A national secret IPSec secure communication method supporting quantum-resistant cryptography
By introducing quantum key resistant packaging and quantum signature algorithms in the Guomi IPSec protocol, dual protection of the quantum computing environment is achieved, the security problem of the Guomi IPSec protocol under quantum computer attacks is solved, and the system's resistance to quantum attacks is improved.
Patent Information
- Application Number
- CN202410911510.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-09
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2044-07-09
AI Technical Summary
The existing IPSec protocol lacks quantum resistance when facing quantum computer attacks, resulting in an increase in information security threats. It is necessary to improve the system's quantum attack resistance to ensure security in a quantum computing environment.
The National Secret IPSec protocol introduces quantum key resistant packaging and quantum signature algorithms, and ensures security during the communication process through a dual protection mechanism of mixed signature certificate verification and key exchange parameters.
It significantly improves the system's quantum attack resistance, provides reliable security, and ensures that high level of security is maintained in the quantum computing environment. It is suitable for cryptographic products such as password cards, password machines, gateways and CAs.
Smart Images

Figure CN118631448B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly to a national secret IPSec secure communication method supporting quantum-resistant cryptography. Background Art
[0002] With the rapid development of quantum computing technology, traditional public-key encryption algorithms (such as RSA and ECC) face the risk of being cracked by quantum computers. The powerful computing power of quantum computers could crack many existing cryptographic systems in a fraction of the time, posing a significant threat to information security. The National Cryptography Algorithm (SM series algorithm), as a national cryptographic standard, has been widely used in the information security field. However, to address the challenges posed by future quantum computing, it is necessary to incorporate quantum-resistant cryptographic technology into the existing National Cryptography IPSec protocol to enhance its resistance to quantum attacks.
[0003] Internet Protocol Security (IPSec) is a framework for securing Internet Protocol communications. The IKE (Internet Key Exchange) protocol is responsible for establishing and maintaining security associations (SAs). Currently, IPSec primarily uses nationally recognized algorithms (such as SM2, SM3, and SM4) for encryption and authentication, but these algorithms are also vulnerable to quantum computers. Therefore, researching and designing a method to integrate quantum-resistant key exchange and signature algorithms into nationally recognized IPSec has significant practical significance and application value. Summary of the Invention
[0004] In view of this, the present invention provides a national secret IPSec secure communication method that supports quantum-resistant cryptography, which can enhance the security of the IPSec protocol in the era of quantum computing and achieve dual protection during the communication process.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] A national secret IPSec secure communication method supporting quantum-resistant cryptography, comprising:
[0007] After receiving the security association payload sent by the initiator, the responder sends its pre-applied signature certificate with a hybrid signature of both quantum-resistant signature and national secret signature, and the encryption certificate of the hybrid signature to the initiator;
[0008] The initiator uses the root certificate to verify the responder's hybrid signature dual certificate and generate a temporary key for the quantum-resistant key encapsulation algorithm;
[0009] The initiator constructs the hybrid key exchange parameters and hybrid signature based on the quantum-resistant key encapsulation algorithm temporary key and sends them to the responder;
[0010] The responder extracts the signature certificate and encryption certificate of the hybrid signature pre-applied by the initiator from the hybrid key exchange parameters, which have both a quantum-resistant signature and a national secret signature. The responder verifies the hybrid signature double certificates of the initiator using the root certificate. The responder decrypts the hybrid key exchange parameters constructed by the initiator to obtain the exchange data of the initiator. The responder verifies the hybrid signature of the initiator. The responder performs the key encapsulation operation of the quantum-resistant key encapsulation algorithm to obtain the temporary ciphertext and the quantum-resistant temporary shared key ss.
[0011] The responder constructs the hybrid key exchange parameters and hybrid signature based on the temporary ciphertext and sends them to the initiator;
[0012] The initiator decrypts the responder's hybrid key exchange parameters to obtain the responder's exchange data; verifies the responder's hybrid signature; performs the key decapsulation operation of the quantum-resistant key encapsulation algorithm to obtain the quantum-resistant temporary shared key ss;
[0013] Both the initiator and the responder generate their own hybrid key parameters based on the quantum-resistant temporary shared key ss, and perform subsequent key derivation based on their own hybrid key parameters.
[0014] Furthermore, the process of the initiator verifying the responder's hybrid signature dual certificate includes:
[0015] The initiator uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the responder's signature certificate, and uses the quantum-resistant signature public key in the root certificate to verify the quantum-resistant signature of the responder's signature certificate; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator terminates the connection;
[0016] The initiator uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the responder's encryption certificate, and uses the quantum-resistant signature public key of the root certificate to verify the quantum-resistant signature of the responder's encryption certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator terminates the connection.
[0017] The process by which the responder verifies the initiator's hybrid signature dual certificate includes:
[0018] The responder extracts the signature certificate and the encryption certificate of the hybrid signature pre-applied by the initiator from the hybrid key exchange parameters. The signature certificate has a hybrid signature of both the quantum-resistant signature and the national secret signature, and the hybrid signature is used to verify the national secret signature of the initiator's signature certificate using the national secret asymmetric algorithm signature public key in the root certificate, and the quantum-resistant signature of the initiator's signature certificate using the quantum-resistant signature public key in the root certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder terminates the connection.
[0019] The responder uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the initiator's encryption certificate, and uses the root certificate's quantum-resistant signature public key to verify the initiator's quantum-resistant signature; only when both signatures are verified will the subsequent steps be continued, otherwise the responder terminates the connection.
[0020] Furthermore, the initiator obtains the quantum-resistant key encapsulation algorithm temporary key (PK PQCe _i, SK PQCe _i), where PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, SK PQCe _i represents the temporary private key of the quantum-resistant key encapsulation algorithm.
