Quantum key distribution and anti-quantum signature secure fusion method

By introducing quantum-resistant digital signature algorithms and high-strength symmetric encryption algorithms into the quantum key distribution system, the problems of identity authentication and communication security under quantum computing attacks are solved, achieving efficient and secure quantum key distribution and data encryption, and adapting to the smooth evolution of existing network architectures.

CN121814463APending Publication Date: 2026-04-07WEIDE GUANGDONG INFORMATION TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-06
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies lack protection for initial identity authentication in quantum key distribution systems, which means that quantum computing attacks may break the communication security chain. Furthermore, pure quantum-resistant algorithms have performance bottlenecks, making it difficult to achieve efficient and secure communication.

Method used

The quantum-resistant digital signature algorithm ML-DSA is used for identity authentication. Combined with quantum key distribution QKD and high-strength symmetric encryption algorithm AES-256, a quantum-resistant security system is formed through key derivation, management and update processes to ensure real-time security and forward and backward security of communication.

Benefits of technology

It achieves end-to-end quantum-secure communication, resists quantum computing attacks, ensures absolute security of key distribution and high efficiency of data encryption, adapts to existing network architectures, and provides long-term security and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121814463A_ABST
    Figure CN121814463A_ABST
Patent Text Reader

Abstract

The invention relates to a quantum key distribution and anti-quantum signature secure fusion method, which comprises the following steps: two communication parties initialize a system and establish a communication channel, establish a data channel for transmitting public information, and complete physical synchronization of a quantum channel for transmitting quantum states, and the two communication parties distribute the quantum states through the quantum channel, a shared quantum key is obtained on a data channel through basis vector comparison, information coordination and privacy amplification, two communication parties obtain a session working key for data encryption through a key derivation function based on the shared quantum key, a sender encrypts plaintext data by using the session working key and a symmetric encryption algorithm, and the encrypted plaintext data is transmitted to a server. And S105, the ciphertext is transmitted to a receiver through a data channel, the receiver carries out decryption by using the same session working key, and according to a preset strategy, S103 to S105 are repeatedly executed to update the session working key and carry out secure erasure on an invalid old key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum information technology, specifically to a secure fusion method of quantum key distribution and quantum-resistant signatures. Background Technology

[0002] This invention addresses the "store now, decrypt later" threat faced by existing security solutions in the quantum era. The method proposes a QKD scheme that abandons reliance on traditional digital signatures for authentication and avoids the performance bottleneck caused by pure quantum-resistant algorithms. Its core innovation lies in using the quantum-resistant digital signature algorithm ML-DSA to achieve strong identity authentication and communication integrity protection on public data channels.

[0003] This invention utilizes quantum key distribution (QKD) to generate and transmit key seeds with information-theoretic security on a dedicated quantum channel. Combined with the high-strength symmetric encryption algorithm AES-256, it achieves efficient data encryption. Through a complete key derivation, management, and update process, this invention achieves the organic synergy of quantum-resistant authentication, quantum key distribution, and symmetric encryption. This not only ensures real-time communication security but also provides forward and backward security that is difficult to achieve with traditional cryptography through a real-time key update and destruction mechanism, fundamentally resisting the threat of future quantum computer cracking.

[0004] To address this threat, the industry is exploring two main technological paths: Quantum cryptography approach: represented by quantum key distribution (QKD); QKD is based on the principles of quantum mechanics and can generate and share keys with information theory security between communicating parties; this means that any eavesdropping will inevitably be detected, thus ensuring the absolute security of key distribution from a physical level; Quantum-resistant cryptography (post-quantum cryptography) approach: represented by quantum-resistant cryptographic algorithms (ML-DSA and ML-KEM in the NISTPQC standard); these algorithms are based on lattice and encoding mathematical problems that are still difficult even under quantum computers, aiming to achieve encryption and signature functions that can resist quantum attacks on classical computing devices through algorithmic innovation.

