Hybrid authentication handshake method fusing anti-quantum algorithm and national cryptographic protocol
By using structured labeling and chained numbering rules for key fragment numbering, source, and handshake phase, the problem of inaccurate key fragment source and numbering identification in existing technologies is solved, and the stability of the hybrid authentication handshake method and the consistency of protocol execution are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGXI POWER GRID CORP
- Filing Date
- 2026-04-14
- Publication Date
- 2026-06-23
AI Technical Summary
The existing hybrid authentication handshake method that integrates quantum-resistant algorithms and national cryptographic protocols lacks precise identification of the source and number of key fragments, making it difficult to coordinate location management requirements. The structure lacks a unified labeling system and a complete path mapping mechanism, which affects the consistency of protocol execution and the stability of data delivery.
By structurally labeling the key fragment output with its number, source, and handshake phase, and combining the position field with the advance data, the key information is bound to the writing path. A chained numbering rule and position swapping are introduced to ensure the adjustability of fragment distribution. In the writing process, continuous number verification and data block shifting operations are introduced to coordinate the parallel insertion of national cryptographic and quantum-resistant content.
The hybrid authentication handshake method improves the structural scheduling flexibility, enhances the structural consistency and data integrity of session frames in the execution path, avoids numbering conflicts and position overlaps, and ensures the stability of data delivery and the coherent execution of the protocol.
Smart Images

Figure CN122268651A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum-resistant computing technology, and in particular to a hybrid authentication handshake method that integrates quantum-resistant algorithms and national cryptographic protocols. Background Technology
[0002] The field of quantum-resistant computing technology involves the design of novel encryption algorithms and communication protocols to address the threat posed by quantum computing to the security of existing cryptographic systems. Core aspects include quantum-resistant public-key algorithms, key exchange mechanisms, and their integration and deployment in communication systems. This aims to replace traditional cryptographic systems that rely on large number factorization and discrete logarithm problems, ensuring information security in a quantum environment. Currently, efforts are being made to actively explore its integration with the national cryptographic system.
[0003] The traditional hybrid authentication handshake method, which integrates quantum-resistant algorithms and national cryptographic protocols, combines quantum-resistant key negotiation algorithms with encryption authentication algorithms in national commercial cryptography standards to construct a handshake mechanism for identity authentication and key negotiation between clients and servers. A common approach is to encrypt identity information using national cryptographic algorithms such as SM2, then introduce algorithms like lattice bases to complete quantum-resistant key exchange, or generate a session key by concatenating or hashing the results of the two algorithms, thereby constructing a hybrid authentication system with quantum resistance capabilities.
[0004] Existing solutions lack precise identification of key fragment sources and numbers, making it difficult to handle position management requirements in multi-path inputs and prone to order misalignment during writing. The lack of a unified labeling system in the structure makes it difficult to coordinate fragment insertion positions, and there is a lack of a complete path mapping mechanism. There is no chained numbering logic for fragment conflict handling, making it impossible to automatically complete numbering and data block rearrangement. The lack of parallel insertion control within the handshake execution area means it lacks the ability to synchronously adjust intra-frame fields, affecting the consistency of protocol execution and the stability of data delivery. Summary of the Invention
[0005] To address the technical problems existing in the prior art, embodiments of the present invention provide a hybrid authentication handshake method that integrates quantum-resistant algorithms and national cryptographic protocols. The technical solution is as follows: A hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols includes the following steps: S1: Obtain the key fragments of the national cryptographic and anti-quantum paths, extract the output number, source category and handshake stage, read the fragment position and handshake progress data, attach the source and number to the key data in the writing order, form an insertion description format and write it into the handshake structure to obtain the heterogeneous key handshake injection description content. S2: Call the source field of the heterogeneous key handshake injection description content, compare the positions of continuous stage segments, select segments with the same source and the same scenario, process the writing chain number, expand into the handshake flow format, and obtain the key injection arrangement recognition content. S3: Call the number of the key injection arrangement identification content, extract the Chinese cryptographic and anti-quantum fragments of the handshake structure, read and write the start position and the current position, swap the fragment positions in the structure, move the frame structure field, and write the update after swapping to obtain the hybrid handshake key injection order arrangement content; S4: Call the field of the hybrid handshake key injection sequence arrangement content, insert the fragment into the handshake frame content area, read the number field, check for conflicts or gaps, shift the data block and write it into the channel according to the consecutive numbers, and advance the structure state after writing to obtain the hybrid key carrying session structure. S5: Call the data segment and number field in the hybrid key carrying session structure, execute the handshake path writing step, insert the national cryptographic and anti-quantum content into the handshake area, call the handshake identifier field of the current stage to complete the channel writing, update the handshake frame to the buffer queue and push it into the execution flow to obtain the hybrid authentication handshake structure.
