Sender offline anonymous transaction method and system based on quantum-resistant computing
Through an identity authentication-based key management server, issuing public and private keys to central banks, commercial banks and users, combining hash functions and offline transaction methods, the problems of high storage costs of key fobs and complex system switching in the existing technology are solved, and anonymous transactions and user privacy protection are realized that resistant to quantum computing and user privacy protection are achieved.
Patent Information
- Application Number
- CN202011230624.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-06
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2040-11-06
AI Technical Summary
In the digital signature system that is resistant to quantum computing, the client key fob storage cost is high, the operation is complex, and the replacement cost is too high, which has changed the process and data structure of traditional CA and digital certificates.
The key management server based on identity authentication is used to issue public and private keys to central banks, commercial banks and users, and authentication between systems is realized through identity authentication methods. Public and private keys are generated using hash functions and random numbers, and anonymous transactions are performed in combination with offline transaction methods. Key issuance services based on ID cryptography are used.
It realizes anonymous transactions that are resistant to quantum computing, reduces the storage cost and operation complexity of key fobs, reduces the cost of system switching, enhances user privacy protection and the central bank's control over commercial banks, and prevents quantum computing attacks.
Smart Images

Figure CN114529276B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of identity authentication, and in particular to a sender offline anonymous transaction method and system based on quantum-resistant computing. Background Art
[0002] The core elements of the People's Bank of China's digital currency (D-RMB) system are one currency, two repositories, and three centers. The currency, "D-RMB" (DC / EP), or D-coin for short, refers to an encrypted digital string representing a specific amount signed by the central bank. The two repositories are the D-RMB issuing repository and the bank repositories (the central bank's digital currency database and the commercial bank's digital currency database). The digital currency in the issuing repository represents the central bank's digital currency fund; the digital currency in the bank repositories represents the commercial bank's digital cash reserves. The three centers are: a registration center (which records the entire process of currency generation, circulation, inventory verification, and expiration); and certification centers: a CA certification center (based on the PKI system, centrally managing institution and user certificates, such as CFCA) and an IBC certification center (an identity-based cryptography certification center). The registration center can maintain two tables: a digital currency ownership registration table, which records digital currency ownership, and a transaction flow table.
[0003] The D-RMB system is a hierarchical system, jointly built by the central bank and commercial banks. The central bank digital currency system is a computer system operated and maintained by the central bank or an institution designated by the central bank to process information about digital currency. Its main functions include being responsible for the issuance and verification monitoring of digital currency. The commercial bank digital currency system is a computer system operated and maintained by commercial banks or institutions designated by commercial banks to process information about digital currency. It performs various currency-related functions of existing banks, namely banking functions, which mainly include being directly facing the society and meeting various needs of providing digital currency circulation services after applying for digital currency from the central bank. In order to make the digital signature system resistant to quantum computing, the industry has proposed a quantum computing-resistant digital signature system. For example, patent CN109861813A proposes a quantum computing-resistant HTTPS communication method and system based on an asymmetric key pool, and specifically discloses a communication method. The participants of the method include a server, a certificate authority and a client. The client is configured with a key card, and the key card stores an asymmetric key pool. The quantum computing-resistant HTTPS communication method includes the following steps: the server obtains a digital certificate issued by the certificate authority and sends the digital certificate to the client, wherein the digital certificate records the server's public key pointer random number; the client obtains a root digital certificate issued by the certificate authority that matches the digital certificate, verifies the digital certificate sent by the server based on the root digital certificate, and obtains the server public key from the asymmetric key pool based on the server's public key pointer random number recorded in the verified digital certificate; uses the server public key to encrypt the randomly generated shared key, and sends the encryption result to the server for key negotiation; and uses the shared key to communicate with the server over HTTPS.
[0004] Although the solution proposed in patent CN109861813A can achieve quantum-resistant computing based on quantum secure communication, it has the following drawbacks:
[0005] 1. In the technical solution proposed by patent CN109861813A, the client needs to configure a quantum key card that stores the public keys of all members, which increases the storage cost and operation workload of the client key card, and the user-side key management work is relatively complicated;
[0006] 2. The technical solution proposed by patent CN109861813A changes the overall process and data structure of traditional CA and digital signature systems based on digital certificates. For example, it leads to changes in the format and usage of digital certificates, resulting in excessively high costs for CA and user application systems to switch to quantum-resistant solutions. Summary of the Invention
[0007] In response to the problems in the related technology, the present invention proposes an offline anonymous transaction method and system for the sender based on quantum computing to overcome the above-mentioned technical problems existing in the existing related technology.
[0008] To this end, the specific technical solutions adopted in the present invention are as follows:
[0009] According to one aspect of the present invention, a sender offline anonymous transaction method based on quantum-resistant computing is provided, the method comprising the following steps:
[0010] S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively;
[0011] S2. Implement identity authentication between the commercial bank digital currency system and the central bank digital currency system using an identity authentication method;
[0012] S3. Implementing identity authentication between the user and the commercial bank digital currency system according to an identity authentication method, and obtaining a new anonymous identity for the user;
[0013] S4. Implementing offline digital currency transactions between different users using an offline digital currency transaction method;
[0014] When the key management server corresponding to the central bank digital currency system issues the system public and private keys for the central bank digital currency system, it takes a random number as the system private key, then calculates the system public key based on the system private key, and stores the system private key and the system public key in the quantum-resistant computing device of the central bank digital currency system;
[0015] When the key management server corresponding to the central bank digital currency system issues public and private keys for the central bank digital currency system, it calls a hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the central bank digital currency system and the public and private keys in the quantum-resistant computing device of the central bank digital currency system;
[0016] When the key management server corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the central bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding commercial bank digital currency system;
[0017] When the key management server corresponding to the central bank digital currency system issues public and private keys to the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant computing device of the commercial bank digital currency system;
[0018] When the key management server corresponding to the commercial bank digital currency system issues the system public and private keys to the user, it takes a random number as the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the commercial bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding user terminal;
[0019] When the key management server corresponding to the commercial bank digital currency system issues public and private keys to the user, it calls the hash function to calculate the public key, and then calculates the private key based on the key management server corresponding to the commercial bank digital currency system based on the public key, and stores the user's ID and the public and private keys in the user's quantum-resistant computing device.
[0020] Furthermore, the S2 uses an identity authentication method to implement identity authentication between the commercial bank digital currency system and the central bank digital currency system, including the following steps:
[0021] S21. Send the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system;
[0022] S22. The central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key.
