Post-Quantum-Cryptography-CA-Based Quantum-Computing-Resistant Communication System
By storing the public key pool in the anti-quantum computing service center, the problems of high storage costs of user-side key fobs, low system security, and large hardware upgrade costs in existing anti-quantum computing systems are solved, and the effect of reducing costs and improving security is achieved.
Patent Information
- Application Number
- CN202110208555.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-02-24
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-02-24
AI Technical Summary
Existing quantum-resistant computing systems have problems such as high storage cost of user-side key fobs, low system security, and large hardware upgrade costs.
The certificate authority (CA) and anti-quantum computing service center are adopted based on post-quantum cryptography. By storing public key pools in the service center, the user-side storage needs are reduced, the hardware upgrade costs are reduced, and the system security is improved.
It reduces the cost of users using quantum-resistant computing solutions, improves system security, and avoids the cost of hardware upgrades on the user side.
Smart Images

Figure CN114978481B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of anti - quantum computing, and in particular to an anti - quantum computing communication method and system based on post - quantum cryptography CA. Background Art
[0002] In many applications, people hope to sever the connection between their identities and behaviors, and at the same time hope to authenticate the identities of communication objects and ensure the integrity and confidentiality of transmitted information. Authentication key exchange is proposed to achieve such cryptographic tasks. It involves a server and a group of legitimate users, and requires the server and any legitimate user to share a secure session key on the premise of mutual identity authentication without revealing the user's identity, so as to ensure the security of subsequent communications.
[0003] In classical cryptography, many identity authentication, key exchange, encryption - decryption, and digital signature schemes have been successively proposed. Most classical cryptographic protocols are based on the assumption of mathematical difficult problems. With the emergence of quantum computers, the security of such protocols faces severe threats. Therefore, it is very important to design an anti - quantum computing communication scheme.
[0004] Post - Quantum Cryptography is a very active emerging research direction in cryptography. The National Security Agency (NSA) of the United States announced a migration plan for anti - quantum cryptographic algorithms in August 2015. In the same year, the National Institute of Standards and Technology (NIST) of the United States initiated and held a "Post - Quantum Cybersecurity Workshop", and called for post - quantum public - key cryptographic algorithms in 2017, striving to promote the standardization work of post - quantum cryptography, and initial results have been achieved.
[0005] Problems existing in the prior art:
[0006] 1. In the existing anti - quantum computing system based on an asymmetric key pool (patent with application number "201910034536.8"), it is necessary to generate an asymmetric key pool from the public keys of all members and store it in each key card, which increases the storage cost of the user - side key card, resulting in a relatively high cost for users to use the anti - quantum computing scheme; in addition, it changes the data structure of traditional digital certificates, resulting in too high a cost for the CA and user application systems to switch to the anti - quantum computing scheme; in addition, the asymmetric key pool issuing center in the CA needs to face the demand for all users to apply for the asymmetric key pool, with a large business volume; in addition, all members' public keys are stored in each key card, especially the public key of the CA. Once the key card is lost, stolen, and cracked, it will affect the security of all members, and the security of the entire system is not high enough;
[0007] 2. In the existing quantum-resistant communication system based on ID cryptography (patent with application number "202020815697.9"), an additional key management server based on ID cryptography needs to be deployed, which changes the deployment method of the traditional CA. Since ID cryptography involves relatively complex bilinear pair operations, new uncertainties are introduced, increasing the system complexity;
[0008] 3. In the existing CA system based on post-quantum cryptography, due to the fact that a large number of client-side hardware cannot support the algorithms of post-quantum cryptography, the client side faces huge hardware upgrade costs. Summary of the Invention
[0009] In view of the problems in the related art, the present invention proposes a quantum-resistant communication method and system based on post-quantum cryptography CA to overcome the above-mentioned technical problems existing in the existing related technologies.
[0010] For this purpose, the specific technical solutions adopted by the present invention are as follows:
[0011] A quantum-resistant communication system based on post-quantum cryptography CA includes a quantum-resistant computing service center, a certificate authority, and a number of client terminals. The certificate authority is constructed based on post-quantum cryptographic algorithms, and all members are equipped with quantum-resistant computing key cards, and the quantum-resistant computing key cards have the characteristic of being non-dismantlable;
[0012] The post-quantum cryptographic public and private keys of the certificate authority, the public root certificate based on post-quantum cryptography are stored in the quantum-resistant computing key card of the certificate authority, and a public digital certificate based on post-quantum cryptography is issued to the quantum-resistant computing service center;
[0013] The quantum-resistant computing service center provides a user registration function and issues quantum-resistant computing key cards to the client terminals. The public key pool composed of the public key based on post-quantum cryptography, the private key based on post-quantum cryptography, the public digital certificate based on post-quantum cryptography, the ordinary public key of the service center, the ordinary private key of the service center, the non-public ordinary digital certificate of the service center, and the public keys of all user key cards issued by the service center is stored inside the quantum-resistant computing key card of the quantum-resistant computing service center; The certificate authority of the quantum-resistant computing service center issues a non-public ordinary digital certificate of the service center;
[0014] The ordinary public key of the quantum-resistant computing service center, the ordinary public and private keys of this client terminal, and the non-public ordinary digital certificate of this client key card are stored in the quantum-resistant computing key card of the client terminal. The non-public ordinary digital certificate of the client key card is issued by the certificate authority of the quantum-resistant computing service center;
[0015] The client terminal does not permanently store the public keys or certificates of other client terminals;
[0016] The ordinary public and private keys satisfy the computational relationship defined by the elliptic curve algorithm.