[0021] Furthermore, the initiator obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_r from the responder's encryption certificate and constructs the mixed key exchange parameters: MixXCHi=XCHi||PK PQCe _i;
[0022] Where XCHi=Asymmetric_Enc(ski, pub_enc_r)||Symmetric_Enc(Ni,ski)||Symmetric_Enc(IDi,ski)||MixCERT_sig_i|| MixCERT_enc_i;
[0023] MixXCHi represents the mixed key exchange parameters constructed by the initiator, XCHi represents the national secret IPSec key exchange parameters of the initiator, || represents the link symbol, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, ski represents the national secret symmetric algorithm key randomly selected by the initiator, pub_enc_r represents the national secret asymmetric algorithm encryption public key of the responder, which is extracted from the encryption certificate of the responder's mixed signature, Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Ni represents the random number of the initiator, IDi represents the identity of the initiator, PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, MixCERT_sig_i represents the initiator's hybrid signature signing certificate, and MixCERT_enc_i represents the initiator's hybrid signature encryption certificate.
[0024] Furthermore, the mixed signature constructed by the initiator is expressed as: MixSIGi=SIGi||SIG PQC _i;
[0025] Among them, SIGi=Asymmetric_Sign(mi, priv_sig_i), SIG PQC _i = PQC_Sign(mi,SK PQCs _i), mi=ski||Ni||IDi||MixCERT_enc_i||PK PQCe _i;
[0026] SIGi represents the national secret IPSec signature of the initiator, SIG PQC _i represents the initiator's anti-quantum signature, MixSIGi represents the mixed signature constructed by the initiator; Asymmetric_Sign() represents the national secret asymmetric algorithm signature operation, PQC_Sign represents the anti-quantum signature operation, mi represents the initiator's message to be signed, priv_sig_i represents the initiator's national secret asymmetric algorithm signature private key, SK PQCs _i represents the initiator's quantum-resistant signature private key, ski represents the symmetric key randomly selected by the initiator, Ni represents the initiator's random number, IDi represents the initiator's identity, and MixCERT_enc_i represents the initiator's mixed signature encryption certificate; PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key.
[0027] Furthermore, the process of the responder decrypting the hybrid key exchange parameters constructed by the initiator includes:
[0028] The responder extracts the national secret IPSec key exchange parameter XCHi from the initiator's mixed key exchange parameter MixXCHi, uses its own national secret asymmetric algorithm encryption private key priv_enc_r to decrypt the national secret asymmetric algorithm encrypted part of XCHi, obtains the national secret symmetric algorithm key ski randomly selected by the initiator, uses ski to decrypt the national secret symmetric algorithm encrypted part of XCHi, and obtains the initiator's random number Ni and identity identifier IDi;
[0029] The process by which the responder verifies the hybrid signature constructed by the initiator includes:
[0030] Extract the initiator's quantum-resistant key encapsulation algorithm temporary public key PK from the initiator's hybrid key exchange parameters PQCe _i, use the decrypted parameters to reconstruct the initiator's message to be signed mi = ski||Ni||IDi||MixCERT_enc_i||PK PQCe _i;
[0031] Obtain the initiator's national secret asymmetric algorithm signature public key pub_sig_i and the initiator's quantum-resistant signature public key PK from the initiator's hybrid signature certificate PQCs_i, and extract the national secret IPSec signature SIGi and anti-quantum signature SIG from the initiator's hybrid signature PQC _i;
[0032] Use mi and pub_sig_i to verify the validity of the signature SIGi, and use mi and PK PQCs _i for signature SIG PQC The validity of _i is verified. Only when both signatures are verified at the same time can the subsequent steps be continued. Otherwise, the responder terminates the connection;
[0033] The responder performs the key encapsulation operation of the quantum-resistant key encapsulation algorithm, which is expressed as: (ct,ss) = PQC_Enc(PK PQCe _i);
[0034] Among them, PQC_Enc() represents the key encapsulation operation of the quantum-resistant key encapsulation algorithm, ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm, and ss represents the quantum-resistant temporary shared key.
[0035] Furthermore, the responder obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_i from the initiator's encryption certificate, and the constructed mixed key exchange parameters are expressed as: MixXCHr=XCHr||ct;
[0036] Where XCHr=Asymmetric_Enc(skr, pub_enc_i)||Symmetric_Enc(Nr,skr)||Symmetric_Enc(IDr,skr);
[0037] MixXCHr represents the mixed key exchange parameters constructed by the responder, XCHr represents the national secret IPSec key exchange parameters of the responder, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, skr represents the national secret symmetric algorithm key randomly selected by the responder, pub_enc_i represents the national secret asymmetric algorithm encryption public key of the initiator, which is extracted from the encryption certificate of the initiator's mixed signature, Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Nr represents the random number of the responder, IDr represents the identity of the responder, and ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm.
[0038] Furthermore, the mixed signature constructed by the responder is expressed as: MixSIGr=SIGr||SIG PQC _r, where, SIGr=Asymmetric_Sign(mr, priv_sig_r), SIG PQC _r = PQC_Sign(mr,SK PQCs_r), mr=skr||Nr||IDr||MixCERT_enc_r||ct;
[0039] MixSIGr represents the mixed signature constructed by the responder, SIGr represents the national secret IPSec signature of the responder, SIG PQC _r represents the responder's quantum-resistant signature, mr represents the responder's message to be signed, priv_sig_r represents the responder's national secret asymmetric algorithm signature private key, SK PQCs _r represents the responder's quantum-resistant signature private key, skr represents the national secret symmetric algorithm key randomly selected by the responder, Nr represents the responder's random number, IDr represents the responder's identity, and MixCERT_enc_r represents the responder's mixed signature encryption certificate.
[0040] Furthermore, the process of the initiator decrypting the hybrid key exchange parameters of the responder includes:
[0041] The initiator extracts the national secret IPSec key exchange parameter XCHr from the responder's mixed key exchange parameter MixXCHr, uses its own national secret asymmetric algorithm encryption private key priv_enc_i to decrypt the national secret asymmetric algorithm encrypted part of XCHr, obtains the national secret symmetric algorithm key skr randomly selected by the responder, uses skr to decrypt the national secret symmetric algorithm encrypted part of XCHr, and obtains the initiator's random number Nr and identity identifier IDr;
[0042] The process of the initiator verifying the responder's hybrid signature includes:
[0043] Extract the quantum-resistant key encapsulation algorithm temporary ciphertext ct from the responder's hybrid key exchange parameters, and use the decrypted parameters to reconstruct the responder's message to be signed mr=skr||Nr||IDr||MixCERT_enc_r||ct;
[0044] Extract the responder's national secret asymmetric algorithm signature public key pub_sig_r and the responder's quantum-resistant signature public key PK from the responder's hybrid signature certificate PQCs _r, and extract the national secret IPSec signature SIGr and the anti-quantum signature SIG from the responder's hybrid signature PQC _r;
[0045] Use mr and pub_sig_r to verify the validity of the signature SIGr, and use mr and PK PQCs _r for signature SIG PQC The validity of _r is verified. Only when both signatures are verified at the same time can the subsequent steps be continued. Otherwise, the initiator terminates the connection.
