A quantum-resistant cryptographic transfer method and system

By introducing concatenated encryption and parallel pipeline architecture into the existing symmetric cryptosystem, the quantum security of the system is improved, solving the problems of key strength halving and high hardware modification costs in the existing technology, and realizing a low-cost, low-risk post-quantum migration scheme.

CN122496201APending Publication Date: 2026-07-31STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST
Filing Date
2026-06-24
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing symmetric cryptosystems suffer from halved key strength when facing quantum computing threats, making them unable to effectively resist quantum search attacks using Grover's algorithm. Furthermore, replacing or modifying existing encryption hardware is costly and has poor compatibility, leading to difficulties in system security and migration.

Method used

Without replacing existing encryption algorithms or hardware, this method improves the quantum-resistant security of symmetric cryptosystems by introducing cascaded encryption and parallel pipeline architecture, using pipelined parallel architecture and cascaded encryption technology, combined with a key rotation mechanism, and achieves data integrity protection through cascaded integrity verification codes, supporting dynamic adjustments to security requirements.

Benefits of technology

It effectively improves the equivalent quantum security strength of symmetric cryptosystems, reduces engineering modification costs and migration risks, achieves smooth system compatibility and gradual upgrades, and is suitable for critical infrastructure scenarios with limited key lengths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122496201A_ABST
    Figure CN122496201A_ABST
Patent Text Reader

Abstract

This invention discloses a quantum-resistant symmetric cryptographic migration method and system, belonging to the field of information security technology. The method includes: determining the number of cascade rounds and the cascade method based on security objectives and hardware performance; dividing the plaintext into blocks, filling them, and assigning unique block IDs; configuring the computing cores according to the cascade method, dynamically or statically allocating working keys to each block, and performing cascade encryption in parallel in a pipeline manner, synchronously completing input, parallel processing, and outputting one ciphertext block every clock cycle; reconstructing the ciphertext, generating a cascaded integrity verification code using the sampled values ​​of the intermediate encryption state, encapsulating it, and sending it; the decryption end reconstructs the key sequence according to the synchronization parameters, performs reverse pipeline decryption with symmetric reverse configuration, and outputs plaintext or triggers an anomaly after comparing the integrity verification code. This invention improves resistance to quantum attacks while maintaining high performance, supporting smooth migration and dynamic runtime optimization, and reducing engineering modification costs and compliance risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and more specifically, relates to a quantum-resistant symmetric cryptographic migration method and system. Background Technology

[0002] With the development of quantum computing technology, quantum attacks, represented by Shor's algorithm and Grover's algorithm, pose an unprecedented security threat to existing cryptographic systems. Grover's search algorithm, in particular, can reduce the complexity of brute-force attacks using symmetric keys from that of classical attacks. Reduced to quantum scenarios ( (This refers to the key length), which means that the widely used 128-bit symmetric key only has an equivalent 64-bit security strength in the post-quantum era, failing to meet the needs of high-security fields such as finance, communications, and critical infrastructure.

[0003] Currently, post-quantum cryptography migration mainly relies on methods such as extending key length and replacing quantum-resistant cryptographic algorithms. However, for symmetric cryptographic infrastructures that have already been deployed on a large scale, such as embedded encryption modules and software cryptographic libraries, the cost of modifying and replacing cryptographic algorithms is high, and they also face risks such as long authentication cycles and system compatibility challenges.

[0004] Prior art document 1 (CN120639299B) discloses a quantum-resistant cryptographic migration method, system, electronic device, and storage medium. Its drawback lies in its reliance on introducing and integrating entirely new, untested quantum-resistant cryptographic algorithms. This introduces a series of complex engineering challenges and costs, including algorithm implementation, integration testing, compliance certification, and the need to initiate rollback mechanisms in case of future security vulnerabilities. It addresses quantum-resistant security issues at the key exchange and management levels, rather than directly enhancing the security of the numerous existing deployed symmetric cryptographic modules. Once a security vulnerability is discovered in the algorithm, a rollback mechanism must be initiated, causing the deployed system to face security failure risks, while also resulting in significant engineering rework costs and business continuity disruptions.

[0005] Prior art document 2 (WO2024253846A1) discloses a high-level synthesis of cloud cryptographic circuits. Its shortcomings lie in the fact that, for post-quantum public-key cryptography algorithms, it requires a complete replacement of the symmetric cryptographic modules already deployed on a large scale in existing systems, resulting in high engineering costs and facing lengthy authentication cycles and compatibility risks. Its design relies on reimplementing dedicated computational modules such as NTT / INTT, failing to directly improve the quantum security of existing symmetric cryptographic systems without modifying the underlying symmetric algorithm. It does not address the fundamental problem of halving key strength in symmetric cryptography under Grover's quantum search algorithm, nor does it provide an agile migration scheme for symmetric cryptography. This leaves the fundamental problem of halving key strength under Grover's algorithm unresolved, risking the premature obsolescence of the cryptographic infrastructure already built with substantial investment.

[0006] Prior art document 3 (US202318335665A) discloses systems and methods for post-quantum cryptography optimization. Its shortcoming lies in the fact that it does not provide or resolve a specific migration scheme and technical path for actually executing the migration from the existing cryptographic system to a quantum-resistant cryptographic system after an alert is triggered. It fails to address the complex engineering and technical issues of "how to migrate specifically," resulting in the system being unable to take effective hardening measures when facing quantum computing threats. It can only passively wait for attacks to occur, unable to achieve proactive defense and a smooth transition, severely hindering the post-quantum security upgrade process of critical infrastructure. Summary of the Invention

[0007] To address the shortcomings of existing technologies, this invention provides a quantum-resistant symmetric cryptographic migration method and system. This method, without altering existing symmetric encryption algorithms or replacing existing encryption hardware, minimizes the modifications to existing vertical encryption devices by introducing a pipelined parallel architecture and cascaded encryption technology. It flexibly supports two working modes—pure encryption cascade and alternating encryption / decryption cascade—by utilizing the logical reconfiguration of the same physical computing core. Combined with a dynamic key rotation mechanism based on block identifiers and key derivation functions, it significantly enhances the resistance of the symmetric cryptosystem to Grover's algorithm and quantum encounter-in-the-middle attacks. Simultaneously, it achieves end-to-end data integrity protection through cascaded integrity verification codes derived from encrypted intermediate states, supports dynamic adjustment of the effective cascade depth based on business load and security requirements during runtime, and employs a dual-stack parallel tunnel strategy to achieve smooth compatibility and gray-scale migration with the original system. This overcomes the technical defects of existing technologies, such as high algorithm replacement costs, long authentication cycles, poor compatibility, and inability to dynamically optimize.