[0017] A quantum-resistant computing communication method based on a post-quantum cryptography CA, implemented in the above system, occurring between the user side and the quantum-resistant computing service center, includes the following steps:
[0018] S11. The user side generates a first shared key based on the key derivation function using its own ordinary private key, the ordinary public key of the quantum-resistant computing service center, and the verification information, generates a first true random number, and uses the ordinary private key of the user side to sign the user side identity information and verification information to obtain a first signature. The first signature and the user side's non-public ordinary digital certificate are encrypted using the first true random number to obtain a first ciphertext. The user side sends a third ciphertext, and the third ciphertext includes the user side identity information, verification information, the first ciphertext, and a second ciphertext obtained by encrypting the first true random number using the first shared key;
[0019] S12. After receiving the third ciphertext, the quantum-resistant computing service center corresponding to the user side obtains the ordinary public key of the user side from the public key pool according to the user side identity information, generates a first shared key based on the key derivation function using its own ordinary private key, verification information, and the user side ordinary public key, and decrypts and verifies the third ciphertext using the first shared key. After the verification passes, the quantum-resistant computing service center generates a session key, uses the ordinary private key of the quantum-resistant computing service center to sign the session key, verification message, and the identity information of the quantum-resistant computing service center to obtain a second signature, encrypts the session key and the second signature using the first true random number to obtain a fourth ciphertext, and sends a fifth ciphertext composed of the identity information of the quantum-resistant computing service center, verification message, and the fourth ciphertext to the user side;
[0020] S13. After receiving the fifth ciphertext, the user side decrypts it using the first true random number to obtain the session key and the second signature, and verifies the second signature using the ordinary public key of the quantum-resistant computing service center, and the authentication is completed;
[0021] S14. The user side and the corresponding quantum-resistant computing service center use the session key for secure communication.
[0022] Occurring between quantum-resistant computing service centers, includes the following steps:
[0023] S21. The first service center extracts the post - quantum cryptographic public key of the second service center from the post - quantum cryptographic digital certificate publicly disclosed by the second service center, generates a second true random number, signs the identity information and verification message of the first service center using the ordinary private key of the first service center to obtain a third signature, encrypts the ordinary digital certificate and the third signature that are not publicly disclosed by the first service center using the second true random number to obtain a sixth ciphertext, encrypts the second true random number using the post - quantum cryptographic public key of the second service center based on post - quantum cryptography to obtain a seventh ciphertext, and forms an eighth ciphertext by combining the identity information of the first service center, the verification message, the sixth ciphertext and the seventh ciphertext and sends it to the second service center;
[0024] S22. After receiving the eighth ciphertext, the second service center decrypts the seventh ciphertext using the post - quantum cryptographic private key of the second service center to obtain the second true random number, decrypts the sixth ciphertext using the second true random number to obtain the third signature and the ordinary digital certificate of the first service center, and verifies the digital certificate and the signature; after the verification passes, the second service center saves the ordinary public key of the first service center, generates a first session key, signs the identity information, verification message and the first session key of the second service center using the ordinary private key of the second service center to obtain a fourth signature, encrypts the first session key, the fourth signature and the ordinary digital certificate of the second service center using the second true random number to obtain a ninth ciphertext, and forms a tenth ciphertext by combining the identity information of the second service center, the verification message and the ninth ciphertext and sends it to the first service center;
[0025] S23. After receiving the tenth ciphertext, the first service center decrypts it using the second true random number to obtain the first session key, the fourth signature and the ordinary digital certificate of the second service center, verifies the signature and the digital certificate, and after the verification passes, confirms to obtain the first session key;
[0026] S24. The first service center and the second service center conduct secure communication through the first session key.
[0027] Optionally, the verification of the digital certificate and the signature includes the following steps: First, obtain the post - quantum cryptographic public key of the service center from the post - quantum cryptographic digital certificate publicly disclosed by the service center, then verify the digital signature in the ordinary digital certificate using the post - quantum cryptographic public key, then obtain the ordinary public key of the service center from the ordinary digital certificate, and then verify the signature using the ordinary public key.
