A Digital Currency Anti-Quantum Computing Transaction Method and System with the Receiver Offline
Through the key management server and certificate issuance agency to issue quantum-resistant computing devices and certificates to the user side and commercial bank systems. Combined with the key management method of ID cryptography, the problems of high storage costs of key fuses and high system switching costs in the prior art are solved, and low-cost and high-security quantum-resistant computing digital currency communication is realized.
Patent Information
- Application Number
- CN202011203339.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-02
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2040-11-02
AI Technical Summary
In the prior art, the client needs to configure a quantum key fob that stores the public keys of all members, which increases the storage cost and operational workload of the key fob, and the user-side key management is complex, and at the same time, it changes the overall process and data structure of traditional CA and digital certificate-based digital signature systems, resulting in excessive switching costs.
A key management server is used to issue anti-quantum computing devices to the user side and the commercial bank's digital currency system, and the public and private keys are calculated through a hash function, and stored in the anti-quantum computing device. A certificate authority is used to issue root certificates and certificates to the user side and the commercial bank system to realize offline digital currency transactions on the receiver. A key management method based on ID cryptography is used to calculate symmetric keys in real time.
The digital currency communication system that is resistant to quantum computing is realized, which reduces the cost of symmetric key management and storage, maintains the overall process and data structure of traditional CA and digital signature systems, improves security and communication reliability, and reduces the cost of system improvement.
Smart Images

Figure CN114529272B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of digital certificates, and in particular to a quantum computing-resistant digital currency transaction method and system with an offline recipient. Background Art
[0002] The core elements of the digital currency D-RMB system of the People's Bank of China are one kind of currency, two types of libraries, and three centers. One kind of currency, namely "D-RMB" (DC / EP), abbreviated as D-currency, specifically refers to a string of encrypted digital strings representing specific amounts signed by the central bank. Two types of libraries: the issuance library of D-RMB and the bank library (central bank digital currency database, commercial bank digital currency database). Digital currency in the issuance library is manifested as the central bank's digital currency fund; digital currency in the bank library is manifested as the commercial bank's inventory digital cash. Three centers: one is the registration center (recording the whole process of currency generation, circulation, checking, and extinction); the other two are certification centers, namely the CA certification center (based on the PKI system, centrally managing institutional and user certificates, such as CFCA) and the IBC certification center [i.e., the certification center established based on identity-based cryptography (Identity-Based Cryptograph)]. Two tables can be designed in the registration center, one is the digital currency ownership registration form, recording the ownership of digital currency, and the other is the transaction record form.
[0003] The D-RMB system is a hierarchical system, jointly built by the central bank and each commercial bank. The central bank digital currency system is a computer system operated and maintained by the central bank or an institution designated by the central bank to process information about digital currency, and its main functions include being responsible for the issuance and verification monitoring of digital currency. The commercial bank digital currency system is a computer system operated and maintained by a commercial bank or an institution designated by the commercial bank to process information about digital currency, and it performs various functions related to currency of existing banks, that is, bank functions, mainly including after applying for digital currency from the central bank, being responsible for directly facing the society and meeting various requirements for providing digital currency circulation services.
[0004] To enable a digital signature system to resist quantum computing, an anti-quantum computing digital signature system has been proposed in the industry. For example, Patent CN109861813A proposes an anti-quantum computing HTTPS communication method and system based on an asymmetric key pool, and specifically discloses a communication method. The participants in this method include a server, a certificate authority, and a client. The client is configured with a key card, and the asymmetric key pool is stored in the key card. The anti-quantum computing HTTPS communication method includes the following steps: The server obtains a digital certificate issued by the certificate authority and sends the digital certificate to the client. The public key pointer random number of the server is recorded in the digital certificate. The client obtains a root digital certificate issued by the certificate authority that matches the digital certificate, verifies the digital certificate sent by the server based on the root digital certificate, and obtains the server public key from the asymmetric key pool according to the public key pointer random number of the server recorded in the verified digital certificate. Encrypt the randomly generated shared key with the server public key and send the encryption result to the server for key negotiation. Conduct HTTPS communication with the server using the shared key.
[0005] Although the solution proposed in Patent CN109861813A can achieve anti-quantum computing based on quantum secure communication, it has the following defects:
[0006] 1. In the technical solution proposed in Patent CN109861813A, the client needs to be configured with a quantum key card that stores the public keys of all members, which increases the storage cost and operation workload of the client key card, and the key management work of the user side is relatively complex;
[0007] 2. In the technical solution proposed in Patent CN109861813A, it changes the overall process and data structure of the traditional CA and the digital signature system based on digital certificates. For example, it causes changes in the format and usage method of digital certificates, resulting in too high costs for the CA and user application systems to switch to the anti-quantum computing solution. Summary of the Invention
[0008] Aiming at the problems in the related technologies, the present invention proposes a method and system for anti-quantum computing transactions of digital currency with the recipient offline to overcome the above-mentioned technical problems existing in the existing related technologies.
