Anti-quantum composite digital certificate implementation method and device, equipment and storage medium

By introducing a composite signature and layered verification mechanism of classical cryptographic algorithms and quantum-resistant cryptographic algorithms into the existing certificate system, a combination of public keys and signature values ​​is generated and verified, which solves the problems of inflexible algorithm combinations and imperfect verification mechanisms in existing technologies, and achieves dual security protection and smooth transition in a quantum computing environment.

CN120639503APending Publication Date: 2025-09-12KOAL SOFTWARE CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202511068321.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing quantum-resistant algorithm certificates lack the flexibility and scalability of algorithm combinations in the existing certificate system, and the collaborative verification mechanism between different cryptographic algorithms is not perfect, making it difficult to achieve a smooth transition.

Method used

It adopts a composite signature and layered verification mechanism of classical cryptographic algorithms and quantum-resistant cryptographic algorithms to generate public key combinations and signature value combinations of classical and quantum-resistant algorithms. After verification by the CA certificate authority, it issues a digital certificate. It supports dynamic algorithm configuration and ASN.1/X.509 compatible design.

Benefits of technology

It achieves dual security protection under the threat of quantum computing, supports dynamic configuration of algorithms, smoothly transitions to quantum-resistant cryptographic standards, resists "store first, decrypt later" attacks, and meets long-term quantum-resistant security needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639503A_ABST
    Figure CN120639503A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum composite digital certificate implementation method. The method comprises the following steps: generating a classical cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; combining the classical key algorithm public key and the anti-quantum cryptography algorithm public key to obtain a public key algorithm identifier and a dual-algorithm public key combination; respectively performing signature processing on the certificate request by using a classical cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key, and combining two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination; submitting a composite digital certificate application request to a CA certificate authority; and verifying the dual-algorithm signature value combination by using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issuing the digital certificate if the verification is passed. The invention also discloses a device for realizing the anti-quantum composite digital certificate realization method, computer equipment and a storage medium. According to the invention, dual security assurance under the threat of quantum computing is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptography and information security technology, and in particular to a method, device, equipment and storage medium for implementing a quantum-resistant composite digital certificate. Background Art

[0002] With the rapid development of quantum computing technology, traditional public-key cryptography algorithms (such as RSA and elliptic curve cryptography) are at risk of being cracked by quantum computers. Quantum computers, leveraging properties such as quantum superposition and entanglement, can solve complex problems in a fraction of a second, far beyond the efficiency of classical computers. For example, quantum computers can factor large integers in polynomial time, posing a serious threat to the widely used RSA encryption algorithm.

[0003] Currently, due to the immaturity of quantum-resistant technology and an imperfect ecosystem, it is unrealistic to directly replace all current digital certificates for classical cryptographic algorithms with quantum-resistant algorithm certificates. To achieve a smooth transition to quantum-resistant algorithm certificates, some common solutions are currently available. However, these solutions lack the flexibility and scalability of algorithm combinations within the existing certificate system, and the collaborative verification mechanisms between different cryptographic algorithms are not yet fully developed.

[0004] Therefore, the applicant has found a solution to the above-mentioned problem through beneficial exploration and research. The technical solution to be introduced below is produced in this context. Summary of the Invention

[0005] One of the technical problems to be solved by the present invention is: to address the problem of smooth transition of existing quantum-resistant algorithm certificates, a method for implementing quantum-resistant composite digital certificates is provided. The method combines quantum-resistant cryptographic algorithms with classical cryptographic algorithms, adopts a layered coding structure compatible with the X.509 standard, supports flexible combinations of NIST PQC third-round candidate algorithms, and ensures that cracking a single algorithm does not affect the security of the overall system, which can effectively resist quantum computing attacks and traditional computing attacks.

[0006] The second technical problem to be solved by the present invention is to provide a quantum-resistant composite digital certificate implementation device that implements the above-mentioned quantum-resistant composite digital certificate implementation method.

[0007] The third technical problem to be solved by the present invention is to provide a computer device for implementing the above-mentioned method for implementing quantum-resistant composite digital certificates.

[0008] The fourth technical problem to be solved by the present invention is to provide a computer-readable storage medium for implementing the above-mentioned method for implementing quantum-resistant composite digital certificates.

