File encryption transmission method supporting selectable quantum key and random key
By mapping the operating state of the encryption system to non-Newtonian fluid dynamics parameters and dynamically controlling key distribution using the equivalent Reynolds number to generate a hybrid key stream, the problem of response lag and transmission instability in quantum key distribution systems under complex network conditions is solved, achieving efficient data transmission and business continuity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEFEI D2S INFORMATION TECH CO LTD
- Filing Date
- 2026-03-23
- Publication Date
- 2026-04-21
AI Technical Summary
When faced with complex network conditions, existing quantum key distribution systems suffer from a mismatch between key generation rate and data transmission rate, leading to delayed response, data blockage, or service interruption under sudden traffic surges. Furthermore, system parameter jitter can easily cause transmission link instability.
The operating parameters of the encryption system are mapped to non-Newtonian fluid dynamics parameters. The key distribution is dynamically controlled by the equivalent Reynolds number to generate a hybrid key stream to adapt to complex network environments. A nonlinear adjustment strategy is adopted to balance security and transmission efficiency.
It enables the encryption system to adapt and adjust in complex network environments, improving the stability of data transmission and business continuity, and reducing the risk of system response delays and transmission blockages under sudden traffic surges.
Smart Images

Figure CN121907613A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of file encryption technology, and more specifically, to a file encryption transmission method that supports the selection of quantum keys and random keys. Background Technology
[0002] Quantum key distribution (QKD) technology is considered a core means of ensuring communication security. However, due to physical limitations such as fiber attenuation and detector efficiency, the key generation rate of current QKD systems is usually much lower than the data transmission rate of high-speed communication networks. This imbalance between low key generation rate and high throughput limits the application of QKD technology in large-scale high-speed networks.
[0003] To address these issues, existing technologies often employ a hybrid encryption strategy of "quantum key and random key". However, traditional key scheduling strategies are mostly based on static threshold decisions or linear mapping of a single parameter. This scheduling method has several problems when facing complex network conditions: On the one hand, in the face of sudden network traffic, existing scheduling strategies are unable to respond to the exponentially increasing key consumption demand, which can easily lead to underloading of the quantum key buffer pool, resulting in data blockage or service interruption, making it difficult to balance high security and service availability; on the other hand, when the system is operating near the critical threshold for policy switching, small fluctuations in network parameters can easily trigger high-frequency oscillations in the scheduling strategy, which increases the computation and scheduling overhead of the encryption system and can easily lead to abnormal data packet transmission timing, thereby affecting the stability of the transmission link.
[0004] To address the above problems, this invention proposes a solution. Summary of the Invention
[0005] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide a file encryption transmission method that supports the selection of quantum keys and random keys. By mapping the operating state to a non-Newtonian fluid parameter with shear-thinning characteristics and dynamically adjusting the key allocation according to the equivalent Reynolds number, the method solves the problem of strategy adjustment delay and transmission blockage caused by key supply and demand imbalance under complex operating conditions in the prior art.
[0006] To achieve the above objectives, the present invention provides the following technical solution: A file encryption transmission method supporting optional quantum key and random key includes the following steps: obtaining the operating state parameters of the current encryption system; establishing a numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics, wherein the numerical mapping relationship is obtained by performing nonlinear operations and weighted corrections on the operating state parameters to obtain the dynamic parameters; calculating the equivalent Reynolds number of the current data block of the target file based on the dynamic parameters, wherein the equivalent Reynolds number is used to characterize the equivalent flow stability of the current encryption system; matching the key allocation strategy of the current data block of the target file according to the equivalent Reynolds number, and generating a hybrid key stream based on the original bit streams of quantum key and random key; encrypting the current data block using the hybrid key stream, and encapsulating and transmitting the encrypted data blocks.
[0007] In a preferred embodiment, establishing the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: performing nonlinear operations on the computational resource parameters in the operating state parameters based on a preset load congestion threshold to obtain the density parameter of the virtual fluid; calculating the supply-demand ratio of data throughput and real-time quantum key generation rate in the operating state parameters, and obtaining the relative flow velocity of the virtual fluid through logarithmic compression operations.
[0008] In a preferred embodiment, establishing the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: using the channel packet loss rate in the operating state parameters as a drag coefficient, and weighting and correcting the effective payload length of the current data block of the target file to obtain the characteristic length of the virtual fluid.
[0009] In a preferred embodiment, establishing the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: taking the key consumption rate in the operating state parameters as the equivalent shear rate, and combining the quantum key buffer pool inventory and data block sensitivity identifier in the operating state parameters to calculate the equivalent apparent viscosity parameter of the non-Newtonian fluid, wherein the apparent viscosity has a nonlinear negative correlation with the equivalent shear rate.
