Sender Offline Quantum-Computing Resistant Transaction Method and System Based on Digital Currency

By issuing public and private keys to central banks, commercial banks and users based on identity authentication, the problems of high storage costs of key fuses and complex system switching in the existing technology are solved, and an offline digital currency communication system that is resistant to quantum computing is realized, reducing system switching costs and enhancing transaction security.

CN114529274BActive Publication Date: 2025-08-05RUBAN QUANTUM TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202011223637.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-05
Publication Date
2025-08-05
Estimated Expiration
2040-11-05

AI Technical Summary

Technical Problem

In the digital signature system that is resistant to quantum computing, the client key fob storage cost is high and the operation is complex, and the process and data structure of traditional CA and digital certificates have been changed, resulting in excessive system switching costs.

Method used

The key management server based on identity authentication is used to issue public and private keys to central banks, commercial banks and users, and authentication between systems is realized through identity authentication methods. The hash function and message authentication code are used to generate and verify public keys and private keys to avoid publicizing the system public keys and protect digital signatures using symmetric keys.

Benefits of technology

The offline digital currency communication system that is resistant to quantum computing has been realized, which reduces the storage cost and operational workload of key fobs, reduces the complexity of system switching, enhances the central bank's control over commercial banks, and protects transaction privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114529274B_ABST
    Figure CN114529274B_ABST
Patent Text Reader

Abstract

The present invention discloses a sender-offline quantum computing-resistant digital currency transaction method and system. The method comprises the following steps: S1. Using a key management server to issue system public and private keys and public and private keys to the central bank digital currency system, the commercial bank digital currency system, and the user, respectively; S2. Implementing identity authentication between the commercial bank digital currency system and the central bank digital currency system; S3. Implementing identity authentication between the user and the commercial bank digital currency system; S4. Implementing sender-offline digital currency transactions between different users. Beneficial effects: Not only can a quantum computing-resistant digital currency communication system based on ID cryptography with an offline sender be implemented, but by using a key issuance service based on ID cryptography, the complexity of system construction and upgrade is reduced, and the central bank's control over commercial banks is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of digital currency, and in particular to a sender-based offline quantum computing-resistant transaction method and system for digital currency. Background Art

[0002] The core elements of the People's Bank of China's digital currency (D-RMB) system are one currency, two repositories, and three centers. The currency, "D-RMB" (DC / EP), or D-coin for short, refers to an encrypted digital string representing a specific amount signed by the central bank. The two repositories are the D-RMB issuing repository and the bank repositories (the central bank's digital currency database and the commercial bank's digital currency database). The digital currency in the issuing repository represents the central bank's digital currency fund; the digital currency in the bank repositories represents the commercial bank's digital cash reserves. The three centers are: a registration center (which records the entire process of currency generation, circulation, inventory verification, and expiration); and certification centers: a CA certification center (based on the PKI system, centrally managing institution and user certificates, such as CFCA) and an IBC certification center (an identity-based cryptography certification center). The registration center can maintain two tables: a digital currency ownership registration table, which records digital currency ownership, and a transaction flow table.

[0003] The D-RMB system is a hierarchical system, jointly built by the central bank and commercial banks. The central bank digital currency system is a computer system operated and maintained by the central bank or an institution designated by the central bank to process information about digital currency. Its main functions include being responsible for the issuance and verification monitoring of digital currency. The commercial bank digital currency system is a computer system operated and maintained by commercial banks or institutions designated by commercial banks to process information about digital currency. It performs various currency-related functions of existing banks, namely banking functions, which mainly include being directly facing the society and meeting various needs of providing digital currency circulation services after applying for digital currency from the central bank.

[0004] In order to make the digital signature system resistant to quantum computing, the industry has proposed a quantum computing-resistant digital signature system. For example, patent CN109861813A proposes a quantum computing-resistant HTTPS communication method and system based on an asymmetric key pool, and specifically discloses a communication method. The participants of the method include a server, a certificate authority and a client. The client is configured with a key card, and the key card stores an asymmetric key pool. The quantum computing-resistant HTTPS communication method includes the following steps: the server obtains a digital certificate issued by the certificate authority and sends the digital certificate to the client, wherein the digital certificate records the server's public key pointer random number; the client obtains a root digital certificate issued by the certificate authority that matches the digital certificate, verifies the digital certificate sent by the server based on the root digital certificate, and obtains the server public key from the asymmetric key pool based on the server's public key pointer random number recorded in the verified digital certificate; uses the server public key to encrypt the randomly generated shared key, and sends the encryption result to the server for key negotiation; and uses the shared key to communicate with the server over HTTPS.

[0005] Although the solution proposed in patent CN109861813A can achieve quantum-resistant computing based on quantum secure communication, it has the following drawbacks:

[0006] 1. In the technical solution proposed by patent CN109861813A, the client needs to configure a quantum key card that stores the public keys of all members, which increases the storage cost and operation workload of the client key card, and the user-side key management work is relatively complicated;

[0007] 2. The technical solution proposed by patent CN109861813A changes the overall process and data structure of traditional CA and digital signature systems based on digital certificates. For example, it leads to changes in the format and usage of digital certificates, resulting in excessively high costs for CA and user application systems to switch to quantum-resistant solutions. Summary of the Invention

[0008] In response to the problems in the related technology, the present invention proposes an offline quantum computing-resistant transaction method and system based on digital currency to overcome the above-mentioned technical problems existing in the existing related technology.

