A Digital Currency Communication Method and System Based on Digital Certificates Against Quantum Computing
By using a key management server in the digital currency communication system to issue quantum-resistant computing devices and certificates, combined with ID cryptography key management, the problem that existing systems cannot resist quantum computing is solved, and high security and low-cost digital currency communication is achieved.
Patent Information
- Application Number
- CN202011023509.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-25
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-09-25
AI Technical Summary
The existing identity authentication system based on digital certificates cannot resist quantum computing, and the existing identity authentication system that resists quantum computing is costly and complex, increasing the storage and operation burden of users.
The key management server is used to issue anti-quantum computing devices to the user and the commercial bank's digital currency system, and the root certificate and certificate are issued to the user and the commercial bank's digital currency system through the root certificate issuance method, and key negotiation is used to use a key management server based on ID cryptography during the identity authentication process.
The digital currency communication system based on digital certificates that resist quantum computing is realized, which reduces the storage cost and operational workload of client key fuses, avoids major changes to the traditional CA system process and data structure, and reduces the switching cost.
Smart Images

Figure CN114331422B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication. Specifically, it relates to a quantum-computing-resistant digital currency communication method and system based on digital certificates. Background Art
[0002] The core elements of the digital currency D-RMB system of the People's Bank of China are one kind of currency, two types of libraries, and three centers. One kind of currency, namely "D-RMB" (DC / EP), abbreviated as D-currency, specifically refers to a string of encrypted digital strings representing specific amounts signed by the central bank. Two types of libraries: the issuance library of D-RMB and the bank library (central bank digital currency database, commercial bank digital currency database). Digital currency in the issuance library is manifested as the central bank's digital currency fund; digital currency in the bank library is manifested as the commercial bank's inventory digital cash. Three centers: one is the registration center (recording the whole process of currency generation, circulation, checking, and extinction); the other two are authentication centers, namely the CA authentication center (based on the PKI system, centrally managing institutional and user certificates, such as CFCA) and the IBC authentication center [i.e., the authentication center established based on identity-based cryptography (Identity-Based Cryptograph)]. Two tables can be designed in the registration center. One is the digital currency ownership registration form, recording the ownership of digital currency, and the other is the transaction record form.
[0003] The D-RMB system is a hierarchical system, jointly built by the central bank and each commercial bank. The central bank digital currency system is a computer system operated and maintained by the central bank or an institution designated by the central bank to process information about digital currency. Its main functions include being responsible for the issuance and verification monitoring of digital currency. The commercial bank digital currency system is a computer system operated and maintained by a commercial bank or an institution designated by the commercial bank to process information about digital currency. It performs various functions related to currency of existing banks, that is, bank functions, mainly including after applying for digital currency from the central bank, being responsible for directly facing the society and meeting various demands for providing digital currency circulation services.
[0004] The main principle of the existing identity authentication system based on digital certificates is as follows: A user applies for a digital certificate from an authoritative institution to prove the binding relationship between the user and their public key; the server installs the root certificate of the same authoritative institution to verify other service certificates issued by this authoritative institution. The process for the server to authenticate the user's identity is as follows:
[0005] The user uses a hash function to operate on the plaintext to be sent, generating a digest, and then encrypts the digest with their own private key to obtain a digital signature; the user sends the plaintext, digital signature, and the digital certificate applied from the authoritative institution to the server together.
[0006] After the server receives the information sent by the user, it verifies the user's digital certificate with the root certificate. After successful verification, it uses the public key of the user in the digital certificate to verify the user's digital signature. If the verification is successful, the identity authentication is successful; otherwise, the authentication fails.
[0007] However, in the existing identity authentication system based on digital certificates, data interaction among user terminals, servers, and authoritative institutions cannot achieve quantum-computing-resistant secure communication.
[0008] To enable the identity authentication system based on digital certificates to have quantum-computing resistance, Patent CN109861813A proposes a quantum-computing-resistant HTTPS communication method and system based on an asymmetric key pool, and specifically discloses a communication method. The participants in this method include a server, a certificate authority, and a client. The client is configured with a key card, and an asymmetric key pool is stored in the key card; the quantum-computing-resistant HTTPS communication method includes the following steps: The server obtains the digital certificate issued by the certificate authority and sends the digital certificate to the client. The public key pointer random number of the server is recorded in the digital certificate; the client obtains the root digital certificate issued by the certificate authority that matches the digital certificate, verifies the digital certificate sent by the server based on the root digital certificate, and obtains the server public key in the asymmetric key pool according to the public key pointer random number recorded in the verified digital certificate; encrypts the randomly generated shared key with the server public key and sends the encryption result to the server for key negotiation; conducts HTTPS communication with the server using the shared key.
[0009] Although the solution proposed in Patent CN109861813A can achieve quantum-computing-resistant communication after identity authentication, in the technical solution proposed in Patent CN109861813A, the client needs to be configured with a quantum key card that stores the public keys of all members, which requires high storage capacity for the client. Moreover, the entire identity authentication process has been modified compared with the existing technology, which requires the transformation of the internal structure of traditional CA institutions, resulting in too high costs.
[0010] Based on the above analysis, the existing technologies of digital currency communication systems have the following defects:
[0011] 1) The existing CA and identity authentication systems based on digital certificates cannot resist quantum computing;
[0012] 2) In the existing quantum-computing-resistant identity authentication systems based on quantum secure communication, the cost for users is too high and the symmetric key management is complex;
[0013] 3) In the existing quantum-resistant identity authentication system based on an asymmetric key pool, it is necessary to generate an asymmetric key pool from the public keys of all members and store it in each key card, which increases the storage cost and operation workload of the client key card.
