Long life cycle data encryption method, system, device and storage medium
Patent Information
- Application Number
- CN202610805669.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-05
- Publication Date
- 2026-09-22
AI Technical Summary
然而,直接将现有PQC(后量子密码学)算法应用于DSSAD(自动驾驶数据记录系统)长期数据存储,面临算法过时、密钥静态化管理无法适应技术演进,以及数据间复杂关联关系缺乏长期完整性保护等根本性挑战
[0043]本发明所提供的长生命期数据加密方法,首先通过目标周期的数据加密密钥对目标数据单元进行加密,得到目标周期的第一密文;然后基于目标数据单元与前序数据单元之间的关联关系,生成一个目标数据单元的因果描述符;最后通过抗量子签名算法生成该因果描述符的一个数字签名,并将该数字签名作为一条因果完整性证明写入目标数据单元的封装中。通过本发明中的技术方案,能够为DSSAD数据中关键的时序与逻辑因果关系提供同样具备抗量子能力的、不可伪造的完整性证明。
Smart Images

Figure CN122802141A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum computing technology, and in particular to a long-lifetime data encryption method, system, device, and storage medium. Background Technology
[0002] Existing public-key cryptosystems (such as RSA and ECC) face long-term threats of being cracked. Given the legal evidentiary nature and long-term retention requirements of autonomous driving data, the introduction of quantum-resistant cryptography is being considered. However, directly applying existing PQC (post-quantum cryptography) algorithms to the long-term data storage of DSSAD (Autonomous Driving Data Recording System) faces fundamental challenges, including algorithm obsolescence, the inability of static key management to adapt to technological evolution, and the lack of long-term integrity protection for complex relationships between data. Summary of the Invention
[0003] The present invention aims to solve at least one of the technical problems existing in the prior art, and proposes a long-lifetime data encryption method, system, device and storage medium.
[0004] In a first aspect, embodiments of the present invention provide a long-lifetime data encryption method, the method comprising:
[0005] Obtain the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target version in the target period. Encrypt the target data unit with the data encryption key of the target period to obtain the first ciphertext of the target period.
[0006] Identify the logical and / or temporal relationships between the target data unit and its preceding data units, and generate a causal descriptor for the target data unit based on these relationships.
[0007] The first ciphertext of the target period and the causal descriptor of the target data unit are taken as input. A digital signature of the causal descriptor is generated by the quantum-resistant signature algorithm, and the digital signature is written into the encapsulation of the target data unit as a proof of causal integrity.
[0008] In some embodiments, when the PQC algorithm in the target version is the first PQC algorithm, the process of generating the data encryption key for the target period includes:
[0009] Generate a first master key based on the first PQC algorithm of the target version;
[0010] Generate a period identifier for the target period based on a predefined fixed time period;
[0011] Based on the first master key and the period identifier of the target period, generate a PQC key derivation function for the target period.
[0012] Generate a data encryption key for the target period based on the PQC key derivation function of the target period.
[0013] In some embodiments, it also includes:
[0014] After the data encryption key for the target period is generated, the data encryption key for the target period is encrypted using the first master key to obtain the second ciphertext for the target period.
[0015] The second ciphertext of the target period is associated with the period identifier and stored in a pre-built key management database.
[0016] In some embodiments, when the preset conditions for key recycling are met, the PQC algorithm under the target version is updated to the second PQC algorithm.
[0017] In some embodiments, when the PQC algorithm in the target version is the second PQC algorithm, the process of generating the data encryption key for the target period includes:
[0018] A second root master key is generated based on the second PQC algorithm;
[0019] A second root master key is generated based on the second PQC algorithm of the target version.
[0020] Generate a period identifier for the target period based on a predefined fixed time period;
[0021] Based on the second master key and the period identifier of the target period, generate a PQC key derivation function for the target period.
[0022] Generate a data encryption key for the target period based on the PQC key derivation function of the target period.
[0023] In some embodiments, when the PQC algorithm in the target version is the second PQC algorithm, for each second ciphertext obtained by encryption using the first master key, the following operation is performed:
[0024] The data encryption key for the target period in the second ciphertext can be recovered using the first master key;
[0025] The data encryption key of the restored target period is re-encrypted using the second master key to obtain the re-encrypted second ciphertext.
