Anti-quantum security identity authentication method, system, medium and equipment
By using digital signature algorithm and first key exchange algorithm in the Kerberos protocol, combined with Falcon, Kyber and SM3/SM4 algorithms, the problem of insufficient quantum resistance under quantum computing attacks is solved, and higher identity authentication security and forward security and confidentiality are achieved.
Patent Information
- Application Number
- CN202510467684.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-06-27
Smart Images

Figure CN120223305A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a quantum-resistant secure identity authentication method, system, medium, and device. Background Art
[0002] Currently, the Kerberos protocol is commonly used in communication networks to provide identity authentication services. It uses symmetric key encryption technology, adopts a key management and ticket mechanism, and realizes mutual authentication between the client and the service server through the key distribution center. The implementation of this authentication process does not depend on the authentication of the host operating system, does not require trust based on the host address, and assumes that the data packets transmitted over the network can be read, modified, and inserted with data arbitrarily. Therefore, Kerberos realizes a trusted third-party authentication service through traditional encryption technology (shared key).
[0003] The working mechanism of the Kerberos protocol generally includes the following steps: S1: The client configures its own account and password, and all client accounts and passwords as well as all service server accounts and passwords are configured on the key distribution center. S2: The client uses the HASH algorithm and the PBKDF2 encryption algorithm to calculate the client key Kc based on its password, encrypts the timestamp using the client key Kc, and combines other information to generate an authentication request and send it to the authentication server; after receiving the authentication request, the authentication server obtains the client password in the database to calculate the client key Kc, decrypts it using the client key Kc to obtain the timestamp, and after successfully verifying the timestamp, calculates the authentication server key Kg using the password of the authentication server, encrypts the session key, the client principal, and other information to form a ticket-granting ticket TGT, and generates an authentication response and sends it to the client. S3: After receiving the authentication response and verifying compliance, the client generates a ticket request and sends it to the ticket-granting server; after receiving the ticket request, the ticket-granting server verifies the validity of the ticket-granting ticket and other information. After verification, it generates the service server key Ks using the password of the service server to be accessed and generates a temporary key, encrypts the temporary key, the client principal, and other information to form a service ticket, and generates a ticket response and sends it to the client. S4: After receiving the ticket response, the client decrypts it using the session key to extract the temporary key, encrypts the identity authentication data using the temporary key, combines the service ticket and the identity authentication data into an access request and sends it to the service server; after receiving the access request, the service server decrypts the service ticket using the service server key Ks, and verifies the service ticket and other information. After verification, it encrypts the original access response using the temporary key and forms an access response and sends it to the client. S5: After receiving the access response, the client decrypts and verifies the data using the temporary key. After successful verification, both parties start using the temporary key as the shared key and perform encryption and decryption communication using the shared key.
[0004] During the above authentication process, calculating the key using the password and encrypting the data are vulnerable to data interception and brute - force password cracking to obtain the user's password information. Once the password is obtained, the ticket - granting ticket and service ticket are easily forged, affecting the security of identity authentication. At the same time, it does not have perfect forward secrecy (PFS). The keys are encrypted by password - derived keys. Once the password is cracked, the previous communication data is also insecure. And the HASH algorithm and PBKDF2 encryption algorithm used do not have the ability to resist quantum computing. Therefore, it is necessary to improve the quantum - resistant attack ability of the Kerberos protocol. Summary of the Invention
[0005] The purpose of the present invention is to overcome the above - mentioned disadvantages of the prior art, improve the quantum - resistant attack ability of the Kerberos protocol, and provide a quantum - resistant secure identity authentication method, system, medium and device.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A quantum - resistant secure identity authentication method includes the following steps: S1: The client, the service server and the key distribution center pre - configure keys in advance. The key distribution center includes a database, an authentication server and a ticket - granting server. The keys are generated using a digital signature algorithm; S2: The client sends an authentication request to the authentication server. The authentication server receives the authentication request from the client and verifies the identity of the client. After successful verification, it issues a ticket - granting ticket and generates an authentication response and returns it to the client; S3: Based on the authentication response, the client sends a ticket request to the ticket - granting server. The ticket - granting server verifies the validity of the ticket - granting ticket in the ticket request. After successful verification, it issues a service ticket and generates a ticket response and returns it to the client; S4: After the client obtains the ticket response and verifies it, the client uses the first key - exchange algorithm to generate a client key - exchange public key and a client key - exchange private key, and sends an access request to the service server using the service ticket and the client key - exchange public key. After receiving the access request, the service server verifies it. After successful verification, it calculates a shared key and a ciphertext according to the client key - exchange public key, encrypts the identity information of the service server using the shared key to obtain identity authentication data, and returns an access response to the client using the ciphertext and the identity authentication data; S5: Based on the access response, after the client receives the access response and verifies it, it obtains the shared key according to the ciphertext and the client key - exchange private key, and uses the shared key to conduct encrypted communication with the service server.