[0008] The present invention adopts the following technical solution.

[0009] A first aspect of the present invention provides a quantum-resistant cryptographic transfer method, comprising the following steps: Determine the upper limit of the number of key cascading rounds supported by the hardware, and determine the minimum value of the number of key cascading rounds, wherein the minimum value is less than the upper limit of the number of key cascading rounds supported by the hardware and the pipeline delay does not exceed the maximum allowable delay; set the minimum value as the final number of cascading rounds, and determine the selected cascading method; The original plaintext data is preprocessed to obtain a standardized grouped queue; The selected concatenation method configures the concatenation of several computing core arrays in the final concatenation round of the existing vertical encryption device. The working key for each round is assigned to each group in the standardized group queue. The final concatenation round of concatenation encryption operations is executed in parallel in a pipeline manner, and the ciphertext group of the final concatenation round of operations is output. The ciphertext blocks are reassembled in order of block ID. A concatenated integrity verification code is generated using the intermediate state sampling values ​​from each round of encryption. The ciphertext blocks, the concatenated integrity verification code, and the metadata header are then encapsulated into ciphertext data. The decryption end receives the ciphertext data, parses out the ciphertext blocks and metadata headers, and reconstructs the same key sequence as the encryption end based on the synchronized master key pool and random numbers in the data packets. It then performs the final cascaded rounds of decryption operations in reverse on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reconstructs the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, it outputs the plaintext blocks to achieve quantum-resistant symmetric cryptographic migration.

[0010] Preferably, the minimum number of key cascade rounds is determined by the following formula:

[0011] In the formula, This represents the minimum number of key concatenation rounds. Indicates rounding up. Indicates the target's equivalent quantum security strength. This indicates the native key length of the current symmetric encryption algorithm.

[0012] Preferably, the pipeline delay is expressed by the following formula:

[0013] In the formula, Indicates pipeline delay. This indicates the number of packets a data packet is divided into. This represents the minimum number of key concatenation rounds. This indicates the duration of a single symmetric encryption operation.

[0014] Preferably, determining the selected cascading method includes: If all vertical encryption devices on the main station side and the field station side can be upgraded synchronously, and the vertical encryption device on the main station side does not interoperate with the vertical encryption device that only supports single symmetric encryption operation, the cascading method is to set the computing core array of all vertical encryption devices to encryption mode; otherwise, the cascading method is to configure the computing core array with odd numbered sequence to encryption mode and the computing core array with even numbered sequence to decryption mode.

[0015] Preferably, assigning working keys for each round to each group in the standardized group queue includes: If dynamic rotation is not enabled, each computing core array... Assign a fixed key ; If dynamic rotation is enabled, a containing The master key pool of key seeds; For each group Calculate the index sequence It can be expressed by the following formula:

[0016] Indicates grouping In the first computing core array The index of the key seed used in the master key pool. This represents the j-th group. Indicates the final cascade round number; When grouping Entering the kth computing core array At that time, the seed is retrieved from the master key pool. By combining key derivation functions The working key for this round is derived.

[0017] Preferably, this is achieved through a key derivation function. The working key for this round is derived, expressed by the following formula:

[0018] In the formula, Indicates grouping The actual working key used in the k-th computing core array This represents the key derivation function. This indicates the key retrieved from the master key pool, with index 1. key seed, This represents a fixed constant bound to the k-th processing core array.

[0019] Preferably, generating a cascading integrity verification code includes: Capture the intermediate state sample value of each group after each round of computation core array output; Concatenate the intermediate state sample values ​​of the same group in round order; Use lightweight cryptographic hash functions to compute cascaded integrity verification codes.

[0020] Preferably, the output plaintext packets include: When the decryption end performs the reverse decryption operation, it uses the same key index sequence generation algorithm and key derivation function as the encryption end, and reproduces the key sequence corresponding to each ciphertext block based on the synchronized master key pool and data packet random number. Configure the final cascaded round of the decryption end's several computing core arrays in a mode that is symmetrical and opposite to the encryption process; The ciphertext block first enters the last round of the computation core array, where the inverse operation is performed using the working key corresponding to the last round of encryption. Its output is then used as input to enter the last round -1 computation core array, and so on, until the first round of the computation core array outputs the original plaintext block.

[0021] Preferably, a traditional single-pass encryption channel and a newly constructed final cascaded round-by-round quantum-resistant encryption channel are simultaneously operated on the existing vertical encryption device; the service traffic is switched from the traditional single-pass encryption channel to the final cascaded round-by-round quantum-resistant encryption channel in proportion; after confirming that the latency and throughput of the final cascaded round-by-round quantum-resistant encryption channel meet the requirements, the traditional single-pass encryption channel is shut down to complete the final switch.

[0022] A second aspect of the present invention provides a quantum-resistant cryptographic transfer system, which operates a quantum-resistant cryptographic transfer method as described in the first aspect, comprising: The concatenation determination module is used to determine the upper limit of the number of key concatenation rounds supported by the hardware of the existing vertical encryption device and to determine the minimum value of the number of key concatenation rounds. When the minimum value is less than the upper limit of the number of key concatenation rounds supported by the hardware and the pipeline delay does not exceed the maximum allowable delay, the minimum value is set as the final number of concatenation rounds, and the selected concatenation method is determined. The preprocessing module is used to preprocess the raw plaintext data to obtain a standardized group queue; The ciphertext block module is used to configure the cascading mode of the final cascading rounds of the existing vertical encryption device, assign working keys for each round to each block in the standardized block queue, and execute the final cascading rounds of cascading encryption operations in parallel in a pipeline manner, outputting the ciphertext blocks of all the final cascading rounds of operations. The encapsulation module is used to reassemble the ciphertext blocks in order of block ID, generate a concatenated integrity verification code using the intermediate state sampling values ​​of each round of operation during the encryption process, and encapsulate the ciphertext blocks, the concatenated integrity verification code and the metadata header into ciphertext data; The migration module is used by the decryption end to receive ciphertext data, parse out the ciphertext blocks and metadata headers, reproduce the same key sequence as the encryption end based on the synchronized master key pool and random numbers in the data packets, and reverse-execute the final cascade rounds of decryption operations on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reproduces the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, the plaintext blocks are output to achieve quantum-resistant symmetric cryptographic migration.

[0023] A third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when loaded onto the processor, implements a quantum-resistant symmetric cryptographic migration method as described in the first aspect.

[0024] The fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the quantum-resistant symmetric cryptographic transfer method described in the fourth aspect.