[0026] The re-encrypted second ciphertext is re-associated with the periodic identifier and stored, updating the pre-built key management database.
[0027] In some embodiments, after the target data unit generated in any target cycle has been encapsulated, if it is necessary to verify the target data unit in any encapsulation, the following operations are performed:
[0028] Based on the period identifier written in the header information of any of the packages and the version of the PQC algorithm, the corresponding root master key is found.
[0029] Using the root master key that has been found, the data encryption key that encrypts the target data unit can be decrypted.
[0030] The signature of the tail information in any encapsulation is verified using the PQC algorithm corresponding to the root master key.
[0031] Using the decrypted data encryption key, the first ciphertext of the main information in any encapsulation is decrypted to obtain the target data unit;
[0032] Based on the causal descriptor written in the proof information in any of the encapsulations, verify the association between the target data unit and the preceding data unit;
[0033] Furthermore, if all the above operations are successful, the verification is considered successful; if any of the above operations fail, the verification is considered unsuccessful.
[0034] Secondly, embodiments of the present invention provide a long-lifetime data encryption system, the system comprising:
[0035] The acquisition module is used to acquire the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target version in the target period. The target data unit is encrypted with the data encryption key of the target period to obtain the first ciphertext of the target period.
[0036] The identification module is used to identify the logical and / or temporal relationships between the target data unit and the preceding data unit, and to generate a causal descriptor for the target data unit based on the relationships between the target data unit and the preceding data unit.
[0037] The encapsulation module is used to take the first ciphertext of the target period and the causal descriptor of the target data unit as input, generate a digital signature of the causal descriptor through a quantum-resistant signature algorithm, and write the digital signature as a causal integrity proof into the encapsulation of the target data unit.
[0038] Thirdly, embodiments of the present invention provide an electronic device, the electronic device comprising:
[0039] At least one processor; and a memory communicatively connected to the at least one processor;
[0040] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the steps of the method according to any embodiment of the present invention.
[0041] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions that are used to cause a processor to execute the steps of any embodiment of the method of the present invention.
[0042] Compared with the prior art, the present invention has the following advantages:
[0043] The long-lifetime data encryption method provided by this invention first encrypts the target data unit using the data encryption key of the target period to obtain the first ciphertext of the target period; then, based on the association relationship between the target data unit and the preceding data unit, a causal descriptor for the target data unit is generated; finally, a digital signature of the causal descriptor is generated using a quantum-resistant signature algorithm, and this digital signature is written into the encapsulation of the target data unit as a causal integrity proof. Through the technical solution of this invention, a quantum-resistant and unforgeable integrity proof can be provided for the key temporal and logical causal relationships in DSSAD data. Attached Figure Description
[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only preferred embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 A flowchart illustrating a long-lifetime data encryption method provided in an embodiment of the present invention;
[0046] Figure 2 A flowchart illustrating the process of generating a data encryption key according to an embodiment of the present invention;
[0047] Figure 3 A schematic diagram of a process for re-encrypting a second ciphertext provided in an embodiment of the present invention;
[0048] Figure 4 This is a schematic diagram of the structure of a long-lifetime data encryption system provided in an embodiment of the present invention;
[0049] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0051] To enable those skilled in the art to better understand the technical solutions of the present invention, exemplary embodiments of the present invention are described below in conjunction with the accompanying drawings, including various details of the embodiments of the present invention to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0052] Where there is no conflict, the various embodiments of the present invention and the features thereof may be combined with each other.
[0053] As used herein, the term “and / or” includes any and all combinations of one or more related enumerated entries.
[0054] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used herein, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “made of” are used in this specification, the presence of the stated feature, integral, step, operation, element, and / or component is specified, but the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof is not excluded. Terms such as “connected” or “linked” are not limited to physical or mechanical connections but can include electrical connections, whether direct or indirect.
[0055] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having the meaning consistent with their meaning in the context of the relevant art and the invention, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.
[0056] In the technical solution of this invention, the collection, storage, use, processing, transmission, provision, and disclosure of user personal information all comply with relevant laws and regulations and do not violate public order and good morals. The use of user data in this technical solution follows relevant national laws and regulations (e.g., the "Information Security Technology - Personal Information Security Specification"). For example: appropriate measures are taken for personal information access control; restrictions are imposed on the display of personal information; the purpose of using personal information does not exceed the scope of direct or reasonable association; and explicit identity targeting is eliminated when using personal information to avoid precisely locating a specific individual.
