A lightweight quantum digital signature and quantum signcryption method

By only performing the issuance and verification functions of signature certificates in the trusted CA center, the problem of quantum digital signature on the resource burden of CA certification center is solved, and the security of the signature process is ensured to prevent third parties from knowing communication data.

CN118784243BActive Publication Date: 2025-05-27MATRICTIME DIGITAL TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410935128.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2025-05-27
Estimated Expiration
2044-07-12

AI Technical Summary

Technical Problem

The existing quantum digital signature method poses a great resource burden on the CA certification center, and third parties may know the content of the document signed by both parties, affecting security.

Method used

The lightweight quantum digital signature method is adopted, and the issuance and verification functions of signature certificates are only performed in the trusted CA center, without storing the communication message content between users, and the security of the signature process is achieved through a one-time certificate.

Benefits of technology

Reduces load pressure on trusted CA centers, improves resource utilization, ensures the security of quantum digital signatures, and prevents third parties from knowing communication data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118784243B_ABST
    Figure CN118784243B_ABST
Patent Text Reader

Abstract

The present invention discloses a lightweight quantum digital signature and quantum digital signcryption method. The quantum digital signature method includes: user A generates a request req for performing a quantum digital signature on data M and sends the request req to a trusted CA center; user A registers in the trusted CA center and negotiates with the trusted CA center to generate and store a one-time certificate for signature; user A then signs the data M to generate a signature file M-SIGN; user A generates a transmission file DOC based on the signature file M-SIGN and sends it to user B, and user B performs a signature verification operation on the signature file M-SIGN in the transmission file DOC. User A of the present invention uses a signature certificate otCA, its own public CA certificate CA 1A etc. to sign the data M, realizing the binding of the transmitted data M to the identity of user A; and the communication data is only transmitted between users A and B, and no third party will receive the communication data, ensuring that the communication data will not be known to irrelevant third parties.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital signatures, and particularly to a lightweight quantum digital signature and quantum digital signcryption method. Background Art

[0002] Digital signature is an authentication method for message authenticity that emerged with the rapid development of social digitalization and informatization. It can verify whether a message has been tampered with during transmission, ensuring the integrity, authenticity, and non-repudiation of data transmission.

[0003] A digital signature method is proposed in Application No. 2022101851462. The method includes: the CA certification center registered by user A and the two communicating parties jointly form three participants in quantum signature to perform unconditionally secure quantum signature. Among them, the "one-time one identity" generated in the previous process needs to be added to the quantum signature to complete the complete quantum signature. Among them, the CA (Certificate Authority) certification center, as the signature verification party in the quantum signature process, needs to receive the file to be signed forwarded from user B, and the file contains the message content sent from user A to user B.

[0004] This message content may be relatively large. Then, during the verification process of the quantum signature by the CA certification center, a relatively large resource space needs to be reserved to receive and store this message content. Even more, when many users apply for the verification of quantum signatures simultaneously, a larger resource space is required to receive and store these message contents. However, for the CA certification center, these message contents are not sent to the CA certification center, that is, these message contents that occupy a large storage capacity are only used during the current verification process and are meaningless at other times. Therefore, the CA certification center's receiving of the message content of the communication between the two users for verification will cause a great resource burden on the CA certification center. Over time, it may affect the efficiency of the center. In addition, as the two users of the digital signature, they often do not want a third party to know the content of the signed file.

[0005] In view of this, how to reduce the resource burden of the CA certification center in the process of quantum digital signature, ensure the efficiency of the CA certification center, and at the same time ensure the security of quantum digital signature is a technical issue currently concerned in the industry. Summary of the Invention

[0006] Object of the Invention: The object of the present invention is to provide a lightweight quantum digital signature and quantum digital signcryption method, which solves the problem that the current quantum digital signature causes a great resource burden on the CA certification center, and also solves the problem that the security of the quantum digital signature is affected because a third party knows the files signed by both parties. The trusted CA center of the present invention only needs to execute the issuance of the signature certificate in the quantum digital signature process and provide the verification function of the signature certificate, without sharing its own storage resources to store the communication message content between users, reducing the load pressure on the trusted CA center and ensuring the security of the quantum digital signature.

[0007] Technical Solution: The present invention provides a lightweight quantum digital signature method, and the method includes the following steps:

[0008] (1) User A generates a request req for quantum digital signature of data M and sends the request req to the trusted CA center. The request req includes the serial number No of the quantum digital signature.

[0009] (2) User A registers in the trusted CA center, and then obtains and stores the public CA user certificate CA of user A from the trusted CA center 1A , the private CA user certificate CA 2A and the institutional information ca of the trusted CA center; then, user A negotiates with the trusted CA center to generate and store a one-time certificate for signature, that is, the first certificate otCA.

[0010] (3) User A uses the first certificate otCA, the serial number No, the public CA certificate CA of user A 1A and the institutional information ca of the trusted CA center to jointly sign the data M to generate a signature file M-SIGN.

[0011] (4) User A generates a transmission file DOC based on the signature file M-SIGN and sends it to user B; user B receives the transmission file DOC and performs a signature verification operation on the signature file M-SIGN in the transmission file DOC. If the verification passes, user B receives the data M in the signature file M-SIGN; otherwise, user B refuses to receive, and the quantum digital signature process ends.

[0012] Further, the specific process of user A negotiating with the trusted CA center to generate and store a one-time certificate for signature is as follows:

[0013] 1) User A obtains a group of keys u1 from the local key pool as random numbers for generating an irreducible polynomial p 1 (x), and then records the string composed of the coefficients of each term except the highest term in the irreducible polynomial p 1 (x) as str1.

[0014] 2) User A negotiates a set of keys (u2, u3, u4) with the trusted CA center, and then User A generates a hash function based on the irreducible polynomial p 1 (x) and the key u2 Using this hash function Calculate the first hash value of the privacy CA user certificate CA obtained locally from User A 2A to get XOR encrypt the hash value with the key u3 to obtain the first certificate

[0015] 3) User A encrypts the string str1 with the key u4 negotiated with the trusted CA center to obtain Then send the first certificate otCA and to the trusted CA center, that is, send to the trusted CA center; The trusted CA center receives and decrypts it using the negotiated keys (u3, u4) to obtain the second hash value and the string str1'; The trusted CA center uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the decrypted string str1' to generate an irreducible polynomial p' 1 (x), based on the irreducible polynomial p' 1 (x) and the key u2 to generate a hash function Using the hash function Calculate the third hash value of the privacy CA user certificate CA of User A obtained locally from the trusted CA center 2A to get

[0016] The trusted CA center compares the calculated third hash value with the decrypted second hash value If they are the same, the authentication passes. The trusted CA center stores the first certificate otCA, and at the same time stores the first certificate otCA in association with the serial number No in the request req, that is, stores (No, otCA); If they are not the same, the authentication fails, and User A and the trusted CA center renegotiate to generate a one-time certificate for signature.

