Communication encryption method, system, device and equipment and storage medium
By selecting an encryption algorithm based on the type of terminal SIM card, generating a signature public-private key pair and obtaining a communication key, the problems of high hardware requirements, insufficient algorithm flexibility, and weak resistance to quantum attacks in existing instant messaging encryption technologies are solved, achieving highly secure and flexible communication encryption.
Patent Information
- Application Number
- CN202511141433.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-12-09
AI Technical Summary
Existing instant messaging encryption technologies suffer from several problems, including data being stored in plaintext on servers, which makes data easily leaked; high hardware requirements; high barriers to entry; insufficient algorithm flexibility; and weak resistance to quantum attacks.
Select the appropriate encryption algorithm based on the type of terminal SIM card, generate a signature public-private key pair, and obtain the communication key through the key management service to achieve hardware adaptation to multiple encryption algorithms, hierarchical key management and dynamic updates, and support interoperability between different algorithms.
It improves the security, flexibility, and cross-device compatibility of communication encryption, enhances the ability to resist quantum algorithm attacks, and ensures the security and smoothness of communication.
Smart Images

Figure CN121099313A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to communication encryption methods, systems, devices, equipment and storage media. Background Technology
[0002] Instant messaging encryption technology aims to protect user privacy and data security. It has evolved from simple to complex and from centralized to decentralized, but faces security risks such as data leakage, content tampering, identity forgery, and conflicts between regulation and privacy.
[0003] Existing technologies for channel encryption protect transmission links, are transparent to the application layer and are simple to deploy, but data is stored in plaintext on the server, making it vulnerable to leakage due to vulnerabilities. Another type of source encryption has high hardware requirements, requiring users to change their terminals or SIM cards, which raises the barrier to entry. It relies on a single algorithm, does not consider the needs of different scenarios and the interoperability between algorithms, and is difficult to resist quantum algorithm attacks. Summary of the Invention
[0004] This application provides a communication encryption method, system, device, equipment, and storage medium, which can effectively improve the security, flexibility, and cross-device compatibility of communication encryption.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] In a first aspect, this application provides a communication encryption method, the method comprising:
[0007] Based on the SIM card type identified in the first terminal, a first encryption algorithm corresponding to the SIM card is selected. Encryption algorithms for different SIM cards are interoperable. Based on the first encryption algorithm, a signature public-private key pair is generated. The signature public key is sent to the key management service, and the communication key returned by the key management service is received. The signature public-private key pair includes a signature public key and a signature private key.
[0008] The solution provided in this application selects the corresponding encryption algorithm for the SIM card based on its card type in the first terminal. Based on the encryption algorithm, a public-private key pair for the encryption algorithm is generated. The public key is sent to a key management service, and a communication key returned by the key management service is received. The instant messaging service is accessed via login using the communication key. By adapting multiple encryption algorithms to hardware to improve flexibility, and by implementing layered key management and dynamic updates to enhance security, the solution effectively improves the security level and applicability of communication encryption.
[0009] One possible implementation involves SIM card types including: standard SIM cards, super SIM cards, and quantum-resistant SIM cards. Standard SIM cards use a software-based encryption algorithm. Super SIM cards use both a software algorithm and the super SIM card algorithm, while quantum-resistant SIM cards use both a software algorithm and a quantum-resistant algorithm. By adapting the encryption algorithm to the SIM card type, this approach caters to both standard and high-end hardware, improving flexibility. Different algorithm designs address different security needs, enhancing communication encryption reliability. Support for quantum-resistant algorithms proactively mitigates the risk of quantum attacks, broadening the applicable scenarios.
[0010] Another possible implementation is that the encryption algorithms corresponding to different SIM cards are interoperable. Specifically, the super SIM card algorithm corresponding to the super SIM card or the quantum-resistant algorithm corresponding to the quantum-resistant SIM card are both compatible with ordinary SIM cards.
[0011] Another possible implementation, the storage method of the signature private key generated by different first encryption algorithms, can be specifically implemented as follows: the signature private key generated by the soft algorithm is stored in the terminal, the signature private key generated by the super SIM card algorithm is stored in the SIM card, and the signature private key generated by the quantum-resistant algorithm is stored in the quantum-resistant SIM card.
[0012] Another possible implementation, the communication encryption method provided in this application, may further include: specifically, communicating with a second terminal based on an instant messaging service. By adapting to the instant messaging service, end-to-end encrypted communication with the second terminal is achieved, ensuring the security of message transmission.
[0013] Another possible implementation involves communicating with the second terminal using an instant messaging service. Specifically, this can be achieved by: logging into the instant messaging service using a communication key, obtaining the status of the message key corresponding to the second terminal, and then communicating with the second terminal based on the message key status. This approach adapts to the second terminal to implement end-to-end encryption, balancing security and smooth communication.
[0014] Another possible implementation involves the message key's state including an "existence" state. Communication with the peer is based on the message key's state, specifically implemented as follows: when the message key is in an "existence" state, the message to be sent is encrypted using the message key to obtain a first encrypted message, and the key index corresponding to the message key is obtained. The first encrypted message and the key index are then sent to the second terminal. By reusing an existing message key to encrypt the message, the overhead of repeatedly generating keys is reduced, improving encryption efficiency.
[0015] Another possible implementation involves the message key's state including: non-existent state. Communication with the second terminal is based on the message key's state, specifically implemented as follows: when the message key's state is non-existent, the user IDs of the first and second terminals are obtained; these user IDs are encrypted and sent to the key management service; the message key and key index returned by the key management service are received and decrypted; the message key is used to encrypt the message to be sent to obtain a second encrypted message; and the second encrypted message and key index are sent to the second terminal. This ensures smooth end-to-end encryption and enhances the security and reliability of instant messaging.
[0016] Another possible implementation involves communicating with the peer based on the state of the message key. Specifically, this can be achieved by receiving a third encrypted message and its corresponding key index from the second terminal; then using the third message key corresponding to the key index to decrypt the second encrypted message. This allows for rapid key location and improves decryption efficiency.
[0017] Secondly, a communication encryption system is provided, comprising: a first terminal, configured to identify the card type of a SIM card based on the user identity in the first terminal, select a first encryption algorithm corresponding to the SIM card, wherein encryption algorithms corresponding to different SIM cards are interoperable; the first terminal, configured to generate a signature public-private key pair for the encryption algorithm based on the first encryption algorithm, wherein the signature public-private key pair includes a signature public key and a signature private key; the first terminal, configured to send the signature public key to a key management service and receive a communication key returned by the key management service; and the first terminal, configured to log in to an instant messaging service based on the communication key, wherein during the login process, the key management service adapts to the first encryption algorithm through a key conversion protocol.
