Cryptographic service system and method supporting fast switching of post-quantum cryptographic algorithms

CN122824399APending Publication Date: 2026-09-25KOAL SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611015912.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-09
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0003]现有密码服务平台、密码中间件或密钥管理系统通常存在如下问题:第一,算法实现与业务系统耦合度较高

Benefits of technology

1、本发明通过算法抽象调度适配模块提供统一密码运算调用接口,使上层业务系统无需直接绑定具体后量子密码算法,实现业务逻辑与算法实现解耦;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824399A_ABST
    Figure CN122824399A_ABST
Patent Text Reader

Abstract

The present application relates to a kind of cryptographic service systems and methods for supporting the fast switching of post-quantum cryptographic algorithm, system includes, post-quantum cryptographic algorithm resource pool, for preloading and resident multiple post-quantum cryptographic algorithm instance;Algorithm abstract scheduling adaptation module, for providing cryptographic operation call interface, receive the cryptographic operation request initiated by upper layer business system, OID unique identification or current default algorithm strategy, cryptographic operation request is routed to corresponding post-quantum cryptographic algorithm instance;Algorithm neutral key control module, for with business root key as unified entropy source, OID unique identification, the independent public-private key pair of adaptation different post-quantum cryptographic algorithm is derived and generated;Algorithm switching module, for receiving algorithm switching instruction, the routing object of new cryptographic operation request is switched from in-use algorithm instance to alternative algorithm instance.The present application is applicable to the post-quantum cryptographic algorithm deployment and operation and maintenance management in the high-reliability commercial cryptographic service scene of government, finance, communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cryptography, and more specifically, to a cryptographic service system and method that supports rapid switching of post-quantum cryptographic algorithms. Background Technology

[0002] With the development of quantum computing technology, traditional classical asymmetric cryptographic algorithms such as RSA and ECC face the risk of being broken by quantum computing attacks. To defend against quantum computing attacks, post-quantum cryptographic algorithms are gradually becoming an important direction for the construction of next-generation cryptographic systems. Post-quantum cryptographic algorithms typically include key encapsulation algorithms and digital signature algorithms, and can be used in cryptographic service scenarios such as data encryption, key negotiation, identity authentication, and signature verification. However, post-quantum cryptographic algorithms are still in the stage of continuous evolution and deployment. Different algorithms may differ in terms of security, performance, key length, signature length, ciphertext length, compliance status, and applicable regions. In actual deployment, due to reasons such as algorithm malfunction, exposure of security vulnerabilities, adjustment of compliance policies, regional access restrictions, and changes in business security strategies, it may be necessary to switch or replace the currently used post-quantum cryptographic algorithms.

[0003] Existing cryptographic service platforms, cryptographic middleware, or key management systems typically suffer from the following problems: First, the algorithm implementation is highly coupled with the business system. Business systems often directly call specific algorithm interfaces. When switching algorithms, it is necessary to modify business code, redeploy services, or even shut down for maintenance, making it difficult to meet the requirements of continuous operation of highly reliable business systems. Second, the key system is bound to the algorithm. Traditional methods typically adopt a "one algorithm, one key" construction model, requiring different algorithms to generate, back up, manage, and rotate keys separately. When adding or switching algorithms, it is often necessary to rebuild the key system, increasing operational complexity and security management costs. Third, existing data is difficult to be compatible after algorithm switching. If historical data does not carry a clear algorithm identifier, the system cannot determine which algorithm should be used for decryption, signature verification, or parsing after switching algorithms. This may require re-encrypting, re-signing, or formatting a large amount of existing data, resulting in high costs. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a cryptographic service system and method that supports rapid switching of post-quantum cryptographic algorithms, which can achieve decoupling of business logic and algorithm implementation, decoupling of key system and algorithm switching, and is compatible with the rapid switching scheme of existing data parsing of post-quantum cryptographic algorithms.

