Three-party one-round key negotiation method based on SM9
Through the SM9 key exchange protocol, the key generation center KGC is used to set the main public key and the main private key, which realizes a three-party and one round of key negotiation, solving the problem of low interaction efficiency in multiple rounds of traditional protocols and is suitable for IoT systems.
Patent Information
- Application Number
- CN202510721680.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-12
AI Technical Summary
In the prior art, in the three-party or multi-party communication scenarios, traditional key negotiation protocols require multiple rounds of interaction, are low in efficiency, and lack a three-party one-round key negotiation solution based on domestic commercial cryptography algorithms.
The SM9 key exchange protocol is adopted, and the main public key and the main private key are set through the key generation center KGC, and the device performs key extraction and exchange, realizing a round of key negotiation between three parties and one round of key negotiation. The communication process only requires one round of interaction.
It reduces the number of interactions and calculation overhead, improves the efficiency of tripartite key negotiation, and is suitable for IoT systems.
Smart Images

Figure CN120474703A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network communication privacy protection, and in particular to a three-party one-round key negotiation method based on SM9. Background Art
[0002] The development of network communications has made privacy protection and data security key research areas. Ensuring the confidentiality and integrity of data in multi-party communication scenarios remains a key area of research for many scholars. Key agreement protocols are an effective solution, allowing communicating parties to generate a shared secret key over an insecure channel, effectively ensuring the security of subsequent communications. The traditional Diffie-Hellman key agreement protocol, with its security and simplicity, has been widely used for key agreement in two-way communications. However, when establishing secure communication between three or more parties, the use of the DH protocol requires multiple rounds of interaction, making it relatively inefficient.
[0003] In recent years, researchers have proposed the three-party one-round key agreement. This protocol allows three parties to negotiate and generate a shared key within a single round of interactions, significantly reducing the number of interactions and computational overhead. Compared to traditional multi-round key agreement protocols, the three-party one-round key agreement protocol significantly improves protocol execution efficiency while maintaining security, making it valuable in scenarios where fast secure connections must be established.
[0004] The demand for domestic cryptographic algorithms to be independent, secure, efficient and controllable is put forward, but currently no three-party one-round key negotiation scheme based on domestic commercial cryptographic algorithms has been found. Summary of the Invention
[0005] The purpose of the present invention is to provide a three-party one-round key agreement method based on SM9, apply the SM9 key agreement protocol to the Internet of Things system, and implement the three-party one-round key agreement protocol.
[0006] To achieve the above object, the present invention provides a three-party one-round key agreement method based on SM9, comprising the following steps:
[0007] Step 1: Build an intelligent IoT system that includes a key generation center (KGC) and third-party devices;
[0008] Step 2: The key generation center KGC generates the master public key and master private key based on the security parameters;
[0009] Step 3: The device that needs to communicate extracts the key;
[0010] Step 4: The three devices exchange keys and generate public keys for each of them.
[0011] Optionally, the execution process of step 2 includes the following steps:
[0012] Step 2.1: The key generation center KGC generates an integer d∈[1,N–1] as its master private key;
[0013] Step 2.2: Calculation The element P in pub-e =[d]P1, and P pub-e As the master public key;
[0014] Step 2.3: The key generation center KGC publishes the master public key P pub-e , save the master private key;
[0015] Where N is the integer domain A prime number below is an N-order additive group, P1 is a group The generator of .
[0016] Optionally, the key extraction process in step 3 is as follows: when device i needs to be a communication party, enter the identity ID of device i i , encryption private key generation function identifier hid, the home gateway uses the master private key d to perform the following calculation to obtain the corresponding encryption private key de i ;
[0017] v i =H1(ID i ||hid,V)
[0018] de i =[d(v i +d) -1 ]P2
[0019] Among them, v i User ID i The corresponding identity hash value is used to confirm the identity.
[0020] Optionally, in step 4, the three devices A, B, and C perform key exchange and only perform one round of interaction. The communication process is that device A sends verification data to devices B and C, and receives verification data transmitted by devices B and C.