[0010] In a preferred embodiment, calculating the equivalent Reynolds number of the current data block of the target file includes: calculating the equivalent Reynolds number of the current data block based on non-Newtonian fluid dynamic parameters including fluid density, relative velocity, characteristic length, and equivalent apparent viscosity, using the following formula:
[0011] in, For the equivalent Reynolds number, For fluid density parameters, The relative velocity of the virtual fluid. The characteristic length of the virtual fluid. The equivalent apparent viscosity of the virtual fluid; The global scaling factor is obtained based on the physical limit calibration of the system, so that when the encryption system is under the theoretical maximum physical condition, the calculated equivalent Reynolds number is equal to the critical Reynolds number for turbulence in fluid mechanics.
[0012] In a preferred embodiment, the key allocation strategy for matching the current data block of the target file according to the equivalent Reynolds number includes: defining the numerical domain of the equivalent Reynolds number as a state space that includes at least a stable interval, a transition interval, and a divergent interval based on a preset first threshold and a second threshold; and configuring the quantum key ratio in the corresponding key allocation strategy to a preset saturation value and a preset cutoff value for data blocks whose equivalent Reynolds number is in the stable interval and the divergent interval, respectively.
[0013] In a preferred embodiment, the key allocation strategy for matching the current data block of the target file according to the equivalent Reynolds number further includes: for data blocks whose equivalent Reynolds number is in the transition range, using a preset nonlinear decay curve to perform parameter mapping to obtain the corresponding quantum key allocation ratio.
[0014] In a preferred embodiment, the step of combining the original bit streams based on quantum keys and random keys to generate a hybrid key stream includes: calculating the amount of quantum key data and random key data required for encrypting the current data block according to the quantum key ratio in the key allocation strategy; extracting key fragments from the original bit streams of quantum keys and random keys according to the data amounts, and splicing and combining them to obtain a hybrid key stream that conforms to the key allocation strategy.
[0015] In a preferred embodiment, encrypting the current data block using a hybrid key stream further includes applying perturbation noise in parallel based on the magnitude of the change in the equivalent Reynolds number to obfuscate the power consumption characteristics of the encryption operation.
[0016] An electronic device includes: a memory for storing a computer program; and a processor for executing the computer program to implement the step of the file encryption transmission method supporting optional quantum key and random key.
[0017] The technical effects and advantages of the file encryption transmission method supporting the selection of quantum keys and random keys in this invention are as follows: 1. This invention maps the operating state parameters of the encryption system to non-Newtonian fluid dynamics parameters and uses the shear thinning characteristics of non-Newtonian fluids to simulate the rheological characteristics of the encryption system under high-frequency consumption of key resources. This solves the response lag problem of traditional linear scheduling strategies under sudden traffic surges and achieves nonlinear adaptive adjustment between low load and high security and high load and high throughput. This improves the effective coverage and utilization efficiency of limited quantum resources in the file encryption transmission process.
[0018] 2. This invention achieves an adaptive balance between data security and transmission efficiency during the encryption process by using an equivalent Reynolds number matching key distribution strategy and dynamically generating a hybrid key stream that combines quantum keys and random keys. This suppresses the risk of key distribution strategy oscillation under critical resource conditions, improves the anti-disturbance capability of the encrypted transmission system in complex network environments, and ensures the convergence of service quality and business continuity under full load conditions. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of a file encryption transmission method that supports the selection of quantum keys and random keys, provided as an embodiment of the present invention.
[0020] Figure 2 This is a schematic diagram of the shear-thinning characteristics of the equivalent apparent viscosity of the encryption system in an embodiment of the present invention.
[0021] Figure 3 This is a schematic diagram illustrating the control effect of the key allocation strategy provided in an embodiment of the present invention.
[0022] Figure 4 This is a structural block diagram of an exemplary electronic device provided for implementing embodiments of the present disclosure. Detailed Implementation
[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0024] Example 1, Figure 1 This invention provides a file encryption transmission method that supports the selection of quantum keys and random keys, comprising the following steps: S1. Obtain the current operating status parameters of the encryption system, and establish a numerical mapping relationship between the operating status parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics. The numerical mapping relationship is obtained by performing nonlinear calculations and weighted corrections on the operating status parameters to obtain the dynamic parameters. S101. Obtain the current operating status parameters of the encryption system, as follows: The system receives the target file to be encrypted and transmits it, and divides the target file into a series of data blocks with temporal correlation according to a preset granularity. The granularity can be adaptively adjusted according to the network environment, such as adapting to the size of the network's maximum transmission unit (MTU), or using a fixed length of 4KB or 8KB. The data blocks are the basic units for subsequent parameter sampling and encryption processing. Before encrypting the current data block to be processed, a sliding time window aligned snapshot mechanism is adopted from four dimensions: computing resources, network environment, key status and data attributes. The end time of the sampling window is the time when the current data block starts processing, and the start time is the time when the current moment is traced back to the preset sampling period (e.g., 10ms). The average value or cumulative change of each dimension parameter within the unified sampling period is statistically calculated and used as the running status parameter at the current moment. Specifically, regarding computing resources, a lock-free kernel bypass acquisition technique (such as an eBPF-based probe or a counter that reads shared memory mapping regions) is used to collect the current CPU and memory usage. When collecting CPU usage, a process ID