[0007] The method of the present invention pre-configures keys using a digital signature algorithm, signs and verifies signatures using the keys, improving the security of the keys and communication. During the authentication process between the client and the business server, a first key exchange algorithm is used to generate a shared key, ensuring forward secrecy and resistance to quantum attacks.
[0008] Preferably, the method for pre-configuring keys by the client, the business server, and the key distribution center in step S1 includes: The client generates a client public key and a client private key using a digital signature algorithm, and configures the client public key to the database of the key distribution center. The digital signature algorithm uses the Falcon digital signature algorithm; The business server generates a business server public key and a business server private key using the Falcon digital signature algorithm, and configures the business server public key to the database of the key distribution center; The authentication server generates an authentication server public key and an authentication server private key using the Falcon digital signature algorithm, and configures the authentication server public key to the client and the business server; The ticket issuing server generates a ticket issuing server public key and a ticket issuing server private key using the Falcon digital signature algorithm, and configures the ticket issuing server public key to the client and the business server.
[0009] Preferably, step S2 specifically includes: S2.1: The client generates an original authentication request, signs the original authentication request to obtain an authentication request, and sends the authentication request to the authentication server. The original authentication request includes the client entity, the business server entity, a first random number, and a first timestamp. The client entity is used to represent information about the client, and the business server entity is used to represent information about the business server to be accessed; S2.2: After receiving the authentication request, the authentication server obtains the digital signature of the original authentication request in the authentication request and verifies it using the client public key, and verifies the original authentication request. After verification, it generates a first data group and a ticket granting ticket original text. The first data group includes the ticket issuing server entity and a second random number. The ticket granting ticket original text includes the client entity, the ticket granting ticket expiration time, and a first ticket type. It signs the ticket granting ticket original text to obtain a ticket granting ticket, combines the first data group and the ticket granting ticket into an original authentication response text, and signs the original authentication response text to obtain an authentication response, and sends the authentication response to the client.
[0010] Preferably, step S3 specifically includes: S3.1: After the client receives the authentication response, it verifies the response. After successful verification, it generates the original ticket request text, signs the original ticket request text to obtain the ticket request, and sends the ticket request to the ticket issuing server. The original ticket request text includes the client entity, the business server entity, the ticket granting ticket, the third random number, and the second timestamp; S3.2: After the ticket issuing server receives the ticket request, it verifies the ticket granting ticket. After successful verification, it generates a second data group, which includes the business server entity and the fourth random number, and uses the authentication server's private key to sign the client public key and the business server public key respectively to obtain the digital signature of the client public key and the digital signature of the business server public key; S3.3: Save the digital signature of the client public key and the digital signature of the business server public key in the database of the key distribution center; S3.4: The ticket issuing server generates the original service ticket text, signs the original service ticket text to obtain the service ticket; the original service ticket text includes the client entity, the service ticket expiration time, the second ticket type, the digital signature of the client public key, and the digital signature of the business server public key; S3.5: The ticket issuing server combines the second data group and the service ticket into the original ticket response text, signs the original ticket response text to obtain the ticket response, and sends the ticket response to the client.
[0011] Preferably, the step S4 specifically includes: S4.1: After the client obtains the ticket response, it verifies the response. After successful verification, it extracts and saves the digital signature of the client public key and the digital signature of the business server public key; S4.2: The client generates a client key exchange public-private key pair using the first key exchange algorithm, which uses the Kyber key exchange algorithm. The client key exchange public-private key pair is used for key exchange between the client and the business server, and includes the client key exchange public key and the client key exchange private key; the client generates the original access request text, which includes the service ticket, the client entity, the third timestamp, the client public key, and the client key exchange public key, signs the original access request text to obtain the access request, and sends the access request to the business server; S4.3: After receiving the access request, the business server conducts verification. After successful verification, it generates a business server key exchange public-private key pair using the Kyber algorithm. The business server key exchange public-private key pair is used for key exchange between the client and the business server, and it includes a business server key exchange public key and a business server key exchange private key. Calculate the shared key and ciphertext based on the client key exchange public key, use the shared key to encrypt the business server's identity information using the SM4 block cipher algorithm to obtain the identity authentication data. The business server identity information includes the business server entity, the fourth timestamp, and the fifth random number, generate the access response original text. The access response original text includes the ciphertext, the business server public key, and the identity authentication data, and after signing the access response original text, obtain the access response, and send the access response to the client.
