Communication encryption method, device, and computer equipment
The system public parameters and terminal private keys are generated through the private key generation center, combined with random numbers and multiple decryption, which solves the communication security risks of the PMU system in the power system and achieves higher security encrypted communication.
Patent Information
- Application Number
- CN202211663705.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2042-12-23
AI Technical Summary
The existing communication encryption methods in power systems, especially PMU systems, have communication security risks, and the security of existing encryption technologies still need to be improved.
The private key generation center obtains security parameters and terminal identity information, generates the system public parameters and private keys, and generates the public key and private key of the public key and private key, combines random numbers to generate ciphertext, and ensures communication security through multiple decryption processes, including the generation and verification of the terminal's user public key and private key.
Encrypted communication with higher security is established to ensure the security and accuracy of communication and prevent information tampering.
Smart Images

Figure CN115834058B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication encryption technology, and in particular to a communication encryption method, apparatus, computer equipment, storage medium, and computer program product. Background Art
[0002] With the development of smart grids, the scale of power systems continues to expand, and the number and types of devices connected to the grid have increased dramatically. For example, PMUs (Phasor Measurement Units), which measure grid data in power systems, face communication security risks due to the numerous and complex terminal connections.
[0003] At present, in order to improve communication security, certificate-based public key systems, identity-based public key systems, or certificateless public key systems are often used to encrypt communications. However, the security of encrypted communications using the above methods still needs to be improved. Summary of the Invention
[0004] Based on this, it is necessary to provide a communication encryption method, device, computer equipment, computer-readable storage medium and computer program product that can improve the security of communication between devices in response to the above technical problems.
[0005] In a first aspect, a communication encryption method is provided, which is applied to a private key generation center, and the method includes:
[0006] Acquiring security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal;
[0007] Generate system public parameters based on security parameters;
[0008] Generate and store the private key and public key of the private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal;
[0009] Generate a random number and send the target terminal's private key generation center public key, system public parameters and random number to the target terminal;
[0010] Receive the user public key in the user private key and user public key fed back by the target terminal; wherein the user private key and user public key of the target terminal are generated by the target terminal according to the target terminal private key generation center public key, system public parameters and random numbers;
[0011] Sending the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, the user public key of the second terminal, and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal;
[0012] In response to the ciphertext decryption request from the second terminal, a central private key is generated based on the private key of the second terminal to decrypt the ciphertext, and the decryption result is fed back to the second terminal, so that after receiving the decryption result, the second terminal decrypts the ciphertext again based on the user private key of the second terminal to obtain the session key.
[0013] In one embodiment, responding to the ciphertext decryption request from the second terminal includes:
[0014] In response to the query command about the first terminal sent by the second terminal, and when the user public key of the first terminal is stored, a registration success signal is fed back to the second terminal, so that the second terminal sends a ciphertext decryption request when receiving the registration success signal.
[0015] In one embodiment, sending the system public parameters, the random number, the user public key of the second terminal, and the private key generation center public key of the second terminal to the first terminal includes:
[0016] In response to a query command about the second terminal sent by the first terminal, the system public parameters, the random number, the user public key of the second terminal and the private key generation center public key of the second terminal are fed back to the first terminal.
[0017] In a second aspect, a communication encryption method is provided, applied to a first terminal, the method comprising:
[0018] Sending a query instruction about the second terminal to the private key generation center, and receiving the system public parameters, random number, user public key of the second terminal, and private key generation center public key of the second terminal fed back by the private key generation center in response to the query instruction about the second terminal;
[0019] Generate a central public key encryption session key based on the system public parameter, the random number, the user public key of the second terminal and the private key of the second terminal to generate a ciphertext;
[0020] Sending the ciphertext to the second terminal, causing the second terminal to send a query command about the first terminal to the private key generation center, and receiving the decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain the session key;
[0021] The decryption result is obtained by the private key generation center in response to the ciphertext decryption request by decrypting the ciphertext according to the private key of the private key generation center of the second terminal.
[0022] In one embodiment, the method further comprises:
[0023] The identity information of the first terminal is sent to the second terminal, so that the second terminal generates and sends a query command about the first terminal to the private key generation center according to the identity information of the first terminal.