[0009] As a first aspect of the present invention, a method for implementing a quantum-resistant composite digital certificate includes:

[0010] Generate a classic cryptographic algorithm key pair using a classic key algorithm, and generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0011] Combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0012] Sign the certificate request using the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm, respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0013] Submitting a composite digital certificate application request (CSR) to a CA certificate authority, wherein the composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; and

[0014] The CA certificate authority uses the dual-algorithm public key combination in the composite digital certificate application request to verify the dual-algorithm signature value combination. If the verification is successful, a digital certificate is issued.

[0015] In a preferred embodiment of the present invention, the classical key algorithm is one of the SM2 algorithm, the ECC algorithm or the RSA algorithm, and the quantum-resistant cryptographic algorithm is one of the CRYSTALS-Dilithium algorithm, the FALCON algorithm or the SPHINCS+ algorithm.

[0016] In a preferred embodiment of the present invention, the public key algorithm identifier is in an OID format and the combination of different algorithms is a uniquely determined value. The dual-algorithm public key combination is in an ASN.1 structure and the combination form is not restricted.

[0017] In a preferred embodiment of the present invention, the signature algorithm identifier is in an OID format and the combination of different algorithms is a uniquely determined value. The dual-algorithm signature value combination is an ASN.1 structure and the combination form is not restricted.

[0018] In a preferred embodiment of the present invention, the verification of the dual-algorithm signature value combination by the CA certificate authority using the dual-algorithm public key combination in the composite digital certificate application request includes:

[0019] Extracting a classical cryptographic algorithm public key and a quantum-resistant cryptographic algorithm public key from the dual-algorithm public key combination of the composite digital certificate application request;

[0020] Extracting a classical cryptographic algorithm signature value and a quantum-resistant cryptographic algorithm signature value from the dual-algorithm signature value combination of the composite digital certificate application request;

[0021] Use the public key of the classical cryptographic algorithm and the public key of the quantum-resistant cryptographic algorithm to verify the signature value of the classical cryptographic algorithm and the signature value of the quantum-resistant cryptographic algorithm. If both signature values ​​are verified successfully, a certificate is issued. If any signature value fails to be verified, the digital certificate is refused to be issued.

[0022] In a preferred embodiment of the present invention, the process of issuing the digital certificate includes:

[0023] Find a matching CA quantum-resistant hybrid certificate based on the classical cryptographic algorithm public key in the composite digital certificate application request. If the certificate cannot be found, refuse to issue the certificate.

[0024] When the certificate is found, a digital certificate is generated according to the composite digital certificate application request. The public key in the digital certificate is consistent with the dual-algorithm public key combination in the composite digital certificate application request. The digital certificate is double-signed using the classical cryptographic algorithm private key and the quantum-resistant cryptographic algorithm private key in the CA quantum-resistant hybrid certificate. The two signature values ​​are then assembled into a new signature value structure and placed in the signature value item of the digital certificate.

[0025] As a second aspect of the present invention, a device for implementing a quantum-resistant composite digital certificate for implementing the above-mentioned method for implementing a quantum-resistant composite digital certificate includes:

[0026] A key pair generation module, the key pair generation module is used to generate a classic cryptographic algorithm key pair using a classic key algorithm, and to generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, the classic cryptographic algorithm key pair including a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair including a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0027] A public key combination module, which is used to combine the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0028] A private key signature and combination module, which is used to use the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm to sign the certificate request respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0029] A request sending module, the request sending module is used to submit a composite digital certificate application request (CSR) to a CA certificate authority, the composite digital certificate application request (CSR) including user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; and

[0030] The verification module is used to verify the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issue a digital certificate if the verification is successful.

[0031] As a third aspect of the present invention, a computer device for implementing a method for implementing a quantum-resistant composite digital certificate includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0032] Generate a classic cryptographic algorithm key pair using a classic key algorithm, and generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0033] Combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0034] Sign the certificate request using the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm, respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0035] Submitting a composite digital certificate application request (CSR) to a CA certificate authority, wherein the composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; and

[0036] The CA certificate authority uses the dual-algorithm public key combination in the composite digital certificate application request to verify the dual-algorithm signature value combination. If the verification is successful, a digital certificate is issued.

