Anti-quantum cryptography data security protection system and method for juveniles

By constructing a quantum-resistant cryptographic data security protection system, and adopting NIST-certified algorithms and blockchain evidence storage technology, the system addresses the risk of data leakage for minors under quantum computing, achieving full-process security protection and long-term protection.

CN121887382APending Publication Date: 2026-04-17李雪
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively address the existential threats posed by quantum computing. Data on minors faces the risk of future leakage under traditional encryption, and there is a lack of a systematic quantum security protection system.

Method used

A quantum-resistant cryptographic data security protection system for minors is constructed, including a quantum-resistant cryptographic chip at the terminal layer, a quantum-secure VPN channel at the transmission layer, a quantum-resistant blockchain evidence storage technology at the storage layer, and a real-time auditing mechanism at the regulatory layer, forming a comprehensive defense-in-depth system. It adopts the NIST-certified CRYSTALS-Kyber and Falcon algorithms, combined with blockchain and forward security protocols.

Benefits of technology

It achieves comprehensive protection across the entire data chain, from data generation, transmission, storage to governance, ensuring the long-term security of minors' data in the quantum computing era, reducing deployment costs, improving system resilience and adaptability, and enhancing user experience and security awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887382A_ABST
    Figure CN121887382A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum cryptography data security protection system and method for juveniles. Aiming at the problem that an existing education APP and intelligent equipment only adopt a traditional encryption algorithm (such as RSA and AES) and cannot resist quantum computing attacks, the invention provides a four-layer protection architecture of a terminal layer, a transmission layer, a storage layer and a supervision layer. The terminal layer is provided with a PQC chip in advance and encrypts the biological characteristic data by using a lattice password; the transmission layer establishes a quantum security VPN channel and deploys a forward security protocol; the storage layer adopts an anti-quantum block chain evidence storage technology; the supervision layer introduces a PQC auditing and threat intelligence sharing mechanism. Through experimental verification, the blocking rate of the system to quantum brute force attack reaches 100%, and the man-in-the-middle attack breakthrough rate is reduced to 0%. The method is suitable for education platforms, child intelligent equipment and other scenes, and the long-term safety risk of juvenile data in the quantum era is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the interdisciplinary field of quantum-secure encryption and data protection for minors. It relates to a quantum-resistant cryptographic data security protection system and method for minors, specifically including hardware implementation of NIST standard algorithms such as CRYSTALS-Kyber and Falcon, a four-layer protection architecture design, and supporting educational practice schemes. Background Technology

[0002] With the widespread adoption of the internet and smart devices, minors in my country have become active participants in the digital society. According to authoritative data released by the China Internet Network Information Center (CNNIC), the number of underage internet users has reached 191 million, with an internet penetration rate of 96.8%, and nearly 90% of them own their own internet access devices. While this deep internet penetration promotes educational informatization and convenient communication, it also brings serious data security challenges. Surveys show that over 40% of underage internet users have experienced privacy breaches, nearly 30% of children's smartwatch users have received friend requests from strangers, and some minors have even revealed sensitive information such as their home address online. Currently, the urgency of protecting the digital security of minors cannot be ignored.

[0003] However, a more profound threat stems from the revolutionary shift in computing paradigms—the rapid development of quantum computing. Traditional information security systems rely on public-key cryptography algorithms, such as the widely used RSA and elliptic curve cryptography, whose security rests on the computational complexity of large number factorization or discrete logarithm problems. In July 2022, the National Institute of Standards and Technology (NIST) officially announced the first four quantum-resistant cryptographic algorithm standards, marking the world's entry into the post-quantum cryptography era. Leading experts pointed out that the currently considered robust RSA-2048 encryption algorithm could be cracked in as little as eight hours by the Shor's algorithm used in quantum computing. This assertion is not merely theoretical; in March 2023, an international hacker group claimed to have successfully cracked the historical database of an educational platform using early quantum computing technology, resulting in the leakage of over two million student records. Analysis confirmed that this data used traditional AES-256 encryption, which, while resistant to classical computer attacks, is utterly vulnerable to quantum algorithms. This means that sensitive data of minors protected by traditional encryption methods today, including personal identity, learning records, biometrics, and even whereabouts, may face the risk of being fully exposed once quantum computing becomes practical in the future.

[0004] Faced with this disruptive threat, existing technological measures and policies are significantly lagging behind. Although my country's "Regulations on the Protection of Minors Online" came into effect in January 2024, it has not yet set forth specific requirements and standards for quantum security. In contrast, the United States and the European Union have taken the lead, issuing national memoranda and investing heavily in the migration of critical infrastructure to quantum-resistant cryptography. Field research in several primary schools in Beijing revealed serious security vulnerabilities in digital products currently used by minors. All ten mainstream educational applications on the market use traditional encryption algorithms, six of which have man-in-the-middle attack vulnerabilities, and three even store unencrypted biometric data. The vast majority of parents and students have no concept of the threat posed by quantum computing and have weak security awareness. There is a disconnect between industry and education; only two children's smart device manufacturers have begun developing quantum-resistant cryptographic solutions, and 90% of educational application developers stated that they have not yet considered quantum security.