[0005] The technical solution adopted by the present invention to solve its technical problem is: to construct a cryptographic service system that supports fast switching of post-quantum cryptography algorithms, including an algorithm abstraction scheduling and adaptation module, wherein the algorithm abstraction scheduling and adaptation module is communicatively connected to a post-quantum cryptography algorithm resource pool, an algorithm neutral key management module and an algorithm switching module, and the algorithm neutral key management module is communicatively connected to the post-quantum cryptography algorithm resource pool; A post-quantum cryptography algorithm resource pool is used to preload and maintain multiple types of post-quantum cryptography algorithm instances. The algorithm abstraction scheduling and adaptation module is used to provide a unified cryptographic operation call interface, receive cryptographic operation requests initiated by the upper-layer business system, and route the cryptographic operation request to the corresponding post-quantum cryptographic algorithm instance based on the unique identifier of the algorithm OID carried in the business data or the current default algorithm strategy. The algorithm-neutral key management module is used to derive independent public-private key pairs adapted to different post-quantum cryptography algorithms by using the business root key as a unified entropy source and combining the unique algorithm OID identifier of each post-quantum cryptography algorithm. The algorithm switching module is used to receive algorithm switching instructions and, without interrupting the operation of the currently used algorithm instance, switch the routing object of the newly added cryptographic operation request from the currently used algorithm instance to the alternative algorithm instance.

[0006] According to the above scheme, the multiple types of post-quantum cryptography algorithm instances include in-use algorithm instances and alternative algorithm instances.

[0007] According to the above scheme, the post-quantum cryptography algorithm instances include post-quantum key encapsulation algorithm instances and post-quantum digital signature algorithm instances; the post-quantum key encapsulation algorithm instances are used to perform key encapsulation, key decapsulation, encryption or decryption operations; the post-quantum digital signature algorithm instances are used to perform signature or signature verification operations; each post-quantum cryptography algorithm instance is configured with a corresponding unique algorithm OID identifier, algorithm type, algorithm version, security level and running status information.

[0008] According to the above scheme, the algorithm abstraction scheduling and adaptation module includes an algorithm routing table, which is used to establish a mapping relationship between the unique algorithm OID and the corresponding post-quantum cryptography algorithm instance. When the business data carries the unique algorithm OID, the algorithm abstraction scheduling and adaptation module routes the cryptographic operation request to the corresponding algorithm instance according to the unique algorithm OID. When the new business request does not carry the unique algorithm OID, the algorithm abstraction scheduling and adaptation module routes the cryptographic operation request to the current default algorithm instance according to the current default algorithm strategy.

[0009] According to the above scheme, the algorithm-neutral key management module is configured to use the business root key as the master key, the unique identifier of the target post-quantum cryptography algorithm's algorithm OID as the derived extension field, and combine the random salt value and the security parameters of the target post-quantum cryptography algorithm to generate the private key seed corresponding to the target post-quantum cryptography algorithm through the key derivation function; then, using the private key seed as the entropy source, the native key generation interface of the target post-quantum cryptography algorithm is called to generate the public key and private key corresponding to the target post-quantum cryptography algorithm.

[0010] According to the above scheme, the algorithm-neutral key management module is also used to manage the ciphertext storage of the business root key and the private keys of each post-quantum cryptography algorithm; wherein, the business root key is generated by a hardware cryptographic device and stored in the form of root key ciphertext after being encrypted by a key encryption key; the private keys of each post-quantum cryptography algorithm are stored in the form of private key ciphertext after being hardware encrypted, and are only temporarily decrypted to secure memory during cryptographic operations, and the plaintext private key data is cleared after the operation is completed; the public keys of each post-quantum cryptography algorithm are stored in plaintext form and are associated with the unique identifier of the corresponding algorithm OID.