[0017] Furthermore, the specific process of User A generating the transmission file DOC based on the signature file M-SIGN and sending it to User B is as follows:

[0018] First, User A obtains a set of keys v1 from the local key pool as random numbers for generating the irreducible polynomial p 2 (x). After obtaining the irreducible polynomial, the irreducible polynomial p 2The string formed by the coefficients of each term in (x) except the highest term is denoted as str2;

[0019] Next, user A negotiates a set of keys (v2, v3, v4) with user B. User A generates a hash function based on the irreducible polynomial p 2 (x) and the key v2 Using the hash function Calculate the hash value of the signature file M-SIGN to obtain Then encrypt the hash value and the string str2 respectively using the keys (v3, v4), and then generate the transmission file DOC.

[0020]

[0021] User A sends the transmission file DOC to user B.

[0022] Furthermore, the specific process for user B to receive the transmission file DOC and perform a signature verification operation on the signature file M-SIGN in the transmission file DOC is as follows:

[0023] S1: User B receives the transmission file DOC and uses the negotiated keys (v3, v4) to decrypt and in the transmission file DOC to obtain the decrypted hash value of the signature file and the string str2';

[0024] S2: User B addresses the trusted CA center based on the institutional information ca of the trusted CA center in the signature file M-SIGN in the received transmission file DOC and establishes a connection with the trusted CA center;

[0025] S3: User B negotiates a transmission key k1 with the trusted CA center. User B encrypts the serial number No and the first certificate otCA in the signature file M-SIGN in the received transmission file DOC using the transmission key k1 into ciphertext and sends it to the trusted CA center;

[0026] S4: The trusted CA center receives the ciphertext Decryption using the negotiation key k1 yields (No′, otCA′). The trusted CA center locates the locally stored serial number No based on the decrypted serial number No′, further obtains the first certificate otCA associated with the serial number No, and compares whether the decrypted certificate otCA′ is consistent with the locally stored first certificate otCA. If they are consistent, the trusted CA center sends a message indicating successful certificate verification to user B and proceeds to the next step; otherwise, the trusted CA center sends a message indicating failed certificate verification to user B, the signature verification fails, and the quantum digital signature process ends.

[0027] S5: User B uses the coefficients of each term of the decrypted string str2′ except the highest term to generate an irreducible polynomial p′ 2 (x) with a leading coefficient of 1. Based on the irreducible polynomial p′ 2 (x) and the key v2, a hash function is generated Then, user B uses the hash function to calculate the hash value of the received signed file M - SIGN to obtain Compare the calculated hash value with the decrypted hash value to check if they are consistent. If they are, user B passes the signature verification for the signed file M - SIGN and user B receives the data M in the signed file M - SIGN; if they are not, the signature verification fails, user B refuses to receive the data M in the signed file M - SIGN, and the quantum digital signature process ends.

[0028] Furthermore, the specific process of user A and the trusted CA center negotiating to generate and store a one - time certificate for signing is as follows:

[0029] A1: User B obtains and stores the public CA user certificate CA 1B and the private CA user certificate CA 2B from the trusted CA center; the trusted CA center also stores the public CA user certificate CA 1B and the private CA user certificate CA 2B locally; then, user A obtains the public CA user certificate CA 1B of user B from the trusted CA center;

[0030] A2: User A obtains a set of keys u1 from the local key pool as random numbers to generate an irreducible polynomial p 1 (x), and then records the string composed of the coefficients of each term except the highest term in the irreducible polynomial p 1 (x) as str1;

[0031] A3: User A negotiates a set of keys (u2, u3, u4, u5) with the trusted CA center, and then User A generates a hash function based on the irreducible polynomial p 1 (x) and the key u2 Using this hash function Calculate the first hash value of the privacy CA user certificate CA obtained locally from User A 2A to get XOR-encrypt the hash value with the key u3 to obtain the first certificate

[0032] A4: User A encrypts the string str1 and the public CA user certificate CA of User B respectively using the keys u4, u5 negotiated with the trusted CA center 1B to obtain and Then send the first certificate otCA and to the trusted CA center, that is, send to the trusted CA center; The trusted CA center receives and decrypts using the negotiated keys (u3, u4, u5) to obtain the second hash value the string str1′ and the public CA user certificate CA′ 1B ; The trusted CA center uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the string str1′ obtained by decryption to generate an irreducible polynomial p′ 1 (x) with the highest term coefficient of 1. Based on the irreducible polynomial p′ 1 (x) and the key u2 to generate a hash function Using the hash function Calculate the third hash value of the privacy CA user certificate CA of User A obtained locally from the trusted CA center 2A to get

[0033]

[0034] The trusted CA center compares the calculated third hash value with the decrypted second hash value If they are consistent, the authentication passes. The trusted CA center stores the first certificate otCA, and at the same time, according to the public CA user certificate CA′ 1B obtains the privacy CA user certificate CA of User B from local 2B , and associates and stores the first certificate otCA, the serial number No in the request req, the public CA user certificate CA′ 1B and the privacy CA user certificate CA 2B i.e., store (No, otCA, CA′1B , CA 2B ); If they are inconsistent, the authentication fails, and user A and the trusted CA center renegotiate to generate a one-time certificate for signature.