[0018] In another implementation, the first terminal is also used to communicate with the second terminal according to the instant messaging service.
[0019] In another implementation, the first terminal is also used to: communicate with the second terminal based on the instant messaging service. Specifically, this can be implemented by: logging into the instant messaging service based on the communication key, obtaining the status of the message key corresponding to the second terminal, and communicating with the second terminal based on the status of the message key.
[0020] In another implementation, the first terminal is also used for: the message key's state including: an existence state; and communicating with the second terminal based on the message key's state, including: when the message key's state is existence, using the message key to encrypt the message to be sent to obtain a first encrypted message and obtaining the key index corresponding to the message key, and sending the first encrypted message and the key index to the second terminal.
[0021] In another implementation, the first terminal is also used for: the message key's state including: non-existent state; communicating with the second terminal based on the message key's state, which can be specifically implemented as follows: when the message key's state is non-existent, obtaining the user ID of the first terminal and the user ID of the second terminal; encrypting the user ID of the first terminal and the user ID of the second terminal and sending them to the key management service; receiving and decrypting the message key and key index returned by the key management service; using the message key to encrypt the message to be sent to obtain a second encrypted message, and sending the second encrypted message and key index to the second terminal.
[0022] The technical effects of any implementation method in the second aspect can be found in the technical effects of any implementation method in the first aspect mentioned above, and will not be repeated here.
[0023] Thirdly, a communication encryption device is provided, the device comprising:
[0024] The encryption module selects an encryption algorithm based on the current terminal SIM card and generates a signature public-private key pair for the encryption algorithm. The signature public-private key pair includes a signature public key and a signature private key.
[0025] The processing module sends the signing public key to the key management service and receives the communication key returned by the key management service. The communication key includes: the signing public key generated by the key management service, the communication public key, and a digital envelope containing the end communication private key.
[0026] The communication module uses a communication key to log in and access instant messaging services and communicate with the peer.
[0027] In another implementation, the communication module is also used to communicate with a second terminal based on an instant messaging service.
[0028] In another implementation, the communication module is also used to: log in to access the instant messaging service based on the communication key, obtain the status of the message key corresponding to the second terminal, and communicate with the second terminal based on the status of the message key.
[0029] In another implementation, the communication module is also used to: the message key's state includes: an existence state; when the message key's state is existence, the message to be sent is encrypted using the message key to obtain a first encrypted message and the key index corresponding to the message key is obtained; and the first encrypted message and the key index are sent to the second terminal.
[0030] In another implementation, the communication module is also used to: the message key's state includes: a non-existent state; when the message key's state is non-existent, obtain the user ID of the first terminal and the user ID of the second terminal; encrypt the user ID of the first terminal and the user ID of the second terminal and send them to the key management service; receive and decrypt the message key and key index returned by the key management service; use the message key to encrypt the message to be sent to obtain a second encrypted message; and send the second encrypted message and key index to the second terminal.
[0031] In another implementation, the communication module is also used to: receive the third encrypted message and the corresponding key index sent by the second terminal, and decrypt the third encrypted message using the third message key corresponding to the key index.
[0032] Fourthly, a computer device is provided, comprising: a processor and a memory, wherein the memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the communication encryption method described above.
[0033] Fifthly, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer-readable storage medium, and the at least one computer program is loaded and executed by a processor to implement the communication encryption method described above.
[0034] Sixthly, a computer program product is provided, which includes a computer program or instructions that, when executed by a processor, implement the communication encryption method described above.
[0035] The solutions provided in aspects three through six above are used to implement the method provided in aspect one above, and their specific implementations will not be described in detail here. The technical effects corresponding to any implementation method of the solutions provided in aspects three through six above can be found in the technical effects corresponding to any implementation method in aspect one above, and will not be described in detail here.
[0036] It should be noted that any of the possible implementations of any of the above aspects can be combined, provided that the solutions do not contradict each other. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1A schematic diagram of the computer system architecture provided in the embodiments of this application;
[0039] Figure 2 A flowchart illustrating a communication encryption method provided in an embodiment of this application;
[0040] Figure 3 A flowchart illustrating another communication encryption method provided in an embodiment of this application;
[0041] Figure 4 This is a schematic diagram of the structure of a communication encryption device provided in an embodiment of this application;
[0042] Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0043] In the embodiments of this application, in order to clearly describe the technical solutions of the embodiments of this application, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different. The technical features described by "first" and "second" have no sequential or size order.
[0044] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.
[0045] In the embodiments of this application, at least one can also be described as one or more, and multiple can be two, three, four or more, and this application does not impose any restrictions.
[0046] Furthermore, the network architecture and scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0047] To facilitate understanding, the terms used in the embodiments of this application will be explained first.
[0048] Signature public / private key: refers to the asymmetric key pair used for message signing and signature verification, including a signature private key and a signature public key. The signature private key is generated and privately stored by the client based on the selected encryption algorithm. It is used to sign the message to ensure the integrity of the message and the authenticity of the sender's identity. The signature public key is generated by the client and sent to the key management service. It is used by the receiver or server to verify the validity of the signature.
[0049] Communication public key: The public key in the communication key, generated by the key management service and distributed to the client, is used to control sensitive information transmitted to the client.
[0050] Communication private key: The private key in the communication key is generated by the key management service and sent to the client via a digital envelope. It is used to decrypt received information that has been encrypted with the corresponding communication public key.
[0051] Key Index: Refers to the unique identification information corresponding to the message key. It is generated by the key management service and stored in association with the message key, and is used by the client to retrieve the corresponding message key locally.
[0052] Communication key: refers to a data set containing the key and related verification information generated by the key management service and returned to the client, used for client login to instant messaging services and to implement encrypted communication.
[0053] Key management service: refers to the server-side system that performs key generation, verification, storage, distribution and lifecycle management.
[0054] Digital envelope: refers to an encrypted data structure used for secure transmission of communication private keys. It is generated by a key management service and the communication private key is encrypted to ensure that it can only be decrypted by the target client during transmission.
[0055] It should be noted that all information (including but not limited to device information, personal information of the subject), data (including but not limited to data used for analysis, stored data, and displayed data), and signals involved in this application have been authorized by the subject or fully authorized by all parties, and the collection, use, and processing of related data must comply with relevant laws, regulations, and standards. For example, the user identity and SIM card type involved in this application were obtained with full authorization.