[0006] As a further aspect of the present invention, the heterogeneous key handshake injection description includes output number mapping, source type identifier, handshake phase marker, write position parameter, and progress status information; the key injection arrangement identification includes source matching result, fragment arrangement order, scene consistency label, and write link number; the hybrid handshake key injection order arrangement includes position swap identifier, field synchronization parameter, structure update index, and intra-frame mapping relationship; the hybrid key-bearing session structure includes channel write number, data block arrangement structure, number integrity marker, and status progress identifier; and the hybrid authentication handshake structure includes path write parameter, national cryptographic and quantum-resistant data unit, channel buffer configuration, and execution inflow label.
[0007] As a further aspect of the present invention, the step of obtaining the heterogeneous key handshake injection description content is as follows: S101: Obtain the key fragments output by the national cryptographic path and the quantum-resistant path, extract the corresponding output number, source category and handshake stage data, process them in the order of the fragments, extract the number and source fields, and associate them with the corresponding stage identifiers to form a data reference item that can be used for subsequent attachment operations, and obtain the number source association content. S102: Call the source associated content of the number, read the output position and handshake progress data of each key segment in the handshake structure, append the number and source information to the tail of the corresponding key segment in the writing order, and locate the corresponding offset link in the structure in combination with the progress stage of the segment to obtain the key segment sequence after the number is attached. S103: Call the key fragment sequence with the attached number, write the fragment with attached information into the target position in the handshake structure according to the insertion position of each fragment, and process all key contents item by item in the order of advancement to complete all injection actions in the structure and obtain the heterogeneous key handshake injection description content.
[0008] As a further aspect of the present invention, the step of obtaining the key injection permutation recognition content is as follows: S201: Call the source field in the heterogeneous key handshake injection description to obtain the handshake stage information and insertion position content corresponding to each key segment. After arranging the segments in the stage order, compare the source fields pairwise to filter out the set of segments with the same source in adjacent stages and obtain the source-consistent segment sequence. S202: Based on the source consistent segment sequence, compare the position fields corresponding to each key segment in the continuous stage, extract the part whose position content has not changed, output them in the order of position index, count the number of times each segment appears in the continuous stage, and mark the number according to the handshake progress order to obtain the continuous handshake segment number content. S203: Call the numbered content of the continuous handshake segment, link the key segments corresponding to the number sequence, embed the writing order between each segment into the structure in a progressive numbering manner, complete the position progression path, expand the sequential data in the corresponding link according to the segment number order, and obtain the key injection arrangement identification content.
[0009] As a further aspect of the present invention, the step of obtaining the hybrid handshake key injection sequence arrangement content is as follows: S301: Call the numbered data content in the key injection arrangement identification content, extract the national cryptographic fragment and anti-quantum fragment at the corresponding number position in the handshake structure, obtain the start position and current allocation position of each fragment in the writing structure, group them according to the source field, pair the start position and current allocation position of the writing under the source distinction and output them to obtain the key source position pairing data. S302: Based on the key source location pairing data, the writing positions of the corresponding national cryptographic fragments and anti-quantum fragments in the structure are swapped according to the numbering order, the starting position labeling information of the writing area is changed accordingly, and the numbering field in the fragment remains unchanged. The index order of all the fragments whose positions have been swapped is confirmed, and the position swap structure mapping content is obtained. S303: Call the location exchange structure mapping content, read the exchanged fragment structure information in sequence, write the key fragments with changed positions into the target nodes in the handshake structure in order, and move the target field position in the frame structure to process it synchronously with the adjusted content to complete the overall structure replacement operation and obtain the hybrid handshake key injection order arrangement content.
[0010] As a further aspect of the present invention, the step of obtaining the hybrid key bearer session structure is as follows: S401: Call the write field in the hybrid handshake key injection sequence arrangement content, insert the corresponding key fragments into the content area of the handshake frame in numerical order, extract the write number field and frame position pointing data corresponding to the currently inserted fragment, associate the current fragment position according to the insertion order, and obtain the key fragment insertion index set; S402: Based on the key fragment insertion index set, compare the written number field item by item to identify whether there are duplicate numbers or missing numbers. If the number is found to be discontinuous or duplicate, move the fragment positions in the current chain in ascending order of the index to cover the abnormal positions and repair the number sequence to obtain the number order correction content. S403: Call the numbering order correction content, redistribute the adjusted key fragments to the writing channel, advance the overall arrangement of data in the channel according to the order, update the handshake structure status field item by item, and record the current frame status number after confirming that all fragments have been written, and obtain the hybrid key carrying session structure.
[0011] As a further aspect of the present invention, the step of obtaining the hybrid authentication handshake structure is as follows: S501: Call the data segment field and corresponding number field in the hybrid key bearer session structure, insert the national cryptographic content and anti-quantum content into the execution area in the handshake path in numerical order, extract the corresponding position and write offset of each segment, complete the write process in the insertion order, and obtain the execution area write position sequence. S502: According to the execution area write position sequence, call the identifier field of the current handshake stage, mark the channel status corresponding to the current stage, compare the written data segment number with the channel identifier one by one, and after confirming that the number covers the complete range, write the status identifier to the channel status mark to obtain the stage channel completion identifier content. S503: Call the stage channel to complete the identification content, push the current handshake frame to the end of the channel buffer queue, write the frame content in the order of the number and bind the corresponding writing node, and after all the content is synchronized to the queue, push the current frame to the head of the execution flow queue to obtain the hybrid authentication handshake structure.