[0009] For this reason, the specific technical solution adopted by the present invention is as follows:
[0010] According to one aspect of the present invention, there is provided a method for anti-quantum computing transactions of digital currency with the recipient offline, and the method includes the following steps:
[0011] S1. Use the key management server to issue anti-quantum computing devices to the user side and the commercial bank digital currency system respectively;
[0012] When the key management server issues the system public and private keys to the client, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the key management server, and stores the system public key in the quantum-resistant computing device corresponding to the client;
[0013] When the key management server issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the key management server, and stores the system public key in the quantum-resistant computing device of the commercial bank digital currency system;
[0014] When the key management server issues the public and private keys to the client, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the client and the public and private keys in the quantum-resistant device of the client;
[0015] When the key management server issues the public and private keys to the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant device of the commercial bank digital currency system;
[0016] S2. Use the certificate authority to issue root certificates to the client and the commercial bank digital currency system respectively according to the root certificate issuance method, and store them in the corresponding quantum-resistant computing devices;
[0017] S3. Use the certificate authority to issue certificates to the client and the commercial bank digital currency system respectively through the certificate issuance method, and store them in the corresponding quantum-resistant computing devices;
[0018] S4. Use the currency transaction method to realize the off-line digital currency transaction of the receiving party client;
[0019] Among them, the specific steps for the S4 to use the currency transaction method to realize the off-line digital currency transaction of the receiving party client are as follows:
[0020] S41. The sending party client negotiates with the sending party commercial bank to obtain the session key;
[0021] S42. The sending party client signs to obtain the signed transaction, and sends the signed transaction to the sending party commercial bank;
[0022] S43. The sending commercial bank receives the transaction information and verifies the validity of the sending client certificate through the certificate authority;
[0023] S44. The certificate authority receives the message to be verified and verifies the certificate of the sending client;
[0024] S45. The sending commercial bank receives the verification result and verifies the signed transaction. After passing the verification, the sending commercial bank encrypts the transaction information and forwards it to the central bank;
[0025] S46. The central bank receives the encrypted transaction information and verifies it. After passing the verification, the central bank sends the transaction result to the sending commercial bank and the receiving commercial bank respectively;
[0026] S47. The receiving commercial bank signs and encrypts the transaction result and sends it to the central bank. After receiving the message, the central bank decrypts it and encrypts it and sends it to the sending commercial bank;
[0027] S48. The sending commercial bank receives the message sent by the central bank and notifies the sending client of the transaction result and the signature of the receiving commercial bank;
[0028] S49. The sending client sends the transaction result and the signature of the receiving commercial bank to the receiving client;
[0029] S410. The receiving client receives the transaction result and the signature of the receiving commercial bank, verifies the signature of the receiving commercial bank. After passing the verification, it verifies the transaction result again. After passing the verification, it stores the received currency.
[0030] Further, the S2 uses the certificate authority to issue root certificates for the client and the commercial bank digital currency system respectively according to the root certificate issuance method, and stores them in the corresponding quantum-resistant computing devices, which specifically includes the following steps:
[0031] S21. Use the certificate authority to issue a root certificate for the client and store it in the quantum-resistant computing device of the client;
[0032] S22. Use the certificate authority to issue a root certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
[0033] Further, the step of using the certificate authority to issue a root certificate for the client in S21 includes the following steps:
[0034] S211. The client sends the identity information to the certificate authority.
[0035] S212. The certificate authority returns the root certificate of the certificate authority to the client.
[0036] S213. The client receives the root certificate of the certificate authority.
[0037] Further, the step of using the certificate authority to issue a root certificate for the commercial bank digital currency system in S22 includes the following steps:
[0038] S221. The commercial bank digital currency system sends the identity information to the certificate authority.
[0039] S222. The certificate authority returns the root certificate of the certificate authority to the commercial bank digital currency system.
[0040] S223. The commercial bank digital currency system receives the root certificate of the certificate authority.
[0041] Further, the step of using the certificate authority to issue certificates for the client and the commercial bank digital currency system respectively through the certificate issuance method in S3 and storing them in the corresponding quantum-resistant computing devices specifically includes the following steps:
[0042] S31. Use the certificate authority to issue a certificate for the client and store it in the quantum-resistant computing device of the client.
[0043] S32. Use the certificate authority to issue a certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
[0044] Further, the step of using the certificate authority to issue a certificate for the client in S31 includes the following steps:
[0045] S311. The client sends the identity information and the certificate public key to the certificate authority.
[0046] S312. The certificate authority returns a certificate to the client.
[0047] S313. The client receives the certificate.
[0048] Further, the step of using the certificate authority to issue a certificate for the commercial bank digital currency system in S32 includes the following steps:
[0049] S321. The commercial bank digital currency system sends the identity information and the certificate public key to the certificate issuing authority;
[0050] S322. The certificate issuing authority returns a certificate to the commercial bank digital currency system;
[0051] S323. The commercial bank digital currency system receives the certificate.
[0052] Further, in S41, the sender client and the sender commercial bank negotiate to obtain a session key, which specifically includes the following steps:
[0053] S411. The sender client sends a signed session key to the commercial bank;
[0054] S412. The sender commercial bank verifies the validity of the sender client certificate with the certificate issuing authority;
[0055] S413. The certificate issuing authority verifies the validity of the sender client certificate and sends the verification result to the sender commercial bank;
[0056] S414. The sender commercial bank sends the verification result to the sender client.
[0057] According to another aspect of the present invention, a quantum-resistant digital currency system is provided. The system includes a central bank digital currency system, a commercial bank digital currency system, users, and an authentication system. A quantum key distribution network is established between the central bank digital currency system and the commercial bank digital currency system. The central bank digital currency system and the commercial bank digital currency system perform identity authentication and secure communication. The commercial bank digital currency system and the users perform identity authentication and secure communication;
[0058] Among them, the central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of the digital currency;
[0059] The commercial bank digital currency system is used to perform banking functions for digital currency;
[0060] The users are the entities using the digital currency;
[0061] The authentication system is used to authenticate the interaction between the commercial bank digital currency system and the user terminal device of the digital currency, and is also used to authenticate the interaction between the central bank digital currency system and the commercial bank digital currency system.
[0062] Furthermore, it also includes a certificate issuing authority, in which a quantum-resistant computing device is provided, and a key management server based on ID cryptography is deployed in the quantum-resistant computing device, the central bank digital currency system includes a central bank, the commercial bank digital currency system includes a sender commercial bank and a receiver commercial bank, the users include a sender user terminal and a receiver user terminal, and short-range communication is performed between the sender user terminal and the receiver user terminal.
[0063] The beneficial effects of the present invention are:
[0064] 1) The present invention can realize a digital currency communication system based on digital certificate receiver offline and resistant to quantum computing;
[0065] 2) The symmetric keys used in the present invention are all generated based on real-time calculations of ID cryptography, and there is no need to store the symmetric keys in advance, which is low-cost for users and does not involve symmetric key management and storage issues;
[0066] 3) The present invention does not change the overall process and data structure of the traditional CA and the digital signature system based on digital certificates, so the cost of switching the CA and user application system to the quantum computing-resistant solution is not high;
[0067] 4) In the present invention, the key issuing server based on ID cryptography has different system public and private keys for each different user. Even if the system public key of a user is lost and the system private key is cracked by a quantum computer, it will not endanger the system public and private keys of CA and other users.