[0024] In one embodiment, the system public parameters include a hash function model, and the method further includes:
[0025] Inputting the random number and the session key into the hash function model, generating and sending the original hash value to the second terminal;
[0026] Generate a central public key encryption session key based on the system public parameters, the user public key of the second terminal, and the private key of the second terminal, and generate a ciphertext, including:
[0027] The session key and the original hash value are encrypted based on the system public parameters, the user public key of the second terminal, and the public key of the private key generation center of the second terminal, and a ciphertext is generated and sent to the second terminal, so that the second terminal sends a query command about the first terminal to the private key generation center, and receives the decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value. When the decrypted original hash value is consistent with the original hash value, the verification is passed.
[0028] In a third aspect, a communication encryption method is provided, applied to a second terminal, the method comprising:
[0029] Sending a query command about the first terminal to the private key generation center, and causing the private key generation center to feed back a registration success signal to the second terminal when the private key generation center stores the user public key of the first terminal;
[0030] Upon receiving the registration approval signal, the private key generation center sends a ciphertext decryption request to the private key generation center, so that the private key generation center responds to the ciphertext decryption request from the second terminal, decrypts the ciphertext according to the private key of the private key generation center of the second terminal, and feeds back the decryption result to the second terminal;
[0031] The decryption result fed back by the private key generation center is received, and after receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value.
[0032] In one embodiment, the method further comprises:
[0033] receiving an original hash value sent by the first terminal;
[0034] When the decrypted original hash value and the original hash value are consistent, the verification is successful.
[0035] In a fourth aspect, a communication encryption device is provided, the device comprising:
[0036] A data acquisition module, configured to acquire security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal;
[0037] A parameter generation module is used to generate system common parameters based on security parameters;
[0038] The key generation module generates and stores the private key and public key of the private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal;
[0039] A first data sending module is used to generate a random number and send the target terminal's private key generation center public key, system public parameters and the random number to the target terminal;
[0040] A receiving module, configured to receive a user public key in a user private key and a user public key fed back by a target terminal; wherein the user private key and the user public key of the target terminal are generated by the target terminal according to a public key of a private key generation center of the target terminal, system public parameters, and a random number;
[0041] The second data sending module sends the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, the user public key of the second terminal, and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal;
[0042] The decryption module is used to respond to the ciphertext decryption request of the second terminal, generate a central private key based on the private key of the second terminal to decrypt the ciphertext, and feed back the decryption result to the second terminal, so that the second terminal can perform a second decryption on the ciphertext based on the user private key of the second terminal after receiving the decryption result to obtain the session key.
[0043] In a fifth aspect, a computer device is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method in the above embodiment when executing the computer program.
[0044] The above embodiment includes at least the following beneficial effects during implementation: obtaining security parameters and identity information of the first terminal and the second terminal through the private key generation center, and then generating system public parameters according to the security parameters; and generating and storing the private key generation center private key and the private key generation center public key of the target terminal according to the system public parameters and the identity information of the target terminal; generating a random number, and sending the private key generation center public key of the target terminal, the system public parameters and the random number to the target terminal; receiving the user private key and the user public key in the user public key fed back by the target terminal; wherein the user private key and the user public key of the target terminal are generated by the target terminal according to the private key of the target terminal The system generates a central public key, system public parameters, and a random number; the system public parameters, random number, the user public key of the second terminal, and the second terminal's private key generate a central public key and send it to the first terminal. The first terminal generates a central public key-encrypted session key based on the system public parameters, the user public key of the second terminal, and the second terminal's private key, generates ciphertext, and sends the ciphertext to the second terminal. In response to a ciphertext decryption request from the second terminal, the central private key is generated based on the second terminal's private key to decrypt the ciphertext, and the decryption result is fed back to the second terminal. After receiving the decryption result, the second terminal performs a second decryption on the ciphertext based on the second terminal's user private key to obtain the session key. Based on the above method, encrypted communication formed by the session key is established, ensuring the security of the communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 A diagram illustrating an application environment of a communication encryption method in one embodiment;
[0046] Figure 2 A schematic flow chart of a communication encryption method according to an embodiment;
[0047] Figure 3 A schematic flow chart of a communication encryption method according to another embodiment;
[0048] Figure 4 Schematic diagram of a flow chart of a communication encryption method in another embodiment;
[0049] Figure 5 A schematic flow chart of a communication encryption method according to another embodiment;
[0050] Figure 6 Schematic diagram of a flow chart of a communication encryption method in another embodiment;
[0051] Figure 7 1 is a flow chart of a communication encryption method in yet another embodiment;
[0052] Figure 8 is a diagram of the internal structure of a computer device in one embodiment;
[0053] Figure 9FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0055] The communication encryption method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the first terminal 102, the second terminal 104 and the private key generation center 106 communicate with each other.
