Secure channel establishment method and related equipment
By registering and calculating the shared key at the respective service providers of the communicating parties and establishing a secure communication channel, the problem of dependence on digital certificates in the existing technology is solved, the establishment of a secure channel without the need for a CA is achieved, and communication security is enhanced.
Patent Information
- Application Number
- CN202511188873.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-25
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-08-25
AI Technical Summary
Existing methods for establishing secure Internet channels rely heavily on digital certificates, which makes it easy for man-in-the-middle attacks to succeed when the CA is attacked or maliciously manipulated, posing a serious security threat.
By registering with the service providers of the first and second communication parties, a shared key is calculated, and a secure communication channel is established between the two parties to achieve identity confirmation without relying on digital certificates.
It enables the establishment of a secure channel without the need for a CA, solves the problem of dependence on digital certificates, enhances communication security, and prevents man-in-the-middle attacks.
Smart Images

Figure CN120675712A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a method for establishing a secure channel and related equipment. Background Art
[0002] In today's internet communications, establishing secure channels is crucial for ensuring the confidentiality, integrity, and identity authentication of information transmission. Currently, building secure internet channels relies heavily on the digital certificate system. Digital certificates are issued by certification authorities (CAs). During network communications, both communicating parties use CA-issued digital certificates to authenticate each other's identities and further establish a shared key to ensure communication security. Take SSL / TLS server certificates, for example. While they generally provide a strong guarantee for network communication security, they present a significant security risk. If a trusted CA is compromised, or if the CA itself performs malicious operations, it could issue a server certificate containing false information that still passes verification. In this scenario, even if the client strictly follows the correct certificate verification process and domain name verification steps, a man-in-the-middle attack can still be easily successful. Past security incidents, such as the TurkTrust CA fraudulent certificate incident, the DigiNotar CA attack, and the Comodo CA security incident, demonstrate that such attacks are not theoretical possibilities but have actually occurred in the real world, posing a serious security threat. Therefore, a new solution is urgently needed to address the reliance on digital certificates in establishing secure internet communications, thereby enabling the establishment of secure channels without the need for CAs. Summary of the Invention
[0003] In order to help solve the problem of reliance on digital certificates when establishing an Internet security channel in related technologies, thereby achieving the effect of establishing a secure channel without the need for a CA, the present application provides a secure channel establishment method and related equipment.
[0004] In a first aspect, the present application provides a method for establishing a secure channel, which adopts the following technical solution: A secure channel establishment method, comprising: The first communication party initiates a registration request to the first service provider and registers with the first service provider; The second communication party initiates a registration request to the second service provider and registers with the second service provider; If both the first communication party and the second communication party have completed registration, the first communication party calculates a first shared key, and the second communication party calculates a second shared key; establishing a secure communication channel between the first communication party and the second communication party based on the first shared key and the second shared key; If both the first communication party and the second communication party have completed registration, the first communication party calculates a first shared key, and the second communication party calculates a second shared key, including: If both the first communication party and the second communication party have completed registration, the first communication party sends a request to obtain the second public key to the second service provider, and the second communication party sends a request to obtain the first public key to the first service provider; The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key; The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party; The first communication party determines whether the second public key is correct, and the second communication party determines whether the first public key is correct; If both the first public key and the second public key are correct, the first communication party calculates a first shared key based on the second public key, and the second communication party calculates a second shared key based on the first public key.
[0005] By adopting the above technical solution, the first communication party registers at the first service provider, and the second communication party registers at the second service provider. When the first communication party and the second communication party have completed registration, the first communication party calculates the second shared key corresponding to the second communication party, and the second communication party calculates the first shared key corresponding to the first communication party. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key; by calculating the first shared key and the second shared key, and judging whether the first shared key and the second shared key are consistent, if they are consistent, it means that the identity confirmation between the first communication party and the second communication party is completed, and there is no need to rely on digital certificates. Therefore, it helps to solve the problem of dependence on digital certificates when establishing an Internet security channel in related technologies, thereby achieving the effect of establishing a secure channel without the need for a CA.
[0006] Optionally, the first communication direction initiating a registration request to the first service provider and registering with the first service provider includes: The first communication direction initiates a registration request to the first service provider, and sends the first user identifier to the first service provider; The first service provider sends the target parameter to the first communication party; The first communication party generates a first public-private key pair based on the target parameter, and sends the first public key in the first public-private key pair to the first service provider; The first service provider updates the public key directory.
