Method, device and equipment for evaluating comprehensive performance of anti-quantum public key cryptographic algorithm
By configuring quantum-resistant key exchange and authentication interfaces, simulating network environments and functional modules, and evaluating the performance of quantum-resistant public-key cryptography algorithms, the problem of difficulty in quantifying efficiency and scale indicators in existing technologies is solved, and a comprehensive performance evaluation of the algorithm and a reference for system selection are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGJINKE INFORMATION TECH CO LTD
- Filing Date
- 2025-12-23
- Publication Date
- 2026-05-01
AI Technical Summary
In existing technologies, there is a lack of quantitative criteria for ranking the importance of indicators such as efficiency and scalability of quantum-resistant public-key cryptographic algorithms. This makes it difficult to quantitatively assess the practicality of algorithm design and evaluation, especially in balancing the relationship between security, efficiency, and scalability in the process of improving the technology.
This paper provides a comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms. By configuring a unified quantum-resistant key exchange interface and authentication interface, simulating a network environment for data interaction, generating algorithm interfaces, testing the issuance of quantum-resistant digital certificates, and deploying the algorithm in different functional modules to evaluate its performance.
It realizes the comprehensive performance evaluation of adversarial quantum public-key cryptography algorithms in different protocols, architectures and systems, provides a reference for algorithm standardization solicitation and system selection, and supports the flexible insertion and replacement of algorithms and quantitative performance evaluation.
Smart Images

Figure CN121966875A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of performance evaluation technology, and in particular to a method, apparatus, and device for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms. Background Technology
[0002] To address the potential impact of the rapid development of quantum computing on existing classical public-key cryptography algorithms, quantum-resistant public-key cryptography algorithms have become an important tool for ensuring information security in the post-quantum era. In the process of resisting quantum migration and transformation, in addition to their necessary classical and quantum security, the efficiency and scalability of quantum-resistant public-key algorithms are important indicators affecting their practicality. However, there is still a lack of quantitative judgment criteria for ranking the importance of these indicators.
[0003] The efficiency and scalability of quantum-resistant public-key cryptographic algorithms directly affect their practicality. Therefore, improving efficiency and scalability as much as possible while ensuring security is crucial in algorithm design. However, the impact of efficiency and scalability is not clearly defined in current algorithm evaluation processes. Many improvement techniques often involve trade-offs between efficiency and scalability. For example, if a new technique can improve ciphertext size at the cost of reduced encryption / decryption efficiency while maintaining security, it is difficult to quantitatively characterize the practicality of this technique, the relationship between the cost and the magnitude of the improvement, and its usefulness. This is not only a major problem for cryptographic algorithm designers but also poses a challenge to algorithm evaluation. To quantitatively assess the importance of efficiency and scalability of cryptographic algorithms, comprehensive performance evaluation considering application scenarios is a common approach. For example, NIST used 2000 cycles / byte as a method for converting algorithm scalability to efficiency in common network communication environments during the third round of evaluation for post-quantum standard solicitation, thereby achieving a unified evaluation and measurement of algorithm efficiency and scalability. Microsoft Research proposed a basic framework for comprehensive performance testing of quantum-resistant cryptographic algorithms in the TLS protocol. Zhao Yunlei et al. studied the impact of migrating NIST post-quantum standard candidate algorithms and award-winning algorithms from my country's cryptographic algorithm design competition to the TLS 1.3 protocol. Summary of the Invention
[0004] To address the aforementioned technical problems, embodiments of the present invention provide a method for evaluating the comprehensive performance of quantum-resistant public-key cryptography algorithms, comprising: Configure a unified quantum-resistant key exchange interface and authentication interface that match the target protocol; In a simulated network environment, data interaction is performed based on the algorithm under test, a preset service framework, the quantum-resistant key exchange interface and the authentication interface, wherein the algorithm under test includes a quantum-resistant public-key cryptography algorithm. The first performance of the algorithm under test is evaluated by statistically assessing the state of data interaction using the target protocol in the current network environment. In the target system, an algorithm interface is generated through the algorithm under test, and the algorithm interface is used to test and issue quantum-resistant digital certificates of a specified standard, wherein the specified standard matches the target system. The second performance of the algorithm under test is evaluated based on the test issuance status; Construct digital signature interfaces corresponding to different functional modules in the target system; The algorithm under test calls the digital signature interfaces of different functional modules to perform different network deployments, and evaluates the third performance of the algorithm under test based on the network deployment status. The first performance, second performance, and third performance are different.
