Quantum-Secure Fast Two-Factor Authentication Method and System
By adopting a fast secondary identity authentication method based on quantum security in 5G networks, leveraging the security of quantum cryptography technology and the advantages of quantum communication networks, the problem of easy identity information leakage and attack in the existing technology is solved, and efficient and secure two-way identity authentication is achieved.
Patent Information
- Application Number
- CN202111552695.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-17
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-12-17
AI Technical Summary
The existing 5G network secondary identity authentication protocol has the risk of user identity information leakage, is vulnerable to dictionary or offline dictionary attacks, and requires certificate exchange and complex management and maintenance processes.
The fast secondary identity authentication method based on quantum security is adopted, and the security of quantum cryptography technology and the advantages of quantum communication networks in key distribution are used to achieve lightweight fast authentication, two-way authentication and information hiding between the two parties.
It realizes forward security, integrity and anti-aggressive information, avoids man-in-the-middle attacks, forged identity attacks and replay attacks, and reduces the complexity and cost of the authentication process.
Smart Images

Figure CN114386020B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum communication security, and particularly relates to a fast secondary identity authentication method and system based on quantum security. Background Technique
[0002] The statements in this part only provide background technical information related to the present invention, and do not necessarily constitute prior art.
[0003] Mobile communication technology supports two authentication processes, namely primary authentication and secondary authentication, for enterprise / industry users when accessing the network.
[0004] Primary authentication, also known as main authentication, is the primary authentication of the user's network access by the network when the user accesses the communication network. Before the user terminal accesses the data service network, it first needs to complete the main authentication and authorization between the UDM (Unified Data Management) and the AUSF (Authentication Server Function).
[0005] Secondary authentication is that subsequently, the SMF (Session Management Function) network element will decide whether to initiate secondary identity authentication according to the subscribed information when establishing the user plane data channel for it.
[0006] However, there are still certain problems with this authentication method. Taking the 5G network as an example, as Figure 1 shown, it is the primary authentication and secondary authentication processes of the 5G network and the 5G network elements involved. According to the 3GPP standard TS33.501, the secondary identity authentication process occurs between the user terminal UE and the DN-AAA server of the external data network DN, and the authentication protocol is based on the EAP framework defined in RFC3748 and can be customized.
[0007] According to the regulations of the 3GPP standard on the security process between the UE and the external data network through the 5G network, the secondary authentication protocol between the UE and the AAA server is carried by EAP. During the interaction process of the secondary authentication protocol, network elements such as AN, AMF, SMF, and UPF will not parse the secondary authentication protocol, and end-to-end secondary authentication customized by enterprise / industry users can be achieved.
[0008] Existing common authentication protocols include several methods such as password - based EAP authentication protocol, TLS - based EAP authentication protocol, and SIM - card - based authentication protocol. However, as the inventor understands, the password - based EAP authentication protocol generally transmits in plain text, there is a risk of leakage of user identity information, and it is vulnerable to dictionary or offline dictionary attacks; for the TLS - based EAP authentication protocol, security certificates need to be installed on both the client and the authentication server, and all messages before certificate exchange are transmitted in plain text, and the user's identity information is easily leaked, and it is vulnerable to dictionary or offline dictionary attacks; the SIM - card - based authentication protocol needs to first provide its own identity information to the server side, and the user's identity information is sent in plain text, there is a risk of leakage of the user's identity information. Summary of the Invention
[0009] To solve at least one of the technical problems existing in the above - mentioned background technology, the present invention provides a quantum - secure fast secondary authentication method and system. By utilizing the security of quantum cryptography technology and the advantages of quantum communication networks in key distribution, lightweight fast authentication, two - way authentication, and information hiding of both authentication parties can be achieved, better ensuring the forward security, integrity, and anti - attack ability of information in network applications.
[0010] To achieve the above object, the present invention adopts the following technical solutions:
[0011] A quantum - secure fast secondary authentication method, applied to the authentication server side, includes the following steps:
[0012] Based on locally generated random numbers and serial numbers, calculate and generate a first message, and based on the generated random numbers and identity identification information, calculate and generate a second message;
[0013] Encrypt the first message and the second message to obtain a first ciphertext, and send a message containing the first ciphertext and the serial number;
[0014] Receive a message from the user side containing the updated local serial number, the user - side serial number, and a second ciphertext;
[0015] Verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process;
[0016] Decrypt the second ciphertext to obtain decryption information, extract the local random numbers, identity identification information, the user - side identity identification information and password, calculate the corresponding message, and compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute; otherwise, send an authentication error message and end the authentication process;
[0017] Extract the third message from the decryption information, calculate the client random number, and use the updated client serial number, client random number, identity information, and password to generate the fifth message through operations, and encrypt it to generate the third ciphertext;
[0018] Send a message containing the authentication success information, the updated client serial number, and the third ciphertext;
[0019] Receive an authentication success message or an authentication error message.
[0020] As an alternative implementation, the random number is generated by a local quantum random number generator, and the serial numbers are all generated locally.
[0021] As an alternative implementation, the server and the client have the same shared key.
[0022] As an alternative implementation, all the operations are exclusive OR operations.
[0023] As an alternative implementation, it further includes performing a hash process on the first message and the second message to obtain the first hash value.
[0024] As a further limitation, the process of obtaining the first ciphertext is replaced by encrypting the first message and the first hash value.
[0025] As an alternative implementation, it further includes performing a hash process on the fifth message to obtain the third hash value.
[0026] As a further limitation, the process of generating the third ciphertext is replaced by encrypting the third hash value.
[0027] As an alternative implementation, a hash function is used for the hash process.
[0028] As an alternative implementation, a symmetric encryption algorithm and a shared key are used for the encryption process.
[0029] As an alternative implementation, a symmetric encryption algorithm and a shared key are used for the decryption process.
[0030] As an alternative implementation, when sending an authentication error message, an error code is also sent simultaneously, and the error code includes the authentication error message and the reason for the authentication error.
[0031] As an alternative implementation, if part or all of the identity information and password are zero, only the random numbers of both parties are verified during the verification process.