[0009] To this end, the specific technical solutions adopted in the present invention are as follows:

[0010] According to one aspect of the present invention, a sender offline quantum computing-resistant transaction method based on digital currency is provided, the method comprising the following steps:

[0011] S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively;

[0012] S2. Implement identity authentication between the commercial bank digital currency system and the central bank digital currency system using an identity authentication method;

[0013] S3. Implementing identity authentication between the user and the commercial bank digital currency system according to an identity authentication method;

[0014] S4. Implementing offline digital currency transactions between different users using an offline digital currency transaction method;

[0015] When the key management server corresponding to the central bank digital currency system issues the system public and private keys for the central bank digital currency system, it takes a random number as the system private key, then calculates the system public key based on the system private key, and stores the system private key and the system public key in the quantum-resistant computing device of the central bank digital currency system;

[0016] When the key management server corresponding to the central bank digital currency system issues public and private keys to the central bank digital currency system, it calls a hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the central bank digital currency system and the public and private keys in the quantum-resistant computing device of the central bank digital currency system;

[0017] When the key management server corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the central bank digital currency system, and stores the system public key in the quantum-resistant computing device corresponding to the commercial bank digital currency system;

[0018] When the key management server corresponding to the central bank digital currency system issues public and private keys to the commercial bank digital currency system, it calls a hash function to calculate the public key, then calculates the private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant computing device of the commercial bank digital currency system;

[0019] When the key management server corresponding to the commercial bank digital currency system issues the system public and private keys to the user, it takes a random number as the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the commercial bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding user terminal;

[0020] When the key management server corresponding to the commercial bank digital currency system issues public and private keys to the user, it calls the hash function to calculate the public key, and then calculates the private key based on the key management server corresponding to the commercial bank digital currency system based on the public key, and stores the user's ID and the public and private keys in the user's quantum-resistant computing device.

[0021] Furthermore, the S2 uses an identity authentication method to implement identity authentication between the commercial bank digital currency system and the central bank digital currency system, including the following steps:

[0022] S21. Send the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system;

[0023] S22. The central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key.

[0024] S23. The commercial bank digital currency system receives the authentication result and performs verification, wherein when the authentication result is successful, the corresponding session key is received.

[0025] Furthermore, the S3 implements identity authentication between the user and the commercial bank digital currency system according to the identity authentication method, including the following steps:

[0026] S31. Sending the identity information of the user to be authenticated to the commercial bank digital currency system;

[0027] S32. The commercial bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the user. When the authentication result is successful, it includes the corresponding session key.

[0028] S33. The user receives the authentication result and performs verification. When the authentication result is successful, the user receives the corresponding session key.

[0029] Furthermore, the S4 implements the offline digital currency transaction between different users by the offline digital currency transaction method, including the following steps:

[0030] S41. The sending user terminal signs the transaction to obtain a signed transaction, and sends the signed transaction to the receiving user terminal;

[0031] S42: The receiving user terminal receives the signed transaction and forwards it to the receiving commercial bank digital currency system corresponding to the receiving user terminal. The receiving commercial bank digital currency system forwards it to the sending commercial bank digital currency system corresponding to the sending user terminal via the central bank digital currency system.

[0032] S43. The sending commercial bank digital currency system receives the verification transaction and forwards it to the central bank digital currency system;

[0033] S44. The central bank digital currency system receives the transaction and verifies it, records the change in ownership of the digital currency after the transaction is successful, and forwards it to the recipient's commercial bank digital currency system. The recipient's commercial bank digital currency system receives the transaction, verifies it, and then forwards it to the recipient's user terminal. The recipient's user terminal receives the transaction, verifies it, and then forwards it to the sender's user terminal.

[0034] S45. The sending user terminal receives the transaction and verifies it, and confirms the transaction result after verification.

[0035] Furthermore, the sending user terminal is an offline member, and the sending user terminal and the receiving user terminal exchange information between the two parties through short-range communication. The information includes but is not limited to the data content of the user terminal ID, wallet ID, contact information and hardware device code.

[0036] According to another aspect of the present invention, a sender-side offline quantum computing-resistant transaction system based on digital currency is provided. The system includes a central bank digital currency system, a commercial bank digital currency system, and a user. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, and identity authentication between the commercial bank digital currency system and the user are both based on the theory of ID cryptography.

[0037] The central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of the digital currency;

[0038] The commercial bank digital currency system is used to perform banking functions for digital currency;

[0039] The user is the user of the digital currency.

[0040] Furthermore, both the central bank digital currency system and the commercial bank digital currency system are equipped with corresponding anti-quantum computing devices, and the anti-quantum computing devices are deployed with corresponding key management servers based on ID cryptography. The users are also equipped with corresponding anti-quantum computing devices, and the anti-quantum computing device of the commercial bank digital currency system is issued by the key management server of the central bank digital currency system, and the anti-quantum computing device of the user is issued by the key management server of the commercial bank digital currency system.