[0068] 5) The communication mode of the present invention meets the requirements for security and cost in two different situations, namely: for the communication between the central bank and commercial banks with extremely high confidentiality requirements and relatively small scope of impact of scheme changes, a more costly and more secure quantum secure communication is adopted to achieve communication with higher security; for the communication between commercial banks and users with not extremely high confidentiality requirements and relatively large scope of impact of scheme changes, anti-quantum computing communication based on digital certificates is adopted to achieve communication with higher security and cost. Therefore, the present invention improves the existing digital currency communication system into an anti-quantum computing digital currency communication system, and takes into account the cost of system improvement. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] Figure 1 This is a flow chart of a digital currency quantum computing resistant transaction method in which the receiver is offline according to an embodiment of the present invention;
[0070] Figure 2 A flowchart schematic diagram of a transaction method in a digital currency quantum computing-resistant transaction method in which the receiver is offline according to an embodiment of the present invention;
[0071] Figure 3 This is a flowchart showing the negotiation of keys between the user side and the commercial bank in a quantum-resistant digital currency transaction method with an offline recipient in an embodiment of the present invention;
[0072] Figure 4 This is a structural block diagram of a quantum-resistant digital currency system in an embodiment of the present invention. Detailed implementation manners
[0073] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. It should be understood, however, that the present invention can be implemented in various forms. Some exemplary and non-limiting embodiments presented in the accompanying drawings and described hereinafter are not intended to limit the present invention to the specific embodiments described.
[0074] It should be understood that, where technically feasible, the technical features recited for different embodiments above can be combined with each other to form additional embodiments within the scope of the present invention. In addition, the specific examples and embodiments described herein are non-limiting, and corresponding modifications can be made to the structures, steps, and sequences set forth above without departing from the scope of protection of the present invention.
[0075] According to an embodiment of the present invention, a quantum-resistant digital currency transaction method and system with an offline recipient are provided.
[0076] The present invention will now be further described in conjunction with the accompanying drawings and specific implementation manners. As Figures 1 - 3 shown, according to an embodiment of the present invention, a quantum-resistant digital currency transaction method with an offline recipient is provided, and the method includes the following steps:
[0077] S1. Use the key management server KMS to issue quantum-resistant computing devices to the user side (including the sender user side A and the recipient user side B) and the commercial bank digital currency system (including the sender commercial bank A0 and the recipient commercial bank B0) respectively;
[0078] Among them, when the key management server KMS issues the system public and private keys to the user side, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the key management server KMS, and stores the system public key in the quantum-resistant computing device of the corresponding user side;
[0079] Specifically, the system public and private keys of the key management server KMS are different for each different user. For the user side A, KMS will generate a unique code as the ID A , and the system private key of A is SK MSA, the system private key can be a true random number or obtained through calculation, such as SK MSA = MAC(ID A ,SK MS )(MAC(m,k) calculates the message authentication code for message m using key k), and the system public key of A is PK MSA = SK MSA *P; For client B, the KMS generates a unique code as ID B , the system private key of B is SK MSB , the system private key can be a true random number or obtained through calculation, such as SK MSB = MAC(ID B ,SK MS ), and the system public key of B is PK MSB = SK MSB *P; The system private key is stored in the quantum-resistant computing device of the KMS, and the system public key is stored in the quantum-resistant computing device of the corresponding client, that is, PK MSA is stored in T A , PK MSB is stored in T B ;
[0080] When the key management server KMS issues system public and private keys for the commercial bank digital currency system, it calculates the corresponding system private key by calculating the message authentication code, then calculates the system public key based on this system private key, and stores the system private key in the quantum-resistant computing device of the key management server KMS, and stores the system public key in the quantum-resistant computing device of the commercial bank digital currency system;
[0081] When the key management server KMS issues public and private keys for the client, it calls the hash function to calculate the public key, and then calculates the corresponding private key based on this public key, and stores the ID of the client and the public and private keys in the quantum-resistant device of the client;
[0082] Specifically, taking client A as an example, when the KMS issues public and private keys for client A, it calls the hash function H1 to calculate the public key PK A = H1(ID A ), and then calculates the private key SK A = SK A *PK MSA , and stores A's ID and public and private keys, that is, ID A , PK A , SK A , SK A in A's quantum-resistant computing device T A ;
[0083] When the Key Management Server (KMS) issues public and private keys for the commercial bank digital currency system, it calls a hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant device of the commercial bank digital currency system;
[0084] Specifically, taking Commercial Bank A0 as an example, when KMS issues public and private keys for Commercial Bank A0, it calls the hash function H1 to calculate the public key Then, based on the public key calculate the private key Store the ID of A0 and the public and private keys, that is in the quantum-resistant computing device of A0
[0085] S2. The CA issues root certificates for the client and the commercial bank digital currency system (using the root certificate issuance method, the certificate authority issues root certificates for the client and the commercial bank digital currency system respectively, and stores them in the corresponding quantum-resistant computing devices);
[0086] Among them, S2 includes the CA institution issuing root certificates for all clients and commercial bank digital currency systems. Here, taking client A as an example, the issuance process is described in detail:
[0087] (1) A → CA (The client A sends its identity information to the certificate authority CA);
[0088] The client A calculates PK CA based on its ID CA = H1(ID CA ), and further calculates the symmetric key K A-CA = e(SK A , PK CA ). Obtain the timestamp T1, and encrypt T1 using K A-CA to get the final key K1 = MAC(T1, K A-CA ).
[0089] Encrypt the identity information AINFO of A using K1 to get {AINFO}K1, calculate the message authentication code for T1 and AINFO using K1 to get MAC(T1||AINFO, K1), and send it to CA together with ID A and ID CA and T1. The message sent can be expressed as ID A ||ID CA ||T1||{AINFO}K1||MAC(T1||AINFO, K1).