[0032] As an alternative embodiment, if part or all of the identity identification information is zero, a local random number is used as the identity identification information for both parties.
[0033] As an alternative embodiment, the transmitted information is encapsulated in the EAP format.
[0034] A fast secondary identity authentication method based on quantum security, applied to the client side, includes the following steps:
[0035] Receive a message sent by the server side containing the first ciphertext and its serial number;
[0036] Decrypt the first ciphertext, extract the first message from the decryption information, and calculate the server-side random number;
[0037] Extract the server-side identity identification information, and calculate the message corresponding to the second message based on the random number and the identity identification information;
[0038] Compare whether the corresponding message and the corresponding information in the decryption information are consistent. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process;
[0039] Generate a third message based on the locally generated random number and the serial number;
[0040] Generate a fourth message based on the updated server-side serial number, the server-side random number, the identity identification information, and the local identity identification information and password;
[0041] Encrypt the third message and the fourth message to obtain the second ciphertext;
[0042] Send a message containing the updated server-side serial number, the local serial number, and the second ciphertext;
[0043] Receive a message sent by the server side containing the authentication success information, the updated client-side serial number, and the third ciphertext;
[0044] Verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process;
[0045] Extract the local random number, identity identification information, and password, combine with the updated local serial number, calculate the corresponding message, encrypt the corresponding message to obtain the corresponding ciphertext, compare the corresponding ciphertext with the third ciphertext. If they are consistent, the authentication is successful and send the authentication success information; otherwise, send an authentication error message and end the authentication process.
[0046] As an alternative embodiment, it further includes performing a hash process on the third message and the fourth message to obtain the second hash value.
[0047] As a further limitation, the process of obtaining the second ciphertext is replaced by encrypting the third message and the second hash value.
[0048] As an alternative implementation, the random number is generated by a local quantum random number generator, and the serial numbers are all generated locally.
[0049] As an alternative implementation, the server side and the user side have the same shared key.
[0050] As an alternative implementation, the operations are all exclusive-or operations.
[0051] As an alternative implementation, a hash function is used for the hash processing during the hash processing.
[0052] As an alternative implementation, a symmetric encryption algorithm and a shared key are used for encryption during the encryption process.
[0053] As an alternative implementation, a symmetric encryption algorithm and a shared key are used for decryption during the decryption process.
[0054] As an alternative implementation, when sending an authentication error message, an error code is also sent simultaneously, and the error code includes the authentication error message and the reason for the authentication error.
[0055] As an alternative implementation, if part or all of the identity identification information and the password are zero, only the random numbers of both parties are verified during the verification process.
[0056] As an alternative implementation, if part or all of the identity identification information is zero, the local random number is used as the identity identification information of both parties.
[0057] As an alternative implementation, the transmitted information is encapsulated in the EAP format.
[0058] A fast two-factor authentication method based on quantum security includes the following steps:
[0059] The server side generates a first message based on a locally generated random number and a serial number, and generates a second message based on the generated random number and identity identification information; encrypts the first message and the second message to obtain a first ciphertext, and sends a message including the first ciphertext and the serial number;
[0060] The client receives a message sent by the server that contains the first ciphertext and its serial number; decrypts the first ciphertext, extracts the first message from the decrypted information, and calculates the server random number; extracts the identity information of the server, and calculates the message corresponding to the second message based on the random number and the identity information; compares whether the corresponding messages and the corresponding information in the decrypted information are consistent. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; generates a third message based on the locally generated random number and the serial number; generates a fourth message based on the updated server serial number, the server random number, the identity information, as well as the local identity information and password, encrypts the third message and the fourth message to obtain the second ciphertext, and sends a message that contains the updated server serial number, the local serial number, and the second ciphertext.
[0061] The server receives the message sent back by the client that contains the updated local serial number, the client serial number, and the second ciphertext; verifies whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; decrypts the second ciphertext to obtain the decrypted information, extracts the local random number, the identity information, the client identity information, and the password, calculates the corresponding message, and compares whether the corresponding message and the corresponding information in the decrypted information are consistent. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; extracts the third message from the decrypted information, calculates the client random number, generates a fifth message using the updated client serial number, the client random number, the identity information, and the password, encrypts it to generate the third ciphertext, and sends a message that contains the authentication success information, the updated client serial number, and the third ciphertext.
[0062] The client receives the message sent by the server that contains the authentication success information, the updated client serial number, and the third ciphertext; verifies whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; extracts the local random number, the identity information, and the password, combines them with the updated local serial number, calculates the corresponding message, encrypts the corresponding message to obtain the corresponding ciphertext, and compares the corresponding ciphertext with the third ciphertext. If they are consistent, the authentication is successful and an authentication success message is sent; otherwise, an authentication error message is sent and the authentication process ends.
[0063] A fast two-factor authentication system based on quantum security, including a server and a client, where:
[0064] The server side is used to generate a first message through operations based on a locally generated random number and a serial number, and generate a second message through operations based on the generated random number and identity information; encrypt the first message and the second message to obtain a first ciphertext, and send a message including the first ciphertext and the serial number;
[0065] Receive a message including the updated local serial number, the client serial number, and the second ciphertext feedback from the client; verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message to end the authentication process; decrypt the second ciphertext to obtain decryption information, extract the local random number, identity information, the client's identity information, and the password, calculate the corresponding message, and compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute; otherwise, send an authentication error message to end the authentication process; extract a third message from the decryption information, calculate the client random number, and use the updated client serial number, the client random number, the identity information, and the password to generate a fifth message through operations, encrypt it to generate a third ciphertext, and send a message including the authentication success information, the updated client serial number, and the third ciphertext; receive an authentication success message or an authentication error message;
[0066] The client is used to receive a message including the first ciphertext and its serial number sent by the server side; decrypt the first ciphertext, extract the first message from the decryption information, and calculate the server random number; extract the server's identity information, and calculate the message corresponding to the second message based on the random number and the identity information; compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute; otherwise, send an authentication error message to end the authentication process; generate a third message through operations based on the locally generated random number and the serial number; generate a fourth message through operations based on the updated server serial number, the server random number, the identity information, the local identity information, and the password, perform an encryption process on the third message and the fourth message to obtain a second ciphertext, and send a message including the updated server serial number, the local serial number, and the second ciphertext;
[0067] Verify whether the updated local serial number in the message including the authentication success information, the updated client serial number, and the third ciphertext is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message to end the authentication process; extract the local random number, identity information, and password, combine the updated local serial number, calculate the corresponding message, encrypt the corresponding message to obtain the corresponding ciphertext, compare the corresponding ciphertext and the third ciphertext. If they are consistent, the authentication is successful, and send an authentication success message; otherwise, send an authentication error message to end the authentication process.
