parameters, etc. Specific fields include: function number, request / response, sequence number, version number, transaction number, password identifier, data packet number, whether it is a tail packet, public key length, private key length, plaintext length, signature / ciphertext length, encapsulation key length, and other data lengths.
[0074] The packet body is used to store the data corresponding to each field in the packet header, including the public key, private key, plaintext, signature, ciphertext, encapsulation key, serial number, and version number.
[0075] The packet trailer is used to verify the correctness of data packet transmission, and it uses a CRC checksum.
[0076] Communication module instructions include two types: service instructions and algorithm instructions, including:
[0077] The factory configuration command is a business command. The host computer and the classic cryptographic chip of the SoC send a request data packet. The header field contains the serial number, version number and function code. The quantum-resistant FPGA returns the execution result response data packet.
[0078] The power-on self-test command is a business command. The host computer and the classic cryptographic chip of the SoC send a request data packet to start the self-test function. The quantum-resistant FPGA returns a response data packet with the self-test result.
[0079] The key generation instruction is an algorithm instruction used to generate public and private keys. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the corresponding key generation calculation according to the cryptographic identifier. The quantum-resistant FPGA returns a response data packet, and the packet body fields include public and private key data.
[0080] Encryption instructions are algorithm instructions used to perform encryption calculations and key encapsulation calculations. The host computer and the classic cryptographic chip of the SoC send request data packets and start corresponding calculations according to the cryptographic identifier. The packet body fields include public key data and optional data to be encrypted. The quantum-resistant FPGA returns response data packets, and the packet body fields include ciphertext and encapsulation key data.
[0081] The decryption command is an algorithm command used to perform decryption and decapsulation calculations. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the corresponding calculation according to the cryptographic identifier. The packet body fields include the private key and ciphertext data. The quantum-resistant FPGA returns a response data packet, and the packet body fields include plaintext and encapsulation key data.
[0082] The signature instruction is an algorithm instruction used to perform signature calculations. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the signature calculation based on the cryptographic identifier. The packet body fields include the private key and message data. The quantum-resistant FPGA returns a response data packet, and the packet body fields include the signature data.
[0083] The signature verification command is an algorithmic command used to perform signature verification calculations. The host computer and the classic cryptographic chip of the SoC send request data packets and start decryption calculations based on the cryptographic identifier. The packet body fields include the public key, message, signature, and string data. The quantum-resistant FPGA sends response data packets, and the packet body fields contain the signature verification result data.
[0084] The management module is configured to perform board timing planning, request scheduling, and key management functions.
[0085] Example 7. The quantum-resistant enhancement method according to Example 4 is characterized in that the quantum-resistant FPGA combined with the classical cryptographic chip architecture of SoC includes three types of cryptographic chips and has two working modes;
[0086] Among them, the SoC classical cryptographic chip is the master chip, used to complete classical cryptographic algorithms, host computer data communication, data forwarding, and key management functions; the quantum-resistant FPGA chip is slave chip 1, used to complete quantum-resistant cryptographic algorithm functions; the dedicated non-open-source cryptographic chip is slave chip 2, used to complete non-open-source domain-specific classical cryptographic algorithm functions, and slave chip 2 is an optional configuration; the master chip and slave chip 1 use one or more of the AXI, AHB, and APB bus protocols to complete quantum-resistant cryptographic data communication; the master chip and slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete non-open-source domain-specific classical cryptographic data communication.
[0087] In the first working mode, both quantum-resistant cryptographic and classical cryptographic requests sent by the host computer are processed by the main chip. In the second working mode, quantum-resistant cryptographic requests sent by the host computer are directly processed by slave chip 1, with data packets arranged according to communication protocol fields. Classical cryptographic requests are processed by the main chip and slave chip 2 respectively, based on the cryptographic identifier.