[0021] Optionally, the key exchange process performed by device A includes the following steps:
[0022] Step 4.1: Before interaction, device A pre-calculates g = e (P pub-e ,P2),Q A =[v A ]P1+P pub-e , Q B =[v B ]P1+P pub-e , Q C=[v C ]P1+P pub-e , v A 、v B 、v C is the identity hash value of the corresponding device, Q A , Q B , Q C To precompute the key;
[0023] Step 4.2: Device A is randomly selected and calculate R AB =[r A ]Q B 、R AC =[r A ]Q C , R ij is the key value transmitted from i to j;
[0024] Step 4.3: Device A sends R to devices B and C AB and R AC ;
[0025] Step 4.4: Device A receives R transmitted by devices B and C BA 、R CA , and verify whether
[0026] Step 4.5: If verification is successful, further calculation is performed:
[0027]
[0028] g B =e(R BA ,de A );
[0029] g C =e(R CA ,de A );
[0030] g ABC =g A ·g B ·g C ;
[0031] Step 4.6: Device A generates a three-party public key:
[0032] SK=KDF(ID A ||ID B ||ID C ||g A ||g B ||g C ||gABC ,klen).
[0033] The present invention provides a three-party one-round key negotiation method based on SM9. The SM9 key exchange protocol is introduced to build a three-party system. A master public key and a master private key are set by a key generation center (KGC). Then, each user performs key extraction and key exchange respectively. The communication process is that user A sends verification data to users B and C, and receives verification data transmitted by users B and C. The communication cost is only 4|G| (|G| represents the length of the point on the group G). The negotiation method of the present invention only requires one round of interaction to complete the three-party key negotiation. Compared with the traditional three-party multi-round key negotiation protocol, the number of interactions and computational overhead are reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0035] Figure 1 This is a schematic flow chart of the steps of a three-party one-round key negotiation method based on SM9 of the present invention.
[0036] Figure 2 Schematic diagram of the architecture of the RFAUNet network model of the present invention. DETAILED DESCRIPTION
[0037] The following describes embodiments of the present invention in detail, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and are not to be construed as limiting the present invention.
[0038] See also Figure 1 The present invention provides a three-party one-round key negotiation method based on SM9, comprising the following steps:
[0039] Step 1: Build an intelligent IoT system that includes a key generation center (KGC) and third-party devices.
[0040] Step 2: The key generation center KGC generates the master public key and master private key based on the security parameters;
[0041] Step 3: The device that needs to communicate extracts the key;
[0042] Step 4: The three devices exchange keys and generate public keys for each of them.
[0043] The following is further explained with reference to specific embodiments and execution steps:
[0044] The smart Internet of Things system architecture in this embodiment is as follows Figure 2 As shown in the figure, in the smart IoT field, if control commands are not encrypted, attackers may sniff them through WiFi, exposing user behavior. Consider the devices that need to communicate are smart light A, air conditioner B, and speaker C, and the home gateway is KGC.
[0045] In step 2, the security parameter λ is input, and the home gateway generates a master public key and a master private key as follows.
[0046] (1) The home gateway randomly generates an integer d∈[1,N–1] as its master private key.
[0047] (2) Then, the home gateway calculates The element P in pub-e =[d]P1, and P pub-e As the master public key.
[0048] (3) Finally, the home gateway publishes the master public key P pub-e , save the master private key.
[0049] The home gateway acts as the key generation center, and N is an integer domain. A prime number below is an N-order additive group, P1 is a group The generator of .
[0050] Step 3, key extraction:
[0051] When device i needs to be a communication party, enter the device i's ID i , encryption private key generation function identifier hid, the home gateway uses the master private key d to perform the following calculation to obtain the corresponding encryption private key de i .
[0052] (1) Calculate v i =H1(ID i ||hid,N).
[0053] (2) Calculate de i =[d(v i +d) -1 ]P2.
[0054] in is an N-order additive group, P2 is a group The generator of .
[0055] Step 4 is the key exchange process:
[0056] Devices A, B, and C exchange keys. Taking device A as an example, the specific steps are as follows:
[0057] (1) Before interaction, device A pre-calculates g = e(P pub-e ,P2),Q A =[v A ]P1+P pub-e , Q B =[v B ]P1+P pub-e , Q C =[v C ]P1+P pub-e .
[0058] (2) Device A is randomly selected and calculate R AB =[r A ]Q B 、R AC =[r A ]Q C .
[0059] (3) Device A sends R to devices B and C AB and R AC .
[0060] (4) Device A receives R transmitted by devices B and C BA 、R CA , and verify whether
[0061] (5) If the verification is successful, further calculation is performed:
[0062] (a)
[0063] (b)g B =e(R BA ,de A ).
[0064] (c)g C =e(R CA ,de A ).
[0065] (d)g ABC =g A ·g B ·g C .
[0066] (6) After the above steps, device A generates a three-party public key
[0067] SK=KDF(ID A ||ID B ||IDC ||g A ||g B ||g C ||g ABC ,klen).
[0068] The operation of devices B and C is similar to that of device A.