[0028] Occurs between user terminals, the user terminals belong to the same service center, the anti - quantum computing first service center is equal to the anti - quantum computing second service center, and includes the following steps:
[0029] S31. The first user terminal communicates with the corresponding anti - quantum computing first service center to generate a second session key, and the second user terminal communicates with the corresponding anti - quantum computing second service center to generate a third session key;
[0030] S32. The first client generates a first temporary key, signs the verification message, the second client identity information, and the first temporary key using the ordinary private key of the first client to obtain a fifth signature, forms an eleventh ciphertext with the verification message, the second client identity information, the first temporary key, the fifth signature, and the ordinary digital certificate of the first client, encrypts the eleventh ciphertext using the second session key to obtain a twelfth ciphertext, and sends the twelfth ciphertext to the service center corresponding to the first client;
[0031] S33. The service center corresponding to the first client decrypts the twelfth ciphertext using the second session key to obtain the eleventh ciphertext, finds the second service center corresponding to the second client that resists quantum computing according to the second client identity information, encrypts the eleventh ciphertext using the third session key to obtain a fourteenth ciphertext, and sends the fourteenth ciphertext to the second client;
[0032] S34. After receiving the fourteenth ciphertext, the second client decrypts the fourteenth ciphertext using the third session key to obtain the eleventh ciphertext, verifies the eleventh ciphertext, generates a second temporary key after passing the verification, signs the verification message, the first client identity information, and the second temporary key using the ordinary private key of the second client to obtain a sixth signature, forms a fifteenth ciphertext with the verification message, the first client identity information, the second temporary key, the sixth signature, and the ordinary digital certificate of the second client, encrypts the first temporary key to obtain a first key, encrypts the fifteenth ciphertext using the first key to obtain a sixteenth ciphertext, and sends the sixteenth ciphertext to the first client, generating a fourth session key;
[0033] S35. The first client verifies the sixteenth ciphertext, generates a fourth session key after passing the verification, and calculates a message authentication code for the first client identity information, the second client identity information, and the verification message using the fourth session key; sends the seventeenth ciphertext to the second client, and the seventeenth ciphertext includes the first client identity information, the second client identity information, the verification message, and the message authentication code;
[0034] S36. After receiving the seventeenth ciphertext, the second client verifies the message authentication code using the fourth session key, and confirms that the first client obtains the fourth session key after passing the verification;
[0035] S37. Use the fourth session key as the session key between the first client and the second client.
[0036] Occurs between user terminals, where the user terminals belong to different anti-quantum computing service centers. Step S33 is as follows: The service center corresponding to the first user terminal decrypts the twelfth ciphertext using the second session key to obtain the eleventh ciphertext, finds the second anti-quantum computing service center corresponding to the second user terminal according to the second user terminal identity information, generates the first digital certificate issued by the certificate authority of the first service center for the second service center using the public key of the second service center, encrypts the eleventh ciphertext and the first digital certificate using the first session key to obtain the thirteenth ciphertext, and sends the thirteenth ciphertext to the second service center corresponding to the second user terminal; After receiving the thirteenth ciphertext, the second service center corresponding to the second user terminal decrypts it using the first session key to obtain the eleventh ciphertext and the first digital certificate, generates the second digital certificate issued by the certificate authority of the second service center for the first service center using the public key of the first service center, encrypts the fourteenth ciphertext composed of the eleventh ciphertext, the first digital certificate and the second digital certificate using the third session key and sends it to the second user terminal;
[0037] The fifteenth ciphertext in S34 also includes the first digital certificate.
[0038] Optionally, verifying the eleventh ciphertext includes the following steps: verifying the second digital certificate using the public key of the second service center, then obtaining the public key of the first service center from the second digital certificate, then verifying the ordinary digital certificate of the first user terminal using the public key of the first service center, then obtaining the public key of the first user terminal from the ordinary digital certificate of the first user terminal, and then verifying the fifth signature using the public key of the first user terminal;
[0039] Preferably, the temporary key is calculated from a true random number generated by the user terminal; the fourth session key is calculated from the verification message, the true random number generated by the user terminal and the temporary key generated by another user terminal; the first key is obtained by performing a hash operation on the first temporary key.
[0040] Preferably, the verification information is the current timestamp; the session key is a true random number generated by the anti-quantum computing service center.
[0041] The beneficial effects of the invention are:
[0042] 1. This patent only needs to generate an asymmetric key pool from the public key and store it in the key card of the quantum-resistant computing service. Each client does not need to store the key card of the public key pool. Therefore, the cost for users to use the quantum-resistant computing solution is not high. In addition, since the data structure of traditional digital certificates is not changed, the cost for the CA and user application systems to switch to the quantum-resistant computing solution is not high. Moreover, the CA only needs to issue digital certificates to the quantum-resistant computing service, and the workload is greatly reduced. The quantum-resistant computing service undertakes the demand for users to apply for services, and the workload is reasonably diverted. In addition, only the quantum-resistant computing service stores the public key pool, and the public key pools of different quantum-resistant computing services are different. The key card with the public key pool is deployed together with the service and can generally be properly protected. The possibility of the key card being lost or stolen and then cracked is very small. Even if a user's key card is cracked, the public key in it is the public key of the quantum-resistant computing service, which only affects that quantum-resistant computing service and the other user key cards issued by it. And the quantum-resistant computing service is generally a service within a certain local area network, and the loss is controllable. Therefore, the situation that affects the security of all members basically does not occur, thus enhancing the security of the entire system.
[0043] 2. This patent does not need to deploy an additional key management server based on ID cryptography. Therefore, the cost for the CA and user application systems to switch to the quantum-resistant computing solution is not high.
[0044] 3. In this patent, a CA and a service based on post-quantum cryptography are built. However, a large number of client-side hardware does not need to support post-quantum cryptographic algorithms, that is, quantum-resistant computing communication can be achieved without hardware upgrade. Therefore, the huge hardware upgrade cost faced by the client side is avoided. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0046] Figure 1 is the system structure diagram according to the embodiment of the present invention;
[0047] Figure 2 is the communication flow chart between users in Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] To further illustrate the embodiments, the present invention provides accompanying drawings, which are part of the disclosure of the present invention. These drawings are mainly used to illustrate the embodiments and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention. The components in the drawings are not drawn to scale, and similar component symbols are usually used to represent similar components.
