Multi-mode encryption and decryption system and method, electronic equipment, medium and program product
By using a multimodal encryption and decryption system that combines quantum-resistant and traditional encryption and decryption algorithms, the problem of easy decryption of asymmetric encryption in quantum computing environments has been solved, enabling secure, stable operation and flexible adaptation of power system communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-03-31
AI Technical Summary
In existing technologies, asymmetric encryption algorithms are easily deciphered in a quantum computing environment, threatening the communication security and operational stability of power systems in energy companies.
A multimodal encryption and decryption system is adopted, which combines quantum-resistant encryption and decryption algorithms with traditional encryption and decryption algorithms. By using a startup control module, a key negotiation module, and a message filtering module, the encryption and decryption scheme can be customized and dynamically adapted. A quantum-resistant encryption and decryption chip is also configured to enhance the quantum resistance of network devices.
It improves the flexibility and compatibility of the encryption and decryption system, ensures the security and stability of data transmission, reduces the risk of security service interruption caused by encryption and decryption algorithm anomalies, and enhances the network information security of the power system.
Smart Images

Figure CN121770848A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum-resistant encryption and decryption technology, specifically to multimodal encryption and decryption systems, methods, electronic devices, media, and program products. Background Technology
[0002] With the rapid development of quantum computing technology, the computational advantages of quantum computers in specific fields have brought unprecedented challenges to modern cryptographic systems, making the traditional encrypted communication methods widely used in my country's power monitoring system no longer secure.
[0003] In related technologies, the network security equipment configured in wind farms relies heavily on traditional encryption algorithms such as asymmetric encryption, which are susceptible to being deciphered, seriously threatening the communication security and operational stability of energy companies' power systems. Summary of the Invention
[0004] This invention provides a multimodal encryption and decryption system, method, electronic device, medium, and program product to address the problem that asymmetric encryption algorithms in related technologies seriously threaten the communication security and operational stability of power systems in energy enterprises.
[0005] In a first aspect, the present invention provides a multimodal encryption and decryption system, comprising: a startup control module, a key negotiation module, a message filtering module, and a quantum-resistant encryption and decryption chip configured with multiple quantum-resistant encryption and decryption algorithms and multiple conventional encryption and decryption algorithms; the startup control module is used to start a first target encryption and decryption algorithm corresponding to a preset configuration file according to an acquired preset configuration file, and load the communication tunnel and security rules corresponding to the preset configuration file; the first target encryption and decryption algorithm is one of multiple quantum-resistant encryption and decryption algorithms and multiple conventional encryption and decryption algorithms; the key negotiation module is used to negotiate a key with an external system according to a tunnel table and a key table corresponding to the communication tunnel to obtain a security key; the message filtering module is used to obtain a data packet to be encrypted and decrypted, filter the data packet to be encrypted and decrypted according to the security rules, and obtain a target data packet to be encrypted and decrypted; the quantum-resistant encryption and decryption chip is used to perform encryption and decryption processing on the target data packet to be encrypted and decrypted based on the security key and the first target encryption and decryption algorithm.
[0006] The multimodal encryption / decryption system of this invention includes: a startup control module, a key negotiation module, a message filtering module, and a quantum-resistant encryption / decryption chip configured with multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms. The quantum-resistant encryption / decryption chip is configured with multiple quantum-resistant encryption / decryption algorithms and traditional encryption / decryption algorithms simultaneously, enabling flexible responses to different security requirements and attack scenarios, ensuring the security of data transmission. The startup control module of this invention can flexibly start corresponding algorithms, load communication tunnels and security rules according to a preset configuration file, realizing customized and dynamic adaptation of the encryption / decryption scheme to match the security requirements of different scenarios. The key negotiation module of this invention negotiates a secure key with an external system based on the tunnel table and key table of the communication tunnel, ensuring the security and compliance of the key exchange process and avoiding the risk of key leakage. The message filtering module of this invention filters data packets to be encrypted / decrypted according to security rules, reducing encryption / decryption operations on invalid data packets, improving encryption / decryption efficiency, and preventing non-target data from interfering with the encryption / decryption process. The quantum-resistant encryption / decryption chip of this invention is used to encrypt / decrypt target data packets based on a secure key and a first target encryption / decryption algorithm. Compared with related technologies, this invention simultaneously configures multiple quantum-resistant encryption and decryption algorithms and multiple traditional encryption and decryption algorithms on a quantum-resistant encryption and decryption chip, which enhances the quantum resistance of network devices, ensures the information security of power system networks in the quantum era, greatly improves the flexibility and compatibility of encryption and decryption systems, and guarantees the secure and stable operation of data packet encryption and decryption.