[0057] Before introducing the technical solution of this application, it should be noted that when dealing with long-lifetime data storage for DSSAD, the mainstream approach in the industry when discussing PQC migration is to select one or a set of PQC algorithms that are currently assessed as secure for the DSSAD system (such as CRYSTALS-Kyber for encryption and Dilithium for signing). The system uses a fixed PQC key to encrypt and sign the data, and then stores the encrypted data and signature for a long time. The key itself may be updated through simple periodic rotation, but the core PQC algorithm used remains unchanged throughout the system's lifecycle.
[0058] However, the above mainstream approach has at least the following drawbacks:
[0059] 1) Unable to withstand the risk of algorithm cracking in the long term. The security of cryptographic algorithms is dynamic. The currently secure PQC algorithm may be cracked in the next few decades due to mathematical breakthroughs or improvements in computing power. Using a static algorithm scheme means that once the algorithm is cracked, all historical data protected by it will immediately face the risk of leakage or tampering, and there will be no way to remedy the situation.
[0060] 2) Lack of protection for semantic relationships between data. Mainstream solutions only protect the confidentiality and integrity of individual data packets. However, autonomous driving accident analysis relies heavily on the temporal and logical causal relationships between data (such as "abnormal readings of sensor A" leading to "decision instructions from controller B"). Existing technologies lack quantum-resistant integrity proofs for these "data relationships" themselves. After the algorithm is cracked, attackers may be able to forge logically consistent but completely false event chains by carefully constructing data packet replacements.
[0061] 3) Upgrades and migrations are extremely costly and may disrupt business operations. When a static algorithm needs to be upgraded, massive amounts of historical data must be decrypted and re-encrypted. This process is difficult to perform online under the continuous recording requirements of DSSAD, and there is a temporary data exposure window. The upgrade process is complex, error-prone, and may lead to business interruption.
[0062] Based on this, the technical solution of this application aims to solve the three core problems faced when applying quantum-resistant cryptography to the long-lifetime data storage of DSSAD: the cryptographic system cannot evolve over time, the data association lacks long-term protection, and the security upgrade process is complex.
[0063] Specifically, the technical problems to be solved by the technical solution of this application include at least:
[0064] 1) How to design a key management system that enables DSSAD's cryptographic system to securely and automatically upgrade the core algorithm and key without exposing the original data, in order to cope with the risk of the algorithm being cracked in the future.
[0065] 2) How to go beyond the protection of a single data block and provide equally quantum-resistant, unforgeable integrity proofs for the key temporal and logical causal relationships in DSSAD data.
[0066] 3) How to achieve enhanced security while ensuring uninterrupted business recording by DSSAD, and make the entire upgrade process transparent to upper-layer applications.
[0067] Figure 1 This is a flowchart illustrating a long-lifetime data encryption method provided in an embodiment of the present invention. This method is particularly suitable for scenarios involving the storage of DSSAD long-lifetime data. The method can be executed by a long-lifetime data encryption system, which can be implemented in software and / or hardware and can be configured in an electronic device.
[0068] like Figure 1 As shown, the method specifically includes:
[0069] S1, obtain the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target algorithm version in the target period, encrypt the target data unit with the data encryption key of the target period to obtain the first ciphertext of the target period.
[0070] It should be noted that DSSAD, or Automated Driving Data Recording System, refers to an onboard system that conforms to standards such as GB 44497-2024 and is used to record vehicle autonomous driving status and event data. The legally mandated data retention period is often several years or even decades. The core DSSAD application generates the data unit D (i.e., the target data unit), which can be all the data within a 100ms time slice. The data unit D is encrypted using the target period's data encryption key DEK_Ti to obtain the ciphertext C (i.e., the first ciphertext) for that target period.
[0071] PQC algorithms, or post-quantum cryptography algorithms, refer to a cryptographic algorithm system that can resist attacks from quantum computers. They include digital signature, key encapsulation, and public-key encryption algorithms based on mathematical problems such as lattices, encoding, multivariates, and hashing.
[0072] Figure 2 This invention provides a flowchart illustrating the generation process of a data encryption key. In some embodiments, when the PQC algorithm in the target version is the first PQC algorithm, the generation process of the data encryption key for the target period includes:
[0073] S101, based on the first PQC algorithm under the target version, generates a first root master key.