[0037] As a fourth aspect of the present invention, a computer-readable storage medium for implementing the above-mentioned method for implementing a quantum-resistant composite digital certificate stores a computer program, which, when executed by a processor, implements the following steps:

[0038] Generate a classic cryptographic algorithm key pair using a classic key algorithm, and generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0039] Combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0040] Sign the certificate request using the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm, respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0041] Submitting a composite digital certificate application request (CSR) to a CA certificate authority, wherein the composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; and

[0042] The CA certificate authority uses the dual-algorithm public key combination in the composite digital certificate application request to verify the dual-algorithm signature value combination. If the verification is successful, a digital certificate is issued.

[0043] By employing the above technical solution, the present invention achieves the following beneficial effects: Through a composite signature and layered verification mechanism combining classical and quantum-resistant cryptographic algorithms, it achieves dual security protection against quantum computing threats. Supporting dynamic algorithm configuration and ASN.1 / X.509 compatibility, the present invention seamlessly integrates with existing PKI systems while enabling a smooth transition to quantum-resistant cryptographic standards. Furthermore, through independent key separation verification and a policy-driven model, it resists "store-first, decrypt-later" attacks, meeting the long-term quantum security requirements of diverse scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0045] Figure 1 It is a flow chart of an embodiment of the method for implementing quantum-resistant composite digital certificates of the present invention.

[0046] Figure 2 This is a flow chart of an application embodiment of the method for implementing quantum-resistant composite digital certificates of the present invention.

[0047] Figure 3 It is a structural diagram of an embodiment of the quantum-resistant composite digital certificate implementation device of the present invention.

[0048] Figure 4 It is a diagram of the internal structure of the computer device of the present invention. DETAILED DESCRIPTION

[0049] In order to make the technical means, creative features, objectives and effects achieved by the present invention easier to understand, the present invention is further described below with reference to specific illustrations.

[0050] See also Figure 1 , the figure shows a method for implementing a quantum-resistant composite digital certificate, which includes the following steps:

[0051] Step S10: Generate a key pair for a classical cryptographic algorithm using a classical key algorithm, and generate a key pair for a quantum-resistant cryptographic algorithm using a quantum-resistant cryptographic algorithm. The classical cryptographic algorithm key pair includes a classical cryptographic algorithm public key and a classical cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key. In this embodiment, the classical key algorithm is one of the SM2 algorithm, the ECC algorithm, or the RSA algorithm, and the quantum-resistant cryptographic algorithm is one of the CRYSTALS-Dilithium algorithm, the FALCON algorithm, or the SPHINCS+ algorithm.

[0052] In step S20, the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm are combined to obtain a public key algorithm identifier and a dual-algorithm public key combination. In this embodiment, the public key algorithm identifier is in an OID format and the combination of different algorithms is a unique value. The dual-algorithm public key combination is an ASN.1 structure and has no restrictions on the combination form.

[0053] In step S30, the certificate request is signed using the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm. The two signature results are combined to obtain a signature algorithm identifier and a dual-algorithm signature value combination. In this embodiment, the signature algorithm identifier is in the form of an OID, and the combination of different algorithms is a unique value. The dual-algorithm signature value combination is an ASN.1 structure and has no restrictions on the combination form.

[0054] Step S40: Submit a composite digital certificate application request to the CA certificate authority. The composite digital certificate application request CSR includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination.

[0055] Step S50: The CA certificate authority verifies the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request. If the verification is successful, a digital certificate is issued.

[0056] In step S50, the dual-algorithm signature value combination is verified by the CA certificate authority using the dual-algorithm public key combination in the composite digital certificate application request, including the following steps:

[0057] Step S51, extracting a classical cryptographic algorithm public key and a quantum-resistant cryptographic algorithm public key from the dual-algorithm public key combination in the composite digital certificate application request;

[0058] Step S52: extracting the classical cryptographic algorithm signature value and the quantum-resistant cryptographic algorithm signature value from the dual-algorithm signature value combination of the composite digital certificate application request;

[0059] Step S53: Use the public key of the classical cryptographic algorithm and the public key of the quantum-resistant cryptographic algorithm to verify the signature value of the classical cryptographic algorithm and the signature value of the quantum-resistant cryptographic algorithm. If both signature values ​​are successfully verified, a certificate is issued. If either signature value fails to be verified, the digital certificate is refused to be issued.