[0012] The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following: In this invention, the key fragment output is structurally labeled with its number, source, and handshake phase. Combined with position fields and advance data, the key information is bound to the writing path. Source comparison and scenario filtering introduce a chain-like numbering rule to construct the sequence control logic between fragments. Position swapping and field synchronization make the fragment distribution within the structure adjustable, improving the flexibility of structure scheduling. During the writing process, continuous number verification and data block shifting operations are introduced to avoid numbering conflicts and position overlaps. The channel writing phase, combined with handshake identifier advancement, coordinates the parallel insertion of national cryptographic and quantum-resistant content, enhancing the structural consistency and data integrity of session frames in the execution path. Attached Figure Description
[0013] Figure 1 This is a flowchart of the method of the present invention; Figure 2 A flowchart illustrating the process of obtaining the description content for heterogeneous key handshake injection in this invention; Figure 3 A flowchart illustrating the process of obtaining the key injection permutation recognition content in this invention; Figure 4 This is a flowchart illustrating the process of obtaining the hybrid handshake key injection sequence arrangement content of the present invention. Figure 5 This is a flowchart illustrating the process of obtaining the hybrid key-bearing session structure of the present invention. Figure 6 This is a flowchart illustrating the process of obtaining the hybrid authentication handshake structure of the present invention. Detailed Implementation
[0014] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0015] refer to Figures 1 to 6 The hybrid authentication handshake method, which integrates quantum-resistant algorithms and national cryptographic protocols, includes the following steps: S1: Obtain the key fragments output by the national cryptographic path and the quantum-resistant path, extract the output number, source category and handshake stage of each fragment, read the fragment output position and handshake progress data, attach the number and source to the key data in the order of writing, form a description format for subsequent insertion, and write it into the current handshake structure to obtain the heterogeneous key handshake injection description content. S2: Call the source field already included in the heterogeneous key handshake injection description content, compare the fragment position field that appears in the continuous handshake stage item by item, pick out the key fragments with the same source and the same occurrence scenario, number the writing chain of these key fragments in the structure, expand it into the flow format in the handshake process, and obtain the key injection arrangement recognition content. S3: Call the numbered content in the key injection arrangement identification content, extract the national cryptographic fragments and anti-quantum fragments involved in the handshake structure, read the start position and current allocation position of the writing area, swap the positions of the fragments in the writing structure, and synchronously move the target field position in the frame structure. After completing the position swap, write the updated data into the handshake structure to obtain the hybrid handshake key injection order arrangement content. S4: Call the write field in the sequence arrangement content of the hybrid handshake key injection, insert the fragment into the content area of the handshake frame, read the write number field, check if there is a number conflict or gap, shift the data block in the current chain and write it into the channel according to the consecutive number, and after completing the data writing action, advance to the next structural state to obtain the hybrid key carrying session structure. S5: Call the data segment and corresponding number field in the hybrid key carrying session structure, execute the write step in the handshake path, insert the national cryptographic and anti-quantum content into the handshake execution area, call the handshake identifier field of the current stage to perform channel completion operation, and update the current handshake frame to the channel buffer queue. After the write is completed, push it into the execution flow to obtain the hybrid authentication handshake structure.
[0016] The heterogeneous key handshake injection description includes output number mapping, source type identifier, handshake phase marker, write position parameter, and progress status information. The key injection arrangement identification includes source matching result, fragment arrangement order, scenario consistency label, and write link number. The hybrid handshake key injection order arrangement includes position swap identifier, field synchronization parameter, structure update index, and intra-frame mapping relationship. The hybrid key carrying session structure includes channel write number, data block arrangement structure, number integrity marker, and status progress identifier. The hybrid authentication handshake structure includes path write parameter, national cryptographic and quantum-resistant data unit, channel buffer configuration, and execution inflow label.
[0017] Please see Figure 2 The steps to obtain the description content of heterogeneous key handshake injection are as follows: S101: Obtain the key fragments output by the national cryptographic path and the quantum-resistant path, extract the corresponding output number, source category and handshake stage data, process them in the order of the fragments, extract the number and source fields, and associate them with the corresponding stage identifiers to form a data reference item that can be used for subsequent attachment operations, and obtain the number source association content. During the initialization phase of heterogeneous key handshake injection, a high-speed data transmission interface is established with the national cryptographic SM2 / SM4 encryption module and the quantum-resistant Kyber / Dilithium encryption module. The scanning frequency of the output buffer of each module is set to one-quarter of the system bus clock frequency, i.e., a fixed scanning frequency of 500MHz when the bus frequency is 2GHz. Buffer data is read through a fixed-period polling method. The system reads the generated SM2 elliptic curve public key fragment and SM4 symmetric session key fragment from the national cryptographic path port, and simultaneously reads the Kyber-768 encapsulated ciphertext fragment and Dilithium-3 signature fragment from the quantum-resistant path port. During the reading process, the key type is identified according to the protocol field in the data packet header to extract the metadata of each data segment, including the output number with a starting value of 0x00000001, the category identifiers representing the national cryptographic and quantum-resistant sources respectively, and handshake phase data such as 0xA1 representing the ClientHello phase. The system establishes a temporary stack, pushes the captured key fragments onto it in timestamp order, and performs binary stream parsing when popped from the processing unit. It extracts the output number and converts its format, filters high-order noise in the source category field using bitmasking, and simultaneously compares the extracted handshake phase data with the phase identifiers in the standard protocol flowchart by calling the current state register value of the handshake protocol state machine. Upon successful comparison, the system creates a structure object in memory containing the number value, source type, and current phase identifier. For example, for the first SM2 fragment, it generates an association item containing a specific number and phase identifier, and iterates through all fragments to be processed in the buffer to generate a corresponding list of association items as the data reference for subsequent attachment operations. This list is stored in a specific address range in the cache, thus obtaining the number source association content.