[0049] The present invention will be further described below in conjunction with the accompanying drawings and specific implementation manners. As Figure 1 shown, according to an embodiment of the present invention, a quantum-resistant computing communication method based on post-quantum cryptography CA is provided. This embodiment has a three-layer tree structure, namely the CA layer, the quantum-resistant computing service center layer, and the user layer.
[0050] In this patent, the system structure is as Figure 1 shown, including a Certificate Authority CA, a quantum-resistant computing service center S, and a user terminal, all of which are equipped with quantum-resistant computing key cards. The quantum-resistant computing key card has the characteristic of being non-dismantlable and can self-destruct when disassembled. Preferably, a security chip is provided inside the key card to achieve the non-dismantlable characteristic. The quantum-resistant computing service center S is generally a service providing center within a certain local area network.
[0051] The Certificate Authority CA in this patent is a CA system based on post-quantum cryptography, that is, it is established based on post-quantum cryptographic algorithms. The types of post-quantum cryptographic algorithms are not limited, such as algorithms based on mathematical principles such as error-correcting codes, hash functions, supersingular elliptic curve isogeny problems, lattices, and multivariate equations. The CA has a public key PKCA based on post-quantum cryptography, a private key SKCA based on post-quantum cryptography, a publicly available root certificate CERTCA based on post-quantum cryptography, and issues a digital certificate based on post-quantum cryptography to the quantum-resistant computing service center. The public key in CERTCA is PKCA, and the signature private key is SKCA.
[0052] The quantum-resistant computing key card of the quantum-resistant computing service center S stores internally a public key PKS PQ based on post-quantum cryptography, a private key SKS PQ based on post-quantum cryptography, a publicly available digital certificate CERTS PQ based on post-quantum cryptography, a common public key PKS, a common private key SKS, a non-public common digital certificate CERTS, and a public key pool composed of the public keys of all user key cards issued by the service center S. Among them, the public key in CERTS PQ is PKS PQ , the digital signature private key is SKCA, and this certificate is issued by the CA; the public key in CERTS is PKS, and the digital signature private key is SKS PQ, this certificate is issued by the CA in the service center S (i.e., CAS); the ordinary public and private keys of the quantum-resistant computing service center satisfy the computational relationship defined by the SM2 algorithm or the ECC algorithm, that is, PKS and SKS satisfy PKS = SKS * P, where P is the elliptic curve algorithm parameter.
[0053] The certificate authority CA can be a CA that serves the public or a private CA deployed within a company or family. However, the CA does not directly face users.
[0054] The quantum-resistant computing service center directly faces users. The quantum-resistant computing service center provides a user registration function, issues a quantum-resistant computing key card to the user terminal A, and the quantum-resistant computing key card of the user terminal A stores the ordinary public key of the service center, the ordinary public key PKA of the user terminal A, the ordinary private key SKA of the user terminal A, and an ordinary digital certificate CERTA that is not publicly disclosed by this key card. The public key in CERTA is PKA, and the digital signature private key is the ordinary private key of the service center. This certificate is issued by the CA in the service center, and the public and private keys of the user terminal satisfy the computational relationship defined by the SM2 algorithm or the ECC algorithm, that is, PKA and SKA satisfy PKA = SKA * P.
[0055] Example 1: Communication process between the user terminal and the quantum-resistant computing service center
[0056] Taking the authentication between the user terminal A and the service center SA corresponding to the user terminal A as an example:
[0057] The user terminal A extracts its own ordinary private key SKA and the ordinary public key PKSA of SA from the key card, and generates the current shared key K with SA in combination with the current timestamp TA A-SA = KDF(TA, SKA * PKSA); KDF(*, *): Key derivation function, such as the MAC function, that is, the message authentication code function.
[0058] The user terminal A generates a true random number RA and sends MSGA = IDA || TA || {SIG(IDA || TA, SKA) || CERTA}RA || {RA}K A-SA to SA; where IDA is the identity information of the user terminal A; TA is the current timestamp; SIG(IDA || TA, SKA) is the signature of IDA and TA using the ordinary private key of the user terminal A; CERTA represents the ordinary digital certificate of the user terminal A; {SIG(IDA || TA, SKA) || CERTA}RA is the encryption of the combination of SIG(IDA || TA, SKA) and CERTA using RA; {RA}K A-SA represents the encryption of RA using the shared key K A-SA for RA.
[0059] After the service center SA corresponding to the client A receives MSGA, it obtains PKA from the public key pool according to IDA, and generates the current shared key K with A according to SKSA in the key card and TA in MSGA SA-A = KDF(TA, SKSA * PKA). According to PKA = SKA * P and PKSA = SKSA * P, we have SKSA * PKA = SKSA * (SKA * P) = SKA * (SKSA * P) = SKA * PKSA, so K SA-A = KDF(TA, SKSA * PKA) = KDF(TA, SKA * PKSA) = K A-SA .
[0060] The service center SA corresponding to the client A uses the shared key K SA-A to decrypt MSGA to obtain RA, and further decrypts RA to obtain the signature and digital certificate. After verifying the digital certificate and signature respectively, it recognizes the identity of A; after recognizing the identity of A, the service center SA corresponding to the client A generates a true random number as the session key KS SA-A , and uses RA to confidentially send the session key KS to A SA-A and the signature of this message. That is, this message is MSGSA = IDSA || TA || {KS SA-A || SIG(IDSA || TA || KS SA-A , SKSA)}RA.