[0056] For example, commonly used instant messaging encryption technologies in the industry are mainly divided into two categories: one is channel encryption, such as link layer protection based on the SSL / TLS protocol. Early versions of MSN Messenger and QQ used this method, which ensures the security of data during transmission by encrypting the transmission link, but the server can decrypt the data and store it in plaintext. The other is source encryption, which is an end-to-end encryption scheme. Data is encrypted at the sending end and decrypted at the receiving end, and the server cannot obtain the plaintext. For example, some mainstream instant messaging tools use the client-side direct encryption mode, which generates a key and encrypts the message through the client to comply with privacy regulations such as GDPR.
[0057] However, existing source encryption technologies have significant limitations: First, they have poor hardware compatibility. For example, some advanced encryption algorithms require dedicated terminals or customized SIM cards, requiring ordinary users to change their devices to use them, resulting in a high barrier to entry. Second, they lack algorithm flexibility. Most solutions only support a single encryption algorithm and cannot switch security levels based on the sensitivity of the chat content. Furthermore, users using different algorithms often experience message decryption failures. Third, they are weak against quantum attacks. Existing algorithms are mostly based on classical cryptography principles. When faced with quantum algorithms such as Shor, passwords that would normally take tens of thousands of years to crack can be broken instantly, making it difficult to cope with the security threats posed by future quantum computing.
[0058] Based on this, this application provides a communication encryption method, system, device, equipment, and storage medium. According to the card type of the SIM card used to identify the user in the first terminal, an encryption algorithm corresponding to the SIM card is selected. Based on the encryption algorithm, a signature public-private key pair is generated. The signature public key is sent to a key management service, and a communication key returned by the key management service is received. The instant messaging service is accessed by logging in using the communication key. By adapting multiple encryption algorithms to hardware to improve flexibility, and by implementing layered key management and dynamic updates to enhance security, the security level and applicability of communication encryption can be effectively improved.
[0059] The solutions provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0060] The solution provided in this application can be applied to Figure 1 In the computer system shown, such as Figure 1 The diagram shows the architecture of the computer system.
[0061] For example, Figure 1 The computer system shown includes a first terminal 101, a second terminal 102, and a key management service 103.
[0062] The first terminal 101 refers to a device that initiates encrypted communication, possessing SIM card access capability and encryption processing function, used to generate a signature key, initiate communication requests, and encrypt message transmission. It can be a smartphone, tablet, IoT terminal with a SIM card, etc. In this application, "acquiring" of the first terminal 101 includes any term with acquisition function such as querying, discovering, and extracting, and this application does not limit this terminology.
[0063] Figure 1 An exemplary first terminal 101 is shown. Optionally, the first terminal 101 may be a mobile terminal that supports cellular networks or a fixed terminal with an integrated SIM card slot.
[0064] Specifically, the first terminal 101 may include: a processor, a memory, a SIM card interface, an encryption algorithm processing module, a communication module, and a key storage module. This application embodiment does not limit the implementation method or application scenario of the first terminal 101.
[0065] Optionally, the second terminal 102 refers to the communication peer device of the first terminal, which has decryption and encryption response capabilities matching the first terminal, and is used to receive encrypted messages, decrypt them, and return encrypted responses. It can be a smartphone, tablet computer, smart device with a SIM card, etc., and may be the same or different from the first terminal.
[0066] Specifically, the second terminal 102 may include: a processor, a memory, a SIM card interface, a decryption algorithm processing module, a communication module, and a key storage module.
[0067] Optionally, the key management service can be implemented in hardware or deployed in software. Both must have the core functions of key generation, storage, distribution, verification, and lifecycle management, and the only difference lies in the implementation carrier and security level.
[0068] Hardware-based key management services typically refer to dedicated key management devices that perform key operations through physically isolated chips, tamper-proof casings, and dedicated encryption circuits. Their core characteristic is that key processing is entirely internal to the hardware, preventing leakage to the external environment. This provides strong resistance to physical attacks and makes them suitable for scenarios with extremely high key security requirements.
[0069] Software-based key management services refer to key management software or service programs running on general-purpose servers. They manage the key lifecycle through software algorithms and rely on the security mechanisms of the server operating system to protect the keys. Their core characteristics are flexible deployment, strong scalability, adaptability to small- to medium-scale communication scenarios, and lower cost than hardware-based services. However, their resistance to attacks depends on the security of the underlying system.
[0070] Optionally, the key management service 103 refers to a server-side system that provides key generation, verification, distribution and lifecycle management, acting as a trust intermediary between the communicating parties and responsible for issuing certificates and deriving message keys.
[0071] Optionally, the key management service 103 can be a physical server, a cloud server cluster, or a dedicated key management device.
[0072] Specifically, the key management service 103 may include: an authentication module, a key generation module, a certificate issuance module, an encrypted transmission module, and a key index management module.
[0073] Specifically, this application provides a schematic diagram of a communication encryption system architecture. The communication encryption system includes: a first terminal, a second terminal, and a key management service.
[0074] Specifically, the first terminal establishes a network connection with the key management service through secure channels such as HTTPS and dedicated encryption protocols.
[0075] After generating a signature public key, the first terminal sends the signature public key and user identity information to the key management server through a secure channel. After verifying the legality of the information, the key management server generates a communication key and returns it to the first terminal through a secure channel.
[0076] Specifically, when the first terminal needs to apply for a message key, it encrypts the user IDs of both parties with the communication public key and sends them to the key management server through a secure channel. It then receives and decrypts the message key, key index, and validity period returned by the server.
[0077] Specifically, the second terminal is identical to the first terminal, establishing a network connection with the key management server through a secure channel, and supporting the same or compatible encrypted transmission protocols.
[0078] In some embodiments, the first terminal and the second terminal establish a communication connection through a P2P (Peer-to-Peer) link of an instant messaging service or a server relay link, and the link layer may be based on the TCP / UDP (Transmission Control Protocol / User Datagram Protocol) protocol.
[0079] TCP (Transmission Control Protocol) is a connection-oriented, reliable transport layer protocol that establishes a connection through a three-way handshake and ensures complete data transmission through an acknowledgment and retransmission mechanism. It is suitable for encrypted communication scenarios (such as critical instruction transmission) where message reliability is a high requirement in this application.