[0005] Therefore, the core problem in the current technological field lies in two aspects: firstly, encryption technologies for protecting minors' data remain at the level of countering classical computing, unable to cope with the existential threats posed by quantum computing; secondly, the entire technological ecosystem, from terminal devices and transmission channels to data storage, lacks a systematic, future-oriented quantum security protection system. Experimental data clearly shows that traditional encryption groups are completely breached under simulated quantum attacks, and existing sporadic attempts have failed to form a closed-loop protection system from sensing, transmission, storage to monitoring. This systemic deficiency exposes the digital future of over 190 million minors to enormous and irreversible risks, urgently requiring a completely new technological solution to fundamentally address the quantum threat. Summary of the Invention

[0006] This invention provides a quantum-resistant cryptographic data security protection system and method for minors, applicable to educational platforms, children's smart devices, and other scenarios, effectively addressing the long-term security risks of minors' data in the quantum era.

[0007] This invention relates to a quantum-resistant cryptographic data security protection system and method for minors. The core of the system lies in constructing a comprehensive protection system covering the entire data lifecycle. The terminal layer directly targets minor users, and its pre-installed quantum-resistant cryptographic chip forms the foundation of hardware-level security, ensuring quantum security protection from the source of data generation. This layer particularly emphasizes the use of lattice cryptography to encrypt biometric data (such as voiceprints and facial recognition data collected by children's smartwatches), because biometric information is unique and immutable; leakage would pose a lifelong risk. The quantum-secure VPN channel constructed in the transmission layer employs a hybrid encryption mode design that fully considers a smooth transition strategy from current traditional cryptographic systems to future quantum-resistant cryptographic systems, ensuring compatibility with existing network infrastructure while preparing for future quantum threats. The quantum-resistant blockchain storage technology in the storage layer addresses the cryptographic debt problem of "current encryption, future cracking" faced by the long-term storage of minors' educational data (up to decades). The regulatory layer, acting as the system's "intelligent brain," integrates with the education big data platform to perceive, analyze, and make decisions regarding the overall network security status, ensuring that protection strategies dynamically evolve with the threat landscape. Its systematic and forward-looking approach, through a four-layer architecture design encompassing terminals, transmission, storage, and supervision, achieves comprehensive, seamless protection across the entire data chain, from collection and transmission to storage and governance, transforming previous fragmented and isolated security measures. In particular, it elevates quantum-resistant cryptography from a single algorithmic application to a systematic solution, effectively addressing the long-term and fundamental threats to minors' data security in the era of quantum computing. This architecture ensures that even if one layer is breached in the future, other layers can still provide effective security protection, forming a powerful defense-in-depth capability and building a robust, future-proof barrier for minors' digital identities and privacy data.

[0008] Furthermore, specific standardization requirements and performance indicators were proposed for the core component of the terminal layer—the quantum-resistant cryptographic chip. It requires NIST standard certification to ensure the correctness, security, and interoperability of the CRYSTALS-Kyber-768 and Falcon-512 algorithms implemented on the chip, avoiding the introduction of new security vulnerabilities due to non-standard implementations. A built-in 32-bit quantum random number generator is used to generate truly unpredictable random numbers in a cryptographic sense, which is the foundation for secure operations such as key generation and signature. Its entropy value is far higher than that of traditional pseudo-random number generators, effectively resisting prediction attacks. The performance indicator of encryption latency below 10 milliseconds is designed for smart devices used by minors (such as watches and tablets) with limited computing resources and high real-time requirements (such as voice calls and instant quizzes), ensuring that security functions do not significantly affect user experience, thereby guaranteeing the usability and widespread adoption of the technology. A high standard of balance between security and usability is achieved. Mandatory NIST certification guarantees the reliability and authority of the hardware security module from the source, laying a trustworthy foundation for the entire system. High-performance quantum random number generators and low-latency encryption processing enable the seamless integration of strong quantum-resistant cryptography into resource-constrained mobile devices, providing high-level hardware security without sacrificing device responsiveness or user experience. This is particularly suitable for educational applications requiring real-time interaction, making security protection both seamless and efficient.