[0014] 4) In the existing quantum-resistant identity authentication system based on an asymmetric key pool, the overall process and data structure of the traditional CA and the identity authentication system based on digital certificates are changed, resulting in too high costs for the CA and user application systems to switch to the quantum-resistant computing solution.
[0015] Regarding the problems in the related technologies, no effective solutions have been proposed yet. Summary of the Invention
[0016] Regarding the problems in the related technologies, the present invention provides a quantum-resistant digital currency communication method and system based on digital certificates to overcome the above-mentioned technical problems existing in the existing related technologies.
[0017] For this purpose, the specific technical solutions adopted by the present invention are as follows:
[0018] According to one aspect of the present invention, there is provided a quantum-resistant digital currency communication method based on digital certificates, including the following steps:
[0019] S1. Use a key management server to issue quantum-resistant computing devices to users and commercial bank digital currency systems respectively;
[0020] S2. Use a certificate authority to issue root certificates to users and commercial bank digital currency systems respectively through a root certificate issuing method, and store them in the quantum-resistant computing devices;
[0021] S3. Use the certificate authority to issue certificates to the users and the commercial bank digital currency systems respectively according to the certificate issuing method, and store them in the quantum-resistant computing devices;
[0022] S4. Use an identity authentication method to implement identity authentication between the user and the commercial bank digital currency system;
[0023] Among them, when the key management server issues a system public and private key to the user, it calculates a message authentication code to obtain the corresponding private key, then calculates the system public key according to the system private key, and stores the system private key in the quantum-resistant computing device of the key management server, and stores the public key in the quantum-resistant computing device of the user;
[0024] When the key management server issues the system public and private keys for the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the key management server and the public key in the quantum-resistant computing device of the commercial bank digital currency system;
[0025] When the key management server issues the public and private keys for the user, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the user's ID and the public and private keys in the user's quantum-resistant device;
[0026] When the key management server issues the public and private keys for the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant device of the commercial bank digital currency system.
[0027] Further, the S2 uses the root certificate issuance method to use the certificate authority to issue root certificates for the user and the commercial bank digital currency system respectively, and storing them in the quantum-resistant computing device includes the following steps:
[0028] S21. Use the certificate authority to issue a root certificate for the user and store it in the user's quantum-resistant computing device;
[0029] S22. Use the certificate authority to issue a root certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
[0030] Further, the specific steps of using the certificate authority to issue a root certificate for the user in S21 include the following steps:
[0031] S211. The user sends the identity information to the certificate authority;
[0032] S212. The certificate authority returns the root certificate of the certificate authority to the user;
[0033] S213. The user receives the root certificate of the certificate authority.
[0034] Further, the steps of using the certificate authority to issue a root certificate for the commercial bank digital currency system in S22 include the following steps:
[0035] S221. The commercial bank digital currency system sends the identity information to the certificate authority;
[0036] S222. The certificate issuing authority returns the root certificate of the certificate issuing authority to the commercial bank digital currency system;
[0037] S223. The commercial bank digital currency system receives the root certificate of the certificate issuing authority.
[0038] Furthermore, the S3 uses the certificate issuing method to use the certificate issuing authority to issue certificates for the user and the commercial bank digital currency system respectively, and storing them in the quantum-resistant computing device includes the following steps:
[0039] S31. Use the certificate issuing authority to issue a certificate for the user and store it in the user's quantum-resistant computing device;
[0040] S32. Use the certificate issuing authority to issue a certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
[0041] Furthermore, the specific steps of using the certificate issuing authority to issue a certificate for the user in S31 include the following steps:
[0042] S311. The user sends the identity information and the certificate public key to the certificate issuing authority;
[0043] S312. The certificate issuing authority returns the certificate to the user;
[0044] S313. The user receives the certificate.
[0045] Furthermore, the specific steps of using the certificate issuing authority to issue a certificate for the commercial bank digital currency system in S32 include the following steps:
[0046] S321. The commercial bank digital currency system sends the identity information and the certificate public key to the certificate issuing authority;
[0047] S322. The certificate issuing authority returns the certificate to the commercial bank digital currency system;
[0048] S323. The commercial bank digital currency system receives the certificate.
[0049] Furthermore, the S4 uses the identity authentication method to implement the identity authentication between the user and the commercial bank digital currency system, specifically including the following steps:
[0050] S41. The user sends the identity information of the object to be identity-authenticated to the certificate issuing authority;
[0051] S42. The certificate issuing authority calculates the private key of the user with respect to the object to be authenticated and sends it to the user;
[0052] S43. The user sends the user certificate to the commercial bank digital currency system;
[0053] S44. The commercial bank digital currency system generates a first random number and sends the first random number and the certificate of the commercial bank digital currency system to the user;
[0054] S45. The user generates a second random number and sends the second random number to the commercial bank digital currency system;
[0055] S46. The commercial bank digital currency system calculates a session key using the first random number and the second random number;
[0056] S47. The user calculates a session key using the first random number and the second random number.
[0057] According to another aspect of the present invention, there is provided a quantum-resistant digital currency system based on digital certificates, the system includes a central bank digital currency system, a commercial bank digital currency system, a user, and an authentication system. The central bank digital currency system conducts identity authentication with the commercial bank digital currency system and conducts secure communication. The commercial bank digital currency system conducts identity authentication with the user and conducts secure communication;
[0058] Wherein, the central bank digital currency system is used for producing and issuing digital currency, and is also used for registering the ownership of the digital currency;
[0059] The commercial bank digital currency system is used for performing banking functions for digital currency;
[0060] The user is the subject of using the digital currency;
[0061] The authentication system is used for authenticating the interaction between the commercial bank digital currency system and the user terminal device of the digital currency, and is also used for authenticating the interaction between the central bank digital currency system and the commercial bank digital currency system.