[0007] In one optional implementation, the multimodal encryption and decryption system further includes: an algorithm dynamic switching module, used to switch the first target encryption and decryption algorithm started in the quantum-resistant encryption and decryption chip to a second target encryption and decryption algorithm based on the fact that the start time of the first target encryption and decryption algorithm is greater than a preset time threshold, or by receiving an algorithm switching instruction; the second target encryption and decryption algorithm is an encryption and decryption algorithm that has been verified with an external system.
[0008] The algorithm dynamic switching module of this invention automatically switches encryption and decryption algorithms when the first target algorithm times out or when an algorithm switching command is received. This avoids system lag and service interruption caused by startup delays of a single encryption / decryption algorithm, improving the response efficiency and stability of the encryption / decryption process. It meets the needs of manual intervention while ensuring compatibility of the switched algorithm with external systems, achieving flexible adjustment and cross-system adaptation of encryption / decryption schemes. When a certain encryption / decryption algorithm experiences startup failure or insufficient performance, it can quickly switch to other encryption / decryption algorithms, reducing the risk of security service interruption due to encryption / decryption algorithm anomalies.
[0009] In one optional implementation, the startup control module includes an algorithm determination unit; the algorithm determination unit is used to parse a preset configuration file to obtain a preset encryption / decryption algorithm, and to match the preset encryption / decryption algorithm with a plurality of quantum-resistant encryption / decryption algorithms and a plurality of conventional encryption / decryption algorithms configured in the quantum-resistant encryption / decryption chip to obtain a first target encryption / decryption algorithm.
[0010] In one optional implementation, the key negotiation module includes a key judgment unit, a request generation unit, an authentication unit, and a key generation unit. The key judgment unit is used to scan the tunnel table and the key table to determine the initial key corresponding to the current hop tunnel, determine whether the initial key has expired, and use the initial key as a security key if it has not expired. The request generation unit is used to generate a key negotiation request if the initial key has expired and send the key negotiation request to the external system. The authentication unit is used to obtain the negotiation response message sent by the external system and verify whether the identity of the external system is legitimate. The key generation unit is used to negotiate a key with the external system based on the first target encryption / decryption algorithm, based on the legitimate identity of the external system, to obtain a security key.
[0011] In one optional implementation, the message filtering module includes a data packet acquisition unit, a protocol type filtering unit, a protocol option filtering unit, an address filtering unit, and a port filtering unit. The data packet acquisition unit is used to acquire multiple data packets to be encrypted / decrypted by monitoring the communication interface. The protocol type filtering unit is used to send a first data packet that conforms to a preset protocol from the multiple data packets to be encrypted / decrypted to the protocol option filtering unit. The protocol option filtering unit is used to send a second data packet that conforms to a preset protocol option from the first data packet to the address filtering unit. The address filtering unit is used to send a third data packet that conforms to a preset receiving address or a preset sending address from the second data packet to the port filtering unit. The port filtering unit is used to determine the data packet that conforms to a preset port number from the third data packet as the target data packet to be encrypted / decrypted.
[0012] In one optional implementation, the multimodal encryption and decryption system further includes an anomaly alarm module, which monitors the working status of the startup control module, key negotiation module, message filtering module, and quantum-resistant encryption and decryption chip, and triggers an alarm if the working status is abnormal.
