Key Processing Method, Apparatus and System Based on Unified Multi-Domain Identification

By adopting a unified multi-domain identification key processing method in the era of the Internet of Things, using the identification mapping public key architecture and the identification binding public key architecture, the problem of traditional technology being difficult to achieve cross-domain key processing is solved, and the effects of lightweight, global key processing and low latency are achieved.

CN115001673BActive Publication Date: 2025-06-10YOUMI TECH (BEIJING) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210594925.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-05-23
Filing Date
2022-05-27
Publication Date
2025-06-10
Estimated Expiration
2042-05-27

AI Technical Summary

Technical Problem

It is difficult for the existing technology to realize cross-domain key processing in the Internet of Things era, and the traditional PKI/CA system and IBC system have limitations such as large computing resources, slow speed and high cost, making it difficult to meet the needs of the Internet of Things.

Method used

A key processing method based on unified multi-domain identification is adopted to realize cross-domain key processing through identification mapping public key architecture (IMPK) and identification binding public key architecture (IBPK). The specific implementation includes the root domain key management center (RKMC) and the domain key management center (DKMC), as well as the distribution of preset private key bases and preset public key bases, and jointly generates domain private keys and public keys.

Benefits of technology

It realizes lightweight, full-domain key processing, and low-latency cross-domain key processing, avoids the limitations of the traditional system and meets the needs of the Internet of Things era.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115001673B_ABST
    Figure CN115001673B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a key processing method, apparatus, and system based on a unified multi-domain identifier, belonging to the field of information security technology. The system includes: an identity mapping public key architecture and an identity binding public key architecture. Among them, the IMPK architecture includes a root domain key management center and the domain key management centers it manages. The RKMC is used to generate the domain private key of the DKMC and send it to the corresponding DKMC. The IBPK architecture includes the DKMC and all nodes within the domain it manages. Embodiments of the present disclosure are applicable to the key processing process of nodes within the entire domain.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of information security technology, and more particularly to a key processing method, apparatus, and system based on a unified multi-domain identifier. Background Art

[0002] With the rapid development of information and network communication technologies, especially the rapid development of the Internet of Things, information security issues have become increasingly prominent. In the Internet era, to address information security issues, a series of new cryptographic algorithms and corresponding information security solutions have been proposed in cryptography. For example, since 1976, symmetric encryption algorithm DEA (Data Encryption Algorithm) has emerged in cryptography, as well as a series of new cryptographic algorithms with different functions such as the Diffie-Hellman key exchange protocol, RSA asymmetric encryption algorithm, RSA digital signature algorithm, and MD5 Hash algorithm. In the direction of asymmetric cryptography (also known as public key cryptography), various public key encryption and digital signature algorithms such as the ElGamal algorithm and elliptic curve cryptography (ECC) over finite fields have gradually emerged later. Since public key cryptographic algorithms can be used for remote authentication and encryption on the Internet, these technologies have been widely applied in the Internet era.

[0003] However, when using asymmetric algorithms for encryption and authentication, it is first necessary to ensure that the public key is authentic and valid. In this regard, the technical concept of PKI (Public Key Infrastructure) has been proposed internationally, where a certification authority (CA) is responsible for "K" AIssue a verifiable certificate (signed by the CA for the certificate) for the assertion that "it is the valid public key of User A" to ensure the correctness of this assertion. In the PKI / CA system, multiple levels of CA institutions are required to provide certificate services for a large number of users. These services include the application, issuance, management, and assistance in verifying certificates of public key certificates. This not only requires network online and bandwidth resources, but also the construction and operation and maintenance costs of the CA are very high, thus greatly limiting the application and promotion of PKI. Therefore, in 1984, the cryptographer Shamir proposed the identity-based cryptosystem (IBC, Identity-Based Cryptograph). It "binds" the user's identity with the private key of the key generation center (KGC, Key Generation Center) to form the user's private key, without the need for the user's public key. Or rather, the user's identity identifier can be equivalently regarded as the public key, so there is no need for a public key certificate. However, the IBC algorithm requires a large amount of computing resources and has a slow computing speed, and it is a "heavyweight" cryptographic algorithm. These limitations of IBC make it equally difficult to promote and apply.

[0004] Especially in the Internet of Things era, on the one hand, a large number of Internet of Things terminals need authentication and encryption, and on the other hand, they have limited computing resources. They often also require cross-domain processing of keys and extremely short latency in the processing process. This makes both the PKI / CA system and the IBC system difficult to meet the needs of the Internet of Things era due to their limitations. Summary of the Invention

[0005] The purpose of the embodiments of the present disclosure is to provide a key processing method, device, and system based on a unified multi-domain identifier, which solves the problem of inability to perform cross-domain key processing, realizes both the advantages of the certificate system and the IBC system, can avoid their limitations, and can meet many requirements of the Internet of Things era, especially requirements such as lightweight, global key processing, and low latency.

[0006] To achieve the above purpose, the first aspect of the embodiments of the present disclosure provides a key processing system based on a unified multi-domain identifier. The system includes: an Identity Map to Public Key (IMPK) architecture and an Identity Bound Public Key (IBPK) architecture. Among them, the IMPK architecture includes a Root Key Management Center (RKMC) and the Domain Key Management Center (DKMC) it manages. The RKMC is used to generate the domain private key of the DKMC and send it to the corresponding DKMC. The IBPK architecture includes the DKMC and all nodes within the domain it manages.

[0007] Furthermore, the RKMC is further configured to generate a preset private key base and a preset public key base, and distribute the preset public key base to nodes in all domains, where the preset private key base is used to collaboratively generate a domain private key, and the preset public key base is used to collaboratively generate a domain public key.

[0008] Furthermore, the DKMC is further configured to collaboratively generate private keys for all nodes within a domain.

[0009] A second aspect of the embodiments of the present disclosure provides a key processing method based on a unified multi-domain identifier. The method is applied to a first terminal and includes: generating a self-selected private key factor corresponding to the first terminal identifier, and sending a key application message to a domain key management center DKMC, where the key application message includes the first terminal identifier and a self-selected public key factor corresponding to the self-selected private key factor; receiving key information returned by the DKMC, where the key information includes a distributed private key factor corresponding to the first terminal identifier generated by collaborating the domain private key of the DKMC and the self-selected public key factor; and obtaining a private key corresponding to the first terminal identifier by using the self-selected private key factor and the distributed private key factor.

[0010] Furthermore, the obtaining the private key corresponding to the first terminal identifier by using the self-selected private key factor and the distributed private key factor includes: according to sk 1 =(dsk 1 +usk 1 ) mod n, obtaining the private key sk 1 corresponding to the first terminal identifier, where usk 1 is the self-selected private key factor, dsk 1 is the distributed private key factor, and mod n is modulo n operation.

[0011] Furthermore, the key information further includes adjoint public key information corresponding to the first terminal identifier, and the method further includes: obtaining a public key of the first terminal according to the first terminal identifier, the adjoint public key information, and the domain public key of the DKMC.

[0012] Furthermore, when the adjoint public key information includes an adjoint public key, the obtaining the public key of the first terminal according to the first terminal identifier, the adjoint public key information, and the domain public key of the DKMC includes: according to pk 1 =apk 1 +h(ID 1 ||apk 1 )·pk 1DKMC , obtaining the public key pk 1 of the first terminal, where apk 1 is the adjoint public key, and ID1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 1DKMC is the domain public key of the DKMC.