[0060] In step S50, the process of issuing a digital certificate includes the following steps:

[0061] Step S54: Find a matching CA quantum-resistant hybrid certificate based on the classical cryptographic algorithm public key in the composite digital certificate application request. If the certificate cannot be found, refuse to issue the certificate.

[0062] Step S55: When the certificate is found, a digital certificate is generated according to the composite digital certificate application request. The public key in the digital certificate is consistent with the dual-algorithm public key combination in the composite digital certificate application request. The digital certificate is double-signed using the classical cryptographic algorithm private key and the quantum-resistant cryptographic algorithm private key in the CA quantum-resistant hybrid certificate. The two signature values ​​are then assembled into a new signature value structure and placed in the signature value item of the digital certificate.

[0063] This invention achieves dual security against the threat of quantum computing through a composite signature and layered verification mechanism combining classical and quantum-resistant cryptographic algorithms. Supporting dynamic algorithm configuration and ASN.1 / X.509 compatibility, this invention seamlessly integrates with existing PKI systems while enabling a smooth transition to quantum-resistant cryptographic standards. Furthermore, through independent key separation verification and a policy-driven model, it resists "store-first, decrypt-later" attacks, meeting the long-term quantum security requirements of various scenarios.

[0064] See also Figure 2 , the figure shows a specific application embodiment of the method for implementing the quantum-resistant composite digital certificate of the present invention, which includes the following steps:

[0065] Step 1: The certificate applicant generates a key pair for a classical cryptographic algorithm and a key pair for a quantum-resistant cryptographic algorithm;

[0066] a. Generate a key pair using a classic cryptographic algorithm, including but not limited to SM2, ECC, and RSA;

[0067] b. Generate a quantum-resistant cryptographic algorithm key pair. Algorithms include but are not limited to CRYSTALS-Dilithium, FALCON, SPHINCS+, etc.

[0068] Step 2: The certificate applicant combines the two algorithms and obtains a public key algorithm identifier and a dual-algorithm public key combination;

[0069] a. The public key algorithm is identified in an OID format, and the combination of different algorithms is a unique value;

[0070] b. The dual algorithm public keys are combined into an ASN.1 structure, with no restrictions on the combination form.

[0071] Step 3: The certificate applicant uses the private keys of the two algorithms to sign the certificate request respectively, and combines them to obtain a signature algorithm identifier and a dual-algorithm signature value combination.

[0072] a. The public key algorithm is identified in an OID format, and the combination of different algorithms is a unique value;

[0073] b. The new public key after combination is an ASN.1 structure, and the combination form is not restricted.

[0074] Step 4: The certificate applicant submits a composite digital certificate application request (CSR) to the certificate authority (CA), which includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination;

[0075] Step 5: The certificate authority (CA) verifies the dual-algorithm signature value combination in the CSR using the dual-algorithm public key combination in the composite digital certificate application request (CSR). The certificate issuance request will only be accepted if both algorithm signature values ​​are verified successfully. Otherwise, the digital certificate will be refused.

[0076] a. The certificate authority (CA) extracts the public key of the classical cryptographic algorithm and the public key of the quantum-resistant cryptographic algorithm from the composite digital certificate application request (CSR);

[0077] b. The certificate authority (CA) extracts the signature value of the classical cryptographic algorithm and the signature value of the quantum-resistant cryptographic algorithm from the composite digital certificate application request (CSR);

[0078] c. Use the classical cryptographic algorithm and the quantum-resistant algorithm public key to verify the signature value respectively. If the signature value verification is successful, the certificate is issued; otherwise, the certificate is refused.

[0079] Step 6: When the certificate authority (CA) issues a digital certificate, the digital certificate contains a dual-algorithm public key combination, and the signature value item of the digital certificate also contains a dual-algorithm signature combination. The digital certificate is then sent to the certificate applicant.