filtering mechanism is used to specifically remove the extra CPU overhead caused by noise-injected threads, and only the effective CPU load of business processes and system basic processes is counted. The comprehensive computing load value is obtained by weighting and summing the CPU and memory usage using preset weights, where the CPU usage weight can range from 0.6 to 0.8 (e.g., 0.7), and the sum of the memory usage weight and the CPU usage weight is 1. In terms of the network environment, the instantaneous data throughput (in bps) of the current network interface is obtained through the packet transmission and reception statistics function of the network card driver layer; at the same time, the channel packet loss rate is obtained by monitoring the feedback information of the transport layer protocol. For example, in the TCP protocol, the proportion of retransmitted packets to total sent packets is counted, or in the RTP / RTCP protocol, the packet loss statistics field in the receiver report is parsed. Regarding key status, the real-time key generation rate of the quantum key is read through the instantaneous status interface of the quantum key distribution device; the northbound status interface of the quantum key management system is called synchronously to read the quantum key buffer pool inventory in real time. Specifically, a protected shared storage area is selected as the buffer pool in the system memory and maintained by an atomic counter to obtain the number of currently valid and unextracted key bits; at the same time, the key consumption rate is obtained through the encryption engine statistics interface. Specifically, after setting a microsecond or millisecond time sampling window (e.g., 10ms) to count the total number of key bits consumed, the key consumption rate at the current moment is calculated. Alternatively, based on the 1:1 linear relationship between key consumption and plaintext data volume under the stream encryption mechanism, the equivalent acquisition can be directly obtained using the instantaneous data throughput of the current network interface. Regarding data attributes, the header fields of the target file are first parsed. If a pre-set security classification label exists in the file header, it is directly mapped to a sensitivity identifier value. For example, the label "Top Secret" is mapped to an identifier value of 5, and the label "Public" is mapped to an identifier value of 1. If no security classification label exists, the five-tuple information of the current network connection (source IP, destination IP, source port, destination port, protocol type) is extracted and the local pre-set business sensitivity configuration table is queried. For example, if the port number corresponds to a financial transaction service, or the source IP comes from the core intranet segment, the corresponding sensitivity identifier value of 4 is obtained by matching through the business sensitivity configuration table. It should be noted that for all data blocks belonging to the same target file, the same sensitivity identifier value is usually inherited in the same transmission session to ensure the continuity of the fluid's basic viscosity parameters.
[0025] S102. Based on a preset load congestion threshold, perform nonlinear calculations on the computational resource parameters in the operating status parameters to obtain the density parameters of the virtual fluid, as follows: In fluid mechanics, density is a measure of the inertia of matter, characterizing how easily an object changes its state of motion. In encryption systems, the utilization rate of computing resources (CPU / memory) is equivalently mapped to the system's "computational inertia": the higher the resource utilization rate, the greater the resistance to scheduling new tasks or responding to interrupt requests, and the worse the adjustment flexibility. Therefore, the comprehensive computing load value is mapped to virtual fluid density to reflect the dynamic hysteresis characteristics of the encryption system under high-pressure conditions through changes in density. To characterize the rapid change in inertia when the load of the encryption system approaches its limit, an exponential nonlinear growth model is adopted. Based on the comprehensive calculated load value and combined with a preset load congestion threshold (e.g., 0.85), the virtual fluid density is calculated using the following formula: (1) in, For fluid density, To comprehensively calculate the load value, This is the load congestion threshold. Use the basic density constant (e.g., take 1.0) to normalize the physical dimensions; This is the congestion sensitivity coefficient, ranging from 7.0 to 10.0, used to control the steepness of nonlinear growth; Formula (1) references the congestion model in queuing theory and the exponential impedance function in traffic flow theory. The exponential term in the formula can accurately describe the physical fact that the system's "computational inertia" increases explosively when the load exceeds the threshold, so as to ensure that the inertial force term can dominate near the system congestion point in the subsequent Reynolds number calculation, thereby reflecting the physical trend of the system's stability being destroyed.
[0026] S103. Calculate the supply-demand ratio of data throughput to real-time quantum key generation rate in the operating status parameters, and obtain the relative flow velocity of the virtual fluid through logarithmic compression, as follows: In fluid mechanics, flow velocity characterizes how fast a fluid passes through a cross section and determines the magnitude of the fluid's momentum. In encryption systems, the supply-demand ratio between the throughput of data to be transmitted and the rate of quantum key generation directly reflects the "impact intensity" of the current flow on the system: the larger the supply-demand ratio, the greater the instantaneous throughput of data flow relative to processing capacity. Therefore, the supply-demand ratio is mapped to the relative flow velocity of a virtual fluid to reflect the dynamic impact of data transmission demand on the encryption system. Considering the huge order-of-magnitude difference between data throughput (typically in the Gbps range) and quantum key generation rate (typically in the Kbps range), the natural logarithm function is used to establish the mapping relationship between the supply-demand ratio and the relative flow rate, as shown in the following formula: (2) in, Relative flow velocity; This is a flow rate scaling factor (e.g., 10) used to adjust the magnitude of the ratio; It is a very small positive number (e.g., 10). -6 (), used to prevent the denominator from being zero; For instantaneous data throughput, The real-time key generation rate of quantum keys; Formula (2) references the Weber-Fechner law in the field of signal processing. Logarithmic operation can not only smooth the supply-demand ratio across orders of magnitude, but also retain the sensitivity to the rate of change, that is, it is sensitive in the low flow rate range and smooth in the high flow rate range, which is consistent with the nonlinear saturation characteristics of fluids during the process of pressure acceleration.