[0041] Furthermore, the quantum-resistant computing device includes but is not limited to a key card, a mobile terminal, a cryptographic machine and a gateway, and the quantum-resistant computing device can communicate with the bank's monetary system or each user terminal separately, and the communication includes but is not limited to multiple communication methods such as mainboard interface communication, short-range wireless communication and controllable intranet communication.

[0042] The beneficial effects of the present invention are:

[0043] 1) The present invention can realize a digital currency communication system based on ID cryptography that is resistant to quantum computing and has an offline sender;

[0044] 2) The present invention does not need to generate an asymmetric key pool from the public keys of all members and then store it in each key card. The client key card only needs to store the key related to itself, so the storage cost and operation workload of the key card are small;

[0045] 3) This invention does not change the overall process and data structure of identity authentication and transaction communication in the traditional digital currency system. It only adds protection based on ID cryptography symmetric keys on the basis of existing technologies. Therefore, the cost of switching the digital currency communication system to a quantum computing-resistant solution is not high. This invention does not use the CA communication system that cannot resist quantum computing. Instead, it uses a key issuance service based on ID cryptography, which not only reduces the complexity of system construction and upgrades, but also enhances the central bank's control over commercial banks.

[0046] 4) The key issuance server based on ID cryptography of the present invention has different system public and private keys for each different user. Even if the system public key of a user is lost and its corresponding system private key is cracked by a quantum computer, it will not endanger the system public and private keys of other users. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0048] Figure 1 This is a flow chart of a sender offline quantum computing-resistant transaction method based on digital currency according to an embodiment of the present invention;

[0049] Figure 2 This is a flow chart of a transaction method involved in a sender offline quantum computing-resistant transaction method based on digital currency according to an embodiment of the present invention;

[0050] Figure 3 This is a basic structural diagram of a digital currency-based sender offline quantum computing-resistant transaction system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0051] To further illustrate each embodiment, the present invention provides drawings, which are part of the disclosure of the present invention. They are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. By referring to these contents, ordinary technicians in this field should be able to understand other possible implementation methods and advantages of the present invention. The components in the figures are not drawn to scale, and similar component symbols are generally used to represent similar components.

[0052] According to an embodiment of the present invention, a sender offline quantum computing resistant transaction method and system based on digital currency are provided.

[0053] The present invention will now be further described with reference to the accompanying drawings and specific embodiments. Figure 1-2 As shown, according to one embodiment of the present invention, a sender offline quantum computing-resistant transaction method based on digital currency is provided, and the method includes the following steps:

[0054] S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively;

[0055] Among them, when the key management server KMS corresponding to the central bank digital currency system issues the system public and private keys to the central bank digital currency system S, it takes a random number as the system private key SK MS , and then according to the system private key SK MS Calculate the system public key PK MS =SK MS *P, and the system private key SK MS And the system public key PK MS The quantum-resistant computing device T stored in the central bank digital currency system S inside;

[0056] When the key management server KMS corresponding to the central bank digital currency system issues the public and private keys to the central bank digital currency system S, the hash function H1 is called to calculate the public key PKS =H1(ID S ), and then according to the public key PK S Calculate the corresponding private key SK S =SK MS *PK S , and the ID of the central bank digital currency system and the public and private keys, i.e., ID S PK S SK S A quantum-resistant computing device T deposited in the central bank digital currency system S S ;

[0057] When the key management server KMS corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system A, it calculates the message authentication code (MAC(m,k)) to obtain the corresponding system private key SK MSA =MAC(ID A ,SK MS ), and then according to the system private key SK MSA Calculate the system public key PK MSA =SK MSA *P, and the system private key SK MSA Stored in the quantum-resistant computing device of the central bank digital currency system, the system public key PK MSA Stored in the quantum-resistant computing device corresponding to the commercial bank digital currency system T A ;

[0058] When the key management server KMS corresponding to the central bank digital currency system issues the public and private keys to the commercial bank digital currency system A, the hash function H1 is called to calculate the public key PK A =H1(ID A ), and then according to the public key PK A Calculate the private key SK A =SK MSA *PK A , and the ID of the commercial bank digital currency system and the public and private keys, i.e., ID A PK A SK A Deposited in the quantum-resistant computing device T of the commercial bank digital currency system A A ;

[0059] When the key management server KMSA corresponding to the commercial bank digital currency system issues the system public and private keys to the user A1, it takes a random number as the corresponding system private key SK MSA1 =MAC(ID A1 , SK MSA0 ), and then according to the system private key SKMSA1 Calculate the system public key PK MSA1 =SK MSA1 *P, and the system private key SK MSA1 Stored in the quantum-resistant computing device of the commercial bank digital currency system A, the system public key PK MSA1 Stored in the quantum-resistant computing device on the corresponding user side;

[0060] When the key management server KMSA corresponding to the commercial bank digital currency system issues the public and private keys to the user A1, the hash function H1 is called to calculate the public key PK A1 =H1(ID A1 ), and then according to the public key PK A1 Calculate the private key SK of the key management server KMSA corresponding to the commercial bank digital currency system A1 =SK MSA1 *PK A1 , and the user's ID and the public-private key, i.e., ID A1 PK A1 SK A1 Stored in the quantum-resistant computing device T of user A1 A1 .