[0013] Further, when the accompanying public key information includes an accompanying public key and the validity period of the accompanying public key, obtaining the public key of the first terminal according to the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC includes: According to pk 1 = apk 1 + h(ID 1 || apk 1 || ET 1 ) · pk 1DKMC , obtain the public key pk 1 of the first terminal, where apk 1 is the accompanying public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 1 is the validity period of the accompanying public key, and pk 1DKMC is the domain public key of the DKMC.

[0014] Further, the method further includes: using the public key corresponding to the first terminal identifier generated by the private key corresponding to the first terminal identifier as the first public key; using the public key of the first terminal generated by the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC as the second public key; determining whether the first public key is equal to the second public key; when it is determined that the first public key is equal to the second public key, determining that the public-private key pair corresponding to the first terminal identifier is correct; when it is determined that the first public key is not equal to the second public key, determining that the distribution of the private key factor and the accompanying public key information is incorrect.

[0015] Further, the method further includes an authentication process of the signature data sent by the second terminal by the first terminal: receiving the signature data sent by the second terminal, where the signature data includes the first terminal identifier, the data to be verified, the signature value, the second terminal identifier, and the accompanying public key information of the second terminal; determining the domain public key of the domain where the second terminal is located according to the domain identifier in the second terminal identifier; obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located; and verifying the signature value using the public key of the second terminal and the data to be verified to obtain the authentication result of the signature data.

[0016] Further, determining the domain public key of the domain where the second terminal is located according to the domain identifier in the second terminal identifier includes: determining whether the domain identifier in the first terminal identifier is the same as the domain identifier in the second terminal identifier; when it is determined that the domain identifiers of the two are the same, determining that the domain where the second terminal is located is the same as the domain where the first terminal is located, and determining the domain public key of the domain where the first terminal is located as the domain public key of the domain where the second terminal is located; when it is determined that the domain identifiers of the two are different, determining that the domain where the second terminal is located is different from the domain where the first terminal is located, and obtaining the domain public key of the domain where the second terminal is located according to a preset public key base and the domain identifier in the second terminal identifier.

[0017] Further, obtaining the domain public key of the domain where the second terminal is located according to a preset public key base and the domain identifier in the second terminal identifier includes: selecting a set number of factors of the hash value of the domain identifier in the second terminal identifier, and dividing the set number of factors into preset segments; using the set low-order bits in each preset segment to search for the selected factors in the preset public key base, and taking the remaining bits in each preset segment as the selection factor coefficients corresponding to the selected factors; according to obtaining the domain public key pk of the domain where the second terminal is located 2DKMC , where ID 2DKMC is the domain identifier in the second terminal identifier, h() is a hash function, is a query function, bpk j is the j-th selected factor, λ j is the selection factor coefficient of the j-th selected factor, and k is the number of selected factors.

[0018] Further, when the accompanying public key information includes an accompanying public key, obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key includes: according to pk 2 = apk 2 + h(ID 2 || apk 2 )·pk 2DKMC , obtaining the public key pk of the second terminal 2 , where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 2DKMC is the domain public key of the domain where the second terminal is located.

[0019] Further, when the accompanying public key information includes an accompanying public key and the validity period of the accompanying public key, obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key includes: according to pk 2= apk 2 + h(ID 2 || apk 2 || ET 2 )·pk 2DKMC , obtain the public key pk of the second terminal 2 , where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 2 is the validity period of the accompanying public key, pk 2DKMC is the domain public key of the domain where the second terminal is located.

[0020] A third aspect of the embodiments of the present disclosure provides a key processing method based on a unified multi-domain identifier. The method is applied to DKMC. The method includes: when receiving a key application message sent by a first terminal, generating a hidden private key factor, where the key application message includes the first terminal identifier and a self-selected public key factor; obtaining a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC; sending key information including the distribution private key factor to the first terminal, so that the first terminal uses the self-selected private key factor and the distribution private key factor to obtain the private key corresponding to the first terminal identifier.

[0021] Further, the obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC includes: obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor; obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC.

[0022] Further, the obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor includes: obtaining the hidden public key factor hpk 1 corresponding to the hidden private key factor hsk 1 according to hpk 1 = hsk 1 G; obtaining the accompanying public key apk 1 corresponding to the first terminal identifier according to apk 1 = hpk 1 + upk 1 , and generating the validity period of the accompanying public key, where upk 1is the selected public key factor; the adjoint public key corresponding to the first terminal identifier and the validity period of the adjoint public key are used as the adjoint public key information corresponding to the first terminal identifier.

[0023] Further, the obtaining of the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC includes: according to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DKMC , the distribution private key factor dsk 1 corresponding to the first terminal identifier is obtained, where h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, ET 1 is the validity period of the adjoint public key, * indicates that the content following it is an optional factor, and sk 1DKMC is the domain private key of the DKMC.

[0024] Further, the key information further includes the adjoint public key information corresponding to the first terminal identifier.

[0025] A fourth aspect of the embodiments of the present disclosure provides a key processing device based on a unified multi-domain identifier. The device is applied to a first terminal and includes: a self-selected factor generation module for generating a self-selected private key factor corresponding to the first terminal identifier; a communication module for sending a key application message to the DKMC, where the key application message includes the first terminal identifier and a self-selected public key factor corresponding to the self-selected private key factor; the communication module is further configured to receive key information returned by the DKMC, where the key information includes the distribution private key factor corresponding to the first terminal identifier jointly generated by using the domain private key of the DKMC and the self-selected public key factor; a private key generation module for obtaining the private key corresponding to the first terminal identifier by using the self-selected private key factor and the distribution private key factor.

[0026] The fifth aspect of the embodiments of the present disclosure provides a key processing device based on a unified multi-domain identifier. The device is applied to DKMC and includes: a communication module, configured to receive a key application message sent by a first terminal, where the key application message includes the first terminal identifier and a self-selected public key factor; a factor generation module, configured to generate a hidden private key factor; a distribution factor generation module, configured to obtain a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC; and the communication module is further configured to send key information including the distribution private key factor to the first terminal, so that the first terminal can use the self-selected private key factor and the distribution private key factor to obtain a private key corresponding to the first terminal identifier.

[0027] The sixth aspect of the embodiments of the present disclosure provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to cause a machine to execute the key processing method based on a unified multi-domain identifier applied to the first terminal and / or the key processing method based on a unified multi-domain identifier applied to DKMC as described in the above embodiments.

[0028] Through the key processing system based on a unified multi-domain identifier, a two-layer architecture system of IMPK architecture and IBPK architecture is provided. The IMPK architecture includes RKMC and the DKMC managed by it. The RKMC is configured to generate the domain private key of the DKMC and send it to the corresponding DKMC; the IBPK architecture includes the DKMC and all nodes within the domain managed by it. The embodiments of the present disclosure solve the problem of inability to perform cross-domain key processing, realize the advantages of both the certificate system and the IBC system, avoid their limitations, and can meet many requirements in the Internet of Things era, especially requirements such as lightweight, global key processing, and low latency.