[0056] The private key generation center 106 obtains security parameters and the identity information of the first terminal 102 and the second terminal 104; generates system public parameters based on the security parameters; generates and stores a private key and a public key of the private key generation center corresponding to each terminal based on the system public parameters and the identity information of the first terminal 102 and the second terminal 104; simultaneously generates a random number and sends the private key generation center public key, system public parameters, and random number corresponding to each terminal to each terminal; the private key generation center receives user public keys fed back by each terminal; and sends the system public parameters, random number, user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal encrypts the session key based on the system public parameters, user public key of the second terminal, and the public key of the private key generation center of the second terminal to generate a ciphertext, and sends the ciphertext to the second terminal; in response to a ciphertext decryption request from the second terminal, the private key generation center decrypts the ciphertext based on the private key of the second terminal, and feeds back the decryption result to the second terminal, so that the second terminal, after receiving the decryption result, performs a second decryption on the ciphertext based on the user private key of the second terminal to obtain the session key. Among them, the first terminal 102 and the second terminal 104 can be but are not limited to various personal computers, laptops, smart phones, tablets, Internet of Things devices and portable wearable devices. The Internet of Things devices can be various devices such as synchronous vector measurement devices, vector data concentrators, time synchronization devices, etc.
[0057] In one embodiment, Figure 2 As shown, a communication encryption method is provided, which is applied to Figure 1 The private key generation center in the example is used as an example to illustrate, including the following steps:
[0058] S202, obtaining security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal.
[0059] The security parameter is a number randomly selected from a set of positive integers, such as Z +, the security parameter is k, then k∈Z + The target terminal may refer to both terminals of the information transmission, such as the information receiving terminal and the information sending terminal; for example, if the first terminal is the information sending terminal, the second terminal is the information receiving terminal. The identity information may refer to the identifier or identification code of the target terminal, etc., which is not limited here.
[0060] S204: Generate system public parameters according to the security parameters.
[0061] The specific meanings of the system common parameters are well known to those skilled in the art and will not be elaborated here.
[0062] Specifically, input the security parameter to the parameter generator, and then generate the q-order additive cyclic group G and the q-order multiplicative cyclic group G T (where q is a prime number). Further, generate a bilinear map e: G×G→G T , select the generator P from G. Then randomly select s∈Z q * As the master private key of the private key generation center, the master public key P of the private key generation center can be calculated at this time pub =sP. Select the hash function:
[0063]
[0064]
[0065]
[0066] H4: {0, 1} n →{0, 1} n .
[0067] Choose the plaintext space as M = {0,1} n , ciphertext space C = G * ×{0,1} n Output system common parameters params= <G,G T ,q,e,n,P,P pub , H1, H2, H3, H4>, the meanings of the relevant symbols are shown in the table below.
[0068] Table 1
[0069]
[0070] S206 , generating and storing a private key and a public key of a private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal.
[0071] Specifically, the target terminal is the first terminal as an example for explanation, assuming that the identity information of the first terminal is ID A After receiving the identity information of the first terminal, the private key generation center obtains the public key Q of the first terminal through calculation. IDA =H1(ID A )∈G * Then, the private key of the first terminal can be obtained by the same calculation to generate the central private key d IDA =s×Q IDA Similarly, the above method can also be used for the second terminal to obtain the private key and public key of the private key generation center of the second terminal. After obtaining the private key and public key of the private key generation center of the target terminal, they are stored in the private key generation center for subsequent decryption and use.
[0072] S208, generating a random number, and sending the target terminal's private key generation center public key, system public parameters and the random number to the target terminal.
[0073] Among them, the random number is from Z q * A value randomly selected from the set is called a secret value and is represented by x ID Indicates that the value can represent the identity information of the target terminal.
[0074] Specifically, if the target terminal is the first terminal, after the random number is generated, the public key of the private key generation center of the first terminal, the system public parameters and the random number are sent to the target terminal.