[0005] Existing technical solutions are still primarily focused on optimizing "key management" itself, without addressing the initial authentication of the QKD system. The QKD process still requires communication such as basis vector comparison and information coordination through classical channels, and the integrity and authenticity protection of these classical communications traditionally still relies on digital signatures based on RSA or ECC. This results in a vulnerability in the "authentication" stage of the entire system's security chain, which can be compromised by quantum computing. Existing technologies also focus on extending the QKD transmission distance, with their technical features entirely centered around the physical layer objective of "how to securely transmit quantum keys." There is an urgent need to solve how to seamlessly integrate quantum-resistant authentication (ML-DSA), quantum key distribution (QKD), and efficient symmetric encryption (AES) to form a complete and closed-loop quantum-resistant security system that goes from "trustworthy identity" to "absolute key security" and then to "efficient data confidentiality". Summary of the Invention

[0006] To address the problems existing in the prior art, this application aims to provide a secure fusion method for quantum key distribution and quantum-resistant signatures.

[0007] The secure fusion method of quantum key distribution and quantum-resistant signature described in this application includes: S101. Both communicating parties initialize the system and establish a communication channel, including establishing a data channel for transmitting public information and completing the physical synchronization of the quantum channel for transmitting quantum states. S102. Both communicating parties use the private key of the quantum-resistant digital signature algorithm to sign the exchanged authentication information on the data channel, and use the other party's public key to verify the signature, which is used to complete two-way identity authentication in a quantum computing environment. S103. The two communicating parties distribute quantum states through a quantum channel, perform basis vector comparison, information coordination, and privacy amplification on the data channel, and obtain a shared quantum key. S104. Based on the shared quantum key, the two communicating parties generate a session working key for data encryption through a key derivation function; S105. The sender uses the session working key and symmetric encryption algorithm to encrypt the plaintext data and transmits the ciphertext to the receiver through the data channel. The receiver uses the same session working key to decrypt the data. S106. According to the preset strategy, both parties to the communication repeat S103 to S105 to update the session working key and securely erase the invalid old key.

[0008] Preferably, in S101, the two communicating parties initiate system initialization, obtain their respective local clock signals as time references, measure round-trip delay by exchanging classical pulse sequences, adjust local clock offset for preliminary time alignment, send quantum light pulses, and monitor the interference intensity received by the other end. If the intensity is lower than a preset threshold, the local clock phase is finely adjusted until the interference intensity is maximized, thereby determining precise physical synchronization. The synchronization is used to establish a quantum channel and allocate wavelength resources. Entangled photon pairs are transmitted on the channel using an entanglement distribution protocol. The other end is confirmed to have received the entangled state, and the shared quantum resources are obtained.

[0009] Preferably, in S102, the two communicating parties initiate authentication through the data channel, collect and structure the authentication information to be exchanged to ensure its integrity, use a quantum-resistant digital signature algorithm and their own private key to sign the information content, obtain signed authentication data, exchange these signature data through the data channel, and confirm the integrity of the reception. The receiver uses the sender's public key to verify the signature. If the verification fails, the data is retrieved again until the verification passes. Based on the verification result, identity confirmation is performed. If the information matches, the status is recorded to obtain the final identity verification record. The security mechanism status of both parties is updated according to the record, marking the successful establishment of a trust relationship on the data channel.

[0010] Preferably, in S103, the quantum state is distributed through the quantum channel to obtain the initial quantum bit sequence. The two parties exchange basis selection information through the data channel and record it. By comparing the basis records, the set of quantum bits corresponding to the matching basis is selected. The quantum bits with consistent measurement results are retained to obtain the original bit string. The information coordination process is performed, and parity check information is exchanged using the cascade protocol to locate and correct errors, and the error-corrected bit string is obtained. The corrected bit string is amplified for privacy using a hash function, and the bit string length is compressed to obtain the final shared quantum key. The two communicating parties update their respective key storage states based on this key to obtain a consistent key record.

[0011] Preferably, in S104, an initial session key is generated based on a shared key through a key derivation function. If the key length is insufficient according to the preset key length and format requirements, it is adjusted through a padding mechanism to form a standard session key. Combined with the identity identifiers of both parties, a specific working key is generated. Before encryption, the working key is verified using a hash function. If the results are consistent, its availability is confirmed. Using the available key, the data to be transmitted is processed through a symmetric encryption algorithm to obtain an encrypted data stream, which is then distributed to both parties via a secure transmission protocol. The system obtains the transmission status and judges its integrity. If it is incomplete, it is redistributed until the final transmission result is obtained. Based on the result, the key management records of both parties are updated to clarify the key usage status.