[0080] UDP (User Datagram Protocol) is a connectionless, unreliable transport layer protocol with the characteristics of high transmission speed and low overhead. It is suitable for encrypted communication scenarios with high real-time requirements in this application, such as rapid sending and receiving of instant messages.
[0081] In some embodiments, the data transmission layer is processed using the encryption method of this application.
[0082] Figure 2 This is a flowchart illustrating a communication encryption method provided in an embodiment of this application. The method can be executed by a first terminal. The communication encryption method provided in this embodiment is applicable to scenarios requiring end-to-end communication security. It dynamically selects encryption algorithms based on the terminal's SIM card type, strengthens authentication through keys, and dynamically encrypts transmission based on message key status. This ensures that communication content is not stolen or tampered with, while also being compatible with terminal devices of different security levels. Furthermore, through key indexing and expiration management, efficient reuse and automatic updates of message keys are achieved, improving communication security while reducing key interaction overhead, making it suitable for communication scenarios with high real-time requirements.
[0083] like Figure 2 As shown, the communication encryption method provided in this application embodiment may include:
[0084] Step S201: The first terminal identifies the SIM card type based on the user identity in the first terminal, selects the first encryption algorithm corresponding to the SIM card, and the first encryption algorithms corresponding to different SIM cards are interoperable.
[0085] Among them, user identity refers to the user identification information bound to the SIM card, which is used to uniquely identify the user using the first terminal.
[0086] For example, user identity typically includes the mobile phone number corresponding to the SIM card, the user's registered account, and real-name identity information.
[0087] Optionally, user identity can be represented by the International Mobile Subscriber Identity (IMSI) built into the SIM card, the user ID registered on the terminal, etc., and different forms of user identity can be associated with the same user entity.
[0088] For example, a user's identity could be "mobile number 138xxxx0001". This mobile number is bound to a SIM card and has completed real-name registration on the key management server. The first terminal reads the International Mobile Subscriber Identity (IMSI) of the SIM card to parse the mobile number as the user's identity identifier.
[0089] The card category of the user identification SIM card in the first terminal refers to the classification of SIM cards based on their hardware security capabilities, built-in encryption modules, and supported algorithm types.
[0090] Optionally, the SIM card type can be determined by the terminal reading the SIM card's attribute information, without requiring the user to manually select it.
[0091] In some embodiments, SIM cards are specifically classified as follows: ordinary SIM card (supports only basic communication functions and has no dedicated encryption chip), super SIM card (integrates hardware encryption chip and supports SM2 and other algorithm acceleration), and quantum-resistant SIM card (built-in quantum-resistant encryption module, supports SM2 and quantum-resistant hybrid algorithms).
[0092] Correspondingly, the first terminal selects the soft algorithm, the super SIM card algorithm, and the quantum-resistant algorithm according to the card type of the aforementioned SIM card.
[0093] The encryption algorithms for ordinary SIM cards are: software algorithm; the encryption algorithms for super SIM cards are: software algorithm and super SIM card algorithm; and the encryption algorithms for quantum-resistant SIM cards are: software algorithm and quantum-resistant algorithm.
[0094] Software algorithms refer to encryption algorithms implemented in terminal software. They do not rely on special functions of the SIM card hardware. The encryption program is run by the terminal processor to complete the key generation and encryption / decryption operations. Typical examples are software implementations of algorithms such as SM2 and AES based on the terminal operating system.
[0095] The Super SIM card algorithm refers to an encryption algorithm implemented using the hardware encryption chip built into the Super SIM card. It performs core operations such as key generation and signature calculation through the SIM card chip, typically using a hardware-accelerated implementation based on the Chinese national cryptographic algorithm SM2. This algorithm isolates sensitive key operations within the SIM card chip, offering higher resistance to side-channel attacks compared to software algorithms, making it suitable for scenarios with high security requirements.
[0096] Quantum-resistant algorithms are encryption algorithms that can resist attacks from quantum computers. They introduce quantum-resistant mechanisms on the basis of traditional cryptography, such as the SM2 and quantum-resistant hybrid algorithm used in this application (e.g., based on lattice cryptography, coding cryptography, and other post-quantum cryptosystems).
[0097] The first encryption algorithm refers to the encryption algorithm selected by the first terminal according to the card type of the SIM card, which is compatible with the hardware security capabilities and supported algorithm types of the SIM card. Its types include software algorithms, super SIM card algorithms and quantum-resistant algorithms, and are used to implement secure operations such as signature key generation, communication key negotiation and message encryption during the communication process.
[0098] Specifically, the first encryption algorithm for a regular SIM card is a software algorithm, implemented in terminal software. It uses the Chinese national cryptographic algorithms SM2, SM3, and SM4, and the encryption program is run by the terminal processor to complete key generation and encryption / decryption operations without relying on special hardware functions of the SIM card. The first encryption algorithm for a super SIM card includes both a software algorithm and a super SIM card algorithm. The super SIM card algorithm is implemented using the hardware encryption chip built into the super SIM card and uses the Chinese national cryptographic algorithms SM2, SM3, and SM4, isolating sensitive key operations within the SIM card chip. The first encryption algorithm for a quantum-resistant SIM card includes both a software algorithm and a quantum-resistant algorithm. This quantum-resistant algorithm is a hybrid algorithm based on the Chinese national cryptographic algorithm SM2 and a quantum-resistant mechanism, capable of resisting attacks from quantum computers.
[0099] Interoperability of the first encryption algorithm refers to the ability of terminals using different first encryption algorithms to achieve normal encryption, decryption, and communication of encrypted messages. In other words, encrypted messages sent between users using different encryption algorithms, such as ordinary SIM card users and super SIM card users or quantum-resistant SIM card users, can be correctly decrypted by the other party, ensuring smooth communication links across algorithm types.
[0100] Specifically, different first encryption algorithms mainly affect the generation and management of signature keys and communication keys, but the message encryption key used to encrypt actual communication messages uniformly adopts the national standard SM4 algorithm. Therefore, regardless of which first encryption algorithm the terminal uses, the message encryption key it negotiates and generates follows the SM4 standard, enabling terminals using different first encryption algorithms to encrypt and decrypt messages based on this unified key, thereby achieving interoperability.
[0101] For example, when a regular SIM card user sends a message to a Super SIM card user, the regular SIM card user uses the communication key generated by the software algorithm to obtain the SM4 message encryption key and encrypt the message. The Super SIM card user uses the communication key generated by the Super SIM card algorithm to obtain the same SM4 message encryption key and decrypt the message. The two parties can communicate normally. When a quantum-resistant SIM card user sends a message to a regular SIM card user, the message encryption key corresponding to the communication key generated by the quantum-resistant algorithm is still the SM4 algorithm. The regular SIM card user can decrypt the message using the key system corresponding to the software algorithm, and vice versa.