[0009] Furthermore, the technical implementation path of the transport layer quantum-secure VPN channel is refined. The dual-stack encryption mode refers to nesting and integrating the CRYSTALS-Kyber-768 algorithm within the existing, widely deployed TLS secure transport protocol stack. This design ensures that the channel is compatible with existing internet services while incrementally introducing quantum-resistant capabilities. Combined with forward-secure protocols such as HMQV, its key role is to ensure that each communication session uses an independent, ephemeral session key. Even if an attacker uses a future quantum computer to crack the long-term private key used for authentication, they cannot deduce any past or future session key, thus protecting the confidentiality of historical communications. This directly addresses the long-term confidentiality challenge mentioned in the document, which involves "data needing to be stored for decades." Its smooth transition capability and protection of historical data are also significant advantages. The dual-stack design avoids "rebuild" technology updates, greatly reducing deployment costs and complexity, enabling educational institutions and service providers to upgrade their system security in a progressive manner. The introduction of forward security features is a key strategy to address quantum threats. It ensures that the communications of minors today will not be decrypted due to the leakage of long-term keys even in the distant future, achieving full confidentiality of data throughout its lifecycle and effectively solving the risk of "backtracking" brought about by quantum computing.

[0010] Furthermore, the specific implementation plan for quantum-resistant blockchain evidence storage technology was clarified. The Dilithium algorithm, based on lattice structures, is used to digitally sign each data block. Its advantages lie in its fast signing speed and short signature length, making it ideal for blockchain scenarios that require frequent signature verification. The hash value of the signed data (rather than the original data itself) is stored in a distributed ledger, leveraging the immutability and traceability of blockchain while avoiding storage and privacy issues associated with directly storing large amounts of sensitive data on the chain. The timestamp and PQC algorithm version identifier in each block header provide a precise evidence storage time and proof of the strength of the security algorithm used at that time. This is crucial for future security audits, dispute arbitration, or judicial evidence collection, clearly defining security responsibilities. The ingenious combination of quantum-resistant cryptography and blockchain evidence storage technology achieves dual protection of data integrity and long-term verifiability. Utilizing the characteristics of the Dilithium algorithm and blockchain, it ensures that any tampering of critical data belonging to minors (such as student registration information and academic records) is immediately detected once stored. The timestamp and algorithm version identifier add a "secure timestamp" to the data, forming a complete chain of evidence. This not only prevents data from being maliciously tampered with, but also provides a technical foundation for the long-term reliable preservation of educational data, which is especially in line with the long life cycle of educational data.

[0011] Furthermore, two core functional modules for the regulatory layer are defined. The PQC audit module continuously monitors the actual operational status of encryption algorithms in the system, such as checking whether keys are rotated regularly according to security policies and whether various services strictly use compliant quantum-resistant algorithms (such as CRYSTALS-Kyber and Falcon), preventing security degradation due to misconfiguration or malicious tampering. The threat intelligence database is a dynamic knowledge base that regularly synchronizes the latest quantum attack technology developments, vulnerability information, and best practice solutions from authoritative institutions such as NIST. When the intelligence database is updated, the system can automatically or semi-automatically adjust its protection strategies, such as updating intrusion detection rules for newly detected attack patterns or issuing warnings for algorithms with potential risks, thereby upgrading from static protection to dynamic adaptive protection. This endows the entire system with continuous evolution and proactive defense capabilities. Traditional security systems are often statically configured, while this solution, through auditing and intelligence-driven approaches, enables the system to perceive changes in internal security status and external threats in real time and respond promptly. This effectively addresses the challenge of rapidly evolving cybersecurity threats, ensuring that the protection system for minors' data does not become outdated over time. It transforms security management from a passive response to proactive operation and maintenance, greatly improving the overall resilience and intelligence of the system.

[0012] Furthermore, the system's architectural features are transformed into executable operational methods, clarifying four key steps in the protection process. Step S1 is the trusted initialization of device network access identity. This is achieved by generating a key pair using a hardware PQC chip and performing a Falcon-512 signature on the device identity upon initial startup, establishing a trusted starting point for all subsequent secure interactions. Step S2 is crucial for secure communication. It stipulates that before each data transmission, both communicating parties must negotiate a one-time session key using a key exchange protocol that integrates quantum-resistant algorithms and forward security mechanisms, ensuring the confidentiality and integrity of the transmission process. Step S3 is secure archiving. Quantum-resistant signatures and blockchain technology are used to imprint an unforgeable "digital seal" on the data and store it as evidence. Step S4 is continuous security monitoring and enforcement. The regulatory body, acting as the guardian of the rules, intervenes in real-time for behaviors that violate security policies (such as attempts to connect insecurely). This transforms the complex security technology system into a clear, coherent, and strictly followable operational process. These four interconnected steps form a complete security closed loop, covering the entire lifecycle of a data interaction from identity authentication and secure connection to data evidence storage and behavioral supervision. It makes the deployment, operation, and auditing of the system more systematic and standardized, and translates advanced security concepts into concrete and verifiable steps, greatly enhancing the feasibility and manageability of the solution and ensuring that security policies can be effectively implemented in real-world environments.