[0007] Optionally, the first communication party generating a first public-private key pair based on the target parameter, and sending the first public key in the first public-private key pair to the first service provider includes: The first communication party obtains target data as a first private key based on a preset rule; The first communication party calculates the first public key based on the first user identifier, the target parameter and the first private key; The first communication party sends the first public key to the first service provider.
[0008] Optionally, the first service provider generating a first identity certificate based on the first public key includes: The first service provider obtains the first user identifier and the first public key corresponding to the first communication party; The first service provider obtains a random parameter and calculates a first random public key based on the random parameter; The first service provider calculates a first proof parameter based on the first user identifier, the first public key, and the first random public key; The first service provider obtains the first identity proof based on the random parameter and the first proof parameter; The first proof parameter satisfies the following calculation formula: ; in, represents the first proof parameter, Represents a cryptographic hash algorithm, represents the first user ID, represents the first public key, represents the first random public key, and || represents the connection.
[0009] Optionally, the second communication party determining whether the first public key is correct includes: When the second communication party receives the first public key and the first identity certificate sent by the first service provider, the second communication party obtains the first user identifier, the first public key, the first random public key and the first identity certificate; The second communication party calculates a second proof parameter based on the first user identifier, the first public key, the first random public key and the first identity proof; The second communication party calculates a second random public key based on the target parameter and the second proof parameter; Determining, by the second communication party, whether the second random public key is consistent with the first random public key; If the second random public key is consistent with the first random public key, the second communication party determines that the first public key is correct; The second random public key satisfies the second calculation formula: ; in, is the second random public key, ɡ and q are target parameters, As the first proof of identity, is the second proof parameter.
[0010] Optionally, the first communication party calculating a first shared key based on the second public key includes: The first communication party obtains a second private key; Calculating a first shared key based on the second public key, the first private key, the target parameter, and the second private key; The first shared key satisfies the following calculation formula: ; Among them, key1 is the first shared key, is the second public key, ɡ and q are target parameters, is the first private key, and b is the second private key.
[0011] In a second aspect, the present application also discloses a secure channel establishment system, which adopts the following technical solutions: A secure channel establishment system, comprising: The first communication party module initiates a registration request to the first service provider module and registers at the first service provider module; The second communication party module initiates a registration request to the second service provider module and registers at the second service provider module; If both the first communication party module and the second communication party module are registered, the first communication party module calculates the second shared key corresponding to the second communication party module, and the second communication party module calculates the first shared key corresponding to the first communication party module; If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party module and the second communication party module based on the first shared key and the second shared key.
[0012] By adopting the above technical solution, the first communication party registers at the first service provider, and the second communication party registers at the second service provider. When the first communication party and the second communication party have completed registration, the first communication party calculates the second shared key corresponding to the second communication party, and the second communication party calculates the first shared key corresponding to the first communication party. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key; by calculating the first shared key and the second shared key, and judging whether the first shared key and the second shared key are consistent, if they are consistent, it means that the identity confirmation between the first communication party and the second communication party is completed, and there is no need to rely on digital certificates. Therefore, it helps to solve the problem of dependence on digital certificates when establishing an Internet security channel in related technologies, thereby achieving the effect of establishing a secure channel without the need for a CA.
[0013] In a third aspect, the present application provides a computer device that adopts the following technical solution: An intelligent terminal comprises a memory and a processor, wherein the memory is used to store a computer program that can be run on the processor, and when the processor loads the computer program, the method of the first aspect is executed.
[0014] By adopting the above technical solution, a computer program is generated based on the method of the first aspect and stored in a memory to be loaded and executed by a processor, thereby making an intelligent terminal based on the memory and the processor, which is convenient for users to use.
[0015] In a fourth aspect, the present application provides a computer-readable storage medium, which adopts the following technical solution: A computer-readable storage medium stores a computer program, and when the computer program is loaded by a processor, the method of the first aspect is executed.
[0016] By adopting the above technical solution, a computer program is generated based on the method of the first aspect and stored in a computer-readable storage medium so as to be loaded and executed by a processor. The computer-readable storage medium facilitates the readability and storage of the computer program.