[0061] S2. The commercial bank digital currency system and the central bank digital currency system S perform identity authentication (identity authentication between the commercial bank digital currency system and the central bank digital currency system is achieved using an identity authentication method);

[0062] The following takes the identity authentication between commercial bank digital currency system A and central bank digital currency system S as an example. The process of identity authentication between other commercial bank digital currency systems and central bank digital currency system S is similar.

[0063] Wherein, the S2 comprises the following steps:

[0064] S21. A sends its own identity information to S (sends the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system);

[0065] AAccording to ID S Calculate PK S =H1(ID S ), take out your own KMS-based private key SK A Calculate the symmetric key K between A and S A-S =e(SK A , PK S ). Get timestamp T1, use K A-S Calculate the message authentication code for T1 and get K1=MAC(T1, KA-S ). Combine the ID A ||ID S ||T1||AINFO as MSG A , where AINFO is the identity information of A used for authentication.

[0066] Use SK A MSG A To make a digital signature based on ID cryptography, the process is as follows: take the random number parameter r, calculate UMSG A =r*PK S , h=H3(MSG A ,UMSG A ), VMSG A =(r+h)*SK A Among them, H3(*) is a hash operation. Get the signature SIG A =SIGN(MSG A , SK A )=(UMSG A , VMSG A ).

[0067] Using K1 to detect AINFO and SIG A Encrypted to get {AINFO||SIG A}K1, together with ID A 、ID S and T1 are sent to S. The message sent can be represented by ID A ||ID S ||T1|{AINFO||SIG A}K1.

[0068] S22. S sends the authentication result (including the session key if the authentication is successful) to A (the central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key);

[0069] After S receives the message from A, the KMS in S calculates its system private key to A as SK MSA =MAC(ID A , SK MS ), according to PK S =H1(ID S ) Get S's private key SK for A SA =SK MSA *PK S . Further obtain the symmetric key K between S and A S-A =e(SK SA , PKA ). According to ID cryptography, we can get: K A-S =e(SK A , PK S )=e(SK MSA *PK A , PK S )=e(PK A , SK MSA *PK S )=e(PK A , SK SA )=e(SK SA , PK A )=K S-A Using K S-A Calculate the message authentication code for T1 and get K′1=MAC(T1,K S-A ). Use K′1 to decrypt {AINFO||SIG A}K1, get A's identity information AINFO and SIG A .

[0070] S According to ID A Calculate PK A =H1(ID A ), according to SK MSA Calculate the KMS system public key for A as PK MSA =SK MSA *P, use PK A and PK MSA To verify the signature SIG A To verify the signature, you only need to verify (P, PK MSA ,UMSG A +h*PK A , VMSG A ) is a valid Diffie-Hellman tuple. If the verification succeeds, S generates the session key KS S-A It is combined with the authentication success message and is called RET S ; If the verification fails, the authentication failure message is called RET S Get timestamp T2 and combine ID S ||ID A ||T2||RET S As MSG S .

[0071] Use SK SA MSG S Make a digital signature based on ID cryptography. The process is the same as above to get the signature SIG S =SIGN(MSG S , SKSA )=(UMSG S , VMSG S ).

[0072] Use K S-A Calculate the message authentication code for T2 and get K2=MAC(T2, K S-A ), use K2 to RET S and SIG S Encrypted to get {RET S ||SIG S}K2, together with ID S 、ID A and T2 are sent to A. The message sent can be represented by ID S ||ID A ||T2|{RET S ||SIG S}K2.

[0073] S23. A receives the authentication result (including the session key if the authentication is successful) (the commercial bank digital currency system receives the authentication result and verifies it, wherein, when the authentication result is successful, the corresponding session key is received);

[0074] After A receives the message from S, it uses K A-S Calculate the message authentication code for T2 and get K′2=MAC(T2,K A-S ), decrypt using K′2 {RET S ||SIG S}K2, get RET S and SIG S .

[0075] A verifies the signature SIG in the same way as above S If A verifies the signature successfully, and RET S If the message carried in the message is that S has successfully verified the signature, then you can take out RET S The session key KS in S-A , so A and S can use the session key for confidential communication; in other cases, the session key cannot be obtained.

[0076] From the above process, we can see that the system public key based on ID cryptography is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process can resist the attack of quantum computers on ID cryptography. In addition, the KMS based on ID cryptography has different system public and private keys for different users such as A, B, and C. Even if A's system public key PK MSA Loss of the corresponding system private key SK MSAEven if it is cracked by a quantum computer, it will not endanger the system public and private keys of other users such as B and C.

[0077] S3. The user performs identity authentication with the commercial bank digital currency system (identity authentication between the user and the commercial bank digital currency system is implemented according to an identity authentication method);

[0078] The following example uses user A1's identity authentication with commercial bank digital currency system A. The identity authentication process for other users with the corresponding commercial bank digital currency system is similar.

[0079] Wherein, the S3 includes the following steps:

[0080] S31, A1 sends its own identity information to A (sends the identity information of the user to be authenticated to the commercial bank digital currency system);

[0081] A1 According to ID A Calculate PK A =H1(ID A ), take out your own KMSA-based private key SK A1 Calculate the symmetric key K between A1 and A A1-A =e(SK A1 , PK A ). Get timestamp T3, use K A1-A Calculate the message authentication code for T3 and get K3=MAC(T3,K A1-A ). Combine the ID A1 ||ID A ||T3||A1INFO as MSG A1 , where A1INFO is the identity information of A1 used for authentication.