[0013] Furthermore, the key exchange protocol in step S2 was refined. The method of sending a Kyber-768 public key from the client and generating a temporary RSA-3072 key pair for encryption on the server side is a robust transitional strategy. This approach transmits quantum-safe public key materials while utilizing currently secure traditional cryptographic algorithms for enhancement and compatibility. Both parties confirm the key via the HMQV protocol, ensuring the consistency of the negotiated session key and preventing man-in-the-middle attacks. Strictly limiting the session key's validity period to no more than 24 hours and immediately destroying the key materials after the meeting embodies the forward security principle, minimizing the key's validity window. Even if a session key is compromised, its impact is strictly limited to a very short time and a single session. This refined key management strategy ensures strong security while also considering practical feasibility. The hybrid encryption mode ensures compatibility with existing infrastructure, lowering the deployment threshold. Strict key lifecycle management (short validity period, timely destruction) is the core of forward security. It acts like a unique, one-time-use lock for each session, making it difficult for attackers to decrypt historical communications on a large scale even if they obtain long-term keys, thus minimizing potential losses. This design provides ultimate protection against quantum computing threats for minors' frequent, short-term data interactions (such as classroom interactions and homework submissions).

[0014] Furthermore, the technical details of blockchain-based evidence preservation are specified in detail. It requires the use of the more secure Dilithium-1024 algorithm for signing, combined with the more collision-resistant SHA-3 hash function, aiming to address security challenges in the longer term. Clearly recording the PQC algorithm identifier (such as Kyber-768) and its corresponding NIST quantum attack resistance level (such as L3) in the block header provides crucial information for future "security archaeology." When the authenticity of data needs to be verified decades later, the information in the block header can be used to determine whether the algorithm used was still secure under the quantum computing power at that time. Setting a minimum preservation period of 20 years directly corresponds to the critical growth cycle of minors from school to adulthood, ensuring the long-term verifiability of their important educational records. Support for judicial evidence tracing gives this evidence preservation legal effect. Its thoughtful consideration and meticulous design regarding the long-term verifiability of data, by recording the algorithm identifier and security level, provides future verifiers with key insights into the "historical security context," avoiding the problem of being unable to verify the authenticity of historical data due to outdated algorithms. Linking the evidence preservation period to the developmental cycle of minors reflects the humanistic care and practical needs orientation of the solution design. Supporting judicial traceability greatly enhances the practical value and social significance of this technical solution, making it not only a technical measure but also an infrastructure for building a trustworthy digital education environment.

[0015] Furthermore, regular PQC compliance checks (e.g., quarterly) are a proactive, institutionalized security inspection designed to ensure that all devices and services accessing the education platform continuously comply with established quantum-resistant security standards. Uncertified devices are blocked from access, eliminating security risks at the source. Real-time monitoring of network traffic and detection of quantum attack simulations (e.g., identifying traffic simulated using Shor's algorithm with tools like Qiskit) constitutes a passive, threat-signature-based real-time defense. Upon detecting such advanced threats, the system doesn't simply issue alerts but automatically triggers contingency plans, switching to alternative PQC algorithms with different mathematical difficulties (e.g., hash-based SPHINCS+), ensuring service continuity and security, and maintaining resilience even against attacks targeting specific algorithms. This constructs a dual security mechanism combining proactive inspection and real-time emergency response. Regular compliance checks create constant security pressure, driving all parties to continuously adhere to security regulations. Meanwhile, the real-time threat response mechanism based on traffic analysis endows the system with rapid self-healing and continuous protection capabilities when facing emerging, targeted quantum attack simulations. This design makes the system no longer fragile and rigid, but highly resilient and adaptable, effectively responding to unknown threats and providing highly available security for core education operations.

[0016] Furthermore, the defined quantum-resistant cryptography education experimental platform is a crucial supporting facility for the understanding, verification, and promotion of the entire system. The quantum attack simulation module, by integrating mainstream quantum computing simulation frameworks such as IBM Qiskit, vividly demonstrates in a visual way how Shor's algorithm efficiently breaks traditional RSA encryption, transforming the abstract quantum threat into an intuitive understanding and greatly enhancing the security awareness of teachers, students, and parents. The PQC encryption exercise module provides a hands-on environment where students can use open-source toolkits such as OpenQuantumSafe to personally operate algorithms like Kyber and Dilithium for encryption, decryption, and signature verification, understanding their principles and advantages through practice. The security attack and defense range, by constructing a near-realistic network environment, allows security researchers or students to simulate various attacks (such as man-in-the-middle attacks and quantum brute-force attacks) in a controlled environment and verify the effectiveness of the aforementioned four-layer protection system, thereby continuously optimizing protection strategies. This platform transforms cutting-edge security technologies into educational and capacity-building tools. It not only serves technology verification but also undertakes the vital functions of educational enlightenment and talent cultivation. By employing an edutainment approach, it breaks down the cognitive barriers to quantum-resistant cryptography, helping to cultivate quantum risk awareness and security skills across society, particularly in the education sector. This is a crucial link in achieving the document's goal of "a three-dimensional linkage of education, policy guidance, and technological innovation," laying a solid practical foundation for protecting minors' data security and cultivating future cybersecurity talent for the nation.