[0011] This invention also provides a cryptographic service method that supports fast switching of post-quantum cryptography algorithms, including the following methods: S1. Preload multiple types of post-quantum cryptography algorithm instances to keep them permanently in the post-quantum cryptography algorithm resource pool. The multiple types of post-quantum cryptography algorithm instances include in-use algorithm instances and candidate algorithm instances. S2. Configure a business root key for the business system, and use the business root key as a unified entropy source, combined with the unique algorithm OID identifier and security parameters of different post-quantum cryptography algorithms, derive independent public-private key pairs corresponding to each post-quantum cryptography algorithm; S3. Receive cryptographic operation requests initiated by the upper-layer business system through the unified cryptographic operation call interface, and route the cryptographic operation request to the corresponding post-quantum cryptographic algorithm instance to perform cryptographic operations based on the unique identifier of the algorithm OID carried in the business data or the current default algorithm strategy. S4. Receive the algorithm switching instruction, verify the validity of the candidate algorithm instance and its corresponding key, and switch the default route object of the new cryptographic operation request from the current algorithm instance to the candidate algorithm instance without interrupting the operation of the current algorithm instance. S5. After the algorithm switch, keep the algorithm instance before the switch and the algorithm instance after the switch running in parallel. For existing business data carrying the unique identifier of the old algorithm OID, route it to the algorithm instance before the switch for compatibility parsing. For new business cryptographic operation requests, route them to the algorithm instance after the switch to perform cryptographic operations and output business data carrying the unique identifier of the new algorithm OID.

[0012] According to the above scheme, step S2, which involves deriving and generating independent public-private key pairs for each post-quantum cryptography algorithm, specifically includes: using the business root key K_root as the master key, and combining the unique Algorithm OID (Algorithm_ID) and random salt value Salt of the target post-quantum cryptography algorithm, the key derivation function KDF is used to generate the private key seed SK_seed corresponding to the target post-quantum cryptography algorithm. The derivation formula is as follows: SK_seed = KDF(K_root, Algorithm_ID∥Salt); Wherein, ∥ represents the string concatenation operator, and the output length of the key derivation function KDF is determined according to the standard security parameters of the target post-quantum cryptography algorithm; Then, using the private key seed SK_seed as the entropy source, the native key generation interface of the target post-quantum cryptography algorithm is called to generate the public key PQ_PK and private key PQ_SK corresponding to the target post-quantum cryptography algorithm.

[0013] According to the above scheme, in step S4, the algorithm switching instruction is triggered by manual operation and maintenance or by the system's automatic policy; the triggering scenarios include at least one of the following: algorithm operation abnormality, algorithm security vulnerability exposure, regional usage restriction, compliance policy update, business security policy adjustment, or algorithm version obsolescence; before performing the algorithm switching, the running status, unique identifier of the algorithm OID, key integrity, and key validity of the candidate algorithm instance are verified. After the verification is passed, the candidate algorithm instance is activated as the default algorithm instance for new business requests.

[0014] According to the above scheme, in step S5, after the algorithm switch is completed, traffic is diverted by parsing the unique algorithm OID carried in the business data; if the business data carries the unique old algorithm OID, the corresponding decryption request, key decapsulation request, or signature verification request is routed to the old algorithm instance; if the business request is a new encryption request, key encapsulation request, or signature request, it is routed to the new algorithm instance after the switch, and the unique algorithm OID corresponding to the new algorithm instance is written into the output data.

[0015] The cryptographic service system and method supporting rapid switching of post-quantum cryptography algorithms, as described in this invention, have the following beneficial effects: 1. This invention provides a unified cryptographic operation call interface through an algorithm abstraction scheduling and adaptation module, so that the upper-layer business system does not need to be directly bound to a specific post-quantum cryptographic algorithm, thereby decoupling business logic from algorithm implementation; 2. This invention preloads and keeps multiple types of post-quantum cryptography algorithm instances resident in a post-quantum cryptography algorithm resource pool, eliminating the need for temporary deployment or loading of algorithm programs during algorithm switching, which is beneficial for achieving rapid online switching; 3. This invention uses a single business root key as a unified entropy source through an algorithm-neutral key management module, and derives independent public and private key pairs for each algorithm by combining the unique identifiers of different algorithm OIDs, thereby reducing the complexity of key management in multi-algorithm scenarios. 4. This invention uses the unique OID of the algorithm carried in the business data, so that after the algorithm is switched, the existing business data can still be routed to the old algorithm instance for compatible parsing, without the need to re-encrypt or re-sign the existing data. 5. This invention can adapt to various algorithm switching scenarios such as algorithm malfunctions, changes in compliance policies, regional usage restrictions, and business strategy adjustments, and is suitable for high-reliability cryptographic service environments such as government affairs, finance, and communications. Attached Figure Description