[0090] (2) CA → A (The Certificate Authority CA returns the Certificate Authority root certificate to the client A);
[0091] The KMS in CA calculates the system private key of A as SK MSA = MAC(ID A , SK MS ), and according to PK CA = H1(ID CA ) to obtain SK CAA = SK MSA * PK CA . Further obtain the symmetric key K between CA and A CA-A = e(SK CAA , PK A ). According to ID cryptography, it can be obtained that: K A-CA = e(SK A , PK CA ) = e(SK MSA * PK A , PK CA ) = e(PK A , SK MSA * PK CA ) = e(PK A , SK CAA ) = e(SK CAA , PK A ) = K CA-A . Use K CA-A to calculate the message authentication code for T1 to obtain K'1 = MAC(T1, K CA-A ). Use K'1 to decrypt and verify the message authentication code to obtain the identity information AINFO of A.
[0092] CA retrieves the CA root certificate CERT CA , obtains the timestamp T2, and uses K CA-A to encrypt and calculate T2 to obtain the final key K2 = MAC(T2, K CA-A ). Use K2 to encrypt CERT CA to obtain {CERT CA}K2, and use K2 to calculate the message authentication code for T2 and CERT CA to obtain MAC(T2 || CERT CA , K2), and send it to A together with ID CA , ID A and T2. The sent message can be expressed as ID CA || ID A || T2 || {CERT CA}K2 || MAC(T2 || CERT CA , K2).
[0093] (3) Client A receives the CA root certificate (the client A receives the root certificate of the certificate authority CA).
[0094] After A receives the message, it uses K A-CA to encrypt and calculate T2 to obtain the final key K'2 = MAC(T2, K A-CA ). Use K'2 to decrypt and verify the message authentication code to obtain the CA root certificate CERT CA . After A verifies it, it stores it in the local quantum-resistant computing device T A .
[0095] S3. CA issues certificates for the client and the commercial bank digital currency system (using the certificate issuance method, the certificate authority issues certificates for the client and the commercial bank digital currency system respectively, and stores them in the corresponding quantum-resistant computing devices).
[0096] Among them, S3 includes the CA institution issuing certificates for all clients and the commercial bank digital currency system. Here, the issuance process is detailed taking client A as an example:
[0097] (1) A → CA (the client A sends the identity information and the certificate public key to the certificate authority CA).
[0098] The client A calculates the symmetric key K A-CA = e(SK A , PK CA ). Obtain the timestamp T3, use K A-CA to encrypt and calculate T3 to obtain the final key K3 = MAC(T3, K A-CA ).
[0099] A generates a certificate public-private key pair PK CERTA , SK CERTA , which can be based on various asymmetric cryptographic algorithms such as RSA, ECC, discrete logarithm, and ID cryptography. Use K3 to encrypt A's identity information AINFO and A's certificate public key PK CERTA to obtain {AINFO||PK CERTA}K3, use K3 to calculate the message authentication code for T3, AINFO, and PK CERTA to obtain MAC(T3||AINFO||PK A , K3), and send it to CA together with ID A , ID CA and T3. The sent message can be expressed as ID A ||ID CA ||T3||{AINFO||PK CERTA}K3||MAC(T3||AINFO||PK CERTA ,K3).
[0100] (2) CA→A (The certificate authority CA returns a certificate to the client A);
[0101] The KMS in CA calculates the system private key of A as SK MSA = MAC(ID A ,SK MS ), and according to PK CA = H1(ID CA ) to obtain SK CAA = SK MSA * PK CA . Further obtain the symmetric key K CA-A = e(SK CAA , PK A ). According to ID cryptography, it can be obtained that: K A-CA = e(SK A , PK CA ) = e(SK MSA * PK A , PK CA ) = e(PK A , SK MSA * PK CA ) = e(PK A , SK CAA ) = e(SK CAA , PK A ) = K CA-A . Use K CA-A to encrypt and calculate T3 to obtain the final key K'3 = MAC(T3, K CA-A ). Use K'3 to decrypt and verify the message authentication code to obtain the identity information AINFO of A and the PK A used to calculate CERT CERTA .
[0102] CA makes the certificate CERT A of A. Then CA obtains the timestamp T4, and uses K CA-A to encrypt and calculate T4 to obtain the final key K4 = MAC(T4, K CA-A ). Use K4 to encrypt CERT A to obtain {CERT A}K4, and use K4 to calculate the message authentication code for T4 and CERT A to obtain MAC(T4||CERT A , K4), together with ID CA , ID ASend it to A together with T4, and the sent message can be expressed as ID CA ||ID A ||T4||{CERT A}K4||MAC(T4||CERT A ,K4).
[0103] (3) A receives the CA certificate (the client A receives the certificate of the certificate authority CA);
[0104] After A receives the message, use K A-CA to encrypt and calculate T4 to get K'4 = MAC(T4, K A-CA ). Use K'4 to decrypt and verify the message authentication code to obtain its own certificate CERT A , after A verifies it, store it in the local quantum-resistant computing device T A inside.
[0105] In addition, for the client B in this embodiment, the client B generates a certificate public-private key pair PK CERTB , SK CERTB , and also performs the same steps as above with the CA to obtain its own certificate CERT B . After B verifies CERT B , store it in the local quantum-resistant computing device T B inside.
[0106] Commercial bank B0 generates a certificate public-private key pair and also performs the same steps as above with the CA to obtain its own certificate B0 pairs After verification, store it in the local quantum-resistant computing device inside.
[0107] S4, off-chain digital currency transaction of the receiving party A (realize the off-chain digital currency transaction of the receiving party client A using the currency transaction method);
[0108] Among them, the S4 includes the following steps:
[0109] S41. B negotiates a session key with the commercial bank (the sending party client negotiates with the sending party commercial bank to obtain the session key);
[0110] Specifically, the S41 specifically includes the following steps:
[0111] S411. B sends a signed session key to the commercial bank (the sending party client sends a signed session key to the commercial bank);
[0112] B generates a session key KSB, obtains a timestamp T5, and calculates the symmetric key K with the CAB-CA = e(SK B , PK CA ), and then use K B-CA to encrypt and calculate T5 to obtain K5 = MAC(T5, K B-CA ). Use the certificate private key SK CERTB of B to calculate the signature for T5 and KSB to obtain SIG B = SIGN(T5||KSB, SK CERTB ). Use K5 to encrypt KSB||SIG B and CERT B respectively to obtain {KSB||SIG B}K5 and {CERT B}K5. Together with T5, they are used as MSG5, which can be expressed as MSG5 = T5||{KSB||SIG B}K5||{CERT B}K5. Use K5 to calculate the message authentication code for MSG5 to obtain MAC(MSG5, K5). B sends MSG5||MAC(MSG5, K5) to B0.
