Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

359 results about "Quantum codes" patented technology

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Quantum key distribution method based on cryptographic infrastructure system

The embodiment of the invention provides a quantum key distribution method based on a cryptographic infrastructure system, relates to the technical field of quantum secret communication, and provides a quantum key distribution method based on fusion of quantum key distribution and post quantum cryptography, which integrates a classical commercial cryptographic algorithm, a PQC post quantum cryptographic algorithm and quantum key distribution. A QKD-based quantum key secure distribution process combining SM2 and PQC mixed signature, SM2 and PQC mixed key packaging, PQC collaborative signature, PQC collaborative decryption, token access and other cryptographic technologies is designed, and anti-quantum cryptographic capability support is provided for voice applications through collaborative signature and collaborative decryption, so that the security of software for realizing a PQC cryptographic algorithm is improved, and the security of the PQC cryptographic algorithm is improved. Moreover, the software implementation mode does not have the inherent security problem of the IP, the dependency on the server is low, and the standardization program is high.
Owner:中电信量子信息科技集团有限公司

Configurable number-theory transformation parallel computing acceleration method and device for post quantum cryptography algorithm

The invention discloses a configurable number-theory transformation parallel computing acceleration method and device for a post quantum cryptographic algorithm, and relates to the technical field of cryptographic algorithms. The number theory transformation is a calculation bottleneck in lattice-based post-quantum cryptography and PQC; a hardware accelerator specially designed for number theory transformation (NTT) is an effective solution for improving the execution speed. At present, a mainstream design neglects the influence of the scale of a calculation array, so that the design of an NTT calculation circuit is poor in flexibility and low in memory utilization rate, and a two-dimensional reconfigurable number theory transformation acceleration circuit is provided; the method is applied to a key generation stage, an encryption stage and a decryption stage of the post-quantum cryptographic algorithm. The NTT reconfigurable computing circuit provided by the invention can keep the utilization rate of hardware resources, and is suitable for mobile terminal equipment with limited resources; the NTT circuit adopts a low-complexity memory mapping scheme, so that the address control logic is greatly simplified, and the hardware overhead is reduced.
Owner:BEIJING INST OF TECH +1

Substation dispatching data network security communication method based on quantum tunnel encryption

The invention discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security assurance, and aims to solve the problems of endpoint security loss, boundary solidification, weak quantum threat resistance and inflexible deployment of a dispatching data network. According to the method, the establishment of a secure session and the encapsulation, encryption and restoration of data are realized by integrating quantum key distribution and a post quantum cryptographic operation module through quantum secure communication terminals deployed in a dispatching master station and a transformer substation. According to the method, application layer encryption and signature are carried out on telecontrol protocol data, a double-layer encryption tunnel is constructed, and transmission of various physical network media is supported. By means of the scheme, end-to-end protection is achieved, quantum attacks are effectively resisted, double encryption is provided, and networking flexibility and smooth evolution are improved.
Owner:INNER MONGOLIA HUIQIANG TECH CO LTD

Vehicle-gauge-level rear quantum cryptography acceleration and side channel protection device

The invention relates to the technical field of vehicle-gauge-level password protection, and discloses a vehicle-gauge-level post quantum password acceleration and side channel protection device. The device comprises a quantum key injection unit, a quantum noise analysis unit, a post quantum cryptography acceleration engine, a side channel feature extraction unit and a protection strategy generator. The quantum key injection unit performs format standardization processing on input quantum key information; the quantum noise analysis unit collects a power consumption time sequence signal and an electromagnetic radiation signal of the cryptographic operation chip, and extracts a quantum noise characteristic spectrum through a quantum Fourier transform algorithm; the post quantum cryptographic acceleration engine adopts a lattice-based cryptographic algorithm to implement layered acceleration operation on the target encrypted message data; a side channel feature extraction unit constructs a space-time joint side channel feature tensor according to the quantum noise feature spectrum; the protection strategy generator identifies the physical fragile area according to the tensor and generates a corresponding protection strategy instruction. The device integrates a quantum cryptography acceleration function and a side channel protection function, and is suitable for a vehicle-specification-level scene.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Anti-quantum serial digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum serial digital certificate implementation method. The method comprises the following steps: generating a traditional cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; submitting a certificate request; splicing the traditional cryptographic algorithm public key and the anti-quantum cryptographic algorithm public key to form a dual-cryptographic algorithm public key, and generating a digital certificate according to the dual-cryptographic algorithm public key; signing the digital certificate by using a traditional cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key; and splicing and combining the traditional cryptographic algorithm signature value and the anti-quantum cryptographic algorithm signature value into a dual-cryptographic algorithm signature value, putting the dual-cryptographic algorithm signature value into a signature value item of the digital certificate, so that the digital certificate forms a hybrid serial digital certificate, and returning the hybrid serial digital certificate to the client. The invention further discloses a device for implementing the quantum serial digital certificate implementation method, computer equipment and a storage medium. According to the method, the problems of poor compatibility, low storage efficiency, slow verification speed and the like of the existing digital certificate under the threat of quantum computing are solved.
Owner:KOAL SOFTWARE CO LTD