[0012] Preferably, in S105, the session working key is confirmed to be consistent with the encryption algorithm and the version identifier is the same to determine that the key is available. An initialization vector is generated in combination with the algorithm parameters. The plaintext is encrypted in groups using the vector to generate a preliminary ciphertext block sequence. These blocks are connected through a chain encryption mode to obtain a complete ciphertext data stream, which is sent to the receiver along with the message authentication code through the data channel. The receiver uses the same key to verify the authentication code. After confirming the integrity of the ciphertext, it uses the same initialization vector to perform chain-like decryption of the data stream, and finally recovers the original plaintext data.

[0013] Preferably, in S106, the system confirms the availability of the current key by verifying the consistency of the key version identifier, and obtains the algorithm initialization vector by combining the symmetric encryption algorithm parameters. The vector is used to encrypt the plaintext data in groups to obtain a preliminary ciphertext sequence. These ciphertext blocks are connected by a chain encryption mode to obtain a complete ciphertext data stream. The sender generates a message authentication code for this data stream, sends it along with the ciphertext to the receiver and obtains confirmation. After receiving it, the receiver uses the same session working key to verify the consistency of the authentication code. If a match is found, the ciphertext is confirmed to be complete. The same initialization vector is used to perform chained decryption on the ciphertext data stream to recover the original plaintext data. Later in the process, the system repeatedly performs key version verification and status confirmation to update the working key, securely erases invalid old keys, and removes all residual data.

[0014] The present application describes a secure fusion method for quantum key distribution and quantum-resistant signatures, which realizes end-to-end quantum-resistant secure communication. By organically integrating quantum-resistant digital signatures (ML-DSA), quantum key distribution (QKD), and high-strength symmetric encryption (AES-256), it covers the entire process from identity authentication and key distribution to data encryption. The overall security of the system no longer relies on traditional public-key cryptography and can resist current and future quantum computing attacks. A quantum-resistant digital signature algorithm is used to replace the traditional RSA or ECC digital signature, which completes strong identity authentication and communication integrity protection on classical channels. This makes up for the quantum attack vulnerability in the initial authentication stage of the existing QKD system and ensures the consistency of the entire security chain. QKD provides key seeds with information-theoretic security, ensuring absolute security of key distribution at the physical level; it combines efficient symmetric encryption algorithms to encrypt data, ensuring extremely high security while avoiding the performance bottleneck that pure quantum-resistant algorithms may bring, and meeting the practical application requirements of high throughput and low latency. Through dynamic key derivation, periodic updates, and secure erasure after the session, even if the key for a single session is cracked in the future, it will be impossible to deduce the key for other sessions, thus achieving long-term security that is difficult to guarantee with traditional cryptography. This application does not rely on breakthroughs in specific quantum hardware or long-distance QKD relays. Based on achieving strong authentication and high-security key distribution, it can be flexibly adapted to existing network architectures, providing a feasible path for the smooth evolution to quantum-resistant communication systems. Attached Figure Description

[0015] Figure 1 This application describes the steps of a secure fusion method for quantum key distribution and quantum-resistant signatures. Figure 1 ; Figure 2 This is the flow chart of a secure fusion method for quantum key distribution and quantum-resistant signatures provided in the preferred embodiment of this application. Figure 1 ; Figure 3 This is the flow chart of a secure fusion method for quantum key distribution and quantum-resistant signatures provided in the preferred embodiment of this application. Figure 2 . Detailed Implementation

[0016] like Figures 1-3 As shown, this application describes a secure fusion method for quantum key distribution and quantum-resistant signatures.

[0017] like Figures 1-3 As shown, in S101, both communicating parties initialize the system and establish a communication channel, including establishing a data channel for transmitting public information and completing the physical synchronization of the quantum channel for transmitting quantum states.

[0018] Furthermore, in step S101, both communicating parties initiate the system initialization process and generate their respective local clock signals; Obtain the time reference from the local clock signal and send the classic pulse sequence to the other end; The round-trip delay difference is determined by using a classic pulse sequence, and the local clock offset is adjusted to obtain preliminary time alignment. Based on the initial time alignment, quantum light pulses are sent, and the interference intensity at the receiving end is monitored. If the interference intensity is lower than the preset threshold, the local clock phase is finely adjusted until the interference intensity reaches the maximum value to determine precise physical synchronization; A quantum channel is established through precise physical synchronization, and wavelength resources are allocated for quantum state transmission. Entangled photon pairs are transmitted over a quantum channel using an entanglement distribution protocol, and the recipient confirms that the other end has received the entangled state and thus obtained shared quantum resources.