[0016] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a schematic diagram illustrating the overall architecture of the cryptographic service system that supports rapid switching of post-quantum cryptography algorithms according to the present invention. Figure 2 This is a fast switching sequence diagram of the post-quantum key encapsulation algorithm switching from ML-KEM to HQC provided in the embodiments of the present invention; Figure 3 This is a fast switching sequence diagram of the post-quantum digital signature algorithm provided in this embodiment of the invention, switching from ML-DSA to FN-DSA. Detailed Implementation

[0017] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0018] like Figure 1-3 As shown, the cryptographic service system supporting rapid switching of post-quantum cryptography algorithms of the present invention includes a post-quantum cryptography algorithm resource pool, an algorithm abstraction scheduling and adaptation module, an algorithm neutral key management module, and an algorithm switching module.

[0019] The post-quantum cryptography algorithm resource pool preloads and maintains multiple types of post-quantum cryptography algorithm instances. These instances can include post-quantum key encapsulation algorithm instances and post-quantum digital signature algorithm instances. For example, post-quantum key encapsulation algorithm instances can include ML-KEM, HQC, or other similar algorithms; post-quantum digital signature algorithm instances can include ML-DSA, FN-DSA, or other similar algorithms. Each algorithm instance is configured with a unique algorithm OID, algorithm type, algorithm version, security level, running status, and key index. The algorithm abstraction scheduling and adaptation module provides a unified cryptographic operation call interface to upper-layer business systems. Upper-layer business systems can initiate encryption, decryption, signing, signature verification, key encapsulation, or key decapsulation requests through this unified interface without being aware of the differences in the underlying specific algorithm calls. The algorithm abstraction scheduling and adaptation module internally maintains an algorithm routing table, which is used to establish the mapping relationship between the unique algorithm OID and the algorithm instance.

[0020] When business data carries a unique algorithm OID, the algorithm abstraction scheduling and adaptation module parses the unique algorithm OID and routes the request to the corresponding algorithm instance. For example, when historical ciphertext carries a unique algorithm OID corresponding to ML-KEM, the system routes the decryption or decapsulation request to the ML-KEM algorithm instance; when historical signature data carries a unique algorithm OID corresponding to ML-DSA, the system routes the signature verification request to the ML-DSA algorithm instance. When a new business request does not carry a unique algorithm OID, the algorithm abstraction scheduling and adaptation module determines the algorithm instance to use based on the current default algorithm policy. For example, before the switch, new encryption requests are routed to the ML-KEM algorithm instance by default; after the switch, new encryption requests are routed to the HQC algorithm instance by default. All new business output data is written with the corresponding unique algorithm OID for subsequent parsing.

[0021] The algorithm-neutral key management module manages the business root key and various algorithm keys. The business root key can be generated by a true random number generator in a hardware cryptographic device and encrypted using a key encryption key to form the root key ciphertext. The algorithm-neutral key management module uses the business root key as a unified entropy source and, combined with the unique algorithm OID, random salt value, and security parameters of the target algorithm, derives the private key seed corresponding to the target algorithm. It then calls the target algorithm's native key generation interface to generate the public and private keys. The algorithm switching module receives manual maintenance instructions or automatic system policy instructions. When algorithm malfunctions, security vulnerabilities occur, regional usage restrictions arise, compliance policies are updated, business policies are adjusted, or algorithm versions are deprecated, the algorithm switching module issues an algorithm switching instruction to the algorithm abstraction scheduling and adaptation module. The algorithm abstraction scheduling and adaptation module updates the default algorithm policy according to this instruction and switches new business requests to the alternative algorithm instance.