[0012] Preferably, the step S5 specifically includes: The client extracts the business server public key and the data signature of the business server public key and verifies their correctness. After successful verification, verify the data signature of the access response original text. After successful verification, obtain the shared key based on the ciphertext and the client key exchange private key, decrypt the identity authentication data using the shared key to obtain the business server entity, the fourth timestamp, and the fifth random number and verify them. After successful verification, conduct encrypted communication with the business server using the shared key.
[0013] Preferably, the method of obtaining the authentication request after signing the authentication request original text in the step S2.1 includes: calculating the hash value of the authentication request original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the client private key to obtain the digital signature of the authentication request, and combining the authentication request original text and the digital signature of the authentication request original text to form the authentication request; The method of obtaining the ticket-granting ticket after signing the ticket-granting ticket original text in the step S2.2 includes: calculating the hash value of the ticket-granting ticket original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the ticket-issuing server private key to obtain the digital signature of the ticket-granting ticket original text, and combining the ticket-granting ticket original text and the digital signature of the ticket-granting ticket original text to form the ticket-granting ticket; The method of obtaining the authentication response after signing the authentication response original text in the step S2.2 includes: calculating the hash value of the authentication response original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the authentication server private key to obtain the digital signature of the authentication response original text, and combining the authentication response original text and the digital signature of the authentication response original text to form the authentication response; Preferably, the method for obtaining a ticket request after signing the original ticket request text in step S3.1 includes: calculating a hash value for the original ticket request text using the SM3 cryptographic hash algorithm and encrypting the hash value using the client private key to obtain a digital signature of the original ticket request text, and combining the original ticket request text and the digital signature of the original ticket request text to form a ticket request; The method for obtaining a service ticket after signing the original service ticket text in step S3.4 includes: calculating a hash value for the original service ticket text using the SM3 cryptographic hash algorithm and encrypting the hash value using the private key of the ticket issuing server to obtain a digital signature of the original service ticket text, and combining the original service ticket text and the digital signature of the original service ticket text to form a service ticket; The method for obtaining a ticket response after signing the original ticket response text in step 3.5 includes: calculating a hash value for the original ticket response text using the SM3 cryptographic hash algorithm and encrypting the hash value using the private key of the authentication server to obtain a digital signature of the original ticket response text, and combining the original ticket response text and the digital signature of the original ticket response text to form a ticket response; Preferably, the method for obtaining an access request after signing the original access request text in step 4.2 includes: calculating a hash value for the original access request text using the SM3 cryptographic hash algorithm and encrypting the hash value using the client private key to obtain a digital signature of the original access request text, and combining the original access request text and the digital signature of the original access request text to form an access request; The method for obtaining an access response after signing the original access response text in step 4.3 includes: calculating a hash value for the original access response text using the SM3 cryptographic hash algorithm and encrypting the hash value using the private key of the service server to obtain a digital signature of the original access response text, and combining the original access response text and the digital signature of the original access response text to form an access response.
[0014] The method of the present invention has the capabilities of forward-secure quantum-resistant attack and strong identity authentication. By using the Falcon digital signature algorithm verification system for identity authentication, using the Kyber key exchange algorithm to exchange shared keys to ensure forward-secure secrecy PFS, using the SM3 cryptographic hash algorithm for hash value calculation and signature, and using the SM4 block cipher algorithm as the symmetric encryption algorithm, the authentication method is ensured to be quantum-resistant.
[0015] A quantum-resistant secure identity authentication system for implementing the quantum-resistant secure identity authentication method as described above, comprising: a key configuration module for configuring keys for a client, a service server, and a key distribution center respectively, wherein the key distribution center includes an authentication server, a database, and a ticket issuing server; a client authentication request module for sending authentication request information for obtaining a ticket granting ticket; an authentication server response module for receiving and verifying the authentication request information, and after successful verification, sending an authentication response message carrying the ticket granting ticket to the client; a client ticket request module for receiving and verifying the authentication response message, and after successful verification, sending ticket request information for obtaining a service ticket to the ticket issuing server; a ticket issuing server response module for receiving and verifying the ticket request information, and after successful verification, sending a ticket response message carrying the service ticket to the client; a client access request module for receiving and verifying the ticket response message, and after successful verification, sending access request information for obtaining access rights to the service server; a service server response module for receiving and verifying the access request information, and after successful verification, sending an access response to the client; a client communication module for receiving and verifying the access response, and after successful verification, obtaining a shared key and communicating with the service server using the shared key.