[0061] After the client A receives it, it uses RA to decrypt to obtain the session key KS SA-A and the signature of this message. After verifying the signature with the ordinary public key PKSA of SA, the identity authentication with SA is completed.
[0062] Subsequently, the two parties use the session key for confidential communication.
[0063] Similarly, the communication process between B and SB is similar, and the formed session key is KS SB-B .
[0064] Embodiment 2: Communication process between arbitrary services
[0065] Taking the authentication between the quantum-resistant computing service center SA and another quantum-resistant computing service center SB as an example:
[0066] SA extracts its own ordinary private key SKSA from the key card, and obtains the post-quantum cryptography public key PKSB of SB from the post-quantum cryptography digital certificate CERTSB PQ publicly disclosed by SB PQ, generate a true random number RA2 and combine it with the current timestamp TSA, send MSGSA=IDSA||TSA||{SIG(IDSA||TSA,SKSA)||CERTSA}RA2||ENC PQ (RA2,PKSB PQ ) to SA; IDSA is the identity information of SA; TSA is the current timestamp; SIG(IDSA||TSA,SKSA) is the use of SA's common private key SKSA to sign IDSA and TSA; CERTSA represents SA's common digital certificate; ENC PQ (RA2,PKSB PQ ) indicates the use of PKSB PQ RA2 is encrypted using post-quantum cryptography.
[0067] After SB receives MSGSA, use SKSB PQ About ENC PQ (RA2,PKSB PQ ) performs post-quantum cryptography decryption to obtain RA2, and further decrypts RA2 to obtain the signature and digital certificate. After verifying the digital certificate and signature respectively, the identity of SA is recognized: First, the post-quantum cryptography digital certificate CERTSA published by SA is obtained. PQ Get the post-quantum cryptographic public key PKSA of SA PQ Then use PKSA PQ Verify the digital signature in CERTSA, then obtain SA's common public key PKSA from CERTSA, and then use PKSA to verify SIG(IDSA||TSA,SKSA). After recognizing SA's identity, SB saves SA's common public key PKSA and generates a true random number as the session key KS SB-SA , the message sent is MSGSB=IDSB||TSA||{KS SB-SA ||SIG(IDSB||TSA||KS SB-SA ,SKSB)||CERTSB}RA2; IDSB is the identity information of SB; SIG(IDSB||TSA||KS SB-SA ,SKSB) is the common private key SKSB of SB to IDSB, TSA and KS SB-SA Signature; CERTSB indicates SB's common digital certificate.
[0068] After receiving SA, it uses RA2 to decrypt and obtain the session key KS SB-SA , digital signature and SB's ordinary digital certificate. After verifying the ordinary digital certificate and signature as described above, the identity authentication between SB is completed, and SB's ordinary public key PKSB is saved.
[0069] Subsequently, the two parties use the session key for secure communication.
[0070] Embodiment 3: Communication process between users belonging to different services
[0071] Suppose there are user A and user B, belonging to service SA and service SB respectively.
[0072] (1) The client A sends a message
[0073] The client A generates a true random number ra and calculates the temporary key RA = ra * P.
[0074] Encrypt MSGA = TA || IDB || RA || SIG(TA || IDB || RA, SKA) || CERTA using the session key KS between the client A and the service center SA corresponding to the client A SA-A and send it to SA. Here, TA is the current timestamp, IDB is the identity information of the client B, SIG(TA || IDB || RA, SKA) is the signature of TA, IDB, and the temporary key RA using the ordinary private key SKA of the client A, and CERTA is the ordinary digital certificate of the client A.
[0075] After receiving it, the service center SA uses the session key KS with A SA-A to decrypt it. According to the identity information IDB of the client B, find that the service it belongs to is the service center SB. SA generates the ordinary digital certificate CERTSB issued by SA's CA (i.e., CASA) for SB according to the ordinary public key PKSB of SB CASA . The public key in CERTSB CASA is PKSB, and the signature private key is SKSA.
[0076] The service center SA encrypts MSGA2 = MSGA || CERTSB CASA using the session key with SB and sends it to the service center SB.
[0077] After receiving it, the service center SB decrypts it using the session key with SA, and generates the ordinary digital certificate CERTSA issued by SB's CA (i.e., CASB) for SA according to the ordinary public key PKSA of SA CASB . The public key in CERTSB CASB is PKSA, and the signature private key is SKSB. Encrypt MSGA3 = MSGA || CERTSB CASA || CERTSA CASB using the session key KS with B SB-B and send it to B.
[0078] (2) B receives the message
[0079] After B receives the message, it uses the session key KS between it and SB SB-B to decrypt and obtain MSGA3. It uses PKSB to verify CERTSA CASB and then obtains the public key PKSA of SA from CERTSA CASB and then uses PKSA to verify CERTA, and then obtains the public key PKA of A from CERTA, and then uses PKA to verify SIG(TA||IDB||RA,SKA). After the verification passes, it recognizes A's identity.
[0080] (3) B sends a message
[0081] The client B generates a true random number rb and calculates the temporary key RB = rb * P.
[0082] It encrypts MSGB = TA||IDA||RB||SIG(TA||IDA||RB,SKB)||CERTB||CERTSB CASA with HASH(RA) and sends it to A. Among them, HASH(*) is a hashing algorithm, TA is the current timestamp, IDA is the identity information of the client A, SIG(TA||IDA||RB,SKB) is the signature of the current timestamp, the identity information of the client A, and the temporary key using the private key of the client B; CERTB is the public digital certificate of the client B.