[0082] Use SK A1 MSG A1 Make a digital signature based on ID cryptography. The process is the same as above to get the signature SIG A1 =SIGN(MSG A1 , SK A1 )=(UMSG A1 , VMSG A1 ).

[0083] Use K3 to check A1INFO and SIG A1 Encrypted to get {A1INFO||SIG A1}K3, together with ID A1 、ID A and T3 are sent to A. The message sent can be represented by ID A1 ||ID A||T3|{A1INFO||SIG A1}K3.

[0084] S32. A sends the authentication result (including the session key if the authentication is successful) to A1 (the commercial bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the user. When the authentication result is successful, it includes the corresponding session key);

[0085] After A receives the message from A1, the KMSA in A calculates its private key to A1 as SK MSA1 =MAC(ID A1 , SK MSA0 ), according to PK A =H1(ID A ) Get A's private key SK for A1 AA1 =SK MSA1 *PK A . Further obtain the symmetric key K between A and A1 A-A1 =e(SK AA1 , PK A1 ). According to ID cryptography, we can get: K A1-A =e(SK A1 , PK A )=e(SK MSA1 *PK A1 , PK A )=e(PK A1 , SK MSA1 *PK A )=e(PK A1 , SKAA1)=e(SK AA1 , PK A1 )=K A-A1 Using K A-A1 Calculate the message authentication code for T3 and get K′3=MAC(T3,K A-A1 ). Use K′3 to decrypt {A1INFO||SIG A1}K3, get A1's identity information A1INFO and SIG A1 .

[0086] A verifies the signature SIG in the same way as above A1 If the verification is successful, A generates the session key KS A-A1 It is combined with the authentication success message and is called RET A ; If the verification fails, the authentication failure message is called RET A Get timestamp T4 and combine ID A ||ID A1 ||T4||RETA As MSG A .

[0087] Use SK AA1 MSG A Make a digital signature based on ID cryptography, the process is the same as above, and get the signature SIG′ A =SIGN(MSG′ A , SK AA1 )=(UMSG′ A , VMSG′ A ).

[0088] Use K A-A1 Calculate the message authentication code for T4 and get K4=MAC(T4, K A-A1 ), use K4 to RET A and SIG′ A Encrypted to get {RET A ||SIG′ A}K4, together with ID A 、ID A1 and T4 are sent to A1. The message sent can be represented by ID A ||ID A1 ||T4||{RET A ||SIG′ A}K4.

[0089] S33, A1 receives the authentication result (including the session key if the authentication is successful) (the user receives the authentication result and verifies it, wherein, when the authentication result is successful, the corresponding session key is received);

[0090] After A1 receives the message from A, it uses K A1-A Calculate the message authentication code for T4 and get K′4=MAC(T4,K A1-A ), decrypt using K′4 {RET A ||SIG′ A}K4, get RET A and SIG′ A .

[0091] A1 verifies the signature SIG′ using the same method as above A If A1 successfully verifies the signature and RET A If the message carried in the file is also a successful signature verification message by A, then RET can be taken out. A The session key KS in A-A1 , so A1 and A can use the session key for confidential communication; in other cases, the session key cannot be obtained.

[0092] From the above process, we can see that the system public key based on ID cryptography is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process can resist the attack of quantum computers on ID cryptography. In addition, the system public and private keys of different users such as A1, A2, and A3 are different for KMSA based on ID cryptography. Even if A1's system public key PK MSA1 Loss of the corresponding system private key SK MSA1 Even if it is cracked by a quantum computer, it will not endanger the system public and private keys of other users such as A2 and A3.

[0093] The process of identity authentication between users B1, B2, B3 and the commercial bank digital currency system B is the same as above. For example, after user B1 completes identity authentication with the commercial bank digital currency system B, there is a session key KS B-B1 .

[0094] S4. Conducting offline digital currency transactions between different users (using an offline digital currency transaction method to achieve offline digital currency transactions between different users);

[0095] The following example uses a digital currency transaction between user A1 and user B1. The process for digital currency transactions between other users is similar.

[0096] User A1 is an offline member in the transaction and communicates with B1 in close proximity to conduct digital currency transactions.

[0097] Users A1 and B1 exchange information through short-range communication. The sender's information includes the sender's ID, wallet ID, contact information, hardware device code, etc.; the receiver's information is similar.

[0098] Flowchart as Figure 2 The specific steps are described as follows:

[0099] S41. A1 signs to obtain a signed transaction (the sending user terminal signs to obtain a signed transaction and sends the signed transaction to the receiving user terminal);

[0100] Client A1 calculates the symmetric key K between itself and A. A1-A =e(SK A1 , PK A ). Use K A-CA Encrypt the signature time T to obtain the final key K T =MAC(T,K A1-A The message to be signed is the transaction TX, which includes the sender information, receiver information, digital currency and other transaction information. A1 , T and TX together as MSG′ A1 , which can be expressed as MSG′A1 =ID A1 ||T||TX.

[0101] Use A1's private key SK A1 MSG A1 Calculate the signature based on ID cryptography to get SIG′ A1 =SIGN(MSG′ A1 , SK A1 )=(UMSG′ A1 , VMSG′ A1 ).