[0113] S412. The commercial bank seeks verification from the CA (the sending commercial bank verifies the validity of the sender client certificate from the certificate authority);
[0114] After receiving it, B0 confirms the validity of B's certificate with the CA. B0 calculates the symmetric key between it and the CA Obtain the timestamp T6, and use to encrypt and calculate T6 to obtain will ID CA , T6, ID B , T5, and {CERT B}K5 are combined to obtain Use K6 to calculate the message authentication code for MSG6 to obtain MAC(MSG6, K6). The message sent by B to the CA is MSG6||MAC(MSG6, K6).
[0115] S413. The CA returns the verification result (the certificate authority verifies the validity of the sender client certificate and sends the verification result to the sending commercial bank);
[0116] After receiving it, the KMS in the CA calculates the system private key of B0 as According to PK CA = H1(ID CA ) to calculate and obtain Furthermore, according to Obtain the symmetric key between CA and B0 According to ID cryptography, it can be obtained that: CA uses to encrypt and calculate T6 to obtain Use K′6 to verify the message authentication code to confirm that the message comes from B0.
[0117] The KMS in CA calculates the system private key of B as SK MSB = MAC(ID B , SK MS ), and calculate to obtain SK CAB = SK MSB * PK CA . Further, according to PK B = H1(ID B ), obtain the symmetric key K between CA and B CA-B = e(SK CAB , PK B ). According to ID cryptography, it can be obtained that: K B-CA = e(SK B , PK CA ) = e(SK MSB * PK B , PK CA ) = e(PK B , SK MSB * PK CA ) = e(PK B , SK CAB ) = e(SK CAB , PK B ) = K CA-B . CA uses K CA-B to encrypt and calculate T5 to obtain K′5 = MAC(T5, K CA-B ). Use K′5 to decrypt {CERT B}K5 to obtain CERT B . Judge the validity of CERT B and whether it is in the certificate revocation list, and record the judgment result as RET B .
[0118] CA obtains the timestamp T7, and uses to encrypt and calculate T7 to obtain K7 = MAC(T7, K CA-B ). Use K7 to encrypt RET B and K′5 to obtain {RET B ||K′5}K7, and combine ID CA , T7, and {RETB ||The combination of K′5 and K7 gives MSG7 = ID CA ||ID B0 ||T7||{RET B ||K′5 and K7. Use K7 to calculate the message authentication code for MSG7 to get MAC(MSG7, K7). The message sent by CA to B0 is MSG7||MAC(MSG7, K7).
[0119] S414. The commercial bank notifies B of the result (the sending commercial bank sends the verification result to the sending client);
[0120] After B0 receives the message from CA, use K B-CA to encrypt and calculate T7 to get K′7 = MAC(T7, K B-CA ). Use K′7 to decrypt {RET B ||K′5 and K7 to get RET B and K′5. If RET B is a failure, the negotiation of the key fails and the process ends; otherwise continue. Use K′5 to decrypt {CERT B}K5 and {KSB||SIG B}K5 in MSG5 to get CERT B 、SIG A and KSB. Use the PK CA in CERT CERTCA to verify B's certificate CERT B . After successful verification, use PK CERTB to verify SIG B . After successful verification, trust that KSB is the session key between B and itself.
[0121] B0 encrypts RET B using KSB to get {RET B}KSB and sends it to B. After B receives it, use KSB to decrypt to get RET B and trust that KSB is the session key between B and B0;
[0122] S42. B sends a signed transaction to B0 (the sending client signs to get a signed transaction and sends the signed transaction to the sending commercial bank);
[0123] Use the private key SK CERTB of B's certificate to calculate the signature for T and TX to get SIG′ B = SIGN(T||TX, SK CERTB ), where T is the signature time and TX is the message to be signed, i.e., the transaction, including transaction information such as sender information, recipient information, and digital currency. Send T, TX, CERTB and SIG' B are combined as MSG B and can be expressed as MSG B = T || TX || CERT B || SIG' B .
[0124] B uses the session key KSB between B and B0 to encrypt MSG B to obtain {MSG B}}KSB and sends it to the commercial bank B0 to which B belongs.
[0125] S43. B0 receives the signed transaction (the sending commercial bank receives the transaction information and verifies the validity of the sender's client certificate through the certificate authority);
[0126] After B0 receives {MSG B}}KSB, it uses KSB to decrypt and obtain MSG B , and then confirms the validity of B's certificate with CA. B0 obtains the timestamp T8 and uses to encrypt T8 and calculate to obtain will ID CA , T8, T, ID A and {CERT B}}K8 are combined to obtain Then use K8 to calculate the message authentication code for MSG8 to obtain MAC(MSG8, K8). The message sent by B0 to CA is MSG8 || MAC(MSG8, K8).
[0127] S44. CA verifies B's certificate (the certificate authority receives the message to be verified and verifies the certificate of the sender's client);
[0128] After CA receives the message, it uses to encrypt T8 and calculate to obtain Use K'8 to verify the message authentication code to confirm that the message comes from B0. Use K'8 to decrypt {CERT B}}K8 in MSG8 to obtain CERT B . Judge the validity of CERT B and whether it is in the certificate revocation list, and the judgment result is recorded as RET' B .
[0129] The KMS in CA calculates the system private key of A as SK MSA = MAC(ID A , SK MS ), and calculates to obtain SK CAA = SKMSA *PK CA . Further, based on PK A = H1(ID A ), the symmetric key K between CA and A is obtained CA-A = e(SK CAA , PK A ). CA uses K CA-A to encrypt and calculate T to obtain K T = MAC(T, K CA-A ).
