A transparent method and system for implicit certificates

Through the transparent method of implicit certificates, the overhead of the certificate transparency scheme is reduced by using public key reconstruction values, solving the problem of excessive space and calculation overhead of the certificate transparency scheme in resource-constrained environments, and improving the mitigation effect of attacking false certificates.

CN114611078BActive Publication Date: 2025-05-13INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011409117.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-03
Publication Date
2025-05-13
Estimated Expiration
2040-12-03

AI Technical Summary

Technical Problem

In resource-constrained environments, traditional certificate transparency solutions are difficult to effectively reduce the risk of attacks on false certificates due to the excessive space and computing overhead caused by the signature of the public log server.

Method used

Through the transparent method of implicit certificates, the digital signature and the public key are combined into one by using the public key reconstruction value, reducing the space and computing overhead of the signature of the certificate transparency of the public log server.

Benefits of technology

It realizes the overhead of certificate transparency solutions in resource-constrained environments, and improves the mitigation effect of attacking false certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114611078B_ABST
    Figure CN114611078B_ABST
Patent Text Reader

Abstract

The present invention discloses a transparent method and system for implicit certificates, which supports submitting implicit certificates to multiple certificate transparency public log servers and is compatible with implicit certificate verification that does not support certificate transparency. The present invention makes implicit certificates transparent without incurring new signature and signature verification overhead, and does not need to verify separately whether to submit to a single public log server. While verifying whether the implicit certificate is valid, it can verify whether to submit to multiple public log servers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of identity authentication, and in particular, relates to a method and system for making implicit certificates transparent. Background Art

[0002] With the development of industrial Internet of Things, the identity authentication of devices in the Internet of Things and the confidential transmission of data need to be guaranteed. For IoT nodes with limited computing power and storage space, the overhead of using explicit certificates such as X.509 certificates is too high, while implicit certificates are smaller in size and faster in verification, making them more suitable for identity authentication in resource-constrained environments. In traditional explicit certificates, the public key and digital signature are different data, while in implicit certificates, the public key and digital signature are combined into one and represented by the public key reconstruction value. A typical implicit certificate authentication scheme is ECQV (Elliptic Curve Qu-Vanstone), whose mathematical basis is the elliptic curve theory.

[0003] The Certificate Authority (CA) is a widely trusted entity in the public key infrastructure. It binds the identity information of the certificate subject and the public key by issuing certificates. The identity information in the digital certificate is strictly reviewed by the CA to ensure its authenticity. The CA's strict review of certificate information and secure management of signature keys are the basis for the safe operation of the public key infrastructure system.

[0004] However, some CA misoperation incidents and attacks on CAs have shown that CAs may issue "fake certificates". Fake certificates can be verified, but the actual holder of the key in the certificate is not the subscriber claimed by the certificate. "Fake certificates" can be used by adversaries to launch identity fraud attacks, invade the communication between servers and users, and destroy the data security of sites and users. More seriously, since CAs are trusted by everyone, any CA that issues fake certificates and is successfully attacked will pose a threat to the entire public key infrastructure system.

[0005] In order to mitigate the possible attacks caused by issuing fake certificates, the industry has proposed a certificate transparency scheme. In the certificate transparency scheme, all legitimate certificates are publicly visible to everyone. The CA submits the certificate it issues to a public log server, and the public log server proves that the certificate has been submitted to the public log server by adding its own signature to the certificate content. In a resource-constrained environment, the overhead caused by the signature of the public log server in the certificate is too high, and multiple public log servers will bring multiple signatures. It is necessary to design a transparent method for implicit certificates to reduce the overhead caused by the signature of the public log server. Summary of the invention

[0006] To solve the above problems, the present invention provides a method for making implicit certificates transparent. By combining the digital signature and the public key into one as the public key reconstruction value in the implicit certificate, the space overhead and computing overhead brought by the transparent public log server signature of the certificate are reduced.

