Method for identity authentication based on quantum key
By using the quantum key distribution network to obtain shared keys in identity authentication, the complexity and security issues of key sharing are solved, and a more efficient and secure identity authentication process is achieved.
Patent Information
- Application Number
- CN202110891668.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-04
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2041-08-04
AI Technical Summary
In the existing identity authentication technology based on symmetric passwords, the increase in the number of user nodes leads to the increase in the complexity and cost of key sharing, and the key update is frequently to ensure security.
The identity authentication method based on quantum key is adopted to obtain the shared key through the quantum key distribution network, which is used for the calculation of message verification code and data transmission, reducing the complexity of key presetting and enhancing security.
It reduces the complexity of key presetting, shortens the key update cycle, improves the security of keys, supports online acquisition, and enhances the security of the identity authentication process.
Smart Images

Figure CN115913521B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum communication, and in particular relates to a method for identity authentication based on quantum keys. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] Identity authentication is the process of verifying whether the user's true identity is consistent with the identity he claims. Symmetric key-based authentication requires the proving party and the verifier to share a key, and maintain a trust relationship between them through the shared key. During each authentication, the verifier sends a different piece of data to the proving party, usually a different random number; after receiving the data message, the verifier gives a corresponding response according to the agreed rules; the verifier verifies the identity of the proving party by comparing the response message to see if it is correct according to the agreed rules. If the two communicating parties perform identity authentication with each other as proving parties, a two-way identity authentication is completed, that is, both parties authenticate the identity of the other party.
[0004] However, most of the existing identity authentication technology solutions based on symmetric encryption require key sharing between both users. Therefore, if users in the network need to perform identity authentication, they need to have a shared key between each other. Assuming that the number of user nodes in the network is N, the number of keys that need to be shared is N*(N-1) / 2. As the number of user nodes increases, the number of keys that need to be preset will increase dramatically, and the difficulty and cost of presetting keys will also continue to increase. At the same time, in order to ensure that the shared key is not stolen by others, it is necessary to frequently update the key to reduce the security issues caused by attackers stealing the key. Summary of the invention
[0005] In order to solve the above problems, the present invention proposes a method for identity authentication based on quantum key. The present invention adopts a method of obtaining shared keys from a quantum key distribution network, which can greatly reduce the complexity of users pre-setting shared keys and also enhance the security of the identity authentication process.
[0006] According to some embodiments, the present invention adopts the following technical solutions:
[0007] A method for identity authentication based on quantum key, comprising the following steps:
[0008] Each communication direction sends a request to the quantum key distribution node connected to itself to obtain the same quantum key as other communication parties participating in identity authentication;
[0009] Each communication party divides the obtained multiple sets of quantum keys into an authentication key pool and a communication key pool and stores them separately;
[0010] One of the communication parties initiates an identity authentication request and receives the verification result of the identity information of the requesting party from the other communication party, and verifies the identity information of the other party. During the verification process, the identity of the other party is verified by identifying the message check code, and the shared key used to calculate the message check code is obtained from the authentication key pool;
[0011] After the identity information is verified, data transmission is performed, and the transmitted data is encrypted using the encryption key obtained from the communication key pool, and the check code used to verify the identity of the data sender and the integrity of the data is calculated using the check key obtained from the communication key pool.
[0012] As an optional implementation method, the communication parties participating in the information exchange are all configured with or connected to a quantum key distribution node, and the quantum key distribution nodes distribute the shared quantum key through the quantum key distribution technology, and the communication parties obtain the shared quantum key through the quantum key distribution node.
[0013] As an optional implementation, the quantum key distribution node includes a quantum key distribution device and a quantum key management device according to the actual deployment of the quantum key distribution network.
[0014] As an optional implementation, the communication key pool includes encryption keys and verification keys, and the storage medium capacity of the authentication key pool and the communication key pool is set by the communication requirements of the communicating parties.
[0015] As an optional implementation, the authentication key pool and the communication key pool are marked with key type and key identification information when they are stored.