[0046] The key decapsulation operation of the quantum-resistant key encapsulation algorithm performed by the initiator is: ss = PQC_Dec(ct,SK PQCe _i);
[0047] Among them, PQC_Dec() represents the key decapsulation operation of the quantum-resistant key encapsulation algorithm, and ss is the quantum-resistant temporary shared key.
[0048] Furthermore, the process for the initiator and responder to generate their respective mixed key parameters is as follows:
[0049] The initiator and responder generate the basic key parameter SKEYID according to the GM / T0022-2014 Chinese IPSec protocol steps, and generate the mixed key parameter MixSKEYID=SKEYID||ss based on the quantum-resistant temporary shared key ss;
[0050] MixSKEYID represents the mixed key parameter, and the key derivation step parameters of subsequent GM / T0022-2014 are completely based on this mixed key parameter.
[0051] It can be seen from the above technical solutions that compared with the prior art, the present invention has the following beneficial effects:
[0052] 1. By introducing quantum-resistant key encapsulation and quantum-resistant signature into the national secret IPSec protocol, this invention not only significantly improves the system's ability to resist quantum attacks, but also provides reliable security protection in the current and future quantum computing environments. It can be used in cryptographic products such as cryptographic cards, cryptographic machines, gateways, CAs, etc. to resist the threat of quantum attacks.
[0053] 2. By introducing a dual protection mechanism, this invention ensures a smooth transition and high-level security as quantum computing technology matures and becomes more widespread. This approach provides a practical solution for information security, with significant application value and potential for widespread adoption. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0055] Figure 1 This is a flowchart of the national secret IPSec secure communication method that supports quantum-resistant cryptography provided by the present invention. DETAILED DESCRIPTION
[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0057] like Figure 1 As shown, the embodiment of the present invention discloses a national secret IPSec secure communication method supporting quantum-resistant cryptography, including:
[0058] S1. After receiving the security association payload sent by the initiator, the responder sends the signature certificate and encryption certificate of the hybrid signature with both quantum-resistant signature and national secret algorithm that it has applied for in advance to the initiator;
[0059] S2. The initiator uses the root certificate to verify the responder's hybrid signature dual certificate and generate a temporary key for the quantum-resistant key encapsulation algorithm;
[0060] S3. The initiator constructs the hybrid key exchange parameters and hybrid signature based on the quantum-resistant key encapsulation algorithm temporary key and sends them to the responder.
[0061] S4. The responder extracts the signature certificate and encryption certificate of the hybrid signature that the initiator pre-applied for from the hybrid key exchange parameters, which have both a quantum-resistant signature and a national secret signature, and verifies the initiator's hybrid signature dual certificates using the root certificate.
[0062] Decrypt the hybrid key exchange parameters constructed by the initiator to obtain the initiator's exchange data;
[0063] Verify the initiator's hybrid signature;
[0064] Perform the key encapsulation operation of the quantum-resistant key encapsulation algorithm to obtain the temporary ciphertext and the quantum-resistant temporary shared key ss;
[0065] S5. The responder constructs the hybrid key exchange parameters and hybrid signature based on the temporary ciphertext and sends them to the initiator.
[0066] S6. The initiator decrypts the responder's hybrid key exchange parameters to obtain the responder's exchange data; verifies the responder's hybrid signature; performs a key decapsulation operation using the quantum-resistant key encapsulation algorithm to obtain the quantum-resistant temporary shared key ss;
[0067] S7. The initiator and the responder both generate their own hybrid key parameters based on the quantum-resistant temporary shared key ss, and perform subsequent key derivation based on their own hybrid key parameters.
[0068] The above steps are further explained below.
[0069] S1. After receiving the security association payload sent by the initiator, the responder sends the signature certificate MixCERT_sig_r with a hybrid signature that includes both quantum-resistant signature and national secret signature, and the encryption certificate MixCERT_enc_r with the hybrid signature to the initiator.
[0070] S2. The initiator verifies the responder's hybrid signature dual certificate. The specific verification process is as follows:
[0071] The initiator first uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the responder's signature certificate, and uses the root certificate's anti-quantum signature public key to verify the responder's signature certificate's anti-quantum signature; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator will terminate the connection; then the national secret asymmetric algorithm signature public key in the root certificate will be used to verify the national secret signature of the responder's encryption certificate, and the root certificate's anti-quantum signature public key will be used to verify the responder's encryption certificate's anti-quantum signature; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator will terminate the connection;
[0072] Afterwards, the initiator obtains the quantum key encapsulation algorithm temporary key (PK PQCe _i, SK PQCe _i), where PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, SK PQCe _i represents the temporary private key of the quantum-resistant key encapsulation algorithm.
[0073] S3. The initiator constructs the mixed key exchange parameters MixXCHi and the mixed signature MixSIGi and sends them to the responder.
[0074] Specifically, the initiator obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_r from the responder's encryption certificate, and the constructed mixed key exchange parameters are expressed as: MixXCHi=XCHi||PK PQCe _i, where
[0075] Among them, MixXCHi represents the mixed key exchange parameters constructed by the initiator, XCHi represents the national secret IPSec key exchange parameters of the initiator, || represents the link symbol, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, ski represents the national secret symmetric algorithm key randomly selected by the initiator, pub_enc_r represents the national secret asymmetric algorithm encryption public key of the responder, which is extracted from the encryption certificate of the responder's mixed signature, Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Ni represents the random number of the initiator, IDi represents the identity of the initiator, PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, MixCERT_sig_i represents the initiator's hybrid signature signing certificate, and MixCERT_enc_i represents the initiator's hybrid signature encryption certificate.