[0007] The technical contents of the present invention include:

[0008] A transparent implicit certificate generation method is applicable to a system consisting of a user, a certificate authentication center, and w certificate transparency log servers, w ≥ 1, wherein the certificate authentication center generates a public-private key pair (q ca , Q ca ), each certificate transparency log server generates a public and private key pair The steps include:

[0009] 1) The certificate authentication center generates a temporary public key P ca With the received temporary public key P u , temporary public key Generate and broadcast the public key reconstruction value R ct , where the temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and temporary public and private key pairs It is generated by the certificate authentication center, the user and each certificate transparency log server, 1≤i≤w;

[0010] 2) Reconstruct the value R based on the received user information and certificate transparency log server information, the timestamp of submitting the certificate to the certificate transparency log server, and the public key ct Generate a user certificate Cert u , and based on the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca , the user certificate Cert u Send to each certificate transparency log server so that each certificate transparency log server can disclose and store user certificates Cert u ;

[0011] 3) Receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct , and the user certificate Cert u Reconstruct the value r with the private key ct Sent to the user so that the user can obtain the user certificate Certu and generate public and private key pairs that support certificate transparency (q u , Q u );

[0012] Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

[0013] Furthermore, the elliptic curve includes: elliptic curve secp256k1.

[0014] Furthermore, the public key reconstruction value

[0015] Further, the private key reconstruction value r is generated by the following steps: ca :

[0016] 1) Calculate the user certificate Cert u The hash value of e = H(Cert u ), where H is a hash function;

[0017] 2) Calculate the private key reconstruction value r ca =e×k ca +q ca .

[0018] Further, the private key reconstruction value is generated by the following steps:

[0019] 1) Calculate the user certificate Cert u The hash value of e = H(Cert u ), where H is a hash function;

[0020] 2) Calculate the private key reconstruction value

[0021] Furthermore, the hash function includes: SHA-256.

[0022] Furthermore, the private key reconstruction value

[0023] Furthermore, the user generates a public-private key pair that supports certificate transparency through the following steps (q u , Q u ):

[0024] 1) Calculate the user certificate Certu The hash value of e = H(Cert u ), where H is a hash function;

[0025] 2) Calculate the private key q that supports certificate transparency u =e×k u +r ct ;

[0026] 3) Calculate the public key that supports certificate transparency

[0027] A transparent implicit certificate generation system, comprising:

[0028] User, used to generate a temporary public-private key pair (k u , P u );The temporary public key P u Send to the certificate authority; receive the user certificate Cert generated by the certificate authority u Reconstruct the value r with the private key ca ; Generate a public-private key pair that supports certificate transparency (q u , Q u );

[0029] Certificate Authority, used to generate public and private key pairs (q ca, Q ca ) and the temporary public-private key pair (k ca , P ca );Receive the user's temporary public key P u , the temporary public key of each certificate transparency log server User information and each certificate transparent log server information; according to the temporary public key P ca , temporary public key P u With temporary public key According to the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca ; Reconstruct the value R based on user information, certificate transparency log server information, timestamp and public key ct Generate a user certificate Cert u ; Generate private key reconstruction value r ca ; The user certificate Cert u Send to each certificate transparency log server; receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct ; The user certificate Cert u Reconstruct the value r with the private key ctSend to user;

[0030] w certificate transparency log servers, used to generate public and private key pairs Receive the user certificate Cert sent by the certificate authority u ; Will generate private key reconstruction value Return to the certificate authority; send the user certificate Cert u Public and stored, w≥1;

[0031] Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

[0032] A transparent implicit certificate generation method is applicable to a system consisting of a user, a certificate authentication center, and w certificate transparency log servers, w ≥ 1, wherein the certificate authentication center generates a public-private key pair (q ca , Q ca ), each certificate transparent log server public and private key pair The steps include:

[0033] 1) The certificate authentication center generates a temporary public key P ca With the received temporary public key P u , temporary public key Generate and broadcast the public key reconstruction value R ct , based on the temporary public key P ca and the received temporary public key P′ u , generate and broadcast the public key reconstruction value R′ ct , where the temporary public-private key pair (k ca , P ca ) and a temporary public-private key pair The temporary public and private key pair (k u , P u ) and the temporary public-private key pair (k′ u , P′ u ) are generated by users, 1≤i≤w;

[0034] 2) Reconstruct the value R based on the received user information and certificate transparency log server information, the timestamp of submitting the certificate to the certificate transparency log server, and the public key ct and public key reconstruction value R′ ctGenerate user certificate Cert′ u , generate the private key reconstruction value r ca , the user certificate Cert′ u Send to each certificate transparency log server so that each certificate transparency log server can publish and store the user certificate Cert′ u ;

[0035] 3) Receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct , and the user certificate Cert′ u , private key reconstruction value r ct Reconstruct the value r with the private key ca Sent to the user so that the user can obtain the user certificate Cert′ u and generate public and private key pairs that support certificate transparency (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u );

[0036] Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ), temporary public-private key pair (k′ u , P′ u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

[0037] Furthermore, the public key reconstruction value R′ ct =P ca +P′ u .

[0038] Furthermore, the user generates a public-private key pair that supports certificate transparency through the following steps (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u ):

[0039] 1) Calculate the user certificate Cert u The hash value of e = H(Cert′ u ), where H is a hash function;

[0040] 2) Calculate the private key q that supports certificate transparency u =e×k u +r ct ;

[0041] 3) Calculate the public key that supports certificate transparency

[0042] 4) Calculate the private key q′ that does not support certificate transparency u =e×k′ u +r ca ;

[0043] 5) Calculate the public key Q′ that does not support certificate transparency u =e×R′ ct +Q ca .

[0044] Further, when the user certificate holder verifies his identity by signing a specific message with a certificate, the elliptic curve signature (x, s, s′) is sent to the signature verifier for identity verification; if the signature verifier supports certificate transparency verification, the elliptic curve signature (x, s) is verified; if the signature verifier does not support certificate transparency verification, the elliptic curve signature (x, s′) is verified; the elliptic curve signature (x, s, s′) is generated by the following steps:

[0045] 1) Generate a key pair (k, P) based on the elliptic curve;

[0046] 2) Get the x-axis coordinate of point P on the elliptic curve and obtain the parameter x;

[0047] 3) Calculate s = k -1 (m+x×q u ) mod n, where m is the hash value of the message to be signed and n is the elliptic curve parameter;

[0048] 4) Calculate s′=k -1 (m+x×q′ u )mod n.

[0049] A transparent implicit certificate generation system, comprising:

[0050] User, used to generate a temporary public-private key pair (k u , P u ) and the temporary public-private key pair (k′ u , P′ u );The temporary public key P u With the temporary public key P′ u Send to the certificate authentication center; receive the user certificate Cert′ generated by the certificate authentication center u , private key reconstruction value r ctReconstruct the value r with the private key ca ; Generate a public-private key pair that supports certificate transparency (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u );

[0051] Certificate Authority, used to generate public and private key pairs (q ca , Q ca ) and the temporary public-private key pair (k ca , P ca );Receive the user's temporary public key P u With the temporary public key P′ u , the temporary public key of each certificate transparency log server User information and information of each certificate transparency log server; based on user information, certificate transparency log server information, timestamp of submitting certificate to certificate transparency log server, public key reconstruction value R ct and public key reconstruction value R′ ct Generate user certificate Cert′ u ; Generate private key reconstruction value r ca ; User certificate Cert′ u Send to each certificate transparency log server; receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct ; The user certificate Cert u , private key reconstruction value r ct Reconstruct the value r with the private key ca Send to user;

[0052] w certificate transparency log servers, used to generate public and private key pairs Receive the user certificate Cert′ sent by the certificate authority u ; Will generate private key reconstruction value Return to the certificate authority; send the user certificate Cert′ u Public and stored, w≥1;

[0053] Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ), temporary public-private key pair (k′ u , P′u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

[0054] Compared with the prior art, the advantages of the present invention include:

[0055] 1) While making implicit certificates transparent, there is no need to incur new signature and signature verification overhead;

[0056] 2) After the implicit certificate is submitted to multiple certificate transparency log servers, it is not necessary to verify whether it is submitted to a single certificate transparency log server separately. When verifying whether the implicit certificate is valid, it is possible to verify whether it is submitted to multiple certificate transparency log servers. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is a framework diagram of the implicit certificate transparency method of the present invention.