[0025] Compared with the prior art, the beneficial effects of the present invention include at least the following: This invention introduces n-round cascaded encryption (pure encryption cascade or "encryption") Decryption The encryption is "alternating concatenation". Without changing the underlying symmetric algorithm (such as AES, SM4), the effective key length is extended to n times the original. This increases the equivalent quantum security strength of the 128-bit symmetric key under the Grover algorithm from 64 bits to about n×64 bits (for example, 3 rounds can reach an equivalent of 192 bits), effectively resisting quantum brute-force attacks and improving the equivalent quantum security strength. This invention completely avoids the use of any new quantum-resistant cryptographic algorithms, and does not replace or modify existing symmetric cryptographic algorithms or their hardware / software modules. Upgrades can be completed solely through structural cascading and parallel scheduling modifications. This significantly reduces the engineering modification costs, testing complexity, compliance certification cycles, and rollback risks associated with algorithm replacement, thereby reducing engineering modification costs and migration risks and truly achieving "agile migration." Through an innovative parallel pipeline architecture, the intermediate states of different groups are processed simultaneously using n independent computing cores, reducing the total latency of the original serial n-round encryption to near the level of a single-round operation. Real-world testing data shows that the 3-stage SM4 pipeline achieves a speedup of 2.91, maintaining high security while still meeting the throughput requirements of high-performance scenarios such as real-time communication, thus improving both system throughput and real-time performance. In the alternating encryption / decryption concatenation mode, when the same key is used in all rounds, the encryption result is completely equivalent to the original single encryption, achieving binary-level compatibility with both new and old systems. This allows the system to adopt a dual-stack parallel tunneling strategy for canary deployments, supporting phased and rollback-enabled incremental upgrades, greatly reducing interoperability risks during hybrid deployment phases. Compared to schemes that rely on public-key cryptography algorithms (such as KyberKEM), this invention adheres to the symmetric cryptography path, eliminating the need to replace the entire cryptographic system and avoiding the redesign and lengthy authentication of dedicated computation modules such as NTT / INTT. Compared to schemes that only focus on "threat detection," this invention provides a complete and executable migration scheme, offering quantifiable security enhancements and performance guarantees. This invention is particularly suitable for critical infrastructure scenarios such as power monitoring where key length is limited and algorithm modules cannot be replaced, providing a low-cost, low-risk post-quantum transition path, improving the quantum attack resistance and migration efficiency of existing symmetric cryptographic systems, while significantly reducing engineering modification costs, compliance authentication cycles, and system migration risks. Attached Figure Description

[0026] Figure 1 This is a schematic diagram of a quantum-resistant cryptographic transfer method provided according to an embodiment of the present invention; Figure 2 This is a schematic diagram of an n-round pure encryption cascading process provided according to an embodiment of the present invention; Figure 3 This is a schematic diagram of an n-round encryption / decryption alternating cascade process provided according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the control command protection process of a power vertical encryption SCADA system provided according to an embodiment of the present invention. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of this invention.

[0028] like Figure 1 As shown, Embodiment 1 of the present invention provides a quantum-resistant cryptographic transfer method, comprising the following steps: Step 1: Determine the upper limit of the number of key concatenation rounds supported by the existing vertical encryption device's hardware. Determine the minimum number of key concatenation rounds based on the target equivalent quantum security strength and the original key length. If the minimum value does not exceed the upper limit of the number of key concatenation rounds supported by the hardware, determine the number of key concatenation rounds, select the concatenation method, and determine whether to enable dynamic rotation.

[0029] In a preferred but non-limiting embodiment of the present invention, step 1 includes: Step 1.1: Determine the upper limit of the number of cascaded rounds supported by the hardware by measuring the duration of a single symmetric encryption operation and the maximum throughput. Determine whether to enable dynamic rotation is_algorithm_fixed, and obtain the maximum allowable latency for protected services. Data packet size and flow characteristics.

[0030] More preferably, step 1.1 includes: Actual measured time of a single symmetric encryption operation Maximum throughput Based on available hardware resources (such as the number of remaining available symmetric encryption engines on the FPGA), the upper limit of the number of cascaded rounds that the hardware can support is determined. It can be expressed by the following formula:

[0031] In the formula, This indicates the maximum number of key cascading rounds supported by the hardware. This indicates taking the minimum value. This indicates rounding down. This represents the logical resource availability coefficient. The remaining available logic resources refer to the total number of unused logic units on a hardware platform (such as an FPGA) that can be used to instantiate a symmetric encryption engine. This represents the bandwidth utilization coefficient. Indicates memory bandwidth. This represents the equivalent bandwidth amplification factor, with a value of 1.2. Indicates fixed block length, which refers to the fixed block size that a symmetric encryption algorithm processes in one operation. Indicates the duration of a single symmetric encryption operation. For maximum throughput, The duration of a single symmetric encryption operation is... and maximum throughput The amount of logical resources required to build a symmetric encryption engine can be considered as the number of logical units required to build a symmetric encryption engine, expressed by the following formula:

[0032] In the formula, This represents the resource conversion factor.

[0033] Confirm the currently used symmetric algorithms and their versions, verify whether they meet industry confidentiality requirements, and determine whether dynamic rotation is enabled in the algorithm's core. .

[0034] Determine whether the existing key system can generate, securely store, and distribute n_candidate independent keys, and record any gaps.

[0035] Analyze the maximum allowable latency of protected services Typical packet size (packet_size) and traffic characteristics.

[0036] Step 1.2: Determine the minimum number of cascade rounds based on the target equivalent quantum security strength and the native key length of the current symmetric encryption algorithm. If the minimum number of cascade rounds does not exceed the upper limit of the key cascade rounds and the pipeline delay does not exceed the maximum allowable delay, set the minimum number of cascade rounds as the final number of cascade rounds.

[0037] More preferably, step 1.2 includes: Determine the equivalent quantum security strength of the target For example, a quantum security strength equivalent to 192 or 256 bits is required.

[0038] Let the native key length of the current symmetric encryption algorithm be . (e.g., SM4 is 128 bits). The equivalent strength of a single encryption attempt using the Grover algorithm is approximately... / 2, the target relationship after cascading is expressed by the following formula:

[0039] In the formula, Indicates the target's equivalent quantum security strength. Indicates the number of cascaded rounds.

[0040] Minimum number of key concatenation rounds based on the target relationship after concatenation. It can be expressed by the following formula:

[0041] In the formula, This indicates rounding up to the nearest integer.

[0042] Check if it meets the requirements. ≤ If these conditions are not met, the objective cannot be achieved, and adjustments to the security objectives or hardware are necessary.

[0043] The pipeline delay is determined by the following formula:

[0044] In the formula, This represents pipeline latency, used to describe the estimated processing latency after adopting a pipelined parallel architecture. The number of packets into which a data packet is divided is expressed by the following formula:

[0045] In the formula, This indicates the data packet size, used to describe the typical data packet size of the protected service, such as 1KB = 1024 bytes. This indicates a fixed block length, which is the number of bits in each plaintext block.