[0023] S23. The commercial bank digital currency system receives the authentication result and performs verification. When the authentication result is successful, the corresponding session key is received.
[0024] Furthermore, S3 implements identity authentication between the user and the commercial bank digital currency system according to the identity authentication method, and obtains the user's new anonymous identity, including the following steps:
[0025] S31. Send the anonymous identity information of the user to be authenticated to the commercial bank digital currency system and apply for updating and generating a new anonymous identity for the user;
[0026] S32. The commercial bank digital currency system receives the user's information with an anonymous identity, verifies whether the identity information to be authenticated is the real identity corresponding to the anonymous identity, and returns the authentication result to the user. When the verification is successful, the commercial bank digital currency system generates a new anonymous identity for the user, calculates the system public and private keys and public and private keys of the user's new anonymous identity, and generates a session key. The session key, the authentication success message, the new anonymous identity, the new system public key, and the new private key are combined to obtain the next identity information. At the same time, the key management server corresponding to the commercial bank digital currency system records the correspondence between the user's real identity and the new anonymous identity. When the verification fails, the authentication failure message is called change information, and the timestamp is obtained to obtain the corresponding sent message.
[0027] S33. The user receives the authentication result and verifies it. When the user's signature verification is successful and the change information carries a message that the commercial bank digital currency system has successfully verified the signature, the session key, new anonymous identity, new system public key and new private key in the next identity information are taken out. The user replaces the anonymous identity, system public key and private key originally stored in the quantum-resistant computing device with the new anonymous identity, new system public key and new private key, and uses the new anonymous identity as the anonymous identity to be used next time.
[0028] Furthermore, the S4 implements the offline digital currency transaction between different users by the offline digital currency transaction method, including the following steps:
[0029] S41. The sending user terminal signs the transaction to obtain a signed transaction, and sends the signed transaction to the receiving user terminal;
[0030] S42: The receiving user terminal receives the signed transaction and forwards it to the receiving commercial bank digital currency system corresponding to the receiving user terminal. The receiving commercial bank digital currency system forwards it to the sending commercial bank digital currency system corresponding to the sending user terminal via the central bank digital currency system.
[0031] S43. The sending commercial bank digital currency system receives the verification transaction, generates change information corresponding to the sending user terminal, and forwards it to the central bank digital currency system.
[0032] S44. The central bank digital currency system receives the transaction and verifies it, records the change in ownership of the digital currency after the transaction is successful, and forwards it to the recipient's commercial bank digital currency system. After receiving the transaction and verifying it, the recipient's commercial bank digital currency system generates change information corresponding to the recipient's user terminal and forwards it to the recipient's user terminal. After receiving the transaction and verifying it, the recipient's user terminal saves the digital currency in the transaction and the recipient's user terminal's next identity information, and forwards a message with the signature time and change information to the sender's user terminal.
[0033] S45. The sending user terminal receives the message and performs verification, and confirms the transaction result after verification. When the transaction is successful, the sending user terminal stores the next identity information.
[0034] Furthermore, the sending user terminal is an offline member, and the sending user terminal and the receiving user terminal exchange information through short-range communication, wherein the sending information includes the sending party's anonymous ID, and the receiving party information includes the receiving party's anonymous ID.
[0035] Furthermore, the S43 further includes the following steps:
[0036] The signature is verified using the user's public key to confirm that the message comes from the sender's user terminal, and the real identity is found based on the anonymous identity. When the verification fails, the message of failed authentication is called the change information corresponding to the sender's user terminal. When the verification is successful, the digital currency system of the sender's commercial bank generates a new anonymous identity for the sender's user terminal, and calculates the system public and private keys and public and private keys of the sender's new anonymous identity. The new anonymous identity, new system public key and new private key of the sender's user are combined to obtain the next identity information of the sender's user. The digital currency system of the sender's commercial bank combines the authentication success message and the next identity information of the sender's user to obtain the change information corresponding to the sender's user terminal, and performs a signature based on ID cryptography.
[0037] Furthermore, the S44 further includes the following steps:
[0038] The receiving commercial bank digital currency system verifies the message of the central bank digital currency system. When the verification fails, the authentication failure message is called the change information corresponding to the receiving user terminal. When the verification is successful, the receiving commercial bank digital currency system generates a new anonymous identity for the receiving user terminal, and calculates the system public and private keys and public and private keys of the new anonymous identity of the receiving user terminal, and combines the receiving user's new anonymous identity, the new system public key and the new private key to obtain the receiving user's next identity information. The receiving commercial bank digital currency system combines the authentication success message and the receiving user terminal's next identity information to obtain the change information corresponding to the receiving user terminal.
[0039] According to another aspect of the present invention, a sender offline anonymous transaction system based on quantum-resistant computing is provided. The system includes a central bank digital currency system, a commercial bank digital currency system, and a user. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, and identity authentication between the commercial bank digital currency system and the user are both based on the theory of ID cryptography.
[0040] The central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of digital currency;
[0041] The commercial bank digital currency system is used to perform banking functions for digital currency;
[0042] The user is the user of the digital currency.
[0043] Furthermore, both the central bank digital currency system and the commercial bank digital currency system are equipped with corresponding anti-quantum computing devices, and corresponding key management servers based on ID cryptography are deployed in the anti-quantum computing devices. The users are also equipped with corresponding anti-quantum computing devices, and the anti-quantum computing device of the commercial bank digital currency system is issued by the key management server of the central bank digital currency system, and the anti-quantum computing device of the user is issued by the key management server of the commercial bank digital currency system.
[0044] Furthermore, the quantum-resistant computing device includes but is not limited to a key card, a mobile terminal, a cryptographic machine and a gateway, and the quantum-resistant computing device can communicate with the bank's monetary system or each user terminal separately, and the communication includes but is not limited to multiple communication methods such as mainboard interface communication, short-range wireless communication and controllable intranet communication.
[0045] The beneficial effects of the present invention are:
[0046] 1) The present invention can realize a quantum computing-resistant digital currency anonymous transaction method based on ID cryptography with the sender offline;
[0047] 2) The present invention does not need to generate an asymmetric key pool from the public keys of all members and then store it in each key card. The client key card only needs to store the key related to itself, so the storage cost and operation workload of the key card are small;
[0048] 3) This invention does not change the overall process and data structure of identity authentication and transaction communication in the traditional digital currency system. It only adds protection based on ID cryptography symmetric keys on the basis of existing technologies. Therefore, the cost of switching the digital currency communication system to a quantum computing-resistant solution is not high. This invention does not use the CA communication system that cannot resist quantum computing. Instead, it uses a key issuance service based on ID cryptography, which not only reduces the complexity of system construction and upgrades, but also enhances the central bank's control over commercial banks.
