SM9-based client-multi-server rapid self-adaptive key negotiation method

By introducing a client-multi-server fast self-adaptation method into the SM9 key negotiation protocol, the problem of computation and storage limitations in communication between mobile devices and base stations is solved, achieving fast adaptation and efficient communication.

CN120880655APending Publication Date: 2025-10-31SOUTHEAST UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511170666.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In the traditional SM9 key negotiation protocol, mobile devices have limited computing power and storage capacity, making it difficult to communicate efficiently with base station servers. In particular, adapting quickly to the server becomes a challenge in high-speed mobile scenarios.

Method used

A fast, self-adaptive key negotiation method based on SM9, using a client-multiple-server architecture, is proposed. The client initiates a communication request, and multiple servers automatically adapt according to load and latency. The key negotiation process requires only three communications, and the computational overhead is shifted to the server side. The client does not perform complex bilinear operations and uses online/offline optimization techniques for pre-computation.

Benefits of technology

It enables clients to quickly select the optimal server in a multi-server environment, reducing interaction time, improving online response efficiency, and reducing client computational load. It is suitable for communication between mobile devices and base stations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880655A_ABST
    Figure CN120880655A_ABST
Patent Text Reader

Abstract

The invention provides an SM9-based client-multi-server rapid self-adaptive key negotiation method. The SM9-based client-multi-server rapid self-adaptive key negotiation method mainly comprises the following steps: an initialization stage, a private key extraction stage, a broadcasting stage, an offline preparation stage, an online response stage and a session key generation stage. The method has the following characteristics: 1, the method is suitable for a client-multi-server scene, a client initiates a communication request, a plurality of servers are automatically adapted to communicate with the client according to states such as self load and communication delay, and a key negotiation process only needs three times of communication; 2, aiming at a client-server communication mode, computing load optimization is carried out; different from the traditional P2P key negotiation with the same calculation amount of both parties, the method migrates the calculation overhead to the server side as much as possible; and 3, the client does not need to carry out complex bilinear pairing operation, and particularly, the calculated amount in an online response stage can be almost ignored. And meanwhile, an online / offline optimization technology is adopted, so that the client can carry out pre-calculation before communication, and the online response efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer security, specifically relating to a fast self-adaptive key negotiation method for "client-multiple servers" based on SM9. Background Technology

[0002] To address the difficulties in storing and managing certificate systems under traditional public-key cryptography, Shamir proposed Identity-Based Cryptography (IBC) in 1984, which establishes a binding between a user's public key and their identity. IBC eliminates the need for public key certificates to verify the authenticity of public keys. Unlike traditional public-key cryptography, it avoids the complexities of building and managing certificate systems, especially with a large user base, because it does not involve a third-party trusted certificate authority (CA) or its issued certificates. In IBC, a user's public key is a string that identifies that user entity; the authenticity of the public key is naturally linked to the user's identity information, eliminating the need for public key certificates.

[0003] Identity-Based Key Exchange (IBKE) is one of the most fundamental functions of identity-based cryptography. Key exchange technology is primarily used in scenarios where two communicating parties, after authenticating each other's identities, negotiate the same session key value for subsequent communication. No third party other than the two parties wishing to negotiate the key can obtain the final session key. IBKE inherits the advantages of identity-based cryptography, eliminating the need for cumbersome certificate authentication processes, and represents an important research direction in key exchange technology.

[0004] Currently, numerous identity-based cryptographic methods have been proposed and are already being applied in real-world scenarios. The ISO / IEC organization has standardized a series of identity-based cryptographic methods. Among them, the SM9 algorithm, published by the State Cryptography Administration, is a widely recognized identity-based cryptographic scheme with broad applications, including encryption, signatures, and key negotiation. Although the SM9 key negotiation method is widely used in practice, its efficiency is poor in some scenarios due to the complex bilinear pairing operations and the elliptic curve scalar multiplication required before interaction.

[0005] For example, some high-speed moving devices, such as drones and communication equipment on trains, need to communicate with base station servers. In these scenarios, due to the limitations of mobile devices, they may not be able to carry devices capable of complex calculations, and their limited storage capacity prevents them from remaining on standby for extended periods while waiting for signal reception. In contrast, the hardware configuration of base station servers can meet the requirements for long-term standby and complex computation. Compared to lightweight and portable devices, base station servers also have a greater advantage in terms of stability due to their fixed location. On the other hand, because client communication devices are moving at high speeds, the contact time with the base station server is unpredictable, making it another challenge to quickly identify a suitable server and achieve efficient communication.