[0046] check ≤ If successful, the minimum number of cascaded rounds will be set as the final number of cascaded rounds. Otherwise, it is necessary to increase hardware or lower security requirements.

[0047] Step 1.3: If all vertical encryption devices on the main station side and the field station side can be upgraded synchronously, and the vertical encryption device on the main station side does not interoperate with the vertical encryption device that only supports single symmetric encryption operation, select pure encryption cascading; otherwise, select alternating encryption and decryption cascading.

[0048] Based on migration strategy and compatibility requirements, decisions should be made according to the following logic: If all longitudinal encryption devices on both the main station and the field station sides can be upgraded synchronously, and the longitudinal encryption device on the main station side does not interoperate with longitudinal encryption devices that only support single symmetric encryption operations, the cascading method... Choose pure encryption cascading .

[0049] Otherwise, choose alternating encryption and decryption concatenation. If the main station's vertical encryption device requires canary release, dual-stack operation, key management temporarily unable to support completely independent keys, or any of the following scenarios, the concatenation method should be used. If you choose to cascade encryption and decryption alternately, the final number of cascade rounds must be odd, and the same key is allowed for non-adjacent rounds; when all keys are the same, the cascade degenerates into a single encryption to maintain compatibility with the original system.

[0050] like Figure 2As shown, this flowchart illustrates the data processing flow of a cascaded encryption system. The core functionality involves pipelined multi-round encryption to convert plaintext into ciphertext. The connections and logic of each module are as follows: The top input is plaintext P, which is divided into multiple plaintext groups, denoted as P1, P2, ..., Pn (where n is the total number of groups, determined by the plaintext length and group length). Each plaintext group Pj (j=1, 2, ..., n) independently enters the subsequent cascaded encryption pipeline. The "key generators K1, K2, ..., Kn" on the left are responsible for generating the keys required for multiple rounds of encryption (in an "encryption-decryption alternating" mode, the key may contain encryption / decryption key pairs, but this is simplified to a unified key generation in the diagram). The generated key is fed into the first encryption unit (core1) in the pipeline, providing key material for each round of encryption. The encryption unit pipeline contains n encryption units (core1, core2, ..., coren), which are connected sequentially to form a cascaded structure: the output of core1 is directly used as the input of core2; the output of core2 is used as the input of the next encryption unit (represented by "..." in the diagram); finally, the last encryption unit coren completes the nth round of encryption. The function of each encryption unit is to perform encryption on the input plaintext / intermediate ciphertext using the corresponding key (in "alternating mode," some units may perform decryption, but this is simplified to unified encryption in the diagram).

[0051] The "pipeline control module" is responsible for coordinating the timing and status of the encryption units to ensure efficient data flow in the pipeline: controlling the timing of plaintext packets entering core1; synchronizing the processing rhythm of each encryption unit to avoid data conflicts; and managing the system's state switching from "idle" to "fill", "run" and then to "flush" (refer to the FSM logic of the previous method).

[0052] The output of each encryption unit is a ciphertext block, denoted as C1, C2, ..., Cn (Cj corresponds to the result of Pj after n rounds of encryption). All ciphertext blocks are eventually merged (concatenated) into a complete ciphertext, completing the encryption process.

[0053] Plaintext P is first divided into multiple groups. Each group enters a cascaded pipeline consisting of n encryption units. Under the coordination of the key provided by the "key generator" and the "pipeline control module", it undergoes n rounds of encryption (or alternating encryption and decryption) in sequence, and finally outputs the corresponding ciphertext group and reassembles it into complete ciphertext C.

[0054] This process combines pipeline parallelism (processing multiple packets simultaneously in the pipeline) and cascaded encryption (processing a single packet in multiple rounds) to optimize processing efficiency while ensuring security.

[0055] As shown in Figure 3, the top input is plaintext P, which is divided into multiple parallel plaintext packets through a branching structure. Each plaintext packet independently enters the cascaded pipeline below for deep processing. The "key generator" on the left is responsible for generating the key sequences required for multiple rounds. The encryption / decryption unit pipeline (alternating structure) is the biggest change in the figure. The pipeline is no longer a single type of computational core, but rather an alternating arrangement of encryption and decryption units. The data flow passes through Core1 (usually encryption), then enters Core2 (usually decryption), and then enters the subsequent Core3 (encryption), and so on. This structural design is used to introduce internal state transformation or compatibility logic (e.g., degrading to single-round encryption under the same key configuration) while maintaining the overall encryption characteristics of the system. This module is responsible for coordinating the timing of the entire alternating pipeline, ensuring that encryption and decryption operations process the data in relay within the correct clock cycle, realizing multi-path parallel EDE computation. The data flow processed by the end encryption unit is output as ciphertext packets. All ciphertext packets are finally converged and spliced ​​to form a complete ciphertext. The diagram illustrates the physical implementation of alternating encryption and decryption. Through the built-in decryption unit, the system has structural flexibility: when specific parameters are configured (such as using the same key at the beginning and end), the internal decryption operations can cancel each other out, thus completely degrading the overall function to traditional single-round encryption, ensuring binary-level compatibility with old systems.

[0056] Explanation regarding the number of cascaded rounds: In a pure cryptographic cascade, the number of cascade rounds is a positive integer greater than or equal to 2.

[0057] In alternating encryption and decryption concatenation, the number of concatenation rounds must be odd to ensure that the concatenation operation begins and ends with encryption. With special configuration of the key sequence, the entire concatenation operation can be degenerated into a single encryption, achieving full compatibility with the original encryption system. Alternatively, multiple independent keys can be generated and distributed to different encryption rounds according to a preset complex sequence (such as an "encryption-decryption" alternation strategy based on group numbering), thereby greatly enhancing security.

[0058] Through the above design, the same set of physical computing unit arrays can flexibly support two cascading methods by logically reconfiguring the mode control unit, realizing the reuse of hardware resources and agile switching of system functions.

[0059] Step 1.4: If the security strength requirement is the highest security strength and the hardware allows for this highest security strength, then enable dynamic rotation. Set the number of key seeds in the master key pool. , This indicates redundancy. Otherwise, to simplify deployment, dynamic rotation is not enabled, and static allocation is selected. Static allocation is used, at this time Set it to 0.

[0060] Step 2: Preprocess the original plaintext data to obtain a standardized group queue.

[0061] In a preferred but non-limiting embodiment of the present invention, step 2 includes: Step 2.1, according to fixed group length Original plaintext data Cut into For the last data block, if its length is insufficient... Then, fill in the blanks according to the standard fill rule (such as PKCS#7) to complete the blanks. bytes, get A plain text segment of equal length The length of each segment is .