Cryptographic system for post-quantum cryptographic operations

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.
Owner:PQSHIELD LTD

Dynamic key generation system and method based on multi-source QRNG and QKD

The invention relates to the technical field of quantum cryptography, in particular to a dynamic key generation system and method based on multi-source QRNG and QKD, and the system comprises an interface registration method, a calling method, related equipment and a storage medium, is used for generating a high-security quantum key, and is a quantum key service system with a layered architecture. By abstracting, integrating and managing bottom-layer multi-source QRNG and QKD equipment and fully utilizing the flexible scheduling of quantum equipment, the security of key generation is ensured, so that the key service has higher performance, usability and security, and unified, dynamic and high-security quantum key generation and supply services are provided for various applications of the upper layer. The method is widely applied to the industries and fields of government, finance, energy, traffic, electric power and the like, meets the requirements of quantum key acquisition of various business applications in cloud computing and non-cloud environments, and ensures information security and business continuity.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GROUP (GUIZHOU) CO LTD

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Anti-quantum cryptography migration method and system for power system

The invention relates to the technical field of data security, in particular to a quantum cryptography migration resisting method and system for a power system, and the method comprises the steps: carrying out the quantum threat risk assessment of a communication link based on the layering and partitioning architecture features of the power system; obtaining attribute data of the encryption component, and performing parallel migration risk analysis on the encryption component in combination with a quantum threat risk assessment result to generate an anti-quantum migration risk matrix; carrying out compatibility evaluation on a traditional public key algorithm and an anti-quantum cryptography algorithm based on algorithm features, and constructing a double-track encryption migration strategy; dynamically adjusting a double-track weight ratio, and constructing a double-track encryption hierarchical migration strategy based on a control hierarchy to which a communication link belongs; and executing the double-track encryption layered migration strategy and monitoring the migration effect, and performing self-adaptive correction on the double-track encryption layered migration strategy based on the migration effect. According to the method, a quantum threat assessment and double-track encryption layered migration mechanism is constructed, so that safe and smooth migration of the power system under the threat of quantum computing is realized.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

Distributed quantum security encryption method, system and device

The invention provides a distributed quantum security encryption method, system and device. The method comprises the following steps: monitoring the quality of a quantum key distribution link in real time, and dynamically selecting a quantum key, a post-quantum session key or a fusion key of the quantum key and the post-quantum session key as a working key; and when the node cannot be directly reached, the trusted relay node generates an end-to-end key seed by using a quantum key and a post-quantum cryptography shared key which are respectively established with the two ends, the end-to-end key seed is encrypted and distributed by a public key and then a session key is independently derived by the two communication parties, and the relay node cannot decrypt. The system adopts a distributed Mesh network architecture supporting a terminal / relay dual mode. The device integrates a quantum random number generator, a post quantum cryptography coprocessor and a mixed key engine. The method integrates the advantages of quantum physical security and post quantum cryptography, has high security and availability, and is suitable for constructing a key infrastructure security communication network resisting quantum computing attack.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Data encryption method and device, electronic equipment and storage medium

The invention provides a data encryption method and device, electronic equipment and a storage medium, and belongs to the technical field of data encryption. Determining the data type of the to-be-encrypted data; if the data type is a first type, encrypting the to-be-encrypted data by adopting a post quantum cryptography encryption standard corresponding to the first type; if the data type is a second type, encrypting the to-be-encrypted data by adopting a post quantum cryptography encryption standard corresponding to the second type; wherein the encryption efficiency of the post quantum cryptography encryption standard corresponding to the first type is higher than that of the post quantum cryptography encryption standard corresponding to the second type, and the security of the post quantum cryptography encryption standard corresponding to the second type is higher than that of the post quantum cryptography encryption standard corresponding to the first type. According to the method, the encryption requirements of two types of data requiring encryption efficiency and security can be met at the same time.
Owner:INSPUR TIANYUAN COMM INFORMATION SYST CO LTD