[0068] A computer-readable storage medium stores a computer program thereon, and when the program is executed by a processor, the steps in the method as described above are implemented.
[0069] A computer device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps in the method as described above are implemented.
[0070] Compared with the prior art, the beneficial effects of the present invention are:
[0071] The present invention can achieve two-way authentication, hide the identity information of both parties in authentication, achieve multiple authentication, protect information, and have confidentiality, integrity, forward security, and true randomness of keys, and can resist attack means such as man-in-the-middle attack, forged identity attack, and replay attack.
[0072] The present invention uses a symmetric encryption algorithm to implement two-way identity verification, rather than the traditional asymmetric public key algorithm signature method, avoiding the complex management and maintenance processes of the public-private key certificate system for certificate generation, verification, change, cancellation, etc., and realizing lightweight authentication. During the authentication process, in addition to the exclusive OR operation, only the symmetric encryption and decryption algorithm and the hashing algorithm are involved, and the purpose of fast authentication can be achieved.
[0073] Considering security, the authentication not only requires the server side to authenticate the user side, but also the user side needs to authenticate the identity of the server side, meeting the requirement of two-way authentication. And during the process of participating in the verification with identity information, only ciphertext is transmitted, achieving the effect of hiding the information of both parties in authentication.
[0074] The present invention uses the identity identification information or random numbers generated by both parties as the identity authentication identifier. At the same time, if there is verifiable identity information or user password between the two parties, it can also participate in the identity verification, achieving the effect of multi-factor verification.
[0075] The information transmitted between the two parties in authentication of the present invention is encrypted to ensure the confidentiality of the information. Sensitive information such as user identity information, server identity information, user password, etc. of both parties is not transmitted in plain text, or even not transmitted in cipher text, and only participates in the hashing operation and is verified by transmitting the hash value, ensuring the unconditional security of the original data.
[0076] The present invention realizes the integrity of the transmitted information through the hashing algorithm. At the same time, for the security of sensitive information such as identity information, only the ciphertext after encrypting the hash value of these information is transmitted.
[0077] The shared key of the present invention is based on a quantum key distribution system with quantum security, ensuring the freshness and security of the shared key and enabling forward security.
[0078] The generation of the encryption key and random number of the present invention is based on quantum security, which can ensure the uniformity, independence and unpredictability of the random sequence, and guarantee the true randomness of the key and random number.
[0079] During the two-way authentication process, since the attacker does not have the pre-shared key of both parties and cannot obtain the data information, and due to the hiding of the identity, the attacker cannot even obtain the true identities of both parties, so the man-in-the-middle attack cannot be realized; the attacker cannot obtain the negotiated key, so it cannot impersonate the session participant either.
[0080] The present invention does not take the user password as the only authentication credential, and the user password does not participate in the transmission. Only the user password participates in the authentication, and the transmitted is the hashed hash value / ciphertext and encrypted transmission. Therefore, this protocol is not vulnerable to dictionary attacks.
[0081] The present invention adds independent serial number values in both directions of communication for anti-replay attack detection. The serial number participates in data operations and has two functions: one is to be used to confuse the ciphertext output, which is equivalent to the initialization vector of the data; the second is to participate in the operation process for anti-replay verification.
[0082] The advantages of the additional aspects of the present invention will be partially given in the following description, partially will become obvious from the following description, or will be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] The specification drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0084] Figure 1 It is a schematic diagram of the first authentication and second authentication in the 5G network;
[0085] Figure 2 It is a schematic diagram of the second authentication framework and protocol stack;
[0086] Figure 3 It is a schematic diagram of the second authentication process of the EAP encapsulation format;
[0087] Figure 4 It is a schematic diagram of the second identity authentication process of at least one embodiment of the present invention;
[0088] Figure 5 It is a schematic diagram of the second identity authentication process of at least one embodiment of the present invention;
[0089] Figure 6 It is a schematic diagram of the EAP message format of at least one embodiment of the present invention;
[0090] Figure 7It is a schematic diagram of the EAP extended authentication protocol of at least one embodiment of the present invention. Detailed implementation manners
[0091] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0092] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0093] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0094] For the convenience of those skilled in the art to understand, 5G communication is used as an example for description in this part, but it does not mean that the present invention can only be used in this scenario.
[0095] As Figure 1 and Figure 2 shown, the 5G secondary authentication follows the Extensible Authentication Protocol (EAP). The authentication message is carried by the NAS signaling. Among them, the terminal UE acts as the authenticated end (Peer), the SMF network element acts as the authenticator (Authenticator), and the AAA acts as the authentication server (Server). The 5G secondary authentication process is as Figure 3 shown. The SMF network element sends a message to start the authentication to the AAA server and establishes an authentication channel between the UE and the AAA. The UE and the AAA will go through several EAP-Request / EAP-Response message interactions. The specific number of interactions and the content of the interactions depend on the authentication protocol used. The user can use public protocols such as PAP, CHAP, AKA, TLS, etc., or can customize algorithms and protocols. Finally, the AAA sends the authentication result to the UE. After the secondary authentication is passed, the 5G core network will establish a connection for the terminal to the data network.
[0096] Follow the encapsulation format of the Extensible Authentication Protocol (EAP), and build a secondary authentication method for 5G networks based on quantum keys, namely EAP_QSSEH (Quantum Secure Symmetrical Encryption and Hash - function), based on the quantum cryptographic network. Utilize the security of quantum cryptographic technology and the advantages of quantum communication networks in key distribution, and combine the secondary authentication requirements of vertical enterprises in 5G networks to propose a lightweight and fast secondary authentication solution for 5G networks based on quantum security.