[0076] The mixed signature constructed by the initiator is expressed as: MixSIGi=SIGi||SIG PQC _i, where SIGi=Asymmetric_Sign(mi, priv_sig_i), SIG PQC _i = PQC_Sign(mi,SK PQCs _i), mi=ski||Ni||IDi||MixCERT_enc_i||PK PQCe _i;
[0077] Among them, SIGi represents the national secret IPSec signature of the initiator, SIG PQC _i represents the initiator's anti-quantum signature, MixSIGi represents the mixed signature constructed by the initiator; Asymmetric_Sign() represents the national secret asymmetric algorithm signature operation, PQC_Sign represents the anti-quantum signature operation, mi represents the initiator's message to be signed, priv_sig_i represents the initiator's national secret asymmetric algorithm signature private key, SK PQCs _i represents the initiator's quantum-resistant signature private key, ski represents the national secret symmetric algorithm key randomly selected by the initiator, Ni represents the initiator's random number, IDi represents the initiator's identity, MixCERT_enc_i represents the signature certificate of the initiator's mixed signature; PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key.
[0078] S4. The responder verifies the initiator's hybrid signature dual certificates. Specifically, it extracts the signature certificate MixCERT_sig_i and the encryption certificate MixCERT_enc_i of the hybrid signature, which are pre-applied by the initiator and have both anti-quantum signature and national secret signature, from the hybrid key exchange parameters. First, the national secret signature of the initiator's signature certificate is verified using the national secret asymmetric algorithm signature public key in the root certificate, and the anti-quantum signature public key of the root certificate is used to verify the anti-quantum signature of the initiator's signature certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder will terminate the connection. Then, the national secret signature of the initiator's encryption certificate is verified using the national secret asymmetric algorithm signature public key in the root certificate, and the anti-quantum signature public key of the root certificate is used to verify the anti-quantum signature of the initiator's encryption certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder will terminate the connection.
[0079] Afterwards, the responder extracts the national secret IPSec key exchange parameter XCHi from the initiator's mixed key exchange parameter MixXCHi, uses its own national secret asymmetric algorithm encryption private key priv_enc_r to decrypt the national secret asymmetric algorithm encrypted part of XCHi, obtains the initiator's national secret symmetric algorithm key ski, uses ski to decrypt the national secret symmetric algorithm encrypted part of XCHi, and obtains the initiator's random number Ni and identity identifier IDi.
[0080] Then, the responder first extracts the initiator's quantum-resistant key encapsulation algorithm temporary public key PK from the initiator's hybrid key exchange parameters. PQCe _i, use the decrypted parameters to reconstruct the initiator's message to be signed mi = ski||Ni||IDi||MixCERT_enc_i||PK PQCe _i; then obtain the initiator's national secret asymmetric algorithm signature public key pub_sig_i and the initiator's quantum-resistant signature public key PK from the initiator's hybrid signature certificate PQCs _i, and extract the national secret IPSec signature SIGi and anti-quantum signature SIG from the initiator's hybrid signature PQC _i; then use mi and pub_sig_i to verify the validity of the signature SIGi, and use mi and PK PQCs _i for signature SIG PQC The validity of _i is verified, and only when both signatures are verified at the same time can the subsequent steps be continued.
[0081] The responder performs the key encapsulation operation of the quantum-resistant key encapsulation algorithm, which is expressed as: (ct,ss) = PQC_Enc(PK PQCe _i);
[0082] Among them, PQC_Enc() represents the key encapsulation operation of the quantum-resistant key encapsulation algorithm, ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm, and ss represents the quantum-resistant temporary shared key.
[0083] S5. The responder constructs the mixed key exchange parameter MixXCHr and the mixed signature MixSIGr and sends them to the initiator.
[0084] Specifically, the responder obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_i from the initiator's encryption certificate, and constructs the mixed key exchange parameter as follows: MixXCHr=XCHr||ct, where XCHr=Asymmetric_Enc(skr,pub_enc_i)||Symmetric_Enc(Nr,skr)||Symmetric_Enc(IDr,skr);
[0085] Among them, MixXCHr represents the mixed key exchange parameters constructed by the responder, XCHr represents the national secret IPSec key exchange parameters of the responder, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, skr represents the national secret symmetric algorithm key randomly selected by the responder, pub_enc_i represents the national secret asymmetric algorithm encryption public key of the initiator, which is extracted from the encryption certificate of the initiator's mixed signature, Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Nr represents the random number of the responder, IDr represents the identity of the responder, and ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm.
[0086] The mixed signature constructed by the responder is expressed as: MixSIGr=SIGr||SIG PQC _r, where, SIGr=Asymmetric_Sign(mr, priv_sig_r), SIG PQC _r = PQC_Sign(mr,SK PQCs _r), mr=skr||Nr||IDr||MixCERT_enc_r||ct;
[0087] MixSIGr represents the mixed signature constructed by the responder, SIGr represents the national secret IPSec signature of the responder, SIG PQC _r represents the responder's quantum-resistant signature, mr represents the responder's message to be signed, priv_sig_r represents the responder's national secret asymmetric algorithm signature private key, SK PQCs_r represents the responder's quantum-resistant signature private key, skr represents the national secret symmetric algorithm key randomly selected by the responder, Nr represents the responder's random number, IDr represents the responder's identity, and MixCERT_enc_r represents the responder's mixed signature encryption certificate.