[0016] A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the device where the computer-readable storage medium is located executes the quantum-resistant secure identity authentication method.
[0017] An electronic device, comprising: a memory and a processor, wherein a program that can run on the processor is stored on the memory, and when the processor executes the program, the quantum-resistant secure identity authentication method as described above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The present invention will be further described in detail below with reference to the accompanying drawings: Figure 1 is a schematic flow chart of the method of the present invention; Figure 2 is a schematic diagram of the request and response relationship of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] As Figure 1 shown, a quantum-resistant secure identity authentication method provided by the present invention includes the following steps.
[0020] S1: The client, the business server AP, and the key distribution center KDC perform key configuration in advance. The key distribution center KDC includes a database, an authentication server AS, and a ticket-granting server TGS. The keys are generated using a digital signature algorithm. Specifically, the client uses the Falcon digital signature algorithm to generate the client public key FalconPk_C and the client private key FalconSk_C, and configures the client public key FalconPk_C to the database of the key distribution center KDC. The business server AP uses the Falcon digital signature algorithm to generate the business server public key FalconPk_S and the business server private key FalconSk_S, and configures the business server public key FalconPk_S to the database of the key distribution center KDC. The authentication server AS uses the Falcon digital signature algorithm to generate the authentication server public key FalconPk_G and the authentication server private key FalconSk_G, and configures the authentication server public key FalconPk_G to the client and each business server AP. The ticket-granting server TGS uses the Falcon digital signature algorithm to generate the ticket-granting server public key FalconPk_P and the ticket-granting server private key FalconSk_P, and configures the ticket-granting server public key FalconPk_P to the client and each business server AP. Configuring keys using the Falcon digital signature algorithm improves the security of the keys and ensures resistance to quantum computing attacks.
[0021] As Figure 2 shown, S2: The client sends an authentication request to the authentication server AS. The authentication server AS receives the authentication request from the client, verifies the identity of the client, and issues a ticket-granting ticket TGT after successful verification, and generates an authentication response and returns it to the client. The specific steps are as follows.
[0022] S2.1: The client generates the original authentication request, which includes the client principal principal_client, the business server principal principal_server, a first random number, and a first timestamp. The client principal principal_client is used to represent the information of the client, and the business server principal principal_server is used to represent the information of the business server AP to be accessed. The hash value of the original authentication request is calculated using the SM3 cryptographic hash algorithm, and the hash value is encrypted using the client private key FalconSk_C to obtain the digital signature of the authentication request. Then, the original authentication request and the digital signature of the original authentication request are combined to form the authentication request. After that, the client sends the authentication request to the authentication server AS. Signing using the SM3 cryptographic hash algorithm with the client private key FalconSk_C improves the collision resistance and attack resistance of the digital signature.
[0023] S2.2: After receiving the authentication request, the authentication server AS obtains the digital signature of the original authentication request in the authentication request and verifies it using the client public key FalconPk_C, and verifies the original authentication request. After successful verification, a first data group T1 and a ticket-granting ticket original text are generated. The first data group T1 includes the ticket-granting server principal principal_tgs and a second random number. The ticket-granting ticket original text includes the client principal principal_client, the ticket-granting ticket expiration time, and a first ticket type, and the first ticket type defaults to 1. Calculate the hash value of the ticket-granting ticket original text using the SM3 cryptographic hash algorithm and encrypt the hash value using the ticket-granting server private key FalconSk_P to obtain the digital signature of the ticket-granting ticket original text. Combine the ticket-granting ticket original text and the digital signature TGTSignature of the ticket-granting ticket original text to form the ticket-granting ticket TGT. Combine the first data group T1 and the ticket-granting ticket TGT to form the original authentication response text. Calculate the hash value of the original authentication response text using the SM3 cryptographic hash algorithm and encrypt the hash value using the authentication server private key FalconSk_G to obtain the digital signature of the original authentication response text, and combine the original authentication response text and the digital signature of the original authentication response text to form the authentication response. After that, the authentication server AS sends the authentication response to the client.
[0024] S3: Based on the authentication response, the client sends a ticket request to the ticket-granting server TGS. The ticket-granting server TGS verifies the validity of the ticket-granting ticket TGT in the ticket request. After successful verification, it issues a service ticket ST and generates a ticket response to return to the client. The specific steps are as follows.