[0074] In secure hardware (such as HSM), the current generation PQC algorithm Alg_v1 (i.e., the first PQC algorithm) is used to generate a root master key RMK_v1 (i.e., the first root master key).
[0075] It should be noted that v1 in the first PQC algorithm Alg_v1 and the first root master key RMK_v1 both refer to the version of the PQC algorithm.
[0076] S102, Generate a period identifier for the target period based on a predefined fixed time period.
[0077] Define a fixed time period T, for example, set the fixed time period to 1 month. At the beginning of the target period, generate a period identifier Ti for the target period.
[0078] S103, based on the first master key and the period identifier of the target period, generate a PQC key derivation function for the target period.
[0079] At the beginning of each time period, a PQC key derivation function for the target period is generated based on the first master key RMK_v1 and the period identifier Ti.
[0080] S104, based on the PQC key derivation function of the target period, generates the data encryption key for the target period.
[0081] At the beginning of each cycle, a PQC key derivation function based on the first root master key RMK_v1 and the cycle identifier Ti is used to derive the data encryption key DEK_Ti for that target cycle.
[0082] In this embodiment, the data encryption keys for different time periods are constructed into a key evolution tree to achieve iterative key upgrades. A key evolution tree specifically refers to a hierarchical key management structure where a long-term stored root master key, through a defined PQC key derivation function, derives multiple periodic data encryption keys according to the time period, forming a tree-like derivation relationship.
[0083] Furthermore, the key evolution tree can also adopt a more complex structure, such as adding intermediate layers like "quarterly keys" and "annual keys" to adapt to access control strategies for data of different granularities.
[0084] In some embodiments, after the data encryption key for the target period is generated, the data encryption key for the target period is encrypted using the first master key to obtain the second ciphertext of the target period; the second ciphertext of the target period is then associated with the period identifier and stored in a pre-built key management database.
[0085] After the data encryption key DEK_Ti for the target period is generated, it is immediately encrypted by the root master key RMK_v1 to obtain the second ciphertext for that target period, which has the ciphertext form: Enc(RMK_v1, DEK_Ti). The second ciphertext is stored in the key management database in association with the period identifier Ti. The original data encryption key DEK_Ti for the target period exists only in the secure hardware memory and is used to encrypt the data unit D generated within that target period.
[0086] S2, identify the logical and / or temporal relationships between the target data unit and the preceding data unit, and generate a causal descriptor for the target data unit based on the relationships between the target data unit and the preceding data unit.
[0087] If there is no relationship between the target data unit and the preceding data unit, a default descriptor is used as the causal descriptor of the target data unit.
[0088] It is understandable that the target data unit refers to the data unit to be analyzed, while the preceding data unit refers to the data produced upstream before the target data unit was generated. The relationship between the target data unit and the preceding data unit can be a logical relationship, a temporal relationship, or both.
[0089] Logical temporal association specifically refers to relationships that are independent of time, focusing on data content, business rules, and computational dependencies. Even if the timing is disordered, the logical binding remains unchanged. Logical temporal association includes: computational dependency, state recursion, attribution / subordination, and triggering causality. Computational dependency means that the target unit field is derived from the preceding unit, for example: the target data is the speed difference, and the preceding data is the actual speed at the previous moment; state recursion means that the preceding record is the previous state of the system, and the target is the state transition result, for example: the preceding data is the vehicle's fault-free parking state, and the target data is normal operation data; attribution / subordination means that the target unit is a subset or derived subordinate data of the preceding data, for example: the preceding data is the overall vehicle message, and the target data is the sub-data of a single module; triggering causality means that the occurrence of a preceding event triggers the generation of the target data, for example: the preceding data is the door opening signal, and the target data is the window power-on data.
[0090] Among them, temporal sequence relationships specifically refer to those constrained by a time axis, determined by the generation time, sampling time, transmission and reception time, or sequence number. This is a physical sequence, focusing only on time and not on business meaning. Temporal sequence relationships include: immediate preceding sequence, interval sequence, and asynchronous sequence. Immediately preceding sequence means that the target unit is generated immediately after the preceding unit finishes or is generated; for example, the preceding data is sampled from the previous frame of the sensor, and the target data is sampled from the next frame. Interval sequence refers to a sequence with several data units in between, existing with a fixed period or time offset; for example, a statistical data packet is generated after every 5 sampled data units. Asynchronous sequence refers to a sequence where the preceding event randomly triggers the target data, with no fixed time interval; for example, multiple abnormal sampled data points before a fault alarm.