[0005] In one embodiment, the target protocol includes the TLS 1.3 protocol; When the target protocol is TLS 1.3, the configuration of a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol includes: Configure a unified quantum-resistant key exchange interface and authentication interface that are compatible with the TLS 1.3 protocol.
[0006] In one embodiment, the step of data interaction in a simulated network environment based on the algorithm under test, a preset service framework, and the quantum-resistant key exchange interface and authentication interface includes: In various simulated network environments, data interaction is performed based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface, and the authentication interface. The preset service framework includes a standalone client and a server test framework.
[0007] In one embodiment, the statistical evaluation of the first performance of the algorithm under test through the state of data interaction of the target protocol in the current network environment includes: The key exchange time, authentication time, and message transmission length are statistically analyzed when data interaction is performed using the target protocol in the current network environment. The performance of the algorithm under test under the TLS 1.3 protocol is evaluated based on the key exchange time, authentication time, and message transmission length.
[0008] In one embodiment, the target system includes a PKI system; In the target system, the algorithm interface is generated through the algorithm under test, including: Under the PKI system, the algorithm interface is generated using a quantum-resistant certificate generation tool and the algorithm under test.
[0009] In one embodiment, the second performance evaluation of the algorithm under test based on the test issuance status includes: The performance of the algorithm under test in the target system, including the PKI system, is evaluated based on the completion time of issuing different numbers of quantum-resistant digital certificates.
[0010] In one embodiment, the target system includes a blockchain system; The construction of digital signature interfaces corresponding to different functional modules in the target system includes: Multiple digital signature interfaces are constructed in the blockchain system, corresponding to the transaction module, consensus module, and node communication module, respectively.
[0011] In one embodiment, the step of calling different digital signature interfaces of the functional modules through the algorithm under test to perform different network deployments, and evaluating the third performance of the algorithm under test based on the network deployment status, includes: By calling the digital signature interfaces of different functional modules through the algorithm under test, a network deployment of different numbers of transaction nodes, consensus nodes, and communication nodes is carried out, and the read latency, read throughput, transaction latency, transaction throughput, and block size of the algorithm under test during the network deployment are statistically analyzed. The performance of the algorithm under test in the blockchain system is evaluated based on the statistical metrics of read latency, read throughput, transaction latency, transaction throughput, and block size.
[0012] Another embodiment of the present invention also provides a comprehensive performance evaluation device for quantum-resistant public-key cryptography algorithms, comprising: The configuration module is used to configure a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol. The interaction module is used to perform data interaction in a simulated network environment based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface and the authentication interface. The algorithm under test includes a quantum-resistant public-key cryptography algorithm. The first evaluation module is used to evaluate the first performance of the algorithm under test by statistically analyzing the state of data interaction through the target protocol in the current network environment. The issuance module is used to generate an algorithm interface in the target system through the algorithm under test, and to test and issue quantum-resistant digital certificates of a specified standard using the algorithm interface, wherein the specified standard matches the target system. The second evaluation module is used to evaluate the second performance of the algorithm under test based on the test issuance status. The building module is used to build digital signature interfaces corresponding to different functional modules in the target system; The third evaluation module is used to call the digital signature interfaces of different functional modules through the algorithm under test to perform different network deployments, and evaluate the third performance of the algorithm under test based on the network deployment status. The first performance, second performance and third performance are different.
[0013] Another embodiment of the present invention also provides an electronic device, comprising: One or more processors; Memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the comprehensive performance evaluation method for quantum-resistant public-key cryptography as described above.
[0014] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings.