[0049] 4) In the present invention, the key management server issues an anonymous identity to the user. The user uses the frequently updated anonymous identity to communicate with the commercial bank digital currency system, which can protect the user's privacy information and make transactions more secure.
[0050] 5) The key issuance server based on ID cryptography of the present invention has different system public and private keys for each different user. Even if a user's system public key is lost and its corresponding system private key is cracked by a quantum computer, it will not endanger the system public and private keys of other users. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0052] Figure 1 This is a flow chart of a sender offline anonymous transaction method based on quantum-resistant computing according to an embodiment of the present invention;
[0053] Figure 2 is a flow chart of a transaction method involved in a sender offline anonymous transaction method based on quantum-resistant computing according to an embodiment of the present invention;
[0054] Figure 3 This is a basic structural diagram of a sender offline anonymous transaction system based on quantum-resistant computing according to an embodiment of the present invention. DETAILED DESCRIPTION
[0055] To further illustrate each embodiment, the present invention provides drawings, which are part of the disclosure of the present invention. They are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. By referring to these contents, ordinary technicians in this field should be able to understand other possible implementation methods and advantages of the present invention. The components in the figures are not drawn to scale, and similar component symbols are generally used to represent similar components.
[0056] According to an embodiment of the present invention, a sender offline anonymous transaction method and system based on quantum-resistant computing are provided.
[0057] The present invention will now be further described with reference to the accompanying drawings and specific embodiments. Figure 1-2 As shown, according to one embodiment of the present invention, a sender offline anonymous transaction method based on quantum-resistant computing is provided, and the method includes the following steps:
[0058] S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively;
[0059] Among them, when the key management server KMS corresponding to the central bank digital currency system issues the system public and private keys to the central bank digital currency system S, it takes a random number as the system private key SK MS , and then according to the system private key SK MS Calculate the system public key PK MS =SK MS *P, and the system private key SK MS And the system public key PK MS The quantum-resistant computing device T stored in the central bank digital currency system S inside;
[0060] When the key management server KMS corresponding to the central bank digital currency system issues the public and private keys to the central bank digital currency system S, the hash function H1 is called to calculate the public key PK S =H1(ID S ), and then according to the public key PK S Calculate the corresponding private key SK S =SK MS *PK S , and the ID of the central bank digital currency system and the public and private keys, i.e., ID S PK S SK S A quantum-resistant computing device T deposited in the central bank digital currency system S S ;
[0061] When the key management server KMS corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system A, it calculates the message authentication code (MAC(m, k)) to obtain the corresponding system private key SK MSA =MAC(ID A , SK MS ), and then according to the system private key SK MSA Calculate the system public key PK MSA =SK MSA*P, and the system private key SK MSA Stored in the quantum-resistant computing device of the central bank digital currency system, the system public key PK MSA Stored in the quantum-resistant computing device corresponding to the commercial bank digital currency system T A ;
[0062] When the key management server KMS corresponding to the central bank digital currency system issues the public and private keys to the commercial bank digital currency system A, the hash function H1 is called to calculate the public key PK A =H1(ID A ), and then according to the public key PK A Calculate the private key SK A =SK MSA *PK A , and the ID of the commercial bank digital currency system and the public and private keys, i.e., ID A PK A SK A Deposited in the quantum-resistant computing device T of the commercial bank digital currency system A A ;
[0063] When the key management server KMSA corresponding to the commercial bank digital currency system issues the system public and private keys to the user A1, it takes a random number as the corresponding system private key SK MSA1 =MAC(ID A1 , SK MSA0 ), and then according to the system private key SK MSA1 Calculate the system public key PK MSA1 =SK MSA1 *P, and the system private key SK MSA1 Stored in the quantum-resistant computing device of the commercial bank digital currency system A, the system public key PK MSA1 Stored in the quantum-resistant computing device on the corresponding user side;
[0064] When the key management server KMSA corresponding to the commercial bank digital currency system issues the public and private keys to the user A1, the hash function H1 is called to calculate the public key PK A1 =H1(ID A1 ), and then according to the public key PK A1 Calculate the private key SK of the key management server KMSA corresponding to the commercial bank digital currency system A1 =SK MSA1 *PK A1 , and the user's ID and the public-private key, i.e., ID A1 PK A1 SK A1Stored in the quantum-resistant computing device T of user A1 A1 .
[0065] S2. The commercial bank digital currency system and the central bank digital currency system S perform identity authentication (using the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, the commercial bank digital currency system and the user respectively);
[0066] The following takes the identity authentication between commercial bank digital currency system A and central bank digital currency system S as an example. The process of identity authentication between other commercial bank digital currency systems and central bank digital currency system S is similar.
[0067] Wherein, the S2 comprises the following steps:
[0068] S21. A sends its own identity information to S (sending the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system);
[0069] Specifically, A according to ID S Calculate PK S =H1(ID S ), take out your own KMS-based private key SK A Calculate the symmetric key K between A and S A-S =e(SK A , PK S ). Get timestamp T1, use K A-S Calculate the message authentication code for T1 and get K1=MAC(T1, K A-S ). Combine the ID A ||ID S ||T1||AINFO as MSG A , where AINFO is the identity information of A used for authentication.
[0070] Use SK A MSG A To make a digital signature based on ID cryptography, the process is as follows: take the random number parameter r, calculate UMSG A =r*PK S , h=H3(MSG A ,UMSG A ), VMSG A =(r+h)*SK A Among them, H3(*) is a hash operation. Get the signature SIG A =SIGN(MSG A , SK A )=(UMSG A , VMSG A ).
[0071] Using K1 to detect AINFO and SIG A Encrypted to get {AINFO||SIG A}K1, together with ID A 、ID S and T1 are sent to S. The message sent can be represented by ID A ||ID S ||T1|{AINFO||SIG A}K1.
[0072] S22. S sends the authentication result (including the session key if successful) to A (the central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key);
[0073] Specifically, after S receives the message from A, the KMS in S calculates its system private key to A as SK MSA =MAC(ID A , SK MS ), according to PK S =H1(ID S ) Get S's private key SK for A SA =SK MSA *PK S .