[0062] Furthermore, the communication between the commercial bank digital currency system and the user adopts a quantum-resistant identity authentication system based on digital certificates. The authentication system includes, but is not limited to, a certificate issuing authority. The certificate issuing authority is provided with a quantum-resistant computing device, and a key management server based on ID cryptography is deployed in the quantum-resistant computing device.
[0063] The beneficial effects of the present invention are as follows:
[0064] 1), The present invention can implement a quantum-resistant digital currency communication system based on digital certificates;
[0065] 2), The present invention does not require generating an asymmetric key pool for the public keys of all members and storing them in each key card, so the storage cost and operation workload of the client key card are small;
[0066] 3), The present invention does not change the overall process and data structure of the traditional CA and the identity authentication system based on digital certificates. Therefore, the cost of switching the CA and the digital currency communication system to a quantum-resistant computing solution is not high;
[0067] 4), The key issuance server based on ID cryptography in the present invention has different system public and private keys for each different user. Even if the system public key of a certain user is lost and the system private key is cracked by a quantum computer, it will not endanger the system public and private keys of the CA and other users;
[0068] 5), The communication mode of the present invention meets the requirements for security and cost in two different situations, that is: for the communication between the central bank and commercial banks with extremely high confidentiality requirements and a relatively small scope of impact on the scheme change, quantum-secure communication with higher cost and higher security is adopted to achieve communication with a higher level of security; for the communication between commercial banks and users with not extremely high confidentiality requirements and a relatively large scope of impact on the scheme change, quantum-resistant computing communication based on digital certificates is adopted to achieve communication with relatively high security and cost consideration. Therefore, the present invention improves the existing digital currency communication system into a quantum-resistant digital currency communication system and takes into account the cost of system improvement. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0070] Figure 1 is a flowchart of a quantum-resistant digital currency communication method based on digital certificates according to an embodiment of the present invention;
[0071] Figure 2 is a flowchart of the identity authentication steps between a commercial bank digital currency system and a user involved in a quantum-resistant digital currency communication method based on digital certificates according to an embodiment of the present invention;
[0072] Figure 3It is the basic structure diagram of a quantum-resistant digital currency system based on digital certificates according to an embodiment of the present invention. Detailed implementation manners
[0073] To further illustrate each embodiment, the present invention provides accompanying drawings, which are part of the disclosure of the present invention. They are mainly used to illustrate the embodiments and can be combined with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention. The components in the figures are not drawn to scale, and similar component symbols are usually used to represent similar components.
[0074] According to an embodiment of the present invention, there is provided a quantum-resistant digital currency communication method and system based on digital certificates.
[0075] Now, the present invention will be further described in combination with the accompanying drawings and specific implementation manners. As Figure 1 - Figure 2 shown, according to an embodiment of the present invention, there is provided a quantum-resistant digital currency communication method based on digital certificates, including the following steps:
[0076] S1. Use the key management server KMS to issue quantum-resistant computing devices to user A and the commercial bank digital currency system B respectively;
[0077] Among them, when the key management server KMS issues the system public and private keys to the user A, it calculates the message authentication code to obtain the corresponding private key SK MSA = MAC(ID A , SK MS ), and then calculates the system public key PK MSA according to the system private key SK MSA = SK MSA *P, and saves the system private key SK MSA in the quantum-resistant computing device of the key management server KMS, and saves the public key PK MSA in the quantum-resistant computing device T A of the user A;
[0078] When the key management server KMS issues the system public and private keys to the commercial bank digital currency system B, it calculates the message authentication code to obtain the corresponding private key SK MSB = MAC(ID B , SK MS ), and then calculates the system public key PK MSB according to the system private key SK MSB = SK MSB *P, and saves the system private key SK MSBStored in the quantum-resistant computing device of the key management server KMS, the public key PK MSB Stored in the quantum-resistant computing device T of the commercial bank digital currency system B B Inside;
[0079] When the key management server KMS issues public and private keys to the user A, it calls the hash function H1 to calculate the public key PK A = H1(ID A ), and then calculates the corresponding private key SK according to the public key PK A = SK A * PK MSA , and stores the ID of the user A and the public and private keys, namely ID A , PK A , SK A into the quantum-resistant device T of the user A A ; A ;
[0080] When the key management server KMS issues public and private keys to the commercial bank digital currency system B, it calls the hash function H1 to calculate the public key PK B = H1(ID B ), and then calculates the corresponding private key SK according to the public key PK B = SK B * PK MSB , and stores the ID of the commercial bank digital currency system B and the public and private keys, namely ID B , PK B , SK B into the quantum-resistant device T of the commercial bank digital currency system B B . B .
[0081] S2. Use the root certificate issuance method to use the certificate authority CA to issue root certificates to the user A and the commercial bank digital currency system B respectively, and store them in the quantum-resistant computing device;
[0082] Among them, the S2 includes the following steps:
[0083] S21. Use the certificate authority CA to issue a root certificate to the user A and store it in the quantum-resistant computing device T of the user A A ;
[0084] Specifically, the S21 specifically includes the following steps:
[0085] S211. The user A sends the identity information to the certificate authority CA;
[0086] The user A according to IDCA Calculate the public key PK CA = H1(ID CA ), and further calculate the symmetric key K between the user and CA A-CA = e(SK A , PK CA ). Obtain the timestamp T1, and use K A-CA to calculate the message authentication code for T1 to get K1 = MAC(T1, K A-CA ).
