Key generation method and device based on Galois permutation representation
By using a key generation method based on Galois group permutation representation, the problems of limited key space and security dependency are solved, achieving efficient and secure key generation that is adaptable to different application scenarios and resource conditions, and meets the high security requirements of financial transactions and military communications.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANTONG UNIV
- Filing Date
- 2026-03-27
- Publication Date
- 2026-05-15
AI Technical Summary
Existing key generation technologies are difficult to meet the needs of complex and ever-changing application scenarios. Key space is limited, security depends on mathematical structures, making them vulnerable to attacks. Furthermore, they have high computational complexity in resource-constrained environments, making them ineffective and unable to meet the high security requirements of financial transactions and military communications.
A key generation method based on Galois group permutation representation is adopted. By selecting appropriate base fields and extension fields to construct Galois groups, multiple initial key fragments are generated using the permutation representation of Galois group elements. The final key is generated by combining a nonlinear fusion algorithm and dynamic random factors, and the key generation strategy is automatically adjusted in real time by monitoring changes in the application scenario.
It achieves a large key space, can resist various attacks, adapts to various application scenarios, improves the security and operating efficiency of information systems, is suitable for various computing resource conditions, and meets high security requirements.
Smart Images

Figure CN122053057A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a key generation method and apparatus, particularly a key generation method and apparatus based on Galvaro permutation representation, belonging to the field of network communication security. Background Technology
[0002] In the digital age, the importance of information security is increasingly prominent. With the rapid development of network technology, data faces numerous security threats during transmission and storage, such as data theft, tampering, or forgery. As a core element in ensuring information security, the security, adaptability, and performance of key generation technology directly affect the secure and stable operation of the entire information system.
[0003] Traditional key generation techniques have several limitations. Firstly, many traditional algorithms struggle to meet the diverse key requirements of complex and ever-changing application scenarios. While algorithms like RSA (based on the large integer factorization problem) and ElGamal (based on the discrete logarithm problem) offer some degree of security, their key spaces are limited by the algebraic scale of the chosen mathematical structure. With increasing computational power and continuous optimization of factorization algorithms, existing key lengths face the risk of exhaustive search. Secondly, while elliptic curve-based key generation techniques can achieve shorter key lengths with the same security strength, their security is highly dependent on the choice of curve. Weak curves are vulnerable to MOV attacks, Smart attacks, and the elliptic curve discrete logarithm problem also faces challenges from quantum computing attacks. Furthermore, traditional key generation methods are mostly based on commutative algebraic structures, which are relatively simple and susceptible to algebraic attacks. Once a key is generated, it is used for a long time, lacking dynamic responsiveness to changes in application scenarios and making it difficult to cope with real-time attack threats. In resource-constrained environments, traditional key generation techniques may fail to operate effectively due to high computational complexity, impacting system performance. In fields with extremely high security requirements, such as financial transactions and military communications, the key strength of existing technologies may be insufficient to meet the high standards of security.
[0004] Therefore, developing a key generation technology that can provide a large key space, has a complex algebraic structure, can adapt to various application scenarios, has dynamic adaptive capabilities, and has true randomness has become an urgent problem to be solved in the field of cryptography. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a key generation method and apparatus based on Galvaro permutation representation, so as to improve the security, stability and operating efficiency of information systems.
[0006] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:
[0007] A key generation method based on Galois group permutation representation includes the following steps: S1. Select the base domain and extension domain based on security requirements to construct the domain expansion. Determine the Galois group And establish Galois group elements in extended domain Permutation representation on ; S2. Obtain user identity information and encryption requirement parameters, and select the extended domain. The basic elements in the group, using the Galois group Elements of different orders are applied to the base elements respectively. The elements after the permutation are represented as polynomials over the extended field. The coefficient vectors are extracted and compressed and mapped to generate multiple initial key fragments. S3. A nonlinear fusion algorithm is used to integrate multiple initial key fragments to construct an S-box based on the Galois field. Multiple key fragments are input into the S-box for nonlinear transformation to obtain an intermediate key. A dynamic random factor based on system timestamps, hardware physical noise, or statistical characteristics of network data packet arrival intervals is introduced to perturb the intermediate key and generate the final key. S4. Set the threshold for monitoring parameters to monitor changes in encryption requirements and computing resource dynamics in the application scenario in real time. Once the monitoring parameters exceed the preset threshold, immediately start the key regeneration process, automatically adjust the number of domain expansions, change the base domain characteristics, or switch the Galois group type, and re-execute steps S1-S3 to generate a new key adapted to the current environment.