[0088] Example 8. The quantum-resistant enhancement method according to Example 4 is characterized in that the quantum-resistant FPGA combined with a non-SoC classical cryptographic chip architecture includes three types of cryptographic chips, wherein the quantum-resistant FPGA chip is the master chip, used to complete the functions of quantum-resistant cryptographic algorithms, host computer data communication, data forwarding, and key management; the non-SoC classical cryptographic chip is slave chip 1, used to complete the functions of classical cryptographic algorithms; and the dedicated non-open-source cryptographic chip is slave chip 2, used to complete the functions of non-open-source domain-specific classical cryptographic algorithms. Slave chip 2 is an optional configuration; the master chip and slave chip 1 and slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete classical cryptographic data communication.
[0089] Among them, the quantum-resistant cryptographic requests sent by the host computer are processed by the main chip, and the data packets are arranged according to the communication protocol fields. The classical cryptographic requests sent by the host computer are forwarded by the main chip to slave chip 1 and slave chip 2 respectively for processing according to the cryptographic identifier.
[0090] Example 9. The quantum-resistant enhancement method according to Example 4, characterized in that the key transmission and storage method of the quantum-resistant cryptographic card includes:
[0091] For the quantum-resistant FPGA combined with the classic SoC cryptographic chip architecture, key data is transmitted between the quantum-resistant FPGA and the classic SoC cryptographic chip through one or more of the AXI, AHB, and APB bus protocols; the classic SoC cryptographic chip uses a symmetric encryption algorithm to store the quantum-resistant cryptographic private key in ciphertext form in the on-board memory.
[0092] For quantum-resistant FPGA combined with non-SoC classical cryptographic chip architecture, key data is transmitted between the quantum-resistant FPGA and the classical cryptographic chip via one or more of the SPI, IIC, and UART protocols; the quantum-resistant FPGA chip stores the quantum-resistant cryptographic private key in on-board memory.
[0093] Example 10. The quantum-resistant enhancement method according to Example 4 is characterized in that the quantum-resistant cryptographic card uses a cryptographic identifier and a user identifier, and supports multi-user key storage under multiple cryptographic algorithms; when a cryptographic algorithm request is made, it is determined whether the corresponding key data already exists on the board according to the identifier; if not, the corresponding information needs to be transmitted; if it exists, there is no need to send it again, saving communication bandwidth;
[0094] Specifically, regarding the quantum-resistant FPGA combined with the classical cryptographic chip architecture of the SoC: when the quantum-resistant key data inside the quantum-resistant FPGA is lost and an error occurs, it can proactively send an error code to the classical cryptographic chip of the SoC, requesting retransmission of the key data under that identifier; when the quantum-resistant key data inside the classical cryptographic chip of the SoC is lost and an error occurs, it can proactively send an error code to the quantum-resistant FPGA, requesting retransmission of the quantum-resistant key data under that identifier; when the quantum-resistant key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer, requesting to restart the session; when the classical key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer, requesting to restart the session.
[0095] For a quantum-resistant FPGA combined with a non-SoC classical cryptographic chip architecture: when the quantum-resistant key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer to request the session to be restarted; when the classical key data of the non-SoC classical cryptographic chip is lost and an error occurs, it can proactively send an error code to the quantum-resistant FPGA to request the retransmission of the key data under that identifier; when the classical key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer to request the session to be restarted.
[0096] Example 11. The quantum-resistant enhancement method according to Example 4 is characterized in that the random number generator generates random numbers from physical noise sources that comply with national commercial cryptography certification standards, and uses one or more of the SPI, IIC, and UART protocols to interact with the quantum-resistant FPGA and the classical cryptographic chip of the SoC respectively.
[0097] Example 12. The quantum-resistant enhancement method according to Example 4 is characterized in that, through the memory, the quantum-resistant FPGA chip and the SoC classical cryptographic chip can respectively access the program, key information, and user configuration information used.
[0098] Example 13. A quantum-resistant security enhancement device for existing classical cryptographic devices, comprising a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, and a computing program stored in the memory and running on the quantum-resistant FPGA or the classical cryptographic chip, characterized in that the quantum-resistant FPGA or the classical cryptographic chip executes the computer program to implement the quantum-resistant enhancement method described in any of Examples 1-12 above.