[0083] The client B generates the session key KS B-A = KDF(TA,rb*RA).
[0084] For security considerations, the client does not permanently store the public keys or certificates of other clients, and preferably deletes them after successful authentication.
[0085] (4) The client A receives the message
[0086] After the client A receives the message, it decrypts the message using HASH(RA), and verifies the digital certificate and digital signature in the message in the manner described above. After the verification passes, it recognizes B's identity.
[0087] (5) The client A sends a message
[0088] The client A generates the session key KS A-B = KDF(TA,ra*RB). According to RA = ra * P and RB = rb * P, we have ra * RB = ra * (rb * P) = rb * (ra * P) = rb * RA, so KS A-B = KDF(TA,ra*RB) = KDF(TA,rb*RA) = KS B-A .
[0089] The client A generates MSGAB = IDA||IDB||TA||MAC(IDA||IDB||TA, KS A-B ), where IDA is the identity information of client A, IDB is the identity information of client B, TA is the current timestamp, and MAC(IDA||IDB||TA, KS A-B ) is to calculate the message authentication code for IDA, IDB, and TA using the session key KS A-B .
[0090] The client A sends MSGAB to the client B.
[0091] The client A uses KS A-B as the session key for communication with B.
[0092] (6) B receives the message
[0093] The client B uses KS B-A to verify the message authentication code MAC(IDA||IDB||TA, KS A-B ). After successful verification, it confirms that A has obtained the session key.
[0094] The client B uses KS B-A as the session key for communication with the client A.
[0095] (7) Secure communication between both parties
[0096] Subsequently, both parties use the session key for secure communication.
[0097] Embodiment 4: Communication process between users belonging to the same service
[0098] Suppose there are user A and user B, both belonging to service SA. There is a session key KS SA-A between the client A and the service center SA, and there is a session key KS SA-B between the client B and the service center SA.
[0099] (1) The client A sends out a message
[0100] The client A generates a true random number ra and calculates the temporary key RA = ra*P.
[0101] Encrypts MSGA = TA||IDB||RA||SIG(TA||IDB||RA, SKA)||CERTA using the session key KS SA-AIt is sent to SA after encryption, where TA is the current timestamp, IDB is the identity information of client B, SIG(TA||IDB||RA,SKA) is the signature of TA, IDB, and the temporary key RA using the ordinary private key SKA of client A, and CERTA is the ordinary digital certificate of client A.
[0102] After the service center SA receives it, it uses the session key KS with A SA-A to decrypt, and finds the service to which it belongs as the service center SA according to the identity information IDB of client B.
[0103] The service center SA encrypts MSGA with the session key KS with B SA-B and sends it to B.
[0104] (2) B receives the message
[0105] After B receives the message, it uses the session key KS with SA SA-B to decrypt to obtain MSGA. It verifies CERTA using PKSA, then obtains the ordinary public key PKA of A from CERTA, and then verifies SIG(TA||IDB||RA,SKA) using PKA. After the verification passes, it recognizes the identity of A.
[0106] (3) B sends out a message
[0107] Client B generates a true random number rb and calculates the temporary key RB = rb*P.
[0108] It encrypts MSGB = TA||IDA||RB||SIG(TA||IDA||RB,SKB)||CERTB with HASH(RA) and sends it to A. Among them, HASH(*) is the hash algorithm, TA is the current timestamp, IDA is the identity information of client A, SIG(TA||IDA||RB,SKB) is the signature of the current timestamp, the identity information of client A, and the temporary key using the ordinary private key of client B; CERTB is the ordinary digital certificate of client B.
[0109] Client B generates the session key KS B-A = KDF(TA,rb*RA).
[0110] For security considerations, the client does not permanently store the public keys or certificates of other clients, and preferably deletes them after successful authentication.
[0111] (4) Client A receives the message
[0112] After client A receives the message, it decrypts the message using HASH(RA), and verifies the digital certificate and digital signature in the message in the manner described above. After the verification passes, it recognizes the identity of B.
[0113] (5) The client A sends a message
[0114] The client A generates a session key KS A-B = KDF(TA, ra * RB). According to RA = ra * P and RB = rb * P, we have ra * RB = ra * (rb * P) = rb * (ra * P) = rb * RA. So KS A-B = KDF(TA, ra * RB) = KDF(TA, rb * RA) = KS B-A .
[0115] The client A generates MSGAB = IDA || IDB || TA || MAC(IDA || IDB || TA, KS A-B ), where IDA is the identity information of the client A, IDB is the identity information of the client B, TA is the current timestamp, and MAC(IDA || IDB || TA, KS A-B ) is the message authentication code calculated for IDA, IDB, and TA using the session key KS A-B .
[0116] The client A sends MSGAB to the client B.
[0117] The client A uses KS A-B as the session key for communication with B.
[0118] (6) B receives the message
[0119] The client B uses KS B-A to verify the message authentication code MAC(IDA || IDB || TA, KS A-B ). After successful verification, it confirms that A has obtained the session key.
[0120] The client B uses KS B-A as the session key for communication with the client A.
[0121] (7) Secure communication between both parties
[0122] Subsequently, both parties use the session key for secure communication.