[0029] Other features and advantages of the embodiments of the present disclosure will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The drawings are used to provide a further understanding of the embodiments of the present disclosure, and constitute a part of the specification. Together with the following specific implementation, they are used to explain the embodiments of the present disclosure, but do not constitute a limitation to the embodiments of the present disclosure. In the drawings:

[0031] Figure 1 is a schematic diagram of the architecture of a key processing system based on a unified multi-domain identifier provided by the embodiments of the present disclosure;

[0032] Figure 2 is a schematic diagram of the process of a key processing method based on a unified multi-domain identifier provided by the embodiments of the present disclosure;

[0033] Figure 3 It is a schematic flowchart of the authentication process of the signature data of the second terminal by the first terminal provided in an embodiment of the present disclosure;

[0034] Figure 4 It is a schematic flowchart of another key processing method based on a unified multi-domain identifier provided in an embodiment of the present disclosure;

[0035] Figure 5 It is a schematic structural diagram of a key processing device based on a unified multi-domain identifier provided in an embodiment of the present disclosure;

[0036] Figure 6 It is a schematic structural diagram of another key processing device based on a unified multi-domain identifier provided in an embodiment of the present disclosure. Detailed implementation manners

[0037] In order to make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of the present disclosure without creative efforts shall also fall within the scope of protection of the present disclosure.

[0038] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which the subject matter of the present disclosure belongs. Further, it will be understood that terms such as those defined in commonly used dictionaries shall be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and will not be interpreted in an idealized or overly formal form unless clearly defined herein otherwise.

[0039] Since public key encryption and authentication technologies are basic technologies for identity authentication and data encryption in network security and are even more indispensable in the Internet of Things era. However, the advent of the Internet of Things has led to a sharp increase in the number of entities or terminals that need to perform key processing. The traditional PKI / CA scheme has become difficult to adapt to the key processing of a large number of entities, especially cross-domain key processing, which is even more difficult. Therefore, the embodiments of the present disclosure propose a key processing method based on a unified multi-domain identifier, which not only has the advantages of the certificate system and the IBC system but also can avoid their limitations and meet many requirements in the Internet of Things era, especially requirements such as lightweight, global key processing, cross-domain key processing, and low latency.

[0040] The embodiments of the present disclosure are based on ECC-based public key algorithms, ElGamal public key algorithms, etc., including but not limited to the national commercial cryptography standard algorithm SM2. For the ECC-based public key algorithm, let the base field be F q, E q is an n - order additive cyclic group composed of elliptic curves over a finite field F q , where G is E q = <g>。

[0041] Example 1

[0042] In the first embodiment of the present disclosure, as Figure 1 shown, a key processing system based on a unified multi-domain identifier is provided, including a two-layer architecture system of an Identity Map to Public Key (IMPK) architecture 11 and an Identity Bound Public Key (IBPK) architecture 12. Among them, the IMPK architecture 11 includes a Root Key Management Center (RKMC) 111 and a Domain Key Management Center (DKMC) 112 managed by it. The RKMC 111 is used to generate the domain private key of the DKMC 112 and send it to the corresponding DKMC 112; the IBPK architecture 12 includes the DKMC 112 and all nodes 121 within the domain managed by it.

[0043] Among them, the RKMC is also used to randomly generate a preset private key base and a preset public key base, and distribute the preset public key base to the nodes of all domains. Among them, the preset private key base is used to cooperate in generating the domain private key, and the preset public key base is used to cooperate in generating the domain public key. The preset public key base contains r public keys, denoted as BPK = {bpk 1 , …, bpk r}. The preset private key base (abbreviated as BSK) corresponding to BPK is denoted as BSK = {bsk 1 , …, bsk r}. Moreover, bsk i and bpk i constitute a key pair, that is, bpk i = bsk i G. The RKMC is the core of the entire system. The preset private key base is a core sensitive parameter. The entire life cycle of the generation, storage, use, and destruction of the preset private key base is within the security device of the RKMC, and any external access is prohibited. In addition, in addition to distributing the domain private keys of each DKMC, the RKMC is also responsible for updating the domain private keys of each DKMC and the update of the domain identifiers of each DKMC. The preset public key base is a system public parameter, stored in each node, and can be regarded as a basic parameter in this embodiment of the present disclosure like the elliptic curve used.

[0044] Among them, the DKMC is also used to collaboratively generate the private keys of all nodes within the domain. In addition, the DKMC is also responsible for the generation and distribution of the private key factors for all nodes within its domain, the collaborative update of the node private keys, and the revocation management of the unified multi-domain identities of the nodes, etc.

[0045] In addition, there is also an edge gateway (not shown in the figure) between the DKMC and the nodes it manages, which is used to control the communication mechanism of the nodes managed by the DKMC.

[0046] Among them, the RKMC represents the root domain, and 1 to n DKMCs represent several different subdomains. The concept of the domain involved in the embodiments of the present disclosure has a wide range of applications. Taking the Ministry of Public Security as an example, all the nodes under the jurisdiction of the Ministry of Public Security form a global domain. The Ministry of Public Security is the RKMC in the global domain. Each provincial department and directly affiliated unit of the Ministry of Public Security constitute multiple subdomains, and each provincial department and directly affiliated unit of the Ministry of Public Security is the DKMC under the management of the RKMC. Each node under the management of the DKMC refers to any subject, device, equipment, etc. that needs to be authenticated.

[0047] Embodiment 2

[0048] Figure 2 It is a schematic flow diagram of a key processing method based on a unified multi-domain identity provided by the embodiments of the present disclosure. As Figure 2 shown, the method is applied to a first terminal, that is, a node under the management of a certain DKMC, and includes the following steps:

[0049] Step 201, generate a self-selected private key factor corresponding to the first terminal identifier, and send a key application message to the DKMC to which it belongs. The key application message includes the first terminal identifier and a self-selected public key factor corresponding to the self-selected private key factor;

[0050] Step 202, receive the key information returned by the DKMC. The key information includes a distributed private key factor corresponding to the first terminal identifier generated by collaborating the domain private key of the DKMC with the self-selected public key factor;

[0051] Step 203, use the self-selected private key factor and the distributed private key factor to obtain the private key corresponding to the first terminal identifier.

[0052] Among them, the unified multi-domain identity (UMI) proposed in the embodiments of the present disclosure, each different identity can have a public and private key pair. The identity of the UMI includes at least two segments. The front segment is the domain identifier, and the back segment is the identifier of the node within the domain (including users, devices, etc.). Among them, since the root domain also occupies a domain identifier, if the length of the domain identifier is k, the global domain can include 2 k -1 sub - domain. If the length of the node identifier in the domain is l, the number of entities in this domain can reach 2 l -1, and thus the identifier length of each node in the global domain is k + l.

[0053] Among them, the first terminal randomly generates a self - selected private key factor usk corresponding to the first terminal identifier 1 . Additionally, when generating the self - selected private key factor, the self - selected public key factor upk corresponding to the self - selected private key factor can be obtained by using the elliptic curve base point and the self - selected private key factor 1 , that is, upk 1 = usk 1 ·G. After that, in order to apply for the private key, the first terminal sends the first terminal identifier and the self - selected public key factor corresponding to the self - selected private key factor to its affiliated DKMC together.

[0054] After the first terminal receives the key information returned by the DKMC, it generates its private key by using the distributed private key factor and the self - selected private key factor in it. Specifically, the private key sk corresponding to the first terminal identifier is obtained according to the following formula (1) 1 :

[0055] sk 1 =(dsk 1 + usk 1 ) mod n Formula (1)

[0056] Among them, usk 1 is the self - selected private key factor, dsk 1 is the distributed private key factor, and mod n is the modulo n operation. The private key corresponding to the first terminal identifier can be used in the data signature process.

