Authentication method, device and equipment
By multiplexing the elliptic curve types determined during the TLS handshake process during the EAP-TLS authentication process for IBS authentication, the complex operation problem caused by the independence of elliptic curve types in the prior art is solved, and a simplified authentication process is realized.
Patent Information
- Application Number
- CN202110001469.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-04
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-01-04
AI Technical Summary
In the prior art, the independence of elliptic curve types during EAP-TLS authentication leads to complex operational processes.
By obtaining the elliptic curve type in the first handshake message sent by the second authentication end, the target elliptic curve type is determined, and the type and public key are sent in the second handshake message, and the same type of signature algorithm is used to perform identity-based digital signature IBS authentication.
The elliptic curve type used in the IBS signature is consistent with the elliptic curve type used in the TLS handshake process, simplifying the operation of the authentication process.
Smart Images

Figure CN114722364B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to an authentication method, device and equipment. Background Art
[0002] The Extensible Authentication Protocol (EAP) was first defined in RFC2284 in 1998, and now there are more than 20 EAP-based authentication methods.
[0003] EAP-Transport Layer Security (TLS) uses X509 certificates to authenticate the identities of both parties in communication. However, in the IoT scenario, the large size of the certificate will lead to a bottleneck problem in EAP-TLS authentication. EAP-TLS-Identity Based Signature (IBS) uses the original public key to replace the X509 certificate. It is a digital signature technology based on the Identity-Based Cryptograph (IBC) technology and can be used for user identity authentication. IBS has the same function as the traditional digital signature, but the difference is that when using IBS, the authenticator directly uses the identity ID of the authenticated party to verify the authenticity of the signature, so there is no need for a complex certificate system, thus solving the problem of too large certificates.
[0004] The existing IBS signature scheme is implemented using elliptic curve cryptography (ECC). However, in the usual technical solution, the elliptic curve type used in the TLS handshake and the elliptic curve type used in the IBS signature are independent, which causes the computational complexity of the authentication process. Summary of the invention
[0005] The technical solution of the present invention aims to provide an authentication method, device and equipment to solve the problem of complex calculation process in the authentication method using the existing technology.
[0006] An embodiment of the present invention provides an authentication method, which is applied to a first authentication end, wherein the method includes:
[0007] Obtaining a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0008] Determining, according to a target elliptic curve type in at least one of the elliptic curve types, a public key of the first authenticator for key negotiation;
[0009] Sending a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key;
[0010] The signature algorithm corresponding to the target elliptic curve type is used to perform identity authentication of the identity-based digital signature IBS with the second authentication end.
[0011] Optionally, the authentication method, wherein the signature algorithm corresponding to the target elliptic curve type is used to perform identity-based digital signature IBS identity authentication with the second authentication end, includes:
[0012] Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message;
[0013] The second certificate indication information includes:
[0014] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0015] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0016] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0017] Optionally, in the authentication method, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0018] Optionally, in the authentication method, the first certificate indication information includes:
[0019] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0020] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0021] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0022] Optionally, in the authentication method, the second certificate indication information further includes:
[0023] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0024] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0025] Optionally, in the authentication method, sending the second certificate indication information to the second authentication end includes:
[0026] Encrypting the second certificate indication information using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message;
[0027] Send the encrypted second certificate indication information to the second authentication end.
[0028] Optionally, the authentication method further comprises:
[0029] Obtaining third certificate indication information sent by the second authentication end;
[0030] The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
[0031] The embodiment of the present invention further provides an authentication method, which is applied to a second authentication end, wherein the method includes:
[0032] Sending a first handshake message to a first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0033] Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type;
[0034] The signature algorithm corresponding to the target elliptic curve type is used to perform identity authentication of the identity-based digital signature IBS with the first authentication end.
[0035] Optionally, the authentication method, wherein the signature algorithm corresponding to the target elliptic curve type is used to perform identity-based digital signature IBS identity authentication with the first authentication end, includes:
[0036] Obtaining second certificate indication information sent by the first authentication end;
[0037] Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information;
[0038] The second certificate indication information includes:
[0039] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0040] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0041] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0042] Optionally, in the authentication method, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0043] Optionally, in the authentication method, the first handshake information includes first certificate indication information, and the first authentication end sends the second authentication indication information according to the first certificate indication information;
[0044] The first certificate indication information includes:
[0045] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0046] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0047] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0048] Optionally, in the authentication method, the second certificate indication information further includes:
[0049] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0050] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0051] Optionally, the authentication method, wherein the signature algorithm corresponding to the target elliptic curve type is used to perform identity-based digital signature IBS identity authentication with the first authentication end, further includes:
[0052] Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
[0053] The embodiment of the present invention further provides an authentication terminal device, the authentication terminal device is a first authentication terminal, which includes a transceiver and a processor, wherein:
[0054] The transceiver is used to obtain a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0055] The processor is used to determine the public key of the first authentication end for key negotiation according to the target elliptic curve type in at least one of the elliptic curve types;
[0056] The transceiver is further used to send a second handshake message to the second authentication end; the second handshake message includes the target elliptic curve type and the public key;
[0057] The processor is further configured to perform identity-based digital signature IBS identity authentication with the second authentication end using a signature algorithm corresponding to the target elliptic curve type.