[0062] Step 2.2, for each plaintext segment Assign a unique group number j, This represents the j-th plaintext segment, 1 ≤ j ≤ Let j be the j-th group. Group all Stored in the buffer queue in ascending order of the unique group number j. This is for step 3 to extract in sequence.

[0063] Step 3: Configure the cascading method of the final cascading rounds of the existing vertical encryption device to cascade the core arrays of the selected cascading method. Assign working keys for each round to each group in the standardized group queue. Perform the final cascading rounds of cascading encryption operations in parallel in a pipeline manner and output the ciphertext group of all the final cascading rounds of operations.

[0064] Step 3.1, Create One computing core array Each computing core array can operate in encryption mode E or decryption mode D: If cascaded = All computing core arrays are set to encryption mode E.

[0065] If cascaded =alternate, the odd-numbered operation core array (1, 3, 5, ...) is set to encryption mode E, and the even-numbered operation core array (2, 4, ...) is set to decryption mode D.

[0066] Step 3.2, if dynamic rotation is not enabled For each computing core array Assign a fixed key (common (One key), the entire encryption process remains unchanged.

[0067] If dynamic rotation is enabled Initialize a containing A master key pool with independent key seeds Pre-generated A cryptographically secure key seed Synchronize the master key pool with the decryption terminal through a secure channel. and random number of data packets .

[0068] For each group The generation of the key index sequence includes: The first index is calculated using the following formula:

[0069] In the formula, Indicates grouping In the first computing core array The index of the key seed used in the master key pool. Represents a hash function. This represents a random number for each data packet, and each data packet is unique. It is used to ensure that different data packets have different key index sequences, preventing replay attacks. Indicates modulo, This represents the k-th processing core array, responsible for performing the k-th round of encryption or decryption operations.

[0070] Recursive Subsequent Index It can be expressed by the following formula:

[0071] Obtain the index sequence It can be expressed by the following formula:

[0072] When grouping Enter the computing core array At that time, the seed is retrieved from the master key pool. By combining the key derivation function KDF with constants Derive the working key for this round:

[0073] In the formula, Indicates grouping The actual working key used in the k-th computing core array This represents the key derivation function, used to derive the actual working key from the seed. This indicates the key retrieved from the master key pool, with index 1. key seed, This represents a fixed constant bound to the k-th processing core array.

[0074] Step 3.3: Use a clock-based finite state machine to control the timing, with the states defined as follows: When the state is IDLE, the action is to wait for the encryption start signal; When the status is INIT, the actions are as follows: configure all core roles according to step 3.1; clear the group counter and clock cycle counter; notify the key side to prepare; Status is FILL (previous) When the period is t (1 ≤ t ≤ 1), the action is period t (1 ≤ t ≤ ):Will Send in Simultaneously, groups already in the pipeline are moved one level backward. At the end of this stage, all cores are filled, but no complete ciphertext is yet output; When the status is RUN (stable operation), the actions are executed synchronously every clock cycle: ① From Retrieve a new group Send in ② All Each core processes the currently stored intermediate state in parallel; ③ Output a statement that all tasks have been completed. Ciphertext blocks of round operation ; The status is FLUSH (last) During each cycle, the action is to stop inputting new groups, continue driving the clock, and allow the last remaining group in the pipeline to... Each group completes the calculation sequentially and from Output; When the status is ERROR, the action is to immediately stop the pipeline, block input and output, and report the error code when a timeout, check error, or hardware failure is detected.

[0075] Serial execution delay The formula is expressed as follows:

[0076] The state machine defines the following core states to achieve comprehensive control over the pipeline lifecycle: IDLE (Idle): The system is in its initial or reset state. Waiting for the encryption / decryption task to start signal.

[0077] INIT (Initialization): Upon receiving the task start signal, based on the configuration of the mode control unit (mode 1 or mode 2), set the n operation units (Core_1 to Core_n) to the corresponding working mode (encryption or decryption). Simultaneously, initialize the block counter and clock cycle counter, and notify the key expansion and distribution module to prepare key materials (static key or initiate dynamic key sequence generation).

[0078] FILL (Pre-fill): This state is a critical stage in pipeline setup. The state machine controls the packet scheduling module, sequentially injecting the first n data packets P_1, P_2, …, P_n into the pipeline over n consecutive clock cycles. In the k-th clock cycle, packet P_k enters Core_1, while previously entered packets move to the next stage according to the pipeline cycle. During this stage, the key expansion and distribution module calculates and distributes the corresponding dynamic key sequence for each packet entering the pipeline in real time (if dynamic rotation mode is enabled). There is no complete ciphertext output during this stage.

[0079] RUN (Stable Operation): When the nth packet enters Core_1 and the pipeline is completely full, the state machine enters the RUN state. This is the stage where the system throughput reaches its highest level. Each clock cycle, the state machine synchronously triggers the following operations: This "one input, one parallel processing, one output" cycle is the core of this invention, which amortizes the n-round serial delay to near the level of a single round, thus achieving high performance.

[0080] FLUSH: After all p plaintext packets have been input into the pipeline, the state machine enters the FLUSH state. During the next n-1 clock cycles, no new packets are input, but the state machine continues to drive the clock, causing the last n-1 packets remaining in the pipeline to complete the remaining rounds of computation and be output from Core_n. This stage ensures that all data has been processed.

[0081] ERROR (Error Handling): When the clock synchronization unit or verification logic of the pipeline control module detects a timeout, data verification error, or module failure, the state machine transitions to the ERROR state. In this state, the current pipeline is immediately stopped, data input and output are blocked, and an error code is reported to the upper-level system for retransmission or safety isolation, ensuring system reliability.

[0082] The state transition is jointly determined by the "group counter value", the "clock cycle counter value", and the "ready / complete signals of each module", reflecting deep collaboration with other modules in the system. The transition from IDLE to INIT is triggered by an external task start signal.

[0083] The transition from INIT to FILL occurs immediately after module initialization is complete.

[0084] The transition condition from FILL to RUN is that the group counter = n and the clock cycle counter = n, which precisely corresponds to the moment when the pipeline is completely filled with the first group of data.

[0085] The transition condition from RUN to FLUSH is that all p packets have been input (i.e., the input packet counter reaches p).

[0086] The transition condition from FLUSH back to IDLE is that there is no remaining data in the pipeline (i.e., the clock cycle counter meets the clearing end condition).

[0087] This precise, counter- and hardware-signal-based coordinated control ensures that the entire system maintains correct timing and extremely high processing efficiency even when multiple complex processes such as data segmentation, dynamic key allocation, and parallel computing are performed concurrently. This is something that software implementations or simple controllers cannot achieve.

