Method and device for Java smart card key negotiation
By randomly generating system parameters and public-private key pairs on Java smart card, data encryption and decryption based on Streamlined NTRU Prime key negotiation solution is implemented, solving the problem of difficulty in realizing data encryption and decryption on Java smart card.
Patent Information
- Application Number
- CN202010864597.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-25
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2040-08-25
AI Technical Summary
It is difficult for the prior art to implement data encryption and decryption based on the Streamlined NTRU Prime key negotiation scheme on Java smart cards.
By randomly generating system parameters and public and private key pairs, the key is encrypted by using the public key to generate ciphertext, and the ciphertext is decrypted by using the private key to realize the negotiation of the key and the encryption and decryption of the data.
It realizes data encryption and decryption based on Streamlined NTRU Prime key negotiation solution on Java smart cards, solving the problem of limited range of random numbers on Java smart cards.
Smart Images

Figure CN114117560B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of cryptography and information security, and more specifically, to a method and device for Java smart card key negotiation. Background Art
[0002] A smart card is a small computer in the format of a credit card and without a human-machine interface. It can provide secure identity authentication and personalized services for each cardholder. The data stored in the smart card can prevent unauthorized access and tampering. Smart cards are considered to be an ideal medium for storing secret keys and executing cryptographic algorithms.
[0003] Currently, it is difficult to implement encryption and decryption of data stored on Java smart cards based on the public key system Streamlined NTRU Prime scheme. Summary of the invention
[0004] The present application provides a method and device for Java smart card key negotiation, which can encrypt and decrypt data stored on a Java smart card based on a Streamlined NTRU Prime key negotiation scheme.
[0005] In a first aspect, a Java smart card key negotiation method is provided, comprising:
[0006] The first device randomly generates system parameters and a public-private key pair, wherein the system parameters include a first system parameter p, a second system parameter q, and a third system parameter ω, p and q are prime numbers, ω is a positive integer, and 2p≥3ω, q≥16ω+1, and the public-private key pair includes a private key f and a public key h, and the private key f is determined according to a first random polynomial R and a second random polynomial S, and the first random polynomial R=Z[x] / (x p -x-1), and x p -x-1 is irreducible on the polynomial ring (Z / q)[x], the coefficients of the first random polynomial belong to the set {-1,0,1}, the second random polynomial S is a (p-1)th order polynomial, ω coefficients of the p coefficients of the second random polynomial S are randomly generated positive or negative 1, the remaining (p-ω) coefficients are zero, and S∈R, the public key h is determined according to the third random polynomial g and the private key f, the third random polynomial g is a (p-1)th order polynomial, the p coefficients of the third random polynomial g belong to the set {-1,0,1}, the third random polynomial g is reversible in R / 3, R / 3=(Z / 3)[x] / (x p -x-1), the public key h satisfies the following expression: h = g / (3f);
[0007] The first device sends the public key h to the second device, and the public key h is used by the second device to process the key k stored in the second device to obtain the ciphertext C||c;
[0008] The first device receives the ciphertext C||c sent by the second device;
[0009] The first device processes the ciphertext C||c according to the private key f to obtain the key k.
[0010] It should be understood that the first device may be a Java smart card, or a device including a Java smart card. The second device may be a Java smart card, or a device including a Java smart card.
[0011] Based on the above technical solution, the first device can generate any integer greater than or equal to zero, so that the data stored on the Java smart card can be encrypted and decrypted based on the Streamlined NTRU Prime key agreement scheme based on the public key system.
[0012] In combination with the first aspect, in some implementations of the first aspect, the first system parameter p is equal to 761, the second system parameter q is equal to 4591, and the third system parameter ω is equal to 286.
[0013] Based on the above technical solution, the embodiment of the present application provides an optimal combination of p, q and ω.
[0014] It should be understood that p, q and ω may also be other values, but they must satisfy that p and q are prime numbers, ω is a positive integer, and 2p≥3ω, q≥16ω+1.
[0015] In combination with the first aspect, in certain implementations of the first aspect, the ciphertext C||c includes a first ciphertext C and a second ciphertext c, the ciphertext C||c is obtained by performing a concatenation operation on the first ciphertext C and the second ciphertext c, the first ciphertext C is obtained by performing a hash process on the key k and a fourth random polynomial r, the fourth random polynomial r is a (p-1)th order polynomial, ω of the p coefficients of the fourth random polynomial r belong to {-1,1}, the remaining (p-ω) coefficients are zero, and r∈R, the second ciphertext c is obtained by rounding the coefficients of the fifth random polynomial hr and multiplying them by 3, the fifth random polynomial hr is the product of the public key h and the fourth random polynomial r, hr∈R, and the coefficients of hr are in the interval [-(q-1) / 2,(q-1) / 2].