[0022] This invention also provides a cryptographic service method that supports rapid switching of post-quantum cryptography algorithms, comprising the following methods: S1. Preload multiple types of post-quantum cryptography algorithm instances to keep them permanently in the post-quantum cryptography algorithm resource pool. The multiple types of post-quantum cryptography algorithm instances include in-use algorithm instances and candidate algorithm instances. S2. Configure a business root key for the business system, and use the business root key as a unified entropy source, combined with the unique algorithm OID identifier and security parameters of different post-quantum cryptography algorithms, derive independent public-private key pairs corresponding to each post-quantum cryptography algorithm; S3. Receive cryptographic operation requests initiated by the upper-layer business system through the unified cryptographic operation call interface, and route the cryptographic operation request to the corresponding post-quantum cryptographic algorithm instance to perform cryptographic operations based on the unique identifier of the algorithm OID carried in the business data or the current default algorithm strategy. S4. Receive the algorithm switching instruction, verify the validity of the candidate algorithm instance and its corresponding key, and switch the default route object of the new cryptographic operation request from the current algorithm instance to the candidate algorithm instance without interrupting the operation of the current algorithm instance. S5. After the algorithm switch, keep the algorithm instance before the switch and the algorithm instance after the switch running in parallel. For existing business data carrying the unique identifier of the old algorithm OID, route it to the algorithm instance before the switch for compatibility parsing. For new business cryptographic operation requests, route them to the algorithm instance after the switch to perform cryptographic operations and output business data carrying the unique identifier of the new algorithm OID.

[0023] During system initialization, the hardware cryptographic device generates a high-entropy random number, which the system uses as the business root key K_root. After the business root key is generated, it is not stored persistently in plaintext. Instead, it is encrypted using the key encryption key in the hardware cryptographic device to form the root key ciphertext E(K_root), and stored in a local secure database or encrypted file system.

[0024] When a key needs to be generated for the target post-quantum cryptography algorithm, the algorithm-neutral key management module reads the root key ciphertext E(K_root) and calls the hardware cryptographic device to decrypt it in a secure environment to obtain the business root key K_root. Then, using K_root as the master key, combined with the unique Algorithm OID (Algorithm_ID) and random salt value Salt of the target post-quantum cryptography algorithm, the key derivation function KDF is used to generate the private key seed SK_seed. SK_seed = KDF(K_root, Algorithm_ID∥Salt) Here, ∥ represents the string concatenation operator. The specific implementation of KDF can use a key derivation function that conforms to security standards, and its output length is determined according to the security parameters of the target post-quantum cryptography algorithm.

[0025] After generating the private key seed SK_seed, the algorithm-neutral key management module calls the native key generation interface of the target post-quantum cryptography algorithm to generate the corresponding public key PQ_PK and private key PQ_SK. Immediately after generation, the private key PQ_SK is encrypted by a hardware cryptographic device to form the ciphertext E(PQ_SK), and stored in association with the public key PQ_PK and the algorithm's unique OID. The plaintext private key is not persisted to disk and is only temporarily decrypted to secure memory during cryptographic operations, and destroyed immediately after the operations are completed. It can derive independent key pairs for multiple post-quantum cryptography algorithms based on a single business root key. The keys for different algorithms are isolated from each other due to differences in the algorithm's unique OID, random salt value, and security parameters. Even if the private key of one algorithm is leaked, it will not directly lead to the derivation of the private keys of other algorithms.

[0026] During normal operation, upper-layer business systems initiate cryptographic operation requests. Upon receiving the request, the algorithm abstraction, scheduling, and adaptation module determines whether the request carries a unique algorithm OID. For new encryption, key encapsulation, or signature requests, if the request does not carry a unique algorithm OID, the system selects an existing algorithm instance to perform the operation based on the current default algorithm policy. For example, if the current default encryption algorithm is ML-KEM, a new key encapsulation request is routed to the ML-KEM algorithm instance; if the current default signature algorithm is ML-DSA, a new signature request is routed to the ML-DSA algorithm instance. After the operation is completed, the system writes the unique algorithm OID corresponding to the algorithm used into the output data. For decryption, key decapsulation, or signature verification requests, the business data typically carries a unique algorithm OID. The algorithm abstraction, scheduling, and adaptation module parses this unique algorithm OID and routes the request to the corresponding algorithm instance according to the algorithm routing table. Thus, the system can accurately identify the algorithm used in historical data and call the corresponding algorithm to complete compatibility parsing.