[0075] S210, receiving the user public key in the user private key and the user public key fed back by the target terminal; wherein, the user private key and the user public key of the target terminal are generated by the target terminal according to the target terminal private key generation center public key, system public parameters and random numbers.
[0076] Specifically, after receiving the input private key generation center public key, system public parameters and random number, the target terminal obtains the private key of the target terminal through calculation. Take the first terminal as an example. The secret value of the first terminal is xIDA. At this time, the user private key of the first terminal is DIDA=xIDA×QIDA, and the user public key of the first terminal can be further obtained. Set the user public key of the first terminal PIDA=<XIDA,YIDA> , where: XIDA = xIDAP, YIDA = xIDAPpub. Similarly, when the target terminal is a second terminal, the above method can also be used to obtain the corresponding user private key and user public key. After generating the user private key and user public key, the target terminal uploads the user public key to the private key generation center, and the private key generation center receives the user public key from the target terminal. The meanings of the symbols are shown in Table 2 below:
[0077] Table 2
[0078] symbol significance <![CDATA[Q ID ]]> The user public key of the target terminal <![CDATA[d IDA ]]> The user private key of the target terminal <![CDATA[x ID ]]> Random number of the target terminal <![CDATA[D IDA ]]> Private key of the first terminal <![CDATA[P ID ]]> Public key of the target terminal <![CDATA[X ID ]]> The value that constitutes the public key of the target terminal <![CDATA[Y ID ]]> The value that constitutes the public key of the target terminal
[0079] S212, the system public parameters, random number, user public key of the second terminal and the private key generation center public key of the second terminal are sent to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, user public key of the second terminal and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal.
[0080] Specifically, at this time, the second terminal acts as the information receiver and the first terminal acts as the information sender. The first terminal receives the system public parameters, random number, user public key of the second terminal and public key of the private key generation center sent by the private key generation center, and randomly selects σ∈{0,1} n , calculate the hash value r = H3 (σ, M), further encrypt the session key M, and calculate the ciphertext C =<U,V,W> ,in:
[0081] U=rP;
[0082]
[0083]
[0084] S214, in response to the ciphertext decryption request from the second terminal, a central private key is generated based on the private key of the second terminal to decrypt the ciphertext, and the decryption result is fed back to the second terminal, so that after receiving the decryption result, the second terminal decrypts the ciphertext again based on the user private key of the second terminal to obtain the session key.
[0085] Specifically, after the second terminal receives the session ciphertext sent by the first terminal, it begins to decrypt the session ciphertext. At this time, the second terminal needs to send a ciphertext decryption request to the private key generation center. After receiving the decryption request, the private key generation center uses the private key of the second terminal to perform preliminary decryption, obtains a preliminary decryption result, and feeds the decryption result back to the second terminal. In a specific embodiment, if the second terminal receives the ciphertext C=<U,V,W> After that, the second terminal sends a decryption request to the private key generation center, and the private key generation center uses the private key generation center private key d of the second terminal stored therein. IDB Perform preliminary decryption and obtain a decryption result g PKG =e(d IDB , U). After receiving the first decryption result, the second terminal performs a second decryption on the received ciphertext based on the second terminal user private key to obtain a second decryption result. In a specific embodiment, after receiving the first decryption result, the second terminal uses the second terminal user private key stored internally to decrypt and obtain a second decryption result gID =e(D IDB , U). Combining the first decryption result and the second decryption result to obtain the session key M, where:
[0086]
[0087]
[0088] r′=H3(σ′,M′).
[0089] At this point, the first terminal and the second terminal have established encrypted communication formed by the session key M. Subsequent communications can be symmetrically encrypted and decrypted using the session key M. The symbols and their meanings in the above embodiment are shown in Table 3 below:
[0090] Table 3
[0091] symbol significance σ Random Numbers r Values involved in the calculation C Encryption result value structure U Elements of group G V Ciphertext structure value W Ciphertext structure value <![CDATA[g PKG ]]> Decryption result once <![CDATA[g ID ]]> Decryption secondary results M Session Key
[0092] In the above embodiment, the communication session key is encrypted by using the public and private keys of the target terminal generated by the private key generation center and the public and private keys of the user of the target terminal, thereby forming encrypted communication based on the session key and improving the security of the communication.