[0016] In combination with the first aspect, in some implementations of the first aspect, the first ciphertext C is obtained by performing a hash process on the key k and the fourth random polynomial r, including obtaining the first ciphertext C by following steps 1 to 5:
[0017] Step 1: Process the fourth random polynomial r to obtain a (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], where x p 、x p+1 and x p+2 The coefficient of is zero, i is an integer, 0≤i≤p+3;
[0018] Step 2: For the (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], add 1 to the coordinates corresponding to each vector in the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ), and for this vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ) to obtain four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 );
[0019] Step 3: According to the four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ) Calculate the set A = (A0, A1, A2, A i ,...,A 190 ), where A i =a 4i +4×a 4i+1 +4 2 ×a 4i+2 +4 3 ×a 4i+3 , i is an integer, 0≤i≤190, wherein the set A is the first ciphertext C;
[0020] Step 4: Use the hash algorithm to95 ,A 96 ,A 97 ,...,A 190 ) is processed to obtain a 32-byte session key;
[0021] Step 5: Use the 32-byte session key with the (A0, A1, A2, ..., A 94 ) to verify that the set A=(A0,A1,A2,A i ,...,A 190 ).
[0022] In combination with the first aspect, in some implementations of the first aspect, the private key f is a (p-1)th order polynomial, and the coefficient of the private key f is in the interval [-(q-1) / 2, (q-1) / 2], and the first device processes the ciphertext C||c according to the private key f to obtain the key k, including:
[0023] The first device obtains the second ciphertext c from the ciphertext C||c;
[0024] The first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c;
[0025] The first device processes the seventh random polynomial r' in R / 3 so that r'∈R, the seventh random polynomial r' is obtained by performing a modulo 3 operation on the sixth random polynomial gr, r'=1 / ge=r(mod3), e is gr(mod3), gr(mod3)=3.((699051.a+220)>>21), a∈[-3000,3000];
[0026] The first device performs hash processing on the seventh random polynomial r' in R / 3 to generate a third ciphertext C' and a second key k';
[0027] When the first device determines that the third ciphertext C' is identical to the first ciphertext C, the second key k' is equal to the key k, so that the first device obtains the key k.
[0028] In combination with the first aspect, in some implementations of the first aspect, the first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c, including:
[0029] In the case where the absolute value of the sixth random polynomial gr is less than or equal to (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=3fc=3f.hr=3f.(g / 3f)r;
[0030] In a case where the absolute value of the sixth random polynomial gr is greater than (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=sgn(3fc)(|3fc|-q).
[0031] Based on the above technical solution, the coefficient range of the sixth random polynomial gr can be quickly determined.
[0032] In combination with the first aspect, in some implementations of the first aspect, before the first device randomly generates a system parameter and a public-private key pair, the method further includes:
[0033] The random number generated by the first device is constructed so that the constructed first device generates any integer greater than or equal to zero.
[0034] Based on the above technical solution, the range of random numbers generated by the Java smart card can be modified.
[0035] In a second aspect, a device for Java smart card key negotiation is provided, the device comprising a processing unit and a transceiver unit, so that the processing unit and the transceiver unit can execute the method in the above-mentioned first aspect and any possible implementation manner of the first aspect.
[0036] In a third aspect, a device for Java smart card key negotiation is provided, which includes a memory and a processor, the memory is used to store instructions, and the processor is used to read the instructions stored in the memory, so that the device executes the method in the above-mentioned first aspect and any possible implementation of the first aspect.
[0037] In a fourth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is used to receive a signal through the input circuit and transmit a signal through the output circuit, so that any aspect of the first aspect and the method in any possible implementation of the first aspect are implemented.
[0038] In the specific implementation process, the processor can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, a gate circuit, a trigger, and various logic circuits. The input signal received by the input circuit can be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit can be, for example, but not limited to, output to a transmitter and transmitted by the transmitter, and the input circuit and the output circuit can be the same circuit, which is used as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation methods of the processor and various circuits.
[0039] In a fifth aspect, a processing device is provided, comprising a processor and a memory. The processor is used to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter to execute the method in the first aspect and any possible implementation of the first aspect.
[0040] Optionally, the number of the processors is one or more, and the number of the memories is one or more.
[0041] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0042] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated with the processor on the same chip or can be set on different chips respectively. The embodiments of the present application do not limit the type of memory and the setting method of the memory and the processor.
[0043] It should be understood that the relevant data interaction process, such as sending indication information, can be a process of outputting indication information from a processor, and receiving capability information can be a process of receiving input capability information from a processor. Specifically, the processed output data can be output to a transmitter, and the input data received by the processor can come from a receiver. Among them, the transmitter and the receiver can be collectively referred to as a transceiver.
[0044] In a sixth aspect, a computer-readable storage medium is provided for storing a computer program, wherein the computer program includes instructions for executing the method in the first aspect and any possible implementation of the first aspect.
[0045] In a seventh aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute the method in the first aspect and any possible implementation of the first aspect.
[0046] In an eighth aspect, a chip is provided, comprising at least one processor and an interface; the at least one processor is used to call and run a computer program so that the chip executes the method in the above-mentioned first aspect and any possible implementation of the above-mentioned first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 A schematic diagram showing an application scenario suitable for the present application is shown.
[0048] Figure 2 A schematic flow chart of a Java smart card key negotiation method 200 provided in the present application is shown.
[0049] Figure 3 A schematic structural diagram of a Java smart card key negotiation device 300 provided in an embodiment of the present application is shown.
[0050] Figure 4 A schematic diagram of the hardware structure of a Java smart card key negotiation device 300 provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0051] The technical solution in this application will be described below in conjunction with the accompanying drawings.
[0052] The present application will present various aspects, embodiments or features around a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these schemes may also be used.