[0025] S3.1: After receiving the authentication response, the client verifies it. First, it verifies the correctness of the digital signature of the original authentication response text. Second, it verifies the correctness of the ticket-granting ticket. After that, it verifies other data. After successful verification, a ticket request original text is generated. The ticket request original text includes the client principal principal_client, the service server principal principal_server, the ticket-granting ticket TGT, a third random number, and a second timestamp. Calculate the hash value of the ticket request original text using the SM3 cryptographic hash algorithm and encrypt the hash value using the client private key FalconSk_C to obtain the digital signature of the ticket request original text. Combine the ticket request original text and the digital signature of the ticket request original text to form the ticket request. The client sends the ticket request to the ticket-granting server TGS.
[0026] S3.2: After receiving the ticket request, the ticket issuing server TGS verifies the ticket-granting ticket TGT. After successful verification, it generates a second data group, which includes the business server principal principal_server and a fourth random number. It uses the authentication server private key FalconSk_G to sign the client public key FalconPk_C and the business server public key respectively to obtain the digital signature of the client public key and the digital signature of the business server public key.
[0027] S3.3: Save the digital signature of the client public key and the digital signature of the business server public key in the database of the key distribution center; S3.4: The ticket issuing server TGS generates the original service ticket, which includes the client principal principal_client, the service ticket expiration time, the second ticket type, the digital signature of the client public key, and the digital signature of the business server public key. The second ticket type defaults to 2. Calculate the hash value of the original service ticket using the SM3 cryptographic hash algorithm and encrypt the hash value using the ticket issuing server private key FalconSk_P to obtain the digital signature of the original service ticket. Combine the original service ticket and the digital signature of the original service ticket to form the service ticket ST.
[0028] S3.5: The ticket issuing server TGS combines the second data group and the service ticket ST into the original ticket response. Calculate the hash value of the original ticket response using the SM3 cryptographic hash algorithm and encrypt the hash value using the authentication server private key FalconSk_G to obtain the digital signature of the original ticket response. Combine the original ticket response and the digital signature of the original ticket response to form the ticket response. The ticket issuing server TGS sends the ticket response to the client.
[0029] S4: After obtaining the ticket response, the client verifies it. After successful verification, the client uses the first key exchange algorithm to generate the client key exchange public key KyberPk_AC and the client key exchange private key KyberSk_AC, and sends an access request to the business server using the service ticket ST and the client key exchange public key KyberPk_AC. After receiving the access request, the business server AP verifies it. After successful verification, it calculates the shared key KyberK_AC and the ciphertext based on the client key exchange public key KyberPk_AC, uses the shared key KyberK_AC to encrypt the identity information of the business server AP to obtain the authentication data Authenticator, and returns an access response to the client using the ciphertext and the authentication data Authenticator. The specific steps are as follows.
[0030] S4.1: After the client obtains the ticket response and passes the verification, it extracts and saves the digital signatures of the client public key and the business server public key.
[0031] S4.2: The client generates a client key exchange public-private key pair using the first key exchange algorithm. The first key exchange algorithm uses the Kyber key exchange algorithm. The client key exchange public-private key pair is used for key exchange between the client and the business server AP. The client key exchange public-private key pair includes the client key exchange public key KyberPk_AC and the client key exchange private key KyberSk_AC. The client generates the original access request, which includes the service ticket ST, the client principal principal_client, the third timestamp, the client public key FalconPk_C, and the client key exchange public key. The client calculates the hash value of the original access request using the SM3 cryptographic hash algorithm and encrypts the hash value using the client private key FalconSk_C to obtain the digital signature of the original access request. The client combines the original access request and the digital signature of the original access request to form the access request. The client sends the access request to the business server AP.
[0032] S4.3: After receiving the access request, the business server AP verifies it. After passing the verification, it uses the Kyber algorithm to generate a business server key exchange public-private key pair. The business server key exchange public-private key pair is used for key exchange between the client and the business server. The business server key exchange public-private key pair includes the business server key exchange public key KyberPk_CA and the business server key exchange private key KyberSk_CA. The client calculates the shared key KyberK_AC and the ciphertext Kyberct_AC based on the client key exchange public key KyberPk_AC, and uses the shared key KyberK_AC to encrypt the identity information of the business server AP using the SM4 block cipher algorithm to obtain the authentication data Authenticator. The business server AP identity information includes the business server principal principal_server, the fourth timestamp, and the fifth random number. The client generates the original access response, which includes the ciphertext Kyberct_AC, the business server public key, and the authentication data Authenticator. The client calculates the hash value of the original access response using the SM3 cryptographic hash algorithm and encrypts the hash value using the business server private key FalconSk_S to obtain the digital signature of the original access response. The client combines the original access response and the digital signature of the original access response to form the access response. The business server AP sends the access response to the client. The shared key exchange is performed through the Kyber key exchange algorithm, avoiding the use of the original password to derive the key for encryption. Even if the original password is leaked, the security of the foregoing communication data can be guaranteed, and it has the ability of forward secrecy.