[0058] The embodiment of the present invention further provides an authentication terminal device, the authentication terminal device is a second authentication terminal, which includes a transceiver and a processor, wherein:
[0059] The transceiver is used to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; and
[0060] Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type;
[0061] The processor is used to perform identity-based digital signature IBS identity authentication with the first authentication end using a signature algorithm corresponding to the target elliptic curve type.
[0062] The embodiment of the present invention further provides an authentication device, which is applied to a first authentication terminal, wherein the device includes:
[0063] A first message acquisition module, used to acquire a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0064] A first processing module, configured to determine a public key of the first authentication end for key negotiation according to a target elliptic curve type in at least one of the elliptic curve types;
[0065] A first message sending module, configured to send a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key;
[0066] The second processing module is used to use the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end.
[0067] The embodiment of the present invention further provides an authentication device, which is applied to a second authentication terminal, wherein the device includes:
[0068] A second message sending module, configured to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0069] A second message acquisition module is used to acquire a second handshake message sent by the first authentication end in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authentication end according to at least one of the elliptic curve types, and a public key of the first authentication end for key negotiation determined according to the target elliptic curve type;
[0070] The third processing module is used to use the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end.
[0071] An embodiment of the present invention further provides an authentication device, characterized in that it includes: a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the authentication method described in any one of the above items is implemented.
[0072] An embodiment of the present invention further provides a readable storage medium, wherein a program is stored on the readable storage medium, and when the program is executed by a processor, the steps in the authentication method as described in any one of the above items are implemented.
[0073] At least one of the above technical solutions of the present invention has the following beneficial effects:
[0074] In the authentication method described in the embodiment of the present invention, the target elliptic curve type determined for key exchange is reused as the elliptic curve type used for IBS identity authentication to determine the signature algorithm, so that the elliptic curve type used for the IBS signature is the same as the elliptic curve type used in the TLS handshake process, and the identity authentication method between the first authentication end and the second authentication end has a simple operation process. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Figure 1A flowchart of one implementation of the authentication method described in an embodiment of the present invention;
[0076] Figure 2 This is a schematic diagram of the authentication process of EAP-TLS-IBS;
[0077] Figure 3 A flowchart of another implementation of the authentication method according to an embodiment of the present invention;
[0078] Figure 4 A schematic diagram of the structure of one implementation of the authentication device described in an embodiment of the present invention;
[0079] Figure 5 A schematic diagram of the structure of another implementation of the authentication device according to an embodiment of the present invention;
[0080] Figure 6 A schematic diagram of the structure of one implementation of the authentication device according to an embodiment of the present invention;
[0081] Figure 7 A schematic diagram of the structure of another implementation of the authentication device according to an embodiment of the present invention;
[0082] Figure 8 A schematic diagram of the structure of one implementation of the authentication device described in an embodiment of the present invention;
[0083] Fig. 9 This is a schematic diagram of the structure of another implementation of the authentication device described in an embodiment of the present invention. DETAILED DESCRIPTION
[0084] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0085] In order to solve the problem of complicated operation process in the authentication method using the existing technology, an embodiment of the present invention provides an authentication method, which reuses the elliptic curve type used by the IBS signature and the elliptic curve type used in the TLS handshake process as the same elliptic curve type, so as to solve the problem of complicated operation process in the authentication method using the existing technology.
[0086] One embodiment of the present invention provides an authentication method, such as Figure 1 As shown, the authentication method described in this embodiment is applied to a first authentication end, and the method includes:
[0087] S110, obtaining a first handshake message sent by a second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0088] S120, determining a public key of the first authenticator for key negotiation according to a target elliptic curve type in at least one of the elliptic curve types;
[0089] S130, sending a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key;
[0090] S140: Use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end.
[0091] In the authentication method described in the embodiment of the present invention, in the key exchange process of the TLS handshake performed by the first authentication end and the second authentication end in steps S110 to S130, the target elliptic curve type determined for key exchange is multiplexed as the elliptic curve type used for IBS identity authentication to determine the signature algorithm in step S140, so that the elliptic curve type used for the IBS signature is the same elliptic curve type as the elliptic curve type used in the TLS handshake process.