[0053] In addition, in the embodiments of the present application, words such as "exemplary" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present concepts in a concrete way.
[0054] In the embodiments of the present application, "corresponding (corresponding, relevant)" and "corresponding (corresponding)" can sometimes be used interchangeably. It should be pointed out that when the distinction between them is not emphasized, the meanings they intend to express are consistent.
[0055] In the embodiments of the present application, sometimes a subscript such as W1 may be mistakenly written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are consistent.
[0056] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person of ordinary skill in the art can appreciate that with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0057] References to "one embodiment" or "some embodiments" etc. described in this specification mean that a particular feature, structure or characteristic described in conjunction with the embodiment is included in one or more embodiments of the present application. Thus, the phrases "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear at different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0058] In the present application, "at least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0059] When the Streamlined NTRU Prime key encapsulation scheme is used to encrypt and decrypt data to be transmitted, a large number of random numbers in any range are usually required to process the data to be transmitted. However, the range of random numbers generated on Java smart cards is usually limited, which makes it difficult to implement data encryption and decryption based on the Streamlined NTRU Prime key encapsulation scheme on Java smart cards.
[0060] Figure 1 Schematic diagram showing an application scenario applicable to the present application. Figure 1 As shown, the application scenario may include at least a first device 110 and at least one second device 120 .
[0061] exist Figure 1In the embodiment, the first device 110 can be understood as a receiving device, and the second device 120 can be understood as a sending device. The first device 110 and the second device 120 can communicate with each other (for example, through wireless technology or limited technology). Among them, the first device 110 as a receiving device can generate a public-private key pair and send the public key to the second device 120. The second device 120, as a sending device, can receive the public key sent by the first device 110, use the public key to encrypt the information to be sent (for example, a bank card password), and send the encrypted information to the first device 110. The first device 110 uses the private key to decrypt the received encrypted information, and then obtains the content of the information sent by the second device 120.
[0062] In the present application, the first device may be a Java smart card, or a device including a Java smart card. The second device may be a Java smart card, or a device including a Java smart card. However, the types of the first device 110 and the second device 120 are not specifically limited.
[0063] For example, the first device 110 may be a server including a Java smart card, and the second device 120 may also be a server including a Java smart card.
[0064] It should be understood that Figure 1 The first device 110 and the second device 120 are schematically shown for ease of understanding, but this should not constitute any limitation to the present application. For example, the application scenario may also include a larger number of first devices 110 and a larger number of second devices 120, which is not limited in the present application.
[0065] Figure 2 FIG. 2 is a schematic flow chart of a method 200 for Java smart card key negotiation provided by the present application. Figure 2 As shown, method 200 includes steps 210 to 250, and steps 210 to 250 are described in detail below.
[0066] exist Figure 2 In the present invention, the first device can be understood as a device that receives encrypted data, and the first device can also be called a receiving device. The second device can be understood as a device that sends encrypted data, and the second device can also be called a sending device.
[0067] Before step 210, the method further includes: constructing the random number L generated by the first device so that the constructed first device generates any integer M greater than or equal to zero.
[0068] In some implementations, when L is an integer and 0≤L≤255, constructing the range of random numbers generated by the first device so that the constructed first device generates any integer M greater than or equal to zero includes:
[0069] The first device processes the range of random numbers generated by the first device to obtain a first range Rand(256), where the first range includes [0, 255].
[0070] If the first device determines that the second parameter k is less than t×(L+1), the first device generates M, and M=k%(L+1);
[0071] If the first device determines that the second parameter k is greater than or equal to t×(L+1), the second parameter k is updated, and the updated second parameter k is compared with t×(L+1);
[0072] The first parameter t is an integer not greater than 256 / (L+1), and the second parameter k is equal to any integer included in the first range.
[0073] Below, Java Card 3.1.0 is taken as an example to introduce the method of constructing a random number. It should be understood that the method of constructing a random number provided in this application can also be applied to other versions of Java Card, and this is not specifically limited.
[0074] Java Card 3.1.0 can generate random numbers in the range of [-128, 127]. The range can be simply transformed to [0, 255], i.e., Rand(256). Then, the random number L is generated using Rand(256), where L is a positive integer greater than or equal to 1. Tables 1 and 2 show the method for constructing data numbers provided by this application.
[0075] Table 1
[0076]
[0077] Table 2
[0078]
[0079] It should be understood that the methods for constructing random numbers in Tables 1 and 2 are only for illustration and do not constitute any limitation to the present application. In some embodiments, the Java smart card may also be a smart card of other versions, for example, Java Card 2.1.0. In this case, the range of random numbers that can be generated by Java Card 2.1.0 may be simply modified to [0, 255], and then the random number generation algorithm 1 or random number generation algorithm 2 provided in the present application may be used.
[0080] In the present application, the method of transforming the range of random numbers that can be generated by the Java smart card to [0, 255] is not specifically limited.
[0081] It should be noted that the random numbers in steps 210 to 250 below can be generated by using the above method.
[0082] Step 210: The first device randomly generates system parameters and a public-private key pair.
[0083] In step 210, the system parameters include a first system parameter p, a second system parameter q, and a third system parameter ω, where p and q are prime numbers, ω is a positive integer, and p, q, and ω satisfy the following expression:
[0084]
[0085] In this application, there is no limitation on the specific values of p, q and ω, but p, q and ω must satisfy the relationship of formula (2.1), and p and q are prime numbers, and ω is a positive integer.