[0057] Additionally, the key information also includes the accompanying public key information corresponding to the first terminal identifier. The first terminal can obtain the public key of the first terminal according to the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC.

[0058] Specifically, when the accompanying public key information includes the accompanying public key, the public key pk of the first terminal is obtained according to the following formula (2) 1 :

[0059] pk 1 = apk 1 + h(ID 1 || apk 1 )·pk 1DKMC Formula (2)

[0060] Among them, apk 1 is the accompanying public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 1DKMC is the domain public key of the DKMC.

[0061] When the accompanying public key information includes the accompanying public key and the validity period of the accompanying public key, the public key pk of the first terminal is obtained according to the following formula (3) 1 :

[0062] pk 1 = apk 1 + h(ID 1 || apk 1 || ET 1 ) · pk 1DKMC Formula (3)

[0063] where, apk 1 is the accompanying public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 1 is the validity period of the accompanying public key, and pk 1DKMC is the domain public key of the DKMC.

[0064] Among them, since the first terminal exists in the DKMC, therefore, the domain public key of the DKMC is required to participate in the calculation when calculating its public key. The domain public key of the DKMC can be obtained through the following method:

[0065] Select a set number of factors of the hash value of the domain identifier in the first terminal identifier, and divide the set number of factors into preset segments. Then, use the set low-order bits in each preset segment to search for the selected factors in the preset public key base, and use the remaining bits in each preset segment as the selection factor coefficients corresponding to the selected factors. Then, according to the following formula (4), obtain the domain public key pk of the domain where the first terminal is located 1DKMC :

[0066]

[0067] where ID 1DKMC is the domain identifier in the first terminal identifier, h() is a hash function, is a query function, bpk j is the jth selected factor, and λ j is the jth selection factor coefficient, and k is the number of selected factors.

[0068] Specifically, calculate the hash value h(ID of the domain identifier in the first terminal identifier 1DKMC ), Select a set number of factors from the hash values. Generally, the set number l is 256, 160, or 128. Then, divide the set number of factors into a preset number of segments k, and l is an integer multiple of k. Assume the length of each preset segment is m, then l = mk. Use the set number of low-order bits t in each preset segment to obtain the selected factors in the corresponding preset public key basis for each preset segment. Thus, as many selected factors can be obtained as there are preset segments, that is, k selected factors can be obtained. Then use the remaining bits in each preset segment as the corresponding selected factor coefficients, that is, use the m - t bits in each preset segment as the selected factor coefficients, and the k obtained selected factor coefficients are λ 1 , λ 2 , …, λ k . Thus, according to the above formula (4), obtain the domain public key pk of the domain where the first terminal is located 1DKMC . In addition, to adapt to the situation of limited terminal storage space, it is recommended that k = 4 and t = 2.

[0069] Similarly, when the first terminal obtains another terminal identifier, it can calculate the domain identifier of the domain where the other terminal is located. Whether the other terminal and the first terminal are in the same domain or across domains, it can be obtained through the above formula (4), as long as the domain identifier in the first terminal identifier in formula (4) is replaced with the domain identifier in the other terminal identifier.

[0070] After the first terminal calculates its private key through formula (1), it can use the public key corresponding to the private key generated by the first terminal identifier, that is, pk′ 1 = sk 1 ·G, and use this public key as the first public key. At the same time, use the public key of the first terminal generated by the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC as the second public key, that is, use the public key pk 1 obtained from formula (2) or formula (3) as the second public key. Then, determine whether the first public key is equal to the second public key. When it is determined that the first public key is equal to the second public key, it is determined that the public-private key pair corresponding to the first terminal identifier is correct; when it is determined that the first public key is not equal to the second public key, it is determined that the distribution of the private key factor and the accompanying public key information is incorrect, and the DKMC needs to redistribute.

[0071] Under the condition that the first terminal can calculate the domain identifier of the domain where the other terminal is located using the domain identifier in the other terminal identifier, when the first terminal obtains the signature data of the other terminal, global authentication can be achieved, that is, any two ends in the root domain and all subdomains can perform public key-based authentication, including intra-domain authentication and cross-domain authentication.

[0072] Figure 3 It is a schematic flowchart of the authentication process of the signature data sent by the first terminal to the second terminal provided by an embodiment of the present disclosure. As Figure 3 shown, the following steps are included:

[0073] Step 301: Receive the signature data sent by the second terminal. The signature data includes the first terminal identifier, the data to be verified, the signature value, the second terminal identifier, and the accompanying public key information of the second terminal.

[0074] Among them, the first terminal and the second terminal are two nodes in the global domain. When two-way unified strong authentication is required between the second terminal and the first terminal, that is, digital signature based on the asymmetric algorithm is used for authentication, taking the second terminal sending signature data to the first terminal as an example, the first terminal needs to use the public key of the second terminal to verify the signature value in the signature data.

[0075] Among them, M is the data to be verified, which is the data that the second terminal sends to the first terminal and needs to be verified. S 2 is the signature value. In the embodiment of the present disclosure, S 2 = Sig(sk 2 , h(ID 2 ||M)), that is, the signature content includes the second terminal identifier ID 2 and the data M. We usually use the symbol Sig ψ (sk A ) to represent that node A signs the message M using the signature algorithm ψ and its own private key sk A . When ψ is the default algorithm, it is abbreviated as Sig(sk A , M). Since the hash value h(M) of M is used during actual signature, it is sometimes also written as Sig ψ (sk A , h(M)).

[0076] In addition, ID 2 is the second terminal identifier. When the validity period of the accompanying public key is issued, the accompanying public key information includes the accompanying public key apk 2 of the second terminal and the validity period ET 2 of the accompanying public key. When the validity period of the accompanying public key is not issued, the accompanying public key information includes the accompanying public key apk 2 of the second terminal.

[0077] Step 302: Determine the domain public key of the domain where the second terminal is located according to the domain identifier in the second terminal identifier.

[0078] Among them, the first terminal and the second terminal may exist in the same subdomain or in different subdomains. Therefore, it is possible to determine whether they are in the same subdomain by judging whether the domain identifier in the first terminal identifier is the same as the domain identifier in the second terminal identifier. Since the identifier of each terminal contains two parts: a domain identifier and an in-domain identifier. Therefore, when it is determined that the domain identifiers of the two are the same, it is determined that the domain where the second terminal is located is the same as the domain where the first terminal is located, and the domain public key of the domain where the first terminal is located is determined as the domain public key of the domain where the second terminal is located, that is, the domain public keys of the two are the same and known.

[0079] When it is determined that the domain identifiers of the two are different, it is determined that the domain where the second terminal is located is different from the domain where the first terminal is located, and the domain public key of the domain where the second terminal is located is obtained according to the preset public key base and the domain identifier in the second terminal identifier. Since each terminal stores the same preset public key base BPK = {bpk 1 , …, bpk r} locally, the locally stored preset public key base can be used to participate in the calculation.