[0074] Further obtain the symmetric key K between S and A S - A =e(SK SA , PK A ). According to ID cryptography, we can get:
[0075] K A-S =e(SK A , PK S )=e(SK MSA *PK A , PK S )=e(PK A , SK MSA *PK S )=e(PK A , SK SA )=e(SK SA , PK A )=K S-A Using K S-A Calculate the message authentication code for T1 and get K′1=MAC(T1,K S-A ). Use K′1 to decrypt {AINFO||SIG A}K1, get A's identity information AINFO and SIG A .
[0076] S According to ID A Calculate PK A =H1(ID A ), according to SK MSA Calculate the KMS system public key for A as PK MSA =SK MSA *P, use PK A and PK MSA To verify the signature SIG A To verify the signature, you only need to verify (P, PK MSA ,UMSG A +h*PK A , VMSG A ) is a valid Diffie-Hellman tuple. If the verification succeeds, S generates the session key KS S-A It is combined with the authentication success message and is called RET S ; If the verification fails, the authentication failure message is called RET S Get timestamp T2 and combine ID S ||ID A ||T2||RET S As MSG S .
[0077] Use SK SA MSG S Make a digital signature based on ID cryptography. The process is the same as above to get the signature SIG S =SIGN(MSG S , SK SA )=(UMSG S , VMSG S ).
[0078] Use K S-A Calculate the message authentication code for T2 and get K2=MAC(T2, K S-A ), use K2 to RET S and SIG S Encrypted to get {RET S ||SIG S}K2, together with ID S 、ID A and T2 are sent to A. The message sent can be represented by ID S ||ID A ||T2|{RET S ||SIG S}K2.
[0079] S23. A receives the authentication result (including the session key if the authentication is successful) (the commercial bank digital currency system receives the authentication result and verifies it. When the authentication result is successful, the corresponding session key is received);
[0080] Specifically, after A receives the message from S, it uses K A-S Calculate the message authentication code for T2 and get K′2=MAC(T2,K A-S ), decrypt using K′2 {RET S ||SIG S}K2, get RET S and SIG S .
[0081] A verifies the signature SIG in the same way as above S If A verifies the signature successfully, and RET S The message carried in the message is also a successful signature verification by S, then the session key KS in RETS can be taken out. S-A , so A and S can use the session key for confidential communication; in other cases, the session key cannot be obtained.
[0082] From the above process, we can see that the system public key based on ID cryptography is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process can resist the attack of quantum computers on ID cryptography. In addition, the KMS based on ID cryptography has different system public and private keys for different users such as A, B, and C. Even if A's system public key PK MSA Loss of the corresponding system private key SK MSA Even if it is cracked by a quantum computer, it will not endanger the system public and private keys of other users such as B and C.
[0083] S3. The user performs identity authentication with the commercial bank digital currency system (authentication between the user and the commercial bank digital currency system is performed according to the identity authentication method, and the user's new anonymous identity is obtained);
[0084] The following takes the identity authentication of user A1 with the commercial bank digital currency system A as an example. The process for other users to authenticate with the corresponding commercial bank digital currency system is similar.
[0085] Wherein, the S3 includes the following steps:
[0086] S31. A1 sends its own identity information to A and applies to update and generate a new anonymous identity (sends the anonymous identity information of the user to be authenticated to the commercial bank digital currency system and applies to update and generate a new anonymous identity for the user);
[0087] Specifically, A1 according to ID A Calculate PK A =H1(ID A ), take out your own KMSA-based private key SK A1 Calculate the symmetric key K between A1 and A A1-A =e(SK A1 , PK A ). Get timestamp T3, use K A1-A Calculate the message authentication code for T3 and get K3=MAC(T3,K A1-A ). Combine the ID A1 ||ID A ||T3||A1INFO as MSG A1 , where A1INFO is the identity information of A1 used for authentication.
[0088] Use SK A1 MSG A1 Make a digital signature based on ID cryptography. The process is the same as above to get the signature SIG A1 =SIGN(MSG A1 , SK A1 )=(UMSG A1 , VMSG A1 ).
[0089] Use K3 to check A1INFO and SIG A1 Encrypted to get {A1INFO||SIG A1}K3, together with A1's anonymous ID A1 、ID A and T3 are sent to A. The message sent can be represented by ID A1 ||ID A ||T3|{A1INFO||SIG A1}K3.
[0090] S32. A sends the authentication result (including the session key if successful) to A1.
[0091] Specifically, after A receives the message from A1, the KMSA in A calculates its private key to A1 as SK MSA1 =MAC(ID A1 , SK MSA0 ), according to PK A =H1(ID A ) Get A's private key SK for A1 AA1 =SK MSA1 *PK A . Further obtain the symmetric key K between A and A1 A-A1=e(SK AA1 , PK A1 ). According to ID cryptography, we can get: K A1-A =e(SK A1 , PK A )=e(SK MSA1 *PK A1 , PK A )=e(PK A1 , SK MSA1 *PK A )=e(PK A1 , SK AA1 )=e(SK AA1 , PK A1 )=K A-A1 Using K A-A1 Calculate the message authentication code for T3 and get K′3=MAC(T3,K A-A1 ). Use K′3 to decrypt {A1INFO||SIG A1}K3, get A1's identity information A1INFO and SIG A1 A verifies whether A1INFO is ID A1 The corresponding real identity.
[0092] A verifies the signature SIG in the same way as above A1 If the verification fails, the authentication failure message is called RET A If the verification is successful, A generates a new anonymous ID for A1 A1new , calculate KMSA pair ID A1new System private key SK MSA1new =MAC(ID A1new , SK MSA ), system public key PK MSA1new =SK MSA1new *P, calculation ID A1new Public key PK A1new =H1(ID A1new ), private key SK A1new =SK MSA1new *PK A1new A generates a session key KS A-A1 And KS A-A1 , authentication success message and ID A1new ||PK MSA1new ||SK A1new The combination is called RET A At the same time, KMSA records A1's real identity and its anonymous identity ID A1new Get timestamp T4 and combine ID A ||ID A1||T4||RET A As MSG A .
[0093] Use SK AA1 MSG A Make a digital signature based on ID cryptography, the process is the same as above, and get the signature SIG′ A =SIGN(MSG′ A , SK AA1 )=(UMSG′ A , VMSG′ A ).