[0018] S102: Call the associated content of the number source, read the output position and handshake progress data of each key segment in the handshake structure, append the number and source information to the end of the corresponding key segment according to the writing order, and locate the corresponding offset link in the structure in combination with the progress stage of the segment to obtain the key segment sequence after the number is attached. The system invokes the source association information stored in the cache and initiates the metadata encapsulation process for the original key fragment. It accesses the handshake structure definition file to read the memory layout information of the current handshake protocol frame, including the starting address of the reserved buffer for each handshake stage and the standard length of each key fragment. An offset accumulator with an initial value of the data segment start address is set, and the corresponding handshake advancement data is read for each key fragment in the sequence. Based on the writing order, the system converts the generated number and source information into a fixed-length binary suffix. For example, a 4-byte number and a 1-byte source information are concatenated to the end of the original key fragment, making the original 32-byte fragment 37 bytes. Combining this with the advancement stage information of the fragment, the system calculates its specific physical address within the handshake structure by retrieving the base offset and accumulating the total length of the preceding fragments. During this process, the system accurately determines the target write start address of each segment in the handshake frame structure according to the linear accumulation rule. For example, for the ClientHello stage with a base address of 0x2000, the first segment is located at 0x2000, and the second segment following it is located at 0x2025. The system writes these calculated address parameters into the segment header to form a new data packet format containing the address, payload, and suffix, thereby obtaining the key segment sequence after the number is attached.
[0019] S103: Call the key fragment sequence with the attached number, write the fragment with attached information into the target position in the handshake structure according to the insertion position of each fragment, and process all key contents item by item in the order of advancement to complete all injection actions in the structure and obtain the heterogeneous key handshake injection description content.
[0020] The system invokes the sequence of key fragments with attached numbers, reads the header address information of the fragments in the sequence, sets the target address register to the pre-calculated offset address, and simultaneously sets the source address register to the start bit of the data payload of the current fragment. After the system initiates the transmission command, the controller copies the binary stream of the fragments with attached information byte by byte to the target location in the handshake structure buffer. After completing the writing of the first fragment, the controller automatically increments the pointer to the next fragment in the sequence based on the handshake progress data, and the write counter maintained internally by the system increases accordingly. The system monitors the status of the handshake structure memory area in real time, processes all key content item by item in ascending order of number, and performs post-write verification based on the XOR comparison of the first and last bytes for each write operation until the value of the write counter equals the total number of fragments in the sequence, at which point it sends an injection completion signal to the bus. At this point, the reserved blank area in the handshake structure has been filled with specific national cryptographic and quantum-resistant key data, and each data block carries a number and source tag for subsequent traceability. This complete memory image reflecting the coexistence state of heterogeneous keys in physical memory is the heterogeneous key handshake injection description content.
[0021] Please see Figure 3The steps for obtaining the key injection permutation recognition content are as follows: S201: Call the source field in the heterogeneous key handshake injection description to obtain the handshake stage information and insertion position content corresponding to each key fragment. After arranging the fragments in the stage order, compare the source fields pairwise to filter out the fragment set with consistent source in adjacent stages and obtain the sequence of fragments with consistent source. The system accesses the memory region containing the heterogeneous key handshake injection description, reads the additional information field at the end of each data block, extracts the source field, handshake stage information, and insertion position of all fragments, and constructs a temporary index table in the local register for initial sorting by handshake stage value. The system then initiates a sliding window algorithm to compare the source fields pairwise, determining whether fragments in adjacent handshake stages have the same source. If two fragments in adjacent stages are both from national cryptographic standards or both from quantum-resistant sources, the pair is determined to be cross-stage homogeneous continuous and extracted into a set queue. Through full sequence traversal filtering, the system removes noise data where heterogeneous algorithms alternate, retaining only the continuous transmission characteristics of homogeneous algorithms on the time axis. For example, fragment pairs from both national cryptographic standards in stages 1 and 2 are included in the set. The resulting data set recording the dominant algorithm in consecutive stages is the source-consistent fragment sequence.