[0080] a. The certificate authority (CA) uses the classical cryptographic algorithm public key in the CSR request to find a matching CA quantum-resistant hybrid certificate. If the certificate cannot be found, it refuses to issue the digital certificate.

[0081] b. The certificate authority (CA) generates a digital certificate based on the CSR. The public key in the certificate is consistent with the public key in the CSR. The CA then uses the classical cryptographic algorithm private key and the quantum-resistant cryptographic algorithm private key in the CA's quantum-resistant hybrid certificate to double-sign the certificate. The two signature values ​​are assembled into a new signature value structure and placed in the signature value item of the digital certificate.

[0082] As can be seen from this example, the present invention can significantly improve the security of digital signature certificates in the face of future quantum computing attacks by introducing a dual-key mechanism of classical cryptographic algorithms and quantum-resistant cryptographic algorithms, and adopting a dual-algorithm joint signing and verification mechanism.

[0083] See also Figure 3 The figure shows a quantum-resistant composite digital certificate implementation device, which includes a key pair generation module 100, a public key combination module 200, a private key signature and combination module 300, a request sending module 400 and a verification module 500.

[0084] The key pair generation module 100 is used to generate a classical cryptographic algorithm key pair using a classical key algorithm, and to generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm. The classical cryptographic algorithm key pair includes a classical cryptographic algorithm public key and a classical cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key.

[0085] The public key combination module 200 is used to combine the public key of the classical key algorithm and the public key of the quantum-resistant cryptographic algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination.

[0086] The private key signature and combination module 300 is used to use the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm to sign the certificate request respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination.

[0087] The request sending module 400 is used to submit a composite digital certificate application request to the CA certificate authority. The composite digital certificate application request CSR includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination.

[0088] The verification module 500 is used to verify the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issue a digital certificate if the verification is successful.

[0089] Each module in the quantum-resistant composite digital certificate implementation device of the present invention can be implemented in whole or in part through software, hardware, or a combination thereof. Each of these modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0090] The present invention also provides a computer device for implementing the above-mentioned quantum-resistant composite digital certificate implementation method. The computer device can be a server, and its internal structure diagram can be as follows: Figure 4 As shown. The computer device includes a processor, memory, network interface and database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as user information, record information and files. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements the above-mentioned method for implementing a quantum-resistant composite digital certificate.

[0091] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the present technical solution, and does not constitute a limitation on the computer device to which the present application solution is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0092] Specifically, the computer device of the present invention includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are implemented:

[0093] Step S10, generating a classic cryptographic algorithm key pair using a classic key algorithm, and generating a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0094] Step S20: combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0095] Step S30: Use the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm to sign the certificate request respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0096] Step S40: Submitting a composite digital certificate application request (CSR) to the CA certificate authority. The composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination.

[0097] Step S50: The CA certificate authority verifies the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request. If the verification is successful, a digital certificate is issued.

[0098] The present invention also provides a computer-readable storage medium for implementing the above-mentioned method for implementing quantum-resistant composite digital certificates, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0099] Step S10, generating a classic cryptographic algorithm key pair using a classic key algorithm, and generating a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key;

[0100] Step S20: combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination;

[0101] Step S30: Use the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm to sign the certificate request respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination;

[0102] Step S40: Submitting a composite digital certificate application request (CSR) to the CA certificate authority. The composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination.

[0103] Step S50: The CA certificate authority verifies the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request. If the verification is successful, a digital certificate is issued.

[0104] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0105] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for implementing quantum-resistant composite digital certificates, characterized in that: include: Generate a classic cryptographic algorithm key pair using a classic key algorithm, and generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, wherein the classic cryptographic algorithm key pair includes a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair includes a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key; Combining the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination; Sign the certificate request using the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm, respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination; Submit a composite digital certificate application request (CSR) to the CA certificate authority, wherein the composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; as well as The CA certificate authority uses the dual-algorithm public key combination in the composite digital certificate application request to verify the dual-algorithm signature value combination. If the verification is successful, a digital certificate is issued.