[0094] Use K A-A1 Calculate the message authentication code for T4 and get K4=MAC(T4, K A-A1 ), use K4 to RET A and SIG′ A Encrypted to get {RET A ||SIG′ A}K4, together with ID A 、ID A1 and T4 are sent to A1. The message sent can be represented by ID A ||ID A1 ||T4||{RET A ||SIG′ A}K4.
[0095] S33. A1 receives the authentication result (including the session key if the authentication is successful).
[0096] Specifically, after A1 receives the message from A, it uses K A1-A Calculate the message authentication code for T4 and get K′4=MAC(T4,K A1-A ), decrypt using K′4 {RET A ||SIG′ A}K4, get RET A and SIG′ A .
[0097] A1 verifies the signature SIG′ using the same method as above A If A1 successfully verifies the signature and RET A If the message carried in the file is also a successful signature verification message by A, then RET can be taken out. A The session key KS in A-A1 and ID A1new ||PK MSA1new ||SK A1new , A1 will use the new anonymous identity, system public key and private key, namely ID A1new ||PK MSA1new||SK A1new Replace quantum-resistant computing device T A1 The original stored ID A1 ||PK MSA1 ||SK A1 and use the ID A1new As a new anonymous identity, A1 and A can use the session key to communicate confidentially; otherwise, the session key cannot be obtained.
[0098] From the above process, we can see that the system public key based on ID cryptography is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process can resist the attack of quantum computers on ID cryptography. In addition, the system public and private keys of different users such as A1, A2, and A3 are different for KMSA based on ID cryptography. Even if A1's system public key PK MSA1 Loss of the corresponding system private key SK MSA1 Even if cracked by a quantum computer, the public and private keys of other users, such as A2 and A3, will not be compromised. Furthermore, after each authentication, users can obtain a new anonymous identity from their respective commercial banks. This process protects user privacy and makes user information more secure.
[0099] The process of identity authentication between users B1, B2, B3 and the commercial bank digital currency system B is the same as above. For example, after user B1 completes identity authentication with the commercial bank digital currency system B, there is a session key KS B-B1 .
[0100] S4. Conducting offline digital currency transactions between different users (using an offline digital currency transaction method to achieve offline digital currency transactions between different users);
[0101] The following example uses a digital currency transaction between user A1 and user B1. The process for digital currency transactions between other users is similar.
[0102] User A1 is an offline member in the transaction and communicates with B1 in close proximity to conduct digital currency transactions.
[0103] Users A1 and B1 exchange information through short-range communication. The sender's information includes the sender's anonymous ID; the receiver's information includes the receiver's anonymous ID.
[0104] Flowchart as Figure 2 The specific steps are described as follows:
[0105] S41. A1 signs to obtain a signed transaction (the sending user terminal signs to obtain a signed transaction and sends the signed transaction to the receiving user terminal);
[0106] Specifically, client A1 calculates the symmetric key K between itself and A. A1-A =e(SK A1 , PK A ). Use K A-CA Encrypt the signature time T to obtain the final key K T =MAC(T,K A1-A The message to be signed is the transaction TX, which includes the sender information, receiver information, digital currency and other transaction information. A1 , T and TX together as MSG′ A1 , which can be expressed as MSG′ A1 =ID A1 ||T||TX.
[0107] Use A1's private key SK A1 MSG A1 Calculate the signature based on ID cryptography to get SIG′ A1 =SIGN(MSG′ A1 , SK A1 )=(UMSG′ A1 , VMSG′ A1 ).
[0108] Use K T TX||SIG′ A1 Encrypt to get {TX||SIG′ A1}K T . Together with ID A1 Together with T as TXS, it can be expressed as TXS = ID A1 ||T||{TXllSIG′ A1}K T A1 sends TXS to B1 via short-range communication.
[0109] S42. B1 receives the signed transaction and forwards it to A (the receiving user terminal receives the signed transaction and forwards it to the receiving commercial bank digital currency system corresponding to the receiving user terminal, which then forwards it to the sending commercial bank digital currency system corresponding to the sending user terminal via the central bank digital currency system);
[0110] Specifically, after B1 receives the session key KS between it and B B-B1 Send TXS to B under the protection of .
[0111] The session key KS between B and S S-B The real identity of TXS and B1 is sent to S under the protection of .
[0112] The session key KS between S and AS-A Send TXS to A under the protection of .
[0113] S43. A verifies the transaction and forwards it to the central bank (the sending commercial bank digital currency system receives the verification transaction, generates change information corresponding to the sending user end, and forwards it to the central bank digital currency system at the same time);
[0114] Specifically, after A receives TXS, KMSA in A calculates the system private key SK for A1 MSA1 =MAC(ID A1 , SK MSA ), further calculate the private key SK for A1 AA1 =SK MSA1 *PK A . Calculate the symmetric key K between A1 and A-A1 =e(SK AA1 , PK A1 ). According to ID cryptography, we can get:
[0115] K A-A1 =e(SK AA1 , PK A1 )=e(SK MSA1 *PK A , PK A1 )=e(PK A , SK MSA1 *PK A1 )=e(PK A , SK A1 )=e(SK A1 , PK A )=K A1-A Using K A-A1 Calculate the message authentication code for T to get K′ T =MAC(T,K A-A1 ). Use K′ T Decrypt {TX||SIG′ A1}K T , get TX and SIG′ A1 .
[0116] Use PK A1 Verification SIG′ A1 , confirming that the message came from A1, according to ID A1 Find its real identity A1INFO. If the verification fails, the authentication failure message is recorded as RET. If the verification succeeds, A generates a new anonymous identity ID for A1 A1new , calculate KMSA pair ID A1new System private key SK MSA1new =MAC(ID A1new , SKMSA ), system public key PK MSA1new =SK MSA1new *P, calculation ID A1new Public key PK A1new =H1(ID A1new ), private key SK A1new =SK MSA1new *PK A1new A will authenticate the successful message and use K′ T The encrypted next identity information of A1 is {ID A1new ||PK MSA1new ||SK A1new}K′ T The combination is called RET, using SK A Sign T||RET based on ID cryptography to obtain SIG″ A =SIGN(T||RET,SK A ). Use K′ T RET and SIG A Encrypt to get RET′ A ={RET||SIG″ A}K′ T .
[0117] A will A1INFO||T||TX||RET||RET′ A The session key KS between S S-A Sent to S under the protection of .