[0033] S5: Based on the access response, after the client receives the access response, it conducts verification. After the verification passes, it obtains the shared key KyberK_AC by exchanging private keys according to the ciphertext and the client key, and uses the shared key KyberK_AC to conduct encrypted communication with the service server AP. The specific method is as follows.
[0034] The client extracts the public key of the service server and the digital signature of the public key of the service server and verifies its correctness. After the verification passes, it verifies the digital signature of the original access response data. After the verification passes, it obtains the shared key KyberK_AC according to the ciphertext Kyberct_AC and the client key exchange private key. It decrypts the authentication data Authenticator according to the shared key KyberK_AC to obtain the service server principal principal_server, the fourth timestamp, and the fifth random number and conducts verification. After the verification passes, it uses the shared key KyberK_AC to conduct encrypted communication with the service server AP.
[0035] The method of the present invention has the ability of forward-secure quantum-resistant attack and strong identity authentication. By adopting the Falcon digital signature algorithm verification system for identity authentication, using the Kyber key exchange algorithm to exchange shared keys to ensure forward-secure confidentiality PFS, using the SM3 cryptographic hashing algorithm for hash value calculation and signature, and using the SM4 block cipher algorithm as the symmetric encryption algorithm, it ensures that the authentication method is quantum-resistant.
[0036] The present invention also provides a quantum-resistant secure identity authentication system for implementing the quantum-resistant secure identity authentication method, including: a key configuration module for respectively configuring keys for the client, the service server, and the key distribution center. The key distribution center includes an authentication server, a database, and a ticket issuing server; a client authentication request module for sending authentication request information for obtaining a ticket-granting ticket; an authentication server response module for receiving the authentication request information and verifying it, and after the verification passes, sending the authentication response information carrying the ticket-granting ticket to the client; a client ticket request module for receiving the authentication response information and verifying it, and after the verification passes, sending ticket request information for obtaining a service ticket to the ticket issuing server; a ticket issuing server response module for receiving the ticket request information and verifying it, and after the verification passes, sending the ticket response information carrying the service ticket to the client; a client access request module for receiving the ticket response information and verifying it, and after the verification passes, sending access request information for obtaining access rights to the service server; a service server response module for receiving the access request information and verifying it, and after the verification passes, sending an access response to the client; a client communication module for receiving the access response and verifying it, and after the verification passes, obtaining the shared key and communicating with the service server using the shared key.
[0037] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the device where the computer-readable storage medium is located executes the anti-quantum secure identity authentication method as described above. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory and other memories, etc.
[0038] The present invention also provides an electronic device, including: a memory and a processor. A program that can run on the processor is stored on the memory. When the processor executes the program, the anti-quantum secure identity authentication method as described above is implemented.
[0039] If the modules / units integrated in the electronic device described in the present application are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present application, it can also be completed by a computer program instructing relevant hardware devices. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented.
[0040] Further, the computer-readable storage medium mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of blockchain nodes, etc.
[0041] The above is only a preferred embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope defined by the claims.
Claims
1. A quantum-resistant secure identity authentication method, characterized in that: The following steps are involved: S1: The client, the service server and the key distribution center configure keys in advance. The key distribution center includes a database, an authentication server and a ticket issuance server. The key is generated using a digital signature algorithm. S2: The client sends an authentication request to the authentication server. The authentication server receives the authentication request and verifies the identity of the client. After successful verification, it issues a ticket granting ticket and generates an authentication response and returns it to the client. S3: Based on the authentication response, the client sends a ticket request to the ticket issuing server. The ticket issuing server verifies the validity of the ticket granting ticket in the ticket request. After successful verification, it issues a service ticket and generates a ticket response and returns it to the client. S4: After the client obtains the ticket response, it performs verification. After the verification is successful, the client uses the first key exchange algorithm to generate a client key exchange public key and a client key exchange private key, and uses the service ticket and the client key exchange public key to send an access request to the business server. After receiving the access request, the business server performs verification. After the verification is successful, the shared key and ciphertext are calculated based on the client key exchange public key, and the shared key is used to encrypt the identity information of the business server to obtain the identity authentication data, and the ciphertext and the identity authentication data are used to return the access response to the client; S5: Based on the access response, the client performs verification after receiving the access response. After the verification is passed, the client obtains the shared key based on the ciphertext and the client key exchange private key, and uses the shared key to perform encrypted communication with the business server.