[0130] CA obtains the timestamp T9 and uses to encrypt and calculate T9 to obtain uses K9 to encrypt RET′ B and K T to obtain {RET′ B || K T}K9, combines ID CA , T9, and {RET′ B || K T}K9 to obtain uses K9 to calculate the message authentication code for MSG9 to obtain MAC(MSG9, K9). The message sent by CA to B0 is MSG9 || MAC(MSG9, K9).
[0131] S45, B0 reports to the central bank (the sending commercial bank receives the verification result and verifies the signed transaction. After verification, the sending commercial bank encrypts the transaction information and forwards it to the central bank);
[0132] After B0 receives the message, it uses to encrypt and calculate T9 to obtain uses K′9 to decrypt {RET′ B || K T}K9 to obtain RET′ B and K T . If RET′ B is a failure, the transaction signature verification fails and the process ends; otherwise, continue. Use the PK in CERT CA to verify the certificate CERT of B CERTCA , after verification, use PK B to verify SIG′ CERTB , after verification, trust that TX is a transaction from B B .
[0133] B0 forwards the message MSG received in S42 B that is, T || TX || CERT B || SIG′B Encrypt with the QKD key K Q and forward it to the central bank.
[0134] S46. The central bank notifies the commercial bank (the central bank receives the encrypted transaction information and conducts verification. After the verification passes, the central bank sends the transaction results to the sending commercial bank and the receiving commercial bank respectively);
[0135] After receiving it, the central bank uses K Q to decrypt and obtain MSG B , and then verifies the transaction. Use the PK CA in CERT CERTCA to verify the certificate CERT of B B . After the verification passes, use PK CERTB to verify SIG′ B . After the verification passes, trust that TX is a transaction from B. The verification result is recorded as RET TX .
[0136] After the central bank records the change in the ownership of the digital currency after the successful transaction, it encrypts and sends T||TX||RET TX to the commercial banks A0 to which B0 and A belong through the QKD key. A0 and B0 decrypt and verify the message from the central bank, and record T||TX||RET TX .
[0137] S47. A0 sends a signature to the central bank, and the central bank forwards it to B0 (the receiving commercial bank signs and encrypts the transaction result and sends it to the central bank. After receiving the message, the central bank decrypts and encrypts it and sends it to the sending commercial bank);
[0138] A0 confirms that the recipient is a legitimate user of this bank according to the recipient information in TX. After confirmation, use its own certificate private key to calculate the signature for T||TX||RET TX to obtain and encrypt it with the QKD key K′ Q for and then send it to the central bank.
[0139] After the central bank receives it, it uses K′ Q to decrypt and obtain and encrypt it with K Q and forward it to B0.
[0140] S48. B0 notifies B of the result (the sending commercial bank receives the message sent by the central bank and notifies the transaction result and the signature of the receiving commercial bank to the sending client);
[0141] After B0 receives the central bank's message, it uses K Q to decrypt and obtain Then it uses K T to encrypt and obtain and sends it together with T||TX||RET TX to B.
[0142] S49. B notifies A of the result (the sending client sends the transaction result and the signature of the receiving commercial bank to the receiving client);
[0143] After B confirms RET TX , it confirms the end of the transaction. B sends to A.
[0144] S410. A confirms the result (the receiving client receives the transaction result and the signature of the receiving commercial bank, verifies the signature of the receiving commercial bank, and then verifies the transaction result after passing the verification. After passing the verification, it stores the received currency);
[0145] After A receives it, it calculates the symmetric key K with CA A-CA = e(SK A , PK CA ). According to ID cryptography, we can get: K CA-A = e(SK CAA , PK A ) = e(SK MSA *PK CA , PK A ) = e(SK MSA *PK A , PK CA ) = e(SK A , PK CA ) = K A-CA . It uses K A-CA to encrypt T and calculate K' T = MAC(T, K A-CA ), and then uses K' T to decrypt to obtain
[0146] A uses the PK CA in CERT CERTCA to verify After passing the verification, it uses to verify After passing the verification and confirming RET TX , if successful, it stores the received digital currency.
[0147] To facilitate the understanding of the above technical solution of the present invention, the following will provide a detailed description of the method for establishing a set of system parameters based on ID cryptography in the actual process of the present invention.
[0148] When the KMS issues public and private keys to a certain member, it is first necessary to establish a set of system parameters based on ID cryptography. The steps are as follows:
[0149] (1) G1 and G2 are groups of order q of the GDH (Diffie–Hellman group), q is a large prime number, G1 is an additive cyclic group composed of points on an elliptic curve, and P is a generator of the group G1; G2 is a multiplicative cyclic group; the bilinear mapping e: G1×G1→G2.
[0150] (2) Randomly take SK MS ∈Z p * as the system private key of the CA. SK MS is only stored in the quantum-resistant computing device of the KMS. Calculate the system public key PK MS = SK MS *P. PK MS is stored in the quantum-resistant computing device T CA of the CA. The system public and private keys of the KMS for each different user are different. For the user side A, the KMS will generate a unique code as ID A , the system private key of A is SK MSA , and the system private key can be a true random number or obtained by calculation. For example, SK MSA = MAC(ID A , SK MS ) (MAC(m,k) is to calculate the message authentication code for the message m using the key k). The system public key of A is PK MSA = SK MSA *P; for the user side B, the KMS will generate a unique code as ID B , the system private key of B is SK MSB , and the system private key can be a true random number or obtained by calculation. For example, SK MSB = MAC(ID B , SK MS ), and the system public key of B is PK MSB = SK MSB *P; the system private key is stored in the quantum-resistant computing device of the KMS, and the system public key is stored in the quantum-resistant computing device of the corresponding user side, that is, PK MSA is stored in T A , and PK MSB is stored in T BSimilarly for commercial banks A0 and B0. If the system private key is a true random number, the KMS stores the system private key and its corresponding client ID in the database and directly retrieves them when needed; if the system private key is obtained by calculation, the KMS calculates and generates it in real time when needed without storage; the following embodiments take the system private key obtained by calculation as an example.
[0151] (3) Select hash functions H1: {0, 1} * →G1, H2: G2 → {0, 1} * .
[0152] (4) The system parameters are {q, G1, G2, e, n, P, H1, H2}.