[0035] Further, the specific process for user B to receive the transmitted file DOC and perform a signature verification operation on the signature file M-SIGN in the transmitted file DOC is as follows:

[0036] B1: User B receives the transmitted file DOC and uses the negotiated keys (v3, v4) to decrypt and in the transmitted file DOC to obtain the hash value of the decrypted signature file and the string str2';

[0037] B2: User B negotiates the transmission key k1 with the trusted CA center. User B uses the transmission key k1 to encrypt the serial number No, the first certificate otCA in the signature file M-SIGN of the received transmitted file DOC, and its own locally stored private CA user certificate CA 2B to obtain and sends it to the trusted CA center;

[0038] B3: The trusted CA center receives and decrypts it using the negotiated key k1 to obtain (No″, otCA′, CA 2B ′); Then the trusted CA center checks the identity of user B. After passing the check, it finds the locally stored serial number No based on the decrypted serial number No″, and further obtains the first certificate otCA associated with the serial number No. It compares whether the decrypted certificate otCA′ is consistent with the locally stored first certificate otCA. If they are consistent, the trusted CA center sends a message indicating successful certificate verification to user B and proceeds to the next step; otherwise, the trusted CA center sends a message indicating failed certificate verification to user B, the signature verification fails, and the quantum digital signature process ends;

[0039] B4: User B uses the coefficients of each term of the string str2' obtained by decryption, except for the highest term, to generate an irreducible polynomial p′ 2 (x) with the highest term coefficient of 1. Based on the irreducible polynomial p′ 2 (x) and the key v2, a hash function is generated. Then, user B uses the hash function to calculate the hash value of the received signature file M-SIGN to obtain and compares the calculated hash value with the hash value obtained by decryption Whether they are consistent. If they are consistent, user B passes the signature verification on the signature file M-SIGN, and user B receives the data M in the signature file M-SIGN; if they are inconsistent, the signature verification fails, user B refuses to receive the data M in the signature file M-SIGN, and the quantum digital signature process ends.

[0040] Furthermore, the specific process for the trusted CA center to verify the identity of user B is as follows:

[0041] The trusted CA center locates the locally stored serial number No based on the decrypted serial number No″, and further obtains the private CA user certificate CA associated with the serial number No for storage. 2B , if the stored private CA user certificate CA 2B is consistent with the decrypted certificate CA′ 2B , then the identity verification of user B passes, and the certificate verification is executed; otherwise, the verification fails, and the trusted CA center refuses to execute the certificate verification.

[0042] Furthermore, the specific process for the trusted CA center to verify the identity of user B may also be:

[0043] C1: User B obtains a group of keys w1 from the local key pool as random numbers to generate an irreducible polynomial p 3 (x). After obtaining the irreducible polynomial, the string formed by the coefficients of each term except the highest term in the irreducible polynomial p 3 (x) is denoted as str3;

[0044] C2: User B negotiates keys (w2, w3, w4, w5) with the trusted CA center. User B generates a hash function based on the irreducible polynomial p 3 (x) and the key w2 Using the hash function Calculate the hash value of user B's private CA user certificate CA 2B to obtain

[0045] C3: User B encrypts the received serial number No, hash value and the string str3 using the negotiated keys (w3, w4, w5) respectively to obtain and then sends them to the trusted CA center;

[0046] C4: The trusted CA center decrypts using the negotiated keys (w3, w4, w5) to obtain the serial number No″′, hash value and the string str3′; The trusted CA center generates a highest-term coefficient of 1 irreducible polynomial p′ based on the coefficients of each term corresponding to the polynomial except the highest term of the decrypted string str3′3 (x), generating a hash function based on the irreducible polynomial p′ 3 (x) and the negotiated key w2 The trusted CA center locates the locally stored serial number No based on the decrypted serial number No″′, and further obtains the private CA user certificate CA associated with the serial number No stored 2B , and then uses the generated hash function to calculate the hash value of the private CA user certificate CA associated with the serial number No stored 2B to obtain Compare the calculated hash value with the decrypted hash value to check whether they are consistent. If they are consistent, the identity verification of user B passes, and the certificate verification is executed; otherwise, the verification fails, and the trusted CA center refuses to execute the certificate verification.

[0047] The present invention further includes a lightweight quantum digital signature and encryption method, and the method includes the following steps:

[0048] a. Encryption: User A encrypts the data M using the encryption key a to obtain the ciphertext

[0049] b. Perform a digital signature on the ciphertext m through the quantum digital signature method according to any one of claims 1-8, and form a signature file by signing the ciphertext m during the digital signature process; and user A also sends the encryption key a to user B in an unconditionally secure manner;

[0050] c. After completing the quantum digital signature, user B decrypts the ciphertext m according to the encryption key a to obtain the plaintext data M, and the plaintext data M is the message to be transmitted.

[0051] Further, in the step b, the unconditionally secure manner is implemented by using quantum key distribution technology or the method of securely delivering quantum random numbers.

[0052] The beneficial effects of the present invention:

[0053] (1) Through the quantum digital signature method proposed by the present invention, while ensuring the security of the quantum digital signature, the load pressure on the trusted CA center is reduced. The trusted CA center only needs to execute the issuance of the signature certificate during the quantum digital signature process and provide the verification function of the signature certificate, without sharing its own storage resources to store the communication message content between users and consuming its own computing power resources to verify the signature of the message content; in this way, the trusted CA center can effectively utilize its limited storage resources, improve resource utilization, and reduce the hardware cost of the trusted CA center;

[0054] (2) Through the quantum digital signature method proposed by the present invention, user A uses the signature certificate otCA, its own public CA certificate CA 1A , and the institutional information ca of the trusted CA center to jointly sign the data M. This signature process realizes the binding of the transmitted data M with the identity of user A, and truly plays the role of user A signing the data M; moreover, by using the quantum digital signature method of the present invention, the integrity (i.e., non-tamperability) and non-repudiation of the data during the transmission process can be ensured, guaranteeing the security of data transmission; and the communication data is only transmitted between users A and B, and no third party will receive this communication data, ensuring that the communication data will not be known to irrelevant third parties;

[0055] (3) By using the quantum digital signcryption method proposed by the present invention, before user B performs the last decryption operation, all the previous steps are performed on the ciphertext m, reducing the risk of leakage of the plaintext data M and improving the security of the data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 is a schematic diagram of the connection of the participants in the quantum digital signature method of the present invention;

[0057] Figure 2 is a schematic flowchart of the quantum digital signature method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0058] The present invention will be further described below in conjunction with the drawings and embodiments:

[0059] As mentioned in the background art, as the signature verification party in the digital signature process, the CA certification center needs to receive the message content of the communication between users, and the payload size of the message content has become a resource burden on the CA certification center. In view of this, the present application proposes a lightweight quantum digital signature method.

[0060] As Figure 1 shown, the lightweight quantum digital signature participants proposed by the present application include user A, user B and the trusted CA center that are connected to each other in pairs. Among them, user A is the data sender and signer, user B is the data receiver and signature verification party, and the trusted CA center is used to provide the signature of user A for this quantum digital signature process. The trusted CA center here can obtain its own trusted identity and prove its trusted identity to a higher-level CA center that governs the trusted CA center by using the method in the patent with the application number 2022101851462 described in the background art; after one proof, there is no need to repeat the proof subsequently.