[0080] Specifically, a set number of factors of the hash value of the domain identifier in the second terminal identifier are selected, and the set number of factors are divided into preset segments. First, calculate the hash value h(ID 2DKMC ) of the domain identifier in the second terminal identifier, and select a set number of factors. Generally, the set number l is 256, 160, or 128. Then, the set number of factors are divided into preset segments k, and l is an integer multiple of k. Assume that the length of each preset segment is m, then l = mk. Using the set low-order bits t in each preset segment, the selected factors in the preset public key base corresponding to each preset segment are obtained. Thus, as many preset segments as there are, as many selected factors can be obtained, that is, k selected factors can be obtained. Then, the remaining bits in each preset segment are used as the corresponding selected factor coefficients, that is, m - t bits are used as the selected factor coefficients, and the k selected factor coefficients obtained are λ 1 , λ 2 , …, λ k . Then, the domain public key pk 2DKMC of the domain where the second terminal is located is obtained according to the following formula (5):

[0081]

[0082] Where ID 2DKMC is the domain identifier in the second terminal identifier, h() is the hash function, is the query function, bpk j is the jth selected factor, λ j is the coefficient of the j-th selection factor, and k is the number of the selection factors, that is, the preset segment. Similarly, in order to adapt to the situation of limited storage space of the terminal, it is recommended that k = 4 and t = 2.

[0083] Step 303: Obtain the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located.

[0084] Through the above step 202, whether the first terminal and the second terminal are in the same domain or across domains, the domain public key of the domain where the second terminal is located can be obtained.

[0085] When the accompanying public key information includes the accompanying public key apk 2 at this time, the public key pk of the second terminal is obtained according to the following formula (6) 2 :

[0086] pk 2 = apk 2 + h(ID 2 || apk 2 )·pk 2DKMC Formula (6)

[0087] where "||" is a concatenation operator.

[0088] When the accompanying public key information includes the accompanying public key apk 2 and the validity period ET of the accompanying public key 2 at this time, the public key pk of the second terminal is obtained according to the following formula (7) 2 :

[0089] pk 2 = apk 2 + h(ID 2 || apk 2 || ET 2 )·pk 2DKMC Formula (7)

[0090] Step 304: Verify the signature value by using the public key of the second terminal and the data to be verified, and obtain the authentication result of the signature data.

[0091] The first terminal can use the public key pk of the second terminal 2 and the data to be verified to verify the signature value S 2 If the verification passes, the identity identifier of the second terminal is authenticated, and at the same time, it is verified that the data M is indeed sent from the second terminal to the first terminal. That is to say, the authentication content of the embodiments of the present disclosure includes both that the second terminal is the real source, that is, the identity identifier of the second terminal is authenticated, and that the first terminal is the destination designated by the second terminal, that is, the identity identifier of the message receiver is authenticated, and at the same time, the integrity of the data M is also authenticated. If M contains a time value, the freshness of the data M, that is, the real-time nature of the communication, can be further authenticated.

[0092] In addition, if encryption services are required during the authentication process, both parties need to authenticate first and negotiate a session key, or one party designates a session key, encrypts the session key with the public key of the other party, and then places the encrypted data in M.

[0093] The authentication process of the second terminal for the signature data of the first terminal is similar to the above embodiments and will not be elaborated here.

[0094] The reason why cross-domain authentication can be performed between the first terminal and the second terminal lies in that there is the same preset public key base in the global domain. In this way, although the first terminal and the second terminal are not in the same domain, they can calculate the domain public key of the other party's domain from the preset public key base, and thus can calculate the public key of the other party. In addition, considering that the storage space of many terminal nodes may be limited, the public key base should not be too large. We suggest that r ≤ 16.

[0095] In addition, when the first terminal needs to send encrypted data to the second terminal, the data to be encrypted is similarly encrypted using the public key of the second terminal, and the public key of the second terminal is also obtained through the above formula (6) or formula (7) after obtaining the accompanying public key information of the second terminal, so as to encrypt the data to be encrypted. After the second terminal obtains the encrypted data, Figure 2 the private key of the second terminal is obtained through the shown embodiment, and the second terminal decrypts the encrypted data.

[0096] Embodiments of the present disclosure are based on lightweight cryptographic algorithms, have a wide range of applications, do not use certificates, and there is a corresponding or binding relationship between the public key of a terminal (host or entity) and its identity identifier. However, different from IBC, it can achieve intra-domain authentication in multiple domains, cross-domain authentication between multiple domains, etc., and the authentication delay is relatively small. There is a root domain above multiple domains, and the root domain and its respective sub-domains form the entire domain, so it is also called global domain authentication. Among them, the entity public key is calculated by the user (data encryptor or digital signature verifier), and the calculation process needs to use the identifier of the public key owner and the domain public key of the domain to which it belongs, so that the calculation process of the public key is the "proof" process of the public key, which is a lightweight public key management method with a light center. It neither depends on public key certificates (PKI CA) nor is it the same as the identity-based cryptosystem (IBC), and can effectively reduce the computational amount brought by verifying public key certificates and the communication amount of certificate transmission. Its public key management system is simple, and the construction and operation and maintenance costs are low, and it is especially suitable for scenarios where network environment, computing resources, and communication resources are limited, including the Internet of Things scenario.

[0097] Embodiment III

[0098] Figure 4 is a schematic flowchart of a key processing method based on a unified multi-domain identifier provided by an embodiment of the present disclosure. As Figure 4 shown, the method is applied to DKMC and includes the following steps:

[0099] Step 401, when receiving a key application message sent by a first terminal, generate a hidden private key factor, where the key application message includes the first terminal identifier and a self-selected public key factor;

[0100] Step 402, obtain a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC;

[0101] Step 403, send key information including the distribution private key factor to the first terminal, so that the first terminal uses the self-selected private key factor and the distribution private key factor to obtain a private key corresponding to the first terminal identifier.

[0102] Among them, when the DKMC receives the key application message sent by the first terminal, it randomly generates a hidden private key factor hsk 1 , and then obtains the adjoint public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor. Specifically, the hidden private key factor hsk 1 corresponding hidden public key factor hpk 1 is obtained according to the following formula (8):

[0103] hpk 1 = hsk 1 G formula (8)

[0104] After that, the adjoint public key apk corresponding to the first terminal identifier is obtained according to the following formula (9) 1 :

[0105] apk 1 = hpk 1 + upk 1 Formula (9)

[0106] where upk 1 is the self - selected public key factor. At the same time, the validity period ET of the adjoint public key is generated 1 . The adjoint public key corresponding to the first terminal identifier and the validity period of the adjoint public key are used as the adjoint public key information corresponding to the first terminal identifier.

[0107] Then, according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC, the distribution private key factor corresponding to the first terminal identifier is obtained. Specifically, the distribution private key factor dsk corresponding to the first terminal identifier is obtained according to the following formula (10) 1 :

[0108] dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DKMC Formula (10)

[0109] where h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, ET 1 is the validity period of the adjoint public key, * indicates that the content following it is an optional factor, and sk 1DKMC is the domain private key of the DKMC.

[0110] In addition, when sending the distribution private key factor to the first terminal, the adjoint public key information corresponding to the first terminal identifier can also be included in the key information.

[0111] In addition, the generation of the domain private key of the DKMC is the responsibility of the RKMC, but its generation process is similar to that of its domain public key generation process, except that the preset public key base is replaced with a preset private key base.