[0088] The ingenuity of state machines is also reflected in their real-time support for dynamic rotation modes and working mode switching: During each clock cycle of the FILL and RUN states, the state machine sends a "key request" pulse to the key expansion and distribution module while triggering data movement. This pulse carries the current clock cycle and the ID of the group being scheduled, triggering the module to calculate and output the dynamic key required for the next round for the corresponding group. This achieves strict one-to-one, real-time synchronization between the data stream and the key stream.

[0089] When the system needs to switch between Mode 1 (pure encryption) and Mode 2 (alternating encryption and decryption), external instructions can trigger the state machine to enter the IDLE state, or, after completing the processing of the current data packet and entering IDLE, re-execute the INIT state to configure all computing units according to the new mode. This design supports the system's runtime reconfiguration capability, enabling flexible and rapid adaptation of the same set of hardware resources to different security policies.

[0090] Step 4: Reassemble the ciphertext blocks output in Step 3 according to the block ID order, generate the Cascaded Integrity Verification Code (CIVC) using the intermediate state sampling values ​​of each round of encryption, and encapsulate the ciphertext blocks, CIVC, and metadata header containing encryption parameters into a ciphertext data unit and send it to the decryption end.

[0091] Step 4.1, divide the ciphertext into groups. according to By concatenating in ascending order, the ciphertext body is obtained. Indicates the j-th completed The ciphertext blocks encrypted by round-cascading encryption.

[0092] Step 4.2, for each group , 1≤j≤ : Collect the intermediate state sample values ​​of this group after each round of core operation output during the encryption process. Each sample value has a fixed length, such as 32 bits. Indicates grouping During the encryption process, the first A fixed length for sampling at the wheel outlet.

[0093] Cascaded in round order

[0094] Calculate using a lightweight cryptographic hash function (such as a truncated version of SHA-256):

[0095] In the formula, This represents a lightweight cryptographic hash. This represents a cascading integrity verification code.

[0096] Step 4.3: Construct the metadata header ,Include: , , Algorithm identifiers, etc.

[0097] Assemble the final data unit :

[0098] Will Send to the decryption end.

[0099] Step 5: The decryption end receives the ciphertext data, parses out the ciphertext blocks and metadata header, and reproduces the same key sequence as the encryption end based on the synchronized master key pool and the random number of the data packet. It then performs the final cascaded rounds of decryption operations in reverse on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reproduces the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, it outputs the plaintext block to achieve quantum-resistant symmetric cryptographic migration.

[0100] Step 5.1, from Tail extraction Analyze , , Confirm that the parameters are consistent with the local synchronization parameters. Divide the encrypted data into individual packets according to a fixed structure. and its accompanying cascading integrity verification code .

[0101] Step 5.2, group each ciphertext. Execute the same index generation algorithm as the encryption end:

[0102]

[0103] From the master key pool Seeds were extracted from the middle By combining the key derivation function KDF with constants Derive the working key for this round:

[0104] Step 5.3, decrypt the end of the terminal. The array of computing cores is configured in a mode that is symmetrical to and opposite to that of the encryption end: if encryption is performed... If the encryption mode is E, then during decryption... For decryption mode D, if encryption is performed... If the decryption mode is D, then during decryption... Encryption mode E; Ciphertext Grouping First enter Using a key Perform the inverse operation; output enters ,use And so on, until... Output plaintext block P'j, where P'j represents the j-th plaintext block recovered by the decryption end; During the decryption process, intermediate state sample values ​​of the output of each stage of the computing core array are also collected. , This represents the intermediate state sample value (fixed bit width, such as 32 bits) of the j-th block after the output of the core operation in the k-th round during the decryption process.

[0105] Step 5.4: For each group j, concatenate the intermediate states that have been decrypted and reproduced according to round order:

[0106] In the formula, This represents the cascade sequence of intermediate states that are decrypted and reproduced.

[0107] Calculate using the same hash function as the encryption end:

[0108] In the formula, This represents the cascaded integrity verification code recalculated by the decryption end.

[0109] Compare With received If they are equal, the packet is determined not to have been tampered with, and plaintext P'j is output; if they are not equal, exception handling is triggered: the current session decryption pipeline is stopped, the affected packet is discarded, an integrity verification failure alarm is reported, and a key update or session reset can be triggered.

[0110] Step 6: Simultaneously run the traditional single-pass encryption channel and the newly constructed final cascaded round-by-round quantum-resistant encryption channel on the existing vertical encryption device; switch the service traffic from the traditional single-pass encryption channel to the final cascaded round-by-round quantum-resistant encryption channel in proportion; after confirming that the latency, throughput, and stability of the final cascaded round-by-round quantum-resistant encryption channel meet the requirements, shut down the traditional single-pass encryption channel to complete the final switch.

[0111] A parallel tunneling or dual-stack operation strategy is adopted for canary deployment. The traditional encryption channel and the quantum-resistant encryption channel constructed by this method are run simultaneously on the encryption device. The business traffic is gradually switched from the traditional channel to the new channel, and the final switch is completed after monitoring and confirming that the latency, throughput and stability meet the requirements.

[0112] Step 7: During operation, monitor the input buffer fill rate, measured processing latency, and business priority tag in real time, and dynamically adjust the effective pipeline depth neff according to the predefined strategy, where 1≤neff≤Nmax; When the buffer fill rate exceeds the set high watermark, the difference between the latency and the maximum allowable latency is less than the latency threshold, and the service priority label is the set emergency instruction, the effective pipeline depth is reduced to prioritize performance; when the buffer fill rate is consistently below the set low watermark, the system load is light, and the service priority label is the set high-sensitivity critical instruction or batch historical data, the effective pipeline depth is increased to enhance the equivalent quantum security strength. The depth adjustment occurs at the packet boundary, and the new valid pipeline depth value and the corresponding key indexing strategy are written into the metadata header to notify the decryption end to switch synchronously.

[0113] Prioritize performance (reduce depth), if fill_rate exceeds the high watermark, or delay_actual is close to delay_max_allowed, or priority_tag is an urgent instruction, wait for the current packet to finish processing (after FLUSH), reduce n_eff for the next encryption task (e.g., from 5 to 3 or 2), bypass redundant cores, and only enable the first n_eff level; Prioritize safety (increase depth), fill_rate is consistently below the low watermark, system load is light, and priority_tag is a highly sensitive critical instruction or batch historical data. Wait for the current data packet to finish processing, increase n_eff (e.g., from 3 to 5), and enable more cores.

[0114] After each adjustment, the new n_eff value and the corresponding key indexing strategy are written to the metadata header to notify the decryption end to switch synchronously. Adjustments are only made at packet boundaries to ensure that currently en route packets are not affected.

