An operating method for a key system applied between a client and a server

Through the key negotiation mechanism between the client and the server, combined with the multi-layer encryption algorithm, the security problem of sensitive information in Internet information transmission is solved, and the confidentiality, integrity and anti-replay attacks of data are realized, which is suitable for information transmission between the client and the server.

CN114826588BActive Publication Date: 2025-07-18BANK OF SHANGHAI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210525663.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-06
Publication Date
2025-07-18
Estimated Expiration
2042-05-06

AI Technical Summary

Technical Problem

In the transmission of Internet information, the confidentiality and integrity of sensitive information are difficult to guarantee, especially in the transmission of information between the client and the server.

Method used

A key system operation method is adopted, including a key negotiation mechanism between the client and the server, randomly generate index numbers and random keys, combined with XOR operations to generate session keys, and data encryption is used using multi-layer encryption algorithms such as SM2 and SM4 to ensure the security of data transmission.

Benefits of technology

Effectively prevent sensitive data from being brute-forced, improve the security of information transmission, ensure data confidentiality and integrity, prevent replay attacks, and meet the regulatory requirements of domestic cryptographic algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114826588B_ABST
    Figure CN114826588B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of information transmission, and discloses an operation method for a key system applied between a client and a server, including the following steps: S1: A password control conducts a transaction; S2: The server randomly generates a digest value hks of data; S3: The public keys PK, RS, and hks corresponding to the index number are sent to the client; S4: The password control conducts verification and encryption; S5: The key is encrypted and transmitted to the server; S6: The encrypted key is transmitted to the password service platform; S7: The encrypted key is verified and re-encrypted; S8: After receiving the encryption result, the server deletes the random key number RS; S9: The client responds to the keys encrypted twice, establishing a key negotiation mechanism for the index key and the session key. Based on domestic cryptographic algorithms, it can securely transmit sensitive data such as passwords, ID numbers, and mobile phone numbers entered by users on the password control of the client to the background server, ensuring the confidentiality, integrity, and anti-replay of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information transmission, and specifically to an operation method of a key system applied between a client and a server. Background Art

[0002] In the era of Internet prevalence, information transmission is no longer like traditional letters. Through digitalizing information on the Internet for transmission, the transmission speed is faster. However, due to the interoperability of the Internet, information transmission has certain insecurity and poor confidentiality, and the confidentiality and integrity of some sensitive information cannot be guaranteed during transmission. Summary of the Invention

[0003] (I) Technical Problems to be Solved

[0004] In view of the deficiencies of the prior art, the present invention provides an operation method of a key system applied between a client and a server.

[0005] (II) Technical Solutions

[0006] To achieve the above object, the present invention provides the following technical solutions: An operation method of a key system applied between a client and a server, including the following steps:

[0007] S1: The client invokes the password control and conducts a transaction, and applies for the public key PK from the server in real time;

[0008] S2: The server randomly generates an index number, randomly generates RS, and calculates the digest value hks of PK and RS;

[0009] S3: Send the public key PK, RS, and hks corresponding to the index number to the client;

[0010] S4: Conduct verification and encryption through the password control;

[0011] S5: The client encrypts the key and transmits it to the server;

[0012] S6: The server transmits the encrypted key in S5 to the password service platform;

[0013] S7: The password service platform verifies and re-encrypts the encrypted key in S6, and then conveys it to the server;

[0014] S8: After receiving the re-encryption result from the password service platform, the server deletes the random key number RS and conveys it to the client;

[0015] S9: The client responds to the key encrypted twice.

[0016] Preferably, the public key PK is randomly selected from 32 index public keys saved on the server. If it is found that the index key is insecure, only the 32 index key values saved on the server and the password service platform need to be updated.

[0017] Preferably, for each transaction that invokes the password control, the server generates a random key number RS, and the client generates a random number key RC. When generating the random keys, weak and semi-weak keys are excluded. RC and RS jointly generate a session key R through the XOR operation; the random numbers are generated in the CSPRNG manner. The client's random key number RC is encrypted with the public key PK and then transmitted to the server. After the server receives the re-encrypted result from the password service platform, it deletes the random key number RS.

[0018] The public key PK in the S1 step is randomly selected from 32 index public keys saved on the server;

[0019] When it is found that the index key is insecure, only the 32 index key values saved on the server and the password service platform need to be updated.

[0020] Preferably, the specific steps of the S4: verification and encryption through the password control are as follows:

[0021] 1. Verify hks;

[0022] 2. Randomly generate a client random number RC;

[0023] 3. Calculate the session key R = RS xor RC;

[0024] 4. Use the index public key to perform SM2 encryption on the sensitive data: enc1 = PK(data);

[0025] 5. Use the session key to perform SM4 encryption on the above enc1: enc3 = R(enc1);

[0026] 6. Use the index public key to perform SM2 encryption on the client random number: enc2 = PK(RC);

[0027] 7. Calculate the digest h = Hash(enc2||enc3) for the concatenation of enc1, enc2, and enc3 using SM3.