[0099] Example 14. An electronic device comprising a memory, a processor, and a computing program stored in the memory and capable of running on the processor, characterized in that the processor executes the computer program to implement any of the quantum-resistant enhancement methods described in Examples 1-12 above.
[0100] Example 15. A computer-readable storage medium having a computer program stored thereon, characterized in that, when the program is executed by a processor, it implements any of the quantum-resistant enhancement methods described in Examples 1-12 above.
[0101] Example 16. A computer program product comprising a computer program / instructions, characterized in that, when executed by a processor, the computer program / instructions implement any of the quantum-resistant enhancement methods described in Examples 1-12 above.
[0102] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0103] The specific embodiments described above further illustrate the purpose, technical approach, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A quantum-resistant enhancement method for existing classical cryptographic device systems, the method comprising: For existing classical cryptographic devices, a gatekeeper-style quantum-resistant security enhancement device is adopted. This gatekeeper-style quantum-resistant security enhancement device interacts with existing classical cryptographic devices externally and independently via a high-speed interface or is integrated into existing cryptographic systems or devices. It supports multi-channel access and employs quantum-resistant encryption algorithms to provide quantum-resistant security protection for key exchange processes and digital envelope key encapsulation processes based on Diffie-Hellman type cryptographic protocols and elliptic curve derivative protocols, thereby achieving black-box quantum-resistant security enhancement of existing classical cryptographic device systems.
2. The anti-quantum enhancement method according to claim 1, characterized in that, For existing classical cryptographic devices with PCIe interfaces, a quantum-resistant cryptographic card is adopted in an internally integrated manner. The quantum-resistant cryptographic card interacts with the existing classical cryptographic devices through the PCIe interface. It adopts a hybrid architecture of quantum-resistant FPGA programmable devices and classical cryptographic chips, providing classical cryptographic algorithms and quantum-resistant cryptographic algorithms, and supporting the continued use of existing classical cryptographic chips in the post-quantum era.
3. The anti-quantum enhancement method according to claim 2, characterized in that, The classical cryptographic algorithm refers to a cryptographic algorithm constructed based on the large integer factorization and the discrete logarithm / discrete logarithm problem on elliptic curves. The existing classical cryptographic device system is one or more of the cryptographic chips, cryptographic machines, signature verification machines, gateways, and software systems that support the classical cryptographic algorithm. Among them, quantum-resistant cryptographic algorithms refer to cryptographic algorithms that can resist attacks from both classical and quantum computers and can run on classical computers, including lattice-based, hash-based, encoding-based, multivariate-based, and homology-based algorithms.
4. The anti-quantum enhancement method according to claim 2, characterized in that, Classic cryptographic chips use ASICs to fabricate and solidify one or more classic cryptographic algorithms, including SoC classic cryptographic chips and non-SoC classic cryptographic chips, supporting SM1, SM2, SM3, SM4, SM7, SM9, AES, RSA, and EC-DSA algorithms.
5. The anti-quantum enhancement method according to claim 2, characterized in that, The quantum-resistant cryptographic card adopts two architectures: quantum-resistant FPGA combined with classical cryptographic chip of SoC and quantum-resistant FPGA combined with non-SoC classical cryptographic chip. It supports both classical cryptographic algorithms and quantum-resistant cryptographic algorithms, ensuring the full life cycle application of classical cryptographic chips in the pre-quantum and post-quantum eras. In this system, existing classical cryptographic devices serve as the host computer, while quantum-resistant cryptographic cards serve as the slave computer. Data communication is conducted through a PCIe interface. A quantum-resistant cryptographic card includes one or more of the following: a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, a PCIe interface, a network port, a USB 3.0 port, a serial port, and an expansion interface. Quantum-resistant cryptographic algorithms are deployed within the quantum-resistant FPGA, enabling the expansion of various quantum-resistant algorithms.