[0112] Embodiment 4

[0113] Figure 5 is a schematic structural diagram of a key processing device based on a unified multi - domain identifier provided by an embodiment of the present disclosure. As Figure 5 As shown, the device is applied to a first terminal. The device 50 includes: a self - selected factor generation module 51, configured to generate a self - selected private key factor corresponding to the first terminal identifier; a communication module 52, configured to send a key application message to the DKMC, where the key application message includes the first terminal identifier and a self - selected public key factor corresponding to the self - selected private key factor; the communication module is further configured to receive key information returned by the DKMC, where the key information includes a distributed private key factor corresponding to the first terminal identifier co - generated by using the domain private key of the DKMC and the self - selected public key factor; a private key generation module 53, configured to obtain the private key corresponding to the first terminal identifier by using the self - selected private key factor and the distributed private key factor.

[0114] Further, the private key generation module is specifically configured to: According to sk 1 =(dsk 1 +usk 1 ) mod n, obtain the private key sk 1 corresponding to the first terminal identifier, where usk 1 is the self - selected private key factor, dsk 1 is the distributed private key factor, and mod n is the modulo n operation.

[0115] Further, the key information further includes adjoint public key information corresponding to the first terminal identifier. The device further includes: a public key generation module 54, configured to obtain the public key of the first terminal according to the first terminal identifier, the adjoint public key information, and the domain public key of the DKMC.

[0116] Further, when the adjoint public key information includes an adjoint public key, the public key generation module is specifically configured to: According to pk 1 =apk 1 +h(ID 1 ||apk 1 )·pk 1DKMC , obtain the public key pk 1 of the first terminal, where apk 1 is the adjoint public key, ID 1 is the first terminal identifier, h() is a hash function, "||” is a concatenation operator, and pk 1DKMC is the domain public key of the DKMC.

[0117] Further, when the adjoint public key information includes an adjoint public key and the validity period of the adjoint public key, the public key generation module is specifically configured to: According to pk 1 =apk 1 +h(ID 1 ||apk 1 ||ET 1 )·pk 1DKMC , obtain the public key pk of the first terminal 1 , where apk 1 is the accompanying public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 1 is the validity period of the accompanying public key, pk 1DKMC is the domain public key of the DKMC.

[0118] Furthermore, the device further includes: a private key verification module 55, configured to use the public key corresponding to the first terminal identifier generated by the private key corresponding to the first terminal identifier as the first public key; use the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC to generate the public key of the first terminal as the second public key; determine whether the first public key is equal to the second public key; when it is determined that the first public key is equal to the second public key, determine that the public-private key pair corresponding to the first terminal identifier is correct; when it is determined that the first public key is not equal to the second public key, determine that the distribution of the private key factor and the accompanying public key information is incorrect.

[0119] Furthermore, the method further includes: an authentication module 56, configured to perform an authentication process on the signature data sent by the second terminal by the first terminal; the communication module is further configured to receive the signature data sent by the second terminal, and the signature data includes the first terminal identifier, the data to be verified, the signature value, the second terminal identifier, and the accompanying public key information of the second terminal; the authentication module is specifically configured to: determine the domain public key of the domain where the second terminal is located according to the domain identifier in the second terminal identifier; obtain the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located; use the public key of the second terminal and the data to be verified to verify the signature value, and obtain the authentication result of the signature data.

[0120] Furthermore, the authentication module is further configured to: determine whether the domain identifier in the first terminal identifier is the same as the domain identifier in the second terminal identifier; when it is determined that the domain identifiers of the two are the same, determine that the domain where the second terminal is located is the same as the domain where the first terminal is located, and determine the domain public key of the domain where the first terminal is located as the domain public key of the domain where the second terminal is located; when it is determined that the domain identifiers of the two are different, determine that the domain where the second terminal is located is different from the domain where the first terminal is located, and obtain the domain public key of the domain where the second terminal is located according to the preset public key base and the domain identifier in the second terminal identifier.

[0121] Further, the authentication module is further configured to: select a set number of factors of the hash value of the domain identifier in the second terminal identifier, and divide the set number of factors into preset segments; use the set low-order bits in each preset segment to search for the selected factors in the preset public key base, and use the remaining bits in each preset segment as the selection factor coefficients corresponding to the selected factors; according to obtain the domain public key pk 2DKmC of the domain where the second terminal is located, where 2DKMC ID is the domain identifier in the second terminal identifier, h() is a hash function, is a query function, bpk j is the j-th selected factor, λ j is the selection factor coefficient of the j-th selected factor, and k is the number of the selected factors.

[0122] Further, when the accompanying public key information includes an accompanying public key, the authentication module is further configured to: according to pk 2 = apk 2 + h(ID 2 || apk 2 )·pk 2DkMC , obtain the public key pk 2 of the second terminal, where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 2DKMC is the domain public key of the domain where the second terminal is located.

[0123] Further, when the accompanying public key information includes an accompanying public key and the validity period of the accompanying public key, the authentication module is further configured to: according to pk 2 = apk 2 + h(ID 2 || apk 2 || ET 2 )·pk 2DKMC , obtain the public key pk 2 of the second terminal, where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 2 is the validity period of the accompanying public key, and pk 2DKMC is the domain public key of the domain where the second terminal is located.

[0124] The specific working principle and benefits of the key processing device based on unified multi-domain identifiers provided in the embodiments of the present disclosure are similar to those of the key processing method based on unified multi-domain identifiers provided in the second embodiment of the present disclosure, and will not be elaborated here.

[0125] Example 5

[0126] Figure 6 It is a schematic structural diagram of a key processing device based on a unified multi - domain identifier provided by an embodiment of the present disclosure. As Figure 6 shown, the device is applied to DKMC, and the device 60 includes: a communication module 61, configured to receive a key application message sent by a first terminal, where the key application message includes the first terminal identifier and a self - selected public key factor; a factor generation module 62, configured to generate a hidden private key factor; a distribution factor generation module 63, configured to obtain a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self - selected public key factor, and the domain private key of the DKMC; and the communication module is further configured to send key information including the distribution private key factor to the first terminal, so that the first terminal uses the self - selected private key factor and the distribution private key factor to obtain a private key corresponding to the first terminal identifier.

[0127] Further, the distribution factor generation module is specifically configured to: obtain adjoint public key information corresponding to the first terminal identifier according to the hidden private key factor and the self - selected public key factor; and obtain a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC.

[0128] Further, the distribution factor generation module is further configured to: according to hpk 1 = hsk 1 G, obtain a hidden public key factor hpk 1 corresponding to the hidden private key factor hsk 1 ; according to apk 1 = hpk 1 + upk 1 , obtain an adjoint public key apk 1 corresponding to the first terminal identifier, and generate a validity period of the adjoint public key, where upk 1 is the self - selected public key factor; and use the adjoint public key corresponding to the first terminal identifier and the validity period of the adjoint public key as the adjoint public key information corresponding to the first terminal identifier.

[0129] Further, the distribution factor generation module is further configured to: according to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DKMC , obtain a distribution private key factor dsk corresponding to the first terminal identifier 1 where h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, and ET 1 is the validity period of the accompanying public key, and * indicates that the content following it is an optional factor, and sk 1DKMC is the domain private key of the DKMC.

[0130] Furthermore, the key information further includes the accompanying public key information corresponding to the first terminal identifier.