[0058] Figure 2 This is a schematic diagram of the main contents of a certificate that is compatible with a certificate that does not support certificate transparency in an example.

[0059] Figure 3 A flowchart of a user requesting a certificate authority to issue a certificate in an example.

[0060] Figure 4 A schematic diagram of an example in which a certificate authentication center submits a user certificate to a public log server. DETAILED DESCRIPTION

[0061] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described below through specific embodiments.

[0062] A transparent method for implicit certificates, such as Figure 1 As shown, it is applied between the user, the certificate authentication center and the certificate transparency log server, and includes the following steps:

[0063] 1) Generate elliptic curve parameters (p, a, b, G, n, h);

[0064] 2) Generate the private key q of the certificate authority ca 、Public key Q ca , and the private key q of the certificate transparency log server log 、Public key Q log ;

[0065] 3) The user generates a temporary public-private key pair (k u , P u ), when applying for a certificate, the user information and temporary public key P u Send to the certificate authority;

[0066] 4) The certificate authority generates a temporary public and private key pair (k ca , P ca ), the certificate transparency log server generates a temporary public and private key pair (k log , P log ) and the temporary public key P log Send to the certificate authority;

[0067] 5) The certificate authentication center uses the user's temporary public key P u , your temporary public key P ca And the temporary public key P of the certificate transparency log server log , generate the public key reconstruction value R for the user certificate ct ;

[0068] 6) The certificate authentication center reconstructs the timestamp and public key value R of the certificate submitted to the certificate transparency log server based on the user information and the certificate transparency log server information. ct Generate a user certificate Cert u , and generate a private key reconstruction value r for the user certificate ca , where the information of the certificate transparency log server is stored in advance in the certificate authentication center or obtained through public channels;

[0069] 7) The certificate authentication center submits the issued user certificate to the certificate transparency log server. The certificate transparency log server checks the received user certificate and uploads it to the public server, and then generates a private key reconstruction value r for the user certificate. log And send it to the certificate authority;

[0070] 8) The certificate authority reconstructs the value r based on the private key ca and the private key reconstruction value r generated by the certificate transparency log server log , generate the private key reconstruction value r ct Sent to the user together with the user certificate.

[0071] Furthermore, all public-private key pairs (including temporary public-private keys) mentioned in the present invention are generated based on the same elliptic curve parameters and use the same secure hash function.

[0072] Furthermore, the user certificate Cert u The timestamp in is the time when the certificate authority submits the user certificate to the certificate transparency log server.

[0073] Furthermore, the specific method for the certificate authentication center to generate a public key reconstruction value for the user certificate is as follows: ct =P ca +Pu +P log .

[0074] Furthermore, the certificate authority generates a private key reconstruction value r for the user certificate. ca The specific method is:

[0075] 1) Use the hash function H to calculate the user certificate Cert u The hash value e, that is, e = H (Cert u );

[0076] 2) Calculate the private key reconstruction value r ca =e×k ca +q ca , where k ca Indicates a temporary private key generated by a certificate authority.

[0077] Furthermore, the certificate transparency log server generates a private key reconstruction value r for the user certificate. log The specific method is:

[0078] 1) Use the hash function H to calculate the user certificate Cert u The hash value e, that is, e = H (Cert u );

[0079] 2) Calculate the private key reconstruction value r log =e×k log +q log , where k log Indicates the temporary private key generated by the Certificate Transparency log server.

[0080] Furthermore, the certificate authority can ca and r log Generate private key reconstruction value r ct The specific method is r ct =r ca +r log .