[0016] As an optional implementation, each authentication key in the authentication key pool and each communication key in the communication key pool are used only once, cleared after use, and a new key is used in the next communication.
[0017] As an optional implementation, when one of the communication parties initiates an identity authentication request, the user information of the communication party and a locally generated random number are sent, and the user information includes at least one of a user name, a user IP address, and a user serial number.
[0018] As an optional implementation method, the specific process of other communication parties verifying the identity information of the requester is to verify the legitimacy of the user information of the requester. If it is illegal, the authentication process is terminated; if it is legal, the next authentication message is sent to the requester, and the message content is that the recipient selects the first key for authentication from the authentication key pool, and uses the first key to calculate the message verification code of the local random number of the requester as a response message; at the same time, another random number is generated locally, and its own user information, the response message, the key identifier of the first key, and another random number are sent together to the identity authentication requester.
[0019] As a further limitation, when the first key is used to calculate the message check code of the requester's local random number as the response message, the calculation method is an HMAC algorithm implemented by a one-way hash function or a block cipher calculation method.
[0020] As an optional implementation method, the process of the requesting party verifying the other party's identity information includes: verifying whether the other party's user information is legal. If the user is illegal, the authentication process is terminated; if the user is legal, according to the authentication key identifier, the corresponding authentication key is selected from the authentication key pool, and the message verification code of its own random number is calculated and compared with the received response message. If the comparison fails, the authentication process is terminated and an authentication failure message is sent to the other party; if the comparison is successful, an authentication success message is sent to the other party.
[0021] As an optional implementation, the process of the receiver verifying the identity information of the requester includes:
[0022] The identity authentication requester selects a second authentication key from the authentication key pool, uses the second authentication key to calculate a message verification code of another random number sent by the other party, and sends the local user information, the message verification code, and the second authentication key key identifier to the identity authentication receiver;
[0023] After receiving the message, the identity authentication recipient first verifies the legitimacy of the user information of the identity authentication requester, then selects the corresponding second authentication key according to the authentication key identifier, uses the key to calculate another random number message verification code, and compares it with the received message verification code. If the comparison fails, the authentication process is terminated and a verification failure message is sent to the identity authentication requester; if the comparison is successful, an authentication success message is sent to the identity authentication requester. At this time, the identity authentication of both parties is successful.
[0024] As an optional implementation method, when performing data transmission, the data sending end selects the key of the first key identifier from the communication key pool as the encryption key, selects the key of the second key identifier as the verification key, uses the encryption key to encrypt the data to be transmitted to generate ciphertext, uses the verification key to calculate the message verification code based on the information including the ciphertext, the sending end user information, the first key identifier and the second key identifier, and sends the ciphertext, the sending end user information, the first key identifier, the second key identifier and the message verification code to the receiving end; the receiving end uses the verification key to calculate the corresponding message verification code based on the information including the ciphertext, the sending end user information, the first key identifier and the second key identifier, and compares it with the received message verification code. If the comparison is consistent, it means that the data is complete and comes from the sender; then the receiving end uses the encryption key to decrypt the ciphertext to obtain the plaintext.
[0025] Compared with the prior art, the present invention has the following beneficial effects:
[0026] The technical solution provided by the present invention is that when the communicating parties perform identity authentication and data transmission, the shared key used for the message verification code is obtained from the quantum key distribution network, which can reduce the complexity of pre-setting the shared key, shorten the update cycle of the shared quantum key, improve the security of the key, and support online acquisition.
[0027] In the process of data transmission, the two communicating parties of the present invention use the shared quantum key as the key to calculate the check code of the data message transmitted by both parties, and verify the identity of the data sender and the integrity of the data by identifying the message check code. The shared quantum key is cleared after use, and a new key is selected at the next communication. Because the shared quantum key uses quantum key distribution technology, even if the computing power is improved, it can resist the risk of being stolen, and only the communicating parties hold the key, so that the security of the message check code is improved, and the security of the identity authentication process is enhanced.