[0008] Furthermore, in step S1, an appropriate domain expansion is selected based on the security level and application scenario; for general commercial applications, a limited domain is selected. As a base domain construction extension Its Galois group is a cyclic group. For military and financial fields, non-commutative Galois groups are chosen, such as by constructing polynomials. A splitting domain over a rational number field has a Galois group that is a cubic symmetric group. .
[0009] Furthermore, in step S2, the elements after the substitution are represented as polynomials over the extended field. Extracting the coefficient vector And perform compression mapping on the coefficient vector. Generate a fixed-length binary key fragment, where Convert the field elements to their binary representation. This represents the XOR operation.
[0010] Furthermore, in step S3, a Galois domain-based system is constructed. S box ,in for An invertible matrix, The key is a constant vector. Multiple key fragments are concatenated and then input into an S-box for nonlinear transformation to obtain the intermediate key. Dynamic random factors are generated through an entropy extraction algorithm. Perform an affine transformation on the intermediate key. ,in Given an invertible matrix, the final key is obtained.
[0011] Further, in step S4, the threshold values for the monitored parameters include... Network Traffic Sudden Change Index , set when Triggered at time; Attack detection alert level Set to levels 1-5, when Triggered at time; System load rate , set when Triggered at time; The adjustment strategy is expressed as .
[0012] A key generation system for performing a key generation method based on Galois group permutation representation, comprising: The parameter collection module is used to collect user identity information, encryption requirement parameters, and computing resource status data; The Galois group construction module constructs a domain extension and determines its Galois group based on the application scenario and security requirements, and establishes a permutation representation of Galois group elements. The key generation module selects the basic elements in the extended field, generates multiple initial key fragments by using the permutation of the Galois group elements, integrates the multiple initial key fragments using a nonlinear fusion algorithm to obtain the intermediate key, and introduces a dynamic random factor to generate the final key. The key adaptation monitoring module sets monitoring parameter thresholds to monitor changes in encryption requirements and computing resource dynamics in application scenarios in real time. When the monitoring parameters exceed the preset threshold, the key generation module is triggered to regenerate the key and automatically adjust the domain expansion parameters and Galois group type.
[0013] Compared with the prior art, the present invention has the following advantages and effects: 1. This invention provides a key generation method based on Galois group permutation representation. By leveraging the complexity of the group structure, the key space can be maximized. The scale is far greater than that of traditional methods. The scale is large enough to effectively resist brute-force attacks; at the same time, by combining noncommutative algebraic structures and nonlinear fusion technology, it can resist various attack methods such as linear cryptanalysis, differential cryptanalysis, and algebraic attacks, which greatly improves the security of information systems. 2. Through a unique key adaptation mechanism, it can flexibly generate adapted keys according to different application scenarios and computing resource conditions; based on a dynamic adjustment mechanism of security situation awareness, the key generation strategy can adapt to changes in application scenarios in real time. Whether in resource-constrained mobile devices and IoT terminals, or in financial transaction systems and military communications fields with extremely high security requirements, it can ensure the validity and adaptability of keys, greatly expanding the application scope of this technology. 3. During the key generation process, parallel computing units and pipelined structures support the parallel generation of multiple segments, which significantly improves the speed and efficiency of key generation. At the same time, the utilization efficiency of computing resources is fully considered. Through reasonable algorithm design and optimization, unnecessary computing steps are reduced, the system burden is lowered, and the technology can run efficiently under various computing resource conditions. Attached Figure Description
[0014] Figure 1 This is a schematic flowchart of a key generation method based on Galois group permutation representation according to the present invention.
[0015] Figure 2 This is a flowchart illustrating the Galois group construction and substitution representation establishment of the present invention.
[0016] Figure 3 This is a flowchart of the initial key fragment generation process of the present invention.
[0017] Figure 4 This is a comparison diagram of key spaces generated by different Galois group types according to the present invention.
[0018] Figure 5 This is a key generation time and security level adaptation diagram of the present invention.