[0086] Optionally, in some embodiments, p may be equal to 761, q may be equal to 4591, and ω may be equal to 286.
[0087] In step 210, the public-private key pair includes a private key f and a public key h. The private key f is determined according to a first random polynomial R and a second random polynomial S. The first random polynomial R = Z[x] / (x p -x-1), and x p -x-1 is irreducible on the polynomial ring (Z / q)[x], the coefficients of the first random polynomial belong to the set {-1,0,1}, the second random polynomial S is a (p-1)th order polynomial, ω of the p coefficients of the second random polynomial S are randomly generated positive or negative 1, the remaining (p-ω) coefficients are zero, and S∈R, the public key h is determined based on the third random polynomial g and the private key f, the third random polynomial g is a (p-1)th order polynomial, the p coefficients of the third random polynomial g belong to the set {-1,0,1}, the third random polynomial g is reversible in R / 3, R / 3=(Z / 3)[x] / (x p -x-1), the public key h satisfies the following expression:
[0088] h=g / (3f) (2.2)
[0089] The second random polynomial S is a (p-1)th order polynomial, and the second random polynomial S can be expressed by the following formula:
[0090] S=S0+S1(x)+S i (x)...+S p-1 (x) p-1(2.3)
[0091] Table 3 shows the method for generating a private key f provided in an embodiment of the present application.
[0092] Table 3
[0093]
[0094] The third random polynomial g can be understood as a (p-1)th order polynomial, and the third random polynomial g can be expressed by the following formula:
[0095] g(x)=g0+g1(x)+...+g p-1 (x) p-1 (2.4)
[0096] It should be understood that each coefficient of the third random polynomial g is any number in the first set {-1, 0, 1}. That is, g0, g1, g2, ..., g p-1 The coefficient of can be any number in {-1, 0, 1}. For example, the coefficient of g0 can be -1, the coefficient of g1 can be 1, the coefficient of g2 can be 0, and so on.
[0097] Table 4 shows the method for generating the third random polynomial g provided by the present application, as shown in Table 4.
[0098] Table 4
[0099]
[0100] Step 220: The second device receives the public key h from the first device.
[0101] In step 220, the public key h can be used by the second device to process the key k stored in the second device to obtain the ciphertext C||c.
[0102] The key k stored in the second device may be understood as the key k generated by the second device itself and stored in the second device, or may be understood as the key k sent to the second device by other devices and stored in the second device.
[0103] Step 230: The second device encrypts the key k according to the public key h to obtain the ciphertext C||c.
[0104] In step 230, the ciphertext C||c includes the first ciphertext C and the second ciphertext c. The ciphertext C||c is obtained by performing a concatenation operation on the first ciphertext C and the second ciphertext c. The first ciphertext C is obtained by performing a hash process on the key k and the fourth random polynomial r. The fourth random polynomial r is a (p-1)th order polynomial. Among the p coefficients of the fourth random polynomial r, ω coefficients belong to {-1,1}, and the remaining (p-ω) coefficients are zero, and r∈R. The second ciphertext c is obtained by rounding the coefficients of the fifth random polynomial hr and multiplying them by 3. The fifth random polynomial hr is the product of the public key h and the fourth random polynomial r, hr∈R, and the coefficients of hr are in the interval [-(q-1) / 2,(q-1) / 2].
[0105] In some implementations, the first ciphertext C is obtained by performing a hash process on the key k and the fourth random polynomial r. Specifically, the first ciphertext C is obtained by using a hash SAH-256 algorithm, including the following steps 1 to 5:
[0106] Step 1: Process the fourth random polynomial r to obtain a (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], where x p 、x p+1 and x p+2 The coefficient is zero, i is an integer, 0≤i≤p+3.
[0107] For example, when p = 761, i = 0, 1, 2, ..., 763, where x 761 、x 762 and x 763 The coefficients are all 0.
[0108] Step 2: For the (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], the coordinates corresponding to each vector in the equation are added by 1, and the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ), and for the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ) to obtain four elements (a 4i ,a 4i+1 ,a4i+2 ,a 4i+3 );
[0109] Step 3: According to the four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ) Calculate the set A = (A0, A1, A2, A i ,...,A 190 ), where A i =a 4i +4×a 4i+1 +4 2 ×a 4i+2 +4 3 ×a 4i+3 , i is an integer, 0≤i≤190, wherein the set A is the first ciphertext C;
[0110] Step 4: Use the hash algorithm to sort (A 95 ,A 96 ,A 97 ,...,A 190 ) is processed to obtain a 32-byte session key;
[0111] Step 5: Compare the 32-byte session key with the (A0, A1, A2, ..., A 94 ) to verify that the set A = (A0, A1, A2, A i ,...,A 190 ).
[0112] Step 240: The second device sends the ciphertext C||c to the first device.
[0113] Step 250: The first device processes the ciphertext C||c according to the private key f to obtain the key k.