[0013] Secondly, the present invention provides a multimodal encryption and decryption method, comprising: activating a first target encryption and decryption algorithm corresponding to the preset configuration file according to an acquired preset configuration file; loading a communication tunnel and security rules corresponding to the preset configuration file; the first target encryption and decryption algorithm being one of multiple quantum-resistant encryption and decryption algorithms and multiple traditional encryption and decryption algorithms; negotiating a key with an external system according to a tunnel table and a key table corresponding to the communication tunnel to obtain a security key; acquiring a data packet to be encrypted and decrypted, filtering the data packet according to the security rules to obtain a target data packet to be encrypted and decrypted; and encrypting and decrypting the target data packet according to the first target encryption and decryption algorithm based on the security key.
[0014] Thirdly, the present invention provides an electronic device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the multimodal encryption and decryption method of the second aspect above by executing the computer instructions.
[0015] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the multimodal encryption / decryption method of the second aspect described above.
[0016] Fifthly, the present invention provides a computer program product, including computer instructions for causing a computer to execute the multimodal encryption / decryption method described in the second aspect above. Attached Figure Description
[0017] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of an application scenario according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the first structure of a multimodal encryption / decryption system according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a second structure of a multimodal encryption / decryption system according to an embodiment of the present invention; Figure 4 This is a schematic diagram of a third structure of a multimodal encryption / decryption system according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the fourth structure of a multimodal encryption / decryption system according to an embodiment of the present invention; Figure 6This is a flowchart illustrating a multimodal encryption / decryption method according to an embodiment of the present invention; Figure 7 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] It is understood that before using the technical solutions disclosed in the various embodiments of the present invention, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in the present invention and their authorization should be obtained in accordance with relevant laws and regulations through appropriate means.
[0021] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0022] As an optional application scenario of this invention, such as Figure 1 As shown, the multimodal encryption / decryption system may include at least one terminal device and at least one server. Figure 1 The system is illustrated in the example, which includes a computer 101, a mobile terminal 102, and a server 103, and the terminal devices such as the computer 101 and the mobile terminal 102 are connected to the server 103 through a network 110.
[0023] Specifically, the terminal device can be a smartphone, tablet, laptop, PDA, desktop computer, game console, smart TV, smart wearable device, in-vehicle terminal, VR (Virtual Reality) device, AR (Augmented Reality) device, etc. Server 103 can be a standalone physical server, a server cluster, a distributed system, or a cloud server providing cloud services. Network 110 can be a wired or wireless network, examples of which include, but are not limited to, the Internet, corporate intranet, local area network, wide area network, mobile communication network, and combinations thereof.
[0024] This invention provides a multimodal encryption and decryption system that improves the communication security of power systems in energy companies by configuring multiple quantum-resistant encryption and decryption algorithms and multiple traditional encryption and decryption algorithms on a quantum-resistant encryption and decryption chip.
[0025] According to an embodiment of the present invention, a multimodal encryption and decryption system embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0026] This embodiment provides a multimodal encryption / decryption system that can be used in computer equipment, specifically, in computer equipment installed in wind farms. Figure 2 This is a first structural diagram of a multimodal encryption / decryption system according to an embodiment of the present invention, such as... Figure 2 As shown, the structure includes: The system includes a startup control module 201, a key negotiation module 202, a message filtering module 203, and a quantum-resistant encryption / decryption chip 204 configured with multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms.
[0027] The startup control module 201 is used to start the first target encryption / decryption algorithm corresponding to the preset configuration file according to the obtained preset configuration file, and load the communication tunnel and security rules corresponding to the preset configuration file; the first target encryption / decryption algorithm is one of multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms.
[0028] The preset configuration file is a pre-defined file used to specify encryption and decryption algorithms, communication tunnels, and security rules; the communication tunnel is an encrypted channel for the multimodal encryption and decryption system of this invention to transmit data with external systems; the security rules are preset security specifications that constrain data processing, communication, and other processes, and the security rules set preset protocols, preset protocol options, preset receiving addresses or preset sending addresses, and preset port numbers, etc.
[0029] In some alternative implementations, multiple quantum-resistant encryption and decryption algorithms include Kyber, Dilithium, and SPHINCS quantum-resistant computing algorithms; multiple traditional encryption and decryption algorithms include the three national cryptographic algorithms SM3, SM4, and SM9.