[0028] During the data transmission process, the present invention uses a shared quantum key to calculate and compare check codes for transmitted messages. Based on the identity authentication performed in the handshake phase, the quantum key can be used again in the data transmission phase to authenticate the sender's identity and verify the integrity of the transmitted data for each piece of transmitted data, thereby enhancing the strength of identity authentication.
[0029] The present invention solves the problem that in identity authentication methods based on symmetric keys, a large number of shared keys are usually required, and the keys need to be re-acquired when they are updated. The prior art generally adopts a pre-set method with high complexity. The present invention greatly shortens the update cycle of shared quantum keys, improves the security of keys, improves the efficiency of key acquisition, and can provide a "one-time one-key" key usage method to solve the instantaneous problem of shared symmetric keys in identity authentication.
[0030] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0032] Figure 1 It is the quantum key distribution method between the communicating parties;
[0033] Figure 2 It is a schematic diagram of generating multiple sets of identical keys between quantum key distribution nodes at both ends;
[0034] Figure 3 It is a schematic diagram of key storage method;
[0035] Figure 4 It is a schematic diagram of the authentication / communication key storage format;
[0036] Figure 5 It is a schematic diagram of the identity authentication and data transmission process. DETAILED DESCRIPTION
[0037] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0038] It should be noted that the following detailed descriptions are all illustrative and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0039] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, it indicates the presence of features, steps, operations, devices, components and / or combinations thereof.
[0040] A method for identity authentication based on quantum key. In this embodiment, to facilitate the understanding of technical personnel, two communicating parties are taken as an example for explanation, but the scope of protection of the present invention is not limited to this.
[0041] The method of this embodiment specifically includes the following steps:
[0042] 1. Quantum key distribution stage
[0043] Through quantum key distribution technology, quantum keys are distributed between the communicating parties Alice and Bob. The key distribution method is as follows: Figure 1 As shown. Quantum key distribution node 1 and quantum key distribution node 2 are two nodes in the quantum key distribution network. They distribute the shared quantum key through quantum key distribution technology, and then provide the quantum key to Alice and Bob respectively. In this way, Alice and Bob will also have a shared quantum key.
[0044] The quantum key distribution network can distribute shared quantum keys between any two nodes in the network through quantum key distribution technology. As long as a user accesses a node in the quantum key distribution network, he can obtain the shared quantum key with any other node through the node. The acquisition method can be near-end charging or remote online acquisition. Online acquisition is recommended because it is more convenient, shortens the key update cycle, and improves key security.
[0045] The quantum key distribution process between Alice and Bob is carried out in the following steps:
[0046] Step 1:
[0047] Through quantum key distribution technology, multiple sets of identical quantum keys are distributed between quantum key distribution nodes at both ends, such as Figure 2 shown.
[0048] Step 2:
[0049] Before starting identity authentication, Alice and Bob each obtain the same quantum key as the other party from the quantum key distribution node to which they are connected. Key updates can also be carried out in the same way.
[0050] Step 3:
[0051] Alice and Bob store the multiple sets of quantum keys they obtain or update in two categories: one is authentication key and the other is communication key. Communication key includes encryption key and verification key. The storage quantity of authentication key and communication key can be set according to the capacity of storage medium or specific needs of users. Figure 3 shown.
[0052] When storing authentication keys and communication keys, the key type, key identifier and other information must be marked. Figure 4 shown.
[0053] The authentication key and communication key are used once during use, and are cleared after use, and new keys are used in the next communication.
[0054] (II) Handshake Phase
[0055] In the first stage, Alice and Bob have shared the quantum key through quantum key distribution technology, which is used as the authentication key and communication key in the identity authentication process. The specific identity authentication method is as follows: Figure 5 As shown;
[0056] like Figure 5 As shown, the detailed steps of identity authentication and data transmission using quantum keys are as follows:
[0057] Step 1:
[0058] Alice sends an identity authentication request to Bob. The message contains Alice's user information UserInfo1 and Alice's locally generated random number Random1.