[0102] Use K T TX||SIG′ A1 Encrypt to get {TX||SIG′ A1}K T . Together with ID A1 Together with T as TXS, it can be expressed as TXS = ID A1 ||T||{TX||SIG′ A1}K T A1 sends TXS to B1 via short-range communication.

[0103] S42, B1 receives the signed transaction and forwards it to A;

[0104] After B1 receives the session key KS between it and B B-B1 Send TXS to B under the protection of .

[0105] The session key KS between B and S S-B Send TXS to S under the protection of .

[0106] The session key KS between S and A S-A Send TXS to A under the protection of .

[0107] S43. A verifies the transaction and forwards it to the central bank (the sending commercial bank digital currency system receives the verified transaction and forwards it to the central bank digital currency system);

[0108] After A receives TXS, KMSA in A calculates the system private key SK for A1 MSA1 =MAC(ID A1 , SK MSA ), further calculate the private key SK for A1 AA1 =SK MSA1 *PK A . Calculate the symmetric key K between A1 and A-A1 =e(SK AA1 , PK A1 ). According to ID cryptography, we can get: KA-A1 =e(SK AA1 , PK A1 )=e(SK MSA1 *PK A , PK A1 )=e(PK A , SK MSA1 *PK A1 )=e(PK A , SK A1 )=e(SK A1 , PK A )=K A1-A Using K A-A1 Calculate the message authentication code for T to get K′ T =MAC(T,K A-A1 ). Use K′ T Decrypt {TX||SIG′ A1}K T , get TX and SIG′ A1 .

[0109] Use PK A1 Verification SIG′ A1 , confirming that the message comes from A1. The digital currency transaction result is RET, which contains the result information such as success or failure.

[0110] Use SK A Make a digital signature based on ID cryptography for T||RET, the process is the same as above, and the signature SIG″ is obtained A =SIGN(T||RET,SK A ) A Combine with RET and use K′ T Encrypt it to get RETA = {RET||SIG" A}K′ T . Change T||TX||RET||RET A The session key KS between S S-A Sent to S under the protection of .

[0111] S44. The central bank verifies the transaction and forwards it;

[0112] S receives T||TX||RET||RET A After that, record the ownership change of digital currency after the transaction is successful, and then convert T||TX||RET||RET A The session key KS between B and S-B After receiving the message, B verifies the central bank's message and sends T||TX||RET||RET A Session key KS with B1B-B1 After receiving it, B1 verifies B's message and saves the digital currency in TX, and then sends T||RET A Send to A1.

[0113] S45, A1 confirms the transaction;

[0114] A1 uses K T Decrypting RET A Get RET and SIG A , using PK A About SIG A After verification, confirm the transaction result.

[0115] As can be seen from the above process, the public key of the ID cryptography system is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process is resistant to quantum computer attacks on ID cryptography. In addition, the actual transaction content is encrypted by the symmetric key during each digital currency transaction, thus protecting transaction privacy and making user transactions more secure.

[0116] According to another aspect of the present invention, Figure 3 As shown, a digital currency-based, sender-side, quantum-resistant transaction system is provided. This system consists of a central bank digital currency system, a commercial bank digital currency system (which can be multiple commercial bank digital currency systems in practice), and a user terminal. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, as well as between the commercial bank digital currency system and the user, is based on the theory of ID cryptography. The central bank digital currency system is used to generate and issue digital currency and register its ownership; the commercial bank digital currency system is used to perform banking functions for digital currency; and the user terminal is the main user of digital currency.

[0117] The central bank digital currency system is denoted as S, and its ID is ID S , with quantum-resistant device T S , T S A key management server KMS based on ID cryptography is deployed in the system;

[0118] The commercial bank digital currency system is denoted as A, B, C..., and their IDs are ID A 、ID B 、ID C ..., each with a quantum-resistant computing device T A 、T B 、T C ..., issued by KMS. A 、T B 、TC ...and the key management servers KMSA, KMSB, and KMSC based on ID cryptography are deployed on them respectively;

[0119] Commercial bank digital currency system A includes users A1, A2, A3, etc., whose IDs are ID A1 、ID A2 、ID A3 ..., the commercial bank digital currency system B includes users B1, B2, B3..., whose IDs are ID B1 、ID B2 、ID B3 ..., all users also have quantum-resistant computing devices T A1 、T A2 、T A3 、T B1 、T B2 、T B3 ..., issued by KMSA and KMSB respectively.

[0120] Anti-quantum computing devices can be key cards, mobile terminals, cipher machines, gateways, etc., which can communicate with the bank currency system or each user terminal through the mainboard interface, short-range wireless communication, controllable intranet communication, etc., to ensure that information will not be stolen by quantum computers within the communication range. For example, the anti-quantum computing device can be a key card plugged into the host motherboard of the bank currency system, or the anti-quantum computing device can be a mobile terminal that conducts NFC communication with two mobile terminals, or the anti-quantum computing device can be a cipher machine or gateway that conducts secure intranet communication with PC hosts on the same intranet.