[0092] In the embodiment of the present invention, optionally, the second authentication end that sends the first handshake message can be called a client, and the first authentication end that receives the first handshake message can be called a server. It should be noted that the client and the server can be bidirectionally authenticated, and the first authentication end and the second authentication end can be interchangeable as the client and the server.
[0093] In the authentication method described in the embodiment of the present invention, steps S110 to S130 are a TSL handshake process. Optionally, the key exchange algorithm of the TSL handshake process is not limited to any one of the following algorithms:
[0094] Use the Diffie-Hellman (DH) key agreement protocol (ECDHE) based on the elliptic curve type signcryption scheme (EC, Elliptic Curve);
[0095] Only pre-shared key (PSK) mode is used, that is, PSK-only;
[0096] PSK comes with ECDHE.
[0097] Taking the key exchange algorithm of ECDHE as an example, optionally, in step S110, the first handshake message sent by the acquired second authentication end (such as a client) includes a random number C and an extended parameter, wherein the extended parameter includes the supported version supported_version, supported groups supported_groups, signature list signatureschemlist and shared key key_shared of the second authentication end. Optionally, the supported group supported_groups carries at least one elliptic curve type supported by the second authentication end, and the second authentication end calculates a public key POINT(Ha) for each supported elliptic curve type, and optionally, the calculated public key is carried by the shared key key_shared.
[0098] Optionally, the public key POINT(Ha) can be calculated and determined based on the random number C.
[0099] Furthermore, after the first authentication end obtains the first handshake message sent by the second authentication end, the first authentication end determines the target elliptic curve type according to at least one elliptic curve type carried in the first handshake message, and determines the public key of the first authentication end for key negotiation according to the determined elliptic curve type.
[0100] Optionally, the public key used for key negotiation of the first authentication end is a public key used for Diffie–Hellman (DH) key negotiation.
[0101] Specifically, the first authentication end selects the type of elliptic curve to be adopted according to the first handshake message received and determines the corresponding public key POINT (Ha) of the second authentication end through the shared key key_shared, and determines the public key POINT (Hb) of the first authentication end for key negotiation according to the private key random_S (or private key db) of the first authentication end and the public key of the first authentication end.
[0102] Optionally, the public key of the second authentication end for key negotiation is calculated as follows: POINT(Ha)=Random_C*base point G; the public key of the first authentication end is calculated as follows: POINT(Hb)=random_S*base point G.
[0103] Furthermore, the first authentication end also calculates the master key H(X, Y) according to the private key random_S and the public key Ha of the second authentication end, and selects the X coordinate of the master key as the handshake key handshake_secret, and encrypts the second handshake message to be sent by the handshake key handshake_secret according to the selected encryption method. In the embodiment of the present invention, optionally, the elliptic curve types carried in the first handshake message and supported by the second authentication end include but are not limited to only secp256r1, secp384r1, secp521r1, x25519 and x448. Among them, the first authentication end can select one of the above elliptic curve types for key negotiation.
[0104] Based on the above-mentioned TSL handshake process, the constructed EAP-TLS-IBS process provides the supported signature algorithms through the signature algorithm signature_algorithm information sent by the second authentication end to the first authentication end, and identifies the supported certificate types through the server certificate type server_certificate_type and the client certificate type client_certificate_type.
[0105] Specifically, Figure 2 As shown in the figure, the authentication process of EAP-TLS-IBS mainly includes:
[0106] S201, the first authentication end (server) sends an EAP request to the second authentication end (client);
[0107] S202, the second authentication end sends first authentication information to the first authentication end;
[0108] S203, the first authentication end sends second authentication information to the second authentication end;
[0109] S204, the second authentication end sends third authentication information to the first authentication end;
[0110] S205, authentication ends.
[0111] Specifically, the first authentication information includes first handshake information, and the information carried by the first handshake information includes:
[0112] Supported cipher suites;
[0113] Supported version supported_version extension;
[0114] The supported_groups extension includes the supported elliptic curve types;
[0115] First certificate indication information.
[0116] The first certificate indication information includes:
[0117] Signature algorithm signature_algorithm, used to indicate the IBS signature algorithm supported by the second authentication end;
[0118] The first certificate type information is used to indicate the certificate type that the second authentication end can process; it may also be called the service certificate type server_certificate_type;
[0119] The second certificate type information is used to indicate the certificate type that the second authentication end can provide; it may also be called the client certificate type client_certificate_Type.