[0087] Use K1 to encrypt the identity information AINFO of A to get {AINFO}K1, use K1 to calculate the message authentication code for T1 and AINFO to get MAC(T1||AINFO, K1), and send it to CA together with ID A , ID CA and T1. The sent message can be expressed as:
[0088] ID A ||ID CA ||T1||{AINFO}K1||MAC(T1||AINFO, K1);
[0089] S212. The certificate authority CA returns the CA root certificate to the user A;
[0090] The KMS in CA calculates the system private key of A as SK MSA = MAC(ID A , SK MS ). According to PK CA = H1(ID CA ), obtain SK CAA = SK MSA * PK CA . Further obtain the symmetric key K between CA and A CA-A = e(SK CAA , PK A ). According to ID cryptography, it can be obtained that: K A-CA = e(SK A , PK CA ) = e(SK MSA * PK A , PK CA ) = e(PK A , SK MSA * PK CA ) = e(PK A , SK CAA ) = e(SK CAA , PK A ) = K CA-A . Use K CA-ACalculate the message authentication code for T1 to obtain K1’ = MAC(T1, K CA-A ). Decrypt and verify the message authentication code using K1’ to obtain the identity information AINFO of A.
[0091] The CA retrieves the CA root certificate CERT CA , obtains the timestamp T2, and calculates the message authentication code for T2 using K CA-A to obtain K2 = MAC(T2, K CA-A ). Encrypt CERT CA using K2 to obtain {CERT CA}K2, calculate the message authentication code for T2 and CERT CA using K2 to obtain MAC(T2||CERT CA ,K2), and send it to A together with ID CA , ID A and T2. The sent message can be expressed as ID CA ||ID A ||T2||{CERT CA}K2||MAC(T2||CERT CA ,K2).
[0092] S213. The user A receives the root certificate of the certificate authority CA.
[0093] After A receives the message, calculate the message authentication code for T2 using K A-CA to obtain K2’ = MAC(T2, K A-CA ). Decrypt and verify the message authentication code using K2’ to obtain the CA root certificate CERT CA , and after A verifies it, store it in the local quantum-resistant computing device.
[0094] S22. Use the certificate authority CA to issue a root certificate for the commercial bank digital currency system B and store it in the quantum-resistant computing device T B of the commercial bank digital currency system B.
[0095] Specifically, S22 includes the following steps:
[0096] S221. The commercial bank digital currency system B sends the identity information to the certificate authority CA;
[0097] S222. The certificate authority CA returns the CA root certificate to the commercial bank digital currency system B;
[0098] S223. The commercial bank digital currency system B receives the root certificate of the certificate authority CA.
[0099] S3. Use the certificate issuing method to issue certificates to the user A and the commercial bank digital currency system B respectively by using the certificate authority CA, and store them in the quantum-resistant computing device;
[0100] Among them, the S3 includes the following steps:
[0101] S31. Use the certificate authority CA to issue a certificate to the user A and store it in the user A's quantum-resistant computing device T A ;
[0102] Specifically, the S31 specifically includes the following steps:
[0103] S311. The user A sends the identity information and the certificate public key to the certificate authority CA;
[0104] The user A calculates the symmetric key K between the user A and the CA A-CA = e(SK A , PK CA ). Obtain the timestamp T1, and use K A-CA to calculate the message authentication code for T1 to get K1 = MAC(T1, K A-CA ).
[0105] A generates a certificate public and private key pair PK CERTA , SK CERTA , which can be based on various asymmetric cryptographic algorithms such as RSA, ECC, discrete logarithm, and ID cryptography. Use K1 to encrypt the identity information AINFO of A and the certificate public key PK CERTA of A to get {AINFO||PK CERTA}K1, use K1 to calculate the message authentication code for T1, AINFO, and PK CERTA to get MAC(T1||AINFO||PK A , K1), and send it to the CA together with ID A , ID CA and T1. The sent message can be expressed as ID A ||ID CA ||T1||{AINFO||PK CERTA}K1||MAC(T1||AINFO||PK CERTA , K1).
[0106] S312. The certificate authority CA returns a certificate to the user A;
[0107] The KMS in the CA calculates the system private key of A as SK MSA = MAC(ID A , SK MS), according to PK CA = H1(ID CA ) to obtain SK CAA = SK MSA * PK CA . Further obtain the symmetric key K between CA and A CA-A = e(SK CAA , PK A ). According to ID cryptography, it can be obtained that: K A-CA = e(SK A , PK CA ) = e(SK MSA * PK A , PK CA ) = e(PK A , SK MSA * PK CA ) = e(PK A , SK CAA ) = e(SK CAA , PK A ) = K CA-A . Use K CA-A to calculate the message authentication code for T1 to obtain K1' = MAC(T1, K CA-A ). Use K1' to decrypt and verify the message authentication code to obtain the identity information AINFO of A and the PK A used to calculate CERT CERTA .
[0108] CA makes the certificate CERT A of A. Then CA obtains the timestamp T2, and uses K CA-A to calculate the message authentication code for T2 to obtain K2 = MAC(T2, K CA-A ). Use K2 to encrypt CERT A to obtain {CERT A}K2, use K2 to calculate the message authentication code for T2 and CERT A to obtain MAC(T2||CERT A , K2), and send it to A together with ID CA , ID A and T2. The sent message can be expressed as ID CA ||ID A ||T2||{CERT A}K2||MAC(T2||CERT A , K2).
[0109] S313. The user A receives the certificate.
[0110] After A receives the message, use K A-CACalculate the message authentication code for T2 to obtain K2’ = MAC(T2, K A-CA ). Decrypt and verify the message authentication code using K2’ to obtain its own certificate CERT A . After A verifies it, it is stored in the local quantum-resistant computing device T A .
[0111] S32. Use the certificate authority CA to issue a certificate for the commercial bank digital currency system B and store it in the quantum-resistant computing device T of the commercial bank digital currency system B B .