[0118] S44. The central bank verifies the transaction and forwards it (the central bank digital currency system receives the transaction and verifies it, and records the change in ownership of the digital currency after the transaction is successful, and forwards it to the recipient's commercial bank digital currency system. After the recipient's commercial bank digital currency system receives the transaction and verifies it, it generates change information corresponding to the recipient's user terminal and forwards it to the recipient's user terminal. After the recipient's user terminal receives the transaction and verifies it, it saves the digital currency in the transaction and the recipient's user terminal's next identity information, and forwards a message with the signature time and change information to the sender's user terminal);
[0119] Specifically, S receives A1INFO||T||TX||RET||RET′ A After that, record the ownership change of digital currency after the transaction is successful, and then T||TX||RET||RET′ A The session key KS between B and S-B Sent to B under the protection of .
[0120] After receiving the message, B verifies the central bank's message. If the verification fails, the authentication failure message is recorded as RETB If the verification is successful, B generates a new anonymous ID for B1 B1new , calculate KMSB pair ID B1new System private key SK MSB1new =MAC(ID B1new , SK MSB ), system public key PK MSB1new =SK MSB1new *P, calculation ID B1new Public key PK B1new =H1(ID B1new ), private key SK B1new =SK MSB1new *PK B1new B will send the authentication success message and B1's next identity information, i.e. ID B1new ||PK MSB1new ||SK B1new The combination is called RET B .
[0121] B will T||TX||RET B ||RET′ A The session key KS between B1 and B-B1 After receiving the message, B1 verifies B's message and saves the digital currency in TX and B1's next identity information, i.e., ID B1new ||PK MSB1new ||SK B1new , then T||RET A Send to A1.
[0122] S45, A1 confirms the transaction (the sending user terminal receives the message and verifies it, and confirms the transaction result after verification. When the transaction is successful, the sending user terminal stores the next identity information);
[0123] Specifically, A1 uses K T Decrypting RET′ A Get RET and SIG A , using PK A About SIG A After verification, confirm the transaction result. If the transaction is successful, A1 stores the next identity information, i.e. ID A1new ||PK MSA1new ||SK A1new .
[0124] As can be seen from the above process, the public key of the ID cryptography-based system is not disclosed, and the digital signature based on ID cryptography is protected by a symmetric key. Therefore, this process is resistant to quantum computer attacks on ID cryptography. Furthermore, after each transaction, A1 and B1 can obtain new anonymous identities from their respective commercial banks. Moreover, during each digital currency transaction, the actual transaction content is encrypted with a symmetric key. Therefore, this process can protect transaction privacy and make user transactions more secure.
[0125] According to another aspect of the present invention, Figure 3 As shown, a quantum-resistant, sender-side, offline anonymous transaction system is provided. This system consists of a central bank digital currency system, a commercial bank digital currency system (which can be multiple commercial bank digital currency systems in practice), and a user terminal. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, as well as between the commercial bank digital currency system and the user, is based on the theory of ID cryptography. The central bank digital currency system is used to generate and issue digital currency and register its ownership; the commercial bank digital currency system is used to perform banking functions for digital currency; and the user terminal is the main user of digital currency.
[0126] The central bank digital currency system is denoted as S, and its ID is ID S , with quantum-resistant device T S , T S A key management server KMS based on ID cryptography is deployed in the system;
[0127] The commercial bank digital currency system is denoted as A, B, C..., and their IDs are ID A 、ID B 、ID C ..., each with a quantum-resistant computing device T A 、T B 、T C ..., issued by KMS. A 、T B 、T C ...and the key management servers KMSA, KMSB, and KMSC based on ID cryptography are deployed on them respectively;
[0128] Commercial bank digital currency system A includes users A1, A2, A3, etc., whose current anonymous identities are ID A1 、ID A2 、ID A3 ..., the commercial bank digital currency system B includes users B1, B2, B3..., whose current anonymous identities are ID B1 、ID B2、ID B3 .... The user's anonymous identity can be updated by the digital currency system of the commercial bank to achieve the purpose of confidential communication. The real ID of all users is stored in the corresponding commercial bank, which has a corresponding table of real ID and current anonymous identity. All users also have quantum-resistant computing devices T A1 、T A2 、T A3 、T B1 、T B2 、T B3 ..., issued by KMSA and KMSB respectively.
[0129] Anti-quantum computing devices can be key cards, mobile terminals, cipher machines, gateways, etc., which can communicate with the bank currency system or each user terminal through the mainboard interface, short-range wireless communication, controllable intranet communication, etc., to ensure that information will not be stolen by quantum computers within the communication range. For example, the anti-quantum computing device can be a key card plugged into the host motherboard of the bank currency system, or the anti-quantum computing device can be a mobile terminal that conducts NFC communication with two mobile terminals, or the anti-quantum computing device can be a cipher machine or gateway that conducts secure intranet communication with PC hosts on the same intranet.
[0130] When issuing public and private keys to a member, you first need to establish a set of system parameters based on ID cryptography. The steps are as follows:
[0131] (1) G1 and G2 are GDH (Diffie-Hellman) groups of order q, where q is a large prime number. G1 is an additive cyclic group consisting of points on an elliptic curve, and P is a generator of group G1. G2 is a multiplicative cyclic group. The bilinear map e: G1×G1→G2.
[0132] (2) Randomly take SK MS ∈Z p * As the system private key of the central bank digital currency system, SK MS The system public key PK of the central bank digital currency system is calculated only in the quantum-resistant computing device of the central bank digital currency system. MS =SK MS *P,PK MS Quantum-resistant computing device T stored in the central bank digital currency system S KMS has different public and private keys for each commercial bank digital currency system. For A, KMS will generate a unique code as ID A , A's system private key is SK MSA , the system private key can be a true random number or calculated, such as SK MSA =MAC(IDA , SK MS )(MAC(m, k) is the message authentication code calculated using key k for message m), A's system public key is PK MSA =SK MSA *P; For B, KMS will generate a unique code as ID B , B's system private key is SK MSB , the system private key can be a true random number or calculated, such as SK MSB =MAC(ID B , SK MS ), B's system public key is PK MSB =SK MSB *P; The system private key is stored in the quantum-resistant computing device of the central bank digital currency system, and the system public key is stored in the quantum-resistant computing device of the corresponding commercial bank digital currency system, namely PK MSA Save in T A PK MSB Save in T B If the system private key is a true random number, KMS stores the system private key and its corresponding user ID in the database and directly accesses it when needed. If the system private key is calculated, KMS generates it in real time when needed without storage. The following embodiments take the system private key obtained by calculation as an example.