[0093] In one embodiment, responding to the ciphertext decryption request from the second terminal includes:
[0094] S302, responding to the query command about the first terminal sent by the second terminal, and feeding back a registration success signal to the second terminal when the user public key of the first terminal is stored, so that the second terminal sends a ciphertext decryption request when receiving the registration success signal.
[0095] Specifically, using the example of a second terminal as the information receiver, when the second terminal receives ciphertext sent by the first terminal, it first needs to verify the identity information of the first terminal. Only if the verification is successful will the ciphertext decryption operation be performed. For example, the second terminal sends a command to query the first terminal's identity information to the private key generation center. If the private key generation center stores the first terminal's user public key, it is determined that the first terminal has successfully registered with the private key generation center. At this time, the private key generation center sends a registration approval signal to the second terminal, and the second terminal begins to send ciphertext decryption requests.
[0096] In the above embodiment, the identity information of the information sender is verified before the ciphertext is decrypted, thereby further ensuring the information security of both parties in the communication.
[0097] In one embodiment, sending the system public parameters, the random number, the user public key of the second terminal, and the private key generation center public key of the second terminal to the first terminal includes:
[0098] S402 : In response to a query command about a second terminal sent by the first terminal, feeding back system public parameters, a random number, a user public key of the second terminal, and a public key of a private key generation center of the second terminal to the first terminal.
[0099] Specifically, before the system public parameters, random number, user public key of the second terminal and the public key of the private key generation center of the second terminal are sent to the first terminal, the first terminal first sends a query command about the second terminal to the private key generation center. The private key generation center responds to the query command about the second terminal sent by the first terminal, and then sends the above data to the first terminal so as to accurately establish encrypted communication.
[0100] In one embodiment, a communication encryption method is provided, applied to a first terminal, the method comprising:
[0101] S502, sending a query instruction about the second terminal to the private key generation center, and receiving the system public parameters, random number, user public key of the second terminal, and private key generation center public key of the second terminal fed back by the private key generation center in response to the query instruction about the second terminal;
[0102] S504, generating a central public key encryption session key based on the system public parameter, the random number, the user public key of the second terminal and the private key of the second terminal to generate a ciphertext;
[0103] S506: Send the ciphertext to the second terminal, causing the second terminal to send a query command about the first terminal to the private key generation center, and receive a decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain a session key.
[0104] The decryption result is obtained by the private key generation center in response to the ciphertext decryption request by decrypting the ciphertext according to the private key of the private key generation center of the second terminal.
[0105] Specifically, the method of this embodiment corresponds to the method in the above embodiment, and its implementation process can refer to the above description, which will not be repeated here.
[0106] In one embodiment, the method further comprises:
[0107] Step 1: Send the identity information of the first terminal to the second terminal, so that the second terminal generates and sends a query command about the first terminal to the private key generation center based on the identity information of the first terminal.
[0108] Specifically, when the first terminal sends the ciphertext to the second terminal, it also sends the identity information of the first terminal to the second terminal. The second terminal sends a query command to the private key generation center based on the identity information of the first terminal obtained to inquire whether the first terminal is a legitimate communication party registered with the private key generation center, thereby improving the security of communication.
[0109] In one embodiment, the system common parameters include a hash function model, and the method further includes:
[0110] S602, inputting the random number and the session key into the hash function model, generating and sending the original hash value to the second terminal;
[0111] Among them, the hash function model is a model well known to those skilled in the art. The specific selection can be made according to actual needs and will not be described in detail here.
[0112] Specifically, by randomly selecting σ∈{0,1} n , calculate and obtain the original hash value r=H3(σ,M), and send the original hash value to the second terminal.
[0113] Generate a central public key encryption session key based on the system public parameters, the user public key of the second terminal, and the private key of the second terminal, and generate a ciphertext, including:
[0114] S604: Encrypt the session key and the original hash value based on the system public parameters, the user public key of the second terminal, and the public key of the private key generation center of the second terminal, generate and send a ciphertext to the second terminal, so that the second terminal sends a query command about the first terminal to the private key generation center, and receives the decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain the decrypted session key and the decrypted original hash value. When the decrypted original hash value is consistent with the original hash value, the verification is successful.