[0017] This invention provides a quantum-resistant cryptographic data security protection system and method for minors, which has the following beneficial effects: The four-layer quantum cryptography protection system and method for data security of minors proposed in this invention exhibits multiple significant advantages compared to existing technologies. Its core value lies in constructing a full-chain, in-depth security barrier capable of resisting future quantum computing attacks.

[0018] The primary advantage lies in its forward-looking approach and fundamental security. This invention is not a mere patching up of existing encryption technologies, but rather a fundamental innovation at the cryptographic level. It directly employs quantum-resistant cryptographic algorithms, such as CRYSTALS-Kyber and Falcon, selected through the standardization process of the National Institute of Standards and Technology (NIST). Simulation experiments have verified that the quantum-resistant cryptographic algorithms used in this system maintain astronomical cracking times against quantum computing attacks, a stark contrast to the traditional RSA algorithm, which can be broken within hours. This fundamental security ensures that the sensitive data of minors, including long-term valuable growth records and biometric information, can be effectively protected throughout their entire lifespan (often spanning decades), avoiding the risk of "cryptographic debt" due to the obsolescence of current encryption technologies leading to large-scale data leaks in the future. This provides a future-oriented and sustainable security guarantee for the digital identities of minors.

[0019] Secondly, this invention possesses a high degree of systematicity and synergy. It innovatively constructs a four-layer protection system comprising a terminal layer, a transmission layer, a storage layer, and a monitoring layer, achieving full-process coverage from data generation, transmission, storage to governance. The terminal layer, through pre-installed dedicated chips, ensures data is securely hardened at the source; the transmission layer establishes a quantum-secure virtual private network channel and forward security protocol, effectively resisting man-in-the-middle attacks and future quantum backtracking decryption; the storage layer introduces quantum-resistant blockchain evidence storage technology, ensuring not only the immutability and traceability of data but also enhancing its resilience against destruction by utilizing the characteristics of distributed ledgers; the monitoring layer, acting as the system's brain, endows the entire protection system with the ability to dynamically adapt and continuously evolve through real-time auditing and threat intelligence sharing. This layered defense and deeply collaborative architecture completely changes the previous fragmented and isolated state of security measures, forming an organically unified whole and significantly improving the overall robustness of the system.

[0020] Third, this invention boasts exceptional practicality and deployability. The solution design fully considers the unique characteristics of the education sector and the usage scenarios of minors. The proposed hybrid encryption transition strategy (combining RSA and quantum-resistant cryptographic algorithms) allows for a smooth evolution of existing systems, reducing upgrade and transformation costs. The experimental platform, specifically designed for educational scenarios, integrates quantum attack simulation and quantum-resistant encryption drills, transforming complex cryptographic principles into visualized teaching practices. It not only serves technical deployment but also fulfills the function of popularizing science education to enhance the quantum security awareness of teachers, students, and parents. This design, closely integrated with educational practice, enables the technical solution to quickly integrate into the campus information environment and promotes a higher level of security across the entire ecosystem from a cognitive perspective. Through targeted protection designs for mainstream educational applications on the market, it can directly address many existing vulnerabilities revealed in the document, such as plaintext caching of biometric data and lack of forward secrecy at the transport layer, providing immediate and effective protection.

[0021] Finally, this invention possesses significant social benefits and strategic value. Against the backdrop of growing societal concern for the protection of minors online, this solution provides a concrete technical path and a high-standard technical benchmark for implementing the "Regulations on the Protection of Minors Online." By pioneering the deployment of quantum-resistant cryptography technology in the education sector, it not only provides a "digital haven" for the most vulnerable minors but also cultivates future talent in cryptography at the national level, accumulating practical experience in quantum-resistant cryptographic migration. This has profound strategic significance for maintaining long-term national cybersecurity and seizing the technological high ground in the quantum era. As cryptography pioneers have stated, the best encryption is anticipating the future. This invention is a vivid practice of this concept, laying a solid technical foundation for building a secure and trustworthy digital future through the three-dimensional linkage of education, policy guidance, and technological innovation. Attached Figure Description

[0022] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings in the following description are merely exemplary, and those skilled in the art can derive other embodiments based on the provided drawings without creative effort.

[0023] Figure 1 This is a diagram of the four-layer protection system architecture of the present invention. Detailed Implementation

[0024] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses consistent with some aspects of this disclosure as detailed in the appended claims.