[0030] The key negotiation module 202 is used to negotiate a key with an external system based on the tunnel table and key table corresponding to the communication tunnel to obtain a security key.
[0031] The tunnel table is a list that records communication tunnel information; the key table is a list that records key information; the external system is a system that encrypts with the multimodal encryption and decryption system of this invention, such as a data management system for wind power generation; and the security key is a confidential key used for encrypting and decrypting data.
[0032] The message filtering module 203 is used to obtain the data packets to be encrypted or decrypted, filter the data packets to be encrypted or decrypted according to security rules, and obtain the target data packets to be encrypted or decrypted.
[0033] Among them, the data packets to be encrypted or decrypted are data packets sent by external systems that require encryption or decryption processing.
[0034] In some optional implementations, the security rules include multiple preset rules. Based on these preset rules, it is determined whether the data packet to be encrypted / decrypted conforms to the preset rules, thus filtering the data packet to obtain the target data packet to be encrypted / decrypted. For example, the multiple preset rules include preset protocol types, preset protocol options, preset addresses, and preset ports, etc.
[0035] The quantum-resistant encryption / decryption chip 204 is used to encrypt and decrypt target data packets based on a security key and a first target encryption / decryption algorithm.
[0036] The algorithm dynamic switching module 205 is used to switch the first target encryption and decryption algorithm started in the quantum-resistant encryption and decryption chip to the second target encryption and decryption algorithm according to the startup time of the first target encryption and decryption algorithm being greater than a preset time threshold, or by receiving an algorithm switching instruction; the second target encryption and decryption algorithm is an encryption and decryption algorithm that has been verified with an external system.
[0037] The preset time threshold can be set according to the actual situation. For example, the preset time threshold can be 7 days. The algorithm switching instruction is a user-input instruction signal used to switch the first target encryption and decryption algorithm. The algorithm switching instruction may or may not include the second target encryption and decryption algorithm. When the second target encryption and decryption algorithm is included, the first target encryption and decryption algorithm is switched to the second target encryption and decryption algorithm. When the second target encryption and decryption algorithm is not included, an appropriate second target encryption and decryption algorithm is selected for switching. For example, when the first target encryption and decryption algorithm is one of multiple quantum-resistant encryption and decryption algorithms, it is switched to one of multiple traditional encryption and decryption algorithms.
[0038] In this embodiment of the invention, the algorithm dynamic switching module 205 automatically switches the encryption / decryption algorithm when the first target algorithm times out or when an algorithm switching instruction is received. This avoids system lag and service interruption caused by startup delays of a single encryption / decryption algorithm, improving the response efficiency and stability of the encryption / decryption process. It meets the needs of manual intervention while ensuring compatibility of the switched algorithm with external systems, achieving flexible adjustment and cross-system adaptation of the encryption / decryption scheme. When a certain encryption / decryption algorithm experiences startup failure or insufficient performance, it can quickly switch to other encryption / decryption algorithms, reducing the risk of security service interruption due to encryption / decryption algorithm anomalies.
[0039] The abnormal alarm module 206 is used to monitor the working status of the startup control module 201, the key negotiation module 202, the message filtering module 203, and the quantum-resistant encryption and decryption chip 204, and trigger an alarm when the working status is abnormal.
[0040] When any one of the following modules malfunctions, such as the start control module 201, the key negotiation module 202, the message filtering module 203, or the quantum-resistant encryption / decryption chip 204, an alarm is triggered. The method of triggering the alarm can be set according to the actual situation. For example, an alarm can be triggered by sending an alarm message.