[0123] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity in description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0124] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
Claims
1. A post - quantum - resistant communication system based on post - quantum cryptography CA, characterized in that, it includes a post - quantum - resistant service center, a certificate authority, and several user terminals. The certificate authority is constructed based on post - quantum cryptographic algorithms. All members are equipped with post - quantum - resistant key cards, and the post - quantum - resistant key cards have the property of being non - disassemblable; The post - quantum - resistant key card of the certificate authority stores the post - quantum cryptographic public and private keys of the certificate authority, the publicly available root certificate based on post - quantum cryptography, and issues a publicly available digital certificate based on post - quantum cryptography to the post - quantum - resistant service center; The post - quantum - resistant service center provides a user registration function and issues post - quantum - resistant key cards to user terminals. The post - quantum - resistant key card of the post - quantum - resistant service center internally stores a public key based on post - quantum cryptography, a private key based on post - quantum cryptography, a publicly available digital certificate based on post - quantum cryptography, a common public key of the service center, a common private key of the service center, a non - publicly available common digital certificate of the service center, and a public key pool composed of the public keys of all user key cards issued by the service center; The certificate authority of the post - quantum - resistant service center issues a non - publicly available common digital certificate of the service center; The post - quantum - resistant key card of the user terminal stores the common public key of the post - quantum - resistant service center, the common public and private keys of this user terminal, and a non - publicly available common digital certificate of this user - terminal key card. The non - publicly available common digital certificate of the user - terminal key card is issued by the certificate authority of the post - quantum - resistant service center; The user terminal does not permanently store the public keys or certificates of other user terminals; The common public and private keys satisfy the computational relationship defined by the elliptic curve algorithm; Implementing in the said system, a post - quantum - resistant communication method based on post - quantum cryptography CA, which occurs between the user terminal and the post - quantum - resistant service center, includes the following steps: S11. The user terminal generates a first shared key based on a key derivation function using its own common private key, the common public key of the post - quantum - resistant service center, and verification information, generates a first true random number, and signs the user terminal identity information and verification information using the common private key of the user terminal to obtain a first signature. Encrypts the first signature and the non - publicly available common digital certificate of the user terminal using the first true random number to obtain a first ciphertext. The user terminal sends a third ciphertext, and the third ciphertext includes the user terminal identity information, verification information, the first ciphertext, and a second ciphertext obtained by encrypting the first true random number using the first shared key; S12. After the anti-quantum computing service center corresponding to the client receives the third ciphertext, it obtains the ordinary public key of the client from the public key pool according to the identity information of the client, and generates the first shared key based on the key derivation function by using its own ordinary private key, verification information and the client's ordinary public key, and uses the first shared key to decrypt and verify the third ciphertext. After the verification passes, the anti-quantum computing service center generates a session key, signs the session key, verification message and the identity information of the anti-quantum computing service center by using the ordinary private key of the anti-quantum computing service center to obtain the second signature, encrypts the session key and the second signature by using the first true random number to obtain the fourth ciphertext, and forms the fifth ciphertext by combining the identity information of the anti-quantum computing service center, verification message and the fourth ciphertext and sends it to the client; S13. After the client receives the fifth ciphertext, it decrypts it by using the first true random number to obtain the session key and the second signature, and verifies the second signature by using the ordinary public key of the anti-quantum computing service center, and the authentication is completed; S14. The client and the corresponding anti-quantum computing service center conduct confidential communication by using the session key; Occurs between anti-quantum computing service centers, including the following steps: S21. The first service center extracts the post-quantum cryptography public key of the second service center from the post-quantum cryptography digital certificate publicly disclosed by the second service center, generates the second true random number, signs the identity information and verification message of the first service center by using the ordinary private key of the first service center to obtain the third signature, encrypts the ordinary digital certificate and the third signature that are not publicly disclosed by the first service center by using the second true random number to obtain the sixth ciphertext, encrypts the second true random number by using the post-quantum cryptography public key of the second service center based on post-quantum cryptography to obtain the seventh ciphertext, and forms the eighth ciphertext by combining the identity information of the first service center, verification message, sixth ciphertext and seventh ciphertext and sends it to the second service center; S22. After the second service center receives the eighth ciphertext, it decrypts the seventh ciphertext by using the post-quantum cryptography private key of the second service center to obtain the second true random number, decrypts the sixth ciphertext by using the second true random number to obtain the third signature and the ordinary digital certificate of the first service center, and verifies the digital certificate and the signature. After the verification passes, the second service center saves the ordinary public key of the first service center, and generates the first session key, signs the identity information, verification message and the first session key of the second service center by using the ordinary private key of the second service center to obtain the fourth signature, encrypts the first session key, the fourth signature and the ordinary digital certificate of the second service center by using the second true random number to obtain the ninth ciphertext, and forms the tenth ciphertext by combining the identity information of the second service center, verification message and the ninth ciphertext and sends it to the first service center; S23. After the first service center receives the tenth ciphertext, it decrypts it by using the second true random number to obtain the first session key, the fourth signature and the ordinary digital certificate of the second service center, verifies the signature and the digital certificate, and after the verification passes, confirms that it has obtained the first session key; S24. The