[0120] Based on the first authentication information including the above information, the first authentication end sends second authentication information to the second authentication end, where the second authentication information includes the above second handshake information and carries the following information:
[0121] The supported versions of the first authentication end are in the field supproted_versions, including the TLS protocol version number selected by the first authentication end from the supported versions in the field supported_version sent by the second authentication end;
[0122] The shared key key_shared extension is used to indicate the target elliptic curve type selected according to the elliptic curve type sent by the second authentication end, and the public key of the first authentication end for key negotiation calculated according to the selected target elliptic curve type.
[0123] Furthermore, the second authentication information also includes: second certificate indication information.
[0124] In the embodiment of the present invention, the second certificate indication information includes:
[0125] Certificate information, including the identity information of the first authentication end, the public parameter information of the first authentication end, and the public parameter information of the key generation center to which the first authentication end belongs;
[0126] Certificate Verify information, including a signature value of the certificate information signed using a signature algorithm corresponding to the target elliptic curve type;
[0127] The certificate request Certificate Request information includes request information for requesting to use the signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0128] Optionally, in the Certificate information, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of a public parameter of the signature algorithm.
[0129] In step S140, during the process of performing identity-based digital signature IBS identity authentication with the second authentication end using the signature algorithm corresponding to the target elliptic curve type, the first authentication end sends second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message.
[0130] Using the above implementation, after receiving the first handshake message, the first authentication end will select the key exchange algorithm to be used, that is, select one of the elliptic curve types in the supported group supported_groups as the target elliptic curve type. According to the above, supported_groups currently supports five types of elliptic curve-based key exchange algorithms: secp256r1, secp384r1, secp521r1, x25519 and x448.
[0131] On this basis, the public key corresponding to the listed elliptic curve type will be pre-stored in the key_share of the first handshake message sent by the second authentication end. The second handshake message sent by the first authentication end will clearly indicate the selected elliptic curve type in the shared key extension Keyshare Extension, and the calculated public key of the first authentication end for key negotiation will be sent to the second authentication end.
[0132] After the first authentication end selects to use the certificate type, the elliptic curve type selected in the key exchange algorithm process is obtained as the signature curve of the IBS.
[0133] Since the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to sign the certificate information, and requests the second authentication end to use the signature algorithm corresponding to the target elliptic curve type for identity authentication request information through Certificate Request information, the second authentication end uses the identity information serverID, certificate message, and signature value of the first authentication end to perform a signature verification operation after receiving certificate and certificateVerify, and passing the signature verification means that the identity authentication is passed. Moreover, the first authentication end also performs the same identity authentication operation on the second authentication end.
[0134] By adopting the above implementation mode, the key exchange process of the TLS handshake and the elliptic curve type used for the IBS signature are reused as the same elliptic curve type, so as to solve the problem of complex calculation process in the authentication method using the prior art.
[0135] Optionally, in the authentication method, after sending the second handshake information, the first authentication end immediately sends an encrypted extension message, which is the first encrypted data, including extended data unrelated to key negotiation, and is used to indicate to the second authentication end.
[0136] Furthermore, the second certificate indication information also includes:
[0137] The second certificate indication information also includes:
[0138] The third certificate type information server_certificate_type is used to indicate the certificate type in the certificate payload;
[0139] The fourth certificate type information client_certificate_Type is used to indicate the type of certificate required to be provided by the second authentication end.
[0140] After completing the sending of the above-mentioned second certificate indication information in sequence, the first authentication end sends an end message to the second authentication end, which is also the last message of the identity authentication phase and is used to detect the integrity of the handshake message. In addition, the end message also provides key confirmation, binding the identity of the endpoint to the exchanged key.
[0141] Further, after completing sending of the second certificate indication information, the first authentication end sends application data Application Data, and the application data Application Data is protected by an application key.
[0142] Optionally, the method further comprises:
[0143] Sending second certificate indication information to the second authentication end includes:
[0144] Encrypting the second certificate indication information using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message;
[0145] Send the encrypted second certificate indication information to the second authentication end.
[0146] Specifically, a handshake_key can be calculated based on the HKDF algorithm using the key material and the hash values of the Client Hello and Server Hello messages. After that, the server_certificate_type, client_certificate_Type, Encrypted Extension, Certificate, Certificate Verify, CertificateRequest, and Finished messages in the handshake phase are all protected by this key.
[0147] Optionally, the authentication method described in the embodiment of the present invention further includes:
[0148] Obtaining third certificate indication information sent by the second authentication end;
[0149] The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
[0150] It should be noted that the third certificate indication information includes:
[0151] Certificate information, including public parameter information and user information of the second authentication end;
[0152] The certificate verification Certificate Verify information includes a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type.
[0153] Optionally, the public parameter information of the second authentication end includes: a public key of the second authentication end used for key negotiation, the signature algorithm, and a hash value of a public parameter of the signature algorithm.