[0041] The multimodal encryption / decryption system provided in this embodiment includes: a startup control module, a key negotiation module, a message filtering module, and a quantum-resistant encryption / decryption chip configured with multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms. The quantum-resistant encryption / decryption chip is configured with multiple quantum-resistant encryption / decryption algorithms and traditional encryption / decryption algorithms simultaneously, enabling flexible responses to different security requirements and attack scenarios, ensuring the security of data transmission. The startup control module of this embodiment can flexibly start corresponding algorithms, load communication tunnels and security rules according to a preset configuration file, realizing customized and dynamic adaptation of encryption / decryption schemes to match the security requirements of different scenarios. The key negotiation module of this embodiment negotiates a secure key with an external system based on the tunnel table and key table of the communication tunnel, ensuring the security and compliance of the key exchange process and avoiding the risk of key leakage. The message filtering module of this embodiment filters data packets to be encrypted / decrypted according to security rules, reducing encryption / decryption operations on invalid data packets, improving encryption / decryption efficiency, and preventing non-target data from interfering with the encryption / decryption process. The quantum-resistant encryption / decryption chip of this embodiment is used to encrypt / decrypt target data packets based on a secure key and a first target encryption / decryption algorithm. Compared with related technologies, the embodiments of the present invention simultaneously configure multiple quantum-resistant encryption and decryption algorithms and multiple traditional encryption and decryption algorithms on the quantum-resistant encryption and decryption chip, which enhances the quantum resistance of network devices, ensures the information security of power system networks in the quantum era, greatly improves the flexibility and compatibility of encryption and decryption systems, and ensures the secure and stable operation of data packet encryption and decryption.
[0042] This embodiment provides a multimodal encryption / decryption system that can be used in computer devices. Figure 3 This is a second structural diagram of a multimodal encryption / decryption system according to an embodiment of the present invention, such as... Figure 3 As shown, the structure includes: The system includes a startup control module 301, a key negotiation module 302, a message filtering module 303, and a quantum-resistant encryption / decryption chip 304 configured with multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms.
[0043] The startup control module 301 is used to start the first target encryption / decryption algorithm corresponding to the preset configuration file according to the acquired preset configuration file, and load the communication tunnel and security rules corresponding to the preset configuration file; the first target encryption / decryption algorithm is one of multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms.
[0044] The key negotiation module 302 is used to negotiate a security key with an external system based on the tunnel table and key table corresponding to the communication tunnel.
[0045] The message filtering module 303 is used to obtain the data packet to be encrypted or decrypted, filter the data packet to be encrypted or decrypted according to the security rules, and obtain the target data packet to be encrypted or decrypted.
[0046] The quantum-resistant encryption / decryption chip 304 is used to encrypt and decrypt target data packets based on a security key and a first target encryption / decryption algorithm.
[0047] In some optional implementations, the startup control module 301 includes an algorithm determination unit 3011; the algorithm determination unit 3011 is used to parse a preset configuration file to obtain a preset encryption and decryption algorithm, and to match the preset encryption and decryption algorithm with a plurality of quantum-resistant encryption and decryption algorithms and a plurality of conventional encryption and decryption algorithms configured in the quantum-resistant encryption and decryption chip 304 to obtain a first target encryption and decryption algorithm.
[0048] The preset encryption / decryption algorithm is the one specified by the user in the preset configuration file.
[0049] In some optional implementations, a first target encryption / decryption algorithm is selected from a plurality of quantum-resistant encryption / decryption algorithms and a plurality of conventional encryption / decryption algorithms configured in the quantum-resistant encryption / decryption chip 304, according to a preset encryption / decryption algorithm.
[0050] In some optional implementations, the key negotiation module 302 includes a key judgment unit 3021, a request generation unit 3022, an authentication unit 3023, and a key generation unit 3024. The key judgment unit 3021 is used to scan the tunnel table and the key table to determine the initial key corresponding to the current hop tunnel, determine whether the initial key has expired, and use the initial key as a security key if it has not expired. The request generation unit 3022 is used to generate a key negotiation request if the initial key has expired and send the key negotiation request to the external system. The authentication unit 3023 is used to obtain the negotiation response message sent by the external system and verify whether the identity of the external system is legitimate. The key generation unit 3024 is used to negotiate a key with the external system based on the first target encryption and decryption algorithm, based on the legitimate identity of the external system, to obtain a security key.
[0051] In some optional implementations, the message filtering module 303 includes a packet acquisition unit 3031, a protocol type filtering unit 3032, a protocol option filtering unit 3033, an address filtering unit 3034, and a port filtering unit 3035.