[0006] This invention addresses the practical problems of the SM9 key negotiation protocol in the aforementioned scenarios by making a series of improvements. It proposes a fast, self-adaptive key negotiation method based on SM9, specifically a "client-multiple server" approach, which improves the efficiency of the SM9 key negotiation algorithm in similar scenarios. The specific improvements are as follows: 1. Applicable to "client-multiple server" scenarios, where the client initiates a communication request, and multiple servers automatically adapt to communicate with the client based on their own load and communication latency. The key negotiation process requires only three communications. 2. Optimized computational load for the client-server communication mode. Unlike traditional P2P key negotiation where both parties have the same computational load, this method shifts computational overhead to the server side as much as possible. 3. The client does not need to perform complex bilinear pairing operations, especially the computational load in the online response phase, which is almost negligible. Simultaneously, online / offline optimization techniques are employed, allowing the client to pre-compute before communication to improve online response efficiency. 4. The server is responsible for calculating the bilinear pairing and sending the result as an exchange message to the client. Upon receiving the exchange message from the client, the server also processes it before using it for session key calculation. Summary of the Invention

[0007] This invention proposes a fast, self-adaptive key negotiation method for client-multiple servers based on SM9. This method allows the client to establish a rapid communication connection with the server, automatically selecting the optimal server among multiple servers based on their current load and communication latency. This method reduces interaction time during communication while ensuring efficient operation during the client's online response phase.

[0008] To achieve the above objectives, the technical method of the present invention is as follows: a fast self-adaptive key negotiation method for "client-multiple servers" based on SM9, the method comprising the following steps:

[0009] Step 1: Initialization phase, run by the key generation center PKG, inputting the security parameter λ, and outputting the system master public-private key pair (mpk, msk), i.e.:

[0010] (mpk,msk)←Setup(1 λ );

[0011] Step 2: Private key extraction stage, run by the key generation center PKG, requires input of the system master public key mpk, master private key msk, and user identity ID. i Output the user's private key d i ,Right now:

[0012] d i ←PrivateKeyExtract(mpk,msk,ID i );

[0013] Step 3: Broadcast phase, using the client ID that initiated the communication. C Run the program and enter the system master public key mpk and the client private key d. C Output the value bd to be broadcast. C and a storage value s for subsequent calculations. C , where s C Stored locally on the client, i.e.:

[0014] (bd C ,s C )←Broadcast(mpk,d C );

[0015] Step 4: Offline preparation phase, consisting of multiple server IDs receiving the broadcast. S1 ID S2 ...run independently, input the system master public key mpk and the client identity identifier ID. C and the broadcast value bd received from the client C Output offline value off S Used for subsequent online key negotiation, i.e.:

[0016] off S ←Offline(mpk,ID C ,bd C );

[0017] Step 5: Online response phase, based on client ID C and an adapter server ID Sj Interactive communication is conducted, with the appropriate server selected from multiple servers based on their current idle status and communication latency policy. The selection is initially based on the appropriate server ID. Sj Input the system master public key mpk and the offline calculation value off generated in step 4. S Output exchange information m S and will exchange information m Sand server identity ID Sj Send to client ID C ,Right now:

[0018] m S ←ServerExchange(mpk,off S );

[0019] Then by client ID C Input the system master public key mpk and the storage value s generated in step 3. C and the server identity ID for communication Sj Output exchange information m C and will exchange information m C Return server ID Sj ,Right now:

[0020] m C ←ClientExchange(mpk,s C ID Sj );

[0021] Step 6: Session key generation phase, based on client ID C and the matching server ID Sj They run independently. The client ID is... C Input the system master public key mpk and the client private key d C Step 3 generates the broadcast value bd C and stored value s C The exchange information m received from the server in step 5 S Output the session key SK for subsequent communication. C ,Right now:

[0022] SK C ←ClientSessionKey(mpk,d C ,bd C ,s C ,m S );

[0023] Server ID Sj Input the system master public key mpk and the server private key d Sj Step 3: Receive the broadcast value bd from the client. C The offline value off generated in step 4 S And the exchange information m received from the client in step 5 C Output the session key SK for subsequent communication. S ,Right now:

[0024] SK S←ServerSessionKey(mpk,d Sj ,bd C ,off S ,m C );

[0025] If both parties to the key agreement execute the correct protocol, the negotiated session key will satisfy SK. C =SK S .

[0026] In Step 3 (broadcast phase), Step 5 (online response phase), and Step 6 (session key generation phase), the client does not need to perform complex bilinear pairing operations. In Step 3 (broadcast phase), the client can pre-calculate the broadcast value; in Step 5 (online response phase), the client only needs to perform simple modular addition and modular multiplication operations; in Step 6 (session key generation phase), the client needs to perform exponentiation operations.