[0015] The technical solution of this application will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0016] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating the comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms in this embodiment of the invention.
[0018] Figure 2 This is a flowchart illustrating the comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms in another embodiment of the present invention.
[0019] Figure 3 This is a flowchart illustrating the comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms in another embodiment of the present invention.
[0020] Figure 4 This is a structural block diagram of the quantum-resistant public-key cryptography algorithm comprehensive performance evaluation device in an embodiment of the present invention. Detailed Implementation
[0021] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings, but these are not intended to limit the scope of the invention.
[0022] It should be understood that various modifications can be made to the embodiments disclosed herein. Therefore, the following description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope of this disclosure will be apparent to those skilled in the art.
[0023] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present disclosure and, together with the general description of the disclosure given above and the detailed description of the embodiments given below, serve to explain the principles of the disclosure.
[0024] These and other features of the invention will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.
[0025] It should also be understood that although the invention has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of the invention, which have the features described in the claims and are therefore all within the scope of protection defined herein.
[0026] The above and other aspects, features and advantages of this disclosure will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.
[0027] Specific embodiments of the present disclosure are described thereafter with reference to the accompanying drawings; however, it should be understood that the disclosed embodiments are merely examples of the present disclosure and can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the present disclosure. Therefore, the specific structural and functional details disclosed herein are not intended to be limiting, but merely to serve as the basis and representative basis for the claims to teach those skilled in the art to use the present disclosure in a variety of substantially any suitable detailed structures.
[0028] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in still another embodiment,” all of which may refer to one or more of the same or different embodiments according to this disclosure.
[0029] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0030] like Figure 1 As shown, this embodiment of the invention provides a method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms, including: S1: Configure a unified quantum-resistant key exchange interface and authentication interface that match the target protocol; S2: In a simulated network environment, data interaction is performed based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface and the authentication interface, wherein the algorithm under test includes a quantum-resistant public-key cryptography algorithm; S3: Statistically evaluate the first performance of the algorithm under test when performing data interaction through the target protocol in the current network environment; S4: In the target system, an algorithm interface is generated through the algorithm under test, and the algorithm interface is used to test and issue a quantum-resistant digital certificate of a specified standard, wherein the specified standard matches the target system; S5: Evaluate the second performance of the algorithm under test based on the test issuance status; S6: Construct digital signature interfaces corresponding to different functional modules in the target system; S7: The algorithm under test calls the digital signature interface of different functional modules to perform different network deployments, and evaluates the third performance of the algorithm under test based on the network deployment status. The first performance, second performance and third performance are different.
[0031] The comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms proposed in this embodiment establishes a comprehensive performance evaluation system for quantum-resistant public-key cryptography. It encapsulates a unified public-key cryptography algorithm interface across three typical application scenarios: different communication protocols, different authentication systems, and different systems. This allows for flexible plug-and-play functionality for different types of algorithms under test. Furthermore, it can determine core performance indicators (such as throughput and response speed) for different protocols, systems, and architectures based on their main functions, enabling a comprehensive performance evaluation of different algorithms under test within these protocols, systems, and architectures. In other words, the method in this embodiment can support the standardization and evaluation of quantum-resistant cryptography algorithms and provide a reference for selecting quantum-resistant cryptography algorithms for various industries.
[0032] In one embodiment, the target protocol includes the TLS 1.3 protocol; When the target protocol is TLS 1.3, the configuration of a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol includes: S101: Configure a unified quantum-resistant key exchange interface and authentication interface that are compatible with the TLS 1.3 protocol.
[0033] Of course, the protocol is not limited to TLS 1.3; it can be other types of protocols as well.
[0034] The process of data interaction in a simulated network environment, based on the algorithm under test, a preset service framework, and the quantum-resistant key exchange interface and authentication interface, includes: S201: In various simulated network environments, data interaction is performed based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface, and the authentication interface. The preset service framework includes a standalone client and a server test framework.