Configurable module-lattice post-quantum cryptography processor for key-encapsulation mechanism

Disclosed is a reconfigurable module-lattice-based key encapsulation mechanism (ML-KEM) post-quantum cryptography system and method using memory-based numbers theoretic transform (NTT). A post-quantum cryptography method of a post-quantum cryptography system including a plurality of internal submodules includes reconfiguring the plurality of internal submodules by variably selecting one security level from among the plurality of security levels; reconfiguring execution of the plurality of internal submodules to be changed through a main controller; and variably processing data according to the selected security level to perform key generation, encapsulation, and decapsulation through the reconfigured plurality of internal submodules.
Owner:INHA UNIV RES & BUSINESS FOUNDATION

File encryption method and device based on quantum cryptography resisting technology

The invention discloses a file encryption method and device based on an anti-quantum cryptography technology, and the method comprises the steps: selecting a target encryption algorithm and a target signature algorithm from a preset anti-quantum cryptography algorithm library in response to a file encryption instruction; generating an asymmetric key pair corresponding to the target encryption algorithm through a secure random number generator; the asymmetric key pair comprises a target public key and a target private key, and the target private key is stored in the protected area; dividing a to-be-encrypted original data file into a plurality of file data blocks; using the target encryption algorithm and the target public key to perform hybrid encryption processing on the file data blocks in sequence to generate encrypted data blocks; performing signature processing on the encrypted data block by using a target signature algorithm to generate a digital signature corresponding to the encrypted data block; and performing data packaging on the encrypted data block and the digital signature to determine an anti-quantum encryption file corresponding to the original data file. And the encryption efficiency is considered while the file resists the quantum computing attack.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

Security analysis method for post-quantum NTRU cryptographic algorithm

The invention provides a security analysis method for a post-quantum NTRU cryptographic algorithm, and the method comprises the steps: an attacker carries out the sampling of a public key, and obtains a public key sample, different private keys g with a public Hamming weight, and a fixed target private key; according to each public key sample and information disclosed by the Hamming weight of the private key, establishing a modular equation, and solving the modular equation by combining a linear technology and a preset initial value; obtaining a complete value of the second polynomial based on a linear relation between the equation set solution and other parts except the constant term in the second polynomial and a linear relation between a preset initial value and the constant term of the second polynomial; and according to the public key sample and the complete value of the second polynomial, utilizing a GS algorithm to obtain a speculative value of the target private key, and according to the relationship between the speculative value and the actual value of the target private key, carrying out security analysis on the password security system. The private key is recovered by using the relation between the solution of the modular equation and the private key, and the bottleneck of the existing technical means is broken through.
Owner:HUBEI UNIV +1

Power business anti-quantum cryptography migration progressive control method based on risk perception

The invention provides a power business anti-quantum cryptography migration progressive control method based on risk awareness, and belongs to the technical field of migration control, and the method comprises the steps: collecting key parameters of all to-be-migrated businesses in a power system, carrying out the standardization preprocessing of the collected key parameters, and constructing a business feature matrix; acquiring relevant parameters of quantum attacks in real time, and calculating a real-time quantum attack risk value of each service to be migrated; based on the service feature matrix and the real-time quantum attack risk value, constructing a dynamic migration rhythm adaptation model, and calculating a migration priority, a migration rate and a migration interval of each service to be migrated; and constructing a migration fault-tolerant and recovery model, monitoring the migration process in real time, calculating a fault influence range and recovery cost based on fault information, and executing corresponding adjustment operation. Accurate, dynamic and high-reliability control of anti-quantum password migration of the power business is realized, safe and stable operation of the power business in the migration process is guaranteed, and the migration efficiency and the anti-quantum attack capability are improved.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

Key distribution method and device for quantum security infrastructure, equipment and medium

The invention provides a key distribution method, device and equipment for quantum security infrastructure and a medium, and relates to the technical field of quantum secure communication and post quantum cryptography, the method comprises the following steps: in a key distribution process, confirming the credibility of a mobile terminal through a first new person strategy, and using a temporary encryption public key to securely transmit a key pair, the security of key transmission is improved, the flexibility is improved through automatic certificate online signing and issuing of an agent, and the password book can be securely transmitted through the use of the certificate and the key pair and the construction of a secure transmission channel, so that the terminal of the quantum security infrastructure can obtain the corresponding core key key elements based on an online mode, and the security of the key transmission is improved. The application expansibility of the quantum security infrastructure is greatly improved, and the security strength of the system is guaranteed.
Owner:中电信量子信息科技集团有限公司