[0017] In summary, this application has the following beneficial technical effects: The first communication party registers at the first service provider, and the second communication party registers at the second service provider. When both the first communication party and the second communication party have completed registration, the first communication party calculates the second shared key corresponding to the second communication party, and the second communication party calculates the first shared key corresponding to the first communication party. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key; by calculating the first shared key and the second shared key, and judging whether the first shared key and the second shared key are consistent, if they are consistent, it means that the identity confirmation between the first communication party and the second communication party is completed, and there is no need to rely on digital certificates. Therefore, it helps to solve the problem of dependence on digital certificates when establishing an Internet security channel in related technologies, thereby achieving the effect of establishing a secure channel without the need for a CA. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 This is a main flow chart of a secure channel establishment method according to an embodiment of the present application; Figure 2 is a flowchart of steps S201 to S204; Figure 3 is a flowchart of steps S301 to S303; Figure 4 is a flowchart of steps S401 to S405; Figure 5 is a flowchart of steps S501 to S504; Figure 6 is a flowchart of steps S601 to S605; Figure 7 It is a flowchart of steps S701 to S702. DETAILED DESCRIPTION
[0019] In a first aspect, the present application discloses a method for establishing a secure channel.
[0020] Reference Figure 1 , a secure channel establishment method, comprising steps S101 to S104: Step S101: a first communication party initiates a registration request to a first service provider and registers with the first service provider.
[0021] Specifically, in this embodiment, the first service provider SPA is the service provider of the first communication party A.
[0022] Step S102: The second communication party initiates a registration request to the second service provider and registers with the second service provider.
[0023] Specifically, in this embodiment, the second service provider SPB is the service provider of the second communication party B.
[0024] Step S103: If both the first communication party and the second communication party have completed registration, the first communication party calculates a first shared key, and the second communication party calculates a second shared key.
[0025] Specifically, in this embodiment, the first shared key is a shared key calculated by the first communication party A, and the second shared key is a shared key calculated by the second communication party B.
[0026] Step S104: If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key.
[0027] Specifically, in this embodiment, it is determined whether the first shared key and the second shared key are consistent. If they are consistent, it means that the shared key calculated by the first communication party and the shared key calculated by the second communication party are the same. Therefore, it can be indicated that the identity confirmation between communication party A and communication party B has been completed, and the secure communication channel between the first communication party and the second communication party has been successfully established.
[0028] The present embodiment provides a method for establishing a secure channel. The first communication party registers at a first service provider, and the second communication party registers at a second service provider. When both the first communication party and the second communication party have completed registration, the first communication party calculates the second shared key corresponding to the second communication party, and the second communication party calculates the first shared key corresponding to the first communication party. If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party and the second communication party based on the first shared key and the second shared key. By calculating the first shared key and the second shared key, and judging whether the first shared key and the second shared key are consistent, if they are consistent, it indicates that identity confirmation is completed between the first communication party and the second communication party, and there is no need to rely on digital certificates. Therefore, it helps to solve the problem of dependence on digital certificates when establishing an Internet secure channel in related technologies, thereby achieving the effect of establishing a secure channel without the need for a CA.
[0029] Reference Figure 2 In one implementation of this embodiment, step S101 wherein the first communication party initiates a registration request to the first service provider, and registering with the first service provider further includes steps S201 to S204: Step S201: A first communication party initiates a registration request to a first service provider and sends a first user identifier to the first service provider.
[0030] Specifically, in this embodiment, when the first communication party A initiates a registration request to the first service provider SPA, it will register its first user ID It is also sent to the SPA. The first user ID is unique and independent in the entire system to prevent identity spoofing.
[0031] Step S202: The first service provider sends the target parameters to the first communication party.
[0032] Specifically, when the first service provider SPA receives the registration request sent by the first communication party A, it selects and saves the target parameters and sends the target parameters to the first communication party A. In this embodiment, the target parameters include q and ɡ, where q is a prime number greater than 2 and ɡ is an integer greater than 1 and less than q.
[0033] Step S203: The first communication party generates a first public-private key pair based on the target parameters, and sends the first public key in the first public-private key pair to the first service provider.
[0034] Specifically, in this embodiment, the first communication party A obtains the corresponding first public-private key pair according to the target parameters q and ɡ, wherein the first public-private key pair includes the first public key and the first private key .