[0133] (3) When KMS issues public and private keys to S, it generates a unique code as ID S , call hash function H1 to calculate the public key PK S =H1(ID S ), then according to the public key PK S Calculate the private key SK S =SK MS *PK S , S's ID and public / private key, namely ID S PK S SK S Quantum-resistant computing device T stored in S S .
[0134] When KMS issues a public and private key to A, it calls the hash function H1 to calculate the public key PK A =H1(ID A ), then according to the public key PK A Calculate the private key SK A =SK MSA *PK A , A's ID and public and private keys, namely ID A PK A SK A Quantum-resistant computing device T stored in A AThe process of KMS issuing public and private keys to other commercial banks such as B, C, etc. is similar.
[0135] (4) KMSA randomly takes SK MSA0 ∈Z p * As the system private key of the commercial bank digital currency system A, SK MSA0 Only stored in A's quantum-resistant computing device, the system public key PK of the commercial bank digital currency system is calculated MSA0 =SK MSA0 *P,PK MSA0 Quantum-resistant computing device T stored in the commercial bank digital currency system A middle.
[0136] KMSA has different system public and private keys for each user. The system private key for A1 is SK MSA1 =MAC(ID A1 , SK MSA0 ), the system public key of A1 is PK MSA1 =SK MSA1 *P; the system private key for A2 is SK MSA2 =MAC(ID A2 , SK MSA0 ), the system public key of A2 is PK MSA2 =SK MSA2 *P, KMSA calculates the public and private keys of other users in a similar way. The private key of the system based on KMSA is stored in A’s quantum-resistant computing device, and the public key of the system based on KMSA is stored in the quantum-resistant computing device of the corresponding user end, that is, PK MSA1 Save in T A1 PK MSA2 Save in T A2 The calculation method of KMSB, KMSC, etc. for the system public and private keys of different users is similar.
[0137] (5) When KMSA issues public and private keys to user A1, it calls the hash function H1 to calculate the public key PK A1 =H1(ID A1 ), then according to the public key PK A1 Calculate the KMSA-based private key SK A1 =SK MSA1 *PK A1 , A1's ID and public / private key, i.e. ID A1 PK A1 SK A1 Quantum-resistant computing device T stored in A1 A1The process by which the KMSA issues public and private keys to other users, such as A2, A3, etc., is similar. Other key management servers, such as KMSB and KMSC, issue public and private keys to their respective users in a similar manner.
[0138] In summary, with the help of the above technical solution of the present invention, the present invention can realize the digital currency anonymous transaction method with the sender offline based on ID cryptography that is resistant to quantum computing; in addition, the present invention does not need to generate an asymmetric key pool from the public keys of all members and then store it in each key card. The client key card only needs to store the key related to itself, so the storage cost and operation workload of the key card are small; in addition, the present invention does not change the overall process and data structure of identity authentication and transaction communication of the traditional digital currency system, but only adds protection based on ID cryptography symmetric keys on the basis of existing technology, so the cost of switching the digital currency communication system to an anti-quantum computing solution is not high; the present invention does not The CA communication system that cannot resist quantum computing is replaced by a key issuance service based on ID cryptography, which not only reduces the complexity of system construction and upgrade, but also enhances the central bank's control over commercial banks. In addition, the key management server in the present invention issues anonymous identities to users. Users use frequently updated anonymous identities to communicate with the commercial bank's digital currency system to protect the user's privacy information, making transactions more secure. In addition, the key issuance server based on ID cryptography of the present invention has different system public and private keys for each different user. Even if a user's system public key is lost and its corresponding system private key is cracked by a quantum computer, it will not endanger the system public and private keys of other users. The various technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the various technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0139] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.
Claims
1. The sender's offline anonymous transaction method based on quantum-resistant computing is characterized by: The method comprises the following steps: S1. Use the key management server to issue system public and private keys and public and private keys to the central bank digital currency system, commercial bank digital currency system, and users respectively; S2. Implement identity authentication between the commercial bank digital currency system and the central bank digital currency system using an identity authentication method; S3. Implementing identity authentication between the user and the commercial bank digital currency system according to an identity authentication method, and obtaining a new anonymous identity for the user; S4. Implementing offline digital currency transactions between different users using an offline digital currency transaction method; When the key management server corresponding to the central bank digital currency system issues the system public and private keys for the central bank digital currency system, it takes a random number as the system private key, then calculates the system public key based on the system private key, and stores the system private key and the system public key in the quantum-resistant computing device of the central bank digital currency system; When the key management server corresponding to the central bank digital currency system issues public and private keys for the central bank digital currency system, it calls a hash function to calculate the public key, then calculates the corresponding private key based on the public key, and stores the ID of the central bank digital currency system and the public and private keys in the quantum-resistant computing device of the central bank digital currency system; When the key management server corresponding to the central bank digital currency system issues the system public and private keys to the commercial bank digital currency system, it calculates the message authentication code to obtain the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the central bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding commercial bank digital currency system; When the key management server corresponding to the central bank digital currency system issues public and private keys to the commercial bank digital currency system, it calls the hash function to calculate the public key, then calculates the private key based on the public key, and stores the ID of the commercial bank digital currency system and the public and private keys in the quantum-resistant computing device of the commercial bank digital currency system; When the key management server corresponding to the commercial bank digital currency system issues the system public and private keys to the user, it takes a random number as the corresponding system private key, then calculates the system public key based on the system private key, and stores the system private key in the quantum-resistant computing device of the commercial bank digital currency system, and stores the system public key in the quantum-resistant computing device of the corresponding user terminal; When the key management server corresponding to the commercial bank digital currency system issues public and private keys to the user, it calls the hash function to calculate the public key, and then calculates the private key based on the key management server corresponding to the commercial bank digital currency system based on the public key, and stores the user's ID and the public and private keys in the user's quantum-resistant computing device.
2. The sender offline anonymous transaction method based on quantum computing according to claim 1 is characterized in that: The S2 uses the identity authentication method to implement identity authentication between the commercial bank digital currency system and the central bank digital currency system, including the following steps: S21. Send the identity information of the commercial bank digital currency system to be authenticated to the central bank digital currency system; S22. The central bank digital currency system receives the identity information and performs authentication, and returns the authentication result to the commercial bank digital currency system. When the authentication result is successful, it includes the corresponding session key. S23. The commercial bank digital currency system receives the authentication result and performs verification. When the authentication result is successful, the corresponding session key is received.