Quantum-resistant security enhancement method for transport layer security protocol

A quantum-resistant security enhancement method for a transport layer security protocol, comprising: (011) acquiring a first quantum key and a quantum key identifier from a serving node; (012) performing post-quantum cryptographic encryption on the quantum key identifier to obtain a first encryption result, and sending the first encryption result to a network device; (013) decrypting a received second encryption result to obtain a second decryption result; (014) obtaining a first terminal handshake key and a first network device handshake key on the basis of the first encryption result and the second decryption result; and (015) generating a second terminal handshake key and a second network device handshake key on the basis of the first quantum key, the first terminal handshake key, the first network device handshake key, the first encryption result and the second decryption result, so as to encrypt communication between the terminal and the network device.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

High-speed hardware acceleration system for Kyber anti-quantum cryptography algorithm and implementation method

The invention discloses a high-speed hardware acceleration system for a Kyber anti-quantum cryptography algorithm and an implementation method, and relates to the technical field of hardware acceleration of the anti-quantum cryptography algorithm, the high-speed hardware acceleration system comprises a dynamic resource management and scheduling center, a reconfigurable NTT computing cluster unit, a streaming polynomial coefficient cache network and a runtime security scheduler; and the dynamic resource management and scheduling center is respectively connected with the reconfigurable NTT computing cluster unit, the streaming polynomial coefficient cache network and the runtime security scheduler. According to the high-speed hardware acceleration system for the Kyber anti-quantum cryptography algorithm and the implementation method, the overall operation throughput rate and the response speed of the system are effectively improved, idle loss caused by fixed resource allocation or data waiting is reduced, the flexible reconstruction and reuse capability of hardware resources is improved, and the implementation efficiency is improved. Therefore, the same set of physical unit can efficiently adapt to different core operation modes in the Kyber algorithm, and the hardware utilization efficiency is improved.
Owner:XIAN DEAN INFORMATION TECH CO LTD

Hybrid collaborative signature method fusing SM2 and post quantum cryptography algorithm

The invention belongs to the technical field of information security, and discloses a hybrid collaborative signature method fusing SM2 and a post-quantum cryptography algorithm, and the method comprises the steps that a client generates a first session key based on a first post-quantum signature key pair and a first post-quantum asymmetric encryption and decryption key pair, generating a first public key ciphertext corresponding to the first public key parameter based on the first session key; the server decrypts the first public key ciphertext based on the first session key, and applies for obtaining a digital signature certificate after generating a common public key through an SM2 algorithm; performing collaborative signature according to a second session key generated by a second post-quantum signature key pair and a second post-quantum asymmetric encryption and decryption key pair, calculating by the server to obtain a first signature component intermediate value, and calculating by the client to obtain a second signature component; the client calculates a target signature value according to the second signature component, the first signature component intermediate value ciphertext and the digital signature certificate; through the method, the safety of the hybrid collaborative signature is improved.
Owner:GUANGDONG CERTIFICATE AUTHORITY

Method for resisting quantum cryptographic migration of Internet of Things equipment based on national cryptographic algorithm

The invention discloses an Internet of Things device anti-quantum password migration method based on a national cryptographic algorithm, and relates to the field of data security, the method comprises the following steps: configuring a Hash agility module taking a national cryptographic SM3 as a default algorithm, and dynamically switching to an anti-quantum or compatibility alternative algorithm based on monitoring; carrying out identity authentication and temporary key negotiation by adopting SM2, and generating a key pair only used for a single session; deriving a session key based on the key pair, and adopting a differential double-layer signature verification mechanism according to the data security level; for firmware updating, a differential package is generated through function level differential analysis, and atomic updating and rollback are achieved through A / B system partition. According to the method, quantum computing threats are effectively resisted, national security compliance and forward security are ensured, the volume of an update package is remarkably reduced through a resource optimization technology, memory occupation is reduced, verification efficiency is improved, and the method is particularly suitable for resource-limited Internet of Things equipment.
Owner:HUAZHONG NORMAL UNIV

Private key full-life-cycle security management system and method based on mobile terminal anti-quantum cryptography algorithm