[0097] The EAP (Extensible Authentication Protocol) is based on the PPP (Point to Point Protocol) mechanism and is an extension of the PPP protocol that supports multiple authentication mechanisms. EAP enables the client to request authentication information from the actual user multiple times, and the server - side executes the specific authentication method. In this way, the client transfers authentication messages between the server - side and the accessing user through the EAP protocol.
[0098] The EAP protocol provides a framework for authentication, on which various EAP authentication methods can be supported. Compared with PAP authentication and CHAP authentication, EAP authentication is more strict in network access management and can better ensure the security of information in network applications.
[0099] The EAP message format is as Figure 6 shown. Among them, the Type occupies one byte and is used to represent the specific EAP message authentication type, which is extensible, and the specific types are as Figure 7 shown.
[0100] For the newly added protocol processing method, a new EAP type value can be newly defined, and a corresponding EAP protocol, namely EAP_QSSEH (an authentication protocol based on quantum - secure symmetric encryption and hashing algorithm under the EAP encapsulation format), can be added, and a corresponding processing branch can be added in the processing module.
[0101] Based on quantum security, the basic principles of quantum communication (such as the principle of non - cloning of quantum states and the measurement collapse of quantum states, etc.) are utilized to ensure the security of information transmission. Quantum cryptographic technology based on Quantum Key Distribution (QKD) is one of the most important practical applications of quantum communication at the present stage. Quantum cryptography is based on quantum mechanics, and its security is established on physical characteristics such as the uncertainty principle, the non - cloning of quantum states, and quantum coherence, and is proven to be unconditionally secure in principle.
[0102] The following is described with different embodiments:
[0103] Example 1
[0104] A secondary authentication method, as Figure 4 shown, includes the following steps:
[0105] Preceding steps: There is already a shared key K between the UE (User Equipment) and the AAA (Authentication Server); the quantum random number generator (QRNG) on the AAA server side generates a random number R1, and the AAA server generates a sequence number N1; the quantum random number generator on the UE side generates a random number R2, and the UE generates a sequence number N2.
[0106] It should be noted that the distribution and transfer of the shared key K can be achieved with the help of a quantum security service platform and a quantum key mobile medium. The shared key K can be a quantum key (or random number key) generated by the QKD process or QRNG stored in the quantum security service platform. The quantum key can be stored in the quantum key mobile medium, so as to realize the offline distribution of the shared key K through the quantum key mobile medium.
[0107] In some embodiments, the preceding steps are not included in the provided authentication method.
[0108] Step 1:
[0109] 1) Perform an exclusive OR operation on N1 and R1 to generate a message m1;
[0110] 2) Perform an exclusive OR operation on R1 and IDa to generate a message m2, where IDa is the identity identification information of the AAA;
[0111] 3) Use a hash function to hash m1 and m2 to obtain a hash value h1;
[0112] 4) Use a symmetric encryption algorithm and the shared key K to encrypt m1 and h1 to obtain a ciphertext e1.
[0113] Step 2:
[0114] The AAA sends N1||e1 to the UE, where || represents a concatenation operation.
[0115] Step 3:
[0116] 1) After the UE receives e1, use a symmetric encryption algorithm and the shared key K to decrypt e1 to obtain d1;
[0117] 2) Extract m1 from d1 to obtain the random number R1 on the AAA server side, R1 = (N1^m1), where ^ represents an exclusive OR operation;
[0118] 3) Extract the identity identification information IDa of the AAA locally and calculate m2' = (R1^IDa);
[0119] 4) Calculate the hash value h1' of m1||m2' using a hashing algorithm, compare h1' with h1 in d1. If they are the same, continue to execute the following steps; if not, send failure and an error code (failure||reason) to the AAA response, and the authentication process ends.
[0120] 5) Exclusive OR N2 and R2 to generate a message m3.
[0121] 6) Exclusive OR (N1 + 1), R1, IDa, IDu, and M to generate a message m4, where IDa is the AAA identity information, IDu is the UE identity information, and M is the UE user password.
[0122] 7) Use a hashing function to hash m3 and m4 to obtain the hash value h2.
[0123] 8) Use a symmetric encryption algorithm and the shared key K to encrypt m3 and h2 to obtain the ciphertext e2.
[0124] Step 4:
[0125] The UE sends the message (N1 + 1)||N2||e2 to the AAA.
[0126] Step 5:
[0127] 1) The AAA verifies whether the sequence number value (N1 + 1) in the message is reasonable. If it is reasonable, continue to execute the following steps; if not, directly discard the data packet, send failure and an error code (failure||reason) to the UE response, and the authentication process ends.
[0128] 2) Use a symmetric encryption algorithm and the shared key K to decrypt e2 to obtain d2.
[0129] 3) Extract the local parameters R1, IDa, IDu, and M, and calculate m4' = ((N1 + 1) ^ R1 ^ IDa ^ IDu ^ M).
[0130] 4) Extract m3 from d2, and use a hashing algorithm to calculate the hash value h2' of m3||m4'. Compare h2' with h2 in d2. If they are the same, continue to execute the following steps; if not, send failure and an error code (failure||reason) to the UE response, and the authentication process ends.
[0131] 5) Obtain the UE random number R2, where R2 = N2 ^ m3.
[0132] 6) Exclusive OR (N2 + 1), R2, IDu, and M to generate a message m5.
[0133] 7) Hash m5 using a hash function to obtain a hash value h3;
[0134] 8) Encrypt h3 using a symmetric encryption algorithm and a shared key K to obtain a ciphertext e3.
[0135] Step 6:
[0136] AAA sends the message success||(N2 + 1)||e3 to the UE.