[0115] Specifically, after performing secondary decryption on the ciphertext, the second terminal obtains the original hash value based on the decryption, compares this value with the original hash value, and when the two are consistent, determines that the verification is successful, that is, determines that the session key has not been tampered with during the communication process, thereby ensuring the accuracy and security of the communication.
[0116] In one embodiment, a communication encryption method is provided, applied to a second terminal, the method comprising:
[0117] S702, sending a query command about the first terminal to the private key generation center, and causing the private key generation center to feedback a registration success signal to the second terminal when the private key generation center stores the user public key of the first terminal;
[0118] S704: Upon receiving the registration approval signal, a ciphertext decryption request is sent to the private key generation center. The private key generation center responds to the ciphertext decryption request from the second terminal, decrypts the ciphertext using the private key of the private key generation center of the second terminal, and feeds back the decryption result to the second terminal.
[0119] S706, receiving the decryption result fed back by the private key generation center, and after receiving the decryption result, performing secondary decryption on the ciphertext based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value.
[0120] Specifically, the method corresponding to this embodiment is similar to that of the above-mentioned communication encryption method embodiment, and its implementation method is also similar, so it will not be repeated here.
[0121] In one embodiment, the method further comprises:
[0122] Step 1: receiving the original hash value sent by the first terminal;
[0123] Step 2: When the original hash value based on decryption is consistent with the original hash value, the verification is successful.
[0124] The method in this embodiment corresponds to the hash value verification process in the above embodiment, and will not be described again here.
[0125] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0126] Based on the same inventive concept, embodiments of the present application also provide a communication encryption device for implementing the communication encryption method involved above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more communication encryption device embodiments provided below can be referred to the limitations of the communication encryption method above and will not be repeated here.
[0127] In one embodiment, a communication encryption device is provided, which is applied to a private key generation center and includes:
[0128] A data acquisition module, configured to acquire security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal;
[0129] A parameter generation module is used to generate system common parameters based on security parameters;
[0130] The key generation module generates and stores the private key and public key of the private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal;
[0131] A first data sending module is used to generate a random number and send the target terminal's private key generation center public key, system public parameters and the random number to the target terminal;
[0132] A receiving module, configured to receive a user public key in a user private key and a user public key fed back by a target terminal; wherein the user private key and the user public key of the target terminal are generated by the target terminal according to a public key of a private key generation center of the target terminal, system public parameters, and a random number;
[0133] The second data sending module sends the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, the user public key of the second terminal, and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal;
[0134] The decryption module is used to respond to the ciphertext decryption request of the second terminal, generate a central private key based on the private key of the second terminal to decrypt the ciphertext, and feed back the decryption result to the second terminal, so that the second terminal can perform a second decryption on the ciphertext based on the user private key of the second terminal after receiving the decryption result to obtain the session key.
[0135] In one embodiment, the decryption module includes:
[0136] The first response unit is used to respond to the query command about the first terminal sent by the second terminal, and feed back a registration success signal to the second terminal when the user public key of the first terminal is stored, so that the second terminal sends a ciphertext decryption request when receiving the registration success signal.
[0137] In one embodiment, the second data sending module includes:
[0138] The second response unit is used to respond to the query command about the second terminal sent by the first terminal, and feedback the system public parameters, random number, user public key of the second terminal and private key generation center public key of the second terminal to the first terminal.
[0139] In one embodiment, a communication encryption device is provided, applied to a first terminal, including:
[0140] an instruction sending module, configured to send a query instruction regarding the second terminal to the private key generation center, and receive the system public parameters, random number, user public key of the second terminal, and private key generation center public key of the second terminal fed back by the private key generation center in response to the query instruction regarding the second terminal;
[0141] A ciphertext generation module, configured to generate a central public key encryption session key based on system public parameters, a random number, a user public key of the second terminal, and a private key of the second terminal, and generate a ciphertext;
[0142] a ciphertext sending module, configured to send the ciphertext to the second terminal, causing the second terminal to send a query command about the first terminal to the private key generation center, receive a decryption result fed back by the private key generation center, and, after receiving the decryption result, perform a secondary decryption on the ciphertext based on the user private key of the second terminal to obtain a session key;
[0143] The decryption result is obtained by the private key generation center in response to the ciphertext decryption request by decrypting the ciphertext according to the private key of the private key generation center of the second terminal.