[0115] Ensure that the entire method is audited and that key lifecycle management complies with the "Regulations on Security Protection of Power Monitoring Systems" and the security assessment requirements for commercial cryptography applications.

[0116] like Figure 4 As shown, the dispatch master station (sender) starts with the SCADA system (Data Acquisition and Monitoring Control System) on the left. This system is responsible for generating specific remote control / remote adjustment commands for remotely controlling equipment within the substation. The generated explicit commands enter the master station's vertical encryption and authentication device. This device contains cascaded encryption cores (encryption Core1 to encryption Core), and the data undergoes multiple layers of encryption processing through these cores, converting it into unreadable ciphertext. Network transmission layer: Dispatch data network. The ciphertext commands encrypted by the master station are sent to the dispatch data network through the network channel. This layer represents a dedicated network environment in the power system specifically used for transmitting dispatch control data. Substation / power plant end (receiver): The ciphertext commands enter the station end's vertical encryption and authentication device on the right. This device is configured with cascaded decryption cores (decryption Core1 to decryption Core) corresponding to the sender. n The encryption / decryption system is used to decrypt the received ciphertext layer by layer, restoring it to the original plaintext control commands. The decrypted correct commands are then sent to the underlying monitoring and control devices, which perform the actual physical operations (such as switching on / off, adjusting generator output, etc.). This diagram illustrates the "master-slave" security architecture of the power monitoring system. By deploying symmetrical cascaded encryption / decryption devices at both ends of the dispatch master station and the substation, an end-to-end encrypted tunnel is constructed. This deployment method ensures that even if the data is intercepted when the control commands are transmitted over the public network or dedicated data network, it cannot be easily cracked, thus preventing malicious tampering or illegal control.

[0117] Embodiment 2 of the present invention provides a quantum-resistant cryptographic transfer system, which, when running the quantum-resistant cryptographic transfer method described in Embodiment 2, includes: The concatenation determination module is used to determine the upper limit of the number of key concatenation rounds supported by the hardware of the existing vertical encryption device and to determine the minimum value of the number of key concatenation rounds. When the minimum value is less than the upper limit of the number of key concatenation rounds supported by the hardware and the pipeline delay does not exceed the maximum allowable delay, the minimum value is set as the final number of concatenation rounds, and the selected concatenation method is determined. The preprocessing module is used to preprocess the raw plaintext data to obtain a standardized group queue; The ciphertext block module is used to configure the cascading mode of the final cascading rounds of the existing vertical encryption device, assign working keys for each round to each block in the standardized block queue, and execute the final cascading rounds of cascading encryption operations in parallel in a pipeline manner, outputting the ciphertext blocks of all the final cascading rounds of operations. The encapsulation module is used to reassemble the ciphertext blocks in order of block ID, generate a concatenated integrity verification code using the intermediate state sampling values ​​of each round of operation during the encryption process, and encapsulate the ciphertext blocks, the concatenated integrity verification code and the metadata header into ciphertext data; The migration module is used by the decryption end to receive ciphertext data, parse out the ciphertext blocks and metadata headers, reproduce the same key sequence as the encryption end based on the synchronized master key pool and random numbers in the data packets, and reverse-execute the final cascade rounds of decryption operations on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reproduces the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, the plaintext blocks are output to achieve quantum-resistant symmetric cryptographic migration.

[0118] Embodiment 3 of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements the quantum-resistant cryptographic migration method described in Embodiment 1.

[0119] Embodiment 4 of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements a quantum-resistant symmetric cryptographic migration method as described in Embodiment 1.

[0120] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.

[0121] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for migrating against quantum symmetric cryptography, characterized in that, include: Determine the upper limit of the number of key cascading rounds supported by the hardware, and determine the minimum value of the number of key cascading rounds, wherein the minimum value is less than the upper limit of the number of key cascading rounds supported by the hardware and the pipeline delay does not exceed the maximum allowable delay; set the minimum value as the final number of cascading rounds, and determine the selected cascading method; The original plaintext data is preprocessed to obtain a standardized grouped queue; The selected concatenation method configures the concatenation of several computing core arrays in the final concatenation round of the existing vertical encryption device. The working key for each round is assigned to each group in the standardized group queue. The final concatenation round of concatenation encryption operations is executed in parallel in a pipeline manner, and the ciphertext group of the final concatenation round of operations is output. The ciphertext blocks are reassembled in order of block ID. A concatenated integrity verification code is generated using the intermediate state sampling values ​​from each round of encryption. The ciphertext blocks, the concatenated integrity verification code, and the metadata header are then encapsulated into ciphertext data. The decryption end receives the ciphertext data, parses out the ciphertext blocks and metadata headers, and reconstructs the same key sequence as the encryption end based on the synchronized master key pool and random numbers in the data packets. It then performs the final cascaded rounds of decryption operations in reverse on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reconstructs the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, it outputs the plaintext blocks to achieve quantum-resistant symmetric cryptographic migration.

2. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: The minimum number of key cascading rounds is determined by the following formula: In the formula, denotes the minimum value of the key cascade round number, denotes the upward rounding, denotes the target equivalent quantum security strength, denotes the native key length of the current symmetric encryption algorithm.

3. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: Pipeline delay is expressed by the following formula: In the formula, represents the pipeline delay, represents the number of packets into which a data packet is divided, represents the minimum value of the key concatenation round number, represents the duration of a single symmetric encryption operation.

4. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: Determining the selected cascading method includes: If all vertical encryption devices on the main station side and the field station side can be upgraded synchronously, and the vertical encryption device on the main station side does not interoperate with the vertical encryption device that only supports single symmetric encryption operation, the cascading method is to set the computing core array of all vertical encryption devices to encryption mode; otherwise, the cascading method is to configure the computing core array with odd numbered sequence to encryption mode and the computing core array with even numbered sequence to decryption mode.

5. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: Assigning working keys for each round to each packet in the standardized packet queue includes: If dynamic rotation is not enabled, a fixed key is assigned to each array of operation cores ;​ If dynamic rotation is enabled, a containing The master key pool of key seeds; For each group Calculate the index sequence It can be expressed by the following formula: Indicates grouping In the first computing core array The index of the key seed used in the master key pool. This represents the j-th group. Indicates the final cascade round number; When grouping Entering the kth computing core array At that time, the seed is retrieved from the master key pool. By combining key derivation functions The working key for this round is derived.

6. The quantum-resistant cryptographic transfer method according to claim 5, characterized in that: By combining key derivation functions The working key for this round is derived, expressed by the following formula: In the formula, Indicates grouping The actual working key used in the k-th computing core array This represents the key derivation function. This indicates the key retrieved from the master key pool, with index 0. key seed, This represents a fixed constant bound to the k-th processing core array.

7. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: Generating cascading integrity verification codes includes: Capture the intermediate state sample value of each group after each round of computation core array output; Concatenate the intermediate state sample values ​​of the same group in round order; Use lightweight cryptographic hash functions to compute cascaded integrity verification codes.

8. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: The output plaintext packets include: When the decryption end performs the reverse decryption operation, it uses the same key index sequence generation algorithm and key derivation function as the encryption end, and reproduces the key sequence corresponding to each ciphertext block based on the synchronized master key pool and data packet random number. Configure the final cascaded round of the decryption end's several computing core arrays in a mode that is symmetrical and opposite to the encryption process; The ciphertext block first enters the last round of the computation core array, where the inverse operation is performed using the working key corresponding to the last round of encryption. Its output is then used as input to enter the last round -1 computation core array, and so on, until the first round of the computation core array outputs the original plaintext block.

9. The quantum-resistant cryptographic transfer method according to claim 1, characterized in that: Simultaneously operate the traditional single-encryption channel and the newly constructed final cascaded round-by-round quantum-resistant encryption channel; proportionally switch the business traffic from the traditional single-encryption channel to the final cascaded round-by-round quantum-resistant encryption channel; after confirming that the latency and throughput of the final cascaded round-by-round quantum-resistant encryption channel meet the requirements, shut down the traditional single-encryption channel to complete the final switch.

10. A quantum-resistant symmetric cryptographic transfer system, characterized in that, include: The concatenation determination module is used to determine the upper limit of the number of key concatenation rounds supported by the hardware of the existing vertical encryption device and to determine the minimum value of the number of key concatenation rounds. When the minimum value is less than the upper limit of the number of key concatenation rounds supported by the hardware and the pipeline delay does not exceed the maximum allowable delay, the minimum value is set as the final number of concatenation rounds, and the selected concatenation method is determined. The preprocessing module is used to preprocess the raw plaintext data to obtain a standardized group queue; The ciphertext block module is used to configure the cascading mode of the final cascading rounds of the existing vertical encryption device, assign working keys for each round to each block in the standardized block queue, and execute the final cascading rounds of cascading encryption operations in parallel in a pipeline manner, outputting the ciphertext blocks of all the final cascading rounds of operations. The encapsulation module is used to reassemble the ciphertext blocks in order of block ID, generate a concatenated integrity verification code using the intermediate state sampling values ​​of each round of operation during the encryption process, and encapsulate the ciphertext blocks, the concatenated integrity verification code and the metadata header into ciphertext data; The migration module is used by the decryption end to receive ciphertext data, parse out the ciphertext blocks and metadata headers, reproduce the same key sequence as the encryption end based on the synchronized master key pool and random numbers in the data packets, and reverse-execute the final cascade rounds of decryption operations on the pipeline with a configuration that is symmetrical and opposite to the encryption process. At the same time, it reproduces the intermediate state sampling values ​​and determines the cascaded integrity verification code recalculated by the decryption end. It compares the code with the received cascaded integrity verification code. If they match, the plaintext blocks are output to achieve quantum-resistant symmetric cryptographic migration.

11. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: The minimum number of key cascading rounds is determined by the following formula: In the formula, This represents the minimum number of key concatenation rounds. Indicates rounding up. Indicates the target's equivalent quantum security strength. This indicates the native key length of the current symmetric encryption algorithm.

12. The quantum-resistant cryptographic transfer method according to claim 10, characterized in that: Pipeline delay is expressed by the following formula: In the formula, Indicates pipeline delay. This indicates the number of packets a data packet is divided into. This represents the minimum number of key concatenation rounds. This indicates the duration of a single symmetric encryption operation.

13. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: Determining the selected cascading method includes: If all vertical encryption devices on the main station side and the field station side can be upgraded synchronously, and the vertical encryption device on the main station side does not interoperate with the vertical encryption device that only supports single symmetric encryption operation, the cascading method is to set the computing core array of all vertical encryption devices to encryption mode; otherwise, the cascading method is to configure the computing core array with odd numbered sequence to encryption mode and the computing core array with even numbered sequence to decryption mode.

14. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: Assigning working keys for each round to each packet in the standardized packet queue includes: If dynamic rotation is not enabled, each computing core array Assign a fixed key ; If dynamic rotation is enabled, a containing The master key pool of key seeds; For each group Calculate the index sequence It can be expressed by the following formula: Indicates grouping In the first computing core array The index of the key seed used in the master key pool. This represents the j-th group. Indicates the final cascade round number; When grouping Entering the kth computing core array At that time, the seed is retrieved from the master key pool. By combining key derivation functions The working key for this round is derived.

15. A quantum-resistant cryptographic migration system according to claim 14, characterized in that: By combining key derivation functions The working key for this round is derived, expressed by the following formula: In the formula, Indicates grouping The actual working key used in the k-th computing core array This represents the key derivation function. This indicates the key retrieved from the master key pool, with index 0. key seed, This represents a fixed constant bound to the k-th processing core array.

16. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: Generating cascading integrity verification codes includes: Capture the intermediate state sample value of each group after each round of computation core array output; Concatenate the intermediate state sample values ​​of the same group in round order; Use lightweight cryptographic hash functions to compute cascaded integrity verification codes.

17. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: The output plaintext packets include: When the decryption end performs the reverse decryption operation, it uses the same key index sequence generation algorithm and key derivation function as the encryption end, and reproduces the key sequence corresponding to each ciphertext block based on the synchronized master key pool and data packet random number. Configure the final cascaded round of the decryption end's several computing core arrays in a mode that is symmetrical and opposite to the encryption process; The ciphertext block first enters the last round of the computation core array, where the inverse operation is performed using the working key corresponding to the last round of encryption. Its output is then used as input to enter the last round -1 computation core array, and so on, until the first round of the computation core array outputs the original plaintext block.

18. A quantum-resistant cryptographic transfer system according to claim 10, characterized in that: Simultaneously operate the traditional single-encryption channel and the newly constructed final cascaded round-by-round quantum-resistant encryption channel; proportionally switch the business traffic from the traditional single-encryption channel to the final cascaded round-by-round quantum-resistant encryption channel; after confirming that the latency and throughput of the final cascaded round-by-round quantum-resistant encryption channel meet the requirements, shut down the traditional single-encryption channel to complete the final switch.

19. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded onto the processor, it implements a quantum-resistant cryptographic migration method according to any one of claims 1-9.

20. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores a computer program that, when executed by a processor, implements a quantum-resistant cryptographic transfer method as described in claims 1-9.