[0028] Preferably, for each transaction that invokes the password control, the server generates a random key number RS, and the client generates a random number key RC. When generating the random keys, weak and semi-weak keys are excluded. RC and RS jointly generate a session key R through the XOR operation.

[0029] Preferably, after verifying the accuracy of the public key PK and the server random key RS sent from the server in step S4, the client uses the public key PK and the session key R to encrypt the user data in two layers.

[0030] The specific encryption steps of S4 are as follows: First, use the public key PK to perform SM2 encryption on the sensitive data; then use the session key R to perform SM4-CBC encryption. The initial vector IV is the first 16 bytes of the digest value of the server random key RS, and PKCS7 mode is used for data padding.

[0031] (III) Beneficial effects

[0032] Compared with the prior art, the present invention provides an operation method of a key system applied between a client and a server, having the following beneficial effects:

[0033] 1. For the operation method of the key system applied between the client and the server, the one-time-one-key key negotiation mechanism between the client and the server effectively prevents the possibility of brute force cracking of sensitive data.

[0034] 2. For the operation method of the key system applied between the client and the server, the key system combining the index key and the session key further improves the security during the transmission of sensitive data.

[0035] 3. For the operation method of the key system applied between the client and the server, a key negotiation mechanism for the index key and the session key is established. Based on domestic cryptographic algorithms, sensitive data such as passwords, ID numbers, and mobile phone numbers entered by users on the password control of the client can be securely transmitted to the background server, ensuring the confidentiality, integrity, and anti-replay of the data.

[0036] 4. For the operation method of the key system applied between the client and the server, the server generates a random key number RS, and the client generates a random number key RC. Weak and semi-weak keys are excluded when generating the random key. RC and RS jointly generate the session key R through the XOR method; the random number is generated in the CSPRNG mode. The client random key number RC is encrypted with the public key PK and then transmitted to the server. After the server receives the re-encrypted result from the password service platform, the random key number RS is deleted to avoid replay attacks on transactions.

[0037] 5. For the operation method of the key system applied between the client and the server, it ensures the confidentiality and integrity of the sensitive information entered by the user on the password control of the client (PC, APP, WeChat mini-program, etc.), unifies the key systems and cryptographic algorithms of various clients, and meets the requirements of supervision for the application of domestic cryptography. Description of the drawings

[0038] Figure 1 Schematic diagram of the key negotiation and data encryption process between the client and the server of the present invention. Specific implementation manners

[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0040] Please refer to Figure 1 , a method for operating a key system applied between a client and a server. Among them, there is a client and a server. A password control is set on the client. The client and the server are connected bidirectionally, and the server is connected bidirectionally to a password service platform.

[0041] It includes the following steps:

[0042] S1: The client invokes the password control and conducts a transaction, and applies for the public key PK from the server in real time;

[0043] S2: The server randomly generates an index number, randomly generates RS, and calculates the digest value hks of PK and RS;

[0044] S3: Send the public key PK, RS, and hks corresponding to the index number to the client;

[0045] S4: Conduct verification and encryption through the password control;

[0046] S5: The client encrypts the key and transmits it to the server;

[0047] S6: The server transmits the encrypted key in S5 to the password service platform;

[0048] S7: The password service platform verifies and re-encrypts the encrypted key in S6, and then conveys it to the server;

[0049] S8: After receiving the re-encryption result from the password service platform, the server deletes the random key number RS and conveys it to the client;

[0050] S9: The client responds to the key encrypted twice.

[0051] The server maintains a comparison table of the client version number and the index public key corresponding to this version. The number of index public keys corresponding to a certain version of the client is 32; the corresponding index public keys for different versions of the same client are also different, and the public key PK is randomly obtained from the 32 index public keys saved by the server. If the index key is found to be insecure, all 32 index key values saved by the server and the cryptographic service platform need to be updated.

[0052] For each transaction that calls up the password control, the server generates a random key number RS and the client generates a random key number RC. Weak and semi-weak keys are eliminated when generating the random key. RC and RS jointly generate the session key R through XOR. The random number is generated using the CSPRNG method. The client's random key number RC is encrypted using the public key PK and transmitted to the server. After receiving the encryption result from the password service platform, the server deletes the random key number RS.

[0053] After verifying the accuracy of the public key PK and the random key RS sent from the server, the client uses the public key PK and the session key R to perform double-layer encryption on the user data.