[0144] In one embodiment, the communication encryption device further includes:
[0145] The identity information sending module is used to send the identity information of the first terminal to the second terminal, so that the second terminal generates and sends a query command about the first terminal to the private key generation center based on the identity information of the first terminal.
[0146] In one embodiment, the communication encryption device further includes:
[0147] A hash value output module, configured to input a random number and a session key into a hash function model, generate and send an original hash value to the second terminal;
[0148] The above ciphertext generation module also includes:
[0149] The ciphertext sending unit is used to encrypt the session key and the original hash value based on the system public parameters, the user public key of the second terminal and the private key generation center of the second terminal, generate and send the ciphertext to the second terminal, so that the second terminal sends a query command about the first terminal to the private key generation center, and receives the decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain the decrypted session key and the decrypted original hash value. When the decrypted original hash value is consistent with the original hash value, the verification is passed.
[0150] In one embodiment, a communication encryption device is provided, applied to a second terminal, including:
[0151] A query command sending module, configured to send a query command about the first terminal to the private key generation center, and enable the private key generation center to feed back a registration success signal to the second terminal when the private key generation center stores the user public key of the first terminal;
[0152] a decryption request sending module, configured to send a ciphertext decryption request to a private key generation center upon receiving a registration approval signal, so that the private key generation center responds to the ciphertext decryption request from the second terminal, decrypts the ciphertext according to the private key of the private key generation center of the second terminal, and feeds back the decryption result to the second terminal;
[0153] The decryption result receiving module is used to receive the decryption result fed back by the private key generation center, and after receiving the decryption result, perform secondary decryption on the ciphertext based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value.
[0154] In one embodiment, the communication encryption device further includes:
[0155] A hash value receiving module, configured to receive an original hash value sent by the first terminal;
[0156] The verification module is used to verify that the original hash value based on the decryption is consistent with the original hash value.
[0157] Each module in the above-mentioned communication encryption device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of the processor of the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0158] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 8 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store communication encryption data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements the communication encryption method applied in the private key generation center in the above embodiment.
[0159] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 9 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface is connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, it implements the communication encryption method applied to the first terminal and / or the second terminal in the above-mentioned embodiment.
[0160] It should be understood that Figure 8 Server class computer equipment shown and Figure 9 The terminal-type computer device shown can communicate to achieve communication encryption between the first terminal, the second terminal and the private key generation center.
[0161] Those skilled in the art will understand that Figure 8-9 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0162] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0163] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0164] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0165] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (RRAM), magnetic random access memory (MRM), ferroelectric random access memory (FRM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (R-first terminal, ndom access memory, R-first terminal, M) or external cache memory, etc. By way of illustration and not limitation, R-first terminal, M may take various forms, such as static random access memory (S-first terminal, ndom access memory, SR-first terminal, M) or dynamic random access memory (D-first terminal, ndom access memory, DR-first terminal, M). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchain. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, etc.
[0166] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0167] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A communication encryption method, characterized in that: Applied to a private key generation center, the method includes: Acquiring security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal; Generate system public parameters according to the security parameters; Generate and store a private key and a public key of a private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal; Generate a random number, and send the target terminal's private key generation center public key, the system public parameters, and the random number to the target terminal; Receive the user public key of the user private key and the user public key fed back by the target terminal; wherein the user private key and the user public key of the target terminal are generated by the target terminal according to the public key of the private key generation center of the target terminal, the system public parameters and the random number; Sending the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, the random number, the user public key of the second terminal, and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal; In response to the ciphertext decryption request from the second terminal, a central private key is generated based on the private key of the second terminal to decrypt the ciphertext, and the decryption result is fed back to the second terminal, so that after receiving the decryption result, the second terminal decrypts the ciphertext again based on the user private key of the second terminal to obtain the session key.
2. The method according to claim 1, characterized in that The responding to the ciphertext decryption request from the second terminal includes: In response to a query command about the first terminal sent by the second terminal, and when the user public key of the first terminal is stored, a registration success signal is fed back to the second terminal, so that the second terminal sends the ciphertext decryption request when receiving the registration success signal.
3. The method according to claim 1, characterized in that The sending the system public parameter, the random number, the user public key of the second terminal, and the private key generation center public key of the second terminal to the first terminal includes: In response to a query command about the second terminal sent by the first terminal, the system public parameters, the random number, the user public key of the second terminal, and the private key generation center public key of the second terminal are fed back to the first terminal.