[0137] Step 7:
[0138] 1) The UE verifies whether the sequence number value (N2 + 1) in the message is reasonable. If it is reasonable, continue to execute downward; if it is not reasonable, directly discard the data packet, send failure and an error code (failure||reason) to AAA as a receipt, and the authentication process ends;
[0139] 2) Extract local parameters such as R2, IDu, and M, and calculate m5’ = ((N2 + 1)^R2^IDu^M);
[0140] 3) Calculate the hash value h3’ of m5’ using a hashing algorithm;
[0141] 4) Encrypt h3’ using a symmetric encryption algorithm and a shared key K to get e3’; compare e3’ and e3. If they are the same, the verification is successful; if they are different, send failure and an error code (failure||reason) to AAA as a receipt, and the authentication process ends.
[0142] Step 8:
[0143] The UE sends the message success to AAA.
[0144] The entire authentication process ends.
[0145] This embodiment realizes the two-way authentication process between the UE and AAA through 8 steps and 4 handshakes. During the entire authentication process, in addition to the exclusive OR operation, the time-consuming processes involved include 6 calls to the symmetric encryption and decryption algorithms (including 4 encryption calls and 2 decryption calls), and 6 calls to the hashing algorithm.
[0146] In some embodiments, the symmetric encryption algorithm can adopt the domestic commercial cipher SM4, and the hashing algorithm can adopt the domestic commercial cipher SM3.
[0147] During the mutual authentication process between the two parties, IDa is the identity identification information of the AAA server, IDu is the identity identification information of the UE device, and M is the user password of the UE. These information are all proof information co-existing locally in both the UE and the AAA, and the random numbers R1 and R2 generated by both parties, which are the multiple factors for implementing multi-factor authentication. If some or all of the proof information does not exist, for example, IDa, IDu, and M are partially or completely 0, this situation only verifies the random numbers R1 and R2 of both parties, and it is also possible to use R1 and R2 as the identity identification information of both parties, which does not affect the implementation of the mutual identity authentication of this protocol.
[0148] All the data transmitted during the handshake process in the entire authentication process are encapsulated in the EAP format.
[0149] Of course, the secondary identity authentication process is also a key negotiation process. After successful authentication, both parties can use the negotiated new shared key Ks to encrypt and protect the subsequent session information. The new shared key Ks = f(R1, R2) is generated by the joint action of the random numbers R1 and R2 generated by both parties. For example, Ks = (R1 ^ R2) or Ks = (R1 || R2).
[0150] The secondary identity authentication method of this embodiment has characteristics such as lightweight, fast authentication, higher efficiency, and higher security, with better comprehensive performance; it can achieve mutual authentication, hide the identity information of both parties in the authentication, implement multi-authentication, protect information, and has confidentiality, integrity, forward security, and true randomness of the key, and can resist attack means such as man-in-the-middle attack, forged identity attack, and replay attack; it also has a key negotiation function.
[0151] Embodiment 2
[0152] The difference between this embodiment and Embodiment 1 is that there is only symmetric encryption operation and no hashing operation during the authentication process. Although the integrity of the message is not as good as that of Embodiment 1, the execution efficiency is higher on the premise of not affecting the implementation of the mutual identity authentication between the UE and the AAA. Of course, since no hashing function is used, m2, m4, and m5 need to be encrypted and transmitted during the authentication process of this embodiment.
[0153] A secondary identity authentication method, as Figure 5 shown, includes the following steps:
[0154] Preparatory work in the early stage (this step may not be included in some embodiments):
[0155] There is already a shared key K between the UE (User Equipment) and the AAA (Authentication Server); the quantum random number generator on the AAA server side generates a random number R1, and the AAA server generates a sequence number N1; the quantum random number generator on the UE side generates a random number R2, and the UE generates a sequence number N2.
[0156] Step 1:
[0157] 1) Perform an exclusive OR operation on N1 and R1 to generate a message m1;
[0158] 2) Perform an exclusive OR operation on R1 and IDa to generate a message m2, where IDa is the identity identification information of the AAA;
[0159] 3) Use the symmetric encryption algorithm and the shared key K to encrypt m1 and m2 to obtain the ciphertext e1.
[0160] Step 2:
[0161] The AAA sends N1||e1 to the UE.
[0162] Step 3:
[0163] 1) After the UE receives e1, use the symmetric encryption algorithm and the shared key K to decrypt e1 to obtain d1;
[0164] 2) Extract m1 from d1 to obtain the random number R1 on the AAA server side, R1 = N1^m1;
[0165] 3) Extract the identity identification information IDa of the AAA locally, calculate m2’ = (R1^IDa); compare m2’ with m2 in d1. If they are the same, continue to execute downward; if they are different, send failure and the error code (failure||reason) to the AAA as a receipt, and the authentication process ends;
[0166] 4) Perform an exclusive OR operation on N2 and R2 to generate a message m3;
[0167] 5) Perform an exclusive OR operation on (N1 + 1), R1, IDa, IDu, and M to generate a message m4, where IDa is the identity identification information of the AAA, IDu is the identity identification information of the UE, and M is the user password of the UE;
[0168] 6) Use the symmetric encryption algorithm and the shared key K to encrypt m3 and m4 to obtain the ciphertext e2.
[0169] Step 4:
[0170] The UE sends the message (N1 + 1)||N2||e2 to the AAA.
[0171] Step 5:
[0172] 1) Check whether the sequence number value (N1 + 1) in the AAA authentication message is reasonable. If it is reasonable, proceed to the next step; if not, directly discard the data packet, send failure and the error code (failure||reason) to the UE as a receipt, and the authentication process ends.
[0173] 2) Use the symmetric encryption algorithm and the shared key K to decrypt e2 to obtain d2.
[0174] 3) Extract the local parameters R1, IDa, IDu, and M, calculate m4’ = ((N1 + 1)^R1^IDa^IDu^M), and compare m4’ with m4 in d2. If they are the same, proceed to the next step; if not, send failure and the error code (failure||reason) to the UE as a receipt, and the authentication process ends.
[0175] 4) Extract m3 from d2, obtain the UE-side random number R2, where R2 = N2^m3.
[0176] 5) Perform an exclusive OR operation on (N2 + 1), R2, IDu, and M to generate a message m5.