[0102] Step S202: The first terminal generates a public-private key pair for the signature of the first encryption algorithm based on the first encryption algorithm.
[0103] The signature public key is a public key used to verify the validity of a digital signature. It is generated by an encryption algorithm and can be made public. As the core identifier of the first terminal's identity, the signature public key is sent to the key management server for legality verification. It is also included in the communication key for the second terminal to obtain and use to verify the signature of the message sent by the first terminal, ensuring that the message source is authentic and has not been tampered with.
[0104] A signature private key is a private key that is paired with a signature public key and used to generate digital signatures. It is generated by an encryption algorithm and must be kept strictly confidential.
[0105] In some embodiments, the storage location of the signature private key is bound to the SIM card type of the first terminal: the signature private key corresponding to a regular SIM card is stored in the local encrypted storage area of the first terminal, the signature private key corresponding to a super SIM card is stored in the hardware encryption chip built into the SIM card, and the signature private key corresponding to a quantum-resistant SIM card is stored in the dedicated security module of the quantum-resistant SIM card.
[0106] Specifically, generating a signature public-private key pair for an encryption algorithm means that the first terminal generates a pair of keys with a unique correspondence through preset mathematical operations based on the selected encryption algorithm. The two keys follow the cryptographic logic of "private key signing and public key verification".
[0107] Specifically, if a soft algorithm or a super SIM card algorithm is chosen, it is generated based on the SM2 elliptic curve cryptography algorithm, and the security of the key pair is ensured by the elliptic curve discrete logarithm problem. If a quantum-resistant algorithm is chosen, it is generated based on a hybrid mechanism of SM2 and quantum-resistant algorithms, which takes into account both the security of traditional encryption and the ability to resist quantum attacks.
[0108] Optionally, the generation process can be dynamically adapted to the terminal hardware capabilities:
[0109] When using a soft algorithm, the processor of the first terminal calls the system encryption library to generate a key seed based on a random number generator, and derives the signature public and private key pair through the SM2 algorithm. The entire generation process is completed in the terminal memory, and the private key is encrypted and written to local storage.
[0110] When using the Super SIM card algorithm, the first terminal sends a key generation command to the Super SIM card. The hardware encryption module inside the SIM card independently generates the signature public and private key pair. The private key is stored in the card and cannot be exported. Only the signature public key is returned to the terminal.
[0111] When using quantum-resistant algorithms, the quantum-resistant SIM card of the first terminal first generates a quantum-resistant key component based on the lattice basis algorithm through a dedicated quantum-resistant cryptographic chip, and then merges it with the traditional key component generated by the SM2 algorithm to form a hybrid signature public-private key pair. The private key is stored in a quantum-resistant secure area and has physical anti-tampering characteristics.
[0112] Step S203: The first terminal sends the signing public key to the key management service and receives the communication key returned by the key management service.
[0113] In this context, the first terminal sending the signature public key to the key management server means that the first terminal transmits the locally generated signature public key and the associated user identity information to the key management server through a secure communication link. The purpose is to request the server to verify the legality of the signature public key and issue a communication key for identity authentication based on it.
[0114] Specifically, during the transmission process, the first terminal can encrypt the user's identity information to prevent sensitive information from being stolen during transmission.
[0115] A communication key is a digital credential issued by a key management server to prove the legitimacy of the first terminal's signature public key. It includes: the first terminal's signature public key, the key management server's digital signature of the first terminal's signature public key and user information using its own private key, metadata such as certificate validity period and encryption algorithm type, the communication public key allocated by the key management server, and a digital envelope of the communication private key encrypted with the first terminal's signature public key.
[0116] Optionally, the key management server can enhance the rigor of user identity verification through multi-factor authentication before issuing certificates.
[0117] Optionally, after receiving the certificate, the first terminal will verify the server signature in the certificate, use the public key pre-configured by the key management server, and store the certificate only after confirming that it has not been tampered with, thus avoiding security risks caused by receiving forged certificates.
[0118] Step S204: The first terminal logs in to access the instant messaging service based on the communication key. During the login process, the key management service adapts to the first encryption algorithm through the key conversion protocol.
[0119] Specifically, accessing instant messaging services based on communication keys means that when a first terminal initiates an instant messaging service login request, it submits its communication key as an identity credential to the key management server. The key management server then verifies the validity of the certificate to complete identity authentication and obtain service access permissions.
[0120] For example, the first terminal retrieves the received communication key from local storage and sends it to the key management server through an encrypted channel. The key management server uses a pre-set signing public key to verify the digital signature of the key management server in the certificate, confirming that the certificate has not been tampered with and was issued by a trusted authority. At the same time, it checks the certificate validity period and algorithm type fields to ensure that the certificate is within its validity period and supports encryption algorithms compatible with the server. The key management server extracts the first terminal's signing public key from the certificate and performs association verification with the user account submitted by the first terminal. It confirms that the user identity corresponding to the public key is consistent with the login account. After successful verification, the key management server returns login credentials to the first terminal, allowing the first terminal to access the service and open the encrypted communication channel. At the same time, it records the encryption algorithm types supported by the terminal to provide a basis for subsequent communication adaptation with the second terminal.
[0121] A key conversion protocol is a protocol mechanism between a key management service and a terminal used to achieve key format conversion, verification rule adaptation, and unified key interaction logic for different encryption algorithms. Its core is to ensure that the key management service can identify and process the key type corresponding to the first encryption algorithm used by the terminal, and realize key generation, verification, and distribution across algorithm types.
[0122] Specifically, the key conversion protocol defines the key format specifications, key verification rules, and key interaction procedures for different encryption algorithms, enabling the key management service to dynamically adjust the key processing logic based on the terminal's first encryption algorithm type.
[0123] Key format specifications, such as the SM2 key format for soft algorithms, the hardware-encapsulated key format for the Super SIM card algorithm, and the hybrid key format for quantum-resistant algorithms;
[0124] Key verification rules, such as terminal local signature verification using soft algorithms, hardware signature verification using super SIM card algorithms, and hybrid signature verification using quantum-resistant algorithms.
[0125] Key exchange processes, such as the encapsulation and parsing methods of digital envelopes, and the private key storage location adapted to different algorithms.