[0022] S202: Based on the consistent fragment sequence, compare the corresponding position fields of each key fragment in the continuous stage, extract the parts whose position content has not changed, output them in the order of position index, count the number of times each fragment appears in the continuous stage, and mark the number according to the handshake progress order to obtain the continuous handshake segment number content. Based on a consistent fragment sequence, the system deeply analyzes the positional stability of fragments in consecutive stages. It extracts the insertion position field and relative index of each pair of consecutive fragments, determining whether the relative index value of the subsequent fragment in the subsequent stage is equal to the relative index value of the previous fragment in the previous stage. This confirms whether the key occupies the same logical slot in the handshake messages at different stages. The system traverses the sequence to maintain a repetition counter, counting fragments that satisfy the positional invariance condition. After the count, it assigns a unique segment number to these consecutive and positionally stable fragment segments according to the handshake progression order. This number is composed of a cardinality, the starting stage value, and a serial number; for example, it generates a segment number of 1101. The system marks the segment number in the corresponding fragment metadata and writes the counted repetition count as a weight value, outputting structured data containing the segment number, start and end indices, and repetition count, thus obtaining the consecutive handshake segment number content.
[0023] S203: Call the content of the continuous handshake segment number, link the key segments corresponding to the number sequence, embed the writing order between each segment into the structure in the manner of advancing the number, complete the position advancement path, expand the sequential data in the corresponding link according to the segment number order, and obtain the key injection arrangement recognition content.
[0024] The process involves calling the sequential handshake segment number content to perform position linking and path completion operations, creating a doubly linked list structure to map the logical flow in the handshake structure, reading the physical positions of the start and end segments corresponding to each segment number, and establishing internal pointers between segments within the same segment to physically link the same-origin, same-position key segments scattered across different handshake stages. The beginning and end of each independent segment are logically connected in numerical order of their segment numbers, and the time gap between segments is calculated. If there are discrete segments in the gap that are not covered by numbers, they are inserted into the corresponding empty node in the linked list in their original order and assigned a temporary transition number. The complete linked list is traversed, and the sequence data corresponding to each node is extracted in segment number order. The absolute execution sequence number of this segment in the entire handshake process is written into the index area of the handshake structure header, forming a complete execution sequence list containing physical pointer links and logical execution sequence numbers, which is the key injection arrangement identification content.
[0025] Please see Figure 4 The steps for obtaining the hybrid handshake key injection sequence arrangement content are as follows: S301: Call the numbered data content in the key injection arrangement identification content, extract the national cryptographic fragment and anti-quantum fragment at the corresponding number position in the handshake structure, obtain the start position and current allocation position of each fragment in the writing structure, group them according to the source field, pair the start position and current allocation position of the writing under the source distinction and output them to obtain the key source position pairing data. The key injection permutation identification process performs resource allocation calculations for hybrid handshake scenarios, locking specific numbered positions in the handshake structure to identify the national cryptographic and anti-quantum fragments that should be accommodated at that position. It also reads the currently allocated physical memory address and the logical write start bit of the memory block to which these fragments belong when they are written. The system establishes a classifier to group the fragment data based on the source field, extracts the corresponding start bit and current position for each group, and performs a pairing operation to bind the national cryptographic fragment position data and the anti-quantum fragment position data under the same logical slot. For example, in the 5th slot of the handshake frame, the system identifies that the start bit of both the pre-allocated SM and PQC fragments is 0x4000, but the PQC fragment is currently allocated at 0x4040 due to a later write. The system integrates this position information to generate a pairing data item containing the slot index and the specific address coordinates of both. The set output after performing this logic on all slots within the handshake structure is the key source position pairing data.
[0026] S302: Based on the key source location pairing data, swap the writing positions of the corresponding national cryptographic fragments and anti-quantum fragments in the structure according to the number order, change the starting position labeling information of the writing area accordingly, and keep the number field in the fragment unchanged, confirm the index order of all the fragments with swapped positions, and obtain the position swap structure mapping content. Based on the key source location pairing data, a physical position swap calculation is performed to meet the high-address priority requirement of the hybrid handshake protocol against quantum algorithms. The paired data items are traversed and their write positions compared. If an anti-quantum fragment is found to be located at a high address and both share the same logical slot, the position swap logic is triggered. The system calculates the new starting position after the swap, adjusts the target address of the anti-quantum fragment to the low address start bit 0x4000 of that slot, and simultaneously adjusts the target address of the national cryptographic fragment to the high address 0x4080 after the anti-quantum fragment. The starting position annotation information of the write area is updated synchronously, but the fragment number field remains unchanged. The system also performs boundary checks to confirm that the rearranged address spacing meets the security threshold and that the overall slot space is sufficient to accommodate the sum of the two. For example, if the address difference of 128 bytes after the swap is confirmed to be greater than the security spacing and the total space meets the requirements, the system confirms the index order of all swapped fragments and obtains the position swap structure mapping content.