[0061] User B, as the signature verification party, will only connect to the trusted CA center when the signature verification process is initiated, thereby reducing the consumption of connection resources for both User B and the trusted CA center caused by continuous connection.

[0062] Embodiment 1

[0063] As Figure 2 shown, the present invention provides a lightweight quantum digital signature method, which includes the following steps:

[0064] (1) User A generates a request req for quantum digital signature of data M and sends the request req to the trusted CA center. The request req includes the serial number No of this quantum digital signature;

[0065] (2) User A registers in the trusted CA center, and then obtains and securely stores the public CA user certificate CA 1A of User A, the privacy CA user certificate CA 2A and the institutional information ca of the trusted CA center;

[0066] Among them, the public CA user certificate CA 1A and the privacy CA user certificate CA 2A can be generated using the digital certificate generation method described in the patent with the application number 2022101851462 in the background technology. That is, the privacy CA user certificate CA 2A =(CA 1A , timestamp, QRN). Among them, the timestamp is an optional item, and the random number QRN comes from the local key pool of the trusted CA center. The random number QRN can be a 128-bit or 256-bit true random number, and the specific length can be determined according to actual usage requirements.

[0067] Next, User A and the trusted CA center negotiate to generate and store a one-time certificate for signature. This one-time certificate is the signature certificate in this quantum digital signature process. The one-time certificate is the first certificate otCA. The specific process of the one-time certificate is as follows:

[0068] 1) User A obtains a group of keys u1 from the local key pool as random numbers to generate an irreducible polynomial p 1 (x). After obtaining the irreducible polynomial, the string composed of the coefficients of each term except the highest term in the irreducible polynomial p 1 (x) is denoted as str1;

[0069] 2) User A negotiates a group of keys (u2, u3, u4) with the trusted CA center. Then, User A generates a hash function based on the irreducible polynomial p 1 (x) and the key u2 Use this hash function Calculate the first hash value of the privacy CA user certificate CA obtained locally from User A 2A to get Encrypt this hash value using the key u3. The encryption selects the XOR operation to obtain the first certificate

[0070] Among them, the length of the key u1 is n, and the specific value of n can be determined according to actual usage requirements. Use the key u1 as a random number to generate an irreducible polynomial p 1 (x). The specific process is as follows

[0071] Step (a): User A successively uses each bit of the key u1 to correspond to the coefficients of each term except the highest term in the polynomial, generating an nth-order polynomial in the GF(2) field, and the coefficient of the highest term is 1

[0072] Step (b): Verify whether this polynomial is an irreducible polynomial. If the verification result is "no", then User A re-obtains another set of keys, returns to step (a) as a new random number to re-generate the polynomial and verify; if the verification result is "yes", then stop the verification, and User A obtains the irreducible polynomial p 1 (x). Among them, the method for verifying whether a polynomial is an irreducible polynomial can adopt the verification method proposed in the patent "A Quantum Digital Hybrid Signcryption Method" with the application number 2021113539547

[0073] 3) Next is to authenticate the validity of the first certificate otCA: User A encrypts the string str1 using the key u4 negotiated with the trusted CA center to obtain Then send the first certificate otCA and to the trusted CA center, that is, send to the trusted CA center; the trusted CA center receives and decrypts using the negotiated keys (u3, u4) to obtain the second hash value and the string str1'; the trusted CA center uses the coefficients of each term except the highest term of the polynomial corresponding to each bit of the decrypted string str1' to generate an irreducible polynomial p' with the highest term coefficient of 1 1 (x), and generate a hash function based on this irreducible polynomial p' 1 (x) and the key u2 Use the hash function Calculate the third hash value of the privacy CA user certificate CA of User A obtained locally from the trusted CA center 2A to get

[0074] The trusted CA center will send the calculated third hash value The second decrypted hash value Perform a comparison. If they are the same, the authentication passes. The trusted CA center stores the first certificate otCA in its secure storage area, and at the same time stores the first certificate otCA associated with the serial number No in the request req, that is, stores (No, otCA). It can also store the name of user A at the same time for subsequent query and verification. If they are not the same, the authentication fails, and user A and the trusted CA center renegotiate to generate a one-time certificate for signature. Authenticate the validity of the first certificate otCA. In response to successful authentication, user A stores the first certificate otCA corresponding to the serial number No of this quantum digital signature for the quantum digital signature of data in subsequent steps. The trusted CA center stores the received first certificate otCA associated with the serial number No of this quantum digital signature, that is, stores (No, otCA), for signature verification in the subsequent quantum digital signature process. In response to authentication failure, user A and the trusted CA center renegotiate to generate a one-time certificate for signature.

[0075] (3) User A uses the first certificate otCA, the serial number No, and the public CA certificate CA of user A 1A , and the institutional information ca of the trusted CA center to jointly sign the data M to generate a signature file M-SIGN;

[0076] M-SIGN = (M, CA 1A , No, otCA, ca)

[0077] In the embodiment, after user A completes the signature, the first certificate otCA stored locally can be destroyed.

[0078] (4) User A generates a transmission file DOC based on the signature file M-SIGN and sends it to user B. The specific process is as follows:

[0079] First, user A obtains a group of keys v1 from the local key pool as random numbers to generate an irreducible polynomial p 2 (x). After obtaining the irreducible polynomial, the string composed of the coefficients of each term except the highest term in the irreducible polynomial p 2 (x) is denoted as str2;

[0080] Next, user A negotiates a group of keys (v2, v3, v4) with user B. User A generates a hash function based on the irreducible polynomial p 2 (x) and the key v2 Use the hash function Calculate the hash value of the signature file M-SIGN to obtain Then encrypt the hash value using the keys (v3, v4) respectively and string str2, and then generate a transmission file DOC,

[0081]

[0082] User A sends the transmission file DOC to User B. The method for generating the irreducible polynomial p 2 (x) is the same as above and will not be elaborated here.