[0154] Among them, the first authentication end performs a signature verification operation on the Certificate information and the signature value based on the third certificate indication information sent by the second authentication end and using the signature algorithm corresponding to the target elliptic curve type determined in the above manner.
[0155] Using the above process, the first authentication end also performs the same identity authentication operation on the second authentication end through the signature algorithm corresponding to the same target elliptic curve.
[0156] The authentication method described in the embodiment of the present invention reuses the elliptic curve type used for IBS signature and the elliptic curve type used in the TLS handshake process as the same elliptic curve type, which can solve the problem of complex calculation process in the authentication method using the prior art.
[0157] Another aspect of the present invention is to provide an authentication method, which is applied to a second authentication end, such as Figure 3 As shown, the method includes:
[0158] S310, sending a first handshake message to a first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0159] S320, obtaining a second handshake message sent by the first authenticating end in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticating end according to at least one of the elliptic curve types, and a public key of the first authenticating end for key negotiation determined according to the target elliptic curve type;
[0160] S330: Use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end.
[0161] By adopting the authentication method described in the embodiment of the present invention, during the authentication process of the first authentication end and the second authentication end, the elliptic curve type used for the IBS signature and the elliptic curve type used in the TLS handshake process are reused as the same elliptic curve type, which can solve the problem of complex calculation process in the authentication method using the existing technology.
[0162] In the embodiment of the present invention, optionally, the second authentication end that sends the first handshake message can be called a client, and the first authentication end that receives the first handshake message can be called a server. It should be noted that the client and the server can be bidirectionally authenticated, and the first authentication end and the second authentication end can be interchangeable as the client and the server.
[0163] Optionally, the authentication method, wherein in step S330, using the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, includes:
[0164] Obtaining second certificate indication information sent by the first authentication end;
[0165] Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information;
[0166] The second certificate indication information includes:
[0167] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0168] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0169] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0170] Optionally, in the authentication method, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0171] Optionally, in the authentication method, the first handshake information includes first certificate indication information, and the first authentication end sends the second authentication indication information according to the first certificate indication information;
[0172] The first certificate indication information includes:
[0173] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0174] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0175] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0176] Optionally, in the authentication method, the second certificate indication information further includes:
[0177] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0178] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0179] Optionally, the authentication method, wherein the signature algorithm corresponding to the target elliptic curve type is used to perform identity-based digital signature IBS identity authentication with the first authentication end, further includes:
[0180] Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
[0181] In the embodiment of the present invention, the content of each information included in the first authentication indication information, the second authentication indication information and the third authentication indication information, and the authentication process of the first authentication end and the second authentication end can refer to the above detailed description and will not be described again here.
[0182] The embodiment of the present invention further provides an authentication terminal device, wherein the authentication terminal device is a first authentication terminal, such as Figure 4 As shown, it includes a transceiver 410 and a processor 420, wherein:
[0183] The transceiver 410 is used to obtain a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0184] The processor 420 is configured to determine, according to a target elliptic curve type in at least one of the elliptic curve types, a public key of the first authenticator for key negotiation;
[0185] The transceiver 410 is further configured to send a second handshake message to the second authentication end; the second handshake message includes the target elliptic curve type and the public key;
[0186] The processor 420 is further configured to perform identity-based digital signature IBS identity authentication with the second authentication end using a signature algorithm corresponding to the target elliptic curve type.
[0187] Optionally, in the authentication device, the processor 420 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end, including:
[0188] Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message;
[0189] The second certificate indication information includes:
[0190] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0191] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0192] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0193] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0194] Optionally, in the authentication device, the first certificate indication information includes:
[0195] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0196] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0197] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0198] Optionally, in the authentication device, the second certificate indication information further includes:
[0199] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0200] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0201] Optionally, in the authentication device, the processor 420 sends the second certificate indication information to the second authentication end, including:
[0202] Encrypting the second certificate indication information using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message;
[0203] Send the encrypted second certificate indication information to the second authentication end.
[0204] Optionally, in the authentication device, the processor 420 is further configured to:
[0205] Obtaining third certificate indication information sent by the second authentication end;
[0206] The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
[0207] The embodiment of the present invention further provides an authentication terminal device, wherein the authentication terminal device is a second authentication terminal, such as Figure 5 As shown, it includes a transceiver 510 and a processor 520, wherein:
[0208] The transceiver 510 is used to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; and
[0209] Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type;
[0210] The processor 520 is configured to perform identity-based digital signature IBS identity authentication with the first authentication end using a signature algorithm corresponding to the target elliptic curve type.