[0131] Embodiment Six

[0132] The embodiments of the present disclosure provide a machine-readable storage medium, on which instructions are stored, and the instructions are used to cause a machine to execute the key management method based on a unified multi-domain identifier described in Embodiment Two above, and / or the key management method based on a unified multi-domain identifier described in Embodiment Three above.

[0133] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0134] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0135] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0136] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the steps in a process Figure 1 one process or multiple processes and / or blocks Figure 1 or steps of the functions specified in multiple blocks.

[0137] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0138] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0139] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0140] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.

[0141] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.< / g>

Claims

1. A key processing system based on a unified multi-domain identifier, characterized in that, the system includes: an identity mapping public key IMPK architecture and an identity binding public key IBPK architecture, wherein, the IMPK architecture includes a root domain key management center RKMC and domain key management centers DKMC managed by it, and the RKMC is used to generate the domain private key of the DKMC and send it to the corresponding DKMC; the IBPK architecture includes the DKMC and all nodes within the domain managed by it, wherein, the DKMC includes a key processing device based on a unified multi-domain identifier, and this device includes: a communication module, used to receive a key application message sent by a first terminal, and the key application message includes a first terminal identifier and a self-selected public key factor; a factor generation module, used to generate a hidden private key factor; a distribution factor generation module, used to obtain a distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC; the communication module is also used to send key information including the distribution private key factor to the first terminal, so that the first terminal can use the self-selected private key factor and the distribution private key factor to obtain the private key corresponding to the first terminal identifier; wherein, the distribution factor generation module is also used to: obtain the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor; obtain the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC; Among them, the distribution factor generation module is further configured to: according to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 ) · sk 1DKMC , obtain the distribution private key factor dsk 1 corresponding to the first terminal identifier, where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the accompanying public key in the accompanying public key information, ET 1 is the validity period of the accompanying public key, * indicates that the content after it is an optional factor, and sk 1DKM is the domain private key of the DKMC; wherein, the nodes within the domain managed by the DKMC include a first terminal, and the first terminal includes a key processing device based on a unified multi-domain identifier, and this device includes: a self-selected factor generation module, used to generate a self-selected private key factor corresponding to the first terminal identifier; a communication module, used to send a key application message to the domain key management center DKMC, and the key application message includes the first terminal identifier and a self-selected public key factor corresponding to the self-selected private key factor; the communication module is also used to receive the key information returned by the DKMC, and the key information includes the distribution private key factor corresponding to the first terminal identifier jointly generated by using the domain private key of the DKMC and the self-selected public key factor; a private key generation module, used to use the self-selected private key factor and the distribution private key factor to obtain the private key corresponding to the first terminal identifier, wherein, the distribution private key factor corresponding to the first terminal identifier jointly generated by using the domain private key of the DKMC and the self-selected public key factor includes: obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor generated by the DKMC and the self-selected public key factor; obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC; Among them, obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC includes: According to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 ) · sk 1DK , the distribution private key factor dsk corresponding to the first terminal identifier is obtained 1 , where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the accompanying public key in the accompanying public key information, ET 1 is the validity period of the accompanying public key, * indicates that the content following it is an optional factor, and sk 1DKMC is the domain private key of the DKMC.

2. The key processing system based on a unified multi-domain identifier according to claim 1, wherein, the RKMC is further configured to generate a preset private key base and a preset public key base, and distribute the preset public key base to nodes in all domains, where the preset private key base is used to cooperate in generating the domain private key, and the preset public key base is used to cooperate in generating the domain public key.

3. The key processing system based on a unified multi-domain identifier according to claim 1, wherein, the DKMC is further configured to cooperate in generating private keys for all nodes within the domain.

4. A key processing method based on a unified multi-domain identifier, wherein, the method is applied to a first terminal, and the method includes: generating a self-selected private key factor corresponding to the first terminal identifier, and sending a key application message to a domain key management center DKMC, where the key application message includes the first terminal identifier and a self-selected public key factor corresponding to the self-selected private key factor; receiving key information returned by the DKMC, where the key information includes the distribution private key factor corresponding to the first terminal identifier generated by cooperating the domain private key of the DKMC with the self-selected public key factor; using the self-selected private key factor and the distribution private key factor to obtain the private key corresponding to the first terminal identifier, wherein, the distribution private key factor corresponding to the first terminal identifier generated by cooperating the domain private key of the DKMC with the self-selected public key factor includes: obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor generated by the DKMC and the self-selected public key factor; obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC; wherein, obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC includes: According to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DKMC , the distribution private key factor dsk corresponding to the first terminal identifier is obtained 1 , where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the adjoint public key in the adjoint public key information, ET 1 is the validity period of the adjoint public key, * indicates that the content following it is an optional factor, and sk 1DKMC is the domain private key of the DKMC.

5. The key processing method based on a unified multi-domain identifier according to claim 4, wherein, using the self-selected private key factor and the distribution private key factor to obtain the private key corresponding to the first terminal identifier includes: According to sk 1 =(dsk 1 +usk 1 ) mod n, the private key sk 1 corresponding to the first terminal identifier is obtained, where usk 1 is the self-selected private key factor, dsk 1 is the distributed private key factor, and mod n is the modulo n operation.

6. The key processing method based on a unified multi-domain identifier according to claim 4, wherein, the key information further includes the accompanying public key information corresponding to the first terminal identifier, and the method further includes: obtaining the public key of the first terminal according to the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC.

7. The key processing method based on a unified multi-domain identifier according to claim 6, wherein, when the accompanying public key information includes an accompanying public key, obtaining the public key of the first terminal according to the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC includes: According to pk 1 = apk 1 + h(ID 1 || apk 1 )·pk 1DKMC , the public key pk of the first terminal is obtained 1 , where apk 1 is the accompanying public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 1DKMC is the domain public key of the DKMC.

8. The key processing method based on unified multi-domain identification according to claim 6, characterized in that, when the accompanying public key information includes an accompanying public key and the validity period of the accompanying public key, obtaining the public key of the first terminal according to the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC includes: According to pk 1 = apk 1 + h(ID 1 || apk 1 || ET 1 )·pk 1DKMC , the public key pk of the first terminal is obtained 1 , where apk 1 is the adjoint public key, ID 1 is the first terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 1 is the validity period of the adjoint public key, and pk 1DKMC is the domain public key of the DKMC.

9. The key processing method based on unified multi-domain identification according to claim 6, characterized in that, the method further includes: using the private key corresponding to the first terminal identifier to generate the public key corresponding to the first terminal identifier as the first public key; using the first terminal identifier, the accompanying public key information, and the domain public key of the DKMC to generate the public key of the first terminal as the second public key; judging whether the first public key is equal to the second public key; when it is judged that the first public key is equal to the second public key, determining that the public-private key pair corresponding to the first terminal identifier is correct; when it is judged that the first public key is not equal to the second public key, determining that the distribution of the private key factor and the accompanying public key information is incorrect.

10. The key processing method based on unified multi-domain identification according to claim 4, characterized in that, the method further includes an authentication process of the signature data sent by the first terminal to the second terminal: receiving the signature data sent by the second terminal, where the signature data includes the first terminal identifier, the data to be verified, the signature value, the second terminal identifier, and the accompanying public key information of the second terminal; determining the domain public key of the domain where the second terminal is located according to the domain identifier in the second terminal identifier; obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located; using the public key of the second terminal and the data to be verified to verify the signature value to obtain the authentication result of the signature data.