[0083] User B receives the transmission file DOC and performs a signature verification operation on the signature file M-SIGN in the transmission file DOC. If the signature verification passes, User B receives the data M in the signature file M-SIGN; otherwise, User B refuses to receive, and the quantum digital signature process ends. Among them, the specific process for User B to receive the transmission file DOC and perform a signature verification operation on the signature file M-SIGN in the transmission file DOC is as follows:

[0084] S1: User B receives the transmission file DOC and uses the negotiated key (v3, v4) to decrypt and in the transmission file DOC to obtain the hash value of the decrypted signature file and string str2′; The signature file received by User B is M-SIGN, and the following is the signature verification operation performed on it;

[0085] S2: The specific process for performing signature verification is as follows: User B addresses the trusted CA center that generated the name for this quantum digital signature process based on the institutional information ca of the trusted CA center in the signature file M-SIGN in the received transmission file DOC and establishes a connection with the trusted CA center;

[0086] S3: User B negotiates the transmission key k1 with the trusted CA center. User B uses the transmission key k1 to encrypt the serial number No and the first certificate otCA in the signature file M-SIGN in the received transmission file DOC into ciphertext and sends it to the trusted CA center;

[0087] S4: The trusted CA center receives the ciphertext decrypts it using the negotiated key k1 to obtain (No′, otCA′). The trusted CA center locates the locally stored serial number No based on the decrypted serial number No′, further obtains the first certificate otCA associated with the serial number No in storage, and compares the decrypted certificate otCA′ with the locally stored first certificate otCA. If they are the same, the trusted CA center sends a message indicating successful certificate verification to User B and proceeds to the next step; otherwise, the trusted CA center sends a message indicating failed certificate verification to User B, the signature verification fails, and the quantum digital signature process ends;

[0088] In an embodiment, regardless of whether the comparison results are consistent, after the comparison ends, the trusted CA center may destroy the one-time certificate otCA stored locally.

[0089] In response to user B receiving the message that the certificate verification is successful, user B verifies the integrity of the received signature file M-SIGN.

[0090] S5: First, user B generates a hash function using the same hash algorithm as user A, that is, user B uses the coefficients of each term of the string str2' obtained by decryption, except for the highest term, corresponding to each polynomial to generate an irreducible polynomial p' 2 (x) with the highest term coefficient of 1. Based on the irreducible polynomial p' 2 (x) and the key v2, a hash function is generated Then, user B uses the hash function to calculate the hash value of the received signature file M-SIGN to obtain Compare the calculated hash value with the hash value obtained by decryption to check if they are consistent. If they are consistent, user B passes the signature verification for the signature file M-SIGN, and user B receives the data M in the signature file M-SIGN; if they are inconsistent, the signature verification fails, and user B rejects the data M in the signature file M-SIGN, and the quantum digital signature process ends.

[0091] Through the above quantum digital signature method, the trusted CA center only performs the generation and verification of the one-time certificate (i.e., the signature certificate) during this quantum digital signature process to confirm the validity of the signature during the quantum digital signature process. The trusted CA center does not need to use its own storage resources to store the transmission data M between users A and B, nor use its own computing power to perform the signature verification operation. In this way, the load pressure on the trusted CA center can be greatly reduced, and the resource utilization rate of the trusted CA center can be improved.

[0092] User A uses the first certificate otCA, its own public CA certificate CA 1A , and the institutional information ca of the trusted CA center to jointly sign the data M to obtain the signature file M-SIGN; user B confirms whether the data M has been tampered with during transmission by verifying the integrity of the signature file. This signature process realizes the binding of the transmitted data M to the identity of user A, and truly plays the role of user A signing the data M.

[0093] In some possible embodiments, the one-time certificate for signature in the quantum digital signature process can be destroyed after the signature and verification processes are completed, truly achieving a one-time certificate with no possibility of reuse. Even if a malicious user can obtain the one-time certificate for this quantum digital signature, since the trusted CA center will destroy the locally stored signature certificate for this time after the first verification operation of the certificate, when the malicious user goes to the trusted CA center for re-verification, it is impossible to conduct a comparison of the certificates. Therefore, the malicious user cannot send any information other than data M by stealing the signature certificate otCA.

[0094] Embodiment 2

[0095] The present invention provides a lightweight quantum digital signature method, which includes the following steps:

[0096] (1) User A generates a request req for quantum digital signature of data M and sends the request req to the trusted CA center. The request req includes the serial number No of this quantum digital signature.

[0097] (2) User A registers in the trusted CA center, and then obtains and securely stores the public CA user certificate CA of User A from the trusted CA center 1A , the private CA user certificate CA 2A and the institutional information ca of the trusted CA center; the trusted CA center also stores the public CA user certificate CA of User A locally 1A and the private CA user certificate CA 2A ; then, User A negotiates with the trusted CA center to generate and store a one-time certificate for signature. This one-time certificate is the signature certificate in this quantum digital signature process, and the one-time certificate is the first certificate otCA; in this embodiment, during the process of User A and the trusted CA center generating the one-time certificate, the identity information of User B is also attached, so that the trusted CA center only accepts the signature verification query of User B for this one-time identity, which further ensures the security of the quantum digital signature in this embodiment.

[0098] Among them, the specific process of User A negotiating with the trusted CA center to generate and store a one-time certificate for signature is as follows:

[0099] A1: User B registers in the trusted CA center, and then obtains and stores the public CA user certificate CA of User B from the trusted CA center 1B , the private CA user certificate CA 2B ; the trusted CA center also stores the public CA user certificate CA of User B locally 1B and the private CA user certificate CA 2B; Next, user A obtains user B's public CA user certificate CA from the trusted CA center 1B ;

[0100] A2: User A obtains a set of keys u1 from the local key pool as random numbers for generating an irreducible polynomial p 1 (x), and then records the string composed of the coefficients of each term except the highest term in the irreducible polynomial p 1 (x) as str1;

[0101] A3: User A negotiates a set of keys (u2, u3, u4, u5) with the trusted CA center. Then, user A generates a hash function 1 based on the irreducible polynomial p using this hash function to calculate the first hash value of the privacy CA user certificate CA obtained from user A's local area 2A to obtain XOR encrypt the hash value with the key u3 to obtain the first certificate

[0102] A4: User A encrypts the string str1 and user B's public CA user certificate CA with the negotiated keys u4 and u5 between user A and the trusted CA center 1B to obtain and Then, send the first certificate otCA, and to the trusted CA center, that is, send to the trusted CA center; The trusted CA center receives and decrypts with the negotiated keys (u3, u4, u5) to obtain the second hash value the string str1' and the public CA user certificate CA' 1B ; The trusted CA center uses the coefficients of each term corresponding to each bit of the decrypted string str1' except the highest term to generate an irreducible polynomial p' 1 (x) with the highest term coefficient being 1. Based on the irreducible polynomial p' 1 (x) and the key u2, generate a hash function using the hash function to calculate the third hash value of the privacy CA user certificate CA of user A obtained from the local area of the trusted CA center 2A to obtain

[0103]

[0104] The trusted CA center will send the calculated third hash value and the decrypted second hash value Perform comparison. If they are consistent, the authentication passes. The trusted CA center stores the first certificate otCA in its secure storage area. At the same time, according to the public CA user certificate CA′ 1B Obtain the private CA user certificate CA of user B from local 2B , the first certificate otCA, the serial number No in the request req, the public CA user certificate CA′ 1B and the private CA user certificate CA 2B are stored in an associated manner, that is, store (No, otCA, CA′ 1B , CA 2B ), and the name of user A can also be stored at the same time for subsequent query and verification; if they are inconsistent, the authentication fails, and user A and the trusted CA center renegotiate to generate a one-time certificate for signature.