[0019] Figure 6 This is a graph showing the results of the key randomness test of the present invention. Detailed Implementation
[0020] To illustrate in detail the technical solutions adopted by the present invention to achieve the intended technical objectives, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Furthermore, the technical means or technical features in the embodiments of the present invention can be replaced without creative effort. The present invention will be described in detail below with reference to the accompanying drawings and embodiments.
[0021] like Figure 1 As shown, a key generation method based on Galois group permutation representation according to the present invention includes the following steps: S1. Select the base domain and extension domain based on security requirements to construct the domain expansion. Determine the Galois group And establish Galois group elements in extended domain Permutation representation on This provides a stable mathematical structure for subsequent key generation.
[0022] like Figure 2 As shown, in practical applications, it is first necessary to select an appropriate domain extension and determine its Galois group based on the specific security level and application scenario.
[0023] For general business applications, a finite field can be selected. Let be the base field, where For large prime numbers, construct an extended field. Its Galois group is Cyclic group , by Frobenius self-isomorphism generate.
[0024] For fields with extremely high security requirements, such as military and financial sectors, it is necessary to choose a non-commutative Galois group and construct a polynomial. A splitting domain over the rational number field Q has a Galois group that is a cubic symmetric group. It has an order of 6 and possesses the noncommutative property. After selecting a field extension, a permutation representation of the Galois group elements on the extended field is established. This ensures that different group elements correspond to different permutation effects. Specifically, for any and any ,have By rigorously selecting suitable base field features and expansion times, a deterministic method is used to generate large prime numbers. satisfy This ensures that certain polynomials are irreducible, completes the initialization of the Galois group, and lays a solid mathematical foundation for the subsequent key generation process.
[0025] S2. Obtain user identity information and encryption requirement parameters, and select the extended domain. The basic elements in the group, using the Galois group Elements of different orders are applied to the base elements respectively. The elements after the permutation are represented as polynomials over the extended field. The coefficient vectors are extracted and compressed to generate multiple initial key fragments.
[0026] like Figure 3 As shown, the user's identity information can be accurately obtained through system interfaces or user input. Such as username, user ID, etc.; at the same time, collect encryption requirement parameters. This includes encryption strength requirements, encryption algorithm type, and current computing resource status information. Factors such as available memory size and processor speed are considered. The user identity information and encryption requirements are hashed to obtain a hash value. ,in Hash algorithms such as SHA-256 are used.
[0027] Select extended domain A set of basic elements Selecting the original element and its powers. Using Galois groups Elements of different orders Each element is applied to the base element to generate multiple initial key fragments. For the cyclic group case, the group element can be represented as... ,in Its function is The elements after the permutation are expressed in polynomial form over the extended field:
[0028] in For a set of bases of the extended field, For coefficients. Extract the coefficient vector. The coefficient vector is then compressed and mapped to generate a fixed-length binary key fragment.
[0029] in, Convert the field elements to their binary representation. This represents the XOR operation. If the selected Galois group is a cyclic group... The original element is Then by calculation Sixteen different permutation results are obtained, and their coefficients are extracted to generate sixteen key fragments. This step fully utilizes the diversity of Galois group elements, resulting in key fragments with high complexity and randomness.
[0030] S3. A nonlinear fusion algorithm is used to integrate multiple initial key fragments to construct an S-box based on the Galois field. Multiple key fragments are input into the S-box for nonlinear transformation to obtain an intermediate key. A dynamic random factor based on system timestamps, hardware physical noise, or statistical characteristics of network data packet arrival intervals is introduced to perturb the intermediate key to generate the final key.
[0031] A nonlinear fusion algorithm is used to integrate multiple initial key fragments to obtain an intermediate key. First, a Galois field-based key is constructed. An S-box is constructed with an algebraic degree reaching the theoretical maximum of 7, a difference uniformity of 4, and a nonlinearity of 112. The S-box can be constructed as follows: Select... Inverse mapping on (Regulation Then, perform an affine transformation:
[0032] in, for An invertible matrix, It is a constant vector. Multiple key fragments are concatenated into the input vector. The S-box is input sequentially and subjected to nonlinear transformation. The fused intermediate key is then output through the nonlinear transformation of the S-box.