[0027] S104. Using the channel packet loss rate in the operating status parameters as a drag coefficient, the effective payload length of the current data block in the target file is weighted and corrected to obtain the characteristic length of the virtual fluid, as follows: In fluid mechanics and turbulence statistics, characteristic length (such as pipe diameter) determines the spatial geometric constraints of the flow field and also characterizes the mixing scale of turbulent vortices, i.e., the effective range of disturbance. In encrypted transmission, the larger the data block, the wider the information envelope of a single processing and the higher the channel packet loss rate, which indicates that the random disturbance of the transmission link is also more severe. Therefore, the channel packet loss rate is mapped to a nonlinear expansion term of characteristic length, i.e., drag coefficient, to characterize the increase in the effective disturbance scale of the encryption system. This is manifested as a larger equivalent turbulent mixing length in harsher environments. Obtain the actual number of encrypted bytes after removing the protocol header from the current data block, i.e., the payload length; and calculate the virtual fluid characteristic length using a geometric series expansion model to characterize the increasing complexity of the perturbation boundary under high packet loss conditions. The calculation formula is as follows: (3) in, For characteristic length, The payload length of the current data block in the target file. Use a reference length base value (e.g., take the MTU size of 1500 bytes) to normalize the data block size; For channel packet loss rate; This is the drag correction factor (e.g., 5.0). This is an environmental degradation index, with a value ranging from 1.0 to 2.0; Formula (3) references Prandtl's mixed length theory and its modified model, with the exponential term... The introduction of this concept draws on the concept of fractal dimension to describe the nonlinear expansion of the system's disturbance scale under high packet loss conditions, ensuring that the calculated characteristic length can accurately reflect the physical fact that the system tends towards turbulence (high Reynolds number) under severe operating conditions.
[0028] S105. Using the key consumption rate in the operating state parameters as the equivalent shear rate, and combining it with the quantum key pool inventory and data block sensitivity identifier in the operating state parameters, calculate the equivalent apparent viscosity parameter of the non-Newtonian fluid. The apparent viscosity and the equivalent shear rate have a non-linear negative correlation, as detailed below: In non-Newtonian fluid dynamics, fluid viscosity is a function of shear rate, where the viscosity of shear-thinned fluids decreases as the shear rate increases. In cryptographic systems, the key consumption rate is analogous to the shear rate of a fluid, and the key buffer pool and data sensitivity are analogous to the fluid's basic viscosity. When keys are consumed too quickly, the system's defense reserves (viscosity) are rapidly depleted, leading to a decrease in the system's ability to maintain a "laminar" (quantum) state. To achieve a rapid response of viscosity to the consumption rate, a negative exponential decay model is adopted. Based on the key consumption rate, the quantum key pool inventory, and the data block sensitivity identifier, the equivalent apparent viscosity parameter is calculated. The calculation formula is as follows: (4) in, Equivalent apparent viscosity; It is the basic viscosity constant, ranging from 1.0 × 10⁻⁵ to 1.0 × 10⁻³, used for dimensional normalization; This is the sensitivity flag value for the data block, ranging from 1 to 5; This is the stock of the quantum key buffer pool; It is a non-zero correction term, such as 1.0, to avoid mathematical singularities; This refers to the key consumption rate; This is the shear-thinning decay factor, which takes a negative value (e.g., from -0.5 to -2.0) to ensure that the exponential term shows a decaying trend; Formula (4) references a variant of the Arrhenius empirical equation in rheology and the characteristics of power-law fluids. This mathematical form endows the system with "digital melting" characteristics, that is, maintaining high viscosity (high security) with low consumption, while when the key consumption rate exceeds the threshold, the viscosity will drop rapidly exponentially, causing the Reynolds number to increase, thereby triggering a phase transition from quantum encryption to a hybrid encryption mode; such as Figure 2 As shown in the figure, the base viscosity is set to 5×10. -4 The response characteristic curves of the equivalent apparent viscosity as a function of key consumption rate are shown for different sensitivity values under typical parameters such as a shear thinning attenuation coefficient of -1.5. It can be seen that as the key consumption rate increases, the equivalent apparent viscosity exhibits a significant exponential nonlinear decay (i.e., shear thinning), especially in the initial stage where the viscosity drops rapidly, which intuitively reflects the physical characteristics of digital circuit breaking. At the same time, the higher the sensitivity value, the higher the overall potential of the corresponding viscosity curve, indicating that high-security services have stronger defensive inertia and shear resistance under the same consumption.