[0088] S6. The initiator extracts the national secret IPSec key exchange parameter XCHr from the responder's mixed key exchange parameter MixXCHr, uses its own national secret asymmetric algorithm encryption private key priv_enc_i to decrypt the national secret asymmetric algorithm encrypted portion of XCHr, obtains the national secret symmetric algorithm key skr randomly selected by the responder, uses skr to decrypt the national secret symmetric algorithm encrypted portion of XCHr, and obtains the initiator's random number Nr and identity identifier IDr;
[0089] Afterwards, the initiator first extracts the quantum-resistant key encapsulation algorithm temporary ciphertext ct from the responder's hybrid key exchange parameters, and uses the decrypted parameters to reconstruct the responder's message to be signed mr=skr||Nr||IDr||MixCERT_enc_r||ct; then extracts the responder's national secret asymmetric algorithm signature public key pub_sig_r and the responder's quantum-resistant signature public key PK from the responder's hybrid signature certificate. PQCs _r, and extract the national secret IPSec signature SIGr and the anti-quantum signature SIG from the responder's hybrid signature PQC _r; then use mr and pub_sig_r to verify the validity of the signature SIGr, and use mr and PK PQCs _r for signature SIG PQC The validity of _r is verified. Only when both signatures are verified at the same time can the subsequent steps be continued; otherwise, the initiator terminates the connection.
[0090] Then, the key decapsulation operation of the quantum-resistant key encapsulation algorithm ss = PQC_Dec(ct,SK PQCe _i);
[0091] Among them, PQC_Dec() represents the quantum-resistant key decapsulation operation, and ss is the quantum-resistant temporary shared key.
[0092] S7. The initiator and responder generate the basic key parameter SKEYID according to the GM / T0022-2014 Chinese IPSec protocol steps, and generate the mixed key parameter MixSKEYID=SKEYID||ss based on the quantum-resistant temporary shared key ss. Subsequent keys of the initiator and responder are all derived based on the mixed key parameter MixSKEYID.
[0093] Next, the method of the present invention is described using the quantum-resistant signature algorithm Dilithium, the quantum-resistant key encapsulation algorithm Kyber, the national secret asymmetric signature algorithm SM2, the national secret asymmetric encryption algorithm SM2, and the national secret symmetric algorithm SM4 as examples. The initiator and responder have already applied for their own hybrid signature signing certificate, hybrid signature encryption certificate, quantum-resistant signature key, national secret asymmetric algorithm signing key, and national secret asymmetric algorithm encryption key in advance, and the root certificate has been pre-installed in the operating systems of the initiator and responder. The above-mentioned hybrid signature refers to the Dilithium signature first, and then the SM2 signature on the message to be signed in the certificate.
[0094] The specific steps include:
[0095] S1. After receiving the security association payload sent by the initiator, the responder sends the signature certificate MixCERT_sig_r with a mixed signature of both the quantum-resistant Dilithium signature and the national secret SM2 signature, and the encryption certificate MixCERT_enc_r with the mixed signature to the initiator.
[0096] S2. The initiator verifies the responder's hybrid signature dual certificate. The specific steps are as follows: the initiator first uses the national secret asymmetric algorithm SM2 signature public key in the root certificate to verify the national secret signature of the responder's signature certificate, and uses the root certificate's anti-quantum Dilithium signature public key to verify the responder's signature certificate's anti-quantum signature; only when both signatures are verified, the subsequent steps will be continued, otherwise the initiator will interrupt the connection; then the national secret asymmetric algorithm SM2 signature public key in the root certificate is used to verify the national secret signature of the responder's encryption certificate, and the root certificate's anti-quantum Dilithium signature public key is used to verify the responder's encryption certificate's anti-quantum signature; only when both signatures are verified, the subsequent steps will be continued, otherwise the initiator will interrupt the connection; then the key generation operation of the anti-quantum key encapsulation algorithm kyber is performed to obtain the anti-quantum key encapsulation algorithm temporary key (PK Kyber _i, SK Kyber _i).
[0097] Among them, PK Kyber _i represents the initiator's quantum-resistant key encapsulation algorithm Kyber temporary public key, SK Kyber _i represents the Kyber temporary private key of the quantum-resistant key encapsulation algorithm.
[0098] S3. The initiator constructs the mixed key exchange parameter MixXCHi=XCHi||PK Kyber _i and mixed signature MixSIGi=SIG SM2 i||SIG Dilithium _i, and sent to the responder. Among them, XCHi=SM2_Enc(ski, pubSM2 _enc_r)||SM4_Enc(Ni,ski)||SM4_Enc(IDi,ski)||MixCERT_sig_i|| MixCERT_enc_i,SIG SM2 i=SM2_Sign(mi,priv SM2 _sig_i), SIG Dilithium _i = Dilithium_Sign(mi,SK Dilithium _i), mi=ski||Ni||IDi||MixCERT_enc_i||PK Kyber _i.
[0099] Among them, XCHi represents the initiator's national secret IPSec key exchange parameters, || represents the link symbol, PK Kyber _i represents the initiator's quantum-resistant key encapsulation algorithm Kyber temporary public key, MixXCHi represents the hybrid key exchange parameters constructed by the initiator, SIG SM2 i represents the initiator's national secret IPSec SM2 signature, SIG Dilithium _i represents the initiator's quantum-resistant Dilithium signature, MixSIGi represents the mixed signature constructed by the initiator, SM2_Enc represents the encryption operation of the national secret asymmetric algorithm SM2, SM4_Enc represents the encryption operation of the national secret symmetric algorithm SM4, pub SM2 _enc_r represents the responder's national secret asymmetric algorithm SM2 encryption public key, which is extracted from the responder's hybrid signature encryption certificate. SM2_Sign() represents the national secret asymmetric algorithm SM2 signature operation. Dilithium_Sign represents the quantum-resistant Dilithium signature operation. mi represents the initiator's message to be signed. priv SM2 _sig_i represents the initiator's national secret asymmetric algorithm SM2 signature private key, SK Dilithium _i represents the initiator's quantum-resistant Dilithium signature private key, ski represents the symmetric key randomly selected by the initiator, Ni represents the initiator's random number, IDi represents the initiator's identity, MixCERT_sig_i represents the initiator's hybrid signature signature certificate, and MixCERT_enc_i represents the initiator's hybrid signature encryption certificate.