[0019] Specifically, in step S101, the two communicating parties first synchronize their respective local high-precision atomic clocks through a classic network using a pre-shared root key and timestamp, so that the clock deviation between the two ends is controlled within 10 nanoseconds; Based on this time base, a simplified variant of the BB84 protocol is used to calibrate the physical parameters of the quantum channel: the sender Alice transmits polarization-coded weak coherent light pulses at a rate of 1 million pulses per second, with an average photon number μ=0.1 for the weak coherent light pulses; the receiver Bob randomly selects a measurement basis, which is either + or ×, and feeds back the bit error rate in real time through a classical channel; both parties jointly monitor the quantum channel. When the initial bit error rate is higher than 11%, the polarization controller is automatically triggered to compensate and iteratively adjust until the quantum bit error rate (QBER) stabilizes below 3.5% and the channel transmittance reaches above 0.62. Both parties establish a classical data channel in parallel. The classical data channel will be used to transmit all publicly available communication information for subsequent basis vector alignment and quantum-resistant signature data. After completing the synchronization and channel establishment, Alice inserts 10% decoy states at fixed intervals, grouped in sets of 256 qubits. The decoy states are set with two strengths: μ=0.02 and μ=0.5. Bob performs statistical analysis based on the publicly announced decoy state positions and calculates the lower bounds of single-photon gain and qubit error rate using the three-strength decoy state method. Then, he estimates the extractable secure key rate. When the estimated result is greater than 0.015 bits / pulse, the system determines that the quantum channel is usable and officially enters the key distribution stage.

[0020] like Figures 1-2 As shown in S102, the two communicating parties use the private key of the quantum-resistant digital signature algorithm to sign the exchanged authentication information on the data channel, and use the other party's public key to verify the signature, which is used to complete two-way identity authentication in a quantum computing environment.

[0021] Furthermore, in step S102, through the data channel, the two communicating parties initialize the authentication information collection process, perform structured organization on the authentication information to be exchanged, obtain the information content after preliminary organization, and determine the integrity of the information; Based on the initially organized information, a quantum-resistant digital signature algorithm is used to generate a signature on the information using private key processing, resulting in signed authentication data. The signed authentication data is sent to the other party through the data channel, and the corresponding signature data is obtained from the other party to determine the integrity of the received data packet. For the received signature data, a public key verification mechanism is used to verify the signature. If the verification result shows that the signature is inconsistent, the signature data is re-acquired until the verification is successful, and the verified data result is obtained. Based on the verified data results, execute the identity verification process. If the identity information matches, record the verification status and obtain the final identity verification record. By updating the security mechanism status of both communicating parties through the final authentication record, it is confirmed that the trust relationship between the two parties on the data channel has been established.

[0022] Specifically, in step S102, the two communicating parties initiate a quantum-resistant identity authentication process on the established classical data channel. Alice uses a key pair based on Dilithium lattice cryptography generated during the system initialization phase, specifically using the Dilithium3 parameter set, with a security level equivalent to AES-192. The private key is approximately 2528 bytes long, and the public key is 1312 bytes long. Furthermore, her public key has been issued as a digital certificate by a trusted CA to prove the identity of the public key owner. Alice used the private key to create an ID containing her own identity information. A The current high-precision timestamp T, with a timestamp accuracy down to the nanosecond level, is consistent with the previously synchronized atomic clock. It is signed with the authentication message M of the random nonce (128 bits). The signature algorithm calculates the message digest through the Keccak-f