2. The quantum-resistant secure identity authentication method according to claim 1, characterized in that: The specific steps of pre-configuring keys by the client, the service server and the key distribution center in step S1 include: The client uses a digital signature algorithm to generate a client public key and a client private key, and configures the client public key to the database of the key distribution center. The digital signature algorithm uses the Falcon digital signature algorithm; The business server uses the Falcon digital signature algorithm to generate the business server public key and business server private key, and configures the business server public key to the database of the key distribution center; The authentication server uses the Falcon digital signature algorithm to generate the authentication server public key and authentication server private key, and configures the authentication server public key to the client and business server; The ticket issuing server uses the Falcon digital signature algorithm to generate the ticket issuing server public key and ticket issuing server private key, and configures the ticket issuing server public key to the client and business server.
3. The quantum-resistant secure identity authentication method according to claim 1, characterized in that: The step S2 specifically includes: S2.1: The client generates an authentication request text, signs the authentication request text to obtain an authentication request, and sends the authentication request text to the authentication server. The authentication request text includes a client body, a service server body, a first random number, and a first timestamp. The client body is used to represent information about the client, and the service server body is used to represent information about the service server to be accessed. S2.2: After receiving the authentication request, the authentication server obtains the digital signature of the authentication request original text in the authentication request and verifies it using the client public key, and verifies the authentication request original text. After the verification is passed, a first data group and a ticket granting ticket original text are generated, wherein the first data group includes the ticket issuing server body and the second random number, and the ticket granting ticket original text includes the client body, the ticket granting ticket expiration time and the first ticket type. After signing the ticket granting ticket original text, the ticket granting ticket is obtained, the first data group and the ticket granting ticket are combined into the authentication response original text, and the authentication response is obtained after signing the authentication response original text, and the authentication response is sent to the client.
4. The quantum-resistant secure identity authentication method according to claim 3, characterized in that: The step S3 specifically includes: S3.1: After receiving the authentication response, the client verifies it. After passing the verification, it generates a ticket request text, signs the ticket request text to obtain a ticket request, and sends the ticket request text to the ticket issuing server. The ticket request text includes the client body, the service server body, the ticket granting ticket, the third random number and the second timestamp; S3.2: After receiving the ticket request, the ticket issuing server verifies the ticket granting ticket. After the verification is passed, a second data group is generated, wherein the second data group includes the service server subject and the fourth random number, and the authentication server private key is used to sign the client public key and the service server public key to obtain the digital signature of the client public key and the digital signature of the service server public key; S3.3: The digital signature of the client public key and the digital signature of the service server public key are stored in the database of the key distribution center; S3.4: The ticket issuing server generates a service ticket text, and signs the service ticket text to obtain the service ticket; the service ticket text includes the client subject, the service ticket expiration time, the second ticket type, the digital signature of the client public key, and the digital signature of the service server public key; S3.5: The ticket issuing server combines the second data group and the service ticket into a ticket response original text, signs the ticket response original text to obtain a ticket response, and sends the ticket response to the client.
5. The quantum-resistant secure identity authentication method according to claim 4, characterized in that: The step S4 specifically includes: S4.1: After the client obtains the ticket response, it verifies it. After the verification is passed, the digital signature of the client public key and the digital signature of the business server public key are extracted and saved; S4.2: The client generates a client key exchange public-private key pair using a first key exchange algorithm, wherein the first key exchange algorithm uses a Kyber key exchange algorithm, wherein the client key exchange public-private key pair is used for key exchange between the client and the service server, and wherein the client key exchange public-private key pair includes a client key exchange public key and a client key exchange private key; the client generates an access request text, wherein the access request text includes a service ticket, a client principal, a third timestamp, a client public key, and a client key exchange public key, signs the access request text to obtain an access request, and sends the access request to the service server; S4.3: After receiving the access request, the business server performs verification. After the verification is passed, the Kyber algorithm is used to generate a business server key exchange public-private key pair, which is used for key exchange between the client and the business server. The business server key exchange public-private key pair includes a business server key exchange public key and a business server key exchange private key. The shared key and ciphertext are calculated according to the client key exchange public key, and the shared key is used to encrypt the identity information of the business server using the SM4 block cipher algorithm to obtain identity authentication data. The business server identity information includes the business server subject, the fourth timestamp and the fifth random number. The access response original is generated, and the access response original includes the ciphertext, the business server public key and the identity authentication data. The access response original is signed to obtain the access response, and the access response is sent to the client.