[0035] Step S204: The first service provider updates the public key directory.
[0036] Specifically, in this embodiment, after receiving the first public key, the first service provider SPA will id and the first public key Store it in the local data directory to update the public key directory.
[0037] It is worth noting that, in this embodiment, through similar steps, the second communication party B can register its own second user identity at the second service provider SPB. and the second public key ,in, , b is the second private key corresponding to the second communication party B.
[0038] Reference Figure 3 In one implementation of this embodiment, step S203 in which the first communication party generates a first public-private key pair based on the target parameter and sends the first public key in the first public-private key pair to the first service provider includes steps S301 to S303: Step S301: The first communication party obtains target data as a first private key based on a preset rule.
[0039] Specifically, the preset rule is a pre-set rule for selecting target data. In this embodiment, according to the preset rule, the first communication party A selects a random integer greater than 1 and less than q as target data, and use the target data as the first private key.
[0040] Step S302: The first communication party calculates a first public key based on the first user identifier, the target parameter and the first private key.
[0041] Specifically, the first public key satisfies the following calculation formula: .
[0042] Step S303: The first communication party sends the first public key to the first service provider.
[0043] Reference Figure 4 In one implementation of this embodiment, if both the first communication party and the second communication party have completed registration, step S103, the first communication party calculates the first shared key, and the second communication party calculates the second shared key, including steps S401 to S405: Step S401: If both the first communication party and the second communication party have completed registration, the first communication party sends a request to obtain the second public key to the second service provider, and the second communication party sends a request to obtain the first public key to the first service provider.
[0044] Specifically, in this embodiment, after the first communication party and the second communication party have completed registration, the second communication party B requests the first service provider SPA for the first public key corresponding to the first communication party A. , the first communication party A requests the second public key corresponding to the second communication party B from the second service provider SPB .
[0045] Step S402: The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key.
[0046] Specifically, in this embodiment, the first service provider SPA is the first public key corresponding to the first communication party A Generate a certificate, which is the first identity certificate; the second service provider SPB is the second public key corresponding to the second communication party B Generate a certificate that serves as a second proof of identity.
[0047] Step S403: The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party.
[0048] Specifically, the first service provider SPA sends the first identity certificate corresponding to the first communication party A and the first public key Send to the second communication party B, in this embodiment, the first service provider SPA can Sent to the second communication party B, where is the first public key, The second service provider SPB sends the second identity certificate and the second public key corresponding to the second communication party B to the first communication party A. In this embodiment, the second service provider SPB can Sent to the first communication party A, where is the second public key, As a second proof of identity.
[0049] Step S404: The first communication party determines whether the second public key is correct, and the second communication party determines whether the first public key is correct.
[0050] Specifically, in this embodiment, the first communication party A verifies the second public key corresponding to the second communication party B Is it correct? The second communication party B verifies the first public key corresponding to the first communication party A. Is it correct?
[0051] Step S405: If both the first public key and the second public key are correct, the first communication party calculates a first shared key based on the second public key, and the second communication party calculates a second shared key based on the first public key.
[0052] Reference Figure 5 In one implementation of this embodiment, in step S402, the first service provider generates the first identity certificate based on the first public key, including steps S501 to S504: Step S501: The first service provider obtains a first user identifier and a first public key corresponding to a first communication party.
[0053] Specifically, in this embodiment, the first service provider SPA finds the first user identifier corresponding to the first communication party A from the storage and the first public key .
[0054] Step S502: The first service provider obtains random parameters and calculates a first random public key based on the random parameters.
[0055] Specifically, in this embodiment, the first random public key , where the random parameter is an integer.
[0056] Step S503: The first service provider calculates a first certification parameter based on the first user identifier, the first public key and the first random public key.
[0057] Specifically, in this embodiment, the first proof parameter satisfies the following calculation formula: ; in, represents the first proof parameter, Represents a cryptographic hash algorithm, represents the first user ID, represents the first public key, represents the first random public key, and || represents the connection.
[0058] Step S504: The first service provider obtains the first identity proof based on the random parameter and the first proof parameter.
[0059] Specifically, in this embodiment, the first identity proof .