[0059] Note: The above “user information” is related information used to identify the user, which may be: user name, user IP address, user serial number and other information unique to each user.
[0060] Step 2:
[0061] After receiving Alice's message, Bob verifies the legitimacy of the user information UserInfo1. If UserInfo1 is not legal, the authentication process is terminated; if UserInfo1 is legal, the next authentication message is sent to Alice. The message content is: Bob selects the key AuKey1 for authentication from the authentication key pool, and its key identifier is ID Aukey1 , use AuKey1 to calculate the message check code MAC of the random number Random1 Aukey1 (Random1) as the response message; at the same time, a random number Random2 is generated locally; Bob's user information is UserInfo2; Bob sends UserInfo2, MAC Aukey1 (Random1), ID Aukey1 , and Random2 are sent to Alice.
[0062] In the above process, (1) the message check code calculation method can use the HMAC algorithm implemented by a one-way hash function, such as HMAC-SHA-256, which is a message check code using the SHA-256 one-way hash function; or use a block cipher to implement it, such as AES-CMAC, which is a message check code using the CBC mode of the AES algorithm.
[0063] (2) The random number can be a classical random number or a quantum random number.
[0064] Step 3:
[0065] After Alice receives Bob's message, she first verifies whether Bob's user information UserInfo2 is legal. If the user is not legal, the authentication process is terminated. If the user is legal, the authentication key ID is used to identify the user. Aukey1 , select the corresponding authentication key from the authentication key pool, calculate the message check code of the random number Random1, and compare it with the received MAC Aukey1(Random1) is compared. If the comparison fails, the authentication process is terminated and a message of authentication failure is sent to Bob; if the comparison succeeds, a message of authentication success is sent to Bob and the following four operations are started.
[0066] Step 4:
[0067] Alice selects the authentication key AuKey2 from the authentication key pool, whose key identifier is ID Aukey2 ; Use AuKey2 to calculate the message check code MAC of the random number Random2 Aukey2 (Random2); Alice sends UserInfo1, MAC Aukey2 (Random2), ID Aukey2 Send them to Bob together;
[0068] Step 5:
[0069] After receiving the message, Bob first verifies the legitimacy of Alice's user information UserInfo1, and then identifies the ID according to the authentication key Aukey2 Select the corresponding authentication key, use the key to calculate the Random2 message check code, and compare it with the received MAC Aukey2 (Random2) comparison. If the comparison fails, the authentication process is terminated and a verification failure message is sent to Alice; if the comparison succeeds, it means that Alice's identity has been successfully passed, and a successful authentication message is sent to Alice. At this time, the identity authentication of both parties is successful, and the following secure data transmission operations can be performed;
[0070] (III) Data transmission stage
[0071] like Figure 5 As shown in the figure, after the handshake between the two communicating parties is completed, the two parties can establish a secure channel for secure data transmission. During the data transmission process, each communication uses a shared quantum key to calculate and compare the check code of the message transmitted this time to verify the identity of the sender. The specific implementation method is as follows:
[0072] When data is transmitted between Alice and Bob, the sender (taking Alice as an example) selects a key identifier from the communication key as ID Enkey1 The key is used as the encryption key, and the key identifier is ID Enkey2 The key is the verification key, and Enkey1 is used to encrypt the data to be transmitted to generate the ciphertext E Enkey1 (Data), use Enkey2 to [UserInfo1, E Enkey1 (Data), ID Enkey1 、ID Enkey2 ] Calculate the message check code as MACEnkey2 , UserInfo1, E Enkey1 (Data), ID Enkey1 、ID Enkey2、 MAC Enkey2 Send to the receiving end; the receiving end uses EnKey2 to [UserInfo1, E Enkey1 (Data), ID Enkey1 、ID Enkey2 ] Calculate the message check code and compare it with MAC Enkey2 Do a comparison. If the comparison is consistent, it means that the data is complete and comes from Alice. Then the receiving end uses Enckey1 to encode E Enkey1 (Data) Decrypt and obtain the plaintext Data.