6. The quantum-resistant secure identity authentication method according to claim 5, characterized in that: The step S5 specifically includes: The client extracts the business server public key and the data signature of the business server public key and verifies their correctness. After the verification is passed, the data signature of the access response original is verified. After the verification is passed, the shared key is obtained based on the ciphertext and the client key exchange private key. The identity authentication data is decrypted based on the shared key to obtain the business server subject, the fourth timestamp and the fifth random number and verify them. After the verification is passed, the shared key is used to encrypt communication with the business server.
7. The quantum-resistant secure identity authentication method according to claim 3, characterized in that: The method for obtaining the authentication request after signing the authentication request original text in step S2.1 comprises: calculating a hash value of the authentication request original text by using the SM3 cryptographic hash algorithm and encrypting the hash value by using the client private key to obtain the digital signature of the authentication request, and forming the authentication request original text and the digital signature of the authentication request original text into an authentication request; The method for obtaining a bill granting bill after signing the bill granting bill original text in step S2.2 comprises: calculating a hash value of the bill granting bill original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the bill issuing server private key to obtain a digital signature of the bill granting bill original text, and combining the bill granting bill original text and the digital signature of the bill granting bill original text into a bill granting bill; The method for obtaining an authentication response after signing the authentication response original text described in step S2.2 includes: calculating a hash value for the authentication response original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the authentication server private key to obtain the digital signature of the authentication response original text, and combining the authentication response original text and the digital signature of the authentication response original text into an authentication response.
8. The quantum-resistant secure identity authentication method according to claim 4, characterized in that: The method for obtaining the bill request after signing the bill request original text in step S3.1 includes: calculating a hash value of the bill request original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the client private key to obtain a digital signature of the bill request original text, and combining the bill request original text and the digital signature of the bill request original text into a bill request; The method for obtaining a service ticket after signing the service ticket original text in step S3.4 includes: calculating a hash value of the service ticket original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the ticket issuing server private key to obtain a digital signature of the service ticket original text, and combining the service ticket original text and the digital signature of the service ticket original text into a service ticket; The method for obtaining a bill response after signing the bill response original text described in step 3.5 includes: calculating a hash value for the bill response original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the authentication server private key to obtain a digital signature of the bill response original text, and combining the bill response original text and the digital signature of the bill response original text into a bill response.
9. The quantum-resistant secure identity authentication method according to claim 5, characterized in that: The method for obtaining the access request after signing the access request original text in step 4.2 includes: calculating a hash value of the access request original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the client private key to obtain the digital signature of the access request original text, and combining the access request original text and the digital signature of the access request original text into an access request; The method for obtaining an access response after signing the access response original text described in step 4.3 includes: calculating a hash value for the access response original text using the SM3 cryptographic hash algorithm and encrypting the hash value using the business server private key to obtain a digital signature of the access response original text, and combining the access response original text and the digital signature of the access response original text into an access response.
10. A quantum-resistant secure identity authentication system, characterized in that: A method for implementing the quantum-resistant secure identity authentication method according to any one of claims 1 to 9, comprising: A key configuration module, used to configure keys for the client, the business server and the key distribution center respectively, wherein the key distribution center includes an authentication server, a database and a ticket issuance server; A client authentication request module, used for sending authentication request information for obtaining a ticket granting ticket; The authentication server response module is used to receive the authentication request information and verify it, and after the verification is passed, send the authentication response information carrying the ticket granting ticket to the client; The client ticket request module is used to receive the authentication response information and verify it, and after the verification is passed, send the ticket request information for obtaining the service ticket to the ticket issuing server; The ticket issuing server response module is used to receive the ticket request information and verify it, and after verification, send the ticket response information carrying the service ticket to the client; The client access request module is used to receive and verify the ticket response information, and after verification, send access request information for obtaining access rights to the business server; The business server response module is used to receive the access request information and verify it, and send an access response to the client after the verification is passed; The client communication module is used to receive the access response and verify it, obtain the shared key after the verification, and use the shared key to communicate with the business server.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the device where the computer-readable storage medium is located executes the quantum-resistant secure identity authentication method according to any one of claims 1 to 9.
12. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores a program that can be run on the processor, and when the processor executes the program, the quantum-resistant secure identity authentication method according to any one of claims 1 to 9 is implemented.
Citation Information
Cited By
Identity authentication method and system, electronic equipment, storage medium and program product
CN120811769A
Shared service operation method and system based on artificial intelligence
CN120915563A
One-way anti-quantum-attack identity authentication method and device for smart park, and medium
CN120934915A
Smart park one-way anti-quantum attack identity authentication method, device and medium
CN120934915B
Authentication management method of BMC of server and related device
CN121396669A