[1600] hash function, and then performs multiple rounds of polynomial sampling and rejection sampling to obtain a signature length of approximately 2448 bytes. Alice will send the signature σ, the authentication message M, and her own digital certificate containing the public key pk. A It is sent to Bob after being encrypted with the AES256-GCM session key; After receiving the data, Bob first uses the session key to decrypt and obtain M, σ, and the certificate. Then, he verifies the validity and authenticity of the certificate, including the CA signature. Once the verification is successful, he extracts the public key pk. A Using PK A The verification process for σ includes recalculating the message digest, performing polynomial challenge-response matching, and checking the rejection sampling threshold to ensure that the probability of signature validity is greater than 1-2. -128 ; After successful verification, Bob also uses the Dilithium3 key pair, which he generated and signed during the system initialization phase, and includes the ID. B timestamp (The deviation from T is less than 15 nanoseconds) and another random nonce response message. Perform signing, generate signature Then, it is encrypted along with its own digital certificate and sent back to Alice; Alice first verifies the authenticity and validity of Bob's certificate and extracts the public key PK. B Perform the complete verification process, including hash recalculation and canonicality checks; Both parties monitor the signature verification failure rate in real time during the verification process. If the verification fails three times in a row, the process will automatically roll back to the channel renegotiation state. Otherwise, after the two-way authentication is successful, the XOR result of the nonce in each party's authentication message will be used as a seed to expand and generate the shared mask key for the subsequent information correction stage. This ensures that the entire identity verification process remains unforgeable under quantum computing attacks, and the total authentication latency is controlled within 45 milliseconds.

[0023] like Figures 1-3 As shown in S103, the two communicating parties distribute quantum states through a quantum channel, perform basis vector comparison, information coordination, and privacy amplification on the data channel, and obtain a shared quantum key.

[0024] Furthermore, in step S103, the quantum state is distributed through the quantum channel to obtain the initial qubit sequence; Based on the initial qubit sequence, basis selection information is transmitted on the data channel to determine the basis records for both parties; By comparing the basis records of both parties, the set of qubits corresponding to the matching basis is obtained; Based on the set of qubits corresponding to the matching basis vectors, retain the qubits with consistent measurement results to obtain the original bit string; For the original bit string, an information coordination process is performed. A concatenation protocol is used to exchange parity check information, and parity check consistency is judged. If there is no consistency, the error position is located and corrected to obtain the error-corrected bit string. Based on the corrected bit string, a hash function is used to perform privacy amplification, compress the bit string length, and determine the final shared quantum key. Based on the final shared quantum key, the key storage state of both communicating parties is updated to obtain a consistent key record.

[0025] Specifically, in step S103, the two communicating parties distribute quantum states based on the BB84 protocol through a quantum channel. Alice sends polarization-encoded single photons at a rate of 5 million photons per second, using four basis vectors: horizontal, vertical, 45-degree diagonal, and 135-degree diagonal, and randomly selects to encode 0 or 1. The transmission distance is set to 50 kilometers, the fiber loss rate is 0.2 dB / km, and the quantum bit error rate is controlled below 3%. Basis vector comparison is performed on the data channel. Both parties publicly compare 10% of the randomly selected quantum state basis vector information, about 50,000 bits, to confirm that the consistency ratio reaches more than 98%. If it is lower than this value, the retransmission mechanism is automatically triggered. In the information coordination phase, Alice and Bob used the Cascade algorithm to perform error correction on the remaining 450,000 bits, which was processed in four rounds of iteration. The group sizes for each round are 5000, 10000, 20000 and 40000 bits respectively. By XOR operation and binary search, the bit error rate is located and corrected, and the bit error rate is finally reduced to below 0.01%, resulting in about 440,000 consistent bits. To further enhance security, both parties used privacy amplification processing and the SHA-3 hash function to output a 256-bit length. The corrected bitstream was then compressed at a compression ratio of 2:1, ultimately generating a shared quantum key of approximately 220,000 bits. Entropy analysis showed that the key randomness reached over 99.9%. To ensure the integrity of the key distribution process, the system automatically records log data for each process, including bit error rate, basis consistency ratio, and compressed key length. It also uses timestamps with microsecond precision to correlate the processing timing of the quantum channel and data channel, ensuring that the entire process is completed within 100 milliseconds. If an abnormal fluctuation is detected, such as a sudden increase in the bit error rate to 5%, the system will automatically switch to the backup quantum channel for redistribution to ensure the stability of the key generation process.

[0026] like Figures 1-3 As shown in S104, the two communicating parties generate a session working key for data encryption through a key derivation function based on the shared quantum key.