[0091] For example, the hash value H_prev of the preceding data unit and the signal ID of the triggering event are taken as the "cause," and the action decision of the target data unit D itself is taken as the "effect." In this case, it can be...<H_prev, Event_ID, ...> Let it be denoted as a causal descriptor Cd.
[0092] In addition, the causal descriptor Cd can contain not only preorder hashes and event IDs, but also data structures such as Merkle roots and vector commitments, to express complex data relationship graphs in a more compact way.
[0093] S3 takes the first ciphertext of the target period and the causal descriptor of the target data unit as input, generates a digital signature of the causal descriptor through a quantum-resistant signature algorithm, and writes the digital signature as a causal integrity proof into the encapsulation of the target data unit.
[0094] For example, taking the first ciphertext C and the causal descriptor Cd as input, a quantum-resistant signature algorithm (such as SPHINCS+) is used to generate a digital signature σ_cause, which is a causal integrity proof. A causal integrity proof specifically refers to cryptographic evidence that uses a quantum-resistant digital signature algorithm to sign the logical or temporal relationship (i.e., "cause" and "effect") between two or more data units, used to prove the long-term authenticity of the correlation between data.
[0095] The encapsulation structure of the target data unit includes: header information, body information, proof information, and tail information.
[0096] The header information includes: the target version of the PQC algorithm, the period identifier of the target period, and the metadata of the target data unit;
[0097] The main information includes: the first ciphertext of the target period;
[0098] The proof information includes: proof of the causal integrity of a target data unit;
[0099] The tail information includes: a signature generated using the PQC algorithm of the target version on the header and body information.
[0100] For example, the final stored data packet structure is: [Header: Version v1 | Period Ti | Metadata]; [Body: Ciphertext C]; [Proof: σ_cause]; [Tail: Signature of (Header|Body) using Alg_v1].
[0101] In some embodiments, when the preset conditions for key recycling are met, the PQC algorithm under the target version is updated to the second PQC algorithm.
[0102] It is understandable that the second PQC algorithm and the first PQC algorithm are different versions of the PQC algorithm. Key recycling specifically refers to a pre-defined, automated security process where, when the predicted lifespan of a cryptographic algorithm ends or a new security threat emerges, the system uses a new generation of more secure PQC algorithms and keys to repackage (re-encrypt) all keys still valid in the key evolution tree, achieving a seamless and secure upgrade of the cryptographic system.
[0103] When the preset conditions for key recycling are met, such as a fixed time interval, receiving an algorithm obsolescence announcement from an authoritative organization, or being triggered by an internal threat assessment model, the system initiates the key recycling process. This process runs in the background with low priority and does not affect foreground data recording.
[0104] In addition to using timed and event-triggered key recycling, a remote authentication mechanism based on a trusted execution environment can be introduced, where cloud security services dynamically issue "recycling instructions" based on global threat intelligence, enabling more intelligent threat response.
[0105] In some embodiments, when the PQC algorithm in the target version is the second PQC algorithm, the process of generating the data encryption key for the target period includes:
[0106] S201, based on the second PQC algorithm of the target version, generate a second root master key;
[0107] S202, Generate a period identifier for the target period based on a predefined fixed time period;
[0108] S203, Based on the second master key and the period identifier of the target period, generate a PQC key derivation function for the target period;
[0109] S204, a PQC key derivation function based on the target period, generates a data encryption key for the target period.
[0110] In the technical solution of this embodiment, when the key cycle condition is triggered, a new root master key RMK_v2 (i.e., the second root master key) is generated in the secure hardware using the new generation PQC algorithm Alg_v2 (i.e., the second PQC algorithm), thereby generating a new cryptographic system.