[0126] The key management service adapts to the first encryption algorithm through the key conversion protocol. This means that during the terminal login process, the key management service identifies the type of the first encryption algorithm used by the first terminal through the aforementioned key conversion protocol, and matches the key generation, verification, and distribution process of the server with the characteristics of the algorithm. This ensures that the generated key, certificate, and digital envelope can be correctly parsed and used by the terminal, supporting the terminal to complete login verification based on the corresponding algorithm.
[0127] Specifically, after receiving the signature public key sent by the first terminal, the key management service parses the algorithm identifier carried in the public key through the key conversion protocol to determine the terminal's first encryption algorithm type. Subsequently, the server generates an appropriate signature public and private key and a communication key according to the key generation rules corresponding to the algorithm in the protocol. At the same time, according to the encapsulation method defined in the protocol, the communication private key is encapsulated into a digital envelope adapted to the algorithm. For example, for the Super SIM card algorithm, the decryption key of the digital envelope needs to be adapted to the decryption logic of the SIM card hardware encryption chip; for quantum-resistant algorithms, the digital envelope needs to be compatible with the private key parsing method of quantum-resistant hybrid algorithms to ensure that the terminal can use the private key of the corresponding algorithm to decrypt the digital envelope and obtain the communication key.
[0128] For example, when the first terminal uses the Super SIM card algorithm, the key management service identifies the algorithm type through the key conversion protocol, generates an SM2 communication key adapted to the hardware encryption chip according to the rules of the Super SIM card algorithm in the protocol, and encapsulates the communication private key into a digital envelope that needs to be decrypted by the private key in the Super SIM card; the terminal decrypts the digital envelope by the private key in the Super SIM card, obtains the communication key, and completes the login, thus realizing the adaptation between the server and the Super SIM card algorithm.
[0129] For example, when the first terminal uses a quantum-resistant algorithm, the key management service identifies it through the key conversion protocol and generates a communication key in a hybrid format of national cryptography and quantum resistance according to the rules of the quantum-resistant hybrid algorithm in the protocol. The communication private key is then encapsulated into a digital envelope that is compatible with the decryption of the hybrid private key in the quantum-resistant SIM card. The terminal uses the private key in the quantum-resistant SIM card to decrypt the envelope to obtain the key and complete the login, demonstrating the server's adaptation to the algorithm through the protocol.
[0130] In summary, the solution provided in this embodiment proposes a communication encryption method. Based on the card type of the SIM card used to identify the user in the first terminal, an encryption algorithm corresponding to the SIM card is selected. A signature public-private key pair for the encryption algorithm is generated. The signature public key is sent to a key management service, and a communication key returned by the key management service is received. The instant messaging service is accessed via login using the communication key. Hardware adaptation to multiple encryption algorithms enhances flexibility, while layered key management and dynamic updates strengthen security, effectively improving the security level and applicability of communication encryption.
[0131] Figure 3 This is a flowchart illustrating a communication encryption method provided in an embodiment of this application. The method can be executed by a first terminal.
[0132] Step S301: The first terminal identifies the SIM card type based on the user identity in the first terminal, selects the first encryption algorithm corresponding to the SIM card, and the first encryption algorithms corresponding to different SIM cards are interoperable.
[0133] For a description of this step, please refer to step S201; it will not be elaborated upon here.
[0134] Step S302: The first terminal generates a public-private key pair for the encryption algorithm based on the first encryption algorithm.
[0135] For a description of this step, please refer to step S202; it will not be elaborated further here.
[0136] Step S303: The first terminal sends the signing public key to the key management service and receives the communication key returned by the key management service.
[0137] For a description of this step, please refer to step S203; it will not be elaborated further here.
[0138] Step S304: The first terminal logs in to access the instant messaging service based on the communication key. During the login process, the key management service adapts to the first encryption algorithm through the key conversion protocol.
[0139] For a description of this step, please refer to step S204; it will not be elaborated further here.
[0140] Step S305: The first terminal communicates with the second terminal according to the instant messaging service.
[0141] The first terminal completes the process of verifying its identity and obtaining communication permissions by submitting a communication key to the key management server.
[0142] Specifically, the first terminal sends the communication key to the key management server. The key management server verifies the server signature on the certificate using the pre-set key management server public key, confirming that the certificate is authentic, valid, and within its validity period. At the same time, it verifies that the user identity in the certificate matches the terminal identifier. After successful verification, the first terminal is allowed to access the service and a communication channel with the second terminal is opened.
[0143] Optionally, a dynamic verification mechanism can be added to the login process: the key management server sends a random challenge code to the first terminal, the first terminal signs the challenge code with its private key and returns it, and the key management server verifies the signature with the public key in the certificate to further confirm that the first terminal holds a legitimate private key and prevent the certificate from being illegally copied and used.
[0144] In some embodiments, the first terminal obtains the status of the message key corresponding to the second terminal.
[0145] The status of the message key refers to the existence and validity of the message key stored locally on the first terminal for communication with the second terminal. Its core purpose is to determine whether direct encrypted communication is possible.
[0146] Specifically, the status of the message key is determined by the following information: the first terminal queries the local key storage module to check whether there is a message key record bound to the second terminal user ID, and whether the key in the record is within its validity period.
[0147] In some embodiments, the first terminal communicates with the second terminal based on the state of the message key.
[0148] Specifically, the first terminal communicates with the second terminal based on the status of the message key, and needs to perform differentiated processes according to the two states of the key: "existing" or "not existing".
[0149] The message key's status includes: present status and non-present status.
[0150] The existence status means that the message key corresponding to the second terminal has been stored in the local key storage area of the first terminal, and the key is within the validity period and has not been marked as invalid, so it can be directly used to encrypt messages sent to the second terminal.
[0151] The "not present" state means that the first terminal does not store the message key corresponding to the second terminal locally, or the stored key has expired or been revoked. If it has exceeded its validity period or has been invalidated by the key management server due to security risks, it cannot be used directly to encrypt messages. The process of applying for a new message key from the key management server must be triggered before encrypted communication can be carried out.
[0152] In some embodiments, when the message key is in an existing state, the message to be sent is encrypted using the message key and the second encrypted message to obtain the first encrypted message and the key index corresponding to the message key is obtained.
[0153] Encrypting a message to be sent using a message key means that the first terminal calls a second encryption algorithm that matches the message key to convert the original message to be sent into ciphertext that cannot be directly read. Symmetric encryption ensures that even if the message is intercepted during transmission, it cannot be decrypted by an unauthorized party.