[0069] Furthermore, to analyze the actual performance, the present invention conducted a simulation test on a personal computer. The configuration used was: Intel(R) Core(TM) i7-10875 CPU @ 2.30GHz 5.10GHz, 16GB memory, Windows 10 operating system, and Go-1.24 programming language.
[0070] The average time of running the algorithm 100 times is 51.77ms, of which the average time of the system establishment algorithm is 65.40μs, the average time of the key extraction algorithm is 137.95μs, and the average time of the key exchange algorithm is 16.02ms.
[0071] The three-party one-round key agreement method based on SM9 of the present invention only performs one round of interaction during operation. The main communication process is that user A sends verification data to users B and C, and receives verification data transmitted by users B and C. Representation Group The communication cost is only
[0072] The above disclosure is merely one or more preferred embodiments of the present invention, and certainly cannot be used to limit the scope of the present invention. A person skilled in the art can understand that all or part of the processes of the above embodiments and equivalent changes made in accordance with the claims of the present invention still fall within the scope of the invention.
Claims
1. A three-party one-round key negotiation method based on SM9, characterized in that: The following steps are involved: Step 1: Build an intelligent IoT system that includes a key generation center (KGC) and third-party devices; Step 2: The key generation center KGC generates the master public key and master private key based on the security parameters; Step 3: The device that needs to communicate extracts the key; Step 4: The three devices exchange keys and generate public keys for each of them.
2. The three-party one-round key agreement method based on SM9 according to claim 1, characterized in that: The execution process of step 2 includes the following steps: Step 2.1: The key generation center KGC generates an integer d∈[1,N–1] as its master private key; Step 2.2: Calculation The element P in pub-e =[d]P1, and P pub-e As the master public key; Step 2.3: The key generation center KGC publishes the master public key P pub-e , save the master private key; Where N is the integer domain A prime number below is an N-order additive group, P1 is a group The generator of .
3. The three-party one-round key agreement method based on SM9 according to claim 1, characterized in that: The key extraction process in step 3 is as follows: When device i needs to be a communication party, enter the device i's ID i , encryption private key generation function identifier hid, the home gateway uses the master private key d to perform the following calculation to obtain the corresponding encryption private key de i ; in i =H1(ID i ||hid,V) the i =[d(v i +d) -1 ]P2 Among them, v i User ID i The corresponding identity hash value is used to confirm the identity.
4. The three-party one-round key agreement method based on SM9 according to claim 1, characterized in that: In step 4, the three devices A, B, and C exchange keys in only one round of interaction. The communication process is that device A sends verification data to devices B and C, and receives verification data transmitted by devices B and C.
5. The three-party one-round key agreement method based on SM9 according to claim 4, characterized in that: The key exchange process on device A includes the following steps: Step 4.1: Before interaction, device A pre-calculates g = e (P pub-e ,P2),Q A =[v A ]P1+P pub-e , Q B =[v B ]P1+P pub-e , Q C =[v C ]P1+P pub-e , v A 、v B 、v C is the identity hash value of the corresponding device, Q A , Q B , Q C To precompute the key; Step 4.2: Device A is randomly selected and calculate R AB =[r A ]Q B 、R AC =[r A ]Q C , R ij is the key value transmitted from i to j; Step 4.3: Device A sends R to devices B and C AB and R AC ; Step 4.4: Device A receives R transmitted by devices B and C BA 、R CA , and verify whether Step 4.5: If verification is successful, further calculation is performed: g B =e(R BA ,of A ); g C =e(R CA ,of A ); g ABC =g A ·g B ·g C ; Step 4.6: Device A generates a three-party public key: <h2 style=";text-align:left;direction:ltr">SK = KDF (ID)<h2 style=";text-align:left;direction:ltr"> A <h2 style=";text-align:left;direction:ltr"> ||ID<h2 style=";text-align:left;direction:ltr"> B <h2 style=";text-align:left;direction:ltr"> ||ID<h2 style=";text-align:left;direction:ltr"> C <h2 style=";text-align:left;direction:ltr"> ||g<h2 style=";text-align:left;direction:ltr"> A <h2 style=";text-align:left;direction:ltr"> ||g<h2 style=";text-align:left;direction:ltr"> B <h2 style=";text-align:left;direction:ltr"> ||g<h2 style=";text-align:left;direction:ltr"> C <h2 style=";text-align:left;direction:ltr"> ||g<h2 style=";text-align:left;direction:ltr"> ABC <h2 style=";text-align:left;direction:ltr"> (clean)