[0029] It should be noted that traditional encrypted transmission system strategy control is usually based on discrete threshold judgment in a single dimension, ignoring the nonlinear strong coupling relationship between computational load, channel environment and key supply and demand. This results in the system often lacking inertial buffer or causing data congestion due to response lag when facing sudden traffic surges. This invention constructs a numerical mapping mechanism between operating state parameters and non-Newtonian fluid dynamic parameters, transforming multi-source operating state parameters such as CPU load, network throughput, packet loss rate and key consumption into physical field quantities. Based on the shear thinning characteristics of non-Newtonian fluids, it simulates the adaptive physical instinct of the encrypted system to automatically reduce "defense viscosity" in exchange for "transmission fluidity" under high-throughput conditions, laying a theoretical foundation for subsequent global precise control using Reynolds numbers.
[0030] S2. Based on the aforementioned dynamic parameters, calculate the equivalent Reynolds number of the current data block in the target file. The equivalent Reynolds number is used to characterize the equivalent flow stability of the current encryption system, including: Based on the definition of the Reynolds number in fluid mechanics, which is the ratio of inertial force to viscous force, the virtual fluid density parameter, relative velocity, characteristic length, and equivalent apparent viscosity parameter obtained in step S1 are comprehensively calculated. In a physical sense, the numerator of the formula represents the "inertial driving force" that attempts to break the system balance and cause congestion or packet loss during the encrypted transmission process, while the denominator of the formula represents the "viscous resisting force" that the system attempts to maintain an ordered and precise quantum encrypted state. Specifically, for the current data block of the target file, the system calls the floating-point arithmetic unit to perform the calculation of the equivalent Reynolds number, and the calculation formula is as follows: (5) in, The equivalent Reynolds number for the current data block. For fluid density, Relative flow velocity For characteristic length, Equivalent apparent viscosity; The global scaling factor is obtained based on the physical limit calibration of the system, so that when the encryption system is under the theoretical maximum physical condition, the calculated equivalent Reynolds number is equal to the critical Reynolds number for turbulence in fluid mechanics; The theoretical maximum physical operating condition refers to the extreme state in which the system is most likely to induce turbulence (i.e., all parameters point to a high Reynolds number). Specifically, this means: the current data throughput reaches the upper limit of the hardware physical bandwidth; the real-time quantum key generation rate is the rated minimum generation rate of the QKD device; the current data block length reaches the maximum transmission unit (MTU) allowed by the protocol stack; the channel packet loss rate is taken as a preset severe congestion reference value (e.g., 5% or 10%); the computing resource utilization rate is 100% and the current data block sensitivity is the lowest level (e.g., 1); and the quantum key buffer pool inventory drops to a preset minimum security threshold (e.g., 0.05).
[0031] This invention transforms discrete heterogeneous parameters into continuous dynamic state ratios by calculating the equivalent Reynolds number, a dimensionless normalization index. Based on the inherent multi-parameter coupling and inertial characteristics of fluids, it smooths out network jitter interference, avoids policy misjudgment caused by small fluctuations in a single parameter, and achieves accurate quantitative characterization of the global stability of the encryption system.
[0032] S3. Match the key distribution strategy of the current data block of the target file according to the equivalent Reynolds number, and generate a hybrid key stream based on the original bit streams of quantum key and random key; In this embodiment, the key allocation strategy for matching the current data block in step S3 includes: S301. Based on the preset first threshold and second threshold, the numerical domain of the equivalent Reynolds number is defined as a state space that includes at least a stable interval, a transition interval, and a divergence interval, as follows: Based on the experimental statistical laws of classical fluid mechanics, the first threshold is set as the critical Reynolds number for laminar flow (which can be 2000), and the second threshold is set as the critical Reynolds number for turbulent flow (which can be 4000). When the Reynolds number is less than the critical Reynolds number for laminar flow, the fluid is mainly controlled by viscous forces, and the flow is stable, i.e., laminar flow. When the Reynolds number is greater than the critical Reynolds number for turbulent flow, the fluid is dominated by inertial forces, and the flow is chaotic, i.e., turbulent flow. Therefore, the range from 0 to the first threshold is defined as the stable interval, which characterizes the system in a low-load, high-security quantum laminar state; the range between the first threshold and the second threshold is defined as the transition interval, which characterizes the system in a critical process of evolving from a steady state to an unsteady state; and the range greater than the second threshold is defined as the divergence interval, which characterizes the system in a high-load or high-disturbance turbulent state.
[0033] S302. For data blocks whose equivalent Reynolds number is in the stable and divergent regions, the quantum key allocation ratio in the corresponding key distribution strategy is configured to a preset saturation value and a preset cutoff value, respectively, as follows: When the equivalent Reynolds number of the current data block is detected to be in a stable range, in order to maximize security, the quantum key distribution ratio is locked to a preset saturation value, which can be 1.0, that is, 100% quantum key usage. When the equivalent Reynolds number of the current data block is detected to be in the congestion or high-interference divergence range, in order to ensure business continuity and prevent the quantum key pool from being exhausted, the quantum key allocation ratio is locked to a preset cutoff value. The cutoff value can be 0 or 0.05, that is, completely switch to random keys or only retain a very small number of quantum keys for signaling handshake.