[0111] Figure 3 The following is a flowchart illustrating a re-encryption of a second ciphertext provided in an embodiment of the present invention. In some embodiments, when the PQC algorithm in the target version is the second PQC algorithm, for each second ciphertext encrypted by the first master key, the following operations are performed:
[0112] S301, the data encryption key for the target period in the second ciphertext is recovered using the first master key;
[0113] S302, the data encryption key of the restored target period is re-encrypted using the second master key to obtain the re-encrypted second ciphertext;
[0114] S303 re-associates the re-encrypted second ciphertext with the periodic identifier and updates the pre-built key management database.
[0115] In this embodiment, the system traverses the key management database. For each historical period key ciphertext Enc(RMK_v1, DEK_Tx) that still needs to be kept confidential: First, within the secure hardware, it is decrypted using the first master key RMK_v1 to obtain the plaintext data encryption key DEK_Tx; then, immediately using the second master key RMK_v2, the data encryption key DEK_Tx is re-encrypted to obtain the re-encrypted second ciphertext, whose ciphertext form is: Enc(RMK_v2, DEK_Tx); finally, the database is updated. This process ensures that the plaintext of the data encryption key DEK_Tx for any period exists only briefly in the secure hardware memory and has never been accessed by the original data.
[0116] In some embodiments, after updating the PQC algorithm under the target version to the second PQC algorithm, the method further includes: securely archiving the first master key RMK_v1 and its related parameters, and marking it as "deprecated but verifiable". Subsequent system operation and new data encryption will default to using the second PQC algorithm Alg_v2.
[0117] In some embodiments, after the target data unit generated in any target cycle has been encapsulated, if it is necessary to verify the target data unit in any encapsulation, the following operations are performed:
[0118] Based on the period identifier written in the header information of any of the packages and the version of the PQC algorithm, the corresponding root master key is found.
[0119] Using the root master key that has been found, the data encryption key that encrypts the target data unit can be decrypted.
[0120] The signature of the tail information in any encapsulation is verified using the PQC algorithm corresponding to the root master key.
[0121] Using the decrypted data encryption key, the first ciphertext of the main information in any encapsulation is decrypted to obtain the target data unit;
[0122] Based on the causal descriptor written in the proof information in any of the encapsulations, verify the association between the target data unit and the preceding data unit;
[0123] Furthermore, if all the above operations are successful, the verification is considered successful; if any of the above operations fail, the verification is considered unsuccessful.
[0124] Understandably, when verifying historical data at any future time, the verifier first determines the periodic identifier Ti and the cryptographic version used (such as v1 or v2) based on the packet header information. Then, from the currently valid key evolution tree, DEK_Ti is decrypted using the corresponding RMK_v1 or RMK_v2, the packet tail signature is verified, and the data body C (i.e., the first ciphertext) is decrypted. Finally, the causal integrity proof σ_cause in the packet is used to verify whether the relationship between the decrypted data and other related data is genuine and has not been tampered with.
[0125] The technical solution in this embodiment proposes a dynamic cryptographic management system that collaboratively designs a "key evolution tree" and a "key cycle" for the key evolution process. Specifically, it proposes an upgrade path that "only repackages the key ciphertext without altering the original data." For the data verification process, it proposes a method for generating and verifying "causal integrity proofs," namely, how to formally extract the correlation between DSSAD data units and solidify them into tamper-proof evidence using a quantum-resistant signature algorithm. Furthermore, it supports an online, lossless upgrade system state machine and task scheduling mechanism to ensure resource isolation and non-interference between the key cycle process and the foreground high-priority data recording tasks.
[0126] The technical solution in this embodiment achieves "dynamic immortality security" through a key recycling mechanism, enabling the system's cryptographic architecture to evolve with time. Even if a certain version of the PQC algorithm is cracked in the future, attackers cannot break through the current key encapsulation chain because the encryption keys for historical data have been re-protected by the new generation of algorithms, thus ensuring the long-term security of all historical data. This is a fundamental improvement over static cryptographic schemes. Furthermore, it protects the semantic integrity of data. Causal integrity proofs extend the protection scope from data bits to data logic. Even if attackers can crack the encryption in the future, they cannot forge or replace a logically consistent false event sequence without breaking the causal proof signature, thus ensuring the deep credibility of the data as legal evidence. Finally, it enables seamless and secure online upgrades. The key recycling process only "re-encapsulates" the ciphertext of the key, without touching the already encrypted original massive amounts of data. This allows security upgrades to be automated and performed in the background, without affecting the continuous data recording business of the DSSAD front end, achieving a balance between security and business continuity. On the other hand, it meets forward-looking regulatory requirements, addressing the forward-looking requirements of domestic and international data security regulations on "long-term confidentiality" and "adopting evaluated cryptographic techniques," providing a future-oriented compliant design for intelligent connected vehicle products.