[0100] S4. The responder verifies the initiator's hybrid signature dual certificate. The specific steps are as follows:
[0101] First, the signature certificate MixCERT_sig_i and the encryption certificate MixCERT_enc_i of the mixed signature, which are pre-applied by the initiator and have both the quantum-resistant Dilithium signature and the national secret SM2 signature, are extracted from the hybrid key exchange parameters. First, the national secret SM2 signature of the initiator's signature certificate is verified using the national secret asymmetric algorithm SM2 signature public key in the root certificate, and the quantum-resistant Dilithium signature of the initiator's signature certificate is verified using the root certificate's quantum-resistant Dilithium signature public key; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder will terminate the connection; then the national secret asymmetric algorithm SM2 signature public key in the root certificate will be used to verify the national secret SM2 signature of the initiator's encryption certificate, and the quantum-resistant Dilithium signature public key of the root certificate will be used to verify the initiator's encryption certificate; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder will terminate the connection.
[0102] Afterwards, the national secret IPSec key exchange parameter XCHi is extracted from the initiator's mixed key exchange parameter MixXCHi, and the private key priv is encrypted using its own national secret asymmetric algorithm SM2 SM2 _enc_r decrypts the encrypted part of XCHi's national secret asymmetric algorithm SM2, obtains the national secret symmetric algorithm key ski randomly selected by the initiator, uses ski to decrypt the encrypted part of XCHi's national secret symmetric algorithm SM4, and obtains the initiator's random number Ni and identity identifier IDi.
[0103] Then, the initiator's quantum-resistant key encapsulation algorithm Kyber temporary public key PK is extracted from the initiator's hybrid key exchange parameters. Kyber _i, use the decrypted parameters to reconstruct the initiator's message to be signed mi = ski||Ni||IDi||MixCERT_enc_i||PK Kyber _i; then obtain the initiator's national secret asymmetric algorithm SM2 signature public key pub from the initiator's hybrid signature certificate SM2 _sig_i and the initiator's quantum-resistant Dilithium signature public key PK Dilithium _i, and extract the SM2 signature SIG of the national secret IPSec from the hybrid signature of the initiator SM2 i and quantum-resistant signatures SIG Dilithium _i; then use mi, pub SM2 _sig_i for signature SIG SM2 The validity of i is verified by using mi, PK Dilithium _i for signature SIG DilithiumThe validity of _i is verified. Only when both signatures are verified at the same time, the subsequent steps will be continued. The responder performs the key encapsulation operation of the quantum-resistant key encapsulation algorithm (ct,ss) = Kyber_Enc(PK Kyber _i), and obtain the temporary ciphertext ct and the quantum-resistant temporary shared key ss.
[0104] Among them, Kyber_Enc() represents the key encapsulation operation of quantum-resistant Kyber, ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm, and ss represents the quantum-resistant temporary shared key.
[0105] S5. The responder constructs the mixed key exchange parameters MixXCHr=XCHr||ct and the mixed signature MixSIGr=SIG SM2 r||SIG Dilithium _r, and send it to the initiator. Among them, XCHr=SM2_Enc(skr, pub SM2 _enc_i)||SM4_Enc(Nr,skr)||SM4_Enc(IDr,skr),SIG SM2 r=SM2_Sign(mr,priv SM2 _sig_r), SIG Dilithium _r=Dilithium_Sign(mr,SK Dilithium _r), mr=skr||Nr||IDr||MixCERT_enc_r||ct.
[0106] Among them, XCHr represents the responder's national secret IPSec key exchange parameter, MixXCHr represents the mixed key exchange parameter constructed by the responder, SIG SM2 r represents the responder's national secret IPSec SM2 signature, SIG Dilithium _r represents the quantum-resistant Dilithium signature of the responder, MixSIGr represents the mixed signature constructed by the responder, SM2_Enc represents the encryption operation of the national secret asymmetric algorithm SM2, SM4_Enc represents the encryption operation of the national secret symmetric algorithm SM4, pub SM2 _enc_i represents the initiator's national secret asymmetric algorithm SM2 encryption public key, which is extracted from the initiator's hybrid signature encryption certificate, mr represents the responder's message to be signed, priv SM2 _sig_r represents the responder's national secret asymmetric algorithm SM2 signature private key, SK Dilithium_r represents the responder's quantum-resistant Dilithium signature private key, skr represents the national secret symmetric algorithm key randomly selected by the responder, Nr represents the responder's random number, IDr represents the responder's identity, and MixCERT_enc_r represents the responder's mixed signature encryption certificate.
[0107] S6. The initiator extracts the national secret IPSec key exchange parameter XCHr from the responder's mixed key exchange parameter MixXCHr, and uses its own national secret asymmetric algorithm SM2 to encrypt the private key priv SM2 _enc_i decrypts the encrypted part of XCHr using the national secret asymmetric algorithm SM2, obtains the national secret symmetric algorithm key skr randomly selected by the responder, uses skr to decrypt the encrypted part of XCHr using the national secret symmetric algorithm SM4, and obtains the initiator's random number Nr and identity identifier IDr.
[0108] Then, the quantum-resistant key encapsulation algorithm temporary ciphertext ct is extracted from the responder's hybrid key exchange parameters, and the decrypted parameters are used to reconstruct the responder's message to be signed mr = skr||Nr||IDr||MixCERT_enc_r||ct; then the responder's national secret asymmetric algorithm SM2 signature public key pub is obtained from the responder's hybrid signature certificate. SM2 _sig_r and the initiator's quantum-resistant Dilithium signature public key PK Dilithium _r, and extract the SM2 signature SIG of the national secret IPSec from the hybrid signature of the responder SM2 r and quantum-resistant signatures SIG Dilithium _r.
[0109] Then use mr, pub SM2 _sig_r for signature SIG SM2 The effectiveness of r was verified by using mr, PK Dilithium _r for signature SIG Dilithium The validity of _r is verified. Only when both signatures are verified at the same time, the subsequent steps will be continued. Otherwise, the initiator will terminate the connection. Then the key decapsulation operation ss= Kyber_Dec(ct, SK Kyber _i), and obtain the quantum-resistant temporary shared key ss.
[0110] Among them, Kyber_Dec() represents the quantum-resistant Kyber key decapsulation operation.
[0111] S7. The initiator and responder generate the basic key parameter SKEYID according to the GM / T0022-2014 Chinese IPSec protocol steps, and generate the mixed key parameter MixSKEYID=SKEYID||ss based on the quantum-resistant temporary shared key ss. The subsequent keys of the initiator and responder are all derived based on MixSKEYID.