[0027] When scenarios such as algorithm malfunction, exposure of algorithm security vulnerabilities, geographical restrictions on use, updates to compliance policies, adjustments to business strategies, or obsolescence of algorithm versions occur, the algorithm switching module receives a switching request. For example, it might need to switch a key encapsulation algorithm from ML-KEM to HQC, or a digital signature algorithm from ML-DSA to FN-DSA. Upon receiving the switching instruction, the algorithm switching module first notifies the algorithm abstraction scheduling and adaptation module to prepare for the switch. The algorithm abstraction scheduling and adaptation module queries the quantum cryptography algorithm resource pool to confirm that the candidate algorithm instance has been pre-loaded and is available. Subsequently, the algorithm-neutral key management module confirms whether the public-private key pair corresponding to the candidate algorithm already exists; if not, it derives the public-private key pair corresponding to the candidate algorithm based on the business root key, the unique OID identifier of the candidate algorithm, and security parameters, and stores the private key in encrypted form. After completing the algorithm instance status verification and key validity verification, the algorithm abstraction scheduling and adaptation module updates the default algorithm policy, switching the default routing object for new business requests from the original in-use algorithm instance to the candidate algorithm instance. During the switchover process, the existing algorithm instances are not immediately shut down, but remain in the algorithm resource pool to process existing business data.

[0028] After the algorithm switch is completed, the system enters a parallel operation state between the old and new algorithms. For existing business data carrying the unique identifier of the old algorithm OID, the system still routes it to the old algorithm instance to perform decryption, key decapsulation, or signature verification operations. For new business requests, the system routes them to the new algorithm instance to perform encryption, key encapsulation, or signature operations, and outputs business data carrying the unique identifier of the new algorithm OID. The system can complete the quantum cryptography algorithm switch without downtime, without modifying existing data, and without reconstructing the overall key system.

[0029] In a preferred embodiment of the present invention, when switching key encapsulation algorithms, the system initially defaults to using the ML-KEM algorithm instance to handle new key encapsulation requests. After the upper-layer business system initiates a key encapsulation request, the algorithm abstraction scheduling and adaptation module routes the request to the ML-KEM algorithm instance and writes the unique algorithm OID corresponding to ML-KEM into the output data. When it is necessary to switch from ML-KEM to HQC, the algorithm switching module receives the switching instruction. The algorithm abstraction scheduling and adaptation module confirms that the HQC algorithm instance is resident and running in the post-quantum cryptography algorithm resource pool, and calls the algorithm-neutral key management module to generate or load the key pair corresponding to HQC. Subsequently, the system updates the default algorithm strategy so that new key encapsulation requests are routed to the HQC algorithm instance. After the switch is completed, the historical ciphertext carrying the unique ML-KEM algorithm OID is still decapsulated by the ML-KEM algorithm instance; the new key encapsulation request is processed by the HQC algorithm instance, and data carrying the unique HQC algorithm OID is output.

[0030] In a preferred embodiment of the present invention, when switching digital signature algorithms, the system initially defaults to using the ML-DSA algorithm instance to handle new signature requests. After the upper-layer business system initiates a signature request, the algorithm abstraction scheduling and adaptation module routes the request to the ML-DSA algorithm instance and writes the unique algorithm OID corresponding to ML-DSA into the output signature data. When it is necessary to switch from ML-DSA to FN-DSA, the algorithm switching module receives the switching instruction. The algorithm abstraction scheduling and adaptation module confirms that the FN-DSA algorithm instance is available and calls the algorithm-neutral key management module to generate or load the public-private key pair corresponding to FN-DSA. Subsequently, the system updates the default signature algorithm policy so that new signature requests are routed to the FN-DSA algorithm instance. After the switch is completed, historical signature data carrying the unique ML-DSA algorithm OID is still verified by the ML-DSA algorithm instance; new signature requests are processed by the FN-DSA algorithm instance, and signature data carrying the unique FN-DSA algorithm OID is output.