6. The anti-quantum enhancement method according to claim 1, characterized in that, A gatekeeper-style quantum-resistant security enhancement device includes a processor, a memory, and a computing program stored in the memory and capable of running on the processor; Among them, the gatekeeper-style quantum security enhancement devices GA and GB are deployed between the sender A and receiver B of the existing classical cryptographic devices and the public network, or are integrated into the system or device of the sender A and receiver B of the existing classical cryptographic devices. They provide quantum security protection for key data frames during the key exchange process of the existing classical cryptographic device system, and ensure the full life cycle application of classical cryptographic devices in the pre-quantum and post-quantum eras without changing the original protocol interaction. For Diffie-Hellman type cryptographic protocols, the session keys for sender A and receiver B in existing classical cryptographic devices are provided by... We obtain, where KDF is the key derivation function. , For sender A's random nonce, For receiver B, the random nonce is 'aux', and for other publicly available information exchanged between the two parties, 'aux' represents the random nonce of receiver B. It is the temporary public key information publicly transmitted under the original protocol; for a string [R] represents any non-empty substring of R and its equivalent variants. An equivalent variant of a string is one that can be reconstructed from the original string in a conventional manner; let [ ]express Any non-empty substring and its equivalent variants, [ ]express Any non-empty substring and its equivalent variants, [ express Any non-empty substring and its equivalent variants, [ ]express Any non-empty substring of aux and its equivalent variants, where [aux] represents any non-empty substring of aux and its equivalent variants; gatekeeper-style quantum security enhancement devices GA and GB for sets Quantum-resistant security is provided for any non-empty subset, where GA is used to... For any non-empty subset of the array, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption. In the case of the classic key encapsulation digital envelope protocol, the session keys for sender A and receiver B of the existing classic cryptographic devices are provided by... We obtain, where K is the ciphertext Encryption or encapsulation key, It is sender A using receiver B's public key The encrypted ciphertext, auxK, represents other publicly available information exchanged between the two parties; in this case, gatekeeper-style quantum-resistant security enhancement devices GA and GB are used to enhance the set. Quantum-resistant security is provided for any non-empty subset, where GA is used to... For any non-empty subset of the array, quantum-resistant encryption is performed, and GB performs corresponding quantum-resistant decryption.
7. The anti-quantum enhancement method according to claim 5, characterized in that, The top-level module for implementing quantum-resistant FPGA functions includes an algorithm module, a communication module, and a management module. The algorithm module is configured to implement quantum-resistant public-key encryption algorithms and digital signature algorithms, and contains six sub-modules: The key generation module is configured to generate public and private keys for public-key encryption and digital signature algorithms; The encryption module is configured for encryption calculations or key encapsulation calculations. The decryption module is configured for decryption calculations or key decapsulation calculations; The signature module is configured to perform signature calculations on messages; The signature verification module is configured for signature verification calculations; The hash module is configured for hash calculations and random bitstream generation calculations. The communication module is configured to facilitate data interaction between the quantum-resistant FPGA and external systems. The host computer and the classical cryptographic chip of the SoC send data requests to the quantum-resistant FPGA, while the quantum-resistant FPGA sends data responses to the host computer and the classical cryptographic chip of the SoC. These data packets are arranged according to the communication protocol fields and consist of a header, body, and trailer. The header is used to indicate the data packet function category, data packet target, version information, and algorithm parameters. Specific fields include: function number, request / response, sequence number, version number, transaction number, password identifier, data packet number, whether it is a tail packet, public key length, private key length, plaintext length, signature / ciphertext length, encapsulation key length, and other data lengths. The packet body is used to store the data corresponding to each field in the packet header, including the public key, private key, plaintext, signature, ciphertext, encapsulation key, serial number, and version number. The packet trailer is used to verify the correctness of data packet transmission, and it uses a CRC checksum. Communication module instructions include two types: service instructions and algorithm instructions, including: The factory configuration command is a business command. The host computer and the classic cryptographic chip of the SoC send a request data packet. The header field contains the serial number, version number and function code. The quantum-resistant FPGA returns the execution result response data packet. The power-on self-test command is a business command. The host computer and the classic cryptographic chip of the SoC send a request data packet to start the self-test function. The quantum-resistant FPGA returns a response data packet with the self-test result. The key generation instruction is an algorithm instruction used to generate public and private keys. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the corresponding key generation calculation according to the cryptographic identifier. The quantum-resistant FPGA returns a response data packet, and the packet body fields include public and private key data. Encryption instructions are algorithm instructions used to perform encryption calculations and key encapsulation calculations. The host computer and the classic cryptographic chip of the SoC send request data packets and start corresponding calculations according to the cryptographic identifier. The packet body fields include public key data and optional data to be encrypted. The quantum-resistant FPGA returns response data packets, and the packet body fields include ciphertext and encapsulation key data. The decryption command is an algorithm command used to perform decryption and decapsulation calculations. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the corresponding calculation according to the cryptographic identifier. The packet body fields include the private key and ciphertext data. The quantum-resistant FPGA returns a response data packet, and the packet body fields include plaintext and encapsulation key data. The signature instruction is an algorithm instruction used to perform signature calculations. The host computer and the classic cryptographic chip of the SoC send a request data packet and start the signature calculation based on the cryptographic identifier. The packet body fields include the private key and message data. The quantum-resistant FPGA returns a response data packet, and the packet body fields include the signature data. The signature verification command is an algorithmic command used to perform signature verification calculations. The host computer and the classic cryptographic chip of the SoC send request data packets and start decryption calculations based on the cryptographic identifier. The packet body fields include the public key, message, signature, and string data. The quantum-resistant FPGA sends response data packets, and the packet body fields contain the signature verification result data. The management module is configured to perform board timing planning, request scheduling, and key management functions.
8. The anti-quantum enhancement method according to claim 5, characterized in that, The quantum-resistant FPGA combined with the classic cryptographic chip architecture of SoC includes three types of cryptographic chips and has two working modes; Among them, the SoC classical cryptographic chip is the master chip, used to complete classical cryptographic algorithms, host computer data communication, data forwarding, and key management functions; the quantum-resistant FPGA chip is slave chip 1, used to complete quantum-resistant cryptographic algorithm functions; the dedicated non-open-source cryptographic chip is slave chip 2, used to complete non-open-source domain-specific classical cryptographic algorithm functions, and slave chip 2 is an optional configuration; the master chip and slave chip 1 use one or more of the AXI, AHB, and APB bus protocols to complete quantum-resistant cryptographic data communication; the master chip and slave chip 2 use one or more of the SPI, IIC, and UART protocols to complete non-open-source domain-specific classical cryptographic data communication. In the first working mode, both quantum-resistant cryptographic and classical cryptographic requests sent by the host computer are processed by the main chip. In the second working mode, quantum-resistant cryptographic requests sent by the host computer are directly processed by slave chip 1, with data packets arranged according to communication protocol fields. Classical cryptographic requests are processed by the main chip and slave chip 2 respectively, based on the cryptographic identifier.
9. The anti-quantum enhancement method according to claim 5, characterized in that, The quantum-resistant FPGA combined with a non-SoC classical cryptographic chip architecture includes three types of cryptographic chips. The quantum-resistant FPGA chip is the master chip, used to complete the functions of quantum-resistant cryptographic algorithms, upper computer data communication, data forwarding, and key management. The non-SoC classical cryptographic chip is slave chip 1, used to complete the functions of classical cryptographic algorithms. The dedicated non-open-source cryptographic chip is slave chip 2, used to complete the functions of non-open-source domain-specific classical cryptographic algorithms. Slave chip 2 is an optional configuration. The master chip and slave chips 1 and 2 use one or more of the SPI, IIC, and UART protocols to complete classical cryptographic data communication. Among them, the quantum-resistant cryptographic requests sent by the host computer are processed by the main chip, and the data packets are arranged according to the communication protocol fields. The classical cryptographic requests sent by the host computer are forwarded by the main chip to slave chip 1 and slave chip 2 respectively for processing according to the cryptographic identifier.