[0081] Optionally, there may be multiple certificate transparency log servers in the method. Assuming that the certificate authentication center submits the user certificate to w certificate transparency log servers, the w certificate transparency log servers generate temporary public and private key pairs respectively. And the temporary public key Sent to the certificate authority, after receiving the user certificate Cert submitted by the certificate authority u After that, generate the private key reconstruction value for the user certificate And send it to the certificate authority.

[0082] Furthermore, the certificate authority reconstructs the public key value generated for the user certificate Generated private key reconstruction value

[0083] Optionally, when the user certificate needs to be compatible with the certificate verifier that does not support certificate transparency, the user generates a second temporary public-private key pair (k′) based on the same elliptic curve. u , P′ u ) and P′ u It is also sent to the certificate authority, which generates another public key reconstruction value R′=P for the user certificate. ca +P′ u The value of R' is added to the user's certificate content, and the certificate authority will also reconstruct the private key value r corresponding to R' ca Sent to the user, the user will generate a private key q that supports certificate transparency u and the private key q′ that does not support certificate transparency u .

[0084] Furthermore, it is characterized in that the user generates a private key q that supports certificate transparency u The private key q′ that does not support certificate transparency u The specific method is:

[0085] 1) Use the hash function H to calculate the user certificate Cert u The hash value e, that is, e = H (Cert u );

[0086] 2)q u =e×k u +r ct ;

[0087] 3)q′ u =e×k′ u +r ca .

[0088] Furthermore, it is characterized in that the user generates a public key Q supporting certificate transparency u and a public key Q′ that does not support certificate transparency u The specific method is:

[0089] 1) Use the hash function H to calculate the user certificate Cert u The hash value e, that is, e = H (Cert u );

[0090] 2)

[0091] 3) Q′ u =e×R′ ct +Q ca .

[0092] Optionally, when the user certificate holder verifies his identity by signing a specific message with a certificate, if it is unknown whether the signature verifier supports certificate transparency, the two private keys of the user certificate can be used to generate an ECDSA signature (x, s, s′) and send it to the signature verifier for identity verification. The specific method of generating an elliptic curve (ECDSA) signature (x, s, s′) is as follows:

[0093] 1) Generate an elliptic curve key pair (k, P);

[0094] 2) Calculate s = k -1 (m+x×q u )mod n;

[0095] 3) Calculate s′=k -1 (m+x×q′ u )mod n;

[0096] Where m is the hash value of the message to be signed, n is the elliptic curve parameter, and x is the x-axis coordinate of point P.

[0097] Furthermore, if the signature verifier supports certificate transparency, the user's public key Q u Verify the ECDSA signature (x, s). If the signature verifier does not support certificate transparency, use the user's public key Q′ u Verify ECDSA signature (x, s′).

[0098] The present invention is compatible with certificates that do not support certificate transparency, such as Figure 2 As shown, there are two public key reconstruction values ​​R ct and R′, and the certificate authentication center submits the user certificate to two certificate transparency log servers. The public log server mentioned in this example refers to the certificate transparency server. In this example, the elliptic curve secp256k1 is used, and the hash function used should also be a hash function that is widely considered to be secure. In this example, SHA-256 is used, which is represented by H in the following examples. The public and private key pair of the certificate authentication center is denoted by (q ca , Q ca ) indicates that the public and private key pair of the public log server 1 is (q l1 , Q l1 ) indicates that the public and private key pair of the public log server 2 is (q l2 , Q l2 ) indicates that Q ca =q ca G, Q l1 =q l1 G, Q l2 =q l2 G. The certificate content generated by the certificate authentication center for the user is Cert uIndicates that the user certificate Cert u The hash value of e = H(Cert u ). In this example, CA is used to represent the certificate authority, Log 1 Indicates public log server 1, Log 2 Indicates public log server 2.

[0099] The specific process of this example is divided into two parts. Figure 3 and Figure 4 shown.