4. A communication encryption method, characterized in that: Applied to a first terminal, the method includes: Sending a query instruction about the second terminal to the private key generation center, and receiving the system public parameters, random number, user public key of the second terminal, and private key generation center public key of the second terminal fed back by the private key generation center in response to the query instruction about the second terminal; Generate a central public key encryption session key based on the system public parameter, the random number, the user public key of the second terminal and the private key of the second terminal to generate a ciphertext; sending the ciphertext to the second terminal, causing the second terminal to send a query command about the first terminal to a private key generation center, receiving a decryption result fed back by the private key generation center, and, after receiving the decryption result, performing a secondary decryption on the ciphertext based on the user private key of the second terminal to obtain the session key; The decryption result is obtained by the private key generation center decrypting the ciphertext according to the private key of the private key generation center of the second terminal in response to the ciphertext decryption request.
5. The method according to claim 4, characterized in that The method further comprises: The identity information of the first terminal is sent to the second terminal, so that the second terminal generates and sends a query command about the first terminal to the private key generation center according to the identity information of the first terminal.
6. The method according to claim 4, characterized in that The system public parameters include a hash function model, and the method further includes: Inputting the random number and the session key into the hash function model, generating and sending an original hash value to the second terminal; The generating of a central public key encryption session key based on the system public parameter, the random number, the user public key of the second terminal, and the private key of the second terminal to generate a ciphertext includes: The session key and the original hash value are encrypted based on the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal, and the ciphertext is generated and sent to the second terminal, so that the second terminal sends a query command about the first terminal to the private key generation center, and receives a decryption result fed back by the private key generation center. After receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value. When the decrypted original hash value is consistent with the original hash value, the verification is passed.
7. A communication encryption method, characterized in that: Applied to the second terminal, the method includes: Sending a query command about the first terminal to a private key generation center, and causing the private key generation center to feed back a registration success signal to the second terminal when the private key generation center stores the user public key of the first terminal; upon receiving the registration approval signal, sending a ciphertext decryption request to the private key generation center, causing the private key generation center to respond to the ciphertext decryption request from the second terminal, decrypt the ciphertext according to the private key of the private key generation center of the second terminal, and feed back the decryption result to the second terminal; The decryption result fed back by the private key generation center is received, and after receiving the decryption result, the ciphertext is decrypted again based on the user private key of the second terminal to obtain a decrypted session key and a decrypted original hash value.
8. The method according to claim 7, characterized in that The method further comprises: receiving an original hash value sent by the first terminal; When the decrypted original hash value is consistent with the original hash value, the verification is successful.
9. A communication encryption device, characterized in that: Applied to a private key generation center, the device includes: A data acquisition module, configured to acquire security parameters and identity information of a target terminal; the target terminal includes a first terminal and a second terminal; A parameter generation module, configured to generate system common parameters based on the security parameters; A key generation module, which generates and stores a private key and a public key of a private key generation center of the target terminal according to the system public parameters and the identity information of the target terminal; A first data sending module, configured to generate a random number, and send the target terminal's private key generation center public key, the system public parameters, and the random number to the target terminal; a receiving module, configured to receive a user public key among a user private key and a user public key fed back by the target terminal; wherein the user private key and the user public key of the target terminal are generated by the target terminal according to a public key of a private key generation center of the target terminal, the system public parameters, and the random number; a second data sending module, configured to send the system public parameters, the random number, the user public key of the second terminal, and the public key of the private key generation center of the second terminal to the first terminal, so that the first terminal generates a central public key encryption session key based on the system public parameters, the random number, the user public key of the second terminal, and the private key of the second terminal, generates a ciphertext, and sends the ciphertext to the second terminal; a decryption module configured to, in response to a ciphertext decryption request from the second terminal, generate a central private key based on the private key of the second terminal to decrypt the ciphertext, and feed back the decryption result to the second terminal, so that the second terminal, after receiving the decryption result, performs a secondary decryption on the ciphertext based on the user private key of the second terminal to obtain the session key.
10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Data encryption method and system based on ECDSA
CN112165386A
Identity-based authentication key negotiation method based on lattice
CN114268439A