Lu He-Jun, Juanatas Roben A, Abisado Mideth B
College of Computing and Information Technologies, National University, Manila, Philippines.
The School of Big Data and Artificial Intelligence, Anhui Xinhua University, Hefei, Anhui, China.
PLoS One. 2025 Sep 15;20(9):e0332665. doi: 10.1371/journal.pone.0332665. eCollection 2025.
With the rapid integration of instant messaging systems (IMS) into critical domains such as finance, public services, and enterprise operations, ensuring the confidentiality, integrity, and availability of communication data has become a pressing concern. Existing IMS security solutions commonly employ traditional public-key cryptography, centralized authentication servers, or single-layer encryption, each of which is susceptible to single-point failures and provides only limited resistance against sophisticated attacks. This study addresses the research gap regarding the complementary advantages of SM2, SM3, and SM4 algorithms, as well as hybrid collaborative security schemes in IMS security. This paper presents a hybrid encryption security framework that combines the SM2, SM3, and SM4 algorithms to address emerging threats in IMS. The proposed framework adopts a decentralized architecture with certificateless authentication and performs all encryption and decryption operations on the client side, eliminating reliance on centralized servers and mitigating single-point failure risks. It further enforces an encrypt-before-store policy to enhance data security at the storage layer. The framework integrates SM2 for key exchange and authentication, SM4 for message encryption, and SM3 for integrity verification, forming a multi-layer defense mechanism capable of countering Man-in-the-Middle (MITM) attacks, credential theft, database intrusions, and other vulnerabilities. Experimental evaluations demonstrate the system's strong security performance and communication efficiency: SM2 achieves up to 642 times faster key generation and 2.2 times faster decryption compared to RSA-3072; SM3 improves hashing performance by up to 11.5% over SHA-256; and SM4 delivers up to 22% higher encryption efficiency than AES-256 for small data blocks. These results verify the proposed framework's practicality and performance advantages in lightweight, real-time IMS applications.
随着即时通讯系统(IMS)迅速融入金融、公共服务和企业运营等关键领域,确保通信数据的保密性、完整性和可用性已成为紧迫问题。现有的IMS安全解决方案通常采用传统的公钥加密、集中式认证服务器或单层加密,这些方法都容易出现单点故障,并且对复杂攻击的抵抗力有限。本研究填补了关于SM2、SM3和SM4算法的互补优势以及IMS安全中的混合协作安全方案的研究空白。本文提出了一种结合SM2、SM3和SM4算法的混合加密安全框架,以应对IMS中出现的威胁。所提出的框架采用具有无证书认证的去中心化架构,并在客户端执行所有加密和解密操作,消除了对集中式服务器的依赖并降低了单点故障风险。它还实施了存储前加密策略以增强存储层的数据安全性。该框架集成了用于密钥交换和认证的SM2、用于消息加密的SM4以及用于完整性验证的SM3,形成了一种能够抵御中间人(MITM)攻击、凭证盗窃、数据库入侵和其他漏洞的多层防御机制。实验评估证明了该系统强大的安全性能和通信效率:与RSA - 3072相比,SM2的密钥生成速度快高达642倍,解密速度快2.2倍;SM3的哈希性能比SHA - 256提高了高达11.5%;对于小数据块,SM4的加密效率比AES - 256高22%。这些结果验证了所提出框架在轻量级、实时IMS应用中的实用性和性能优势。