[0100] like Figure 3 As shown, the user generates his own temporary public-private key pair (k u , P u ), (k′ u , P′ u ), where k u and k′ u Generated by the user's own random number generator, P u =k u G, P′ u = k′ u G. The user will use the temporary public key P u , P′ u The identity information required in the certificate is sent to the CA to request the issuance of a certificate and obtain the private key reconstruction value r ct and r ca After receiving the user's certificate request, the CA will review the user's certificate request information. Figure 3 The process shown generates a certificate Cert for the user u , and the private key reconstruction value r ct and r ca And send it to the user. The value r is reconstructed according to the private key ct Exported user private key q u , the corresponding public key derivation method is Q u =e×R ct +Q ca +Q l1 +Q l2 , applying this public and private key pair to the implicit certificate verification method can simultaneously verify that the user certificate is recognized by the CA and submitted to the Log 1 and Log 2 . The address r is reconstructed according to the private key ca Exported user private key q′ u , the corresponding public key export method is Q′ u =e×R′+Q ca , this pair of public and private keys is the public and private key pair of an ordinary implicit certificate that has nothing to do with certificate transparency.

[0101] like Figure 4 As shown, the CA generates a user certificate and submits the user certificate to the Log 1 and Log 2 The specific process is as follows:

[0102] (1) CA generates a temporary public-private key pair (k ca , P ca ), where k ca Generated by CA using a random number generator and P ca =k ca G, Log1 generates a temporary public and private key pair (k l1 , P l1 ), where k l1 By Log 1 Generate using a random number generator and P l1 =k l1 G,Log 2 Generate a temporary public-private key pair (k l2 , P l2 ), where k l2 By Log 2 Generate using a random number generator and P l2 =k l2 G;

[0103] (2) CA to Log 1 and Log 2 Request to obtain the public key reconstruction value, Log 1 and Log 2 P l1 and P l2 Send to CA;

[0104] (3) CA generates a public key reconstruction value R for the user ct =P ca +P u +P l1 +P l2 , another public key reconstruction value R′=P ca +P u , and then reconstruct the user information and public key value R ct and R′, Log 1 and Log 2 The name or ID of the user, as well as the time t when the certificate is to be submitted to the public log server, are all added to the certificate content and a user certificate Cert is generated. u , and then directly Cert u and P l1 Submit to Log 1 , Cert u and P l2 Submit to Log 2,The time submitted to different public log servers is the same;

[0105] (4) CA for user certificate Cert u The hash value e is obtained by hash calculation, and then the private key reconstruction value r is generated ca =e×k ca +q ca ;

[0106] (5)Log 1 After receiving the user certificate Cert u and P l1 After checking that the certificate meets the requirements, according to P l1 Find the corresponding k l1 , then calculate Cert u The hash value e of the private key is used to calculate the reconstruction value r of the private key. l1 =e×k l1 +q l1 , and the certificate identifier is sent to the CA, and then the user certificate Cert u Public in the log server, similarly, Log 2 Perform the same steps to generate the private key reconstruction value r l2 And make the user certificate public in its own log server;

[0107] (6) CA receives the Log 1 and Log 2 Returned r l1 and r l2 After that, check r l1 Is G equal to e×P? l1 +Q l1 , r l2 Is G equal to e×P? l2 +Q l2 , if they are equal, calculate the private key reconstruction value r ct =r ca +r l1 +r l2 ;

[0108] (7) Finally, the CA sends the certificate Cert u , r ca and r ct Issued to the user.

[0109] The above embodiments are provided only for the purpose of describing the present invention, and are not intended to limit the scope of the present invention. The scope of the present invention is defined by the appended claims. Various equivalent substitutions and modifications made without departing from the spirit and principles of the present invention should all be included within the scope of the present invention.