[0211] Optionally, in the authentication device, the processor 520 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, including:
[0212] Obtaining second certificate indication information sent by the first authentication end;
[0213] Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information;
[0214] The second certificate indication information includes:
[0215] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0216] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0217] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0218] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0219] Optionally, in the authentication device, the first handshake information includes first certificate indication information, and the first authentication end sends the second authentication indication information according to the first certificate indication information;
[0220] The first certificate indication information includes:
[0221] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0222] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0223] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0224] Optionally, in the authentication device, the second certificate indication information further includes:
[0225] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0226] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0227] Optionally, the authentication device, wherein the processor 520 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, further includes:
[0228] Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
[0229] The embodiment of the present invention also provides an authentication device, which is applied to a first authentication end, such as Figure 6 As shown, the device comprises:
[0230] A first message acquisition module 610 is used to acquire a first handshake message sent by a second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0231] A first processing module 620, configured to determine a public key of the first authenticator for key negotiation according to a target elliptic curve type in at least one of the elliptic curve types;
[0232] A first message sending module 630 is configured to send a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key;
[0233] The second processing module 640 is configured to use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end.
[0234] Optionally, in the authentication device, the second processing module 640 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end, including:
[0235] Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message;
[0236] The second certificate indication information includes:
[0237] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0238] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0239] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0240] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0241] Optionally, in the authentication device, the first certificate indication information includes:
[0242] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0243] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0244] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0245] Optionally, in the authentication device, the second certificate indication information further includes:
[0246] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0247] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0248] Optionally, in the authentication device, sending the second certificate indication information to the second authentication end includes:
[0249] Encrypting the second certificate indication information using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message;
[0250] Send the encrypted second certificate indication information to the second authentication end.
[0251] Optionally, in the authentication device, the second processing module 640 is further configured to:
[0252] Obtaining third certificate indication information sent by the second authentication end;
[0253] The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
[0254] The embodiment of the present invention also provides an authentication device, which is applied to a second authentication end, such as Figure 7 As shown, the device comprises:
[0255] The second message sending module 710 is used to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0256] A second message acquisition module 720 is used to acquire a second handshake message sent by the first authenticating end in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticating end according to at least one of the elliptic curve types, and a public key of the first authenticating end for key negotiation determined according to the target elliptic curve type;
[0257] The third processing module 730 is configured to use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end.
[0258] Optionally, in the authentication device, the third processing module 730 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, including:
[0259] Obtaining second certificate indication information sent by the first authentication end;
[0260] Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information;
[0261] The second certificate indication information includes:
[0262] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0263] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0264] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0265] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0266] Optionally, in the authentication device, the first handshake information includes first certificate indication information, and the first authentication end sends the second authentication indication information according to the first certificate indication information;
[0267] The first certificate indication information includes:
[0268] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0269] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0270] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0271] Optionally, in the authentication device, the second certificate indication information further includes:
[0272] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0273] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0274] Optionally, the authentication device, wherein the third processing module 730 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, further includes:
[0275] Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
[0276] Another aspect of the present invention is to provide an authentication device. Optionally, the authentication device is a first authentication terminal, such as Figure 8 As shown, it includes: a processor 801; and a memory 803 connected to the processor 801 through a bus interface 802, the memory 803 is used to store programs and data used by the processor 801 when performing operations, and the processor 801 calls and executes the programs and data stored in the memory 803.
[0277] The transceiver 804 is connected to the bus interface 802 and is used to receive and send data under the control of the processor 801. Specifically, the processor 801 is used to read the program in the memory 803 and execute the following process:
[0278] Obtaining a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0279] Determining, according to a target elliptic curve type in at least one of the elliptic curve types, a public key of the first authenticator for key negotiation;
[0280] Sending a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key;
[0281] The signature algorithm corresponding to the target elliptic curve type is used to perform identity authentication of the identity-based digital signature IBS with the second authentication end.
[0282] Optionally, in the authentication device, the processor 801 adopts the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end, including:
[0283] Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message;
[0284] The second certificate indication information includes:
[0285] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0286] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0287] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0288] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0289] Optionally, in the authentication device, the first certificate indication information includes:
[0290] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0291] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0292] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0293] Optionally, in the authentication device, the second certificate indication information further includes:
[0294] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0295] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0296] Optionally, the authentication device, wherein sending the second certificate indication information to the second authentication end includes:
[0297] Encrypting the second certificate indication information using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message;
[0298] Send the encrypted second certificate indication information to the second authentication end.
[0299] Optionally, in the authentication device, the processor 801 is further configured to:
[0300] Obtaining third certificate indication information sent by the second authentication end;
[0301] The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
[0302] Among them, Figure 8 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 801 and memory represented by memory 803. The bus architecture may also link various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 804 may be a plurality of components, i.e., including a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. The processor 801 is responsible for managing the bus architecture and general processing, and the memory 803 may store data used by the processor 801 when performing operations.