[0112] Specifically, the S32 specifically includes the following steps:
[0113] S321. The commercial bank digital currency system B sends the identity information and the certificate public key to the certificate authority CA;
[0114] S322. The certificate authority CA returns a certificate to the commercial bank digital currency system B;
[0115] S323. The commercial bank digital currency system B receives the certificate.
[0116] In addition, the process of the CA issuing the root certificate and the certificate for the commercial bank digital currency system B is similar to the process of the CA issuing the root certificate and the certificate for the user A. Among them, the commercial bank digital currency system B generates a certificate public-private key pair PK CERTB , SK CERTB , and also performs the same steps as above with the CA to obtain its own certificate CERT B . After B verifies CERT B , it is stored in the local quantum-resistant computing device T B .
[0117] S4. Use the identity authentication method to implement the identity authentication between the user A and the commercial bank digital currency system B.
[0118] Among them, the S4 specifically includes the following steps:
[0119] S41. The user A sends the identity information of the object to be identity-authenticated to the certificate authority CA;
[0120] The user A calculates the symmetric key K A-CA = e(SK A , PK CA ). Obtain the time stamp T1, calculate the message authentication code for T1 using K A-CA to obtain K1 = MAC(T1, K A-CA ). Use K1 to encrypt ID BEncrypt to obtain {ID B}K1, and use K1 for T1 and ID B to calculate the message authentication code to obtain MAC(T1||ID B , K1). Together with ID A , ID CA and T1 are sent to CA, and the sent message can be expressed as M1 = ID A ||ID CA ||T1||{ID B}K1||MAC(T1||ID B , K1).
[0121] S42. The certificate authority CA calculates the private key of the user A relative to the object to be authenticated and sends it to the user A;
[0122] The KMS in CA calculates the system private key of A as SK MSA = MAC(ID A , SK MS ), and calculates SK CAA = SK MSA *PK CA . Further, according to PK A = H1(ID A ), the symmetric key K CA-A = e(SK CAA , PK A ) between CA and A is obtained. According to ID cryptography, it can be obtained that: K A-CA = e(SK A , PK CA ) = e(SK MSA *PK A , PK CA ) = e(PK A , SK MSA *PK CA ) = e(PK A , SK CAA ) = e(SK CAA , PK A ) = K CA-A . Use K CA-A to calculate the message authentication code for T1 to obtain K1' = MAC(T1, K CA-A ). Use K1' to decrypt M1 and verify the message authentication code to obtain ID B .
[0123] CA obtains the timestamp T2, and uses K CA-A to calculate the message authentication code for T2 to obtain K2 = MAC(T2, K CA-A ).
[0124] The KMS in CA calculates the system private key of the commercial bank digital currency system B as SK MSB = MAC(ID B , SK MS ), and calculates SK A ’ = SK MSB * PK A . Use K2 to encrypt SK A ’ to get {SK A ’}K2, use K2 to calculate the message authentication code for T2 and SK A ’ to get MAC(T2||SK’ A , K2). Together with ID CA , ID A and T2 are sent to A, and the sent message can be expressed as M2 = ID CA ||ID A ||T2||{SK’ A}K2||MAC(T2||SK’ A , K2).
[0125] S43. The user A sends the user certificate to the commercial bank digital currency system B;
[0126] After A receives the message, use K A-CA to calculate the message authentication code for T2 to get K2’ = MAC(T2, K A-CA ). Use K2’ to decrypt M2 and verify the message authentication code to get SK A ’.
[0127] A obtains the symmetric key K B between A and B according to PK B = H1(ID A-B ) = e(SK A ’, PK B ). A obtains the timestamp T3, and uses K A-B to calculate the message authentication code for T3 to get K3 = MAC(T3, K A-B ).
[0128] Take out A's certificate CERT A and use A's certificate private key SK CERTA to calculate the signature for T3 and CERT A to get SIG A = SIGN(T3||CERT A , SK CERTA ). Use K3 to encrypt CERT A and SIG A to get {CERT A ||SIGA}K3, use K3 for T3, CERT A and SIG A Calculate the message authentication code to get MAC(T3||CERT A ||SIG A , K3). Together with ID A 、ID B and T3 are sent to B. The message sent can be expressed as M3 = ID A ||ID B ||T3||{CERT A ||SIG A}K3||MAC(T3||CERT A ||SIG A , K3).
[0129] S44. The commercial bank digital currency system B generates a first random number and sends the first random number and the certificate of the commercial bank digital currency system B to the user A;
[0130] After B receives the message, B obtains the symmetric key K A = H1(ID A ) between B and A according to PK B-A = e(SK B , PK A ). According to ID cryptography, it can be obtained that: K A-B = e(SK A ’, PK B ) = e(SK MSB *PK A , PK B ) = e(PK A , SK MSB *PK B ) = e(PK A , SK B ) = e(SK B , PK A ) = K B-A . Obtain the timestamp T3, and calculate the message authentication code for T3 using K A-B to get K3’ = MAC(T3, K B-A ). Decrypt M3 using K3’ and verify the message authentication code. After verification, obtain CERT A and SIG A . Verify the certificate using the PK CA in CERT CERTCA , verify SIG CERTA using PK A , and perform a comparison verification on T3. After verification, trust the message of A.