[0154] The second encryption algorithm is the national standard SM4 algorithm, a symmetric encryption algorithm specifically used to encrypt actual communication messages. Its core function is to encrypt the original message transmitted between the first terminal and the second terminal to generate the first encrypted message, ensuring the confidentiality of the message content.
[0155] Specifically, the core difference between the second encryption algorithm and the first encryption algorithm is that the first encryption algorithm can achieve interoperability, while the second encryption algorithm is only the national standard SM4 algorithm, which is a fixed symmetric encryption algorithm specifically used to encrypt the actual communication message content. It does not involve the generation and management of signature public and private keys or communication keys, and it does not change with the SIM card type. It is the algorithm uniformly used by all terminals when encrypting messages.
[0156] The first encrypted message refers to the ciphertext message generated after being encrypted with the message key. It is the product of the original message encryption process, and its decryption depends on the corresponding message key.
[0157] A key index is a unique identifier that is bound to a message key. It consists of a sequence of numbers or characters and is used to quickly locate the corresponding message key. It is stored locally on the first terminal and forms a mapping relationship with the message key. After being sent to the second terminal, it can help the second terminal quickly retrieve the matching decryption key in its local key store.
[0158] In some embodiments, when the message key is not present, the user ID of the first terminal and the user ID of the second terminal are obtained.
[0159] The user IDs of the first terminal and the second terminal are encrypted and sent to the key management service.
[0160] For example, the key management service derives the message key based on the user ID of the first terminal and the user ID of the second terminal through the key derivation function of the national cryptographic standard. Specifically, the two user IDs are used as input parameters, combined with the master key, timestamp and other dynamic factors preset by the server, and the original key material is generated by hash operation through the national cryptographic algorithm. Then, the message key conforming to the national cryptographic SM4 algorithm standard is obtained through key derivation processing.
[0161] The first terminal receives and decrypts the message key and key index returned by the key management service.
[0162] The message key is used to encrypt the message to be sent to obtain a second encrypted message.
[0163] The second encrypted message and key index are sent to the second terminal.
[0164] The message key refers to a temporary communication key dynamically generated by the key management server for the first terminal and the second terminal when the message key is missing. It is used to encrypt the message to be sent. Unlike the message key, the message key is generated and distributed by the server in real time. It is only effective for the current key missing scenario and has an independent lifespan. After it is generated, it is stored in the temporary key cache area of the first terminal.
[0165] A key index is a unique identifier associated with a message key. It is assigned synchronously by the key management server when the message key is generated, and is used by both the first and second terminals to quickly locate the corresponding message key. Its format is the same as the key index, but it is only associated with the currently generated message key, ensuring accurate matching during decryption and avoiding confusion with other keys.
[0166] The second encrypted message refers to the ciphertext data obtained by the first terminal encrypting the current message to be sent using the message key.
[0167] Optionally, the second encrypted message can be generated by processing the original message using a symmetric encryption algorithm and transmitted to the second terminal along with the key index. Compared to the first encrypted message, the encryption key of the second encrypted message is dynamically allocated by the server, which is suitable for the first communication or key expiration scenarios, ensuring secure communication when there is no pre-stored key.
[0168] In some embodiments, the first terminal receives a third encrypted message and the corresponding key index sent by the second terminal.
[0169] The second encrypted message is decrypted using the third message key corresponding to the key index.
[0170] The third encrypted message refers to the communication content sent by the second terminal to the first terminal and encrypted by the third message key. It forms a two-way encrypted communication with the first encrypted message and the second encrypted message sent by the first terminal. The content may include text, data or instructions, and its encryption strength matches the algorithm type of the third message key.
[0171] The key index refers to the unique identification information bound to the third message key. It is allocated by the key management server or generated by agreement between the communicating parties. It is used by the first terminal to quickly locate the corresponding third message key in the local key store. Its format can be consistent with the first and key indexes to ensure the universality of the indexing mechanism.
[0172] The third message key refers to the symmetric encryption key used when the first terminal and the second terminal communicate in reverse. It is generated and distributed by the key management server based on the user IDs of both parties, or it is generated by the second terminal and synchronized to the first terminal through a security mechanism. Compared with the first and second message keys, its core function is to ensure the encryption of messages from the second terminal to the first terminal. The three keys can share the same key or be generated independently, depending on the key management strategy.
[0173] Specifically, after receiving the third encrypted message and key index, the first terminal first checks whether the corresponding third message key is stored locally using the key index. If it exists, it directly calls the key to perform the decryption operation on the third encrypted message. If it does not exist, it triggers interaction with the key management server, applies for the third message key using the user IDs of both parties, and completes the decryption after obtaining it, thus ensuring the encrypted closed loop of two-way communication.
[0174] In summary, the solution provided in this embodiment offers a communication encryption method. Based on the SIM card type identified in the first terminal, an encryption algorithm corresponding to the SIM card is selected. A signature public-private key pair for the encryption algorithm is generated. The signature public key is sent to a key management service, and a communication key returned by the key management service is received. The instant messaging service is accessed via login using the communication key. Hardware adaptation to multiple encryption algorithms enhances flexibility, while layered key management and dynamic updates strengthen security, effectively improving the security level and applicability of communication encryption.
[0175] The foregoing mainly describes the solution provided in this application. Accordingly, this application also provides a communication encryption device for implementing the above-described method embodiments.
[0176] like Figure 4 The schematic diagram shown illustrates the structure of a communication encryption device, which may include:
[0177] The system includes an acquisition module 401, a processing module 402, a transmission module 403, and a communication module 404. The acquisition module 401 is used to perform... Figure 2 The operation of step S201 in the illustrated method and Figure 3 The illustrated method includes step S301; the processing module 402 is used to execute... Figure 2 The operation of step S202 and Figure 3 The operation of step S302; the transmission module 403 is used to execute Figure 2 The operation of step S203 and Figure 3 The operation of step S303; the communication module 404 is used to execute Figure 2 The operation of step S204 and Figure 3 The operation of step S304.
[0178] In some embodiments, the communication encryption device includes hardware structures and / or software modules corresponding to the execution of each function in order to achieve the above-described functions. Those skilled in the art will readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0179] This application embodiment can divide the communication encryption device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0180] like Figure 5 As shown, the computer device provided in this application embodiment may include a processor 501, a bus 502, a communication interface 503, and a memory 504. The processor 501, memory 504, and communication interface 503 communicate with each other via the bus 502. It should be understood that this application does not limit the number of processors and memories in the computer device.