[0153] When the KMS issues public and private keys for the CA, it generates a unique code as the ID CA , calls the hash function H1 to calculate the public key PK CA = H1(ID CA ), and then calculates the private key SK CA = SK CA * PK MS , and stores the ID of the CA and its public and private keys, namely ID CA , PK CA , SK CA in the quantum-resistant computing device T CA of the CA. T CA also stores the CA root certificate CERT CA , and CERT CA includes the version number, serial number, validity period of the certificate, and the certificate public key PK CA of the CA and the certificate signature, where the certificate public key and the certificate signature can be based on various asymmetric cryptographic algorithms such as RSA, ECC, discrete logarithm, ID cryptography, etc. CERTCA
[0154] When the KMS issues public and private keys for the client A, it calls the hash function H1 to calculate the public key PK A = H1(ID A ), and then calculates the private key SK A = SK A * PK MSA , and stores the ID of A and its public and private keys, namely ID A , PK A , SK A in the quantum-resistant computing device T A of A. A
[0155] When the KMS issues public and private keys for the client A0, it calls the hash function H1 to calculate the public key and then based on the public key Calculated private key The ID and public-private key of A0, namely Are stored in the quantum-resistant computing device of A0 Similarly, KMS issues public-private keys for B and B0.
[0156] According to another aspect of the present invention, a quantum-resistant computing digital currency system is provided. Taking the operation example of central bank digital currency as an example, as Figure 4 shown, the basic structure of the digital currency system mainly includes a central bank digital currency system, a commercial bank digital currency system (which can be multiple commercial bank digital currency systems in practice), and users, as well as a system for authenticating among the three. A QKD network is established between the central bank and each commercial bank. The central bank and each commercial bank conduct identity authentication and secure communication, and each commercial bank and its respective users conduct identity authentication and secure communication.
[0157] Among them, the central bank digital currency system is used to generate and issue digital currency, and conduct ownership registration of digital currency; the commercial bank digital currency system is used to perform banking functions for digital currency; users are the main body of digital currency use; the authentication system includes providing authentication for the interaction between the commercial bank digital currency system and the terminal devices used by the users of digital currency, and providing authentication for the interaction between the central bank digital currency system and the commercial bank digital currency system. The central bank digital currency system and the commercial bank digital currency system conduct identity authentication through QKD (Quantum Key Distribution) communication: both the central bank digital currency system and the commercial bank digital currency system have a QKD device, and the two devices conduct quantum secure communication through a QKD line and negotiate to obtain a session key.
[0158] In addition, the users include a sender user terminal B and a receiver user terminal A. The commercial bank corresponding to user terminal A is denoted as A0, and the commercial bank corresponding to user terminal B is denoted as B0. A is an offline member and communicates with B at close range to conduct digital currency transactions. B is an online member and communicates with A at close range to exchange information between the two parties. The sender information includes the sender ID, wallet ID, contact information, and hardware device code, etc. The receiver information is similar.
[0159] The system of this embodiment also includes a Certificate Authority CA. CA has a quantum-resistant computing device T CA , T CA is deployed with a key management server KMS based on ID cryptography.
[0160] KMS issues quantum-resistant computing devices T A , T B for A and B, and issues quantum-resistant computing devices for A0 and B0 The anti-quantum computing device can be a key card, a mobile terminal, a cryptographic machine, a gateway, etc., which can communicate with the CA institution or each client through mainboard interface communication, short-range wireless communication, controllable intranet communication, etc., and can ensure that information will not be stolen by a quantum computer within the communication range. For example, the anti-quantum computing device can be a key card plugged into the host mainboard of the CA institution, or the anti-quantum computing device can be a mobile terminal performing NFC communication with another mobile terminal, or the anti-quantum computing device is a cryptographic machine or a gateway performing secure intranet communication with a PC host in the same intranet.
[0161] In summary, by means of the above technical solutions of the present invention, the present invention can implement a digital currency communication system based on digital certificate recipients' offline anti-quantum computing; in addition, the symmetric keys used in the present invention are all generated in real time based on ID cryptography and do not require pre-storage of symmetric keys, which is low-cost for users and there are no problems with symmetric key management and storage; in addition, the present invention does not change the overall process and data structure of the traditional CA and digital signature system based on digital certificates, so the cost of switching the CA and user application systems to the anti-quantum computing solution is not high; in addition, in the present invention, the key issuance server based on ID cryptography has different system public and private keys for each different user. Even if the system public key of a certain user is lost and the system private key is cracked by a quantum computer, it will not endanger the system public and private keys of the CA and other users; in addition, the communication mode of the present invention meets the requirements for security and cost in two different situations, that is: for the communication between the central bank and commercial banks with extremely high confidentiality requirements and a relatively small scope of impact on the scheme change, quantum secure communication with higher cost and higher security is adopted to achieve communication with higher security; for the communication between commercial banks and users with not extremely high confidentiality requirements and a relatively large scope of impact on the scheme change, anti-quantum computing communication based on digital certificates is adopted to achieve communication with relatively high security and cost consideration. Therefore, the present invention improves the existing digital currency communication system into an anti-quantum computing digital currency communication system and takes into account the cost of system improvement.