[0127] Based on the same inventive concept, embodiments of the present invention also provide a long-lifetime data encryption system. Figure 4This is a schematic diagram of the structure of a long-lifetime data encryption system provided in an embodiment of the present invention, as shown below. Figure 4 As shown, the system specifically includes:
[0128] The acquisition module 100 is used to acquire the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target version in the target period. The target data unit is encrypted with the data encryption key of the target period to obtain the first ciphertext of the target period.
[0129] The identification module 200 is used to identify the logical and / or temporal relationships between the target data unit and the preceding data unit, and to generate a causal descriptor for the target data unit based on the relationships between the target data unit and the preceding data unit.
[0130] The encapsulation module 300 is used to take the first ciphertext of the target period and the causal descriptor of the target data unit as input, generate a digital signature of the causal descriptor through a quantum-resistant signature algorithm, and write the digital signature as a causal integrity proof into the encapsulation of the target data unit.
[0131] This solution primarily involves system architecture, cryptographic protocols, and algorithm implementation, and is a computer-executed solution. Its product form is manifested in the secure firmware, hardware drivers, and key management middleware within the DSSAD controller. Key software engineering aspects of this solution include: state machine management of the key evolution tree, a causal relationship analyzer, a background loop task scheduler, and a high-efficiency driver interface with the underlying PQC cryptographic hardware accelerator. It is essential to ensure that all key operations are performed within the protected environment of the hardware security module.
[0132] The technical solutions in the embodiments of the present invention have similar beneficial effects to those described above, and will not be repeated here.
[0133] Based on the same inventive concept, embodiments of the present invention also provide an electronic device. Figure 5 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. Figure 5 As shown, an embodiment of the present invention provides an electronic device including: one or more processors 101, a memory 102, and one or more I / O interfaces 103. The memory 102 stores one or more programs, which, when executed by the one or more processors, enable the one or more processors to implement any of the long-lifetime data encryption methods described in the above embodiments; the one or more I / O interfaces 103 are connected between the processor and the memory, configured to enable information interaction between the processor and the memory.
[0134] The processor 101 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 102 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read / write interface) 103 is connected between the processor 101 and the memory 102, and can realize information interaction between the processor 101 and the memory 102, including but not limited to a data bus (BUS).
[0135] In some embodiments, the processor 101, memory 102, and I / O interface 103 are interconnected via bus 104, and thus connected to other components of the computing device.
[0136] In some embodiments, the one or more processors 101 include a field-programmable gate array.
[0137] This invention also provides a computer-readable medium. The computer-readable medium stores a computer program, which, when executed by a processor, implements the steps of any of the long-lifetime data encryption methods described in the above embodiments. The computer-readable storage medium can be volatile or non-volatile.
[0138] This invention also provides a computer program product, including computer-readable code, or a non-volatile computer-readable storage medium carrying computer-readable code. When the computer-readable code is run in the processor of an electronic device, the processor in the electronic device executes the above-described long-lifetime data encryption method.
[0139] Those skilled in the art will understand that all or some of the steps, systems, and apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software can be distributed on a computer-readable storage medium, which may include computer storage media (or non-transitory media) and communication media (or transient media).
[0140] As is known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable program instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technologies, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, it is known to those skilled in the art that communication media typically contain computer-readable program instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0141] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0142] The computer program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing state information from the computer-readable program instructions. This electronic circuitry can execute the computer-readable program instructions to implement various aspects of the invention.
[0143] The computer program product described herein can be implemented specifically through hardware, software, or a combination thereof. In one alternative embodiment, the computer program product is specifically embodied in a computer storage medium; in another alternative embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0144] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0145] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0146] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0147] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0148] Example embodiments have been disclosed herein, and while specific terminology has been used, it is for illustrative purposes only and should be construed as such, and is not intended to be limiting. In some instances, it will be apparent to those skilled in the art that features, characteristics, and / or elements described in conjunction with particular embodiments may be used alone, or in combination with features, characteristics, and / or elements described in conjunction with other embodiments, unless otherwise expressly indicated. Therefore, those skilled in the art will understand that various changes in form and detail may be made without departing from the scope of the invention as set forth in the appended claims.