[0031] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.

Claims

1. A cryptographic service system supporting rapid switching of post-quantum cryptographic algorithms, characterized in that, It includes an algorithm abstraction scheduling and adaptation module, which is communicatively connected to a post-quantum cryptography algorithm resource pool, an algorithm neutral key management module, and an algorithm switching module, respectively. The algorithm neutral key management module is communicatively connected to the post-quantum cryptography algorithm resource pool. A post-quantum cryptography algorithm resource pool is used to preload and maintain multiple types of post-quantum cryptography algorithm instances. The algorithm abstraction scheduling and adaptation module is used to provide a unified cryptographic operation call interface, receive cryptographic operation requests initiated by the upper-layer business system, and route the cryptographic operation request to the corresponding post-quantum cryptographic algorithm instance based on the unique identifier of the algorithm OID carried in the business data or the current default algorithm strategy. The algorithm-neutral key management module is used to derive independent public-private key pairs adapted to different post-quantum cryptography algorithms by using the business root key as a unified entropy source and combining the unique algorithm OID identifier of each post-quantum cryptography algorithm. The algorithm switching module is used to receive algorithm switching instructions and, without interrupting the operation of the currently used algorithm instance, switch the routing object of the newly added cryptographic operation request from the currently used algorithm instance to the alternative algorithm instance.

2. The cryptographic service system supporting rapid switching of post-quantum cryptography algorithms according to claim 1, characterized in that, The examples of various post-quantum cryptography algorithms include both in-use algorithm examples and alternative algorithm examples.

3. The cryptographic service system supporting rapid switching of post-quantum cryptography algorithms according to claim 1, characterized in that, The post-quantum cryptography algorithm instances include post-quantum key encapsulation algorithm instances and post-quantum digital signature algorithm instances; the post-quantum key encapsulation algorithm instances are used to perform key encapsulation, key decapsulation, encryption or decryption operations; the post-quantum digital signature algorithm instances are used to perform signature or signature verification operations; each post-quantum cryptography algorithm instance is configured with a corresponding unique algorithm OID identifier, algorithm type, algorithm version, security level and running status information.

4. The cryptographic service system supporting rapid switching of post-quantum cryptography algorithms according to claim 1, characterized in that, The algorithm abstraction scheduling and adaptation module includes an algorithm routing table, which is used to establish a mapping relationship between the unique algorithm OID and the corresponding post-quantum cryptography algorithm instance. When business data carries the unique algorithm OID, the algorithm abstraction scheduling and adaptation module routes the cryptographic operation request to the corresponding algorithm instance according to the unique algorithm OID. When a new business request does not carry the unique algorithm OID, the algorithm abstraction scheduling and adaptation module routes the cryptographic operation request to the current default algorithm instance according to the current default algorithm strategy.

5. The cryptographic service system supporting rapid switching of post-quantum cryptography algorithms according to claim 1, characterized in that, The algorithm-neutral key management module is configured to use the business root key as the master key, the unique identifier of the target post-quantum cryptography algorithm's algorithm OID as the derived extension field, and combine a random salt value and the security parameters of the target post-quantum cryptography algorithm to generate the private key seed corresponding to the target post-quantum cryptography algorithm through a key derivation function; then, using the private key seed as an entropy source, it calls the native key generation interface of the target post-quantum cryptography algorithm to generate the public key and private key corresponding to the target post-quantum cryptography algorithm.