[0162] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0163] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
Claims
1. A quantum-computing-resistant digital currency transaction method with an offline recipient, characterized in that, The method includes the following steps: S1. Use the key management server to issue anti-quantum computing devices to the client and the commercial bank digital currency system respectively; Among them, when the key management server issues the system public and private keys to the client, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the anti-quantum computing device of the key management server, and stores the system public key in the anti-quantum computing device corresponding to the client; When the key management server issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the anti-quantum computing device of the key management server, and stores the system public key in the anti-quantum computing device of the commercial bank digital currency system; When the key management server issues the public and private keys to the client, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the client and the public and private keys in the anti-quantum device of the client; When the key management server issues the public and private keys to the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the anti-quantum device of the commercial bank digital currency system; S2. Use the certificate authority to issue root certificates to the client and the commercial bank digital currency system respectively according to the root certificate issuing method, and store them in the corresponding anti-quantum computing devices; S3. Use the certificate authority to issue certificates to the client and the commercial bank digital currency system respectively through the certificate issuing method, and store them in the corresponding anti-quantum computing devices; S4. Use the currency trading method to realize the off-line digital currency trading of the receiving party client; Among them, the specific steps for S4 to use the currency trading method to realize the off-line digital currency trading of the receiving party client are as follows: S41. The sending party client negotiates with the sending party commercial bank to obtain a session key; S42. The sending party client signs to obtain a signed transaction, and sends the signed transaction to the sending party commercial bank; S43. The sending party commercial bank receives the transaction information and verifies the validity of the sending party client certificate through the certificate authority; S44. The certificate authority receives the message to be verified and verifies the certificate of the sending party client; S45. The sending party commercial bank receives the verification result and verifies the signed transaction. After the verification passes, the sending party commercial bank encrypts the transaction information and forwards it to the central bank; S46. The central bank receives the encrypted transaction information and verifies it. After the verification passes, the central bank sends the transaction results to the sending party commercial bank and the receiving party commercial bank respectively; S47. The receiving commercial bank signs and encrypts the transaction result and sends it to the central bank. After receiving the message, the central bank decrypts it and then encrypts and sends it to the sending commercial bank. S48. The sending commercial bank receives the message sent by the central bank and notifies the sending client of the transaction result and the signature of the receiving commercial bank. S49. The sending client sends the transaction result and the signature of the receiving commercial bank to the receiving client. S410. The receiving client receives the transaction result and the signature of the receiving commercial bank, verifies the signature of the receiving commercial bank. After passing the verification, it then verifies the transaction result. After passing the verification, it stores the received currency.
2. The method for a quantum-computing-resistant digital currency transaction with the recipient offline according to claim 1, wherein The step that S2 uses the root certificate issuance method to use the certificate authority to issue root certificates for the client and the commercial bank digital currency system respectively and stores them in the corresponding quantum-resistant computing devices specifically includes the following steps: S21. Use the certificate authority to issue a root certificate for the client and store it in the quantum-resistant computing device of the client. S22. Use the certificate authority to issue a root certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
3. A quantum computing-resistant digital currency transaction method with the recipient offline according to claim 2, characterized in that, The step that in S21, the certificate authority is used to issue a root certificate for the client includes the following steps: S211. The client sends the identity information to the certificate authority. S212. The certificate authority returns the root certificate of the certificate authority to the client. S213. The client receives the root certificate of the certificate authority.
4. A quantum-resistant computing digital currency transaction method with the receiving party offline according to claim 2, characterized in that The step that in S22, the certificate authority is used to issue a root certificate for the commercial bank digital currency system includes the following steps: S221. The commercial bank digital currency system sends the identity information to the certificate authority. S222. The certificate authority returns the root certificate of the certificate authority to the commercial bank digital currency system. S223. The commercial bank digital currency system receives the root certificate of the certificate authority.
5. A quantum-computing-resistant digital currency transaction method with the recipient offline according to claim 1, wherein, The step that S3 uses the certificate issuance method to use the certificate authority to issue certificates for the client and the commercial bank digital currency system respectively and stores them in the corresponding quantum-resistant computing devices specifically includes the following steps: S31. Use the certificate authority to issue a certificate for the client and store it in the quantum-resistant computing device of the client. S32. Use the certificate authority to issue a certificate for the commercial bank digital currency system and store it in the quantum-resistant computing device of the commercial bank digital currency system.
6. A method for quantum-computing-resistant digital currency transactions with the recipient offline, characterized in that, The step that in S31, the certificate authority is used to issue a certificate for the client includes the following steps: S311. The client sends the identity information and the certificate public key to the certificate authority. S312. The certificate authority returns the certificate to the client. S313. The client receives the certificate.
7. A quantum-resistant computing digital currency transaction method with the recipient offline according to claim 5, characterized in that, In S32, the process of the Certificate Authority issuing a certificate for the commercial bank digital currency system includes the following steps: S321. The commercial bank digital currency system sends identity information and the certificate public key to the Certificate Authority; S322. The Certificate Authority returns a certificate to the commercial bank digital currency system; S323. The commercial bank digital currency system receives the certificate.
8. A quantum-computing-resistant digital currency transaction method for an offline recipient according to claim 1, wherein In S41, the sender client and the sender commercial bank negotiate to obtain a session key, which specifically includes the following steps: S411. The sender client sends a signed session key to the commercial bank; S412. The sender commercial bank verifies the validity of the sender client's certificate with the Certificate Authority; S413. The Certificate Authority verifies the validity of the sender client's certificate and sends the verification result to the sender commercial bank; S414. The sender commercial bank sends the verification result to the sender client.
9. A quantum-resistant digital currency system for implementing the steps of the quantum-resistant digital currency transaction method with an offline recipient described in any one of claims 1-8, characterized in that, The system includes a central bank digital currency system, a commercial bank digital currency system, users, and an authentication system. A quantum key distribution network is established between the central bank digital currency system and the commercial bank digital currency system. The central bank digital currency system and the commercial bank digital currency system conduct identity authentication and secure communication. The commercial bank digital currency system and the users conduct identity authentication and secure communication; Among them, the central bank digital currency system is used to produce and issue digital currency and also to register the ownership of the digital currency; The commercial bank digital currency system is used to perform banking functions for digital currency; The users are the entities that use the digital currency; The authentication system is used to authenticate the interaction between the commercial bank digital currency system and the user terminal device of the digital currency, and also to authenticate the interaction between the central bank digital currency system and the commercial bank digital currency system.
10. A quantum-resistant digital currency system according to claim 9, characterized in that, It further includes a Certificate Authority. An anti-quantum computing device is set in the Certificate Authority, and a key management server based on ID cryptography is deployed in the anti-quantum computing device. The central bank digital currency system includes a central bank. The commercial bank digital currency system includes a sender commercial bank and a receiver commercial bank. The users include a sender client and a receiver client, and short-range communication is carried out between the sender client and the receiver client.
Citation Information
Patent Citations
An antiquantum computing HTTPS communication method and system based on an asymmetric key pool
CN109861813A
Anti-quantum computation consortium blockchain transaction method and system based on public key pool
CN109687963A
Identity authentication system implementation method based on a quantum key distribution technology
CN109818756A