[0054] Among them, S4: The specific steps for verification and encryption through password control are as follows:

[0055] 1. Verify hks;

[0056] 2. Randomly generate client random number RC;

[0057] 3. Calculate the session key R = RS xorRC;

[0058] 4. Use the index public key to perform SM2 encryption on the sensitive data en c1 = PK (data);

[0059] 5. Use the session key to perform SM4 encryption on enc1 in the previous step, enc3 = R (enc1);

[0060] 6. Use the index public key to perform SM2 encryption on the client random number enc2=PK(RC);

[0061] 7. After concatenating enc1, enc2, and enc3, use SM3 to calculate the digest h = Hash(enC2||enc3).

[0062] The specific steps of S4 encryption include: first, use the public key PK to perform SM2 encryption on the sensitive data; then use the session key R to perform SM4-CBC encryption, the initial vector IV is the first 16 bytes of the summary value of the server random key RS, and the data is filled using the PKCS7 method.

[0063] When using,

[0064] S1: The password control of the client requests the public key PK and the server random number RS.

[0065] S2: The server randomly generates an index number, randomly generates RS, and calculates the digest value hks of PK and RS.

[0066] S3: Send the public key PK, RS, and hks corresponding to the index number to the client.

[0067] S4: Perform verification and encryption through the password control: 1. Verify hks; 2. Randomly generate the client random number RC; 3. Calculate the session key R = RS xor RC; 4. Use the index public key to perform SM2 encryption on the sensitive data enc1 = PK(data); 5. Use the session key to perform SM4 encryption on the previous enc1 enc3 = R(enc1); 6. Use the index public key to perform SM2 encryption on the client random number enc2 = PK(RC); 7. Calculate the digest h = Hash(enc2||enc3) using SM3 after connecting enc1, enc2, and enc3.

[0068] S5: The client encrypts the key and transmits it to the server: Send enc1, enc2, enc3, and h to the server.

[0069] S6: The server transmits the encrypted key in S5 to the password service platform: Send enc1, enc2, enc3, h, RS, keyName, and the account to the password service platform.

[0070] S7: The password service platform verifies and re-encrypts the encrypted key in S6, and then transmits the result to the server: The password service platform first verifies h, then performs re-encryption, and then returns the result to the server.

[0071] S8: After receiving the re-encrypted result from the password service platform, the server deletes the random key number RS and transmits it to the client.

[0072] S9: The client responds to the keys encrypted twice.

[0073] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for operating a key system between a client and a server, characterized in that: It includes the following steps: S1: The client invokes the password control and conducts a transaction, and applies for the public key PK from the server in real time; S2: The server randomly generates an index number, randomly generates RS, and calculates the digest value hks of PK and RS; S3: The server issues the public key PK, RS, and hks corresponding to the index number to the client; S4: Conduct verification and encryption through the password control; S5: The client encrypts the key and transmits it to the server; S6: The server transmits the encrypted key in S5 to the password service platform; S7: The password service platform verifies and re-encrypts the encrypted key in S6, and then conveys it to the server; S8: After receiving the re-encrypted result from the password service platform, the server deletes the random key number RS and conveys it to the client; S9: The client responds to the key encrypted twice; Among them The specific steps of S4: Conduct verification and encryption through the password control are as follows:

1. Verify hks; 2. Randomly generate a client random number RC; 3. Calculate the session key R = RS xor RC; 4. Use the index public key to perform SM2 encryption on sensitive data, enc1 = PK(data); 5. Use the session key to perform SM4 encryption on the above enc1, enc3 = R(enc1); 6. Use the index public key to perform SM2 encryption on the client random number, enc2 = PK(RC); 7. Calculate the digest h = Hash(enc2 || enc3) of the connection of enc1, enc2, and enc3 using SM3; For each transaction that invokes the password control, the server generates a random key number RS, and the client generates a random number key RC. When generating the random key, weak and semi-weak keys are excluded. RC and RS jointly generate the session key R through the exclusive OR method; In the S4 step, after the client verifies the accuracy of the public key PK issued by the server and the server random key RS, the client uses the public key PK and the session key R to perform two-layer encryption on the user data; The specific encryption steps of S4 include the following: First, use the public key PK to perform SM2 encryption on sensitive data; then use the session key R to perform SM4-CBC encryption. The initial vector IV takes the first 16 bytes of the digest value of the server random key RS, and data padding is performed using the PKCS7 method; 2. The operating method of a key system applied between a client and a server according to claim 1, characterized in that: The public key PK in the S1 step is randomly obtained from 32 index public keys saved by the server; When it is found that the index key is insecure, all 32 index key values saved by the server and the password service platform can be updated.

Citation Information

Patent Citations

  • Method of secure communication based on commercial cipher algorithm

    CN104158653A

  • Secure communication method and system for host and trusted cryptographic module

    CN112966254A