[0052] The data packet acquisition unit 3031 is used to acquire multiple data packets to be encrypted / decrypted by monitoring the communication interface; the protocol type filtering unit 3032 is used to send the first data packet that conforms to a preset protocol from the multiple data packets to be encrypted / decrypted to the protocol option filtering unit; the protocol option filtering unit 3033 is used to send the second data packet that conforms to a preset protocol option from the first data packet to the address filtering unit; the address filtering unit 3034 is used to send the third data packet that conforms to a preset receiving address or a preset sending address from the second data packet to the port filtering unit; and the port filtering unit 3035 is used to determine the data packet that conforms to a preset port number from the third data packet as the target data packet to be encrypted / decrypted.
[0053] For example, the preset protocol, preset protocol options, preset receiving address or preset sending address, and preset port number can be set according to the actual situation. For example, the preset protocol can be the HTTP (Hypertext Transfer Protocol) protocol, the preset protocol options can be a specific version number or encryption option in the HTTP protocol, the preset receiving address or preset sending address can be a specific IP (Internet Protocol Address Range) address range or domain name, and the preset port number can be a common security port.
[0054] The multimodal encryption and decryption system in this invention enhances the quantum resistance of network devices, ensuring the security of power system network information in the quantum era, given that traditional encrypted communication methods widely used in my country's power monitoring system are no longer secure. This is especially relevant in the context of traditional encrypted communication methods becoming insecure. Furthermore, by flexibly deploying national cryptographic algorithms or quantum-resistant algorithms, the system's flexibility is greatly enhanced, reducing the migration cost of quantum-resistant algorithms and improving system compatibility, thus ensuring the safe and stable operation of wind farms.
[0055] This embodiment provides a multimodal encryption / decryption system that can be used in computer devices. Figure 4 This is a third structural diagram of a multimodal encryption / decryption system according to an embodiment of the present invention, such as... Figure 4 As shown, the structure includes a quantum-resistant cryptographic module 401 and a main processing module 402, which are connected via a PCI-E (Peripheral Component Interconnect Express) interface.
[0056] In some alternative implementations, such as Figure 5 The diagram shows the fourth architecture of a multimodal encryption / decryption system. The quantum-resistant cryptographic module 501 integrates a quantum-resistant encryption chip, which internally integrates three Chinese national cryptographic algorithms (SM3, SM4, and SM9) and three quantum-resistant algorithms (Kyber, Dilithium, and SPHINCS). The main functions of the quantum-resistant cryptographic module 501 are key negotiation and data encryption / decryption, and it interacts with the main processing module 502 via a high-speed PCI-E interface. The main processing module 502, as the core module of the entire system, runs a domestically developed embedded operating system on its main processor and integrates an IP packet filtering unit 5021, a device monitoring unit 5022, a security management unit 5023, a packet decapsulation unit 5024, and a network data packet receiving and sending unit 5025. The main processing module 502 completes external data interaction through a network interface and exchanges data with the quantum-resistant cryptographic module 501 via a high-speed PCI-E interface.
[0057] Specifically, the processing of the IP packet filtering unit 5021 is completed within the operating system kernel, performing security policy-based checks on all data packets entering and leaving the system. It judges the protocol type, protocol options, source / destination address, source / destination port, and other filtering conditions of passing IP packets, performing corresponding allow or discard operations. If the judgment is successful, the packet is sent to the encryption card for encryption and decryption.
[0058] The equipment monitoring unit 5022 is mainly responsible for monitoring the operating status of each module of the device and the working status of the encryption card. If any abnormality is detected, an alarm will be triggered immediately.
[0059] The security management unit 5023 primarily handles local and remote management. Local management includes system initialization and device configuration (administrator authentication, certificate import, IP address configuration, and encryption / decryption algorithm configuration), providing users with a visual management interface for direct configuration. Remote management mainly involves receiving remote queries and configuration management from the host computer.
[0060] The message decapsulation unit 5024 is mainly used to complete the decapsulation of messages.
[0061] The network packet receiving and sending unit 5025 is mainly used to complete the sending or receiving of decapsulated messages over the network.
