The invention relates to the technical field of
quantum communication, discloses a
quantum key remote security injection method and
system based on PQC and zero trust, and aims to solve the problems that post-
quantum authentication is high in calculation overhead, difficult in terminal
adaptation due to resource limitation and lack of continuous
verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the
server carries out implicit
authentication by comparing the disturbance public key and executes
key encapsulation to generate a
session key; the
server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The
system comprises a key injection
server, a terminal security agent and a disturbance function module. According to the method,
authentication logic is integrated into a
cryptographic primitive algebraic structure, so that authentication internal
biochemistry and light weight are realized, the terminal
power consumption and storage occupation are remarkably reduced, the resource exhaustion
attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.