Claims
1. A long-lifetime data encryption method, characterized in that, include: Obtain the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target version in the target period. Encrypt the target data unit with the data encryption key of the target period to obtain the first ciphertext of the target period. Identify the logical and / or temporal relationships between the target data unit and its preceding data units, and generate a causal descriptor for the target data unit based on these relationships. The first ciphertext of the target period and the causal descriptor of the target data unit are taken as input. A digital signature of the causal descriptor is generated by the quantum-resistant signature algorithm, and the digital signature is written into the encapsulation of the target data unit as a proof of causal integrity.
2. The method according to claim 1, characterized in that, When the PQC algorithm in the target version is the first PQC algorithm, the process of generating the data encryption key for the target period includes: Generate a first master key based on the first PQC algorithm of the target version; Generate a period identifier for the target period based on a predefined fixed time period; Based on the first master key and the period identifier of the target period, generate a PQC key derivation function for the target period. Generate a data encryption key for the target period based on the PQC key derivation function of the target period.
3. The method according to claim 2, characterized in that, Also includes: After the data encryption key for the target period is generated, the data encryption key for the target period is encrypted using the first master key to obtain the second ciphertext for the target period. The second ciphertext of the target period is associated with the period identifier and stored in a pre-built key management database.
4. The method according to claim 3, characterized in that, When the preset conditions for key recycling are met, the PQC algorithm under the target version is updated to the second PQC algorithm.
5. The method according to claim 4, characterized in that, When the PQC algorithm in the target version is the second PQC algorithm, the process of generating the data encryption key for the target period includes: A second root master key is generated based on the second PQC algorithm of the target version. Generate a period identifier for the target period based on a predefined fixed time period; Based on the second master key and the period identifier of the target period, generate a PQC key derivation function for the target period. Generate a data encryption key for the target period based on the PQC key derivation function of the target period.
6. The method according to claim 4, characterized in that, When the PQC algorithm in the target version is the second PQC algorithm, for each second ciphertext obtained by encrypting with the first master key, the following operation is performed: The data encryption key for the target period in the second ciphertext can be recovered using the first master key; The data encryption key of the restored target period is re-encrypted using the second master key to obtain the re-encrypted second ciphertext. The re-encrypted second ciphertext is re-associated with the periodic identifier and stored, updating the pre-built key management database.
7. The method according to claim 1, characterized in that, After the target data unit generated in any target cycle is encapsulated, if it is necessary to verify the target data unit in any encapsulation, the following operation is performed: Based on the period identifier written in the header information of any of the encapsulations and the version of the PQC algorithm, the corresponding root master key is found. Using the root master key that has been found, the data encryption key that encrypts the target data unit can be decrypted. The signature of the tail information in any encapsulation is verified using the PQC algorithm corresponding to the root master key. Using the decrypted data encryption key, the first ciphertext of the main information in any encapsulation is decrypted to obtain the target data unit; Based on the causal descriptor written in the proof information in any of the encapsulations, verify the association between the target data unit and the preceding data unit; Furthermore, if all the above operations are successful, the verification is considered successful; if any of the above operations fail, the verification is considered unsuccessful.
8. A long-lifetime data encryption system, characterized in that, The system is configured to implement the method according to any one of claims 1-7, the system comprising: The acquisition module is used to acquire the target data unit generated by the DSSAD application core in the target period and the data encryption key generated by the PQC algorithm under the target version in the target period. The target data unit is encrypted with the data encryption key of the target period to obtain the first ciphertext of the target period. The identification module is used to identify the logical and / or temporal relationships between the target data unit and the preceding data unit, and to generate a causal descriptor for the target data unit based on the relationships between the target data unit and the preceding data unit. The encapsulation module is used to take the first ciphertext of the target period and the causal descriptor of the target data unit as input, generate a digital signature of the causal descriptor through a quantum-resistant signature algorithm, and write the digital signature as a causal integrity proof into the encapsulation of the target data unit.
9. An electronic device, characterized in that, The electronic device includes: At least one processor, and a memory communicatively connected to said at least one processor; The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the steps of the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to perform the steps of the method according to any one of claims 1-7.