[0062] This embodiment provides a multimodal encryption / decryption method that can be used in a multimodal encryption / decryption system. Figure 6 This is a flowchart of a multimodal encryption / decryption method according to an embodiment of the present invention, such as... Figure 6 As shown, the process includes the following steps: Step S601: Based on the obtained preset configuration file, start the first target encryption / decryption algorithm corresponding to the preset configuration file, and load the communication tunnel and security rules corresponding to the preset configuration file; the first target encryption / decryption algorithm is one of multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms.
[0063] Step S602: Based on the tunnel table and key table corresponding to the communication tunnel, perform key negotiation with the external system to obtain the security key.
[0064] Step S603: Obtain the data packet to be encrypted / decrypted, filter the data packet to be encrypted / decrypted according to the security rules, and obtain the target data packet to be encrypted / decrypted.
[0065] Step S604: Based on the security key, the target data packet to be encrypted or decrypted is encrypted or decrypted according to the first target encryption / decryption algorithm.
[0066] In some optional implementations, the multimodal encryption and decryption method further includes: switching the first target encryption and decryption algorithm started in the quantum-resistant encryption and decryption chip to a second target encryption and decryption algorithm based on the fact that the start time of the first target encryption and decryption algorithm is greater than a preset time threshold, or receiving an algorithm switching instruction; the second target encryption and decryption algorithm is an encryption and decryption algorithm that has been verified with an external system.
[0067] In some optional implementations, the multimodal encryption and decryption method further includes: monitoring the working status of the startup control module, the key negotiation module, the message filtering module, and the quantum-resistant encryption and decryption chip, and triggering an alarm if the working status is abnormal.
[0068] In some optional implementations, the first target encryption / decryption algorithm corresponding to the preset configuration file is activated according to the obtained preset configuration file, including: parsing the preset configuration file to obtain the preset encryption / decryption algorithm, and matching the preset encryption / decryption algorithm with multiple quantum-resistant encryption / decryption algorithms and multiple traditional encryption / decryption algorithms configured in the quantum-resistant encryption / decryption chip to obtain the first target encryption / decryption algorithm.
[0069] In some optional implementations, a key negotiation is performed with an external system based on the tunnel table and key table corresponding to the communication tunnel to obtain a security key. This includes: scanning the tunnel table and key table to determine the initial key corresponding to the current hop tunnel, determining whether the initial key has expired, and using the initial key as a security key if it has not expired; generating a key negotiation request if the initial key has expired, and sending the key negotiation request to the external system; and, based on the legitimacy of the external system's identity, performing key negotiation with the external system using a first target encryption / decryption algorithm to obtain a security key.
[0070] In some optional implementations, acquiring the data packet to be encrypted / decrypted and filtering it according to security rules to obtain the target data packet to be encrypted / decrypted includes: acquiring multiple data packets to be encrypted / decrypted by monitoring the communication interface; filtering a first data packet that conforms to a preset protocol among the multiple data packets to be encrypted / decrypted; filtering a second data packet that conforms to a preset protocol option among the first data packets; filtering a third data packet that conforms to a preset receiving address or a preset sending address among the second data packets; and determining the data packet that conforms to a preset port number among the third data packets as the target data packet to be encrypted / decrypted.
[0071] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.
[0072] The following is a detailed reference. Figure 7 This diagram illustrates a suitable structural schematic for implementing an electronic device according to embodiments of the present invention. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 701, which can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) 702 or a program loaded from memory 708 into random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device. The processor 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0073] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic devices to exchange data via wireless or wired communication with other devices. Although Figure 7 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0074] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 709, or installed from a memory 708, or installed from a ROM 702. When the computer program is executed by the processor 701, it performs the functions defined in the multimodal encryption / decryption method of the embodiments of the present invention.
[0075] Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.
[0076] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the multimodal encryption / decryption methods shown in the above embodiments are implemented.