[0034] S303. For data blocks whose equivalent Reynolds number is in the transition range, parameter mapping is performed using a preset nonlinear decay curve to obtain the corresponding quantum key distribution, as follows: For data blocks with equivalent Reynolds numbers in the transition range, parameter mapping is performed by calling nonlinear decay curves with cosine or S-shaped inversion geometric characteristics to simulate the continuous gradual change characteristics of the transformation from ordered to disordered states during physical phase transitions, thereby eliminating system control oscillations caused by policy jumps at the mathematical level. In this embodiment, a smooth transition curve based on the cosine function is used as the mapping benchmark. The two ends of the smooth transition curve smoothly connect the preset saturation value and the preset cutoff value with zero slope, respectively. The system substitutes the currently calculated equivalent Reynolds number into the mathematical expression of the curve to directly map and obtain a unique quantum key distribution. The functional expression of the smooth transition curve is as follows: (6) in, The quantum key distribution for the current data block; , These are the preset saturation value and the preset cutoff value, respectively. , These are the first threshold and the second threshold, respectively; Pi; To demonstrate the control effect of the key allocation strategy, such as Figure 3 As shown in the figure, the quantum key distribution ratio changes with the equivalent Reynolds number: in the stable region below the first threshold, the system maintains 100% quantum key distribution; after entering the transition region, the quantum key distribution ratio decays nonlinearly along a cosine S-curve in a "slow-fast-slow" manner, avoiding step-like abrupt changes; when it exceeds the second threshold and enters the divergence region, the ratio smoothly converges to a preset cutoff value (5%) to retain a minimum signaling encryption capability.
[0035] In this embodiment, step S3, which combines the original bit streams of quantum key and random key to generate a hybrid key stream, includes: S304. Based on the quantum key ratio in the key distribution strategy, calculate the amount of quantum key data and random key data required for encrypting the current data block, as follows: The payload length of the current data block to be encrypted is padded according to the bit width alignment granularity required by the encryption algorithm (e.g., 8-bit byte alignment, 64-bit word length alignment, or 128-bit block alignment) to obtain the physical length. For example, if the alignment granularity is 8 bits and the payload length is 1001 bits, the system needs to pad with 7 bits of zero or invalid data so that the physical length is 1008 bits, or 126 bytes. Multiply the physical length and the quantum key ratio, divide the product by the alignment granularity, round or round the result, and then multiply back by the alignment granularity to ensure that the quantum key data size is an integer multiple of the alignment granularity. The difference between the physical length and the quantum key data size is used as the random key data size. For example, if the physical length of the current data block is 1008 bits and the alignment granularity is 8 bits, the product of the physical length and the quantum key ratio is calculated to be 705.6 bits. Divide the product by the alignment granularity, round the result, and multiply by the alignment granularity to obtain 704 bits. Therefore, the quantum key data size and the random key data size required for encrypting the current data block are 704 bits and 304 bits, respectively.
[0036] S305. Based on the stated data volume, extract key segments from the original bit streams of the quantum key and the random key respectively, and concatenate and combine them to obtain a hybrid key stream that conforms to the stated key distribution strategy, as follows: First, based on the amount of quantum key data, the quantum key buffer pool is accessed directly through a memory pointer to extract the quantum key bit stream sequence of the corresponding length; at the same time, based on the amount of random key data, a high-speed pseudo-random number generator (such as a generator based on AES-CTR mode or ChaCha20 algorithm) is invoked to calculate and generate the random key bit stream sequence of the corresponding length in real time. Subsequently, the quantum key bitstream sequence and the random key bitstream sequence are physically concatenated according to a preset key concatenation rule to generate a hybrid keystream with a total length identical to the physical length of the current data block. Specifically, the key concatenation rule can adopt various structured assembly forms to adapt to different encryption computation requirements. The concatenation rule includes, but is not limited to: 1. Segmented concatenation topology, which uses a linear padding method to place the quantum key bitstream sequence at the beginning (first 704 bits) of the hybrid keystream and the random key bitstream sequence at the end of the hybrid keystream; 2. Block-level interleaving topology, which, based on the alignment granularity, alternately inserts the two key sequences in blocks (e.g., quantum key, random key, quantum key...) to improve the statistical complexity of the hybrid keystream in the time domain distribution.
[0037] This step achieves adaptive on-demand allocation of quantum key resources by adjusting the key ratio of different strategies, including nonlinear decay, based on the equivalent Reynolds number. This improves the business continuity of the system under load fluctuation scenarios, suppresses strategy oscillations caused by small parameter fluctuations in the critical state, and enhances the control stability and robustness of the encryption system in dynamic network environments.