[0114] The private key f is a (p-1)th order polynomial, and the coefficient of the private key f is in the interval [-(q-1) / 2, (q-1) / 2]. The first device processes the ciphertext C||c according to the private key f to obtain the key k, including:
[0115] The first device obtains the second ciphertext c from the ciphertext C||c;
[0116] The first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c;
[0117] The first device processes the seventh random polynomial r' in R / 3 so that r'∈R, the seventh random polynomial r' is obtained by performing a modulo 3 operation on the sixth random polynomial gr, r'=1 / ge=r(mod3), e is gr(mod3), gr(mod3)=3.((699051.a+220)>>21), a∈[-3000,3000];
[0118] The first device performs hash processing on the seventh random polynomial r' in R / 3 to generate a third ciphertext C' and a second key k';
[0119] When the first device determines that the third ciphertext C' is identical to the first ciphertext C, the second key k' is equal to the key k, so that the first device obtains the key k.
[0120] In some implementations, the first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c, specifically including:
[0121] In the case where the absolute value of the sixth random polynomial gr is less than or equal to (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=3fc=3f.hr=3f.(g / 3f)r;
[0122] In a case where the absolute value of the sixth random polynomial gr is greater than (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=sgn(3fc)(|3fc|-q).
[0123] Based on the above technical solution, encryption and decryption of data stored on a Java smart card can be achieved based on the Streamlined NTRU Prime key negotiation solution.
[0124] Next, combine Figure 3 and Figure 4 The present invention introduces in detail a Java smart card key negotiation device and a hardware structure of the Java smart card key negotiation device provided by the present application.
[0125] Figure 3 A schematic structural diagram of a Java smart card key negotiation device 300 provided in an embodiment of the present application is shown.
[0126] like Figure 3 As shown, the Java smart card key negotiation device 300 includes: a transceiver unit 310 and a processing unit 320. The transceiver unit 310 and the processing unit 320 communicate with each other through an internal connection path to transmit control and / or data signals.
[0127] The processing unit 320 is used to randomly generate system parameters and a public-private key pair, wherein the system parameters include a first system parameter p, a second system parameter q, and a third system parameter ω, p and q are prime numbers, ω is a positive integer, and 2p≥3ω, q≥16ω+1, and the public-private key pair includes a private key f and a public key h, wherein the private key f is determined according to a first random polynomial R and a second random polynomial S, wherein the first random polynomial R=Z[x] / (x p -x-1), and x p -x-1 is irreducible on the polynomial ring (Z / q)[x], the coefficients of the first random polynomial belong to the set {-1,0,1}, the second random polynomial S is a (p-1)th order polynomial, ω coefficients of the p coefficients of the second random polynomial S are randomly generated positive or negative 1, and the remaining (p-ω) coefficients are zero, and S∈R, the public key h is determined according to the third random polynomial g and the private key f, the third random polynomial g is a (p-1)th order polynomial, the p coefficients of the third random polynomial g belong to the set {-1,0,1}, the third random polynomial g is reversible in R / 3, R / 3=(Z / 3)[x] / (x p -x-1), the public key h satisfies the following expression: h = g / (3f);
[0128] The transceiver unit 310 is used to send the public key h to the second device, and the public key h is used by the second device to process the key k stored in the second device to obtain the ciphertext C||c;
[0129] The transceiver unit 310 is further configured to receive the ciphertext C||c sent by the second device;
[0130] The processing unit 320 is further configured to process the ciphertext C||c according to the private key f to obtain the key k.
[0131] Optionally, in some embodiments, the ciphertext C||c includes a first ciphertext C and a second ciphertext c, the ciphertext C||c is obtained by performing a concatenation operation on the first ciphertext C and the second ciphertext c, the first ciphertext C is obtained by performing a hash process on the key k and a fourth random polynomial r, the fourth random polynomial r is a (p-1)th order polynomial, ω of the p coefficients of the fourth random polynomial r belong to {-1,1}, the remaining (p-ω) coefficients are zero, and r∈R, the second ciphertext c is obtained by rounding the coefficients of the fifth random polynomial hr and multiplying them by 3, the fifth random polynomial hr is the product of the public key h and the fourth random polynomial r, hr∈R, and the coefficients of hr are in the interval [-(q-1) / 2,(q-1) / 2].
[0132] Optionally, in some embodiments, the first ciphertext C is obtained by performing hash processing on the key k and the fourth random polynomial r, and the processing unit 320 is further configured to perform the following steps 1 to 5:
[0133] Step 1: Process the fourth random polynomial r to obtain a (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], where x p 、x p+1 and x p+2 The coefficient of is zero, i is an integer, 0≤i≤p+3;
[0134] Step 2: For the (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], add 1 to the coordinates corresponding to each vector in the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ), and for this vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ) to obtain four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 );
[0135] Step 3: According to the four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ) Calculate the set A = (A0, A1, A2, A i ,...,A 190 ), where A i =a 4i +4×a 4i+1 +4 2 ×a 4i+2 +4 3 ×a 4i+3 , i is an integer, 0≤i≤190, wherein the set A is the first ciphertext C;
[0136] Step 4: Use the hash algorithm to 95 ,A96 ,A 97 ,...,A 190 ) is processed to obtain a 32-byte session key;
[0137] Step 5: Use the 32-byte session key with the (A0, A1, A2, ..., A 94 ) to verify that the set A=(A0,A1,A2,A i ,...,A 190 ).