2. The method for implementing a quantum-resistant composite digital certificate according to claim 1, wherein: The classical key algorithm is one of the SM2 algorithm, the ECC algorithm or the RSA algorithm, and the quantum-resistant cryptographic algorithm is one of the CRYSTALS-Dilithium algorithm, the FALCON algorithm or the SPHINCS+ algorithm.

3. The method for implementing a quantum-resistant composite digital certificate according to claim 1, wherein: The public key algorithm identifier is in an OID format and the combination of different algorithms is a uniquely determined value. The dual-algorithm public key combination is in an ASN.1 structure and the combination form is not restricted.

4. The method for implementing a quantum-resistant composite digital certificate according to claim 1, wherein: The signature algorithm identifier is in an OID format and the combination of different algorithms is a uniquely determined value. The dual-algorithm signature value combination is an ASN.1 structure and the combination form is not restricted.

5. The method for implementing a quantum-resistant composite digital certificate according to claim 1, wherein: The verifying the dual-algorithm signature value combination by using the dual-algorithm public key combination in the composite digital certificate application request by the CA certificate authority includes: Extracting a classical cryptographic algorithm public key and a quantum-resistant cryptographic algorithm public key from the dual-algorithm public key combination of the composite digital certificate application request; Extracting a classical cryptographic algorithm signature value and a quantum-resistant cryptographic algorithm signature value from the dual-algorithm signature value combination of the composite digital certificate application request; Use the public key of the classical cryptographic algorithm and the public key of the quantum-resistant cryptographic algorithm to verify the signature value of the classical cryptographic algorithm and the signature value of the quantum-resistant cryptographic algorithm. If both signature values ​​are verified successfully, a certificate is issued. If any signature value fails to be verified, the digital certificate is refused to be issued.

6. The method for implementing a quantum-resistant composite digital certificate according to claim 5, wherein: The issuance process of the digital certificate includes: Find a matching CA quantum-resistant hybrid certificate based on the classical cryptographic algorithm public key in the composite digital certificate application request. If the certificate cannot be found, refuse to issue the certificate. When the certificate is found, a digital certificate is generated according to the composite digital certificate application request. The public key in the digital certificate is consistent with the dual-algorithm public key combination in the composite digital certificate application request. The digital certificate is double-signed using the classical cryptographic algorithm private key and the quantum-resistant cryptographic algorithm private key in the CA quantum-resistant hybrid certificate. The two signature values ​​are then assembled into a new signature value structure and placed in the signature value item of the digital certificate.

7. A device for implementing quantum-resistant composite digital certificates, characterized in that: include: A key pair generation module, the key pair generation module is used to generate a classic cryptographic algorithm key pair using a classic key algorithm, and to generate a quantum-resistant cryptographic algorithm key pair using a quantum-resistant cryptographic algorithm, the classic cryptographic algorithm key pair including a classic cryptographic algorithm public key and a classic cryptographic algorithm private key, and the quantum-resistant cryptographic algorithm key pair including a quantum-resistant cryptographic algorithm public key and a quantum-resistant cryptographic algorithm private key; A public key combination module, which is used to combine the public key of the classical key algorithm and the public key of the quantum-resistant cryptography algorithm to obtain a public key algorithm identifier and a dual-algorithm public key combination; A private key signature and combination module, which is used to use the private key of the classical cryptographic algorithm and the private key of the quantum-resistant cryptographic algorithm to sign the certificate request respectively, and combine the two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination; A request sending module is used to submit a composite digital certificate application request (CSR) to a CA certificate authority, wherein the composite digital certificate application request (CSR) includes user identity information, a dual-algorithm public key combination, and a dual-algorithm signature value combination; as well as The verification module is used to verify the dual-algorithm signature value combination using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issue a digital certificate if the verification is successful.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method for implementing a quantum-resistant composite digital certificate as described in any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for implementing a quantum-resistant composite digital certificate as claimed in any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • Anti-quantum-attack PDF (Portable Document Format) electronic signature method, system and equipment and storage medium

    CN121308987A

  • Digital certificate request file generation and verification method supporting anti-quantum algorithm

    CN121309202A

  • Implementation method and system for anti-quantum-national secret hybrid certificate in public key infrastructure

    CN121441498A

  • Hybrid digital certificate generation method and system based on double-algorithm parallel signature

    CN122027173A