[0027] Furthermore, in step S104, an initial session key is generated by using a key derivation function with a shared key. For the initial session key, the key length and format requirements are obtained. If the length does not meet the preset threshold, it is adjusted through a padding mechanism to obtain a standard session key. Based on the standard session key and the identities of both communicating parties, a specific working key is generated. For a specific working key, before data encryption, a hash function is used to verify whether the verification results are consistent. If they are consistent, the working key is determined to be usable. Based on the available working key, the data to be transmitted is processed using a symmetric encryption algorithm to obtain an encrypted data stream; For encrypted data streams, they are distributed to both communicating parties through a secure transmission protocol, the transmission status is obtained, and it is determined whether the transmission is complete. If it is incomplete, it is redistributed to obtain the final transmission result. Based on the final transmission results, update the key management records of both communicating parties to determine the key usage status.

[0028] Specifically, in step S104, Alice and Bob input the previously generated 220,000-bit quantum key as a seed into HKDF (HMAC-based, Key, Derivation, Function), using SHA-512 as the underlying hash algorithm, setting the salt value to a 32-byte pre-shared random number, which is automatically generated by the system during the initial authentication phase, and inputting the context information string "QKD-Session-Key-2025", which is 24 bytes long, to ensure the key independence of different sessions; HKDF is executed in two phases. The first phase extracts a 512-bit pseudo-random key (PRK), calculated as PRK = HMAC - SHA512(salt, quantum). key It took approximately 0.8 milliseconds. The second phase, the expansion phase, generates a 256-bit session working key (OKM). This can be completed by iterating through HMAC and calling it once. Output OKM = HMAC - SHA512(PRK, context) info ||0x01); The system automatically performs randomness checks on the derived session keys using the restart test and autocorrelation test in the NISTSP800-90B standard. The analysis results show that the pass rate is 100% and the entropy value is estimated to be 255.97 bits, which is close to the ideal value. Both parties synchronously exchange an 8-byte session identifier (encrypted and transmitted over the data channel) and record a derived timestamp (accurate to nanoseconds) and a hash check value, which are used to associate with subsequent encrypted communications; The entire key derivation process is completed within 5 milliseconds. If inconsistency in context information is detected, the system automatically discards the current key and triggers a new quantum key distribution process to ensure the security and uniqueness of the session key.

[0029] like Figures 1-3 As shown in step S105, the sender uses the session working key and symmetric encryption algorithm to encrypt the plaintext data and transmits the ciphertext to the receiver through the data channel. The receiver then decrypts the data using the same session working key.

[0030] Further, in step S105, based on the consistency between the session working key and the symmetric encryption algorithm, it is determined whether the key version identifier is the same. If they are the same, the key consistency status is determined to be available. The algorithm initialization vector is obtained by combining the available key consistency status with the symmetric encryption algorithm parameters; The plaintext data is encrypted by initializing the vector using an algorithm to obtain a preliminary ciphertext block sequence. For the initial ciphertext block sequence, a chain encryption mode is used to connect adjacent blocks to obtain a complete ciphertext data stream; The complete encrypted data stream, along with the message authentication code, is transmitted to the receiver via the data channel to obtain a transmission confirmation signal. After the receiver obtains the complete encrypted data stream, it uses the same session working key to verify the consistency of the message authentication code. If they are consistent, the integrity of the encrypted data is determined. Based on the integrity of the ciphertext and the initialization vector of the same algorithm, a chain-like decryption process is performed on the complete ciphertext data stream to obtain the recovered plaintext data.

[0031] Specifically, in step S105, the sender Alice uses the previously derived 256-bit session working key as input and employs the AES-256-GCM symmetric encryption algorithm to encrypt the plaintext data. In practice, the system automatically generates a 96-bit, 12-byte random nonce, which is generated by a hardware random number generator to ensure the uniqueness of the nonce and prevent reuse. The calculation process follows the NIST SP800-38D recommendation. The GCM mode is initialized by combining the nonce with the session key. The counter is incremented from 1 to generate a key stream, which is XORed with the plaintext to generate ciphertext. At the same time, a 128-bit authentication tag is calculated. Data and ciphertext are associated using a polynomial hash function (GHASH function). The tag calculation formula is: Tag = GHASH(AAD||ciphertext||lengths) + E(K, nonce||0). 31 ||1) The entire encryption process is completed on the FPGA accelerator, and it takes about 1.2 milliseconds to process 1MB of data; The system automatically appends a nonce and an authentication tag to the ciphertext header to form a complete data packet. The data packet consists of a 12-byte nonce, ciphertext, and a 16-byte tag, and is transmitted to the receiver Bob through the data channel. If the plaintext contains associated authentication data, which is a 16-byte message header, then it is added to the GCM input to enhance integrity verification. After receiving the data packet, Bob, the receiver, parses out the nonce, ciphertext, and authentication tag. He initializes the AES-256-GCM decryption mode using the same 256-bit session working key. First, he verifies the authentication tag. If the GHASH calculation result matches the received tag, the tag matching error rate is set to less than 10. -10 If the data integrity and authenticity are confirmed, the same nonce is used to generate a key stream XOR ciphertext to recover the plaintext. The entire verification and decryption process takes about 1.1 milliseconds. If tag verification fails, the system immediately discards the data packet and records the abnormal event, triggering an alarm mechanism and requesting retransmission or update of the session key to ensure the continuity of the communication link and its anti-tampering capability.