[0121] When issuing public and private keys to a member, you first need to establish a set of system parameters based on ID cryptography. The steps are as follows:

[0122] (1) G1 and G2 are GDH (Diffie-Hellman) groups of order q, where q is a large prime number. G1 is an additive cyclic group consisting of points on an elliptic curve, and P is a generator of group G1. G2 is a multiplicative cyclic group. The bilinear map e: G1×G1→G2.

[0123] (2) Randomly take SK MS ∈Z p * As the system private key of the central bank digital currency system, SK MS The system public key PK of the central bank digital currency system is calculated only in the quantum-resistant computing device of the central bank digital currency system. MS =SK MS *P,PK MSQuantum-resistant computing device T stored in the central bank digital currency system S KMS has different public and private keys for each commercial bank digital currency system. For A, KMS will generate a unique code as ID A , A's system private key is SK MSA , the system private key can be a true random number or calculated, such as SK MSA =MAC(ID A , SK MS )(MAC(m, k) is the message authentication code calculated using key k for message m), A's system public key is PK MSA =SK MSA *P; For B, KMS will generate a unique code as ID B , B's system private key is SK MSB , the system private key can be a true random number or calculated, such as SK MSB =MAC(ID B , SK MS ), B's system public key is PK MSB =SK MSB *P; The system private key is stored in the quantum-resistant computing device of the central bank digital currency system, and the system public key is stored in the quantum-resistant computing device of the corresponding commercial bank digital currency system, namely PK MSA Save in T A PK MSB Save in T B If the system private key is a true random number, KMS stores the system private key and its corresponding user ID in the database and directly accesses it when needed. If the system private key is calculated, KMS generates it in real time when needed without storage. The following embodiments take the system private key obtained by calculation as an example.

[0124] (3) When KMS issues a public and private key to S, it generates a unique code as an ID S , call hash function H1 to calculate the public key PK S =H1(ID S ), then according to the public key PK S Calculate the private key SK S =SK MS *PK S , S's ID and public / private key, namely ID S PK S SK S Quantum-resistant computing device T stored in S S .

[0125] When KMS issues a public and private key to A, it calls the hash function H1 to calculate the public key PK A =H1(IDA ), then according to the public key PK A Calculate the private key SK A =SK MSA *PK A , A's ID and public and private keys, namely ID A PK A SK A Quantum-resistant computing device T stored in A A The process of KMS issuing public and private keys to other commercial banks such as B, C, etc. is similar.

[0126] (4) KMSA randomly takes SK MSA0 ∈Z p * As the system private key of the commercial bank digital currency system A, SK MSA0 Only stored in A's quantum-resistant computing device, the system public key PK of the commercial bank digital currency system is calculated MSA0 =SK MSA0 *P,PK MSA0 Quantum-resistant computing device T stored in the commercial bank digital currency system A KMSA has different public and private keys for each user. The system private key for A1 is SK MSA1 =MAC(ID A1 , SK MSA0 ), the system public key of A1 is PK MSA1 =SK MSA1 *P; the system private key for A2 is SK MSA2 =MAC(ID A2 , SK MSA0 ), the system public key of A2 is PK MSA2 =SK MSA2 *P, KMSA calculates the public and private keys of other users in a similar way. The private key of the system based on KMSA is stored in A’s quantum-resistant computing device, and the public key of the system based on KMSA is stored in the quantum-resistant computing device of the corresponding user end, that is, PK MSA1 Save in T A1 PK MSA2 Save in T A2 The calculation method of KMSB, KMSC, etc. for the system public and private keys of different users is similar.

[0127] (5) When KMSA issues public and private keys to user A1, it calls the hash function H1 to calculate the public key PK A1 =H1(ID A1 ), then according to the public key PK A1 Calculate the KMSA-based private key SK A1 =SK MSA1*PK A1 , A1's ID and public / private key A1 PK A1 SK A1 Quantum-resistant computing device T stored in A1 A1 The process by which the KMSA issues public and private keys to other users, such as A2, A3, etc., is similar. Other key management servers, such as KMSB and KMSC, issue public and private keys to their respective users in a similar manner.

[0128] In summary, with the help of the above-mentioned technical solution of the present invention, the present invention can realize a quantum computing-resistant digital currency communication system based on ID cryptography with an offline sender; in addition, the present invention does not need to generate an asymmetric key pool from the public keys of all members and then store it in each key card. The client key card only needs to store the key related to itself, so the storage cost and operation workload of the key card are small; in addition, the present invention does not change the overall process and data structure of identity authentication and transaction communication of the traditional digital currency system, but only adds protection based on ID cryptography symmetric keys on the basis of the existing technology, so the cost of switching the digital currency communication system to a quantum computing-resistant solution is not high; the present invention does not adopt a CA communication system that cannot resist quantum computing, but replaces it with a key issuance service based on ID cryptography, which not only reduces the complexity of system construction and upgrade, but also enhances the central bank's control over commercial banks; in addition, the key issuance server based on ID cryptography of the present invention has different system public and private keys for each different user. Even if a user's system public key is lost and its corresponding system private key is cracked by a quantum computer, it will not endanger the system public and private keys of other users.

[0129] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0130] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.