[0027] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the aforementioned SM9-based "client-multiple server" fast self-adaptive key negotiation method.

[0028] A computer-readable storage medium having stored thereon computer instructions that, when executed by a processor, implement the aforementioned SM9-based "client-multiple server" fast self-adaptive key negotiation method.

[0029] Compared with existing SM9 key negotiation algorithms, this invention has the following characteristics:

[0030] (1) The client can quickly select the server side for communication from multiple servers and establish secure communication;

[0031] (2) The computational load during the client's online response phase is negligible, and key negotiation can be completed in a very short interaction time;

[0032] (3) The computational load of the client and the server is different. The client does not need to perform bilinear pairing operations and the computational overhead is migrated to the server as much as possible.

[0033] (4) Applicable to "client-multiple server" scenarios, where the client initiates the communication request, and multiple servers automatically adapt to communicate with the client based on their own load and communication latency. The key negotiation process requires only 3 communications. The computational load is optimized for the client-server communication mode. Unlike traditional P2P key negotiation where both parties have the same computational load, this method shifts the computational overhead to the server side as much as possible. The client does not need to perform complex bilinear pairing operations, and the computational load in the online response phase is almost negligible. Simultaneously, online / offline optimization techniques are employed, allowing the client to pre-compute before communication to improve online response efficiency. The server is responsible for calculating the bilinear pairing and sending the result as an exchange message to the client. Upon receiving the client's exchange message, the server also needs to process it before using it for session key calculation. Attached Figure Description

[0034] Figure 1 This is a flowchart of the present invention.

[0035] Figure 2 This is a schematic diagram illustrating the specific implementation process of the present invention. Detailed Implementation

[0036] To enhance understanding of the present invention, the technical method will be described in detail below with reference to the accompanying drawings.

[0037] Example 1: See Figure 1 , Figure 2 The present invention is implemented as follows: a fast self-adaptive key negotiation method for "client-multiple servers" based on SM9 consists of the following stages.

[0038] Step 1: Initialization Phase: Input the security parameter λ. The Key Generation Center (PKG) generates the master public-private key pair as follows: select three groups of order p with large prime numbers. and a bilinear pair Randomly select generator and random numbers Calculate P pub =[s]P1,v pub =e(P pub P2), Select a hash function The system master public key is published by the Key Generation Center (PKG) along with the additional value HID.

[0039]

[0040] And save the system master private key msk=s.

[0041] Step 2: Private Key Extraction Stage: Input the system master public key mpk, master private key msk=s, and the user's identity ID. i The Key Generation Center (PKG) calculates the user's private key as follows:

[0042]

[0043] If s+H1(ID) occurs with an extremely low probability i If ||hid,p)≡0 (mod p), then the initialization phase in step 1 is repeated to update the entire system parameters. The key generation center PKG will then generate the private key d. i Send user ID via secure channel i .

[0044] Step 3: Broadcast Phase: Input the system master public key mpk and the client private key d C The client ID that initiated the communication C Select random number And calculate [t]P1+[u]P pub ,[x]d C Set the broadcast value bd C =([t]P1+[u]P pub ,[x]d C ), and broadcast the value bd C and client identity ID C Broadcast to all servers. Finally, the random numbers t, u, x, r are... C As stored value s C Save for subsequent calculations.

[0045] Step 4: Offline Preparation Stage: Enter the system master public key (mpk) and client identity ID. C and the broadcast value bd received from the client C =([t]P1+[u]P pub ,[x]d C Each server should be prepared offline as follows: Select a random number. And calculate the exchanged message m S =e([r S ·H1(ID C ||hid,p)]P1+P pub ),[x]d C ), and random number r S and exchange messages m S As offline value off S storage.

[0046] Step 5: Online Response Phase: After the client and adaptation server complete broadcasting and offline preparation, they begin interactive communication. First, the server ID... Sj Input the system master public key mpk and the offline value off generated in step 4. S =(r S ,m S Then, the exchange information m calculated in step 4 is used... S =e([r S ·H1(ID C ||hid,p)]P1+P pub ),[x]d C ) and server identity ID Sj Send Client ID C ; Received exchange information m sent by the server S and identity ID Sj Then, by client ID C Input the system master public key mpk and the storage value s generated in step 3. C =(t,u,x,r) C ) and server identity ID Sj Calculate the exchanged information m C =(r C (H1(ID Sj ||hid,p)-t)mod p,(rC-u)mod p), and finally exchange information m C Send server ID Sj .