[0131] B generates a random number N B , and uses PK CERTA to encrypt N B and ID B to obtain {N B ||ID B}PK CERTA . B obtains the timestamp T4, and uses K B-A to calculate the message authentication code for T4 to obtain K4 = MAC(T4, K B-A ). Retrieve B's certificate CERT B and use B's certificate private key SK CERTB to calculate the signature for T4, CERT B and {N B ||ID B}PK CERTA to obtain SIG B = SIGN(T4||CERT B ||{N B ||ID B}PK CERTA , SK CERTB ). Let M 4-0 = {N B ||ID B}PK CERTA ||CERT B ||SIG B , and use K4 to encrypt M 4-0 to obtain {M 4-0}K4, and use K4 to calculate the message authentication code for T4 and M 4-0 to obtain MAC(T4||M 4-0 , K4). Together with ID A and ID B and T4, send them to A. The sent message can be expressed as M4 = ID A ||ID B ||T4||{M 4-0}K4||MAC(T4||M 4-0 , K4).
[0132] S45. The user A generates a second random number and sends the second random number to the commercial bank digital currency system B;
[0133] After A receives the message, it obtains the timestamp T4 and uses K A-B to calculate the message authentication code to obtain K4' = MAC(T4, K A-B ). Use K4' to decrypt M4 to verify the message authentication code. After verification, obtain {N B ||ID B}PKCERTA , CERT B and SIG B . Use the PK in CERT CA to verify the certificate, and use the PK CERTA to verify SIG CERTB , and perform a comparison verification on T4. After the verification passes, trust B's message. Then use the SK B to decrypt {N CERTA ||ID B}PK B to obtain N CERTA . B .
[0134] A generates a random number N A , and uses the PK CERTB to encrypt N A , N B and ID A to obtain {N A ||N B ||ID A}PK CERTB . A obtains the timestamp T5, and uses K A-B to calculate the message authentication code for T5 to obtain K5 = MAC(T5, K A-B ). Use A's certificate private key SK CERTA to calculate the signature for T5 and {N A ||N B ||ID A}PK CERTB to obtain SIG A2 = SIGN(T5||{N A ||N B ||ID A}PK CERTB , SK CERTA ).
[0135] Let M 5-0 = {N A ||N B ||ID A}PK CERTB ||SIG A2 , encrypt M with K5 5-0 to obtain {M 5-0}K5, and use K5 to calculate the message authentication code for T5 and M 5-0 to obtain MAC(T5||M 5-0 , K5). Send it to B together with ID A , ID B and T5. The sent message can be expressed as M5 = ID A ||ID B ||T5||{M5-0}K5||MAC(T5||M 5-0 ,K5)。
[0136] S46. The commercial bank digital currency system B calculates a session key using the first random number and the second random number;
[0137] After B receives the message, it obtains the timestamp T5 and uses K B-A to calculate the message authentication code for T5 to get K5’ = MAC(T5, K B-A ). It decrypts M5 using K5’ and verifies the message authentication code. After successful verification, it obtains {N A ||N B ||ID A}PK CERTB and SIG A2 . It verifies SIG CERTA using PK A2 , and conducts a comparison verification on T3. After successful verification, it decrypts {N CERTB using SK A ||N B ||ID A}PK CERTB to obtain N A and N B . It verifies whether the received N B is consistent with the local N B . After successful verification, it trusts user A, and at the same time B obtains the session key calculated through N A and N B .
[0138] After successful verification, B encrypts N CERTA using PK A to obtain {N A}PK CERTA . B obtains the timestamp T6 and calculates the message authentication code for T6 using K B-A to get K6 = MAC(T6, K B-A ). It calculates the signature for T6 and {N CERTB}PK A using the private key SK CERTA to obtain SIG B2 = SIGN(T6||{N A}PK CERTA ,SK CERTB ).
[0139] It encrypts {N A}PK CERTA and SIG B2 using K6 to obtain {{N A}PK CERTA||SIG B2}K6, use K6 for T6, {N A}PK CERTA and SIG B2 Calculate the message authentication code to get MAC(T6||{N A}PK CERTA ||SIG B2 ,K6). Together with ID A 、ID B and T6 are sent to A, and the sent message can be expressed as M6 = ID A ||ID B ||T6||{{N A}PK CERTA ||SIG B2}K6||MAC(T6||{N A}PK CERTA ||SIG B2 ,K6).
[0140] S47. The user A calculates the session key by using the first random number and the second random number.
[0141] After receiving the message, A obtains the timestamp T6, and uses K A-B to calculate the message authentication code for T6 to get K6' = MAC(T6, K A-B ). Decrypt M6 with K6' and verify the message authentication code. After passing the verification, obtain {N A}PK CERTA and SIG B2 . Verify SIG CERTB with PK B2 , and conduct a comparison verification on T6. After passing the verification, use SK CERTA to decrypt {N A}PK CERTA to obtain N A . Verify whether the received N A is consistent with the local N A . After passing the verification, trust the commercial bank digital currency system B, and at the same time, A obtains the session key calculated through N A and N B .
[0142] According to another aspect of the present invention, as Figure 3As shown in the figure, a quantum-resistant digital currency system based on digital certificates is provided. The system includes a central bank digital currency system, a commercial bank digital currency system (which can be multiple commercial bank digital currency systems in practice), users, and an authentication system for authentication among the three. The central bank digital currency system conducts identity authentication and secure communication with the commercial bank digital currency system, and the commercial bank digital currency system conducts identity authentication and secure communication with the users;
[0143] Among them, the central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of the digital currency;
[0144] The commercial bank digital currency system is used to perform banking functions for digital currency;
[0145] The user is the entity that uses the digital currency;
[0146] The authentication system is used to authenticate the interaction between the commercial bank digital currency system and the user terminal device of the digital currency, and is also used to authenticate the interaction between the central bank digital currency system and the commercial bank digital currency system.
[0147] Among them, a quantum-resistant identity authentication system based on digital certificates is used for communication between the commercial bank digital currency system and the user. The authentication system includes User A, Commercial Bank Digital Currency System B corresponding to User A, and a certificate authority CA. An anti-quantum computing device T is set in the certificate authority CA , and a key management server KMS based on ID cryptography is deployed in the anti-quantum computing device.