[0303] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by instructing related hardware through a program, wherein the program includes instructions for executing part or all of the steps of the above method; and the program may be stored in a readable storage medium, which may be any form of storage medium.
[0304] Another aspect of the embodiment of the present invention further provides an authentication device. Optionally, the authentication device is a second authentication terminal, such as Fig. 9 As shown, it includes: a processor 901; and a memory 903 connected to the processor 901 through a bus interface 902, the memory 903 is used to store programs and data used by the processor 901 when performing operations, and the processor 901 calls and executes the programs and data stored in the memory 903.
[0305] The transceiver 904 is connected to the bus interface 902 and is used to receive and send data under the control of the processor 901. Specifically, the processor 901 is used to read the program in the memory 903 and execute the following process:
[0306] Sending a first handshake message to a first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end;
[0307] Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type;
[0308] The signature algorithm corresponding to the target elliptic curve type is used to perform identity authentication of the identity-based digital signature IBS with the first authentication end.
[0309] Optionally, in the authentication device, the processor 901 adopts the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, including:
[0310] Obtaining second certificate indication information sent by the first authentication end;
[0311] Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information;
[0312] The second certificate indication information includes:
[0313] Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs;
[0314] Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type;
[0315] The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
[0316] Optionally, in the authentication device, the public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of the public parameters of the signature algorithm.
[0317] Optionally, in the authentication device, the first handshake information includes first certificate indication information, and the first authentication end sends the second authentication indication information according to the first certificate indication information;
[0318] The first certificate indication information includes:
[0319] Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator;
[0320] First certificate type information, used to indicate the certificate type that the second authentication end can process;
[0321] The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
[0322] Optionally, in the authentication device, the second certificate indication information further includes:
[0323] The third certificate type information is used to indicate the certificate type in the certificate payload;
[0324] The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
[0325] Optionally, the authentication device, wherein the processor 901 uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, further comprising:
[0326] Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
[0327] Among them, Fig. 9In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 901 and memory represented by memory 903. The bus architecture may also link various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver 904 may be a plurality of components, i.e., including a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium. The processor 901 is responsible for managing the bus architecture and general processing, and the memory 903 may store data used by the processor 901 when performing operations.
[0328] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by instructing related hardware through a program, wherein the program includes instructions for executing part or all of the steps of the above method; and the program may be stored in a readable storage medium, which may be any form of storage medium.
[0329] In addition, a specific embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored, wherein the program, when executed by a processor, implements the steps in any of the authentication methods described above.
[0330] In the several embodiments provided in the present application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0331] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may be physically included separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0332] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform some steps of the sending and receiving methods described in various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store program codes.
[0333] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary personnel in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. An authentication method, applied to a first authentication end, characterized in that: The method comprises: Obtaining a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; Determining, according to a target elliptic curve type in at least one of the elliptic curve types, a public key of the first authenticator for key negotiation; Sending a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key; Using the signature algorithm corresponding to the target elliptic curve type, perform identity-based digital signature IBS identity authentication with the second authentication end; The method of using a signature algorithm corresponding to the target elliptic curve type to perform identity authentication of an identity-based digital signature IBS with the second authentication end includes: Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
2. The authentication method according to claim 1, characterized in that: The public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of a public parameter of the signature algorithm.
3. The authentication method according to claim 1, characterized in that: The first certificate indication information includes: Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator; First certificate type information, used to indicate the certificate type that the second authentication end can process; The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
4. The authentication method according to claim 1, characterized in that: The second certificate indication information also includes: The third certificate type information is used to indicate the certificate type in the certificate payload; The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
5. The authentication method according to claim 1, characterized in that: Sending second certificate indication information to the second authentication end includes: Encrypting the second certificate indication information by using a handshake key, wherein the handshake key is calculated based on the first handshake message and the second handshake message; Send the encrypted second certificate indication information to the second authentication end.
6. The authentication method according to claim 1, characterized in that: The method further comprises: Obtaining third certificate indication information sent by the second authentication end; The signature algorithm corresponding to the target elliptic curve type is used to perform signature verification on the third certificate indication information.
7. An authentication method, applied to a second authentication end, characterized in that: The method comprises: Sending a first handshake message to a first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type; Using the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, wherein using the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end includes: Obtaining second certificate indication information sent by the first authentication end; Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
8. The authentication method according to claim 7, characterized in that: The public parameter information of the first authentication end includes: a public key of the first authentication end used for key negotiation, the signature algorithm, and a hash value of a public parameter of the signature algorithm.