3. The sender offline anonymous transaction method based on quantum computing according to claim 1 is characterized in that: The S3 implements identity authentication between the user and the commercial bank digital currency system according to the identity authentication method, and obtains the user's new anonymous identity, including the following steps: S31. Send the anonymous identity information of the user to be authenticated to the commercial bank digital currency system and apply for updating and generating a new anonymous identity for the user; S32. The commercial bank digital currency system receives the user's information with an anonymous identity, verifies whether the identity information to be authenticated is the real identity corresponding to the anonymous identity, and returns the authentication result to the user. When the verification is successful, the commercial bank digital currency system generates a new anonymous identity for the user, calculates the system public and private keys and public and private keys of the user's new anonymous identity, and generates a session key. The session key, the authentication success message, the new anonymous identity, the new system public key, and the new private key are combined to obtain the next identity information. At the same time, the key management server corresponding to the commercial bank digital currency system records the correspondence between the user's real identity and the new anonymous identity. When the verification fails, the authentication failure message is called change information, and the timestamp is obtained to obtain the corresponding sent message. S33. The user receives the authentication result and verifies it. When the user's signature verification is successful and the change information carries the message that the commercial bank digital currency system has successfully verified the signature, the session key, new anonymous identity, new system public key and new private key in the next identity information are retrieved. The user replaces the anonymous identity, system public key and private key originally stored in the quantum-resistant computing device with the new anonymous identity, new system public key and new private key, and uses the new anonymous identity as the anonymous identity to be used next time.
4. The sender offline anonymous transaction method based on quantum computing according to claim 1 is characterized in that: The S4 implements the offline digital currency transaction between different users by the sender through the offline digital currency transaction method, including the following steps: S41. The sending user terminal signs the transaction to obtain a signed transaction, and sends the signed transaction to the receiving user terminal; S42: The receiving user terminal receives the signed transaction and forwards it to the receiving commercial bank digital currency system corresponding to the receiving user terminal. The receiving commercial bank digital currency system forwards it to the sending commercial bank digital currency system corresponding to the sending user terminal via the central bank digital currency system. S43. The sending commercial bank digital currency system receives the verification transaction, generates change information corresponding to the sending user terminal, and forwards it to the central bank digital currency system. S44. The central bank digital currency system receives the transaction and verifies it, records the change in ownership of the digital currency after the transaction is successful, and forwards it to the recipient's commercial bank digital currency system. After receiving the transaction and verifying it, the recipient's commercial bank digital currency system generates change information corresponding to the recipient's user terminal and forwards it to the recipient's user terminal. After receiving the transaction and verifying it, the recipient's user terminal saves the digital currency in the transaction and the recipient's user terminal's next identity information, and forwards a message with the signature time and change information to the sender's user terminal. S45. The sending user terminal receives the message and performs verification, and confirms the transaction result after verification. When the transaction is successful, the sending user terminal stores the next identity information.
5. The sender offline anonymous transaction method based on quantum computing according to claim 4 is characterized in that: The sending user terminal is an offline member, and the sending user terminal and the receiving user terminal exchange information through short-range communication, wherein the sending party information includes the sending party's anonymous ID, and the receiving party information includes the receiving party's anonymous ID.
6. The sender offline anonymous transaction method based on quantum computing according to claim 4 is characterized in that: The S43 further includes the following steps: The signature is verified using the user's public key to confirm that the message comes from the sender's user terminal, and the real identity is found based on the anonymous identity. When the verification fails, the message of failed authentication is called the change information corresponding to the sender's user terminal. When the verification is successful, the digital currency system of the sender's commercial bank generates a new anonymous identity for the sender's user terminal, and calculates the system public and private keys and public and private keys of the sender's new anonymous identity. The new anonymous identity, new system public key and new private key of the sender's user are combined to obtain the next identity information of the sender's user. The digital currency system of the sender's commercial bank combines the authentication success message and the next identity information of the sender's user to obtain the change information corresponding to the sender's user terminal, and performs a signature based on ID cryptography.
7. The sender offline anonymous transaction method based on quantum computing according to claim 4 is characterized in that: The S44 further includes the following steps: The receiving commercial bank digital currency system verifies the message of the central bank digital currency system. When the verification fails, the authentication failure message is called the change information corresponding to the receiving user terminal. When the verification is successful, the receiving commercial bank digital currency system generates a new anonymous identity for the receiving user terminal, and calculates the system public and private keys and public and private keys of the new anonymous identity of the receiving user terminal, and combines the receiving user's new anonymous identity, the new system public key and the new private key to obtain the receiving user's next identity information. The receiving commercial bank digital currency system combines the authentication success message and the receiving user terminal's next identity information to obtain the change information corresponding to the receiving user terminal.
8. A sender offline anonymous transaction system based on quantum computing, used to implement the steps of the sender offline anonymous transaction method based on quantum computing according to any one of claims 1 to 7, characterized in that: The system includes a central bank digital currency system, a commercial bank digital currency system, and users. Identity authentication between the central bank digital currency system and the commercial bank digital currency system, and identity authentication between the commercial bank digital currency system and users are both based on the theory of ID cryptography. The central bank digital currency system is used to produce and issue digital currency, and is also used to register the ownership of digital currency; The commercial bank digital currency system is used to perform banking functions for digital currency; The user is the user of the digital currency.
9. The sender offline anonymous transaction system based on quantum computing according to claim 8 is characterized in that: Both the central bank digital currency system and the commercial bank digital currency system are equipped with corresponding anti-quantum computing devices, and corresponding key management servers based on ID cryptography are deployed in the anti-quantum computing devices. The users are also equipped with corresponding anti-quantum computing devices, and the anti-quantum computing device of the commercial bank digital currency system is issued by the key management server of the central bank digital currency system, and the anti-quantum computing device of the user is issued by the key management server of the commercial bank digital currency system.
10. The sender offline anonymous transaction system based on quantum computing according to claim 9 is characterized in that: The quantum-resistant computing device includes but is not limited to a key card, a mobile terminal, a cryptographic machine and a gateway, and the quantum-resistant computing device can communicate with the bank's monetary system or each user terminal separately. The communication includes but is not limited to multiple communication methods such as mainboard interface communication, short-range wireless communication and controllable intranet communication.
Citation Information
Patent Citations
An antiquantum computing HTTPS communication method and system based on an asymmetric key pool
CN109861813A
Digital currency provision method and system
CN107230049A
Node data processing of quantum attack resistant block chain
CN109672518A