[0047] Step 6: Session Key Generation Phase: After the client and the adaptation server complete the information exchange, they each calculate the session key. Among these, the client ID... C Enter the system master public key (mpk) and the client private key. The broadcast value bd generated in step 3 C and stored value s C =(t,u,x,r) C (and the exchange information m received from the server in step 5) S =e([r S ]([H1(ID C ||hid,p)]P1+P pub ),[x]d C First calculate

[0048]

[0049] Then, calculate a session key of length l using the Key Expansion Function (KDF).

[0050] SK C =KDF(ID)C ||ID Sj ||bd C ||m C ||m S ||g1′||g2′||g3′,l);

[0051] Server ID Sj Input the system master public key (mpk) and the server private key. Step 3: Receive the broadcast value bd from the client C =([t]P1+[u]P pub ,[x]d C The offline value off generated in step 4 S =(r S ,m S (and the exchange information m received from the client in step 5) C =(r C (H1(ID Sj ||hid,p)-t)mod p,(r C -u)mod p), first calculate m′ C =[t]P1+[u]P pub +[r C (H1(ID Sj ||hid,p)-t)]P1+[r C -u]P pub =[r C ·H1(ID C ||hid,p)]P1+P pub ); then calculate

[0052]

[0053] Finally, a session key of length l is calculated using the Key Expansion Function (KDF).

[0054] SK S =KDF(ID) C ||ID Sj ||bd C ||m C ||m S ||g1||g2||g3,l).

[0055] The above description is merely one embodiment of the present invention and is detailed, but it should not be construed as limiting the scope of the patent. Any modifications or minor improvements made by those skilled in the art without inventive effort are similarly included within the scope of patent protection of this invention.

Claims

1. A fast, self-adaptive key negotiation method based on SM9 for "client-multiple servers", characterized in that, The method includes the following steps: Step 1: Initialization phase, run by the key generation center PKG, inputting the security parameter λ, and outputting the system master public-private key pair (mpk, msk), i.e.: (msk,msk)←Setup(1 λ ); Step 2: Private key extraction stage, run by the key generation center PKG, requires input of the system master public key msk, master private key msk, and user's identity ID. i Output the user's private key d i ,Right now: d i ←PrivateKeyExtract(mpk,msk,ID i ); Step 3: Broadcast phase, using the client ID that initiated the communication. C Run the program and enter the system master public key mpk and the client private key d. C Output the value bd to be broadcast. C and a storage value s for subsequent calculations. C , where s C Stored locally on the client, i.e.: (bd C ,s C )←Broadcast(mpk,d C ); Step 4: Offline preparation phase, consisting of multiple server IDs receiving the broadcast. S1 ID S2 ...run independently, input the system master public key mpk and the client identity identifier ID. C and the broadcast value bd received from the client C Output offline value off S Used for subsequent online key negotiation, i.e.: off S ←Offline(mpk,ID C ,bd C ); Step 5: Online response phase, based on client ID C and an adapter server ID Sj Interactive communication is conducted, where the appropriate server is selected from multiple servers based on their current idle status and communication latency policy, starting with the appropriate server ID. Sj Input the system master public key mpk and the offline value off generated in step 4. S Output exchange information m S and will exchange information m S and server identity ID Sj Send to client ID C ,Right now: m S ←ServerExchange(mpk,off S ); Then by client ID C Input the system master public key mpk and the storage value s generated in step 3. C and the server identity ID for communication Sj Output exchange information m C and will exchange information m C Return server ID Sj ,Right now: m C ←ClientExchange(mpk,s C ,ID Sj ); Step 6: Session key generation phase, based on client ID C and the adapter server ID Sj They run independently, where the client ID is... C Input the system master public key mpk and the client private key d C Step 3 generates the broadcast value bd C and stored value s C The exchange information m received from the server in step 5 S Output the session key SK for subsequent communication. C ,Right now: SK C ←ClientSessionKey(mpk,d C ,bd C ,s C ,m S ); Server ID Sj Input the system master public key mpk and the server private key d Sj Step 3: Receive the broadcast value bd from the client. C The offline value off generated in step 4 S And the exchange information m received from the client in step 5 C Output the session key SK for subsequent communication. S ,Right now: SK S ←ServerSessionKey(mpk,d Sj ,bd C ,off S ,m C ); If both parties to the key agreement execute the correct protocol, the negotiated session key will satisfy SK. C =SK S .