[0112] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0113] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A national secret IPSec secure communication method supporting quantum-resistant cryptography, characterized in that: include: After receiving the security association payload sent by the initiator, the responder sends its pre-applied signature certificate with a hybrid signature of both quantum-resistant signature and national secret signature, and the encryption certificate of the hybrid signature to the initiator; The initiator uses the root certificate to verify the responder's hybrid signature dual certificate and generate a temporary key for the quantum-resistant key encapsulation algorithm; The initiator constructs the hybrid key exchange parameters and hybrid signature based on the quantum-resistant key encapsulation algorithm temporary key and sends them to the responder; The responder extracts the signature certificate and encryption certificate of the hybrid signature that the initiator pre-applied for from the hybrid key exchange parameters. The hybrid signature certificate has both quantum-resistant signature and national secret signature, and the encryption certificate of the hybrid signature. The responder uses the root certificate to verify the initiator's hybrid signature dual certificates. Decrypt the encrypted part of the hybrid key exchange parameters constructed by the initiator to obtain the initiator's exchange data; verify the initiator's hybrid signature; perform quantum-resistant key encapsulation operations to obtain temporary ciphertext and quantum-resistant temporary shared key ss; The responder constructs the hybrid key exchange parameters and hybrid signature based on the temporary ciphertext and sends them to the initiator; The initiator decrypts the responder's hybrid key exchange parameters to obtain the responder's exchange data; verifies the responder's hybrid signature; performs quantum-resistant key decapsulation to obtain the quantum-resistant temporary shared key ss; The initiator and responder both generate their own hybrid key parameters based on the quantum-resistant temporary shared key ss, and perform subsequent key derivation based on their own hybrid key parameters; The process for the initiator and responder to generate their respective mixed key parameters is as follows: The initiator and responder generate the basic key parameter SKEYID according to the national secret IPSec protocol, and generate the mixed key parameter MixSKEYID = SKEYID || ss according to the quantum-resistant temporary shared key ss; MixSKEYID represents the mixed key parameter.
2. The method for secure communication with national secret IPSec supporting quantum-resistant cryptography according to claim 1, characterized in that: The process by which the initiator verifies the responder's hybrid signature dual certificate includes: The initiator uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the responder's signature certificate, and uses the quantum-resistant signature public key in the root certificate to verify the quantum-resistant signature of the responder's signature certificate; only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator terminates the connection; The initiator uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the responder's encryption certificate, and uses the quantum-resistant signature public key of the root certificate to verify the quantum-resistant signature of the responder's encryption certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the initiator terminates the connection. The process by which the responder verifies the initiator's hybrid signature dual certificate includes: The responder extracts the signature certificate and the encryption certificate of the hybrid signature pre-applied by the initiator from the hybrid key exchange parameters. The signature certificate has a hybrid signature of both the quantum-resistant signature and the national secret signature, and the hybrid signature is used to verify the national secret signature of the initiator's signature certificate using the national secret asymmetric algorithm signature public key in the root certificate, and the quantum-resistant signature of the initiator's signature certificate using the quantum-resistant signature public key in the root certificate. Only when both signatures are verified successfully will the subsequent steps be continued, otherwise the responder terminates the connection. The responder uses the national secret asymmetric algorithm signature public key in the root certificate to verify the national secret signature of the initiator's encryption certificate, and uses the root certificate's quantum-resistant signature public key to verify the initiator's quantum-resistant signature; only when both signatures are verified will the subsequent steps be continued, otherwise the responder terminates the connection.
3. The method for secure communication with national secret IPSec supporting quantum cryptography according to claim 1, characterized in that: The initiator obtains the quantum key encapsulation algorithm temporary key (PK) by executing the key generation operation of the quantum key encapsulation algorithm. PQCe _i,SK PQCe _i), where PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, SK PQCe _i represents the temporary private key of the quantum-resistant key encapsulation algorithm.
4. The method for secure communication with national secret IPSec supporting quantum cryptography according to claim 1, characterized in that: The initiator obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_r from the responder's encryption certificate and constructs the mixed key exchange parameters, which are expressed as: MixXCHi=XCHi||PK PQCe _i; Where, XCHi=Asymmetric_Enc(ski, pub_enc_r)||Symmetric_Enc(Ni,ski)||Symmetric_Enc(IDi,ski)||MixCERT_sig_i||MixCERT_enc_i; MixXCHi represents the mixed key exchange parameters constructed by the initiator, XCHi represents the national secret IPSec key exchange parameters of the initiator, || represents the link symbol, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, ski represents the national secret symmetric algorithm key randomly selected by the initiator; pub_enc_r represents the national secret asymmetric algorithm encryption public key of the responder, which is extracted from the encryption certificate of the responder's mixed signature; Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Ni represents the random number of the initiator, IDi represents the identity of the initiator, PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key, MixCERT_sig_i represents the initiator's hybrid signature signing certificate, and MixCERT_enc_i represents the initiator's hybrid signature encryption certificate.
5. The method for secure communication of national secret IPSec supporting quantum-resistant cryptography according to claim 4, characterized in that: The mixed signature constructed by the initiator is expressed as: MixSIGi=SIGi||SIG PQC _i; Among them, SIGi = Asymmetric_Sign(mi, priv_sig_i), SIG PQC _i=PQC_Sign(mi,SK PQCs _i),mi=ski||Ni||IDi||MixCERT_enc_i||PK PQCe _in; SIGi represents the national secret IPSec signature of the initiator, SIG PQC _i represents the initiator's anti-quantum signature, MixSIGi represents the mixed signature constructed by the initiator; Asymmetric_Sign() represents the national secret asymmetric algorithm signature operation, PQC_Sign represents the anti-quantum signature operation, mi represents the initiator's message to be signed, priv_sig_i represents the initiator's national secret asymmetric algorithm signature private key, SK PQCs _i represents the initiator's quantum-resistant signature private key, ski represents the national secret symmetric algorithm key randomly selected by the initiator, Ni represents the initiator's random number, IDi represents the initiator's identity, MixCERT_enc_i represents the initiator's mixed signature encryption certificate; PK PQCe _i represents the initiator's quantum-resistant key encapsulation algorithm temporary public key.