[0148] KMS issues anti-quantum computing devices T A 、T B to User A and Commercial Bank Digital Currency System B. The anti-quantum computing device can be a key card, a mobile terminal, a cryptographic machine, a gateway, etc., and can conduct main board interface communication, short-range wireless communication, controllable intranet communication, etc. with the CA institution or each user terminal respectively, which can ensure that information will not be stolen by a quantum computer within the communication range. For example, the anti-quantum computing device can be a key card plugged into the main board of the host of the CA institution, or the anti-quantum computing device can be a mobile terminal conducting NFC communication with another mobile terminal, or the anti-quantum computing device is a cryptographic machine or a gateway conducting secure intranet communication with the user host in the same intranet.
[0149] Among them, the central bank digital currency system and the commercial bank digital currency system authenticate their identities through QKD (Quantum Key Distribution) communication: each of the central bank digital currency system and the commercial bank digital currency system has a QKD device, and the two devices conduct quantum secure communication through a QKD line and negotiate to obtain a session key.
[0150] After the commercial bank digital currency system and the user negotiate a session key and the central bank digital currency system and the commercial bank digital currency system also negotiate a session key, the entire digital currency system can carry out various operations, such as making payments and transfers of digital currency.
[0151] To facilitate the understanding of the above technical solution of the present invention, the following will detail the method for establishing a set of system parameters based on ID cryptography in the actual process of the present invention.
[0152] When the KMS issues public and private keys to a certain member, it is first necessary to establish a set of system parameters based on ID cryptography, and the steps are as follows:
[0153] (1) G1 and G2 are GDH (Diffie–Hellman group) groups of order q, where q is a large prime number. G1 is an additive cyclic group composed of points on an elliptic curve, and P is a generator of the group G1; G2 is a multiplicative cyclic group; the bilinear mapping e: G1xG2 → G2.
[0154] (2) Randomly take SK MS ∈Z P * as the system private key of the CA. SK MS is only stored in the quantum-resistant computing device of the KMS. Calculate the system public key PK MS = SK MS *P, and PK MS is stored in the quantum-resistant computing device T CA of the CA. The system public and private keys of the KMS for each different user are different. For user A, the KMS will generate a unique code as ID A , the system private key of A is SK MSA = MAC(ID A , SK MS ) [MAC(m, k) is to calculate the message authentication code for the message m using the key k], and the system public key of A is PK MSA = SK MSA *P; for the commercial bank digital currency system B, the KMS will generate a unique code as ID B , the system private key of B is SK MSB = MAC(ID B , SK MS ), and the system public key of B is PKMSB = SK MSB * P; The system private key is stored in the quantum-resistant computing device of the KMS, and the system public key is stored in the corresponding quantum-resistant computing device of the client, i.e., PK MSA Stored in T A , PK MSB Stored in T B .
[0155] (3) Select hash functions: H1: {0, 1} * → G1, H2: G2 → {0, 1} * .
[0156] (4) The system parameters are {q, G1, G2, e, n, P, H1, H2}.
[0157] When the KMS issues public and private keys for the CA, a unique code is generated as the ID CA , call the hash function H1 to calculate the public key PK CA = H1(ID CA ), and then calculate the private key SK according to the public key PK CA = SK CA * PK MS , store the ID and public and private keys of the CA, i.e., ID CA , PK CA , SK CA in the quantum-resistant computing device T of the CA CA . T CA also stores the CA root certificate CERT CA , and CERT CA includes the version number, serial number, validity period of the certificate, and the certificate public key PK of the CA CA and the certificate signature, where the certificate public key and the certificate signature can be based on various asymmetric cryptographic algorithms such as RSA, ECC, discrete logarithm, ID cryptography, etc. CERTCA When the KMS issues public and private keys for user A, call the hash function H1 to calculate the public key PK
[0158] = H1(ID A ), and then calculate the private key SK according to the public key PK A = SK A * PK A , store the ID and public and private keys of A, i.e., ID MSA , PK A , SK A in the quantum-resistant computing device T of A A , SK A . A .
[0159] When the KMS issues the public and private keys for the commercial bank digital currency system B, it calls the hash function H1 to calculate the public key PK B = H1(ID B ), and then calculates the private key SK B according to the public key PK B = SK MSB *PK B . Store B's ID and public and private keys, namely ID B , PK B , SK B in B's quantum-resistant computing device T B .
[0160] In summary, by means of the above technical solutions of the present invention, through the use of the present invention, a digital currency communication system based on digital certificates that resists quantum computing can be realized;
[0161] The present invention does not need to generate an asymmetric key pool for all members' public keys and store them in each key card. The storage cost and operation workload of the client key card are small;
[0162] The present invention does not change the overall process and data structure of the traditional CA and the identity authentication system based on digital certificates. Therefore, the cost of switching the CA and the digital currency communication system to a quantum-resistant computing scheme is not high;
[0163] The key issuance server of the present invention based on ID cryptography has different system public and private keys for each different user. Even if the system public key of a certain user is lost and the system private key is cracked by a quantum computer, it will not endanger the system public and private keys of the CA and other users;
[0164] The communication mode of the present invention meets the requirements for security and cost in two different situations, namely: for the communication between the central bank and commercial banks with extremely high confidentiality requirements and a relatively small scope of impact on the scheme change, quantum-secure communication with higher cost and higher security is adopted to achieve communication with a higher level of security; for the communication between commercial banks and users with not extremely high confidentiality requirements and a relatively large scope of impact on the scheme change, quantum-resistant computing communication based on digital certificates is adopted to achieve communication with relatively high security and cost consideration. Therefore, the present invention improves the existing digital currency communication system into a quantum-resistant computing digital currency communication system and takes into account the cost of system improvement.