10. The anti-quantum enhancement method according to claim 5, characterized in that, The key transmission and storage methods of quantum-resistant cryptographic cards include: For the quantum-resistant FPGA combined with the classic SoC cryptographic chip architecture, key data is transmitted between the quantum-resistant FPGA and the classic SoC cryptographic chip through one or more of the AXI, AHB, and APB bus protocols; the classic SoC cryptographic chip uses a symmetric encryption algorithm to store the quantum-resistant cryptographic private key in ciphertext form in the on-board memory. For quantum-resistant FPGA combined with non-SoC classical cryptographic chip architecture, key data is transmitted between the quantum-resistant FPGA and the classical cryptographic chip via one or more of the SPI, IIC, and UART protocols; the quantum-resistant FPGA chip stores the quantum-resistant cryptographic private key in on-board memory.
11. The anti-quantum enhancement method according to claim 5, characterized in that, The quantum-resistant cryptographic card uses cryptographic identifiers and user identifiers, and supports multi-user key storage under various cryptographic algorithms. When a cryptographic algorithm request is made, the identifier is used to determine whether the corresponding key data already exists on the board. If not, the corresponding information needs to be transmitted; if it does, there is no need to send it again, saving communication bandwidth. Specifically, regarding the quantum-resistant FPGA combined with the classical cryptographic chip architecture of the SoC: when the quantum-resistant key data inside the quantum-resistant FPGA is lost and an error occurs, it can proactively send an error code to the classical cryptographic chip of the SoC, requesting retransmission of the key data under that identifier; when the quantum-resistant key data inside the classical cryptographic chip of the SoC is lost and an error occurs, it can proactively send an error code to the quantum-resistant FPGA, requesting retransmission of the quantum-resistant key data under that identifier; when the quantum-resistant key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer, requesting to restart the session; when the classical key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer, requesting to restart the session. For a quantum-resistant FPGA combined with a non-SoC classical cryptographic chip architecture: when the quantum-resistant key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer to request the session to be restarted; when the classical key data of the non-SoC classical cryptographic chip is lost and an error occurs, it can proactively send an error code to the quantum-resistant FPGA to request the retransmission of the key data under that identifier; when the classical key data inside the quantum-resistant cryptographic card is lost and an error occurs, it can proactively send an error code to the host computer to request the session to be restarted.
12. The anti-quantum enhancement method according to claim 5, characterized in that, The random number generator produces random numbers from physical noise sources, conforms to national commercial cryptography certification standards, and uses one or more of the SPI, IIC, and UART protocols to interact with quantum-resistant FPGAs and classical SoC cryptographic chips, respectively.
13. The anti-quantum enhancement method according to claim 5, characterized in that, Through the memory, quantum-resistant FPGA chips and SoC classical cryptographic chips can respectively access the programs, key information, and user configuration information used.
14. A quantum-resistant security enhancement device for existing classical cryptographic devices, comprising a quantum-resistant FPGA chip, a classical cryptographic chip, a random number generator, a memory, and a computational program stored in the memory and running on the quantum-resistant FPGA or the classical cryptographic chip, characterized in that, The quantum-resistant FPGA or classical cryptographic chip executes the computer program to implement the quantum-resistant enhancement method according to any one of claims 1-13.
15. An electronic device comprising a memory, a processor, and a computing program stored in the memory and capable of running on the processor, characterized in that, The processor executes the computer program to implement the quantum-resistant enhancement method according to any one of claims 1-13.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the quantum-resistant enhancement method as described in any one of claims 1-13.
17. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the quantum-resistant enhancement method described in any of claims 1-13.