[0035] Furthermore, such as Figure 2 As shown, the statistics assess the first performance of the algorithm under test by evaluating the state of data interaction of the target protocol in the current network environment, including: S301: Statistically measure the key exchange time, authentication time, and message transmission length when data interaction is performed through the target protocol in the current network environment; S302: Evaluate the performance of the algorithm under test under the TLS 1.3 protocol based on the key exchange time, authentication time, and message transmission length.
[0036] For example, the algorithm encapsulates a unified quantum-resistant key exchange interface and authentication interface. This interface adapts to the standard TLS 1.3 message structure and processing logic, and supports flexible plugging and unplugging of different quantum-resistant key encapsulation algorithms and quantum-resistant digital signature algorithms within the encapsulated interface. In application, this embodiment constructs a single-machine client-server experimental framework to assist in quantifying and controlling network latency and packet loss rate, simulating various network environments. Finally, by statistically analyzing the completion time of key exchange and authentication, as well as the transmission message length, under different network conditions, the overall performance of the algorithm under test under the TLS 1.3 protocol is comprehensively evaluated, i.e., the first performance.
[0037] In another embodiment, the target system includes a PKI system; In the target system, the algorithm interface is generated through the algorithm under test, including: S401: Under the PKI system, the algorithm interface is generated by the quantum-resistant certificate generation tool and the algorithm under test.
[0038] The target system can be a PKI system or other systems, the specifics are uncertain.
[0039] Furthermore, the second performance evaluation of the algorithm under test based on the test issuance status includes: S501: Evaluate the performance of the algorithm under test in a target system, including a PKI system, based on the completion time of issuing different numbers of quantum-resistant digital certificates.
[0040] This embodiment describes the evaluation of quantum-resistant cryptographic algorithms in a PKI system. The proposed solution is a quantum-resistant certificate format compatible with the X.509v3 standard. When applied, a quantum-resistant certificate generation tool can be developed, configured to expose a unified interface for quantum-resistant public-key cryptography algorithms. The specific testing involves measuring the completion time of issuing different numbers of quantum-resistant digital certificates, and then evaluating the overall performance of the algorithm under test in the PKI system based on this completion time—that is, the second performance characteristic.
[0041] In another embodiment, the target system includes a blockchain system, such as a mainstream, thriving open-source blockchain platform that has undergone quantum-resistant transformation (e.g., ChainMaker, Hyperledger Fabric). Of course, other types of systems are also possible, depending on the specific requirements.
[0042] The construction of digital signature interfaces corresponding to different functional modules in the target system includes: S601: Construct multiple digital signature interfaces in the blockchain system that correspond to the transaction module, consensus module, and node communication module, respectively.
[0043] For example, a unified digital signature interface can be encapsulated in the transaction module, consensus module, and node communication module respectively. This interface supports the invocation of various quantum-resistant digital signature algorithms to be tested, that is, it supports the invocation of various algorithms to be tested.
[0044] like Figure 3 As shown, the step of calling different digital signature interfaces of the functional modules through the algorithm under test to perform different network deployments, and evaluating the third performance of the algorithm under test based on the network deployment status, includes: S701: By calling the digital signature interfaces of different functional modules through the algorithm under test, network deployment of different numbers of transaction nodes, consensus nodes, and communication nodes is carried out, and the read latency, read throughput, transaction latency, transaction throughput, and block size of the algorithm under test during the network deployment are statistically analyzed. S702: Evaluate the performance of the algorithm under test in the blockchain system based on the statistical data of read latency, read throughput, transaction latency, transaction throughput, and block size.
[0045] For example, this embodiment uses a single-machine multi-node test environment to support the rapid deployment of the algorithm under test in networks with different numbers of blockchain ledger nodes and consensus nodes. During testing, the overall performance of the algorithm under test in the blockchain system, i.e., the third performance, is evaluated by statistically analyzing the system's read latency, read throughput, transaction latency, transaction throughput, and block size (blocks contain the same number of transactions).