[0032] like Figures 1-3 As shown, in S106, according to the preset strategy, both communicating parties repeatedly execute S103 to S105 to update the session working key and securely erase the invalid old key.

[0033] Further, in step S106, the key consistency status is confirmed to be available based on the key version identifier consistency judgment result; The algorithm initialization vector is obtained by combining the available key consistency status with the parameters of the symmetric encryption algorithm. A preliminary ciphertext sequence is obtained by performing block encryption on plaintext data using an algorithm-initialized vector; The initial ciphertext sequence is encrypted using a chain encryption mode to connect adjacent data blocks to form a complete ciphertext data stream. The complete ciphertext data stream is used to generate a message authentication code, which is then transmitted to the receiver to obtain an acknowledgment signal. After receiving the complete encrypted data stream, the receiver uses the same session working key to verify the consistency of the message authentication code. If they match, the integrity of the encrypted data is confirmed. Based on the integrity of the ciphertext, the same algorithm is used to initialize the vector, and a chained decryption operation is performed on the complete ciphertext data stream to obtain the recovered plaintext data; Repeatedly perform key version identifier consistency check and key consistency status confirmation operations to update the session working key, and perform a secure erase operation to remove residual data for invalid old session working keys.

[0034] Specifically, in step S106, the system automatically triggers the session working key update process according to the preset security policy at fixed time intervals or after reaching a specific communication data volume threshold. The initiator generates a new 256-bit random master key seed, and uses the hardware-supported SHA-3-512 hash function to concatenate the current old session working key with a 64-bit incremental sequence number and the current timestamp (accurate to milliseconds) to form the input data block; The salt value of the HKDF-Extract stage is calculated as PRK=HMAC-SHA512 (salt=zero salt, IKM=old key||sequence number||timestamp), and then the HKDF-Expand stage is entered, outputting an extended key stream of length 512 bits. The first 256 bits are then extracted as the new session working key, and the last 256 bits are used as the backup integrity verification key. The calculation process strictly follows the RFC5869 specification to ensure one-wayness and collision resistance. The total key derivation time on the ARM Cortex-M7 processor is approximately 0.85 milliseconds. After generating a new key, the system immediately uses AES-256-ECB mode to perform three rounds of overwrite erasure on the old session working key. First, write all 0x00 data blocks, then write all 0xFF data blocks, and finally write random data blocks. After each round of erasure, the write success rate is verified to be 100% by a memory verification function. The erasure process complies with the NISTSP800-88 media cleanup guidelines to prevent residual keys from being recovered through side channels or memory dumps. After the update is complete, the initiator sends a key confirmation message through the established secure control channel. This message contains an HMAC-SHA256 signature of the new sequence number (calculated using a backup verification key, with a signature length of 32 bytes). Upon receiving this message, the receiver independently performs the same HKDF derivation process to obtain the same new key and verifies that the signature matching probability is higher than 1-2. -256 If a match is found, the system switches to the new key and performs the same three rounds of overwrite erasure on the old key. The entire update cycle takes no more than 15 milliseconds in an environment where the network latency is less than 50 milliseconds, thus maintaining forward security and long-term key isolation.

[0035] For those skilled in the art, various other corresponding changes and modifications can be made based on the technical solutions and concepts described above, and all such changes and modifications should fall within the protection scope of the claims of this application.