[0138] Optionally, in some embodiments, the private key f is a (p-1)th order polynomial, and the coefficients of the private key f are in the interval [-(q-1) / 2, (q-1) / 2], and the processing unit 320 is further configured to:
[0139] Obtain the second ciphertext c from the ciphertext C||c;
[0140] Generate a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c;
[0141] The seventh random polynomial r' is processed in R / 3 so that r'∈R, the seventh random polynomial r' is obtained by performing a modulo 3 operation on the sixth random polynomial gr, r'=1 / ge=r(mod3), e is gr(mod3), gr(mod3)=3.((699051.a+220)>>21), a∈[-3000,3000];
[0142] The seventh random polynomial r' is hashed in R / 3 to generate a third ciphertext C' and a second key k';
[0143] When it is determined that the third ciphertext C' is identical to the first ciphertext C, the second key k' is equal to the key k, so that the first device obtains the key k.
[0144] Optionally, in some embodiments, the processing unit 320 is further configured to:
[0145] When the absolute value of the sixth random polynomial gr is less than or equal to (q-1) / 2, it is determined that the sixth random polynomial gr satisfies the following expression: gr=3fc=3f.hr=3f.(g / 3f)r;
[0146] In the case where the absolute value of the sixth random polynomial gr is greater than (q-1) / 2, it is determined that the sixth random polynomial gr satisfies the following expression: gr=sgn(3fc)(|3fc|-q).
[0147] Optionally, in some embodiments, the processing unit 320 is further configured to:
[0148] The random number generated by the first device is constructed so that the constructed first device generates any integer greater than or equal to zero.
[0149] Figure 4 A schematic diagram of the hardware structure of a Java smart card key negotiation device 300 provided in an embodiment of the present application is shown. Figure 4 The hardware structure of the Java smart card key negotiation apparatus 300 shown can execute the corresponding steps executed by the Java smart card key negotiation apparatus in the method of the above embodiment.
[0150] like Figure 4 As shown, the hardware structure of the device 300 for Java smart card key negotiation includes a processor 2001, a memory 2002, an interface 2003 and a bus 2004. The interface 2003 can be implemented wirelessly or wired, and can be a network card in detail. The processor 2001, the memory 2002 and the interface 2003 are connected via a bus 2004. The interface 2003 can specifically include a transmitter and a receiver. The processor 2001 is used to perform the processing performed by the device 300 for Java smart card key negotiation in the above embodiment. And / or other processes for the technology described herein. The memory 2002 includes an operating system 20021 and an application 20022, which are used to store programs, codes or computer-executable instructions. When the processor or hardware device executes these programs, codes or computer-executable instructions, the processing process of the device 300 for Java smart card key negotiation in the method embodiment can be completed. Optionally, the memory 2002 can include a read-only memory (ROM) and a random access memory (RAM). The ROM includes a basic input / output system (BIOS) or an embedded system; the RAM includes an application and an operating system. When the device 300 for Java smart card key negotiation needs to be run, the BIOS solidified in the ROM or the bootloader boot system in the embedded system is used to start the device 300 for Java smart card key negotiation, and the device 300 for Java smart card key negotiation is guided to enter a normal operating state. After the device 300 for Java smart card key negotiation enters a normal operating state, the application and the operating system in the RAM are run, thereby completing the processing process of the device 300 for Java smart card key negotiation in the method embodiment.
[0151] Understandably, Figure 3Only a simplified design of the Java smart card key negotiation apparatus 300 is shown. In practical applications, the Java smart card key negotiation apparatus 300 may include any number of interfaces, processors or memories.
[0152] The present application also provides a computer-readable medium, which stores a program code, and when the computer program code is run on a computer, the computer executes the methods in the above aspects. These computer-readable storages include but are not limited to one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM) and hard drive.
[0153] An embodiment of the present application also provides a chip system, which is applied to a Java smart card key negotiation device. The chip system includes: at least one processor, at least one memory and an interface circuit, wherein the interface circuit is responsible for information interaction between the chip system and the outside world, the at least one memory, the interface circuit and the at least one processor are interconnected through lines, and the at least one memory stores computer execution instructions; the computer execution instructions are executed by the at least one processor to perform the operations of the Java smart card key negotiation device in the methods described in the above aspects.
[0154] In the specific implementation process, the chip system can be implemented in the form of a central processing unit (CPU), a microcontroller unit (MCU), a microprocessor (MPU), a digital signal processor (DSP), a system on chip (SoC), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a programmable logic device (PLD).
[0155] An embodiment of the present application also provides a computer program product, which is applied to a Java smart card key negotiation device. The computer program product includes a series of computer execution instructions. When the computer execution instructions are executed, the operations of the Java smart card key negotiation device described in the methods described in the above aspects are performed.
[0156] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0157] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0158] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0159] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0160] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0161] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0162] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including a number of computer execution instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program codes.