11. The key processing method based on unified multi-domain identification according to claim 10, characterized in that, the determining the domain public key of the domain where the second terminal is located according to the second terminal identifier includes: judging whether the domain identifier in the first terminal identifier is the same as the domain identifier in the second terminal identifier; when it is determined that the domain identifiers are the same, determining that the domain where the second terminal is located is the same as the domain where the first terminal is located, and determining the domain public key of the domain where the first terminal is located as the domain public key of the domain where the second terminal is located; when it is determined that the domain identifiers are not the same, determining that the domain where the second terminal is located is different from the domain where the first terminal is located, and obtaining the domain public key of the domain where the second terminal is located according to the preset public key base and the domain identifier in the second terminal identifier.

12. The key processing method based on unified multi-domain identification according to claim 11, characterized in that, the obtaining the domain public key of the domain where the second terminal is located according to the preset public key base and the domain identifier in the second terminal identifier includes: selecting a set number of factors of the hash value of the domain identifier in the second terminal identifier, and dividing the set number of factors into preset segments; Using the set low-order bits in each preset segment, search for the selection factor in the preset public key base, and use the remaining bits in each preset segment as the selection factor coefficient corresponding to the selection factor; According to obtain the domain public key pk of the domain where the second terminal is located 2DKMC , where ID 2DKMC is the domain identifier in the second terminal identifier, h() is a hash function is a query function, bpk j is the j-th selection factor, λ j is the j-th selection factor coefficient, and k is the number of selection factors 13. The key processing method based on unified multi-domain identifiers according to claim 11, wherein, when the accompanying public key information includes an accompanying public key, obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located includes: According to pk 2 = apk 2 + h(ID 2 || apk 2 )·pk 2DKM , the public key pk of the second terminal is obtained 2 , where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, and pk 2DKMC is the domain public key of the domain where the second terminal is located.

14. The key processing method based on unified multi-domain identifiers according to claim 11, wherein, when the accompanying public key information includes an accompanying public key and the validity period of the accompanying public key, obtaining the public key of the second terminal according to the second terminal identifier, the accompanying public key information, and the domain public key of the domain where the second terminal is located includes: According to pk 2 = apk 2 + h(ID 2 || apk 2 || ET 2 )·pk 2DKmC , the public key pk of the second terminal is obtained 2 , where apk 2 is the accompanying public key, ID 2 is the second terminal identifier, h() is a hash function, "||" is a concatenation operator, ET 2 is the validity period of the accompanying public key, and pk 2DKMC is the domain public key of the domain where the second terminal is located.

15. A key processing method based on unified multi-domain identifiers, wherein, the method is applied to a domain key management center DKMC, and the method includes: when receiving a key application message sent by a first terminal, generating a hidden private key factor, where the key application message includes a first terminal identifier and a self-selected public key factor; obtaining a distributed private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC; sending key information including the distributed private key factor to the first terminal, so that the first terminal uses the self-selected private key factor and the distributed private key factor to obtain the private key corresponding to the first terminal identifier, wherein, obtaining the distributed private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self-selected public key factor, and the domain private key of the DKMC includes: obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor; obtaining the distributed private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC; wherein, obtaining the distributed private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the accompanying public key information, and the domain private key of the DKMC includes: According to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 ) · sk 1DKMC , the distribution private key factor dsk corresponding to the first terminal identifier is obtained 1 , where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the accompanying public key in the accompanying public key information, ET 1 is the validity period of the accompanying public key, * indicates that the content following it is an optional factor, and sk 1DK is the domain private key of the DKMC.

16. The key processing method based on unified multi-domain identifiers according to claim 15, wherein, obtaining the accompanying public key information corresponding to the first terminal identifier according to the hidden private key factor and the self-selected public key factor includes: According to hpk 1 = hsk 1 G, to obtain the hidden private key factor hsk 1 The corresponding hidden public key factor hpk 1 ; According to the apk 1 = hpk 1 + upk 1 , the adjoint public key apk corresponding to the first terminal identifier is obtained 1 , and the validity period of the adjoint public key is generated, where upk 1 is the self-selected public key factor; using the accompanying public key corresponding to the first terminal identifier and the validity period of the accompanying public key as the accompanying public key information corresponding to the first terminal identifier.

17. The key processing method based on unified multi-domain identifiers according to claim 16, wherein, the key information further includes the accompanying public key information corresponding to the first terminal identifier.

18. A key processing device based on unified multi-domain identifiers, wherein, the device is applied to a first terminal and includes: A self - selected factor generation module, configured to generate a self - selected private key factor corresponding to the first terminal identifier; A communication module, configured to send a key application message to a domain key management center DKMC, where the key application message includes the first terminal identifier and a self - selected public key factor corresponding to the self - selected private key factor; The communication module is further configured to receive key information returned by the DKMC, where the key information includes a distribution private key factor corresponding to the first terminal identifier generated by collaborating the domain private key of the DKMC with the self - selected public key factor; A private key generation module, configured to obtain the private key corresponding to the first terminal identifier by using the self - selected private key factor and the distribution private key factor, wherein, the distribution private key factor corresponding to the first terminal identifier generated by collaborating the domain private key of the DKMC with the self - selected public key factor includes: Obtaining the adjoint public key information corresponding to the first terminal identifier according to the hidden private key factor generated by the DKMC and the self - selected public key factor; Obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC; wherein, obtaining the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC includes: According to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DKMC , the distribution private key factor dsk corresponding to the first terminal identifier is obtained 1 , where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the accompanying public key in the accompanying public key information, ET 1 is the validity period of the accompanying public key, * indicates that the content following it is an optional factor, sk 1DKMC is the domain private key of the DKMC.

19. A key processing device based on a unified multi - domain identifier, characterized in that, The device is applied to a domain key management center DKMC and includes: A communication module, configured to receive a key application message sent by a first terminal, where the key application message includes a first terminal identifier and a self - selected public key factor; A factor generation module, configured to generate a hidden private key factor; A distribution factor generation module, configured to obtain the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the self - selected public key factor, and the domain private key of the DKMC; The communication module is further configured to send key information including the distribution private key factor to the first terminal, so that the first terminal can obtain the private key corresponding to the first terminal identifier by using the self - selected private key factor and the distribution private key factor, wherein, the distribution factor generation module is further configured to: obtain the adjoint public key information corresponding to the first terminal identifier according to the hidden private key factor and the self - selected public key factor; obtain the distribution private key factor corresponding to the first terminal identifier according to the first terminal identifier, the hidden private key factor, the adjoint public key information, and the domain private key of the DKMC; Among them, the distribution factor generation module is further configured to: according to dsk 1 = hsk 1 + h(ID 1 || apk 1 || *ET 1 )·sk 1DK , obtain the distribution private key factor dsk 1 corresponding to the first terminal identifier, where hsk 1 is the hidden private key factor, h() is a hash function, "||" is a concatenation operator, ID 1 is the first terminal identifier, apk 1 is the accompanying public key in the accompanying public key information, ET 1 is the validity period of the accompanying public key, * indicates that the content after it is an optional factor, and sk 1DKM is the domain private key of the DKMC.

Citation Information

Patent Citations

  • CPK-based key generation method and device capable of realizing multi-state configuration

    CN113259097A