Claims

1. A secure fusion method for quantum key distribution and quantum-resistant signatures, characterized in that, include: S101. The two communicating parties establish a data channel for transmitting public information and synchronize a quantum channel for transmitting quantum states. S102. Both communicating parties use the private key of the quantum-resistant digital signature algorithm to sign the exchanged authentication information on the data channel, and use the other party's public key to verify the signature, which is used to complete two-way identity authentication in a quantum computing environment. S103. The two communicating parties distribute quantum states through a quantum channel, perform basis vector comparison, information coordination, and privacy amplification on the data channel, and obtain a shared quantum key. S104. Based on the shared quantum key, the two communicating parties generate a session working key for data encryption through a key derivation function; S105. The sender uses the session working key and symmetric encryption algorithm to encrypt the plaintext data and transmits the ciphertext to the receiver through the data channel. The receiver uses the same session working key to decrypt the data. S106. According to the preset strategy, both parties to the communication repeat S103 to S105 to update the session working key and securely erase the invalid old key.

2. The secure fusion method of quantum key distribution and quantum-resistant signatures according to claim 1, characterized in that, In step S103, the process of obtaining the shared quantum key after basis vector alignment, information coordination, and privacy amplification on the data channel includes: The initial sequence of qubits is obtained by distributing quantum states through a quantum channel; Both parties exchange and record basis selection information via the data channel; The basis vector records are compared to select the set of qubits corresponding to the matching basis vectors; Retain the qubits that match the measurement results to obtain the original bit string; An information coordination process is performed on the original bit string to correct errors and obtain an error-corrected bit string; The corrected bit string is then subjected to privacy amplification using a hash function to obtain the final shared quantum key.

3. The secure fusion method of quantum key distribution and quantum-resistant signatures according to claim 1, characterized in that, In S104, obtaining the session working key for data encryption through the key derivation function includes: Based on the shared quantum key, the initial session key is obtained through the key derivation function; The initial session key is adjusted according to the preset key length and format requirements to obtain the standard session key; By combining the identities of both communicating parties, a specific working key is obtained; The specific working key is verified using a hash function to confirm its availability.

4. The secure fusion method of quantum key distribution and quantum-resistant signature according to claim 1, characterized in that, In S105, the sender encrypts the plaintext data using a session working key and a symmetric encryption algorithm, including: Confirm that the session working key matches the version identifier of the symmetric encryption algorithm; The initialization vector is obtained by combining the parameters of the symmetric encryption algorithm; The plaintext data is encrypted in blocks using the initialization vector to obtain a preliminary ciphertext block sequence. The initial ciphertext block sequence is connected by a chain encryption mode to obtain a complete ciphertext data stream; The complete encrypted data stream, along with the message authentication code, is sent through the data channel.

5. A secure fusion method for quantum key distribution and quantum-resistant signatures according to claim 4, characterized in that, In S105, the receiver's decryption using the same session working key includes: The recipient uses the same session working key to verify the message authentication code; After successful verification, the complete ciphertext data stream is decrypted in a chain using the same initialization vector to recover the original plaintext data.

6. The secure fusion method of quantum key distribution and quantum-resistant signature according to claim 1, characterized in that, In S106, the repeated execution of S103 to S105 for updating the session working key includes: The key update process is triggered based on a preset time interval or a communication data volume threshold. Based on the current old session working key, the incrementing sequence number, and the timestamp, a new session working key is obtained through a key derivation function.

7. A secure fusion method for quantum key distribution and quantum-resistant signatures according to claim 6, characterized in that, In S106, the secure erasure of the expired old key includes: Replace the old session working key with the new session working key; Perform multiple rounds of overwrite and erase operations on the old session working key.

8. The secure fusion method of quantum key distribution and quantum-resistant signature according to claim 1, characterized in that, The quantum-resistant digital signature algorithm is a lattice-based signature algorithm, the symmetric encryption algorithm is the AES-256 algorithm, and the hash function used for privacy amplification is the SHA-3 hash function.

Citation Information

Patent Citations

  • Quantum key distribution, privacy amplification and data transmission methods, apparatuses, and system

    CN105553648A

  • Clock synchronization system and method based on quantum entanglement

    CN109547144A

  • Post-quantum encryption and decryption method and system based on identity label, equipment and medium

    CN114024676A

  • Safe lightweight networking and communication method based on quantum key distribution

    CN118473667A

  • National password IPSec secure communication method supporting quantum cryptography resistance

    CN118631448A