[0027] S303: Call the position exchange structure mapping content, read the exchanged fragment structure information in sequence, write the key fragments with changed positions into the target nodes in the handshake structure in order, and move the target field position in the frame structure to process it synchronously with the adjusted content, complete the overall structure replacement operation, and obtain the hybrid handshake key injection order arrangement content.
[0028] The system invokes the location swap structure mapping to perform actual memory movement and pointer update operations. A temporary swap buffer equal in size to the maximum key fragment length is allocated, and each swap pair in the mapping is read sequentially. The system reads the original national cryptographic data into buffer area A, and the original quantum-resistant data into buffer area B. The quantum-resistant data in buffer area B is written to the swapped lower address target location, and the national cryptographic data in buffer area A is written to the swapped higher address target location. Simultaneously, the system updates the target field position pointer in the handshake frame structure, modifies the payload pointer field in the frame header definition to point to the new address layout, and recalculates the padding length field to ensure that the data structure in memory fully conforms to the order defined by the hybrid handshake protocol, thus obtaining the hybrid handshake key injection order arrangement.
[0029] Please see Figure 5 The steps for obtaining the hybrid key-bearing session structure are as follows: S401: Call the write field in the hybrid handshake key injection sequence arrangement content, insert the corresponding key fragments into the content area of the handshake frame in numerical order, extract the write number field corresponding to the currently inserted fragment and the data pointing to the position in the frame, associate the current fragment position according to the insertion order, and obtain the key fragment insertion index set; The system processes the sequence arrangement of the hybrid handshake key injection, loading it into the payload area of the session handshake frame. Key fragments are read in numerical order and inserted into the predefined content area of the handshake frame. For each inserted fragment, the system immediately extracts the current write number field and its byte offset relative to the frame header. The system constructs a dynamic array-based key fragment insertion index set, recording tuple records containing the insertion sequence number, write number, and intra-frame offset in the order of insertion time. For example, it records the number 101 and offset 0x0010 corresponding to the first insertion operation. A log of the insertion operations is established for subsequent auditing and verification, thereby obtaining the key fragment insertion index set.
[0030] S402: Based on the key fragment insertion index set, compare the written number field item by item to identify whether there are duplicate numbers or missing numbers. If the number is found to be discontinuous or duplicate, move the fragment positions in the current chain in ascending order of the index to cover the abnormal positions and repair the number sequence to obtain the number order correction content. Based on the key fragment insertion index set, an integrity verification and repair mechanism is initiated. The write number field of all records is extracted to form an integer sequence, and the difference between adjacent numbers is checked. If the difference is zero, it is determined to be a duplicate number; if the difference is greater than one, it is determined to be a numbering gap. Once an anomaly is detected, the system initiates repair logic. For numbering gaps, the number of missing spaces is calculated, and memory shift instructions are invoked to move the positions of all subsequent fragments within the frame forward by the corresponding units to make physical space. Simultaneously, the fragment position indices in the current chain are rearranged. For example, if 102 is detected to be missing between 101 and 103, a shift operation is performed, and empty padding or renaming is inserted. After covering the abnormal positions and reordering the numbering sequence, the system restores the continuity of the numbering sequence, and the resulting data is the numbering order correction content.
[0031] S403: Call the number order correction content, redistribute the adjusted key fragments to the write channel, advance the overall arrangement of data in the channel according to the order, update the handshake structure status field item by item, record the current frame status number after confirming that all fragments have been written, and obtain the hybrid key carrying session structure.
[0032] The system calls the numbering order correction function to redistribute the adjusted key fragments to the write channels mapped to the network transmit buffer. It then advances the overall arrangement of data within the channel according to the order, updating the handshake structure status field item by item. When writing each fragment, the system sets specific bits in the status register based on the fragment type, such as setting mask bits for national cryptographic or quantum-resistant types. After confirming that all fragments have been written, the system records the cyclic redundancy check (CRC) code and status number of the current frame. The resulting structure, containing the complete key payload, correctly ordered data, and synchronized status bit updates, constitutes the hybrid key-bearing session structure.
[0033] Please see Figure 6 The steps to obtain the hybrid authentication handshake structure are as follows: S501: Call the data segment field and corresponding number field in the hybrid key bearer session structure, insert the national cryptographic content and anti-quantum content into the execution area in the handshake path in numerical order, extract the corresponding position and write offset of each segment, complete the write processing in the insertion order, and obtain the execution area write position sequence. The system invokes the data segment field and corresponding number field in the hybrid key carrying session structure to initiate a direct memory access write process for the handshake path execution region. This execution region is configured as a direct memory access ring buffer mapped to the network interface controller. Write permissions for the current buffer are locked to prevent multi-threaded concurrent conflicts. National cryptographic content and quantum-resistant content are extracted sequentially in ascending order of their numbers. During the write process, the absolute physical address of each key segment in the ring buffer is captured in real time using a 64-bit address bus. For example, if the first national cryptographic segment is detected being written to the starting position with a physical base address of 0xE0001000, and the subsequent quantum-resistant segment is written to position 0xE0001040, the system immediately executes the address offset calculation logic. By subtracting the fixed starting base address of the execution region from the captured absolute physical address, the precise write offset is obtained. The system repeats this process for each written segment, binding the generated offset value with the corresponding segment number and recording them sequentially in the high-speed register array according to the insertion order. A check bit is appended to each offset to ensure the integrity of the address data. These records containing precise physical location information are integrated into a linear array structure to obtain the execution region write position sequence.