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0026] How to use 1. System initialization and terminal device registration First, the smart devices used by minors are initialized. Upon turning on a children's watch or tablet, the system automatically activates its pre-installed quantum-resistant cryptographic chip. This chip must be NIST certified, supporting the CRYSTALS-Kyber-768 key encapsulation mechanism and the Falcon-512 digital signature algorithm. During initialization, the chip's built-in 32-bit quantum random number generator generates a unique Kyber-768 key pair and immediately uses the Falcon-512 algorithm to digitally sign the device's identity. This signature serves as the device's trusted digital identity in all subsequent network interactions. The encryption latency of the entire initialization process should be less than 10ms to ensure a smooth user experience. For biometric data, such as voiceprints or facial recognition data, the system automatically uses a lattice cryptography algorithm for local encryption before processing.

[0027] Establish a secure communication session When a device needs to transmit data with the education platform server, it automatically initiates a request to establish a quantum-secure VPN tunnel. This process employs a dual-stack encryption mode, embedding the CRYSTALS-Kyber-768 algorithm within the traditional TLS protocol. The specific key exchange protocol is as follows: the client sends its Kyber-768 public key to the server, which then generates a temporary RSA-3072 key pair and encrypts it. Subsequently, both parties verify key consistency using the HMQV forward security protocol, negotiating a session key valid only for this session. The validity period of this session key is strictly limited to 24 hours. After each session ends, all related key materials are immediately destroyed on both the terminal and the server to prevent future quantum computing attempts to backtrack and crack the key.

[0028] Perform quantum-resistant data storage Before being stored, data must undergo a quantum-resistant blockchain notarization process. The storage layer divides the data into blocks and signs each block using a lattice-based Dilithium algorithm (such as Dilithium-1024). The generated signature value is then hashed using a SHA-3 hash function, and finally, the hash value along with the signature is written into the distributed ledger. The block header of each notarized block contains key information: the identifier of the PQC algorithm used (e.g., Kyber-768, Falcon-512) and the corresponding NIST quantum attack resistance level (L1 to L5). The minimum retention period for this notarized data is set at 20 years to match the growth cycle of minors and ensure its support for future judicial evidence tracing.

[0029] Implement continuous security monitoring and emergency response The regulatory layer provides continuous security auditing and dynamic protection during the operation of the entire system. Its PQC auditing module will monitor the execution status of all encryption algorithms in real time, including key rotation frequency and algorithm compliance. At the same time, a mandatory PQC compliance test is conducted on the devices accessing the education platform every quarter. Devices that fail to pass the certification of the CRYSTALS-Kyber or Falcon algorithm will be prohibited from accessing. The threat intelligence library of the regulatory layer will regularly synchronize the latest quantum attack cases released by institutions such as NIST. Once the real-time network traffic monitoring system detects quantum attack simulation behaviors, such as attack traffic based on the Qiskit-Shor algorithm, the system will automatically execute the emergency response plan and immediately switch the protected communication channel to a backup PQC algorithm (such as SPHINCS+), in order to maintain the continuity and security of the service.

[0030] Utilize the experimental platform for cognition and verification To deepen the understanding and verification effect, the supporting anti-quantum cryptography education experimental platform can be used. The quantum attack simulation module of the platform can demonstrate the process of the Shor algorithm cracking RSA-2048. The PQC encryption exercise module allows users to practice the encryption and decryption of the Kyber and Dilithium algorithms. The security attack and defense range can be used to simulate scenarios such as man-in-the-middle attacks to intuitively verify the effectiveness of this four-layer protection system.

[0031] Embodiment Embodiment 1: Anti-quantum secure communication of children's smart watches This embodiment aims at the privacy leakage risk of children's smart watches mentioned in the document, especially the problem of "28.7% of children's smart watch users stating that they have received friend requests from strangers". We design based on the cooperation plan between the Xiaot天才电话手表 is a registered trademark of Guangdong Xiaot天才电话手表 Co., Ltd. and may not be used without permission.iancai phone watch and the Cryptography Laboratory of Tsinghua University.

[0032] At the terminal layer, the watch is built-in with an anti-quantum cryptographic chip certified by NIST. When the child uses the watch to make a voice call or send location information to the exclusive application on the parent's mobile phone, all data will use the CRYSTALS-Kyber-768 algorithm for key encapsulation to generate a one-time session key before leaving the watch. Subsequently, the call content or location coordinates are encrypted using this session key, and at the same time, the encrypted data packet is digitally signed using the Falcon-512 algorithm to ensure the integrity and credibility of the source of the information.

[0033] At the transmission layer, the data is transmitted through the constructed quantum-secure VPN channel. This channel adopts a hybrid mode, which is compatible with the existing mobile network and nests the Kyber-768 algorithm to counter future quantum attacks. Even if the communication data is intercepted, attackers, whether using classical computers or future quantum computers, cannot crack its content.

[0034] At the storage layer, important historical location data is signed using the Dilithium algorithm on the server side and then stored on a quantum-resistant blockchain for evidence preservation, preventing data tampering. The monitoring layer monitors the watch's communication status in real time. If any connection request attempting to bypass PQC encryption (such as a simulated base station attack) is detected, the connection is immediately severed and a security alert is sent to the parent's device. This solution effectively eliminates the risk of strangers using technical means to simulate trusted nodes and establish illegal communication with the child.

[0035] Example 2: Quantum Security Upgrade of the Education App Zuoyebang This embodiment addresses the issues discovered during document research, such as "the existence of man-in-the-middle attack vulnerabilities in apps like Zuoyebang" and the widespread use of traditional RSA encryption, demonstrating the specific process of migrating to quantum-resistant cryptography.

[0036] When students submit homework answers containing personal information through the Zuoyebang app, the system activates the upgraded security protocol. At the terminal layer, the app calls the device's built-in PQC support library (such as interfaces provided by future operating systems or security chips) and uses the Kyber-768 algorithm to negotiate a forward-secure session key with the Zuoyebang server.

[0037] At the transport layer, this data transmission no longer relies solely on the traditional TLS protocol, but incorporates Kyber-768 key exchange during the TLS handshake phase. This means that even if an attacker performs man-in-the-middle eavesdropping on the current network, or if an adversary uses a quantum computer ten years from now to crack the long-term private key stored on the server, they will not be able to decrypt the specific content of today's assignment submission, because the key for each session is independent and is destroyed after use.

[0038] At the storage layer, long-term information such as students' homework data and learning records are signed using the Dilithium quantum-resistant signature algorithm before being stored on the server, and the hash value is then stored on the blockchain. This ensures the authenticity and immutability of students' growth records, and even if the threat of quantum computing power emerges in the future, the integrity of this historical data can still be verified. Regulatory authorities regularly audit Zuoyebang's encrypted traffic to ensure that its PQC protocol is always correctly enabled and compliant with standards.

[0039] Example 3: Teaching and Verification of a Campus Quantum-Resistant Cryptography Laboratory This embodiment describes a specific teaching practice scenario based on the recommendations for building quantum-resistant cryptography laboratories in Part IV of the document, "Education System Reform Plan".

[0040] In a newly built quantum-resistant cryptography lab at an elementary school in Haidian District, Beijing, an information technology teacher is giving students an introductory lesson on quantum security. Students first see firsthand how traditional encryption is broken through a quantum attack simulation module. Using an IBM Qiskit 32-qubit simulator integrated into the lab's computer, the teacher runs Shor's algorithm program. The large screen clearly displays that a task theoretically requiring 300 trillion years of computation on a classical computer to crack RSA-2048 is expected to take only a few hours in the simulated quantum environment. This demonstration vividly explains the meaning of the experimental data in the document, allowing students to deeply understand the urgency of the quantum threat.

[0041] Following this, the students moved on to the practical session. Using the OpenQuantumSafe development kit deployed in the lab, they worked hands-on in the PQC encryption exercise module. Group tasks included: encrypting a reflection on their studies using the Kyber algorithm, then exchanging and decrypting it; and signing and verifying an electronic transcript using the Dilithium algorithm. Through these comparative operations, students experienced firsthand the usability and efficiency of quantum-resistant cryptographic algorithms.

[0042] Finally, in a security attack and defense simulation, students played the roles of attackers and defenders. The attackers attempted to simulate a man-in-the-middle attack using tools on the Kali Linux platform, easily succeeding in stealing communication data from the "traditional encryption group." However, when they switched to attacking the "PQC protection group," which had deployed a four-layer protection system, all attack attempts were effectively blocked, and the defenders clearly saw the attack alert logs on the monitoring platform. This contrasting practice perfectly validated the experimental conclusion in the document that "the PQC group's breach rate dropped to 0%," greatly enhancing students' security awareness and practical skills.

[0043] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A quantum-resistant cryptographic data security protection system and method for minors, characterized in that, include: Terminal layer: Deployed in smart devices used by minors (such as children's watches and tablets), with a pre-installed quantum-resistant cryptographic chip, supporting CRYSTALS-Kyber algorithm and Falcon-512 signature algorithm, and using lattice cryptography to encrypt biometric data; Transport layer: Construct a quantum-secure VPN tunnel, employing a hybrid encryption mode (combining RSA-2048 and CRYSTALS-Kyber-768), and deploy a forward security protocol to prevent session keys from being cracked by quantum computing; Storage layer: Employing quantum-resistant blockchain notarization technology, all minors' data (such as identity information and learning records) is distributed and stored after being signed by the Dilithium algorithm, ensuring that the data is traceable and tamper-proof; Regulatory authorities: Integrated into the education big data platform, the application status of the PQC algorithm is audited in real time, and attack protection strategies are dynamically updated through a threat intelligence sharing mechanism.