[0177] 6) Use the symmetric encryption algorithm and the shared key K to encrypt m5 to obtain the ciphertext e3.
[0178] Step 6:
[0179] AAA sends the success||(N2 + 1)||e3 message to the UE.
[0180] Step 7:
[0181] 1) The UE checks whether the sequence number value (N2 + 1) in the message is reasonable. If it is reasonable, proceed to the next step; if not, directly discard the data packet, send failure and the error code (failure||reason) to AAA as a receipt, and the authentication process ends.
[0182] 2) Extract the local parameters R2, IDu, and M, and calculate m5’ = ((N2 + 1)^R2^IDu^M);
[0183] 3) Use the symmetric encryption algorithm and the shared key K to encrypt m5’ to obtain e3’; compare e3’ with e3. If they are the same, the verification is successful; if not, send failure and the error code (failure||reason) to AAA as a receipt, and the authentication process ends.
[0184] Step 8:
[0185] The UE sends a success message to AAA.
[0186] The entire authentication process is completed.
[0187] The authentication in this embodiment realizes the two-way authentication process between the UE and the AAA through 8 steps and 4 handshakes. During the entire authentication process, except for the exclusive OR operation, the protocol only uses the symmetric encryption and decryption algorithm 6 times (including 4 encryption calls and 2 decryption calls).
[0188] In some embodiments, the symmetric encryption algorithm can adopt the domestic commercial cipher SM4.
[0189] During the two-way authentication process between both parties, IDa is the identity identification information of the AAA server, IDu is the identity identification information of the UE device, M is the user password of the UE. These information are all proof information co-existing in their respective locals of both the UE and the AAA, as well as the random numbers R1 and R2 generated by both parties, which are the multiple factors used to implement multi-factor authentication. If some or all of the proof information does not exist, such as IDa, IDu, M being partially or entirely 0, this situation only verifies the random numbers R1 and R2 of both parties, and it is also possible to use R1 and R2 as the identity identification information of both parties, which does not affect the realization of the two-way authentication of this protocol.
[0190] The data transmitted during the handshake process are all encapsulated in the EAP format.
[0191] The secondary authentication process of this embodiment has characteristics such as lightweight, fast authentication, higher efficiency, higher security, etc., and has better comprehensive performance. It can achieve two-way authentication, hide the identity information of both authentication parties, implement multi-authentication, protect information, and has confidentiality, forward security, and true randomness of the key. It can resist attack means such as man-in-the-middle attack, forged identity attack, replay attack, etc., and also has the function of key negotiation.
[0192] Embodiment Three
[0193] A quantum-security-based fast secondary authentication system, characterized in that: it includes a server side and a user side, wherein:
[0194] The server side is used to generate a first message based on the locally generated random number and serial number, and generate a second message based on the generated random number and identity identification information; encrypt the first message and the second message to obtain a first ciphertext, and send a message containing the first ciphertext and the serial number;
[0195] Receive a message containing the updated local serial number, the client serial number, and the second ciphertext feedback from the client; verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; decrypt the second ciphertext to obtain decryption information, extract the fourth message from it, extract the local random number, identity information, the client's identity information, and the password, calculate the corresponding message, and compare whether the corresponding message is consistent with the fourth message. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; extract the third message from the decryption information, calculate the client random number, use the updated client serial number, the client random number, identity information, and the password to generate the fifth message through operation, encrypt it to generate the third ciphertext, and send a message containing authentication success information, the updated client serial number, and the third ciphertext; receive an authentication success message or an authentication error message;
[0196] The client is used to receive a message containing the first ciphertext and its serial number sent by the server; decrypt the first ciphertext, extract the first message from the decryption information, and calculate the server random number; extract the server's identity information, and calculate the message corresponding to the second message based on the random number and identity information; compare whether the corresponding message is consistent with the second message extracted from the decryption information. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; generate the third message through operation based on the locally generated random number and serial number; generate the fourth message through operation based on the updated server serial number, the server random number, identity information, the local identity information, and the password, encrypt the third message and the fourth message to obtain the second ciphertext, and send a message containing the updated server serial number, the local serial number, and the second ciphertext;
[0197] Verify whether the updated local serial number in the message containing authentication success information, the updated client serial number, and the third ciphertext is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; extract the local random number, identity information, and password, combine them with the updated local serial number, calculate the corresponding message, encrypt the corresponding message to obtain the corresponding ciphertext, compare the corresponding ciphertext with the third ciphertext. If they are consistent, the authentication is successful and an authentication success message is sent; otherwise, an authentication error message is sent and the authentication process ends.
[0198] Embodiment 4
[0199] This embodiment provides a computer-readable storage medium with a computer program stored thereon. When the program is executed by a processor, it implements the steps in Embodiment 1 or Embodiment 2.
[0200] Embodiment 5
[0201] This embodiment provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps in Embodiment 1 or Embodiment 2 are implemented.
[0202] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.
[0203] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A fast two-factor authentication method based on quantum security, characterized in that: It includes the following steps: Based on the locally generated random number and serial number, calculate and generate the first message, and based on the generated random number and identity information, calculate and generate the second message; Encrypt the first message and the second message to obtain the first ciphertext, and send the message containing the first ciphertext and the serial number; Receive the message containing the updated local serial number, the client serial number, and the second ciphertext feedback from the client; Verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; Decrypt the second ciphertext to obtain the decryption information, extract the local random number, identity information, the client's identity information, and the password, calculate the corresponding message, and compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; Extract the third message from the decryption information, calculate the client random number, and use the updated client serial number, the client random number, identity information, and the password to calculate and generate the fifth message, and encrypt it to generate the third ciphertext; Send the message containing the authentication success information, the updated client serial number, and the third ciphertext; Receive the authentication success message or the authentication error message; The locally generated random number is generated by a local quantum random number generator, and the client serial number is generated by the client; The local and the client have the same shared key; All the calculations are exclusive OR operations; In the encryption process, a symmetric encryption algorithm and the shared key are used for encryption; In the decryption process, a symmetric encryption algorithm and the shared key are used for decryption.