The invention provides a private key full-life-cycle security management system and method based on a mobile terminal anti-quantum cryptography algorithm. The method comprises the following steps: generating a key pair based on the anti-quantum cryptography algorithm; acquiring a certificate containing a public key in the key pair; calling a mobile terminal key management system to generate a symmetric encryption key, encrypting a private key in the key pair by using the symmetric encryption key, storing the encrypted private key into a sandbox, and storing a certificate into the sandbox; extracting a private key and a certificate in the encrypted key pair from the sandbox, calling the hardware-level key management system, and decrypting the private key by using the symmetric encryption key to obtain a decrypted private key; calling an interface matched with the purpose of the private key through a preset anti-quantum algorithm library, and executing signature, signature verification or key exchange operation by using the decrypted private key; and after the operation is completed, clearing the memory area for storing the private key plaintext. According to the method, the life cycle of the anti-quantum private key can be safely managed on the premise of not depending on the native support of a mobile system.
Owner:DONGFENG MOTOR GRP

Quantum cryptography multi-algorithm collaborative acceleration system after dynamic reconstruction

The invention relates to the technical field of post quantum cryptography, and discloses a multi-algorithm collaborative acceleration system for dynamically reconstructing post quantum cryptography. The system comprises a dynamic parameter library, a password graph indexer, a vectorization scheduling engine and a collaborative execution unit. And after dynamic parameter inventory, the quantum cryptography algorithm operates the parameter set in real time, and feedback update is performed according to the collaborative execution unit. A dynamic cryptographic algorithm index graph is constructed by a cryptographic graph indexer, nodes are algorithm instances, edges are in a cooperative relation, and edge weights are fed back and adjusted according to vectorization scheduling engine path weights. The vectorization scheduling engine carries out vectorization coding on a user password task request to generate a task semantic vector, calculates the similarity between the task semantic vector and an index map node embedding vector, and generates an algorithm selection instruction. And the collaborative execution unit receives the instruction, calls a corresponding algorithm instance for operation, and feeds back the parameter change to the dynamic parameter library. According to the system, dynamic optimization and efficient collaboration of the post-quantum cryptography algorithm are realized, and the adaptability to complex scenes is enhanced.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Hardware acceleration calculation method and system based on post quantum cryptography algorithm

The invention relates to a hardware acceleration calculation method and system based on a post quantum cryptography algorithm, and is applied to a chip. The method comprises the steps that hardware engines in a hardware acceleration engine array are adopted to execute post-quantum cryptographic algorithms of corresponding types, and the post-quantum cryptographic algorithms of the corresponding types comprise at least one of polynomial multiplication, multi-branch hash calculation, a tree structure and sparse polynomial operation; in the execution process, resources needed by the quantum cryptography algorithm after the hardware engines execute are dynamically adjusted based on the prediction mechanism and the fuzzy control logic, and the resources comprise at least one of the core number, the cache bandwidth, the voltage and the frequency. Namely, on one hand, a hardware engine is adopted to perform accelerated calculation on the post quantum cryptography algorithm, and on the other hand, resources required by calculation are dynamically adjusted during accelerated calculation, so that the resource utilization rate is increased, and calculation and energy efficiency regulation are optimized. Cooperative improvement of algorithm acceleration efficiency and performance can be realized.
Owner:CHINA SOUTHERN POWER GRID NEW POWER SYSTEM (BEIJING) RESEARCH INSTITUTE CO LTD

PQC and SM2 / 9 cooperative operation cryptographic chip and method based on RISC-V architecture

The invention provides a PQC and SM2 / 9 cooperative operation cryptographic chip and method based on an RISC-V architecture, and belongs to the technical field of cryptographic security. The chip comprises an RISC-V core and a configurable password collaborative operation unit, wherein the configurable password collaborative operation unit comprises a collaborative control state machine and a unified operation unit capable of being dynamically reconfigured. The method comprises the following steps: receiving and decoding a single cooperative operation instruction from an RISC-V core through a cooperative control state machine, and obtaining operation data feature information; the data length and the security level identification are extracted, and the optimal collaborative operation process is selected in a self-adaptive mode through comparison with a preset threshold value; and finally, dynamically configuring and scheduling a unified operation unit according to the selected process, and completing cooperative operation of the post-quantum cryptography algorithm and the SM2 / SM9 algorithm in an atomization mode. According to the method, deep fusion and intelligent scheduling of the two algorithms are realized on the hardware level, and the efficiency, the resource utilization rate and the safety of cooperative operation are improved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Data security protection method, device and system based on anti-quantum cryptography algorithm