Claims

1. A sender-side offline quantum computing-resistant transaction method based on digital currency, characterized in that: The method comprises the following steps: S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively; S2. Implement identity authentication between the commercial bank digital currency system and the central bank digital currency system using an identity authentication method; S3. Implementing identity authentication between the user and the commercial bank digital currency system according to an identity authentication method; S4. Implementing offline digital currency transactions between different users using an offline digital currency transaction method; When the key management server corresponding to the central bank digital currency system issues the system public and private keys for the central bank digital currency system, it takes a random number as the system private key, then calculates the system public key based on the system private key, and stores the system private key and the system public key in the quantum-resistant computing device of the central bank digital currency system; When the key management server corresponding to the central bank digital currency system issues public and private keys to the central bank digital currency system, it calls a hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the central bank digital currency system and the public and private keys in the quantum-resistant computing device of the central bank digital currency system; When the key management server corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the central bank digital currency system, and stores the system public key in the quantum-resistant computing device corresponding to the commercial bank digital currency system; When the key management server corresponding to the central bank digital currency system issues public and private keys to the commercial bank digital currency system, it calls a hash function to calculate the public key, then calculates the private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant computing device of the commercial bank digital currency system; When the key management server corresponding to the commercial bank digital currency system issues the system public and private keys to the user, it takes a random number as the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the commercial bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding user terminal; When the key management server corresponding to the commercial bank digital currency system issues a public and private key to the user, it calls a hash function to calculate the public key, and then calculates the private key based on the key management server corresponding to the commercial bank digital currency system based on the public key, and stores the user's ID and the public and private keys in the user's quantum-resistant computing device; The S2 uses the identity authentication method to implement identity authentication between the commercial bank digital currency system and the central bank digital currency system, including the following steps: S21. Send the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system; S22. The central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key. S23. The commercial bank digital currency system receives the authentication result and performs verification. When the authentication result is successful, the corresponding session key is received. The S3 implements identity authentication between the user and the commercial bank digital currency system according to the identity authentication method, including the following steps: S31. Sending the identity information of the user to be authenticated to the commercial bank digital currency system; S32. The commercial bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the user. When the authentication result is successful, it includes the corresponding session key. S33. The user receives the authentication result and performs verification. When the authentication result is successful, the user receives the corresponding session key.

2. The sender-side offline quantum computing-resistant transaction method based on digital currency according to claim 1 is characterized in that: The S4 implements the offline digital currency transaction between different users by the sender through the offline digital currency transaction method, including the following steps: S41. The sending user terminal signs the transaction to obtain a signed transaction, and sends the signed transaction to the receiving user terminal; S42: The receiving user terminal receives the signed transaction and forwards it to the receiving commercial bank digital currency system corresponding to the receiving user terminal. The receiving commercial bank digital currency system forwards it to the sending commercial bank digital currency system corresponding to the sending user terminal via the central bank digital currency system. S43. The sending commercial bank digital currency system receives the verification transaction and forwards it to the central bank digital currency system; S44. The central bank digital currency system receives the transaction and verifies it, records the change in ownership of the digital currency after the transaction is successful, and forwards it to the recipient's commercial bank digital currency system. The recipient's commercial bank digital currency system receives the transaction, verifies it, and then forwards it to the recipient's user terminal. The recipient's user terminal receives the transaction, verifies it, and then forwards it to the sender's user terminal. S45. The sending user terminal receives the transaction and verifies it, and confirms the transaction result after verification.

3. The sender-side offline quantum computing-resistant transaction method based on digital currency according to claim 2 is characterized in that: The sending user terminal is an offline member, and the sending user terminal and the receiving user terminal exchange information between the two parties through short-range communication. The information includes but is not limited to the data content of the user terminal ID, wallet ID, contact information and hardware device code.

4. A digital currency-based sender offline quantum computing-resistant transaction system, used to implement the steps of any one of claims 1-3 of the digital currency-based sender offline quantum computing-resistant transaction method, characterized in that: The system includes a central bank digital currency system, a commercial bank digital currency system, and users. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, and identity authentication between the commercial bank digital currency system and the users are both based on the theory of ID cryptography. The central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of the digital currency; The commercial bank digital currency system is used to perform banking functions for digital currency; The user is the user of the digital currency.

5. The sender-side offline quantum computing-resistant transaction system based on digital currency according to claim 4 is characterized in that: Both the central bank digital currency system and the commercial bank digital currency system are equipped with corresponding anti-quantum computing devices, and the anti-quantum computing devices are deployed with corresponding key management servers based on ID cryptography. The users are also equipped with corresponding anti-quantum computing devices, and the anti-quantum computing device of the commercial bank digital currency system is issued by the key management server of the central bank digital currency system, and the anti-quantum computing device of the user is issued by the key management server of the commercial bank digital currency system.

6. The sender-side offline quantum computing-resistant transaction system based on digital currency according to claim 5 is characterized in that: The quantum-resistant computing device includes but is not limited to a key card, a mobile terminal, a cryptographic machine and a gateway, and the quantum-resistant computing device can communicate with the bank's monetary system or each user terminal separately. The communication includes but is not limited to multiple communication methods such as mainboard interface communication, short-range wireless communication and controllable intranet communication.

Citation Information

Patent Citations

  • An antiquantum computing HTTPS communication method and system based on an asymmetric key pool

    CN109861813A

  • Method and system for depositing digital currencies into deposit accounts

    CN107230054A

  • Digital currency system

    CN107230070A