9. The authentication method according to claim 7, characterized in that: The first handshake message includes first certificate indication information, wherein the first authenticator sends the second certificate indication information according to the first certificate indication information; The first certificate indication information includes: Signature algorithm information, used to indicate the signature algorithm supported by the second authenticator; First certificate type information, used to indicate the certificate type that the second authentication end can process; The second certificate type information is used to indicate the certificate type that the second authentication end can provide.
10. The authentication method according to claim 9, characterized in that: The second certificate indication information also includes: The third certificate type information is used to indicate the certificate type in the certificate payload; The fourth certificate type information is used to indicate the type of certificate required by the second authentication end.
11. The authentication method according to claim 7, characterized in that: Using the signature algorithm corresponding to the target elliptic curve type to perform identity authentication of the identity-based digital signature IBS with the first authentication end, further comprising: Send third certificate indication information to the first authentication end, so that the first authentication end uses the signature algorithm corresponding to the target elliptic curve type to perform signature verification on the third certificate indication information.
12. An authentication terminal device, the authentication terminal device being a first authentication terminal, characterized in that: It includes a transceiver and a processor, wherein: The transceiver is used to obtain a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; The processor is used to determine the public key of the first authentication end for key negotiation according to the target elliptic curve type in at least one of the elliptic curve types; The transceiver is further used to send a second handshake message to the second authentication end; the second handshake message includes the target elliptic curve type and the public key; The processor is further configured to perform identity authentication of an identity-based digital signature IBS with the second authentication end using a signature algorithm corresponding to the target elliptic curve type; The processor uses the signature algorithm corresponding to the target elliptic curve type to perform identity authentication of the identity-based digital signature IBS with the second authentication end, including: Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
13. An authentication terminal device, the authentication terminal device being a second authentication terminal, characterized in that: It includes a transceiver and a processor, wherein: The transceiver is used to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; and Obtaining a second handshake message sent by the first authenticator in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authenticator according to at least one of the elliptic curve types, and a public key of the first authenticator for key negotiation determined according to the target elliptic curve type; The processor is used to perform identity authentication of the identity-based digital signature IBS with the first authentication end using the signature algorithm corresponding to the target elliptic curve type; The processor uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end, including: Obtaining second certificate indication information sent by the first authentication end; Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
14. An authentication device, applied to a first authentication end, characterized in that: The device comprises: A first message acquisition module, used to acquire a first handshake message sent by the second authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; A first processing module, configured to determine a public key of the first authenticator for key negotiation according to a target elliptic curve type in at least one of the elliptic curve types; A first message sending module, configured to send a second handshake message to the second authenticator; the second handshake message includes the target elliptic curve type and the public key; A second processing module, configured to use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end; The second processing module uses the signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the second authentication end, including: Sending second certificate indication information to the second authentication end according to the first certificate indication information in the first handshake message; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
15. An authentication device, applied to a second authentication terminal, characterized in that: The device comprises: A second message sending module, configured to send a first handshake message to the first authentication end; the first handshake message includes at least one elliptic curve type supported by the second authentication end; A second message acquisition module is used to acquire a second handshake message sent by the first authentication end in response to the first handshake message; the second handshake message includes a target elliptic curve type selected by the first authentication end according to at least one of the elliptic curve types, and a public key of the first authentication end for key negotiation determined according to the target elliptic curve type; A third processing module, configured to use a signature algorithm corresponding to the target elliptic curve type to perform identity-based digital signature IBS identity authentication with the first authentication end; The third processing module uses the signature algorithm corresponding to the target elliptic curve type to perform identity authentication of the identity-based digital signature IBS with the first authentication end, including: Obtaining second certificate indication information sent by the first authentication end; Using a signature algorithm corresponding to the target elliptic curve type, performing signature verification on the second certificate indication information; The second certificate indication information includes: Certificate information, including identity information of the first authentication end, public parameter information of the first authentication end, and public parameter information of a key generation center to which the first authentication end belongs; Certificate verification information, including a signature value obtained by signing the certificate information using a signature algorithm corresponding to the target elliptic curve type; The certificate request information includes request information for requesting to use a signature algorithm corresponding to the target elliptic curve type for identity authentication.
16. An authentication device, characterized in that: include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the program implements the authentication method as described in any one of claims 1 to 6, or implements the authentication method as described in any one of claims 7 to 11.
17. A readable storage medium, characterized in that: The readable storage medium stores a program, and when the program is executed by the processor, the program implements the steps in the authentication method according to any one of claims 1 to 6, or implements the steps in the authentication method according to any one of claims 7 to 11.
Citation Information
Patent Citations
A system and method for designing secure client-server communication protocols based on certificateless public key infrastructure
CN102098157A
Identity-based grid authentication protocol
CN102487379A