[0034] S502: Based on the execution area write position sequence, call the identifier field of the current handshake stage, mark the channel status corresponding to the current stage, compare the written data segment number with the channel identifier one by one, and after confirming that the number covers the complete range, write the status identifier to the channel status mark to obtain the stage channel completion identifier content. Based on the execution region's write position sequence and the identifier field of the current handshake phase, the channel status is calibrated in multiple dimensions. The access channel control block reads the integrity constraint parameters defined in the current protocol phase. These parameters explicitly specify the threshold for the total number of key fragments that must be included in the ClientHello phase and a specific numbering coverage range. The system starts a hardware counter to count the number of valid numbers in the written sequence and compares each written number sequence with the protocol's preset consecutive numbering interval, for example, verifying the existence of a continuous complete sequence from 101 to 104. The system determines that the channel data is complete and ready only if the hardware counter value is strictly equal to the preset threshold and the numbering sequence is complete. It then writes a high-level flag value of 0xFF representing "ready" to a specific bit in the channel status register; otherwise, it writes a low-level flag value of 0x00 representing "waiting" and triggers a wait interrupt. The system packages this rigorously verified status register value with the current phase's channel ID to generate a data block containing a clear indication of the channel's ready status, which is the phase channel completion identifier.
[0035] S503: Call the stage channel to complete the identification content, push the current handshake frame to the end of the channel buffer queue, write the frame content in the order of the number and bind the corresponding write node, and after all the content is synchronized to the queue, push the current frame to the head of the execution flow queue to obtain the hybrid authentication handshake structure.
[0036] The system polls the status of the channel to complete the identification content. Once the status register returns a 0xFF value indicating readiness, the frame push engine is immediately triggered to perform a queue enqueue operation. The system reads the current tail pointer value of the channel buffer queue, writes the completed hybrid key handshake frame into the free memory block pointed to by the tail pointer in burst transmission mode, and calculates the new tail pointer position based on the actual byte length occupied by the frame data. If the calculation result exceeds the queue capacity limit, a wraparound operation is automatically performed to maintain the ring structure. While the data is physically written, the system binds the routing information of the target network node, including the destination IP address and port number, to the queue descriptor and modifies the scheduling weight parameters of the execution flow controller, raising the priority of the current handshake frame to the highest level. This forces the sending scheduler to move the frame to the head of the sending queue to ensure priority processing in the next clock cycle, thereby completing the construction of a data structure containing complete physical payload, routing information, and high-priority scheduling attributes, and obtaining the hybrid authentication handshake structure.
[0037] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A hybrid authentication handshake method fusing an anti-quantum algorithm and a national cryptographic protocol, characterized in that, Includes the following steps: S1: Obtain the key fragments of the national cryptographic and anti-quantum paths, extract the output number, source category and handshake stage, read the fragment position and handshake progress data, attach the source and number to the key data in the writing order, form an insertion description format and write it into the handshake structure to obtain the heterogeneous key handshake injection description content. S2: Call the source field of the heterogeneous key handshake injection description content, compare the positions of continuous stage segments, select segments with the same source and the same scenario, process the writing chain number, expand into the handshake flow format, and obtain the key injection arrangement recognition content. S3: Call the number of the key injection arrangement identification content, extract the Chinese cryptographic and anti-quantum fragments of the handshake structure, read and write the start position and the current position, swap the fragment positions in the structure, move the frame structure field, and write the update after swapping to obtain the hybrid handshake key injection order arrangement content; S4: Call the field of the hybrid handshake key injection sequence arrangement content, insert the fragment into the handshake frame content area, read the number field, check for conflicts or gaps, shift the data block and write it into the channel according to the consecutive numbers, and advance the structure state after writing to obtain the hybrid key carrying session structure.
2. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols as described in claim 1, characterized in that: The heterogeneous key handshake injection description includes output number mapping, source type identifier, handshake phase marker, write position parameter, and progress status information. The key injection arrangement identification includes source matching result, fragment arrangement order, scene consistency label, and write link number. The hybrid handshake key injection order arrangement includes position swap identifier, field synchronization parameter, structure update index, and intra-frame mapping relationship. The hybrid key carrying session structure includes channel write number, data block arrangement structure, number integrity marker, and status progress identifier.
3. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols as described in claim 1, characterized in that: The steps for obtaining the heterogeneous key handshake injection description content are as follows: S101: Obtain the key fragments output by the national cryptographic path and the quantum-resistant path, extract the corresponding output number, source category and handshake stage data, process them in the order of the fragments, extract the number and source fields, and associate them with the corresponding stage identifiers to form a data reference item that can be used for subsequent attachment operations, and obtain the number source association content. S102: Call the source associated content of the number, read the output position and handshake progress data of each key segment in the handshake structure, append the number and source information to the tail of the corresponding key segment in the writing order, and locate the corresponding offset link in the structure in combination with the progress stage of the segment to obtain the key segment sequence after the number is attached. S103: Call the key fragment sequence with the attached number, write the fragment with attached information into the target position in the handshake structure according to the insertion position of each fragment, and process all key contents item by item in the order of advancement to complete all injection actions in the structure and obtain the heterogeneous key handshake injection description content.
4. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols as described in claim 1, characterized in that: The steps for obtaining the key injection permutation recognition content are as follows: S201: Call the source field in the heterogeneous key handshake injection description to obtain the handshake stage information and insertion position content corresponding to each key segment. After arranging the segments in the stage order, compare the source fields pairwise to filter out the set of segments with the same source in adjacent stages and obtain the source-consistent segment sequence. S202: Based on the source consistent segment sequence, compare the position fields corresponding to each key segment in the continuous stage, extract the part whose position content has not changed, output them in the order of position index, count the number of times each segment appears in the continuous stage, and mark the number according to the handshake progress order to obtain the continuous handshake segment number content. S203: Call the numbered content of the continuous handshake segment, link the key segments corresponding to the number sequence, embed the writing order between each segment into the structure in a progressive numbering manner, complete the position progression path, expand the sequential data in the corresponding link according to the segment number order, and obtain the key injection arrangement identification content.
5. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols as described in claim 1, characterized in that: The steps for obtaining the hybrid handshake key injection sequence arrangement content are as follows: S301: Call the numbered data content in the key injection arrangement identification content, extract the national cryptographic fragment and anti-quantum fragment at the corresponding number position in the handshake structure, obtain the start position and current allocation position of each fragment in the writing structure, group them according to the source field, pair the start position and current allocation position of the writing under the source distinction and output them to obtain the key source position pairing data. S302: Based on the key source location pairing data, the writing positions of the corresponding national cryptographic fragments and anti-quantum fragments in the structure are swapped according to the numbering order, the starting position labeling information of the writing area is changed accordingly, and the numbering field in the fragment remains unchanged. The index order of all the fragments whose positions have been swapped is confirmed, and the position swap structure mapping content is obtained. S303: Call the location exchange structure mapping content, read the exchanged fragment structure information in sequence, write the key fragments with changed positions into the target nodes in the handshake structure in order, and move the target field position in the frame structure to process it synchronously with the adjusted content to complete the overall structure replacement operation and obtain the hybrid handshake key injection order arrangement content.
6. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols as described in claim 1, characterized in that: The steps for obtaining the hybrid key bearer session structure are as follows: S401: Call the write field in the hybrid handshake key injection sequence arrangement content, insert the corresponding key fragments into the content area of the handshake frame in numerical order, extract the write number field and frame position pointing data corresponding to the currently inserted fragment, associate the current fragment position according to the insertion order, and obtain the key fragment insertion index set; S402: Based on the key fragment insertion index set, compare the written number field item by item to identify whether there are duplicate numbers or missing numbers. If the number is found to be discontinuous or duplicate, move the fragment positions in the current chain in ascending order of the index to cover the abnormal positions and repair the number sequence to obtain the number order correction content. S403: Call the numbering order correction content, redistribute the adjusted key fragments to the writing channel, advance the overall arrangement of data in the channel according to the order, update the handshake structure status field item by item, and record the current frame status number after confirming that all fragments have been written, and obtain the hybrid key carrying session structure.
7. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols according to claim 1, characterized in that, The method further includes step S5: S5: Call the data segment and number field in the hybrid key bearer session structure, execute the handshake path writing step, insert the national cryptographic and anti-quantum content into the handshake area, call the handshake identifier field of the current stage to complete the channel writing, update the handshake frame to the buffer queue and push it into the execution flow to obtain the hybrid authentication handshake structure; The hybrid authentication handshake structure includes path write parameters, national cryptographic and quantum-resistant data units, channel buffer configuration, and execution inflow tag.
8. The hybrid authentication handshake method integrating quantum-resistant algorithms and national cryptographic protocols according to claim 7, characterized in that: The steps for obtaining the hybrid authentication handshake structure are as follows: S501: Call the data segment field and corresponding number field in the hybrid key bearer session structure, insert the national cryptographic content and anti-quantum content into the execution area in the handshake path in numerical order, extract the corresponding position and write offset of each segment, complete the write process in the insertion order, and obtain the execution area write position sequence. S502: According to the execution area write position sequence, call the identifier field of the current handshake stage, mark the channel status corresponding to the current stage, compare the written data segment number with the channel identifier one by one, and after confirming that the number covers the complete range, write the status identifier to the channel status mark to obtain the stage channel completion identifier content. S503: Call the stage channel to complete the identification content, push the current handshake frame to the end of the channel buffer queue, write the frame content in the order of the number and bind the corresponding writing node, and after all the content is synchronized to the queue, push the current frame to the head of the execution flow queue to obtain the hybrid authentication handshake structure.