[0060] Similarly, in this embodiment, the second service provider SPB can also use similar steps to provide the second public key corresponding to the second communication party B. Generate a second ID .
[0061] Reference Figure 6 In one implementation of this embodiment, the second communication party determines whether the first public key is correct in step S404, including steps S601 to S605: Step S601: After receiving the first public key and the first identity certificate sent by the first service provider, the second communication party obtains the first user identifier, the first public key, the first random public key and the first identity certificate.
[0062] Specifically, in this embodiment, the second communication party B receives the first public key and the first identity certificate sent by the first service provider SPA Afterwards, extract 、 、 and .
[0063] Step S602: The second communication party calculates a second proof parameter based on the first user identifier, the first public key, the first random public key and the first identity proof.
[0064] Specifically, in this embodiment, the second proof parameter satisfies the following calculation formula: .
[0065] Step S603: The second communication party calculates a second random public key based on the target parameter and the second proof parameter.
[0066] Specifically, in this embodiment, the second random public key satisfies the second calculation formula: in, is the second random public key, g and q are target parameters, As the first proof of identity, is the second proof parameter.
[0067] Step S604: Determine whether the second random public key determined by the second communication party is consistent with the first random public key.
[0068] Specifically, the second communication party B judges Is it true to judge the second random public key With the first random public key Are they consistent?
[0069] Step S605: If the second random public key is consistent with the first random public key, the second communication party determines that the first public key is correct.
[0070] Specifically, in this embodiment, if the second random public key With the first random public key If consistent, it means If it is established, it can be determined that the first public key is correct. If it is not established, it means that the first public key is incorrect, then the second communication party B exits the secure channel establishment phase and sends a "secure channel establishment failure" message to the first communication party A.
[0071] In this embodiment, the first communication party A also verifies the second public key R corresponding to the second communication party B through similar steps. b Is it correct?
[0072] Reference Figure 7 In one implementation of this embodiment, in step S405, the first communication party calculates the first shared key based on the second public key, including steps S701 to S702: Step S701: The first communication party obtains a second private key.
[0073] Specifically, in this embodiment, the second private key b is a random integer greater than 1 and less than q.
[0074] Step S702: Calculate a first shared key based on the second public key, the first private key, the target parameter, and the second private key.
[0075] Specifically, in this embodiment, the first shared key satisfies the following calculation formula: ; Among them, key1 is the first shared key, is the second public key, g and q are target parameters, is the first private key, and b is the second private key.
[0076] In this embodiment, the second shared key may also be calculated through similar steps, and the second shared key satisfies the following calculation formula: ; Among them, key2 is the second shared key.
[0077] In a second aspect, the present application also discloses a secure channel establishment system.
[0078] A secure channel establishment system, comprising: The first communication party module initiates a registration request to the first service provider module and registers at the first service provider module; The second communication party module initiates a registration request to the second service provider module and registers at the second service provider module; If both the first communication party module and the second communication party module are registered, the first communication party module calculates the second shared key corresponding to the second communication party module, and the second communication party module calculates the first shared key corresponding to the first communication party module; If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communicating party module and the second communicating party module based on the first shared key and the second shared key.
[0079] In a third aspect, an embodiment of the present application discloses an intelligent terminal, comprising a memory and a processor, wherein the memory is used to store a computer program that can be run on the processor, and when the processor loads the computer program, it executes a secure channel establishment method of the above embodiment.
[0080] In a fourth aspect, an embodiment of the present application discloses a computer-readable storage medium, and a computer program is stored in the computer-readable storage medium, wherein when the computer program is loaded by a processor, a secure channel establishment method of the above embodiment is executed.
[0081] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.
Claims
1. A method for establishing a secure channel, characterized in that: include: The first communication party initiates a registration request to the first service provider and registers with the first service provider; The second communication party initiates a registration request to the second service provider and registers with the second service provider; If both the first communication party and the second communication party have completed registration, the first communication party calculates a first shared key, and the second communication party calculates a second shared key; If the first shared key is consistent with the second shared key, establishing a secure communication channel between the first communication party and the second communication party based on the first shared key and the second shared key; If both the first communication party and the second communication party have completed registration, the first communication party calculates a first shared key, and the second communication party calculates a second shared key, including: If both the first communication party and the second communication party have completed registration, the first communication party sends a request to obtain the second public key to the second service provider, and the second communication party sends a request to obtain the first public key to the first service provider; The first service provider generates a first identity certificate based on the first public key, and the second service provider generates a second identity certificate based on the second public key; The first service provider sends the first identity certificate and the first public key to the second communication party, and the second service provider sends the second identity certificate and the second public key to the first communication party; The first communication party determines whether the second public key is correct, and the second communication party determines whether the first public key is correct; If both the first public key and the second public key are correct, the first communication party calculates a first shared key based on the second public key, and the second communication party calculates a second shared key based on the first public key.