[0077] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0078] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A multi-modal encryption and decryption system, characterized by, The system comprises a start control module, a key negotiation module, a message filtering module, and an anti-quantum encryption chip configured with a plurality of anti-quantum encryption algorithms and a plurality of traditional encryption algorithms; The start control module is configured to start a first target encryption algorithm corresponding to a preset configuration file according to the preset configuration file, load a communication tunnel and a security rule corresponding to the preset configuration file, and the first target encryption algorithm is one of the plurality of anti-quantum encryption algorithms and the plurality of traditional encryption algorithms; The key negotiation module is configured to negotiate a security key with an external system according to a tunnel table and a key table corresponding to the communication tunnel; The message filtering module is configured to obtain a target encryption data packet by filtering a to-be-encrypted data packet according to the security rule; The anti-quantum encryption chip is configured to perform encryption and decryption processing on the target to-be-encrypted data packet according to the first target encryption algorithm based on the security key.
2. The system of claim 1, wherein, The system further comprises: An algorithm dynamic switching module is configured to switch the first target encryption algorithm started in the anti-quantum encryption chip to a second target encryption algorithm when the start time of the first target encryption algorithm is greater than a preset time threshold or an algorithm switching instruction is received, and the second target encryption algorithm is an encryption algorithm that has been verified with the external system.
3. The system of claim 1 or 2, wherein, The start control module comprises an algorithm determination unit; The algorithm determination unit is configured to analyze the preset configuration file to obtain a preset encryption algorithm, and match the preset encryption algorithm with the plurality of anti-quantum encryption algorithms and the plurality of traditional encryption algorithms configured in the anti-quantum encryption chip to obtain the first target encryption algorithm.
4. The system of claim 1 or 2, wherein, The key negotiation module comprises a key judgment unit, a request generation unit, an identity verification unit, and a key generation unit; The key judgment unit is configured to scan the tunnel table and the key table, determine an initial key corresponding to a current tunnel, judge whether the initial key is expired, and use the initial key as the security key when the initial key is not expired; The request generation unit is configured to generate a key negotiation request when the initial key is expired, and send the key negotiation request to the external system; The identity verification unit is configured to obtain a negotiation response message sent by the external system to verify whether the identity of the external system is legal; The key generation unit is configured to negotiate a security key with the external system based on the first target encryption algorithm when the identity of the external system is legal.
5. The system of claim 1 or 2, wherein, The message filtering module comprises a data packet acquisition unit, a protocol type filtering unit, a protocol option filtering unit, an address filtering unit, and a port filtering unit; The data packet acquisition unit is configured to obtain a plurality of to-be-encrypted data packets by listening to a communication interface; The protocol type filtering unit is configured to send a first data packet meeting a preset protocol in the plurality of to-be-encrypted data packets to the protocol option filtering unit; The protocol option filtering unit is configured to send a second data packet meeting a preset protocol option in the first data packet to the address filtering unit. The address filtering unit is configured to send a third data packet meeting a preset receiving address or a preset sending address in the second data packet to the port filtering unit. The port filtering unit is configured to determine a data packet meeting a preset port number in the third data packet as the target data packet to be encrypted or decrypted.
6. The system of claim 1 or 2, wherein, The system further comprises: An exception alarm module configured to monitor working states of the start control module, the key negotiation module, the message filtering module and the quantum-resistant encryption and decryption chip, and trigger an alarm according to the working states being in an abnormal state.
7. A multi-modal encryption and decryption method, characterized by, The method comprises: According to the obtained preset configuration file, a first target encryption and decryption algorithm corresponding to the preset configuration file is started, a communication tunnel and a security rule corresponding to the preset configuration file are loaded, and the first target encryption and decryption algorithm is one of a plurality of quantum-resistant encryption and decryption algorithms and a plurality of traditional encryption and decryption algorithms; According to a tunnel table and a key table corresponding to the communication tunnel, key negotiation is performed with an external system to obtain a security key; A data packet to be encrypted or decrypted is obtained, the data packet to be encrypted or decrypted is filtered according to the security rule, and a target data packet to be encrypted or decrypted is obtained; Based on the security key, the target data packet to be encrypted or decrypted is encrypted or decrypted according to the first target encryption and decryption algorithm.
8. An electronic device, comprising: It comprises: A memory and a processor, which are in communication connection with each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the multi-modal encryption and decryption method of claim 7.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to make a computer execute the multi-modal encryption and decryption method of claim 7.
10. A computer program product, characterised in that, The computer instructions are used to make a computer execute the multi-modal encryption and decryption method of claim 7.