6. The method for secure communication with national secret IPSec supporting quantum-resistant cryptography according to claim 5, characterized in that: The process by which the responder decrypts the hybrid key exchange parameters constructed by the initiator includes: The responder extracts the national secret IPSec key exchange parameter XCHi from the initiator's mixed key exchange parameter MixXCHi, uses its own national secret asymmetric algorithm encryption private key priv_enc_r to decrypt the national secret asymmetric algorithm encrypted part of XCHi, obtains the national secret symmetric algorithm key ski randomly selected by the initiator, uses ski to decrypt the national secret symmetric algorithm encrypted part of XCHi, and obtains the initiator's random number Ni and identity identifier IDi; The process by which the responder verifies the hybrid signature constructed by the initiator includes: Extract the initiator's quantum-resistant key encapsulation algorithm temporary public key PK from the initiator's hybrid key exchange parameters PQCe _i, reconstruct the initiator's message to be signed mi= ski||Ni||IDi||MixCERT_enc_i||PK PQCe _is; Obtain the initiator's national secret asymmetric algorithm signature public key pub_sig_i and the initiator's quantum-resistant signature public key PK from the initiator's hybrid signature certificate PQCs _i, and extract the national secret IPSec signature SIGi and anti-quantum signature SIG from the initiator's hybrid signature PQC _i; Use mi and pub_sig_i to verify the validity of the signature SIGi, and use mi and PK PQCs _i for signature SIG PQC The validity of _i is verified. Only when both signatures are verified at the same time can the subsequent steps be continued. Otherwise, the responder terminates the connection; The key encapsulation operation of the quantum-resistant key encapsulation algorithm performed by the responder is expressed as: (ct, ss) = PQC_Enc(PK PQCe _i); Among them, PQC_Enc() represents the key encapsulation operation of the quantum-resistant key encapsulation algorithm, ct represents the temporary ciphertext of the quantum-resistant key encapsulation algorithm, and ss represents the quantum-resistant temporary shared key.
7. The method for secure communication with national secret IPSec supporting quantum-resistant cryptography according to claim 1, characterized in that: The responder obtains the national cryptographic asymmetric algorithm encryption public key pub_enc_i from the initiator's encryption certificate, and the constructed mixed key exchange parameters are expressed as: MixXCHr = XCHr||ct; Where XCHr=Asymmetric_Enc(skr, pub_enc_i)||Symmetric_Enc(Nr,skr)||Symmetric_Enc(IDr,skr); MixXCHr represents the mixed key exchange parameters constructed by the responder, XCHr represents the responder's national secret IPSec key exchange parameters, Asymmetric_Enc() represents the national secret asymmetric algorithm encryption operation, skr represents the national secret symmetric algorithm key randomly selected by the responder, pub_enc_i represents the initiator's national secret asymmetric algorithm encryption public key, which is extracted from the initiator's mixed signature encryption certificate; Symmetric_Enc represents the national secret symmetric algorithm encryption operation, Nr represents the responder's random number, IDr represents the responder's identity, and ct represents the quantum-resistant key encapsulation algorithm temporary ciphertext.
8. The method for secure communication with national secret IPSec supporting quantum cryptography according to claim 7, characterized in that: The mixed signature constructed by the responder is expressed as: MixSIGr = SIGr || SIG PQC _r; Where, SIGr = Asymmetric_Sign(mr, priv_sig_r), SIG PQC _r=PQC_Sign(mr,SK PQCs _r),mr=skr||Nr||IDr||MixCERT_enc_r||ct; MixSIGr represents the mixed signature constructed by the responder, SIGr represents the national secret IPSec signature of the responder, SIG PQC _r represents the responder's quantum-resistant signature, mr represents the responder's message to be signed, priv_sig_r represents the responder's national secret asymmetric algorithm signature private key, SK PQCs _r represents the responder's quantum-resistant signature private key, skr represents the national secret symmetric algorithm key randomly selected by the responder, Nr represents the responder's random number, IDr represents the responder's identity, and MixCERT_enc_r represents the responder's mixed signature encryption certificate.
9. The method for secure communication with national secret IPSec supporting quantum cryptography according to claim 8, characterized in that: The process by which the initiator decrypts the responder's hybrid key exchange parameters includes: The initiator extracts the national secret IPSec key exchange parameter XCHr from the responder's mixed key exchange parameter MixXCHr, uses its own national secret asymmetric algorithm encryption private key priv_enc_i to decrypt the national secret asymmetric algorithm encrypted part of XCHr, obtains the national secret symmetric algorithm key skr randomly selected by the responder, uses skr to decrypt the national secret symmetric algorithm encrypted part of XCHr, and obtains the initiator's random number Nr and identity identifier IDr; The process of the initiator verifying the responder's hybrid signature includes: Extract the quantum-resistant key encapsulation algorithm temporary ciphertext ct from the responder's hybrid key exchange parameters, and reconstruct the responder's to-be-signed message mr = skr||Nr||IDr||MixCERT_enc_r||ct; Extract the responder's national secret asymmetric algorithm signature public key pub_sig_r and the responder's quantum-resistant signature public key PK from the responder's hybrid signature certificate PQCs _r, and extract the national secret IPSec signature SIGr and the anti-quantum signature SIG from the responder's hybrid signature PQC _r; Use mr and pub_sig_r to verify the validity of the signature SIGr, and use mr and PK PQCs _r for signature SIG PQC The validity of _r is verified. Only when both signatures are verified at the same time can the subsequent steps be continued. Otherwise, the initiator terminates the connection. The key decapsulation operation of the quantum-resistant key encapsulation algorithm performed by the initiator is: ss = PQC_Dec(ct,SK PQCe _i); Among them, PQC_Dec() represents the key decapsulation operation of the quantum-resistant key encapsulation algorithm, and ss is the quantum-resistant temporary shared key.
Citation Information
Patent Citations
Certificate authentication system and authentication method based on post-quantum signature
CN116388986A
IND-CPA safe anti-quantum key packaging method and system
CN116684069A