2. The quantum-resistant cryptographic data security protection system and method for minors according to claim 1, characterized in that, The quantum-resistant cryptographic chip in the terminal layer must be certified by the NIST standard, support the CRYSTALS-Kyber-768 key encapsulation mechanism and the Falcon-512 digital signature algorithm, and its hardware configuration requirements are: built-in 32-bit quantum random number generator and encryption latency of less than 10ms.

3. The quantum-resistant cryptographic data security protection system and method for minors according to claim 1, characterized in that, The quantum-secure VPN channel in the transport layer adopts a dual-stack encryption mode: the CRYSTALS-Kyber-768 algorithm is nested in the traditional TLS protocol, and each session key generation must be combined with a forward security protocol (such as HMQV) to ensure that even if the long-term key is cracked by quantum computing, the historical session is still undecryptable.

4. The quantum-resistant cryptographic data security protection system and method for minors according to claim 1, characterized in that, The quantum-resistant blockchain evidence storage technology of the storage layer specifically involves: using the lattice-based Dilithium algorithm to sign data blocks, storing the hash value of the signed data in a distributed ledger, and ensuring that each block contains a timestamp and a PQC algorithm version identifier to prevent quantum computing power from tampering with historical data.

5. A quantum-resistant cryptographic data security protection system and method for minors according to claim 1, characterized in that, The regulatory layer includes a PQC audit module and a threat intelligence database. The audit module monitors the execution status of encryption algorithms in real time (such as key rotation frequency and algorithm compliance), while the threat intelligence database regularly synchronizes with quantum attack cases released by NIST (such as records of Shor's algorithm cracking) and dynamically adjusts protection strategies.

6. A quantum-resistant cryptographic data security protection system and method for minors according to claims 1-5, characterized in that, Includes the following steps: Step S1: When the terminal device is started for the first time, a Kyber-768 key pair is generated through the pre-configured PQC chip, and the device identity is signed using the Falcon-512 algorithm; Step S2: During data transmission, the terminal layer and the server negotiate the session key through a quantum-secure VPN channel, wherein the key exchange protocol integrates Kyber-768 and forward security mechanisms; Step S3: Before data storage, use the Dilithium algorithm to sign the data and calculate the hash value, and store the signed data and hash value together in the blockchain; Step S4: The regulator audits the data flow in real time. If a transmission request without PQC is detected, the connection is forcibly interrupted and an alarm is triggered.

7. A quantum-resistant cryptographic data security protection system and method for minors according to claim 6, characterized in that, The specific process of the key exchange protocol in step S2 is as follows: The client sends its Kyber-768 public key to the server, and the server generates a temporary RSA-3072 key pair to encrypt it. Both parties verify key consistency via the HMQV protocol, and the session key is valid for no more than 24 hours. The key material is destroyed immediately after each session to prevent quantum computing backtracking and cracking.

8. A quantum-resistant cryptographic data security protection system and method for minors according to claim 6, characterized in that, The specific implementation of blockchain evidence storage in step S3 includes: After data is divided into blocks, it is signed using the Dilithium-1024 algorithm, and the signature value is written to the blockchain after being hashed by SHA-3. Each block header contains a PQC algorithm identifier (such as Kyber-768, Falcon-512) and a quantum attack resistance level (divided into L1-L5 according to NIST standards). The retention period for evidence-based data is matched with the growth cycle of minors (minimum 20 years) and supports judicial evidence collection and tracing.

9. A quantum-resistant cryptographic data security protection system and method for minors according to claim 6, characterized in that, The audit rules for step S4 include: Educational platforms will undergo PQC compliance testing every quarter, and devices that fail to pass CRYSTALS-Kyber or Falcon algorithm certification will be prohibited from accessing the platform. Real-time monitoring of network traffic; if quantum attack simulation behavior (such as Qiskit-Shor algorithm traffic) is detected, automatic switching to backup PQC algorithms (such as SPHINCS+) is initiated.

10. The quantum-resistant cryptography education experimental platform according to any one of claims 1-5, characterized in that, include: Quantum attack simulation module: integrates IBM Qiskit 32-qubit simulator, which can demonstrate the process of Shor's algorithm breaking RSA-2048; PQC Encryption Practice Module: Equipped with the OpenQuantumSafe development kit, it supports students in practicing Kyber and Dilithium algorithms for encryption and decryption. Security Attack and Defense Range: A network range built on Kali Linux to simulate scenarios such as man-in-the-middle attacks and quantum brute-force attacks, and to verify the effectiveness of the four-layer protection.