2. A fast two-factor authentication method based on quantum security according to claim 1, characterized in that: It further includes performing a hash process on the first message and the second message to obtain the first hash value.
3. A fast two-factor authentication method based on quantum security according to claim 2, characterized in that: The process of obtaining the first ciphertext is replaced by encrypting the first message and the first hash value.
4. A fast two-factor authentication method based on quantum security according to claim 1, characterized in that: It further includes performing a hash process on the fifth message to obtain the third hash value.
5. A fast two-factor authentication method based on quantum security according to claim 2, characterized in that: It further includes performing a hash process on the fifth message to obtain the third hash value.
6. A fast two-factor authentication method based on quantum security according to claim 4, characterized in that: The process of generating the third ciphertext is replaced by encrypting the third hash value.
7. A fast two-factor authentication method based on quantum security according to claim 2, characterized in that: In the hash process, a hashing function is used for the hash process.
8. A fast two-factor authentication method based on quantum security according to claim 4, characterized in that: In the hash process, a hashing function is used for the hash process.
9. A fast secondary identity authentication method based on quantum security as claimed in claim 1, characterized in that: when sending an authentication error message, an error code is also sent simultaneously, and the error code includes the authentication error message and the reason for the authentication error.
10. A fast secondary identity authentication method based on quantum security as claimed in claim 1, characterized in that: if part or all of the identity identification information and the password are zero, during the verification process, only the random numbers of both parties are verified.
11. A fast secondary identity authentication method based on quantum security as claimed in claim 1, characterized in that: if part or all of the identity identification information is zero, the local random number is used as the identity identification information of both parties themselves.
12. A fast secondary identity authentication method based on quantum security as claimed in claim 10, characterized in that: if part or all of the identity identification information is zero, the local random number is used as the identity identification information of both parties themselves.
13. A fast secondary identity authentication method based on quantum security as claimed in any one of claims 1-12, characterized in that: the transmitted information is encapsulated in the EAP format.
14. A fast secondary identity authentication method based on quantum security, characterized in that: includes the following steps: receiving a message sent by the server side containing the first ciphertext and its serial number; decrypting the first ciphertext, extracting the first message from the decrypted information, and calculating the server-side random number; extracting the identity identification information of the server side, and calculating the message corresponding to the second message based on the server-side random number and the identity identification information; comparing whether the corresponding message and the corresponding information in the decrypted information are consistent, if they are consistent, continue to execute, otherwise send an authentication error message and end the authentication process; generating a third message based on the locally generated random number and the serial number; generating a fourth message based on the updated server-side serial number, the server-side random number, the identity identification information, and the local identity identification information and password; encrypting the third message and the fourth message to obtain the second ciphertext; sending a message containing the updated server-side serial number, the local serial number, and the second ciphertext; receiving a message sent by the server side containing the authentication success information, the updated client-side serial number, and the third ciphertext; verifying whether the updated local serial number in the message is reasonable, if it is reasonable, continue to execute, otherwise send an authentication error message and end the authentication process; extracting the local random number, the identity identification information, and the password, combining them with the updated local serial number, calculating the corresponding message, encrypting the corresponding message to obtain the corresponding ciphertext, comparing the corresponding ciphertext and the third ciphertext, if they are consistent, the authentication is successful, and send the authentication success information, otherwise send an authentication error message and end the authentication process; the locally generated random number is generated by a local quantum random number generator, and the server-side serial number is generated by the server side; the server side and the local have the same shared key; the operations are all exclusive OR operations; in the encryption process, a symmetric encryption algorithm and the shared key are used for encryption; in the decryption process, a symmetric encryption algorithm and the shared key are used for decryption.
15. A fast secondary identity authentication method based on quantum security as described in claim 14, characterized in that: It further includes performing a hash process on the third message and the fourth message to obtain a second hash value.
16. A fast secondary identity authentication method based on quantum security as described in claim 15, characterized in that: The process of obtaining the second ciphertext is replaced by encrypting the third message and the second hash value.
17. A fast secondary identity authentication method based on quantum security as described in claim 15, characterized in that: A hash function is used for the hash process during the hash process.
18. A fast secondary identity authentication method based on quantum security as described in claim 16, characterized in that: A hash function is used for the hash process during the hash process.
19. A fast secondary identity authentication method based on quantum security as described in claim 14, characterized in that: When sending an authentication error message, an error code is also sent simultaneously, and the error code includes the authentication error message and the reason for the authentication error.
20. A fast secondary identity authentication method based on quantum security as described in claim 14, characterized in that: If part or all of the identity identification information and the password are zero, only the random numbers of both parties are verified during the verification process.
21. A fast secondary identity authentication method based on quantum security as described in claim 14, characterized in that: If part or all of the identity identification information is zero, the local random number is used as the identity identification information of both parties.
22. A fast secondary identity authentication method based on quantum security as described in claim 20, characterized in that: If part or all of the identity identification information is zero, the local random number is used as the identity identification information of both parties.
23. A fast secondary identity authentication method based on quantum security as described in any one of claims 14 - 22, characterized in that: The transmitted information is encapsulated in the EAP format.