[0105] (3) User A uses the first certificate otCA, the serial number No, the public CA certificate CA of user A 1A , and the institutional information ca of the trusted CA center to jointly sign the data M to generate a signature file M-SIGN;

[0106] M-SIGN = (M, CA 1A , No, otCA, ca)

[0107] In the embodiment, after completing the signature, user A can destroy the first certificate otCA stored locally.

[0108] (4) User A generates a transmission file DOC based on the signature file M-SIGN and sends it to user B. The specific process is the same as that in Embodiment 1, so it will not be described repeatedly; user B receives the transmission file DOC and performs a signature verification operation on the signature file M-SIGN in the transmission file DOC. If the signature verification passes, user B receives the data M in the signature file M-SIGN; otherwise, user B refuses to receive, and the quantum digital signature process ends; among them, the specific process of user B receiving the transmission file DOC and performing a signature verification operation on the signature file M-SIGN in the transmission file DOC is as follows:

[0109] B1: User B receives the transmission file DOC and uses the negotiated keys (v3, v4) to decrypt the and in the transmission file DOC to obtain the hash value of the decrypted signature file and the string str2′;

[0110] B2: User B negotiates the transmission key k1 with the trusted CA center. User B uses the transmission key k1 to send the serial number No, the first certificate otCA in the signature file M-SIGN in the received transmission file DOC, and its own locally stored private CA user certificate CA2B Encrypt to obtain Send it to the trusted CA center;

[0111] B3: The trusted CA center receives Decrypt using the negotiated key k1 to obtain (No″, otCA′, CA 2B ′); Then the trusted CA center verifies the identity of user B. The specific process of verification is as follows: The trusted CA center locates the locally stored serial number No based on the decrypted serial number No″, and further obtains the private CA user certificate CA 2B associated with the serial number No. If the stored private CA user certificate CA 2B is consistent with the decrypted certificate CA′ 2B then the identity verification of user B passes, and certificate verification is performed; otherwise, the verification fails, and the trusted CA center refuses to perform certificate verification and sends a message indicating that the certificate verification has failed to user B.

[0112] The specific process of verifying the identity of user B may also be:

[0113] C1: User B obtains a set of keys w1 from the local key pool as random numbers for generating an irreducible polynomial p 3 (x). After obtaining the irreducible polynomial, denote the string formed by the coefficients of each term except the highest term in the irreducible polynomial p 3 (x) as str3;

[0114] C2: Negotiate keys (w2, w3, w4, w5) between user B and the trusted CA center. User B generates a hash function based on the irreducible polynomial p 3 (x) and the key w2 Use the hash function Calculate the hash value of user B's private CA user certificate CA 2B to obtain

[0115] C3: User B encrypts the received serial number No, hash value and the string str3 using the negotiated keys (w3, w4, w5) respectively to obtain and then send it to the trusted CA center;

[0116] C4: The trusted CA center decrypts using the negotiated keys (w3, w4, w5) to obtain the serial number No″′, hash value and the string str3′; The trusted CA center generates a highest-term coefficient 1 irreducible polynomial p′ based on the coefficients of each term corresponding to the polynomial except the highest term in the decrypted string str3′ 3(x), generate a hash function based on the irreducible polynomial p′ 3 (x) and the negotiated key w2 The trusted CA center locates the locally stored serial number No based on the decrypted serial number No″′, and further obtains the private CA user certificate CA associated with the serial number No 2B , and then use the generated hash function Calculate the hash value of the private CA user certificate CA associated with the serial number No 2B to obtain Compare the calculated hash value with the decrypted hash value to see if they are the same. If they are the same, the identity verification of user B passes, and the certificate verification is performed; otherwise, the verification fails, and the trusted CA center refuses to perform the certificate verification and sends a message indicating that the certificate verification has failed to user B

[0117] After the identity verification of user B passes, the certificate verification is performed: that is, locate the locally stored serial number No based on the decrypted serial number No″, and further obtain the first certificate otCA associated with the serial number No. Compare whether the decrypted certificate otCA′ is the same as the locally stored first certificate otCA. If they are the same, the trusted CA center sends a message indicating that the certificate verification has succeeded to user B and proceeds to the next step; otherwise, the trusted CA center sends a message indicating that the certificate verification has failed to user B, the signature verification fails, and the quantum digital signature process ends

[0118] B4: User B uses the coefficients of each term of the polynomial except the highest term corresponding to each bit of the decrypted string str2′ to generate an irreducible polynomial p′ 2 (x) with the highest term coefficient of 1. Based on the irreducible polynomial p′ 2 (x) and the key v2 to generate a hash function Then, user B uses the hash function to calculate the hash value of the received signature file M-SIGN to obtain Compare the calculated hash value with the decrypted hash value to see if they are the same. If they are the same, user B passes the signature verification for the signature file M-SIGN, and user B receives the data M in the signature file M-SIGN; if they are not the same, the signature verification fails, and user B refuses to receive the data M in the signature file M-SIGN, and the quantum digital signature process ends

[0119] The quantum digital signature method of the present invention can ensure the integrity (i.e., non-tamperability) and non-repudiation of data during transmission, guaranteeing the security of data transmission; and the communication data is only transmitted between users A and B, and no third party can receive this communication data, ensuring that the communication data will not be known to unrelated third parties;

[0120] Embodiment 3

[0121] The present invention further includes a lightweight quantum digital signcryption method, which comprises the following steps:

[0122] a. Encryption: User A encrypts data M using encryption key a to obtain ciphertext m = M ⊕ a; at this time, user A is the signcryption party. Before performing quantum digital signature, user A first encrypts data M.

[0123] b. Use the quantum digital signature method in Embodiment 1 or 2 to perform a digital signature on ciphertext m. During the digital signature process, ciphertext m is signed to form a signature file, that is, the signature object in Embodiment 1 or 2 is changed from data M to ciphertext m; and user A also sends encryption key a to user B in an unconditionally secure manner.

[0124] Use the quantum digital signature method to perform a signature verification operation on the signature file. After the signature verification passes, user B receives ciphertext m in the signature file M-SIGN; user A also needs to send encryption key a to user B in an unconditionally secure manner, and the unconditionally secure manner is implemented by using quantum key distribution technology or the method of securely delivering quantum random numbers.

[0125] c. After completing the quantum digital signature, that is, after user B passes the signature verification on the signature file, user B decrypts ciphertext m according to encryption key a to obtain plaintext data M, and the plaintext data M is the message to be transmitted.

[0126] By using the quantum digital signcryption method proposed in this embodiment, before user B performs the last decryption operation, all the foregoing steps are performed on ciphertext m, which reduces the leakage risk of plaintext data M and improves the security of the data transmission process.

Claims

1. A lightweight quantum digital signature method, characterized in that: The method comprises the following steps: (1) User A generates a request req for quantum digital signature of data M and sends the request req to the trusted CA center. The request req includes the serial number No of the quantum digital signature; (2) User A registers with the trusted CA center, and then obtains and stores the public CA user certificate of User A from the trusted CA center. 1A , Privacy CA User Certificate CA 2A and the organization information ca of the trusted CA center; then, user A negotiates with the trusted CA center to generate and store a one-time certificate for signing, namely the first certificate otCA; (3) User A uses the first certificate otCA, serial number No, and user A's public CA certificate CA 1A , the organization information ca of the trusted CA center jointly signs the data M to generate a signature file M-SIGN; (4) User A generates a transmission file DOC based on the signature file M-SIGN and sends it to user B; user B receives the transmission file DOC and performs a signature verification operation on the signature file M-SIGN in the transmission file DOC. If the signature verification is successful, user B receives the data M in the signature file M-SIGN; otherwise, user B refuses to receive it, and the quantum digital signature process ends; after the signature verification and comparison is completed, the trusted CA center destroys the one-time certificate otCA stored locally; The specific process of user A generating a transmission file DOC based on the signature file M-SIGN and sending it to user B is as follows: First, user A obtains a set of keys v1 from the local key pool as random numbers to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p2(x) is recorded as str2; Next, user A and user B negotiate a set of keys (v2, v3, v4). User A generates a hash function based on the irreducible polynomial p2(x) and key v2. Using a hash function Calculate the hash value of the signature file M-SIGN Then use the key (v3, v4) to encrypt the hash value and string str2, and then generate the transmission file DOC, User A sends the transfer file DOC to user B; The specific process of user A negotiating with the trusted CA center to generate and store a one-time certificate for signing may be: A1: User B obtains and stores the public CA user certificate of user B from the trusted CA center 1B and Privacy CA User Certificate CA 2B The trusted CA center also stores user B's public CA user certificate CA 1B and Privacy CA User Certificate CA 2B ; Then, user A obtains user B's public CA user certificate from the trusted CA center 1B ; A2: User A obtains a set of keys u1 from the local key pool as random numbers to generate an irreducible polynomial p1(x), and then records the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) as str1; A3: User A negotiates a set of keys (u2, u3, u4, u5) with the trusted CA center, and then user A generates a hash function based on the irreducible polynomial p1(x) and key u2 Use this hash function Calculate the privacy CA user certificate CA obtained from user A locally 2A The first hash value is obtained Use key u3 to XOR encrypt the hash value and get the first certificate A4: User A uses the keys u4 and u5 negotiated with the trusted CA center to encrypt the string str1 and user B's public CA user certificate CA respectively. 1B get and Then the first certificate otCA, and Sent to the trusted CA center, Sent to the trusted CA center; the trusted CA center receives and decrypts using the negotiated key (u3, u4, u5) to obtain the second hash value String str1′ and public CA user certificate CA′ 1B The trusted CA center uses the coefficients of each item of the polynomial except the highest item in each bit of the decrypted string str1′ to generate an irreducible polynomial p′1(x) with the highest item coefficient of 1, and generates a hash function based on the irreducible polynomial p′1(x) and the key u2 Using a hash function Calculate the private CA user certificate CA of user A obtained locally from the trusted CA center 2A The third hash value is The trusted CA center will calculate the third hash value and the second hash value after decryption Compare and verify. If they are consistent, the authentication is passed. The trusted CA center stores the first certificate otCA and verifies the public CA user certificate CA′ 1B Get the private CA user certificate of user B from the local CA 2B , the first certificate otCA, the serial number No in the request req, and the public CA user certificate CA′ 1B and Privacy CA User Certificate CA 2B Perform associated storage, that is, store (No,otCA,CA′ 12 ,CA 2B ); If they are inconsistent, the authentication fails, and user A renegotiates with the trusted CA center to generate a one-time certificate for signing; The specific process of user B receiving the transmission file DOC and performing the signature verification operation on the signature file M-SIGN in the transmission file DOC is as follows: B1: User B receives the transmission file DOC and uses the negotiated key (v3, v4) to and Decrypt and obtain the hash value of the decrypted signature file and string str2′; B2: User B negotiates with the trusted CA center for the transmission key k1. User B uses the transmission key k1 to convert the serial number No in the signature file M-SIGN in the received transmission file DOC, the first certificate otCA, and its own locally stored privacy CA user certificate CA 2B Encrypted Send to the trusted CA center; B3: Received by the trusted CA center Decrypted using the negotiated key k1, we get (No″,otCA′,CA 2B ′); then the trusted CA center verifies the identity of user B. After the verification is passed, the locally stored serial number No is found based on the decrypted serial number No″, and the first certificate otCA associated with the serial number No is further obtained. The decrypted certificate otCA′ is compared with the locally stored first certificate otCA to see if they are consistent. If they are consistent, the trusted CA center sends a certificate verification success message to user B and proceeds to the next step; otherwise, the trusted CA center sends a certificate verification failure message to user B, the signature verification fails, and the quantum digital signature process ends; B4: User B uses the coefficients of each item of the polynomial except the highest item in each bit of the decrypted string str2′ to generate an irreducible polynomial p′2(x) with the highest item coefficient as 1, and generates a hash function based on the irreducible polynomial p′2(x) and the key v2 Then, user B uses the hash function Calculate the hash value of the received signature file M-SIGN to obtain Compare the calculated hash value And the decrypted hash value Are they consistent? If they are consistent, user B performs signature verification on the signature file M-SIGN and passes it, and user B receives the data M in the signature file M-SIGN; if they are inconsistent, the signature verification fails, user B refuses to receive the data M in the signature file M-SIGN, and the quantum digital signature process ends.

2. A lightweight quantum digital signature method according to claim 1, characterized in that: The specific process of user A negotiating with the trusted CA center to generate and store a one-time certificate for signing is as follows: 1) User A obtains a set of keys u1 from the local key pool as random numbers to generate an irreducible polynomial p1(x), and then records the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) as str1; 2) User A negotiates a set of keys (u2, u3, u4) with the trusted CA center, and then user A generates a hash function based on the irreducible polynomial p1(x) and key u2 Use this hash function Calculate the privacy CA user certificate CA obtained from user A locally 2A The first hash value is obtained Use key u3 to XOR encrypt the hash value and get the first certificate 3) User A uses the key u4 negotiated with the trusted CA center to encrypt the string str1 to obtain Then the first certificate otCA and Sent to the trusted CA center, Sent to the trusted CA center; the trusted CA center receives and decrypts using the negotiated key (u3, u4) to obtain the second hash value and string str1′; the trusted CA center uses the coefficients of each item of the polynomial except the highest item of each bit of the decrypted string str1′ to generate an irreducible polynomial p′1(x) with the highest item coefficient of 1, and generates a hash function based on the irreducible polynomial p′1(x) and the key u2 Using a hash function Calculate the private CA user certificate CA of user A obtained locally from the trusted CA center 2A The third hash value is The trusted CA center will calculate the third hash value and the second hash value after decryption A comparison is performed. If they are consistent, the authentication is successful, and the trusted CA center stores the first certificate otCA, and associates the first certificate otCA with the serial number No in the request req, that is, stores (No, otCA); if they are inconsistent, the authentication fails, and user A renegotiates with the trusted CA center to generate a one-time certificate for signing.

3. A lightweight quantum digital signature method according to claim 1, characterized in that: The specific process of user B receiving the transmission file DOC and performing the signature verification operation on the signature file M-SIGN in the transmission file DOC is as follows: S1: User B receives the transmission file DOC and uses the negotiated key (v3, v4) to and Decrypt and obtain the hash value of the decrypted signature file and string str2′; S2: User B addresses the trusted CA center based on the organization information ca of the trusted CA center in the signature file M-SIGN in the received transmission file DOC, and establishes a connection with the trusted CA center; S3: User B negotiates with the trusted CA center for the transmission key k1. User B uses the transmission key k1 to encrypt the serial number No in the signature file M-SIGN in the received transmission file DOC and the first certificate otCA into ciphertext Send to the trusted CA center; S4: The trusted CA center receives the ciphertext Decrypted using the negotiated key k1 to obtain (No′, otCA′), the trusted CA center finds the locally stored serial number No based on the decrypted serial number No′, further obtains the first certificate otCA associated with the serial number No, and compares the decrypted certificate otCA′ with the locally stored first certificate otCA to see if they are consistent. If they are consistent, the trusted CA center sends a certificate verification success message to user B and proceeds to the next step; Otherwise, the trusted CA center sends a message to user B indicating that the certificate verification failed, and the signature verification fails, and the quantum digital signature process ends; S5: User B uses the coefficients of each item of the polynomial except the highest item in each bit of the decrypted string str2′ to generate an irreducible polynomial p′2(x) with the highest item coefficient being 1, and generates a hash function based on the irreducible polynomial p′2(x) and the key v2 Then, user B uses the hash function Calculate the hash value of the received signature file M-SIGN to obtain Compare the calculated hash value And the decrypted hash value Are they consistent? If they are consistent, user B performs signature verification on the signature file M-SIGN and passes it, and user B receives the data M in the signature file M-SIGN; if they are inconsistent, the signature verification fails, user B refuses to receive the data M in the signature file M-SIGN, and the quantum digital signature process ends.

4. A lightweight quantum digital signature method according to claim 1, characterized in that: The specific process of the trusted CA center verifying the identity of user B is as follows: The trusted CA center finds the locally stored serial number No based on the decrypted serial number No″, and further obtains the private CA user certificate CA associated with the serial number No. 2B If the stored private CA user certificate CA 2B and the decrypted certificate CA′ 2B If they are consistent, user B’s identity verification passes and certificate verification is performed; otherwise, the verification fails and the trusted CA center refuses to perform certificate verification.

5. A lightweight quantum digital signature method according to claim 1, characterized in that: The specific process of the trusted CA center verifying the identity of user B is as follows: C1: User B obtains a set of keys w1 from the local key pool as random numbers to generate an irreducible polynomial p3(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p3(x) is recorded as str3; C2: User B negotiates the key (w2, w3, w4, w5) with the trusted CA center. User B generates a hash function based on the irreducible polynomial p3(x) and the key w2. Using a hash function Calculate user B privacy CA user certificate CA 2B The hash value is obtained C3: User B uses the negotiated keys (w3, w4, w5) to encrypt the received sequence number and hash value and string str3 gets Then send it to the trusted CA center; C4: The trusted CA center uses the negotiated key (w3, w4, w5) to decrypt and obtain the serial number No″′ and hash value and string str3′; the trusted CA center generates an irreducible polynomial p′3(x) with a highest term coefficient of 1 based on the coefficients of each polynomial corresponding to each bit of the decrypted string str3′, and generates a hash function based on the irreducible polynomial p′3(x) and the negotiated key w2 The trusted CA center finds the locally stored serial number No based on the decrypted serial number No″′, and then further obtains the private CA user certificate CA associated with the serial number No. 2B , and then use the generated hash function Calculate the private CA user certificate CA stored in association with serial number No 2B The hash value is obtained Compare the calculated hash value And the decrypted hash value Are they consistent? If they are consistent, user B’s identity verification is successful and certificate verification is performed; otherwise, the verification fails and the trusted CA center refuses to perform certificate verification.

6. A lightweight quantum digital signcryption method, characterized in that: The method comprises the following steps: a. Encryption: User A encrypts data M using encryption key a to obtain ciphertext b. Digitally sign the ciphertext m by the quantum digital signature method described in any one of claims 1 to 5, and sign the ciphertext m in the digital signature process to form a signature file; and user A also sends the encryption key a to user B in an unconditionally secure manner; c. After completing the quantum digital signature, user B decrypts the ciphertext m according to the encryption key a to obtain the plaintext data M. The plaintext data M is the message that needs to be transmitted.

7. A lightweight quantum digital signcryption method according to claim 6, characterized in that: In step b, the unconditionally secure method is implemented by using quantum key distribution technology or securely distributing quantum random numbers.

Citation Information

Patent Citations

  • Agile digital signature verification method and system

    CN115277019A