[0038] S4. Encrypt the current data block using a hybrid key stream, while simultaneously applying perturbation noise in parallel based on the change amplitude of the equivalent Reynolds number to obfuscate the power consumption characteristics of the encryption operation; finally, encapsulate the encrypted data blocks for transmission, as follows: A streaming-based encryption pipeline is established. A hybrid key stream aligned with the physical length of the current data block is used to perform a bitwise XOR operation on the padded current data block to ensure real-time data processing capability. Specifically, the hybrid key stream is loaded into a cache, and the physical bit sequence of the current data block is XORed with the hybrid key stream in parallel using the CPU's vectorized instruction set (such as AVX-512) or a dedicated encryption coprocessor to generate a ciphertext data block. The ciphertext data block is written into a ciphertext output buffer pre-allocated in memory by the system. While performing the bitwise XOR operation, the total CPU utilization of the current system is monitored in real time to determine whether it exceeds a preset warning threshold (e.g., 90%). If it exceeds the threshold, the perturbation noise injection operation is paused; if it does not exceed the threshold, the perturbation noise injection intensity is dynamically adjusted based on the change in the equivalent Reynolds number between adjacent data blocks. The perturbation noise injection intensity is quantified using a standard computing unit as the benchmark. The standard computing unit is defined as the number of benchmark operation loops required for the current hardware to generate a unit power consumption fluctuation, as measured during the system's startup initialization phase. The perturbation noise injection intensity is an integer multiple of the benchmark operation loop count. Specifically, the absolute value of the difference between the equivalent Reynolds number of the current data block and the previous data block is calculated, and the perturbation noise injection intensity to be applied at the current moment is calculated based on the absolute value of the difference. The calculation formula for the perturbation noise injection intensity is as follows: (7) in, Inject intensity to disturb the noise; The characteristic leakage of the static power reference is based on the background noise intensity (e.g., 1000 cycles / block). and These are the equivalent Reynolds numbers for the current data block and the previous data block, respectively; This is the turbulence response gain coefficient, and its value can range from 10.0 to 50.0. It should be noted that traditional encryption systems are prone to generating statistically significant power consumption characteristics during policy switching, facing the risk of leakage inferring the internal state of the system based on differential power consumption analysis. This step quantifies the severity of the system's flow state switching by utilizing the absolute value of the difference between the equivalent Reynolds numbers of adjacent data blocks, and dynamically adjusts the injection intensity of disturbance noise accordingly, achieving precise power consumption masking and improving the encryption system's resistance to side-channel attacks and reliability.
[0039] After the current ciphertext data block is generated, the session identifier negotiated during the session establishment phase is read to mark the channel; the block counter value synchronized with the equivalent Reynolds number calculation index is read as the sequence number, used for reordering and as a synchronization seed parameter for generating pseudo-random key fragments during decryption; the starting index value of the currently consumed quantum key fragment in the global quantum key buffer pool is obtained, that is, the difference between the current memory read pointer and the starting address of the buffer pool, to obtain the absolute offset of the quantum key stream; a cyclic redundancy check algorithm (e.g., the standard CRC-32 algorithm) is called to generate a polynomial to perform a modulo-2 division operation on the current ciphertext data block, and the remainder is used as the integrity check code; An independent protocol header buffer is allocated in memory, and the bit width of each field in the transmission protocol header is set according to the preset protocol frame format. For example, the session identifier occupies 4 bytes, the sequence number occupies 4 bytes, the integrity check code occupies 4 bytes, the current key matching identifier occupies 4 bytes, and the quantum key stream absolute offset occupies 8 bytes. The total length of the protocol header is 24 bytes. The encrypted transmission protocol header frame structure used in this embodiment is shown in Table 1. Table 1 defines the offset and function of each field: Table 1
[0040] Based on the zero-copy interface of the data plane development kit or operating system, a scatter-cluster list containing two physical address pointers is constructed in the descriptor ring of the network card driver layer. The first pointer points to the protocol header buffer, and the second pointer points to the ciphertext output buffer where the ciphertext data block is located. The network card reads the protocol header and ciphertext data sequentially from the scattered physical memory areas according to the scatter-cluster list through the direct memory access mechanism, and automatically assembles them into complete network data packets in the physical link layer. The packets are then transmitted to the predetermined receiving address through the TCP / IP protocol stack or optical transport network channel. After receiving a data packet, the receiving end parses the transport protocol header and uses the session identifier in the header to locate the corresponding encrypted channel context. It reads the sequence number to detect packet loss or out-of-order delivery. Simultaneously, it extracts the ciphertext data block from the data packet and performs local calculations on the ciphertext data block using the same Cyclic Redundancy Check (CRC) algorithm as the sending end to obtain a local checksum. The local checksum is then compared with the integrity checksum carried in the protocol header. If the values do not match, the verification fails, indicating that the data packet is corrupted or maliciously tampered with. The receiving end immediately discards the data packet and sends a retransmission request or waits for a timeout and retransmission. If the values match, the verification passes, and the process proceeds to the decryption stage. For encrypted data packets that have passed verification, the receiving end performs stream decryption based on the reflexivity principle of XOR operation. Specifically, this includes: First, the receiving end extracts the absolute offset of the quantum key stream from the protocol header and determines whether the absolute offset is less than the maximum valid address index of the current local quantum key buffer pool. If it is less, the read pointer of the local quantum key pool is forcibly jumped to the logical position indicated by the absolute offset to ensure that the key streams of the sending and receiving parties are strictly aligned. Otherwise, the current data packet is determined to be an abnormal attack packet, a security alarm is triggered, and the data is discarded. Next, a quantum key fragment with the same position and length as the sender is extracted, and a random key fragment of the same length is generated using the same sequence number and preset seed as the sender. Based on the current key matching identifier and the sender's key concatenation rules, these fragments are combined to form a decryption hybrid key stream. Subsequently, the receiver performs a bitwise XOR operation between the ciphertext data block and the decryption hybrid key stream using CPU instructions to directly restore the plaintext data block containing padding bits. Finally, invalid padding bits at the end of the plaintext data block are removed according to the agreed alignment granularity to recover the original payload data, thus completing the data packet decryption.