2. A secure channel establishment method according to claim 1, characterized in that: The first communication direction initiating a registration request to the first service provider and registering with the first service provider includes: The first communication direction initiates a registration request to the first service provider, and sends the first user identifier to the first service provider; The first service provider sends the target parameter to the first communication party; The first communication party generates a first public-private key pair based on the target parameter, and sends the first public key in the first public-private key pair to the first service provider; The first service provider updates the public key directory.
3. A secure channel establishment method according to claim 2, characterized in that: The first communication party generating a first public-private key pair based on the target parameter, and sending the first public key in the first public-private key pair to the first service provider includes: The first communication party obtains target data as a first private key based on a preset rule; The first communication party calculates the first public key based on the first user identifier, the target parameter and the first private key; The first communication party sends the first public key to the first service provider.
4. A secure channel establishment method according to claim 1, characterized in that: The first service provider generating a first identity certificate based on the first public key includes: The first service provider obtains the first user identifier and the first public key corresponding to the first communication party; The first service provider obtains a random parameter and calculates a first random public key based on the random parameter; The first service provider calculates a first proof parameter based on the first user identifier, the first public key, and the first random public key; The first service provider obtains the first identity proof based on the random parameter and the first proof parameter; The first proof parameter satisfies the following calculation formula: ; in, represents the first proof parameter, Represents a cryptographic hash algorithm, represents the first user ID, represents the first public key, represents the first random public key, and || represents the connection.
5. A secure channel establishment method according to claim 1, characterized in that: The second communication party determines whether the first public key is correct including: When the second communication party receives the first public key and the first identity certificate sent by the first service provider, the second communication party obtains the first user identifier, the first public key, the first random public key and the first identity certificate; The second communication party calculates a second proof parameter based on the first user identifier, the first public key, the first random public key and the first identity proof; The second communication party calculates a second random public key based on the target parameter and the second proof parameter; Determining, by the second communication party, whether the second random public key is consistent with the first random public key; If the second random public key is consistent with the first random public key, the second communication party determines that the first public key is correct; The second random public key satisfies the second calculation formula: ; in, is the second random public key, g and q are target parameters, As the first proof of identity, is the second proof parameter.
6. A secure channel establishment method according to claim 1, characterized in that: The first communication party calculating the first shared key based on the second public key includes: The first communication party obtains a second private key; Calculating a first shared key based on the second public key, the first private key, the target parameter, and the second private key; The first shared key satisfies the following calculation formula: ; Among them, key1 is the first shared key, is the second public key, ɡ and q are target parameters, is the first private key, and b is the second private key.
7. A secure channel establishment system, executing the method according to any one of claims 1 to 6, characterized in that: include: The first communication party module initiates a registration request to the first service provider module and registers at the first service provider module; The second communication party module initiates a registration request to the second service provider module and registers at the second service provider module; If both the first communication party module and the second communication party module are registered, the first communication party module calculates the second shared key corresponding to the second communication party module, and the second communication party module calculates the first shared key corresponding to the first communication party module; If the first shared key is consistent with the second shared key, a secure communication channel is established between the first communication party module and the second communication party module based on the first shared key and the second shared key.
8. An intelligent terminal, comprising a memory and a processor, characterized in that: The memory is used to store a computer program that can be run on the processor, and when the processor loads the computer program, it executes the method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, wherein: When the computer program is loaded into a processor, the method according to any one of claims 1 to 6 is executed.
Citation Information
Patent Citations
Safe communication channel establishment method and system, client and server
CN105141568A
Method for mapping at least two authentication devices to a user account using an authentication server
CN107771383A
Data security channel establishment method, system control processor and boot firmware
CN116340954A
Media data transmission method, apparatus and system
WO2025112578A1