[0046] Based on the above embodiments, it can be seen that the solution is to study the main functions and key indicators in three typical application scenarios: TLS protocol, PKI system, and blockchain system, evaluate the impact of quantum-resistant public key cryptography algorithms on key indicators in these typical application scenarios, and then construct an automated comprehensive performance evaluation tool to implement the comprehensive performance evaluation function of the automated evaluation platform for quantum-resistant public key cryptography algorithms. The specific implementation methods include: First, by extensively studying the main application scenarios of current quantum-resistant public-key cryptography, several representative typical application scenarios are extracted; second, based on the functions and characteristics of each application scenario, key evaluation indicators for each application scenario are summarized, such as: the average running time for client-server key negotiation and authentication in the TLS protocol, the message length of ClientHello, ServerHello, and ServerHello+, etc.; the average time required to issue different numbers of quantum-resistant certificates in the PKI system, etc.; and the average latency and throughput of the system completing read operations, the average latency and throughput of the system completing transactions, and the block size in the blockchain system, etc.; third, by encapsulating a unified quantum-resistant key exchange interface and authentication interface, adapting to the standard protocol message structure and processing logic, and supporting the flexible plugging and unplugging of different quantum-resistant public-key encryption algorithms and quantum-resistant digital signature algorithms in the interface; subsequently, an experimental framework is constructed to quantify and control network latency and packet loss rate, the number of digital certificates generated, network bandwidth, and the number of ledger nodes and consensus nodes to simulate different network environments that each protocol may face for testing; finally, a standard test set and evaluation scheme are formed to provide quantitative evaluation results of the comprehensive performance of the quantum-resistant public-key cryptographic algorithms under test.
[0047] In other words, the comprehensive performance evaluation system for quantum-resistant public-key cryptography algorithms in the aforementioned embodiments comprises a three-layer architecture: a unified cryptographic service supporting algorithm pluggability, a dynamically controllable testing environment implementing layered resource management, and multi-dimensional algorithm evaluation indicators. The cryptographic service is divided into two parts: quantum-resistant certificate management and quantum-resistant key management. The underlying layer is compatible with both x86 and ARM architecture CPUs, supports migration to domestically developed IT systems, and ultimately constructs a unified cryptographic service platform adaptable to multiple systems. The operating environment consists of a network engine and a node engine, used to quantify and control network packet loss rate, network latency, and the number of blockchain nodes, respectively, to achieve elastic blockchain network and network kernel simulation, forming a dynamic network testing framework, and ultimately constructing a complex network resource quantification control mechanism. The multi-dimensional algorithm evaluation system constructs rich test sets in typical application scenarios to statistically and quantitatively evaluate throughput and response speed, thereby proposing comprehensive algorithm performance evaluation standards.
[0048] like Figure 4 As shown, another embodiment of the present invention also provides a comprehensive performance evaluation device for quantum-resistant public-key cryptography algorithms, comprising: The configuration module is used to configure a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol. The interaction module is used to perform data interaction in a simulated network environment based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface and the authentication interface. The algorithm under test includes a quantum-resistant public-key cryptography algorithm. The first evaluation module is used to evaluate the first performance of the algorithm under test by statistically analyzing the state of data interaction through the target protocol in the current network environment. The issuance module is used to generate an algorithm interface in the target system through the algorithm under test, and to test and issue quantum-resistant digital certificates of a specified standard using the algorithm interface, wherein the specified standard matches the target system. The second evaluation module is used to evaluate the second performance of the algorithm under test based on the test issuance status. The building module is used to build digital signature interfaces corresponding to different functional modules in the target system; The third evaluation module is used to call the digital signature interfaces of different functional modules through the algorithm under test to perform different network deployments, and evaluate the third performance of the algorithm under test based on the network deployment status. The first performance, second performance and third performance are different.
[0049] In one embodiment, the target protocol includes the TLS 1.3 protocol; When the target protocol is TLS 1.3, the configuration of a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol includes: Configure a unified quantum-resistant key exchange interface and authentication interface that are compatible with the TLS 1.3 protocol.
[0050] In one embodiment, the step of data interaction in a simulated network environment based on the algorithm under test, a preset service framework, and the quantum-resistant key exchange interface and authentication interface includes: In various simulated network environments, data interaction is performed based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface, and the authentication interface. The preset service framework includes a standalone client and a server test framework.