Claims

1. A transparent implicit certificate generation method, applicable to a system consisting of a user, a certificate authentication center, and w certificate transparency log servers, w ≥ 1, wherein the certificate authentication center generates a public-private key pair (q ca , Q ca ), each certificate transparency log server generates a public and private key pair The steps include: 1) The certificate authentication center generates a temporary public key Pca and receives a temporary public key P u , temporary public key Generate and broadcast the public key reconstruction value R ct , where the temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and temporary public and private key pairs It is generated by the certificate authentication center, the user and each certificate transparency log server, 1≤i≤w; 2) Reconstruct the value R based on the received user information and certificate transparency log server information, the timestamp of submitting the certificate to the certificate transparency log server, and the public key ct Generate a user certificate Cert u , and based on the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca , the user certificate Cert u Send to each certificate transparency log server so that each certificate transparency log server can disclose and store the user certificate Cert u ; 3) Receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct , and the user certificate Cert u Reconstruct the value r with the private key ct Sent to the user so that the user can obtain the user certificate Cert u and generate public and private key pairs that support certificate transparency (q u , Q u ); Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

2. The method according to claim 1, characterized in that Elliptic curves include: Elliptic curve secp256k1.

3. The method according to claim 1, characterized in that Public key reconstruction value Generate the private key reconstruction value r by following the steps below ca : 1) Calculate the user certificate Cert u The hash value of e = H(Cert u ), where H is a hash function; 2) Calculate the private key reconstruction value r ca =e×k ca +q ca .

4. The method according to claim 1, characterized in that Generate the private key reconstruction value by following the steps below 1) Calculate the user certificate Cert u The hash value of e = H(Cert u ), where H is a hash function; Hash functions include: SHA-256; 2) Calculate the private key reconstruction value 5. The method according to claim 1, characterized in that Private key reconstruction value The user generates a public-private key pair that supports certificate transparency by following the steps below (q u , Q u ): 1) Calculate the user certificate Cert u The hash value of e = H(Cert u ), where H is a hash function; 2) Calculate the private key q that supports certificate transparency u =e×k u +r ct ; 3) Calculate the public key that supports certificate transparency 6. A transparent implicit certificate generation system, comprising: User, used to generate a temporary public-private key pair (k u , P u );The temporary public key P u Send to the certificate authority; receive the user certificate Cert generated by the certificate authority u Reconstruct the value r with the private key ca ; Generate a public-private key pair that supports certificate transparency (q u , Q u ); Certificate Authority, used to generate public and private key pairs (q ca , Q ca ) and the temporary public-private key pair (k ca , P ca );Receive the user's temporary public key P u , the temporary public key of each certificate transparency log server User information and each certificate transparent log server information; according to the temporary public key P ca , temporary public key P u With temporary public key Generate public key reconstruction value R ca ; Reconstruct the value R based on user information, certificate transparency log server information, timestamp and public key ct Generate a user certificate Cert u ; Based on the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca ; The user certificate Cert u Send to each certificate transparency log server; receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct ; The user certificate Cert u Reconstruct the value r with the private key ct Send to user; w certificate transparency log servers, used to generate public and private key pairs Receive the user certificate Cert sent by the certificate authority u ; Will generate private key reconstruction value Return to the certificate authority; send the user certificate Cert u Public and stored, w≥1; Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

7. A transparent implicit certificate generation method, applicable to a system consisting of a user, a certificate authentication center, and w certificate transparency log servers, w ≥ 1, wherein the certificate authentication center generates a public-private key pair (q ca , Q ca ), each certificate transparent log server public and private key pair The steps include: 1) The certificate authentication center generates a temporary public key Pca and receives a temporary public key P u , temporary public key Generate and broadcast the public key reconstruction value R ct , based on the temporary public key P ca and the received temporary public key P′ u , generate and broadcast the public key reconstruction value R′ ct , where the temporary public-private key pair (k ca , P ca ) and a temporary public-private key pair The temporary public and private key pair (k u , P u ) and the temporary public-private key pair (k′ u , P′ u ) are generated by users, 1≤i≤w; 2) Reconstruct the value R based on the received user information and certificate transparency log server information, the timestamp of submitting the certificate to the certificate transparency log server, and the public key ct and public key reconstruction value R′ ct Generate user certificate Cert′ u , and based on the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca , the user certificate Cert′ u Send to each certificate transparency log server so that each certificate transparency log server can publish and store the user certificate Cert′ u ; 3) Receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct , and the user certificate Cert′ u , private key reconstruction value r ct Reconstruct the value r with the private key ca Sent to the user so that the user can obtain the user certificate Cert′ u and generate public and private key pairs that support certificate transparency (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u ); Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ), temporary public-private key pair (k′ u , P′ u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