[0163] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for Java smart card key negotiation, characterized in that: The method comprises: The first device randomly generates system parameters and a public-private key pair, wherein the system parameters include a first system parameter p, a second system parameter q, and a third system parameter ω, p and q are prime numbers, ω is a positive integer, and 2p≥3ω, q≥16ω+1, and the public-private key pair includes a private key f and a public key h, and the private key f is determined according to a first random polynomial R and a second random polynomial S, and the first random polynomial R=Z[x] / (x p -x-1), and x p -x-1 is irreducible on the polynomial ring (Z / q)[x], the coefficients of the first random polynomial belong to the set {-1,0,1}, the second random polynomial S is a (p-1)th order polynomial, ω coefficients of the p coefficients of the second random polynomial S are randomly generated positive or negative 1, and the remaining (p-ω) coefficients are zero, and S∈R, the public key h is determined according to the third random polynomial g and the private key f, the third random polynomial g is a (p-1)th order polynomial, the p coefficients of the third random polynomial g belong to the set {-1,0,1}, the third random polynomial g is reversible in R / 3, R / 3=(Z / 3)[x] / (x p -x-1), the public key h satisfies the following expression: h=g / (3f); The first device sends the public key h to the second device, and the public key h is used by the second device to process the key k stored in the second device to obtain the ciphertext C||c; The first device receives the ciphertext C||c sent by the second device; The first device processes the ciphertext C||c according to the private key f to obtain the key k.
2. The method according to claim 1, characterized in that The ciphertext C||c includes a first ciphertext C and a second ciphertext c, the ciphertext C||c is obtained by performing a concatenation operation on the first ciphertext C and the second ciphertext c, the first ciphertext C is obtained by performing a hash process on the key k and a fourth random polynomial r, the fourth random polynomial r is a (p-1)th order polynomial, ω coefficients of the p coefficients of the fourth random polynomial r belong to {-1,1}, the remaining (p-ω) coefficients are zero, and r∈R, the second ciphertext c is obtained by rounding the coefficients of the fifth random polynomial hr and multiplying them by 3, the fifth random polynomial hr is the product of the public key h and the fourth random polynomial r, hr∈R, and the coefficients of hr are in the interval [-(q-1) / 2,(q-1) / 2].
3. The method according to claim 2, characterized in that The first ciphertext C is obtained by performing hash processing on the key k and the fourth random polynomial r, including obtaining the first ciphertext C by following steps 1 to 5: Step 1: Process the fourth random polynomial r to obtain a (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], where x p 、x p+1 and x p+2 The coefficient of is zero, i is an integer, 0≤i≤p+3; Step 2: For the (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], the coordinates corresponding to each vector in the equation are added by 1, and the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ), and for the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ) to obtain four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ); Step 3: According to the four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ) Calculate the set A = (A0, A1, A2, A i ,...,A 190 ), where A i =a 4i +4×a 4i+1 +4 2 ×a 4i+2 +4 3 ×a 4i+3 , i is an integer, 0≤i≤190, wherein the set A is the first ciphertext C; Step 4: Use a hash algorithm to sort (A 95 ,A 96 ,A 97 ,...,A 190 ) is processed to obtain a 32-byte session key; Step 5: Compare the 32-byte session key with the (A0, A1, A2, ..., A 94 ) to verify that the set A = (A0, A1, A2, A i ,...,A 190 ).
4. The method according to claim 2 or 3, characterized in that: The private key f is a (p-1)th order polynomial, and the coefficient of the private key f is in the interval [-(q-1) / 2, (q-1) / 2]. The first device processes the ciphertext C||c according to the private key f to obtain the key k, including: The first device obtains the second ciphertext c from the ciphertext C||c; The first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c; The first device processes the seventh random polynomial r' in R / 3 so that r'∈R, the seventh random polynomial r' is obtained by performing a modulo 3 operation on the sixth random polynomial gr, r'=1 / ge=r(mod3), e is gr(mod3), gr(mod3)=3.((699051.a+220)>>21), a∈[-3000,3000]; The first device performs hash processing on the seventh random polynomial r' in R / 3 to generate a third ciphertext C' and a second key k'; When the first device determines that the third ciphertext C′ is identical to the first ciphertext C, the second key k′ is equal to the key k, so that the first device obtains the key k.
5. The method according to claim 4, characterized in that The first device generates a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c, including: In the case where the absolute value of the sixth random polynomial gr is less than or equal to (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=3fc=3f.hr=3f.(g / 3f)r; In a case where the absolute value of the sixth random polynomial gr is greater than (q-1) / 2, the first device determines that the sixth random polynomial gr satisfies the following expression: gr=sgn(3fc)(|3fc|-q).
6. The method according to any one of claims 1 to 3, characterized in that: Before the first device randomly generates system parameters and a public-private key pair, the method further includes: The random number generated by the first device is constructed so that the constructed first device generates any integer greater than or equal to zero.
7. The method according to any one of claims 1 to 3, characterized in that: The first system parameter p is equal to 761, the second system parameter q is equal to 4591, and the third system parameter ω is equal to 286.