[0051] In one embodiment, the statistical evaluation of the first performance of the algorithm under test through the state of data interaction of the target protocol in the current network environment includes: The key exchange time, authentication time, and message transmission length are statistically analyzed when data interaction is performed using the target protocol in the current network environment. The performance of the algorithm under test under the TLS 1.3 protocol is evaluated based on the key exchange time, authentication time, and message transmission length.
[0052] In one embodiment, the target system includes a PKI system; In the target system, the algorithm interface is generated through the algorithm under test, including: Under the PKI system, the algorithm interface is generated using a quantum-resistant certificate generation tool and the algorithm under test.
[0053] In one embodiment, the second performance evaluation of the algorithm under test based on the test issuance status includes: The performance of the algorithm under test in the target system, including the PKI system, is evaluated based on the completion time of issuing different numbers of quantum-resistant digital certificates.
[0054] In one embodiment, the target system includes a blockchain system; The construction of digital signature interfaces corresponding to different functional modules in the target system includes: Multiple digital signature interfaces are constructed in the blockchain system, corresponding to the transaction module, consensus module, and node communication module, respectively.
[0055] In one embodiment, the step of calling different digital signature interfaces of the functional modules through the algorithm under test to perform different network deployments, and evaluating the third performance of the algorithm under test based on the network deployment status, includes: By calling the digital signature interfaces of different functional modules through the algorithm under test, a network deployment of different numbers of transaction nodes, consensus nodes, and communication nodes is carried out, and the read latency, read throughput, transaction latency, transaction throughput, and block size of the algorithm under test during the network deployment are statistically analyzed. The performance of the algorithm under test in the blockchain system is evaluated based on the statistical metrics of read latency, read throughput, transaction latency, transaction throughput, and block size.
[0056] Another embodiment of the present invention also provides an electronic device, comprising: One or more processors; Memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the comprehensive performance evaluation method for quantum-resistant public-key cryptography as described above.
[0057] Furthermore, one embodiment of the present invention also provides a storage medium storing a computer program, which, when executed by a processor, implements the comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms as described above. It should be understood that the various schemes in this embodiment have the corresponding technical effects in the above-described method embodiments, and will not be repeated here.
[0058] Furthermore, embodiments of the present invention also provide a computer program product, which is tangibly stored on a computer-readable medium and includes computer-readable instructions that, when executed, cause at least one processor to perform a comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms, such as the embodiment described above.
[0059] It should be noted that the computer storage medium of the present invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, system, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access storage medium (RAM), a read-only storage medium (ROM), an erasable programmable read-only storage medium (EPROM or flash memory), an optical fiber, a portable compact disk read-only storage medium (CD-ROM), an optical storage medium, a magnetic storage medium, or any suitable combination thereof. In the present invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program configured for use by or in connection with an instruction execution system, system, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, antenna, optical fiber, RF, etc., or any suitable combination thereof.
[0060] Furthermore, those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0061] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A system that specifies functions in one or more boxes.
[0062] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction set implemented in a process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0063] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of protection of this application is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of one or more embodiments of this application as described above, which are not provided in detail for the sake of brevity.
Claims
1. A method for evaluating the comprehensive performance of quantum-resistant public-key cryptographic algorithms, characterized in that, include: Configure a unified quantum-resistant key exchange interface and authentication interface that match the target protocol; In a simulated network environment, data interaction is performed based on the algorithm under test, a preset service framework, the quantum-resistant key exchange interface and the authentication interface, wherein the algorithm under test includes a quantum-resistant public-key cryptography algorithm. The first performance of the algorithm under test is evaluated by statistically assessing the state of data interaction using the target protocol in the current network environment. In the target system, an algorithm interface is generated through the algorithm under test, and the algorithm interface is used to test and issue quantum-resistant digital certificates of a specified standard, wherein the specified standard matches the target system. The second performance of the algorithm under test is evaluated based on the test issuance status; Construct digital signature interfaces corresponding to different functional modules in the target system; The algorithm under test calls the digital signature interfaces of different functional modules to perform different network deployments, and evaluates the third performance of the algorithm under test based on the network deployment status. The first performance, second performance, and third performance are different.
2. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 1, characterized in that, The target protocol includes the TLS 1.3 protocol; When the target protocol is TLS 1.3, the configuration of a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol includes: Configure a unified quantum-resistant key exchange interface and authentication interface that are compatible with the TLS 1.3 protocol.
3. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 1, characterized in that, The process of data interaction in a simulated network environment, based on the algorithm under test, a preset service framework, and the quantum-resistant key exchange interface and authentication interface, includes: In various simulated network environments, data interaction is performed based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface, and the authentication interface. The preset service framework includes a standalone client and a server test framework.
4. The method for comprehensive performance evaluation of quantum-resistant public-key cryptographic algorithms according to claim 1 or 3, characterized in that, The statistics assess the first performance of the algorithm under test by evaluating the state of data interaction of the target protocol in the current network environment, including: The key exchange time, authentication time, and message transmission length are statistically analyzed when data interaction is performed using the target protocol in the current network environment. The performance of the algorithm under test under the TLS 1.3 protocol is evaluated based on the key exchange time, authentication time, and message transmission length.
5. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 1, characterized in that, The target system includes the PKI system; In the target system, the algorithm interface is generated through the algorithm under test, including: Under the PKI system, the algorithm interface is generated using a quantum-resistant certificate generation tool and the algorithm under test.
6. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 1, characterized in that, The second performance evaluation of the algorithm under test based on the test issuance status includes: The performance of the algorithm under test in the target system, including the PKI system, is evaluated based on the completion time of issuing different numbers of quantum-resistant digital certificates.
7. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 1, characterized in that, The target system includes a blockchain system; The construction of digital signature interfaces corresponding to different functional modules in the target system includes: Multiple digital signature interfaces are constructed in the blockchain system, corresponding to the transaction module, consensus module, and node communication module, respectively.
8. The method for comprehensive performance evaluation of quantum-resistant public-key cryptography algorithms according to claim 7, characterized in that, The process of calling different digital signature interfaces of the functional modules through the algorithm under test to perform different network deployments, and evaluating the third performance of the algorithm under test based on the network deployment status, includes: By calling the digital signature interfaces of different functional modules through the algorithm under test, a network deployment of different numbers of transaction nodes, consensus nodes, and communication nodes is carried out, and the read latency, read throughput, transaction latency, transaction throughput, and block size of the algorithm under test during the network deployment are statistically analyzed. The performance of the algorithm under test in the blockchain system is evaluated based on the statistical metrics of read latency, read throughput, transaction latency, transaction throughput, and block size.
9. A device for evaluating the comprehensive performance of quantum-resistant public-key cryptography algorithms, characterized in that, include: The configuration module is used to configure a unified quantum-resistant key exchange interface and authentication interface that matches the target protocol. The interaction module is used to perform data interaction in a simulated network environment based on the algorithm under test, the preset service framework, the quantum-resistant key exchange interface and the authentication interface. The algorithm under test includes a quantum-resistant public-key cryptography algorithm. The first evaluation module is used to evaluate the first performance of the algorithm under test by statistically analyzing the state of data interaction through the target protocol in the current network environment. The issuance module is used to generate an algorithm interface in the target system through the algorithm under test, and to test and issue quantum-resistant digital certificates of a specified standard using the algorithm interface, wherein the specified standard matches the target system. The second evaluation module is used to evaluate the second performance of the algorithm under test based on the test issuance status. The building module is used to build digital signature interfaces corresponding to different functional modules in the target system; The third evaluation module is used to call the digital signature interfaces of different functional modules through the algorithm under test to perform different network deployments, and evaluate the third performance of the algorithm under test based on the network deployment status. The first performance, second performance and third performance are different.
10. An electronic device, comprising: One or more processors; Memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the comprehensive performance evaluation method for quantum-resistant public-key cryptography algorithms as described in any one of claims 1-8.