8. The method according to claim 7, characterized in that Public key reconstruction value R′ ct =P ca +P′ u ; The user generates a public-private key pair that supports certificate transparency through the following steps (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u ): 1) Calculate the user certificate Cert u The hash value of e = H(Cert′ u ), where H is a hash function; 2) Calculate the private key q that supports certificate transparency u =e×k u +r ct ; 3) Calculate the public key that supports certificate transparency 4) Calculate the private key q′ that does not support certificate transparency u =e×k′ u +r ca ; 5) Calculate the public key Q′ that does not support certificate transparency u =e×R′ ct +Q ca .

9. The method according to claim 7, characterized in that When the user certificate holder verifies his identity by signing a specific message with the certificate, the elliptic curve signature (x, s, s′) is sent to the signature verifier for identity verification; If the signature verifier supports certificate transparency verification, then verify the elliptic curve signature (x, s); if the signature verifier does not support certificate transparency verification, then verify the elliptic curve signature (x, s′); Generate an elliptic curve signature (x, s, s′) by following these steps: 1) Generate a key pair (k, P) based on the elliptic curve; 2) Get the x-axis coordinate of point P on the elliptic curve and obtain the parameter x; 3) Calculate s = k -1 (m+x×q u ) mod n, where m is the hash value of the message to be signed and n is the elliptic curve parameter; 4) Calculate s′=k -1 (m+x×q′ u )mod n.

10. A transparent implicit certificate generation system, comprising: User, used to generate a temporary public-private key pair (k u , P u ) and the temporary public-private key pair (k′ u , P′ u );The temporary public key P u With the temporary public key P′ u Send to the certificate authentication center; receive the user certificate Cert′ generated by the certificate authentication center u , private key reconstruction value r ct Reconstruct the value r with the private key ca ; Generate a public-private key pair that supports certificate transparency (q u , Q u ) and the public-private key pair (q′) that does not support certificate transparency u , Q′ u ); Certificate Authority, used to generate public and private key pairs (q ca , Q ca ) and the temporary public-private key pair (k ca , P ta );Receive the user's temporary public key P u With the temporary public key P′ u , the temporary public key of each certificate transparency log server User information and information of each certificate transparency log server; based on user information, certificate transparency log server information, timestamp of submitting certificate to certificate transparency log server, public key reconstruction value R ct and public key reconstruction value R′ ct Generate user certificate Cert′ u ; Based on the user certificate Cert u and temporary private key k ca Generate private key reconstruction value r ca ; User certificate Cert′ u Send to each certificate transparency log server; receive the private key reconstruction value returned by each certificate transparency log server Reconstruct the value based on each private key Reconstruct the value r with the private key ca Generate private key reconstruction value r ct ; The user certificate Cert u , private key reconstruction value r ct Reconstruct the value r with the private key ca Send to user; w certificate transparency log servers, used to generate public and private key pairs Receive the user certificate Cert′ sent by the certificate authority u ; Will generate private key reconstruction value Return to the certificate authority; send the user certificate Cert′ u Public and stored, w≥1; Among them, the public-private key pair (q ca , Q ca ), public and private key pairs Temporary public-private key pair (k ca , P ca ), temporary public-private key pair (k u , P u ), temporary public-private key pair (k′ u , P′ u ) and a temporary public-private key pair They are independently generated based on the same elliptic curve.

Citation Information

Patent Citations

  • Digital signatures with implicit certificate chains

    CN103733564A

  • Light-weight authentication key negotiation method based on implicit certificate

    CN106411528A