[0181] Bus 502 can be a PCI bus, an Extended Industry Standard Architecture (EISA) bus, or a UB bus, etc. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 5 The bus 502 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 502 may include a path for transmitting information between various components of a computer device (e.g., memory 504, processor 501, communication interface 503).
[0182] Processor 501 may include any one or more processors such as CPU, graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).
[0183] Memory 504 may include volatile memory, such as random access memory (RAM). Processor 501 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0184] The communication interface 503 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between computer devices and other devices or communication networks.
[0185] The memory 504 stores executable program code, and the processor 501 executes the executable program code to implement the functions of the aforementioned method embodiments. That is, the memory 504 stores instructions for executing the above-described communication encryption method.
[0186] In another aspect, a computer-readable storage medium is provided, which stores at least one computer program, which is loaded and executed by a processor to implement the communication encryption method provided in the above-described method embodiments.
[0187] On the other hand, a computer program product is provided, which includes a computer program or instructions that, when executed by a processor, implement the communication encryption method described above.
[0188] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the module can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and units described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0189] Since the communication encryption device, computer-readable storage medium, and computer program product in the embodiments of the present invention can be applied to the above methods, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of the present invention will not be repeated here.
[0190] The method steps in this embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. One exemplary embodiment couples a storage medium to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a network device. Of course, the processor and storage medium can also exist as discrete components in the network device.
[0191] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions of the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable modules. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, a computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); or it can be a semiconductor medium, such as a solid-state drive (SSD). The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication encryption method, characterized in that, The method includes: Based on the card type of the SIM card identified in the first terminal, the first encryption algorithm corresponding to the SIM card is selected, and the first encryption algorithms corresponding to different SIM cards are interoperable. Based on the first encryption algorithm, a signature public-private key pair for the first encryption algorithm is generated, wherein the signature public-private key pair includes a signature public key and a signature private key; Send the signing public key to the key management service and receive the communication key returned by the key management service; Login access to the instant messaging service based on the communication key. During the login process, the key management service adapts to the first encryption algorithm through a key conversion protocol.
2. The method according to claim 1, characterized in that, The SIM card types include: regular SIM cards, super SIM cards, and quantum-resistant SIM cards; The first encryption algorithm corresponding to the ordinary SIM is a software algorithm; The first encryption algorithm corresponding to the Super SIM card is a software algorithm and a Super SIM card algorithm; The first encryption algorithm corresponding to the quantum-resistant SIM card is a software algorithm and a quantum-resistant algorithm.
3. The method according to claim 2, characterized in that, The first encryption algorithms corresponding to the different SIM cards are interoperable, including: The super SIM card algorithm corresponding to the super SIM card or the quantum-resistant algorithm corresponding to the quantum-resistant SIM card are both compatible with the ordinary SIM card.
4. The method according to claim 2, characterized in that, The storage methods for the signature private keys generated by the different first encryption algorithms include: The signature private key generated by the software algorithm is stored in the terminal. The signature private key generated by the Super SIM card algorithm is stored in the SIM card. The signature private key generated by the quantum-resistant algorithm is stored in the quantum-resistant SIM card.
5. The method according to claim 1, characterized in that, The method further includes: Communicate with the second terminal using the instant messaging service.
6. The method according to claim 5, characterized in that, The communication with the second terminal according to the instant messaging service includes... Log in and access instant messaging services based on the communication key; Obtain the status of the message key corresponding to the second terminal; The system communicates with the second terminal based on the state of the message key.
7. The method according to claim 6, characterized in that, The status of the message key includes: an existence status; the communication with the communication peer based on the status of the message key includes: When the message key is in the present state, the message to be sent is encrypted using the message key and the second encryption algorithm to obtain the first encrypted message and the key index corresponding to the message key is obtained. The first encrypted message and the key index are sent to the second terminal.
8. The method according to claim 5, characterized in that, The message key's state includes: non-existent; communicating with the second terminal based on the message key's state includes: When the message key is in a state of non-existence, obtain the user ID of the first terminal and the user ID of the second terminal; The user ID of the first terminal and the user ID of the second terminal are encrypted and sent to the key management service; Receive and decrypt the message key and key index returned by the key management service; The message to be sent is encrypted using the message key and the second encryption algorithm to obtain the second encrypted message; The second encrypted message and the key index are sent to the second terminal.
9. A communication encryption system, characterized in that, The system includes: a first terminal, a second terminal, and a key management service; The first terminal is used to identify the card type of the SIM card based on the user identity in the first terminal, and select the first encryption algorithm corresponding to the SIM card. The encryption algorithms corresponding to different SIM cards are interoperable. The first terminal is configured to generate a signature public-private key pair for the encryption algorithm based on the first encryption algorithm, wherein the signature public-private key pair includes a signature public key and a signature private key; The first terminal is used to send the signing public key to the key management service and receive the communication key returned by the key management service; The first terminal is used to log in and access the instant messaging service based on the communication key. During the login process, the key management service adapts to the first encryption algorithm through a key conversion protocol. The second terminal is used to receive the first encrypted message and the key index; The second terminal is used to receive the second encrypted message and the key index; The key management service is used to receive the signing public key sent by the first terminal; The key management service is used to issue communication keys based on the signing public key.
10. A communication encryption device, characterized in that, The device includes: The encryption module is used to identify the card type of the SIM card based on the user identity in the first terminal, and select the first encryption algorithm corresponding to the SIM card. The encryption algorithms corresponding to different SIM cards are interoperable. The processing module is configured to generate a signature public-private key pair for the first encryption algorithm, wherein the signature public-private key pair includes a signature public key and a signature private key; The transmission module is used to send the signing public key to the key management service and receive the communication key returned by the key management service; The communication module is used to log in and access the instant messaging service based on the communication key. During the login process, the key management service adapts to the first encryption algorithm through a key conversion protocol.
11. A computer device, characterized in that, The computer device includes a processor and a memory, wherein the memory stores at least one computer program, and the at least one computer program is loaded and executed by the processor to implement the communication encryption method as described in any one of claims 1 to 7.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement the communication encryption method as described in any one of claims 1 to 8.
13. A computer program product, characterized in that, The computer program product includes a computer program or instructions that, when executed by a processor, implement the communication encryption method as described in any one of claims 1 to 8.
Citation Information
Cited By
Control method of multi-protocol switching anti-quantum security gateway
CN121530577A