first service center and the second service center conduct confidential communication by using the first session key; The verification of the digital certificate and signature includes the following steps: First, obtain the post-quantum cryptographic public key of the service center from the post-quantum cryptographic digital certificate publicly disclosed by the service center. Then, verify the digital signature in the ordinary digital certificate using the post-quantum cryptographic public key. Next, obtain the ordinary public key of the service center from the ordinary digital certificate, and then verify the signature using the ordinary public key; Occurs between user terminals. The user terminals belong to the same service center, and the first anti-quantum computing service center is equal to the second anti-quantum computing service center, including the following steps: S31. The first user terminal communicates with the corresponding first anti-quantum computing service center to generate a second session key, and the second user terminal communicates with the corresponding second anti-quantum computing service center to generate a third session key; S32. The first user terminal generates a first temporary key, signs the verification message, the identity information of the second user terminal, and the first temporary key using the ordinary private key of the first user terminal to obtain a fifth signature, forms an eleventh ciphertext by combining the verification message, the identity information of the second user terminal, the first temporary key, the fifth signature, and the ordinary digital certificate of the first user terminal, encrypts the eleventh ciphertext using the second session key to obtain a twelfth ciphertext, and sends the twelfth ciphertext to the service center corresponding to the first user terminal; S33. The service center corresponding to the first user terminal decrypts the twelfth ciphertext using the second session key to obtain the eleventh ciphertext, finds the second anti-quantum computing service center corresponding to the second user terminal according to the identity information of the second user terminal, encrypts the eleventh ciphertext using the third session key to obtain a fourteenth ciphertext, and sends the fourteenth ciphertext to the second user terminal; S34. After receiving the fourteenth ciphertext, the second user terminal decrypts the fourteenth ciphertext using the third session key to obtain the eleventh ciphertext, verifies the eleventh ciphertext. After passing the verification, a second temporary key is generated, the verification message, the identity information of the first user terminal, and the second temporary key are signed using the ordinary private key of the second user terminal to obtain a sixth signature, forms a fifteenth ciphertext by combining the verification message, the identity information of the first user terminal, the second temporary key, the sixth signature, and the ordinary digital certificate of the second user terminal, encrypts the first temporary key to obtain a first key, encrypts the fifteenth ciphertext using the first key to obtain a sixteenth ciphertext, and sends the sixteenth ciphertext to the first user terminal to generate a fourth session key; S35. The first user terminal verifies the sixteenth ciphertext. After passing the verification, a fourth session key is generated, and a message authentication code is calculated for the identity information of the first user terminal, the identity information of the second user terminal, and the verification message using the fourth session key; Send the seventeenth ciphertext to the second user terminal. The seventeenth ciphertext includes the identity information of the first user terminal, the identity information of the second user terminal, the verification message, and the message authentication code; S36. After receiving the seventeenth ciphertext, the second user terminal verifies the message authentication code using the fourth session key. After passing the verification, it confirms that the first user terminal obtains the fourth session key; S37. Use the fourth session key as the session key between the first user terminal and the second user terminal.
2. A quantum-resistant communication system based on a post-quantum cryptographic CA according to claim 1, wherein, Occurs between user terminals, where the user terminals belong to different post-quantum computing service centers. Step S33 is as follows: The service center corresponding to the first user terminal decrypts the twelfth ciphertext using the second session key to obtain the eleventh ciphertext, finds the second post-quantum computing service center corresponding to the second user terminal according to the second user terminal identity information, generates the first digital certificate issued by the certificate authority of the first service center for the second service center based on the public key of the second service center, encrypts the eleventh ciphertext and the first digital certificate using the first session key to obtain the thirteenth ciphertext, and sends the thirteenth ciphertext to the second service center corresponding to the second user terminal; after receiving the thirteenth ciphertext, the second service center corresponding to the second user terminal decrypts it using the first session key to obtain the eleventh ciphertext and the first digital certificate, generates the second digital certificate issued by the certificate authority of the second service center for the first service center based on the public key of the first service center, encrypts the fourteenth ciphertext composed of the eleventh ciphertext, the first digital certificate and the second digital certificate using the third session key and sends it to the second user terminal; The fifteenth ciphertext in S34 also includes the first digital certificate.
3. A post-quantum computing communication system based on post-quantum cryptography CA according to claim 2, characterized in that, Verifying the eleventh ciphertext includes the following steps: verifying the second digital certificate using the public key of the second service center, then obtaining the public key of the first service center from the second digital certificate, then verifying the ordinary digital certificate of the first user terminal using the public key of the first service center, then obtaining the public key of the first user terminal from the ordinary digital certificate of the first user terminal, and then verifying the fifth signature using the public key of the first user terminal.
4. A post-quantum computing communication system based on post-quantum cryptography CA according to claim 3, characterized in that, The temporary key is calculated from a true random number generated by the user terminal; the fourth session key is calculated from the verification message, the true random number generated by the user terminal and the temporary key generated by another user terminal; The first key is obtained by performing a hash operation on the first temporary key.
5. A post-quantum computing communication system based on post-quantum cryptography CA according to any one of claims 2-4, characterized in that, The verification information is the current timestamp; the session key is a true random number generated by the post-quantum computing service center.
Citation Information
Patent Citations
A quantum-resistant certificate issuance method and system based on public key pools
CN109918888B
Anti-quantum computing encryption device and anti-quantum computing encryption communication system
CN212115340U
An antiquantum computing HTTPS communication method and system based on an asymmetric key pool
CN109861813A
Antiquantum computing HTTPS signcryption communication method and system based on multiple asymmetric key pools
CN110213044A