6. The cryptographic service system supporting rapid switching of post-quantum cryptography algorithms according to claim 5, characterized in that, The algorithm-neutral key management module is also used for ciphertext storage management of the business root key and the private keys of each post-quantum cryptography algorithm; wherein, the business root key is generated by a hardware cryptographic device and stored in the form of root key ciphertext after being encrypted by a key encryption key; the private keys of each post-quantum cryptography algorithm are stored in the form of private key ciphertext after being hardware encrypted, and are only temporarily decrypted to secure memory during cryptographic operations, and the plaintext private key data is cleared after the operation is completed; the public keys of each post-quantum cryptography algorithm are stored in plaintext and associated with the corresponding algorithm OID unique identifier.

7. A cryptographic service method supporting rapid switching of post-quantum cryptographic algorithms, characterized in that, Including the following methods: S1. Preload multiple types of post-quantum cryptography algorithm instances to keep them permanently in the post-quantum cryptography algorithm resource pool. The multiple types of post-quantum cryptography algorithm instances include in-use algorithm instances and candidate algorithm instances. S2. Configure a business root key for the business system, and use the business root key as a unified entropy source, combined with the unique algorithm OID identifier and security parameters of different post-quantum cryptography algorithms, derive independent public-private key pairs corresponding to each post-quantum cryptography algorithm; S3. Receive cryptographic operation requests initiated by the upper-layer business system through the unified cryptographic operation call interface, and route the cryptographic operation request to the corresponding post-quantum cryptographic algorithm instance to perform cryptographic operations based on the unique identifier of the algorithm OID carried in the business data or the current default algorithm strategy. S4. Receive the algorithm switching instruction, verify the validity of the candidate algorithm instance and its corresponding key, and switch the default route object of the new cryptographic operation request from the current algorithm instance to the candidate algorithm instance without interrupting the operation of the current algorithm instance. S5. After the algorithm switch, keep the algorithm instance before the switch and the algorithm instance after the switch running in parallel. For existing business data carrying the unique identifier of the old algorithm OID, route it to the algorithm instance before the switch for compatibility parsing. For new business cryptographic operation requests, route them to the algorithm instance after the switch to perform cryptographic operations and output business data carrying the unique identifier of the new algorithm OID.

8. The cryptographic service method supporting fast switching of post-quantum cryptography algorithms according to claim 1, characterized in that, In step S2, the derivation of the independent public-private key pairs corresponding to each post-quantum cryptography algorithm specifically includes: using the business root key K_root as the master key, combined with the unique Algorithm OID (Algorithm_ID) and random salt value Salt of the target post-quantum cryptography algorithm, the private key seed SK_seed corresponding to the target post-quantum cryptography algorithm is generated using the key derivation function KDF. The derivation formula is as follows: SK_seed = KDF(K_root, Algorithm_ID∥Salt); Wherein, ∥ represents the string concatenation operator, and the output length of the key derivation function KDF is determined according to the standard security parameters of the target post-quantum cryptography algorithm; Then, using the private key seed SK_seed as the entropy source, the native key generation interface of the target post-quantum cryptography algorithm is called to generate the public key PQ_PK and private key PQ_SK corresponding to the target post-quantum cryptography algorithm.

9. The cryptographic service method supporting fast switching of post-quantum cryptographic algorithms according to claim 6, characterized in that, In step S4, the algorithm switching instruction is triggered by manual operation or automatic system policy. The triggering scenarios include at least one of the following: algorithm operation abnormality, algorithm security vulnerability exposure, regional usage restriction, compliance policy update, business security policy adjustment, or algorithm version obsolescence. Before performing the algorithm switching, the running status, unique identifier of algorithm OID, key integrity, and key validity of the candidate algorithm instance are verified. After the verification is passed, the candidate algorithm instance is activated as the default algorithm instance for new business requests.

10. The cryptographic service method supporting fast switching of post-quantum cryptography algorithms according to claim 1, characterized in that, In step S5, after the algorithm switch is completed, traffic is diverted by parsing the unique algorithm OID carried in the business data. If the business data carries the unique old algorithm OID, the corresponding decryption request, key decapsulation request, or signature verification request is routed to the old algorithm instance. If the business request is a new encryption request, key encapsulation request, or signature request, it is routed to the new algorithm instance after the switch, and the unique algorithm OID corresponding to the new algorithm instance is written into the output data.