The invention provides a data security protection method, device and system based on an anti-quantum cryptography algorithm, and the method comprises the steps: setting a security storage agent node, enabling the security storage agent node to divide original data into hot data or cold data according to the security level of the original data and access data, the hot data and the cold data are encrypted by adopting different encryption modes, so that the data processing performance is optimized under the condition of ensuring the data security; besides, the data encryption key is subjected to fragmentation encryption, a separated secure storage mode is adopted, the traditional key trusteeship single-point risk is broken through, the data security is further improved, the data encryption key is subjected to fragmentation encryption by adopting a post-quantum encryption algorithm, quantum attack can be effectively resisted, and long-term data security can be guaranteed.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Anti-quantum cryptography application method and device based on FIDO2.0 standard and related product

The invention provides an anti-quantum cryptography application method and device based on an FIDO 2.0 standard and a related product, and relates to the technical field of information security. According to the method, on the basis of an FIDO2.0 standard specification, two groups of keys, namely a traditional key and an anti-quantum key, are generated by using cryptographic algorithm key derivation through the same random number seed; the two groups of keys are tightly coupled to serve as a composite key for FIDO authentication to be used for a subsequent authentication signature process, so that the anti-quantum security is enhanced; when the composite signature is used, the anti-quantum signature covers the traditional password signature, so that a strong dependency chain of two password algorithms is formed, and the security authentication strength is enhanced; when the signature is verified, the composite public key is used for verifying the traditional signature and the anti-quantum signature, authentication can be passed only when the traditional signature and the anti-quantum signature pass, double security protection of the traditional password technology and the anti-quantum password technology is achieved, and the attack risk of the traditional password in quantum computing is effectively resisted.
Owner:CHINA FINANCIAL CERTIFICATION AUTHORITY

Anti-quantum migration method and system, electronic device, and storage medium

The application relates to an anti-quantum password migration method, system, electronic equipment and storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: adaptively extending a transmission layer security protocol; and performing secure transmission of application data by an encryption end and a decryption end based on the extended transmission layer security protocol, wherein the secure transmission process of the application data comprises the following steps: respectively generating a master key, a multi-level sub-key and a path key chain based on an extended password suite according to a chained post-quantum key generation mechanism; generating an encryption key by the encryption end using part of the sub-key, encrypting the application data in a symmetric encryption mode to generate ciphertext, and sending the ciphertext and a path node key at the end of the path key chain to the decryption end; verifying the path node key by the decryption end, generating a decryption key by the decryption end using part of the sub-key after the path node key is verified, and decrypting the ciphertext. The application realizes the security and high efficiency of data transmission in the anti-quantum password migration process.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Anti-quantum cryptography agile migration method of dynamic adaptive algorithm

The invention relates to the field of digital certificates and certificate application, and discloses an anti-quantum cryptography agile migration method capable of dynamically adapting to an algorithm, which is cooperatively executed by a strategy server, a certificate server and an application terminal: the strategy server monitors a migration progress and dynamically generates and issues a migration strategy; the application terminal analyzes the strategy and applies for a specified type of certificate from the certificate server; the certificate server carries out processing and issues a certificate; and the application terminal dynamically selects an algorithm compatible with the target application to establish secure connection according to the strategy during communication. According to the method, through automatic certificate management driven by a strategy and terminal self-adaptive algorithm selection, agile and smooth migration of the cryptographic algorithm is realized, and the problems of compatibility and safety management in the migration process are effectively solved.
Owner:KOAL SOFTWARE CO LTD

Anti-quantum security enhancement method for SSL VPN protocol

An anti-quantum security enhancement method for an SSL VPN protocol of a communication network. The method comprises: (011) acquiring a first quantum key and a quantum key identifier from a first network node that has accessed a network device; (012) performing post-quantum cryptographic encryption processing on the quantum key identifier, and sending a first encryption result of the post-quantum cryptographic encryption processing to a terminal; (013) decrypting a received second encryption result sent by the terminal, so as to obtain a second decryption result; (014) obtaining a first master key on the basis of the first encryption result and the second decryption result; and (015) generating and obtaining a second master key on the basis of the first master key, the first encryption result, the second decryption result, and the first quantum key, so as to encrypt communication between the network device and the terminal.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD