Lightweight key exchange protocol method, electronic equipment and storage medium
By designing a lightweight key exchange protocol in a resource-constrained communication environment, the generation and negotiation of quantum shared keys are achieved by using elliptical curve points and public key ciphertexts to achieve quantum shared key resistance, solving the problem of inapplicability in the existing technology in low bandwidth and high latency scenarios, and improving the communication security level.
Patent Information
- Application Number
- CN202510292550.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-17
AI Technical Summary
The existing national secret algorithm SM2 is not applicable in resource-constrained scenarios such as low bandwidth and high latency or frequent key exchange systems. As the demand for quantum security increases, existing key exchange protocols are difficult to balance communication overhead and security requirements.
A lightweight key exchange protocol method is designed to realize the generation and negotiation of quantum shared keys resistant to quantum-shared keys by passing only elliptical curve points and public keys between the server and the client, reducing computing overhead, and improving security through hash checksum signature verification.
This method reduces the computing overhead and communication overhead of key exchange in resource-constrained communication environments, has the ability to resist quantum computing, improves the communication security level, and is suitable for complex network environments and scenarios with high security requirements.
Smart Images

Figure CN120165848A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a lightweight key exchange protocol method, an electronic device, and a storage medium. Background Art
[0002] As a core mechanism of cryptography, the key exchange protocol is dedicated to securely negotiating a shared key for both communication parties over an insecure channel to lay the foundation for encrypted communication. It relies on the complexity of mathematical problems to ensure security and is widely used in security communication protocol scenarios such as TLS, VPN, and mobile payment. Classic ones include Diffie-Hellman (DH), Elliptic Curve Diffie-Hellman (ECDH), and China's SM2 key exchange protocol. Their security depends on the intractability of the discrete logarithm or elliptic curve discrete logarithm problem. However, the rapid development of quantum computing poses a severe challenge. The Shor algorithm based on quantum computing can efficiently solve related mathematical problems, putting traditional key exchange protocols at risk of being cracked and threatening Internet communication security. Therefore, the cryptography community is actively exploring key exchange protocols resistant to quantum computing, relying on mathematical problems such as lattice problems, coding theory, and multivariate polynomial equations that are difficult to overcome by quantum computing to build security guarantees. Considering coping with quantum threats and taking into account the application and compliance of existing national cryptography standards, integrating SM2 and post-quantum cryptography has become a viable strategy. For example, designing a hybrid key exchange protocol where SM2 and post-quantum algorithms each generate part of the key to synthesize the session key, achieving a balance between performance and quantum resistance security.
[0003] However, the inventors found that there are at least the following problems in the related technologies: When encrypting using the national cryptography algorithm SM2, its ciphertext structure composed of elliptic curve points, ciphertext data, and hash values is not suitable for resource-constrained scenarios such as low bandwidth and high latency or in a frequent key exchange system. And with the increasing demand for quantum resistance security, there is a need for a key exchange protocol method that balances communication overhead and security requirements in practical applications. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a lightweight key exchange protocol method, an electronic device, and a storage medium, which are applicable to resource-constrained communication environments and can simultaneously provide protection against potential threats from quantum computers to ensure system security.
[0005] To solve the above technical problems, an embodiment of the present invention provides a lightweight key exchange protocol method, which is applied to a server. The method includes: receiving a first message sent by a client, where the first message includes a first elliptic curve point and a first public key; wherein, the first public key is used to perform verification with the client; verifying the curve equation of the first elliptic curve point, and performing verification with the client when the curve equation verification passes; after completing the verification, calculating a service key according to the first elliptic curve point, and generating a quantum-resistant shared key; the service key is used to perform local key verification on the server side, and the quantum-resistant shared key is used to perform the calculation of the exchange negotiation at both ends; encrypting the quantum-resistant shared key, sending a second message including the encrypted quantum-resistant shared key to the client, and performing negotiation calculation according to the service key and the quantum-resistant shared key to complete the exchange negotiation.
[0006] An embodiment of the present invention also provides a lightweight key exchange protocol method, which is applied to a client. The method includes: receiving a second message sent by a server, where the second message includes a second elliptic curve point and the ciphertext of a quantum-resistant shared key; the quantum-resistant shared key is used to perform the calculation of the exchange negotiation at both ends; verifying the curve equation of the second elliptic curve point, and calculating a client key according to the second elliptic curve point when the curve equation verification passes; the client key is used to perform local key verification on the client side; performing negotiation calculation according to the second shared key and the quantum-resistant shared key to complete the exchange negotiation.
[0007] An embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned lightweight key exchange protocol method.
[0008] An embodiment of the present invention also provides a computer-readable storage medium, storing a computer program, and when the computer program is executed by a processor, the above-mentioned lightweight key exchange protocol method is implemented.
[0009] In the embodiments of the present invention, during the process of realizing communication negotiation, the client and the server only need to send elliptic curve points in terms of national cryptographic algorithms, and can achieve the key exchange negotiation between the two ends through a first public key and the ciphertext of the quantum-resistant key, minimizing the computational overhead to adapt to the resource-constrained communication environment. Moreover, by verifying the curve equation of the first elliptic curve point sent by the client, the data legality and security are ensured, and the negotiation is carried out based on the key generated by the device combined with the shared quantum-resistant shared key, possessing quantum-resistant capabilities, being able to resist the potential threats of quantum computing, enhancing the communication security level, and reducing the security risk of key negotiation. After encrypting the shared key and sending it to the peer end, and combining multiple key negotiation calculations, the exchange negotiation is finally completed, laying an effective key security foundation for encrypted communication, being able to adapt to complex network environments and security requirements, and enhancing the system adaptability and stability.
[0010] In addition, the service key calculation according to the first elliptic curve point includes: extracting a first element from the first elliptic curve point, and verifying the elliptic curve point according to the first element; in the case where the first element passes the elliptic curve point verification, performing service key calculation through the SM2 key module to obtain the service key. By using an independent SM2 key module for service key calculation, the impact of the key module on the entire system is reduced. While improving the system flexibility, it can still maintain strong security in the quantum computing environment, further consolidating the communication security defense line and greatly enhancing the communication security level.
[0011] In addition, in the case where the security level is lower than the preset security standard, the service key is obtained by performing service key calculation through the post-quantum key module. Since the service key calculation is carried out through an independent encryption algorithm module, the compatibility of the existing system is maximally maintained, and at the same time, it has good adaptability. When the threat of quantum computing intensifies, it can dynamically switch to the post-quantum key module for fusing SM2 and post-quantum cryptographic algorithms for encryption, which can provide double guarantees and is applicable to fields with extremely high security requirements such as finance and national defense.
[0012] In addition, the first message further includes a first public key and a first hash value generated by the client; the verification with the client includes: calculating a second hash value according to the first public key, and verifying the second hash value with the first hash value; in the case where the second hash value is the same as the first hash value, performing signature verification negotiation on the second hash value; if the signature verification result of the second hash value fails, the negotiation with the client fails. Since the reliability of two-end authentication is improved through hash value comparison and signature verification, the protocol can be compatible with devices of different types and performances, facilitating deployment in diverse network environments, greatly enhancing the adaptability of the protocol in multiple scenarios; and further enhancing the credibility of identity authentication, effectively preventing security threats such as identity impersonation.
[0013] In addition, the calculating the quantum shared key according to the second elliptic curve point to obtain the quantum shared key includes: extracting a second element from the second elliptic curve point, and verifying the elliptic curve point according to the second element; in the case where the second element passes the elliptic curve point verification, performing quantum shared key calculation through the SM2 key module to obtain the client key.
[0014] In addition, in the case where the security level is lower than the preset security standard, the client key is calculated through the post-quantum key module.
[0015] In addition, the second message further includes a third hash value generated by the server; before calculating the client key according to the second elliptic curve point, the method further includes: calculating a fourth hash value according to the anti-quantum shared key, and verifying the fourth hash value with the third hash value; in the case where the fourth hash value is the same as the third hash value, performing signature verification negotiation on the fourth hash value; if the signature verification result of the fourth hash value fails, the negotiation with the server fails. Description of the Drawings
[0016] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not limit the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated, and the drawings in the figures do not constitute a proportional limitation.
[0017] Figure 1 is a flowchart of a lightweight key exchange protocol method provided by an embodiment of the present application Figure 1 ;
[0018] Figure 2 is a flowchart of a lightweight key exchange protocol method provided by an embodiment of the present application Figure 2 ;
[0019] Figure 3 is a lightweight key exchange protocol method flow provided by an embodiment of the present application Figure 3 ;
[0020] Figure 4 is a schematic diagram of the internal structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0021] When using the national cryptography algorithm SM2 for encryption, the ciphertext structure composed of elliptic curve points, ciphertext data, and hash values is not applicable to resource-constrained scenarios such as low bandwidth and high latency or frequent key exchange systems. Moreover, with the increasing demand for quantum-resistant security, a key exchange protocol method that balances communication overhead and security requirements is needed in practical applications.
[0022] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present invention, many technical details are provided to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present invention. Each embodiment can be combined and cross-referenced with each other on the premise of not being contradictory.
[0023] An embodiment of the present invention relates to a lightweight key exchange protocol method that can be applied to a server. The method includes: receiving a first message sent by a client, where the first message includes a first elliptic curve point and a first public key; wherein, the first public key is used to verify with the client; verifying the first elliptic curve point against a curve equation, and in the case where the curve equation verification passes, verifying with the client; after the verification is completed, calculating a service key based on the first elliptic curve point and generating a quantum-resistant shared key; the service key is used for local key verification on the server side, and the quantum-resistant shared key is used to perform the calculation of the exchange negotiation at both ends; encrypting the quantum-resistant shared key, sending a second message including the encrypted quantum-resistant shared key to the client, and performing negotiation calculation based on the service key and the quantum-resistant shared key to complete the exchange negotiation. Since in the process of realizing communication negotiation, the client and the server only need to send an elliptic curve point in the national cryptography algorithm, and can realize the key exchange negotiation at both ends through a first public key and the ciphertext of the quantum-resistant key, minimizing the computational overhead to adapt to resource-constrained communication environments; and, by verifying the curve equation of the first elliptic curve point sent by the client, ensuring data legality and security, and performing negotiation based on the key generated by the device combined with the shared quantum-resistant shared key, having quantum-resistant capabilities, being able to resist the potential threat of quantum computing, enhancing the communication security level, reducing the security risk of key negotiation; encrypting the shared key and sending it to the other end, and combining multiple key negotiation calculations to finally complete the exchange negotiation, laying an effective key security foundation for encrypted communication, being able to adapt to complex network environments and security requirements, and enhancing the system adaptability and stability. The implementation details of the lightweight key exchange protocol method of the embodiments of the present invention will be specifically described below. The following content is only the implementation details provided for easy understanding and is not necessary for implementing this solution.
[0024] As Figure 1 shown, for the server, in step 101, receive a first message sent by the client, where the first message includes a first elliptic curve point and a first public key; wherein, the first public key is used to verify with the client.
[0025] Specifically, in some embodiments, before receiving the first message sent by the client, the method further includes: generating a second random number, calculating a second elliptic curve point based on the second random number; extracting a second element from the second elliptic curve point and performing a modulo operation on the second element to obtain a second modulo operation result.
[0026] In step 102, verify the first elliptic curve point against a curve equation.
[0027] In step 103, when the curve equation is verified to pass, a service key is calculated based on the first elliptic curve point, and a quantum-resistant shared key is generated; when the curve equation is verified to fail, negotiation failure is returned. Wherein, the service key is used for server-side local key verification, and the quantum-resistant shared key is used for two-end joint verification.
[0028] In step 104, the quantum-resistant shared key is encrypted, and a second message including the encrypted quantum-resistant shared key is sent to the client.
[0029] In step 105, negotiation calculation is performed based on the service key and the quantum-resistant shared key to complete the exchange negotiation.
[0030] In some embodiments, the calculating the service key according to the first elliptic curve point includes: taking out a first element from the first elliptic curve point, and performing elliptic curve point verification according to the first element; when the first element passes the elliptic curve point verification, the service key is calculated through the SM2 key module to obtain the service key.
[0031] In some embodiments, when the security level is lower than a preset security standard, the service key is calculated through a post-quantum key module.
[0032] In some embodiments, the first message further includes a first public key and a first hash value generated by the client; the verification with the client includes: calculating a second hash value according to the first public key, and verifying the second hash value with the first hash value; when the second hash value is the same as the first hash value, signature verification negotiation is performed on the second hash value; if the signature verification result of the second hash value fails, negotiation with the client fails.
[0033] In the embodiments of the present invention, since in the process of implementing communication negotiation, the client and the server only need to send elliptic curve points in terms of national cryptography algorithms, and the key exchange negotiation between the two ends can be realized through a first public key and the ciphertext of the quantum-resistant key, by minimizing the calculation overhead to adapt to the resource-constrained communication environment; and, by verifying the curve equation of the first elliptic curve point sent by the client, the data legality and security are ensured, and negotiation is performed based on the key generated by the device combined with the shared quantum-resistant shared key, with quantum-resistant ability, which can resist the potential threat of quantum computing, improve the communication security level, and reduce the security risk of key negotiation; the shared key is encrypted and sent to the opposite end, and combined with multiple key negotiation calculations, the exchange negotiation is finally completed, laying an effective key security foundation for encrypted communication, being able to adapt to complex network environments and security requirements, and enhancing the system adaptability and stability.
[0034] Another embodiment of the present invention relates to a lightweight key exchange protocol method that can be applied to a client. The method includes: receiving a second message sent by a server, where the second message includes a second elliptic curve point and an anti-quantum shared key; the anti-quantum shared key is used for two-end joint verification; verifying the curve equation for the second elliptic curve point, and when the curve equation verification passes, calculating a client key based on the second elliptic curve point; the client key is used for local key verification on the client side; performing negotiation calculation based on the second shared key and the anti-quantum shared key to complete the exchange negotiation. Since in the process of implementing communication negotiation, the client and the server only need to send elliptic curve points in the national cryptography algorithm, and can achieve two-end key exchange negotiation through a ciphertext of a first public key and an anti-quantum key, minimizing the computational overhead to adapt to resource-constrained communication environments; and, by verifying the curve equation for the first elliptic curve point sent by the client, ensuring data legality and security, and performing negotiation based on the key generated by the device combined with the shared anti-quantum shared key, having anti-quantum capabilities, being able to resist potential threats of quantum computing, enhancing the communication security level, and reducing the security risk of key negotiation; encrypting the shared key and sending it to the peer end, and combining multiple key negotiation calculations to finally complete the exchange negotiation, laying an effective key security foundation for encrypted communication, being able to adapt to complex network environments and security requirements, and enhancing the system adaptability and stability. The following specifically describes the implementation details of the lightweight key exchange protocol method of the embodiments of the present invention. The following content is only implementation details provided for convenient understanding and is not necessary for implementing this solution.
[0035] As Figure 2 shown, for the client, in step 201, receive a second message sent by the server, where the second message includes a second elliptic curve point and a ciphertext of an anti-quantum shared key; the anti-quantum shared key is used in the calculation for implementing the exchange negotiation.
[0036] Specifically, in some embodiments, before receiving the second message sent by the server, the method further includes: generating a first random number, calculating a first elliptic curve point based on the first random number; extracting a first element from the first elliptic curve point, and performing a modulo operation on the first element to obtain a first modulo operation result.
[0037] Further, before receiving the second message sent by the server, the method further includes: generating a first key group through an SM2 key module, where the first key group includes a first public key and a first private key.
[0038] Further, before receiving the second message sent by the server, the method further includes: generating a first hash value according to the first elliptic curve point, and signing the first hash value.
[0039] In step 202, verify the curve equation for the second elliptic curve point.
[0040] In step 203, when the curve equation verification passes, calculate the client key according to the second elliptic curve point; when the curve equation verification fails, return negotiation failure. Wherein, the client key is used for client local key verification.
[0041] In step 204, perform negotiation calculation according to the second shared key and the quantum-resistant shared key to complete the exchange negotiation.
[0042] In some embodiments, calculating the quantum shared key according to the second elliptic curve point to obtain the quantum shared key includes: extracting a second element from the second elliptic curve point, and verifying the elliptic curve point according to the second element; when the second element passes the elliptic curve point verification, perform quantum shared key calculation through the SM2 key module to obtain the client key.
[0043] In some embodiments, when the security level is lower than the preset security standard, the client key is calculated through a post-quantum key module.
[0044] In some embodiments, the second message further includes a third hash value generated by the server; before calculating the client key according to the second elliptic curve point, the method further includes: calculating a fourth hash value according to the quantum-resistant shared key, and verifying the fourth hash value with the third hash value; when the fourth hash value is the same as the third hash value, perform signature verification negotiation on the fourth hash value; if the signature verification result of the fourth hash value fails, the negotiation with the server fails.
[0045] In an embodiment of the present invention, during the process of implementing communication negotiation, the client and the server only need to send elliptic curve points in the aspect of national cryptography algorithms, and can realize the key exchange negotiation between the two ends through a first public key and the ciphertext of the quantum-resistant key, so as to adapt to the resource-constrained communication environment by minimizing the computational overhead; moreover, by verifying the curve equation of the first elliptic curve point sent by the client, the data legality and security are ensured, and the negotiation is carried out based on the key generated by the device combined with the shared quantum-resistant shared key, which has the quantum-resistant ability, can resist the potential threat of quantum computing, improve the communication security level, and reduce the security risk of key negotiation; the shared key is encrypted and sent to the other end, and combined with the multiple key negotiation calculation, and finally the exchange negotiation is completed, laying an effective key security foundation for encrypted communication, being able to adapt to complex network environments and security requirements, and enhancing the system adaptability and stability.
[0046] In a specific embodiment of the present application, for the client (User A), the original data includes: the distinguishable identifier of the client, partial elliptic curve system parameters, and the hash value Z of the client public key A ; the distinguishable identifier of the server, partial elliptic curve system parameters, and the hash value Z of the client public key B ; the client private key d A ; the client public key P A ; the server public key P B . For the server (User B), the original data includes: the distinguishable identifier of the client, partial elliptic curve system parameters, and the hash value Z of the client public key A ; the distinguishable identifier of the server, partial elliptic curve system parameters, and the hash value Z of the client public key B ; the server private key d B ; the client public key P A ; the server public key P B .
[0047] In addition, in the following process, the operations and symbol explanations are as follows:
[0048] E(F q ): The set of all rational points (including the infinite point O) on the elliptic curve E over F q .
[0049] F q : The finite field containing q elements.
[0050] H v (·): The cryptographic hash function with the message digest length of v bits.
[0051] h: The cofactor, h = #E(F q ) / n, where n is the order of the base point G.
[0052] ID A , ID B : Discernible identifiers of User A and User B.
[0053] KDF(·): Key Derivation Function.
[0054] n: The order of the base point G (n is a prime factor of #E(F q ).
[0055] O: A special point on the elliptic curve, called the point at infinity or zero point, which is the identity element of the additive group of the elliptic curve.
[0056] #E(F q ): The number of points on E(F q ), called the order of the elliptic curve E(F q ).
[0057] [k]P: The k - multiple point of point P on the elliptic curve, that is, k is a positive integer.
[0058] As Figure 3 shown, in step 301, the client generates a first random number through a random number generator: r A ∈[1, n - 1]. Specifically, r A can be used as the temporary key value generated by the client in the key exchange.
[0059] In step 302, the client calculates a first elliptic curve point according to the first random number: R A =[r A G=(x1, y1). Where G is a base point of the elliptic curve and its order is a prime number.
[0060] In step 303, the client generates a first key group through the KEM key generation function KEM.keypair. The first key group includes an encapsulation key (public key) ek and a decapsulation key (private key) dk.
[0061] In step 304, the client calculates a hash value h A1 =Hash(x1||y1||P A ||ek). Where Hash(·) is a cryptographic hash function. Specifically, in the above operation, a||b is the concatenation of a and b, where a and b can be bit strings, byte strings or elliptic curve points; if it is an elliptic curve point (x, y), then first convert the x and y coordinates to byte strings in little - endian order, and then concatenate them into a byte string x||y.
[0062] In step 305, the client signs the hash value h through the signature function SIG.sign(h, sk) A1 to obtain the signature SIG.sign(h A1 , sk A ) → sigA. Among them, the input of the signature function SIG.sign(h, sk) is the hash value h to be signed and the private key sk of the signing user, and the output is the signature value sig.
[0063] In step 306, the client sends R A , ek, h A1 , sigA to the server as the first message. It should be noted that in the above steps, steps 304 and 305 are optional execution steps. Those skilled in the art can flexibly choose whether to execute steps 304 and 305 according to actual application requirements. Correspondingly, if step 304 is executed, then h A1 is sent to the server; if step 305 is executed, then the sigA data is also sent to the server.
[0064] In step 307, the client extracts the first element x1 from the first elliptic curve point R A and calculates where & is the bitwise AND operation of two integers.
[0065] In step 308, the client performs a modulo operation on the first element: Then it waits for the server to return a message. Among them, mod n is the modulo n operation.
[0066] In step 401, the server generates a second random number through a random number generator: r B ∈ [1, n - 1]. Specifically, r B : can be used as the temporary key value generated by user B in the key exchange.
[0067] In step 402, the server calculates the first elliptic curve point according to the second random number: R B = [r B G = (x2, y2).
[0068] In step 403, the server extracts the second element x2 from the second elliptic curve point R B and calculates
[0069] In step 404, the server performs a modulo operation on the second element:
[0070] In step 405, the server receives the first message sent by the client and verifies whether R A satisfies the curve equation. If so, it jumps to step 406; if not, it jumps to step 415.
[0071] In step 406, the server calculates the hash value h B1 =Hash(x1||y1||P A ||ek), and determines whether h B1 is the same as the received h A1 . If so, it jumps to step 407; if not, it jumps to step 415.
[0072] In step 407, the server performs signature verification on the hash value h B1 SIG.verify(h B1 ,sigA,pk A )→res, and determines whether the signature verification result is res = ⊥. If not, it jumps to step 408 and executes the subsequent steps; if so, it jumps to step 415. Among them, the input of the signature verification function SIG.verify(h, sig, pk) is the hash value h to be verified, the signature value sig to be verified, and the public key pk of the signing user; the verification result is res, and it returns ⊥ for failure and 1 for success. Among them, pk A is the public key of the client under the SIG signature scheme, and if the SM2 signature scheme is selected, it can be the same as P A .
[0073] In step 408, the server extracts the first element x1 from the first elliptic curve point R A and calculates
[0074] In step 409, the server calculates the elliptic curve point and determines whether V is an infinite point. If not, it jumps to step 410; if so, it jumps to step 415. Among them, is the ceiling function, the smallest integer greater than or equal to x;
[0075] In step 410, the server calculates the service key K B =KDF(x V ||y V ||Z A ||Z B ,klen).
[0076] In step 411, the server performs a KEM key encapsulation operation through the second key encapsulation function KEM.enc(ek), obtaining the shared key ciphertext CT and the quantum-resistant shared key SS. Among them, the input of the second key encapsulation function KEM.enc(ek) is the user's encapsulation key (public key) ek, and the output is the shared key ciphertext CT and the quantum-resistant shared key SS.
[0077] In step 412, the server calculates the hash value: h B2 = Hash(x V ||y V ||Z A ||Z B ||x1||y1||x2||y2||CT||SS)
[0078] In step 413, the server signs the hash value h through the signature function SIG.sign(h,sk) B2 to perform the signature SIG.sign(h B2 ,sk B ) → sigB. Among them, sk B is the private key of the server under the SIG signature scheme. If the SM2 signature scheme is selected, it can be the same as d B .
[0079] In step 414, the server sends R B , CT, h B2 , sigB as the second message to the client and jumps to step 501.
[0080] In step 415, the server returns the server negotiation failure result.
[0081] It should be noted that in the above steps, steps 406 and 407 are optional execution steps corresponding to steps 304 and 305. Those skilled in the art can flexibly choose whether to execute steps 304, 305, 406, and 407 according to actual application requirements.
[0082] In step 309, the client receives the second message sent by the server and verifies whether R B satisfies the curve equation. If so, it jumps to step 310; if not, it jumps to step 316.
[0083] In step 310, the client extracts the second element x2 from the second elliptic curve point R B and calculates
[0084] In step 311, the client calculates the elliptic curve point And determine whether U is the infinite point. If not, jump to step 312; if so, jump to step 316.
[0085] In step 312, the client calculates the client key K through the SM2 key module A = KDF(x U ||y U ||Z A ||Z B , klen).
[0086] In step 313, the client performs the KEM key decapsulation operation through the first key encapsulation function KEM.dec(CT, dk) to obtain the quantum-resistant shared key SS. Among them, the input of the first key encapsulation function KEM.dec(CT, dk) is the shared key ciphertext CT and the user's decapsulation key (private key) dk, and the output is the quantum-resistant shared key SS.
[0087] In step 314, the client calculates the hash value h A2 = Hash(x U ||y U ||Z A ||Z B ||x1||y1||x2||y2||CT||SS), and determines whether h A2 is the same as the received h B2 . If the same, jump to step 315; if different, jump to step 316.
[0088] In step 315, the client performs signature verification on the hash value h A2 SIG.verify(h A2 , sigB, pk B ) → res, and determines whether the signature verification result is res = ⊥. If not, jump to step 501; if so, jump to step 316. Among them, pk B is the public key of user B under the SIG signature scheme. If the SM2 signature scheme is selected, it can be the same as P B .
[0089] In step 316, the client returns the client negotiation failure result.
[0090] In step 501, the client calculates The server calculates Complete the exchange negotiation. The Key A , Key B That is, the final shared key agreed upon by the key exchange protocol in this application.
[0091] In an embodiment of the present invention, the proposed key exchange design against quantum attacks integrates the classical SM2 key exchange protocol and quantum-resistant cryptographic algorithms to form a hybrid key exchange protocol, which combines the computational efficiency advantages of classical cryptographic systems and the strong security resistance of quantum-resistant cryptographic systems. It ensures the confidentiality and integrity of communication keys under the threat of quantum computing, effectively resists the impact of quantum computing on traditional encryption technologies, and lays the foundation for a secure and reliable communication system. Through a multiple authentication mechanism, users are allowed to flexibly select a signature module for identity authentication as needed, verify the legitimacy of both parties' identities during key exchange, ensure the integrity and reliability of data, and improve the protocol adaptability. The efficient key negotiation scheme combines quantum-resistant cryptographic algorithms and the SM2 protocol, and only transmits a ciphertext of an elliptic curve point, a first public key, and a quantum-resistant key, thereby significantly reducing communication and computing resource consumption, improving operation efficiency, and being applicable to Internet of Things scenarios with limited resources. In response to the key leakage risk caused by quantum computing, a dual protection mechanism based on a quantum-resistant key exchange algorithm is designed to significantly enhance the long-term security of communication and prevent potential security threats. The protocol framework has high compatibility and expandability, supports the integration of multiple quantum-resistant algorithm modules, meets diverse security requirements, and provides a platform for the development and innovation of cryptographic technologies. In addition, the hybrid protocol scheme combines the efficiency of the SM2 algorithm and the security of quantum-resistant cryptographic algorithms to achieve a lightweight design, reduce the computational burden, and be applicable to resource-constrained scenarios.
[0092] The step division of the above method is only for clear description. When implemented, it can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of this patent; adding insignificant modifications or introducing insignificant designs to the algorithm or process, but not changing the core design of its algorithm and process, are within the protection scope of this patent.
[0093] In addition, the examples mentioned in the above embodiments can be freely combined, and any combination method can be understood as an embodiment. The "embodiment" or "example" mentioned at various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art can understand that the embodiments described herein can be combined with other embodiments.
[0094] In summary, specific embodiments of the present subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result.
[0095] In the description of the embodiments of the present application, technical terms such as "first" and "second" are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity, specific order, or primary-secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "a plurality of" is more than two, unless otherwise clearly and specifically defined.
[0096] In the description of the embodiments of the present application, the term "and / or" is merely an association relationship describing associated objects, indicating that three relationships may exist. For example, A and / or B may represent: the existence of A, the simultaneous existence of A and B, and the existence of B. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0097] In the description of the embodiments of the present application, the term "a plurality of" means more than two (including two). Similarly, "multiple groups" means more than two groups (including two groups), and "multiple pieces" means more than two pieces (including two pieces).
[0098] Another embodiment of the present invention relates to an electronic device, as Figure 4 shown, including at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the lightweight key exchange protocol method as described above.
[0099] Wherein, the memory and the processor are connected by a bus. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and the memory together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and therefore, will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver may be one element or multiple elements, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted over the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor.
[0100] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory can be used to store the data used by the processor when executing operations.
[0101] Another embodiment of the present invention relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the above method embodiments are implemented.
[0102] That is, those skilled in the art can understand that all or part of the steps in implementing the methods of the above embodiments can be completed by instructing relevant hardware through a program. The program is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.
[0103] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present invention, and in practical applications, various changes can be made to them in form and details without departing from the spirit and scope of the present invention.
Claims
1. A lightweight key exchange protocol method, characterized in that: Applied to the server, the method includes: Receive a first message sent by a client, wherein the first message includes a first elliptic curve point and a first public key; wherein the first public key is used for verification with the client; Performing curve equation verification on the first elliptic curve point, and performing verification with the client if the curve equation verification passes; After the verification is completed, a service key is calculated according to the first elliptic curve point, and a quantum-resistant shared key is generated; the service key is used to verify the local key of the server, and the quantum-resistant shared key is used to implement the exchange negotiation calculation on both ends; The quantum-resistant shared key is encrypted, a second message including the encrypted quantum-resistant shared key is sent to the client, and a negotiation calculation is performed according to the service key and the quantum-resistant shared key to complete the exchange negotiation.
2. The lightweight key exchange protocol method according to claim 1 is characterized in that: The calculating a service key according to the first elliptic curve point includes: Taking out a first element from the first elliptic curve point, and performing elliptic curve point verification according to the first element; When the first element is verified by the elliptic curve point, the service key is calculated by the SM2 key module to obtain the service key.
3. The lightweight key exchange protocol method according to claim 2 is characterized in that: When the security level is lower than the preset security standard, the service key is obtained by calculating the service key through the post-quantum key module.
4. The lightweight key exchange protocol method according to claim 1, characterized in that: The first message also includes a first hash value generated by the client; The verifying with the client includes: Calculate a second Hash value according to the first public key, and verify the second Hash value with the first Hash value; When the second Hash value is the same as the first Hash value, performing signature verification negotiation on the second Hash value; If the signature verification result of the second hash value fails, the negotiation with the client fails.
5. A lightweight key exchange protocol method, characterized in that: Applied to a client, the method comprises: Receiving a second message sent by the server, wherein the second message includes a ciphertext of a second elliptic curve point and a quantum-resistant shared key; the quantum-resistant shared key is used to implement the calculation of the exchange negotiation at both ends; Performing curve equation verification on the second elliptic curve point, and if the curve equation verification passes, performing client key calculation based on the second elliptic curve point; the client key is used to perform client local key verification; A negotiation calculation is performed according to the second shared key and the quantum-resistant shared key to complete the exchange negotiation.
6. The lightweight key exchange protocol method according to claim 5, characterized in that: The step of calculating a quantum shared key according to the second elliptic curve point to obtain a quantum shared key includes: Taking out a second element from the second elliptic curve point, and performing elliptic curve point verification according to the second element; When the second element is verified by the elliptic curve point, the quantum shared key calculation is performed through the SM2 key module to obtain the customer key.
7. The lightweight key exchange protocol method according to claim 6, characterized in that: When the security level is lower than the preset security standard, the customer key is obtained by calculating the customer key through the post-quantum key module.
8. The lightweight key exchange protocol method according to claim 5, characterized in that: The second message also includes a third hash value generated by the server; Before calculating the client key according to the second elliptic curve point, the method further includes: Calculate a fourth Hash value according to the quantum-resistant shared key, and verify the fourth Hash value with the third Hash value; When the fourth Hash value is the same as the third Hash value, performing signature verification negotiation on the fourth Hash value; If the signature verification result of the fourth hash value fails, the negotiation with the server fails.
9. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the lightweight key exchange protocol method as described in any one of claims 1 to 4; or the lightweight key exchange protocol method as described in any one of claims 5 to 8.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it implements the lightweight key exchange protocol method as described in any one of claims 1 to 4; or the lightweight key exchange protocol method as described in any one of claims 5 to 8.
Citation Information
Cited By
Key negotiation method and device and related equipment
CN120639294A