[0165] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A digital currency communication method based on digital certificates against quantum computing, characterized in that, It includes the following steps: S1. Use the key management server to issue anti-quantum computing devices to users and the commercial bank digital currency system respectively; When the key management server issues the system public and private keys to the user, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, saves the system private key in the anti-quantum computing device of the key management server, and saves the public key in the anti-quantum computing device of the user; The anti-quantum computing device includes at least one of a key card, a mobile terminal, a cipher machine or a gateway, and can perform mainboard interface communication, short-range wireless communication, and controllable intranet communication with the CA institution or each client respectively; When the key management server issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, saves the system private key in the anti-quantum computing device of the key management server, and saves the public key in the anti-quantum computing device of the commercial bank digital currency system; When the key management server issues the public and private keys to the user, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the user's ID and the public and private keys in the user's anti-quantum device; When the key management server issues the public and private keys to the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the anti-quantum device of the commercial bank digital currency system; S2. Use the certificate authority to issue root certificates to the user and the commercial bank digital currency system respectively through the root certificate issuance method, and store them in the anti-quantum computing device; S3. Use the certificate authority to issue certificates to the user and the commercial bank digital currency system respectively according to the certificate issuance method, and store them in the anti-quantum computing device; S4. Use the identity authentication method to implement the identity authentication between the user and the commercial bank digital currency system; Specifically, it includes the following steps: S41. The user sends the identity information of the object to be identity-authenticated to the certificate authority; S42. The certificate authority calculates the private key of the user relative to the object to be identity-authenticated and sends it to the user; S43. The user sends the user certificate to the commercial bank digital currency system; S44. The commercial bank digital currency system generates a first random number, and sends the first random number and the certificate of the commercial bank digital currency system to the user; S45. The user generates a second random number and sends the second random number to the commercial bank digital currency system; S46. The commercial bank digital currency system calculates the session key using the first random number and the second random number; S47. The user calculates the session key using the first random number and the second random number.
2. The anti-quantum computing digital currency communication method based on digital certificates according to claim 1, characterized in that, S2 uses the root certificate issuance method to use the certificate authority to issue root certificates for users and the commercial bank digital currency system respectively, and store them in the quantum-resistant computing device, including the following steps: S21. Use the certificate authority to issue a root certificate for the user and store it in the user's quantum-resistant computing device; S22. Use the certificate authority to issue a root certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
3. A method for quantum-computing-resistant digital currency communication based on digital certificates according to claim 2, characterized in that, The specific steps of using the certificate authority to issue a root certificate for the user in S21 include the following steps: S211. The user sends the identity information to the certificate authority; S212. The certificate authority returns the certificate authority root certificate to the user; S213. The user receives the root certificate of the certificate authority.
4. A digital currency communication method based on digital certificates against quantum computing according to claim 2, characterized in that The steps of using the certificate authority to issue a root certificate for the commercial bank digital currency system in S22 include the following steps: S221. The commercial bank digital currency system sends the identity information to the certificate authority; S222. The certificate authority returns the certificate authority root certificate to the commercial bank digital currency system; S223. The commercial bank digital currency system receives the root certificate of the certificate authority.
5. A method for anti-quantum computing digital currency communication based on digital certificates according to claim 1, characterized in that, S3 uses the certificate issuance method to use the certificate authority to issue certificates for the user and the commercial bank digital currency system respectively, and store them in the quantum-resistant computing device, including the following steps: S31. Use the certificate authority to issue a certificate for the user and store it in the user's quantum-resistant computing device; S32. Use the certificate authority to issue a certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
6. The method for anti-quantum computing digital currency communication based on digital certificates according to claim 5, wherein The specific steps of using the certificate authority to issue a certificate for the user in S31 include the following steps: S311. The user sends the identity information and the certificate public key to the certificate authority; S312. The certificate authority returns the certificate to the user; S313. The user receives the certificate.
7. A method for anti-quantum computing digital currency communication based on digital certificates according to claim 5, characterized in that The specific steps of using the certificate authority to issue a certificate for the commercial bank digital currency system in S32 include the following steps: S321. The commercial bank digital currency system sends the identity information and the certificate public key to the certificate authority; S322. The certificate authority returns the certificate to the commercial bank digital currency system; S323. The commercial bank digital currency system receives the certificate.
8. A quantum-computing-resistant digital currency system based on digital certificates, which implements the steps of the quantum-computing-resistant digital currency communication method based on digital certificates described in any one of claims 1-7, characterized in that, The system includes a central bank digital currency system, a commercial bank digital currency system, users, and an authentication system. The central bank digital currency system conducts identity authentication and secure communication with the commercial bank digital currency system. The commercial bank digital currency system conducts identity authentication and secure communication with the users; Among them, the central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of the digital currency; The commercial bank digital currency system is used to perform banking functions for digital currency; The user is the entity using the digital currency; The authentication system is used to authenticate the interaction between the commercial bank digital currency system and the user terminal device of the digital currency, and is also used to authenticate the interaction between the central bank digital currency system and the commercial bank digital currency system.
9. The quantum computing-resistant digital currency system based on digital certificates according to claim 8, wherein, The commercial bank digital currency system and the user communicate using a quantum-resistant identity authentication system based on digital certificates. The authentication system includes a certificate authority, in which a quantum-resistant computing device is provided, and a key management server based on ID cryptography is deployed in the quantum-resistant computing device.
Citation Information
Patent Citations
antiquantum computing HTTPS communication method and system based on a plurality of asymmetric key pools
CN109756500A
An antiquantum computing HTTPS communication method and system based on an asymmetric key pool
CN109861813A