2. The "client-multiple server" fast self-adaptive key negotiation method based on SM9 according to claim 1, characterized in that, Step 1: Initialization Phase: Input the security parameter λ. The Key Generation Center (PKG) generates the master public-private key pair as follows: select three groups of order p with large prime numbers. And a bilinear pair e: Randomly select generator and random numbers Calculate P pub =[s]P1,v pub =e(P pub P2), Select a hash function The system master public key is published by the Key Generation Center (PKG) along with the additional value HID. And save the system master private key msk=s.

3. The fast self-adaptive key negotiation method based on SM9 for "client-multiple servers" according to claim 2, characterized in that, Step 2: Private Key Extraction Stage: Input the system master public key mpk, master private key msk=s, and the user's identity ID. i The Key Generation Center (PKG) calculates the user's private key as follows: If s+H1(ID) occurs with an extremely low probability i If ||hid,p)≡0 (mod p), then the initialization phase in step 1 is repeated to update the entire system parameters. The key generation center PKG will then generate the private key d. i Send user ID via secure channel i .

4. The "client-multiple server" fast self-adaptive key negotiation method based on SM9 according to claim 3, characterized in that, Step 3: Broadcast Phase: Input the system master public key mpk and the client private key d C The client ID that initiated the communication C Choose random numbers t, u, x, And calculate [t]P1 + [u]P pub ,[x]d C Set the broadcast value bd C =([t]P1+[u]P pub ,[x]d C ), and broadcast the value bd C and client identity ID C Broadcast to all servers, and finally, send the random numbers t, u, x, r. C As stored value s C Save for subsequent calculations.

5. The fast self-adaptive key negotiation method based on SM9 for "client-multiple servers" according to claim 4, characterized in that, Step 4: Offline Preparation Stage: Enter the system master public key (mpk) and client identity ID. C and the broadcast value bd received from the client C =([t]P1+[u]P pub ,[x]d C Each server should be prepared offline as follows, selecting a random number. And calculate the exchange message m S =e([r S ·H1(ID C ||hid,p)]P1+P pub ),[x]d C ), and random number r S and exchange messages m S As offline value off S storage.

6. The fast self-adaptive key negotiation method based on SM9 for "client-multiple servers" according to claim 5, characterized in that, Step 5: Online Response Phase: After the client and adaptation server complete broadcasting and offline preparation, they engage in interactive communication, starting with the server ID. Sj Input the system master public key mpk and the offline value off generated in step 4. S =(r S ,m S Then, the exchange information m calculated in step 4 is used... S =e([r S ·H1(ID C ||hid,p)]P1+P pub ),[x]d C ) and server identity ID Sj Send Client ID C ; Received exchange information m sent by the server S and identity ID Sj Then, by client ID C Input the system master public key mpk and the storage value s generated in step 3. C =(t,u,x,r) C ) and server identity ID Sj Calculate the exchanged information m C =(r C (H1(ID Sj ||hid,p)-t)modp,(r C -u)mod p), finally exchange information m C Send server ID Sj .

7. The fast self-adaptive key negotiation method based on SM9 for "client-multiple servers" according to claim 6, characterized in that, Step 6: Session Key Generation Phase: After the client and the adaptation server complete the information exchange, they each calculate the session key, where the client ID... C Enter the system master public key (mpk) and the client private key. The broadcast value bd generated in step 3 C and stored value s C =(t,u,x,r) C (and the exchange information m received from the server in step 5) S =e([r S ]([H1(ID C ||hid,p)]P1+P pub ),[x]d C First calculate Then, calculate a session key of length l using the Key Expansion Function (KDF). SK C =KDF(ID C ||ID Sj ||bd C ||m C ||m S ||g1′||g2′||g3′,l); Server ID Sj Input the system master public key (mpk) and the server private key. Step 3: Receive the broadcast value bd from the client C =([t]P1+[u]P pub ,[x]d C The offline value off generated in step 4 S =(r S ,m S (and the exchange information m received from the client in step 5) C =(r C (H1(ID Sj ||hid,p)-t)mod p,(r C -u)mod p), first calculate m′ C =[t]P1+[u]P pub +[r C (H1(ID Sj ||hid,p)-t)]P1+[r C -u]P pub =[r C ·H1(ID C ||hid,p)]P1+P pub ); Recalculate Finally, a session key of length l is calculated using the Key Expansion Function (KDF). SK S =KDF(ID C ||ID Sj ||bd C ||m C ||m S ||g1||g2||g3,l)。 8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a fast self-adaptive key negotiation method based on SM9, as described in any one of claims 1 to 7.

9. A computer-readable storage medium storing computer instructions thereon, characterized in that, When executed by the processor, the computer instruction implements a fast, self-adaptive key negotiation method based on SM9 as described in any one of claims 1-7.