[0041] See Figure 4 An electronic device includes: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of the file encryption transmission method supporting optional quantum key and random key.
[0042] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0043] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.
[0044] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0045] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0046] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0047] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A file encryption transmission method supporting optional quantum key and random key, characterized in that, Includes the following steps: Obtain the current operating status parameters of the encryption system, establish a numerical mapping relationship between the operating status parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics, and obtain the dynamic parameters by performing nonlinear calculations and weighted corrections on the operating status parameters. Based on the aforementioned dynamic parameters, the equivalent Reynolds number of the current data block of the target file is calculated. The equivalent Reynolds number is used to characterize the equivalent flow stability of the current encryption system. The key allocation strategy for the current data block of the target file is matched according to the equivalent Reynolds number, and a hybrid key stream is generated by combining the original bit streams of quantum key and random key. The current data block is encrypted using a mixed key stream, and the encrypted data blocks are then encapsulated and transmitted.
2. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The establishment of the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: Based on a preset load congestion threshold, nonlinear calculations are performed on the computational resource parameters in the operating status parameters to obtain the density parameter of the virtual fluid. The supply-demand ratio of data throughput to quantum key generation rate in the operating status parameters is calculated, and the relative flow velocity of the virtual fluid is obtained through logarithmic compression.
3. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The establishment of the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: Using the channel packet loss rate in the operating status parameters as a resistance coefficient, the effective payload length of the current data block in the target file is weighted and corrected to obtain the characteristic length of the virtual fluid.
4. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The establishment of the numerical mapping relationship between the operating state parameters and non-Newtonian fluid dynamic parameters containing shear thinning characteristics includes: The key consumption rate in the operating state parameters is used as the equivalent shear rate. Combined with the quantum key buffer pool inventory and data block sensitivity identifier in the operating state parameters, the equivalent apparent viscosity parameter of the non-Newtonian fluid is calculated. The apparent viscosity has a nonlinear negative correlation with the equivalent shear rate.
5. The file encryption transmission method supporting optional quantum key and random key as described in any one of claims 1-4, characterized in that, The calculation of the equivalent Reynolds number of the current data block of the target file includes: Based on non-Newtonian fluid dynamics parameters including fluid density, relative velocity, characteristic length, and equivalent apparent viscosity, the equivalent Reynolds number of the current data block is calculated using the following formula: in, For the equivalent Reynolds number, For fluid density parameters, The relative velocity of the virtual fluid. The characteristic length of the virtual fluid. The equivalent apparent viscosity of the virtual fluid. This is the global scaling factor obtained based on the system's physical limit calibration.
6. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The key allocation strategy for matching the current data block of the target file based on the equivalent Reynolds number includes: Based on the preset first threshold and second threshold, the numerical domain of the equivalent Reynolds number is defined as a state space that includes at least a stable interval, a transition interval, and a divergent interval; the first threshold is the laminar critical Reynolds number, and the second threshold is the turbulent critical Reynolds number. For data blocks whose equivalent Reynolds number is in the stable and divergent ranges, the quantum key ratio in the corresponding key allocation strategy is configured to a preset saturation value and a preset cutoff value, respectively.
7. The file encryption transmission method supporting optional quantum key and random key as described in claim 6, characterized in that, The key allocation strategy for matching the current data block of the target file based on the equivalent Reynolds number further includes: For data blocks whose equivalent Reynolds number is in the transition range, parameter mapping is performed using a preset nonlinear decay curve to obtain the corresponding quantum key distribution.
8. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The original bit streams based on quantum keys and random keys are combined to generate a hybrid key stream, including: Based on the quantum key allocation ratio in the key distribution strategy, calculate the amount of quantum key data and random key data required for encrypting the current data block; Based on the stated data volume, key segments are extracted from the original bit streams of quantum keys and random keys respectively, and then spliced and combined to obtain a hybrid key stream that conforms to the stated key distribution strategy.
9. The file encryption transmission method supporting optional quantum key and random key as described in claim 1, characterized in that, The method of encrypting the current data block using a hybrid key stream also includes applying perturbation noise in parallel according to the change amplitude of the equivalent Reynolds number to obfuscate the power consumption characteristics of the encryption operation.
10. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the file encryption transmission method supporting optional quantum key and random key as described in any one of claims 1 to 9 when executing the computer program.