8. A Java smart card key negotiation device, characterized in that: The device comprises: A processing unit, configured to randomly generate system parameters and a public-private key pair, wherein the system parameters include a first system parameter p, a second system parameter q, and a third system parameter ω, p and q are prime numbers, ω is a positive integer, and 2p≥3ω, q≥16ω+1, and the public-private key pair includes a private key f and a public key h, and the private key f is determined according to a first random polynomial R and a second random polynomial S, and the first random polynomial R=Z[x] / (x p -x-1), and x p -x-1 is irreducible on the polynomial ring (Z / q)[x], the coefficients of the first random polynomial belong to the set {-1,0,1}, the second random polynomial S is a (p-1)th order polynomial, ω coefficients of the p coefficients of the second random polynomial S are randomly generated positive or negative 1, and the remaining (p-ω) coefficients are zero, and S∈R, the public key h is determined according to the third random polynomial g and the private key f, the third random polynomial g is a (p-1)th order polynomial, the p coefficients of the third random polynomial g belong to the set {-1,0,1}, the third random polynomial g is reversible in R / 3, R / 3=(Z / 3)[x] / (x p -x-1), the public key h satisfies the following expression: h=g / (3f); A transceiver unit, used to send the public key h to a second device, where the public key h is used by the second device to process the key k stored in the second device to obtain a ciphertext C||c; The transceiver unit is further configured to receive the ciphertext C||c sent by the second device; The processing unit is further used to process the ciphertext C||c according to the private key f to obtain the key k.
9. The device according to claim 8, characterized in that The ciphertext C||c includes a first ciphertext C and a second ciphertext c, the ciphertext C||c is obtained by performing a concatenation operation on the first ciphertext C and the second ciphertext c, the first ciphertext C is obtained by performing a hash process on the key k and a fourth random polynomial r, the fourth random polynomial r is a (p-1)th order polynomial, ω coefficients of the p coefficients of the fourth random polynomial r belong to {-1,1}, the remaining (p-ω) coefficients are zero, and r∈R, the second ciphertext c is obtained by rounding the coefficients of the fifth random polynomial hr and multiplying them by 3, the fifth random polynomial hr is the product of the public key h and the fourth random polynomial r, hr∈R, and the coefficients of hr are in the interval [-(q-1) / 2,(q-1) / 2].
10. The device according to claim 9, characterized in that The first ciphertext C is obtained by performing hash processing on the key k and the fourth random polynomial r, and the processing unit is further configured to perform the following steps 1 to 5: Step 1: Process the fourth random polynomial r to obtain a (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,xi,...,x p+3 ], where x p 、x p+1 and x p+2 The coefficient of is zero, i is an integer, 0≤i≤p+3; Step 2: For the (p+3)-dimensional vector [x 0 ,x 1 ,x 2 ,x i ,...,x p+3 ], the coordinates corresponding to each vector in the equation are added by 1, and the vector (a 0 ,a 1 ,a 2 ,ai,...,a p+2 ), and for the vector (a 0 ,a 1 ,a 2 ,a i ,...,a p+2 ) to obtain four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ); Step 3: According to the four elements (a 4i ,a 4i+1 ,a 4i+2 ,a 4i+3 ) Calculate the set A = (A0, A1, A2, A i ,...,A 190 ), where A i =a 4i +4×a 4i+1 +4 2 ×a 4i+2 +4 3 ×a 4i+3 , i is an integer, 0≤i≤190, wherein the set A is the first ciphertext C; Step 4: Use a hash algorithm to sort (A 95 ,A 96 ,A 97 ,...,A 190 ) is processed to obtain a 32-byte session key; Step 5: Compare the 32-byte session key with the (A0, A1, A2, ..., A 94 ) to verify that the set A = (A0, A1, A2, A i ,...,A 190 ).
11. The device according to claim 9 or 10, characterized in that The private key f is a (p-1)th order polynomial, and the coefficient of the private key f is in the interval [-(q-1) / 2, (q-1) / 2], and the processing unit is further used for: Obtain the second ciphertext c from the ciphertext C||c; Generate a sixth random polynomial gr according to the third random polynomial g and the second ciphertext c; In R / 3, the seventh random polynomial r' is processed so that r'∈R, the seventh random polynomial r' is obtained by performing a modulo 3 operation on the sixth random polynomial gr, r'=1 / ge=r(mod3), e is gr(mod3), gr(mod3)=3.((699051.a+220)>>21), a∈[-3000,3000]; Performing hash processing on the seventh random polynomial r' in R / 3 to generate a third ciphertext C' and a second key k'; When it is determined that the third ciphertext C′ is identical to the first ciphertext C, the second key k′ is equal to the key k, so that the processing unit obtains the key k.
12. The device according to claim 11, characterized in that The processing unit is also used for: In the case where the absolute value of the sixth random polynomial gr is less than or equal to (q-1) / 2, it is determined that the sixth random polynomial gr satisfies the following expression: gr=3fc=3f.hr=3f.(g / 3f)r; In the case that the absolute value of the sixth random polynomial gr is greater than (q-1) / 2, it is determined that the sixth random polynomial gr satisfies the following expression: gr=sgn(3fc)(3fc-q).
13. The device according to any one of claims 8 to 10, characterized in that: The processing unit is also used for: The random number generated by the processing unit is constructed so that the constructed processing unit generates any integer greater than or equal to zero.
14. The device according to any one of claims 8 to 10, characterized in that: The first system parameter p is equal to 761, the second system parameter q is equal to 4591, and the third system parameter ω is equal to 286.
15. A Java smart card key negotiation device, comprising a processor and a memory, wherein the memory is used to store computer-executable instructions, and the processor is used to read the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
16. A computer-readable storage medium comprising a computer program, which, when executed on a computer, causes the computer to execute the method according to any one of claims 1 to 7.
17. A chip system, characterized in that: It comprises at least one processor and an interface; the at least one processor is used to call and run a computer program so that the chip system executes the method as described in any one of claims 1 to 7.