[0033] Optionally, a feedback mechanism can be introduced, using the result of the previous fusion round as the input for the next fusion round, forming an iterative fusion structure:
[0034] To further enhance the mixing and security of the key, a dynamic random factor is then introduced to perturb the intermediate key, generating the final key. Dynamic random factor Based on system timestamps Hardware physical noise Statistical characteristics of network packet arrival intervals One or more of the following are used to generate truly random numbers using an entropy extraction algorithm:
[0035] Perform affine or permutation transformations on the intermediate key:
[0036] in, It is an invertible matrix, ensuring the reversibility and security of the transformation. By comprehensively considering various factors, a final key adapted to the encryption needs of different scenarios is generated.
[0037] S4. Set the threshold for monitoring parameters to monitor changes in encryption requirements and computing resource dynamics in the application scenario in real time. Once the monitoring parameters exceed the preset threshold, immediately start the key regeneration process, automatically adjust the number of domain expansions, change the base domain characteristics, or switch the Galois group type, and re-execute steps S1-S3 to generate a new key adapted to the current environment.
[0038] Set thresholds for monitoring parameters, including thresholds for changes in encryption strength and changes in computing resources.
[0039] Define the network traffic mutation index , set when Triggered at time; Attack detection alert level Set to levels 1-5, when Triggered at time; System load rate , set when Triggered at time.
[0040] Leveraging a key adaptation mechanism, the system monitors real-time changes in encryption requirements and computing resource dynamics across application scenarios. System performance monitoring tools are used to obtain real-time information such as encryption algorithm upgrade needs, available system memory, and network attack alerts. The monitoring module employs efficient data acquisition and processing algorithms to ensure the accuracy and timeliness of the monitored data. When monitored parameters exceed or fall below preset thresholds, a key regeneration process is triggered, automatically adjusting the domain expansion parameters and Galois group type.
[0041] The adjustment strategy can be expressed as:
[0042] This involves increasing the number of expansions, changing the base domain characteristics, and switching to a non-commutative Galois group. Subsequently, user identity information, encryption requirement parameters, and computational resource status information are re-acquired, and the adapted key is regenerated following the steps outlined above. During key regeneration, previous computation results and optimization strategies are fully utilized, such as caching some intermediate results. This improves generation efficiency, reduces the impact on system performance, ensures that the key is always compatible with the current environment, and safeguards information security.
[0043] A key generation system for performing a key generation method based on Galois group permutation representation, comprising: The parameter collection module is used to collect user identity information, encryption requirement parameters, and computing resource status data; The Galois group construction module constructs a domain extension and determines its Galois group based on the application scenario and security requirements, and establishes a permutation representation of Galois group elements. The key generation module selects the basic elements in the extended field, generates multiple initial key fragments by using the permutation of the Galois group elements, integrates the multiple initial key fragments using a nonlinear fusion algorithm to obtain the intermediate key, and introduces a dynamic random factor to generate the final key. The key adaptation monitoring module sets monitoring parameter thresholds to monitor changes in encryption requirements and computing resource dynamics in application scenarios in real time. When the monitoring parameters exceed the preset threshold, the key generation module is triggered to regenerate the key and automatically adjust the domain expansion parameters and Galois group type.
[0044] This invention proposes a key generation method based on Galois group permutation representation. By leveraging the complexity of the group structure, the key space can be maximized. The scale is far greater than that of traditional methods. The scale of the attack effectively resists brute-force attacks; furthermore, by combining non-commutative algebraic structures with nonlinear fusion techniques, it can resist various attack methods such as linear cryptanalysis, differential cryptanalysis, and algebraic attacks, greatly improving the security of information systems. Figure 4 A comparison diagram of key spaces generated by different Galois group types is shown. Figure 6 The results of the key randomness test are shown in the image.
[0045] This invention, through a unique key adaptation mechanism, can flexibly generate adapted keys according to different application scenarios and computing resource conditions; based on a dynamic control mechanism of security situation awareness, the key generation strategy can adapt to changes in application scenarios in real time. Whether in resource-constrained mobile devices and IoT terminals, or in financial transaction systems and military communications fields with extremely high security requirements, it can ensure the validity and adaptability of keys, greatly expanding the application scope of this technology. In the key generation process, this invention supports the parallel generation of multiple segments through parallel computing units and pipeline structure, which significantly improves the speed and efficiency of key generation. At the same time, it fully considers the utilization efficiency of computing resources, reduces unnecessary computing steps and lowers the system burden through reasonable algorithm design and optimization, so that the technology can run efficiently under various computing resource conditions. Figure 5 A graph showing the adaptation between key generation time and security level is displayed.