24. A fast secondary identity authentication method based on quantum security, characterized in that: It includes the following steps: The server side generates a first message based on the locally generated random number and the serial number, and generates a second message based on the generated random number and the identity identification information; Encrypt the first message and the second message to obtain a first ciphertext, and send a message including the first ciphertext and the serial number; The user side receives the message sent by the server side including the first ciphertext and its serial number; Decrypt the first ciphertext, extract the first message from the decrypted information, and calculate the server side random number; Extract the identity identification information of the server side, calculate the message corresponding to the second message based on the server side random number and the identity identification information; compare whether the corresponding message and the corresponding information in the decrypted information are consistent. If they are consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; generate a third message based on the locally generated random number and the serial number. Based on the updated server - side serial number, the server - side random number, the identity identification information, as well as the local identity identification information and the password, calculate and generate the fourth message, encrypt the third message and the fourth message to obtain the second ciphertext, and send a message containing the updated server - side serial number, the local serial number and the second ciphertext; The server - side receives the message sent by the user - side and containing the updated local serial number, the user - side serial number and the second ciphertext; verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; Decrypt the second ciphertext to obtain the decryption information, extract the local random number, the identity identification information and the user - side identity identification information, the password, calculate the corresponding message, and compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute; otherwise, send an authentication error message and end the authentication process; Extract the third message from the decryption information, calculate to obtain the user - side random number, use the updated user - side serial number, the user - side random number, the identity identification information, and the password, calculate and generate the fifth message, encrypt it to generate the third ciphertext, and send a message containing the authentication success information, the updated user - side serial number and the third ciphertext; The user - side receives the message sent by the server - side and containing the authentication success information, the updated user - side serial number and the third ciphertext; verify whether the updated local serial number in the message is reasonable. If it is reasonable, continue to execute; otherwise, send an authentication error message and end the authentication process; extract the local random number, the identity identification information and the password, combine the updated local serial number, calculate the corresponding message, encrypt the corresponding message to obtain the corresponding ciphertext, compare the corresponding ciphertext and the third ciphertext. If they are consistent, the authentication is successful and send an authentication success message; otherwise, send an authentication error message and end the authentication process; The random number is generated by a quantum random number generator on the server - side or locally on the user - side; The server - side and the user - side have the same shared key; The operations are all exclusive - OR operations; In the encryption process, a symmetric encryption algorithm and the shared key are used for encryption; In the decryption process, a symmetric encryption algorithm and the shared key are used for decryption.
25. A fast two - factor identity authentication method based on quantum security as described in claim 24, characterized in that: When sending an authentication error message, an error code is also sent simultaneously, and the error code includes the authentication error message and the reason for the authentication error.
26. A fast two - factor identity authentication method based on quantum security as described in claim 24, characterized in that: If part or all of the identity identification information and the password are zero, during the verification process, only the random numbers of both parties are verified.
27. A fast two - factor identity authentication method based on quantum security as described in claim 24, characterized in that: If part or all of the identity identification information is zero, use the local random number as the identity identification information of both parties.
28. A fast two - factor identity authentication method based on quantum security as described in claim 26, characterized in that: If part or all of the identity identification information is zero, use the local random number as the identity identification information of both parties.
29. A fast secondary identity authentication method based on quantum security according to any one of claims 24-28, characterized in that: All the transmitted information is encapsulated in the EAP format.
30. A fast secondary identity authentication system based on quantum security, characterized in that: It includes a server side and a user side, where: The server side is used to calculate and generate a first message based on the locally generated random number and serial number, and calculate and generate a second message based on the generated random number and identity identification information; encrypt the first message and the second message to obtain a first ciphertext, and send a message containing the first ciphertext and the serial number; Receive the message containing the updated local serial number, the user side serial number and the second ciphertext fed back by the user side; verify whether the updated local serial number in the message is reasonable, if it is reasonable, continue to execute, otherwise send an authentication error message and end the authentication process; decrypt the second ciphertext to obtain the decryption information, extract the local random number, identity identification information, the user side's identity identification information and password, calculate the corresponding message, and compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute, otherwise send an authentication error message and end the authentication process; extract the third message from the decryption information, calculate the user side random number, and use the updated user side serial number, the user side random number, identity identification information, and password to calculate and generate a fifth message, encrypt it to generate a third ciphertext, and send a message containing the authentication success information, the updated user side serial number and the third ciphertext; receive the authentication success message or the authentication error message; The user side is used to receive the message containing the first ciphertext and its serial number sent by the server side; decrypt the first ciphertext, extract the first message from the decryption information, and calculate the server side random number; extract the server side's identity identification information, and calculate the message corresponding to the second message based on the server side random number and identity identification information; compare whether the corresponding information in the corresponding message and the decryption information is consistent. If it is consistent, continue to execute, otherwise send an authentication error message and end the authentication process; calculate and generate a third message based on the locally generated random number and serial number; calculate and generate a fourth message based on the updated server side serial number, the server side random number, identity identification information, and the local identity identification information and password, perform an encryption process on the third message and the fourth message to obtain a second ciphertext, and send a message containing the updated server side serial number, the local serial number and the second ciphertext; Verify whether the updated local serial number in the message containing the authentication success information, the updated serial number of the client, and the third ciphertext is reasonable. If it is reasonable, continue the execution; otherwise, send an authentication error message and end the authentication process. Extract the local random number, identity information, and password, combine them with the updated local serial number, calculate the corresponding message, encrypt the corresponding message to obtain the corresponding ciphertext, compare the corresponding ciphertext with the third ciphertext. If they are the same, the authentication is successful and an authentication success message is sent; otherwise, an authentication error message is sent and the authentication process ends. The random number is generated by a quantum random number generator on the server side or locally on the client side. The server side and the client side have the same shared key. All the operations are exclusive OR operations. In the encryption process, a symmetric encryption algorithm and the shared key are used for encryption. In the decryption process, a symmetric encryption algorithm and the shared key are used for decryption.
31. A quantum-security-based fast two-factor authentication system as claimed in claim 30, characterized in that: When sending an authentication error message, an error code is also sent simultaneously. The error code includes the authentication error message and the reason for the authentication error.
32. A quantum-security-based fast two-factor authentication system as claimed in claim 30, characterized in that: If part or all of the identity information and the password are zero, only the random numbers of both parties are verified during the verification process.
33. A quantum-security-based fast two-factor authentication system as claimed in claim 30, characterized in that: If part or all of the identity information is zero, the local random number is used as the identity information of both parties.
34. A quantum-security-based fast two-factor authentication system as claimed in any one of claims 30 - 33, characterized in that: The transmitted information is encapsulated in the EAP format.
35. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the program is executed by a processor, the steps in the method as claimed in any one of claims 1 - 23 are implemented.
36. A computer device, characterized in that: It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps in the method as claimed in any one of claims 1 - 23 are implemented.
Citation Information
Patent Citations
Quantum secret communication identity authentication system and method based on secret sharing
CN111416715A
Method for realizing three-factor anonymous identity authentication based on SM2 algorithm
CN113486324A