[0046] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent substitutions, and improvements made to the above embodiments without departing from the scope of the present invention, based on the technical essence of the present invention and within the spirit and principles of the present invention, shall still fall within the protection scope of the present invention.
Claims
1. A key generation method based on Galois group permutation representation, characterized in that... Includes the following steps: S1. Select the base domain and extension domain based on security requirements to construct the domain expansion. Determine the Galois group And establish Galois group elements in extended domain Permutation representation on ; S2. Obtain user identity information and encryption requirement parameters, and select the extended domain. The basic elements in the group, using the Galois group Elements of different orders are applied to the base elements respectively. The elements after the permutation are represented as polynomials over the extended field. The coefficient vectors are extracted and compressed and mapped to generate multiple initial key fragments. S3. A nonlinear fusion algorithm is used to integrate multiple initial key fragments to construct an S-box based on the Galois field. Multiple key fragments are input into the S-box for nonlinear transformation to obtain an intermediate key. A dynamic random factor based on system timestamps, hardware physical noise, or statistical characteristics of network data packet arrival intervals is introduced to perturb the intermediate key and generate the final key. S4. Set the threshold for monitoring parameters to monitor changes in encryption requirements and computing resource dynamics in the application scenario in real time. Once the monitoring parameters exceed the preset threshold, immediately start the key regeneration process, automatically adjust the number of domain expansions, change the base domain characteristics, or switch the Galois group type, and re-execute steps S1-S3 to generate a new key adapted to the current environment.
2. The key generation method based on Galois group permutation representation according to claim 1, characterized in that: In step S1, an appropriate domain expansion is selected based on the security level and application scenario; for general commercial applications, a limited domain is selected. As a base domain construction extension Its Galois group is a cyclic group. For military and financial fields, non-commutative Galois groups are chosen, such as by constructing polynomials. A splitting domain over a rational number field has a Galois group that is a cubic symmetric group. .
3. The key generation method based on Galois group permutation representation according to claim 1, characterized in that: In step S2, the elements after the permutation are represented as polynomials over the extended field. Extracting the coefficient vector And perform compression mapping on the coefficient vector. Generate a fixed-length binary key fragment, where Convert the field elements to their binary representation. This represents the XOR operation.
4. The key generation method based on Galois group permutation representation according to claim 1, characterized in that: In step S3, a Galois domain-based construction is performed. S box ,in for An invertible matrix, The key is a constant vector. Multiple key fragments are concatenated and then input into an S-box for nonlinear transformation to obtain the intermediate key. Dynamic random factors are generated through an entropy extraction algorithm. Perform an affine transformation on the intermediate key. ,in Given an invertible matrix, the final key is obtained.
5. The key generation method based on Galois group permutation representation according to claim 1, characterized in that: In step S4, the threshold values for the monitored parameters include Network Traffic Sudden Change Index , set when Triggered at time; Attack detection alert level Set to levels 1-5, when Triggered at time; System load rate , set when Triggered at time; The adjustment strategy is expressed as .
6. A key generation system for performing the key generation method based on Galois group permutation representation as described in any one of claims 1-5, characterized in that: Include The parameter collection module is used to collect user identity information, encryption requirement parameters, and computing resource status data; The Galois group construction module constructs a domain extension and determines its Galois group based on the application scenario and security requirements, and establishes a permutation representation of Galois group elements. The key generation module selects the basic elements in the extended field, generates multiple initial key fragments by using the permutation of the Galois group elements, integrates the multiple initial key fragments using a nonlinear fusion algorithm to obtain the intermediate key, and introduces a dynamic random factor to generate the final key. The key adaptation monitoring module sets monitoring parameter thresholds to monitor changes in encryption requirements and computing resource dynamics in application scenarios in real time. When the monitoring parameters exceed the preset threshold, the key generation module is triggered to regenerate the key and automatically adjust the domain expansion parameters and Galois group type.