[0073] The quantum key distribution technology of the present invention is based on quantum mechanics. Since the quantum state has the characteristics of non-cloning, uncertainty and measurement collapse, it is guaranteed that the key cannot be effectively eavesdropped. Therefore, the use of quantum key distribution technology in the identity authentication scheme based on symmetric cryptography can provide security for the key sharing process. At the same time, with the construction of quantum communication backbone lines and metropolitan area networks, the coverage of quantum key distribution is gradually increasing, and the quantum key distribution technology can be used to complete the key sharing between access nodes within the coverage range. Therefore, as long as the user accesses the quantum communication network through the access node, the quantum key distribution service provided by the network can complete key sharing and key update, which is used to complete the identity authentication and secure data transmission based on symmetric keys, without the limitation of increased complexity caused by the increase in network scale, etc., which greatly improves the convenience of users and reduces the operating cost.
[0074] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0075] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0076] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0077] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0078] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
[0079] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.
Claims
1. A method for identity authentication based on quantum key, characterized in that: The following steps are involved: Each communication direction sends a request to the quantum key distribution node connected to itself to obtain the same quantum key as other communication parties participating in identity authentication; Each communication party divides the obtained multiple sets of quantum keys into an authentication key pool and a communication key pool and stores them separately; One of the communication parties initiates an identity authentication request and receives the identity information verification result of the other communication party, and verifies the identity information of the other party. During the verification process, the identity of the other party is verified by identifying the message verification code, and the shared key used for the message verification code is obtained from the authentication key pool; The specific process of other communication parties verifying the identity information of the requesting party is to verify the legitimacy of the user information of the requesting party. If it is not legitimate, the authentication process is terminated; If it is legal, the next authentication message is sent to the requester. The content of the message is that the receiver selects the first key for authentication from the authentication key pool, and uses the first key to calculate the message verification code of the requester's local random number as a response message; at the same time, another random number is generated locally, and the receiver sends its own user information, the response message, the key identifier of the first key, and another random number to the identity authentication requester together; When the first key is used to calculate the message check code of the local random number of the requesting party as the response message, the calculation method is an HMAC algorithm implemented by a one-way hash function or a block cipher calculation method; After the identity information is verified, data transmission is performed, and the transmitted data is encrypted using the encryption key obtained from the communication key pool, and the check code used to verify the identity of the data sender and the integrity of the data is calculated using the check key obtained from the communication key pool; When data transmission is performed, the data sending end selects the key of the first key identifier from the communication key pool as the encryption key, selects the key of the second key identifier as the verification key, uses the encryption key to encrypt the data to be transmitted, generates ciphertext, uses the verification key to calculate the message check code based on the information including the ciphertext, the sending end user information, the first key identifier and the second key identifier, and sends the ciphertext, the sending end user information, the first key identifier, the second key identifier and the message check code to the receiving end; the receiving end uses the verification key to calculate the corresponding message check code based on the information including the ciphertext, the sending end user information, the first key identifier and the second key identifier, and compares it with the received message check code. If the comparison is consistent, it means that the data is complete and comes from the sender; then the receiving end uses the encryption key to decrypt the ciphertext and obtain the plaintext.
2. A method for identity authentication based on quantum key according to claim 1, characterized in that: The communication parties participating in information exchange are all configured with or connected to a quantum key distribution node. The quantum key distribution nodes distribute shared quantum keys through quantum key distribution technology, and the communication parties have a shared quantum key.
3. A method for identity authentication based on quantum key according to claim 1, characterized in that: The quantum key distribution node includes quantum key distribution equipment and quantum key management equipment according to the actual deployment of the quantum key distribution network.
4. The method for identity authentication based on quantum key according to claim 1, characterized in that: The communication key pool includes encryption keys and verification keys, and the storage medium capacity of the authentication key pool and the communication key pool is set according to the communication requirements of the communication parties.
5. The method for identity authentication based on quantum key according to claim 1, characterized in that: When storing, the authentication key pool and the communication key pool are marked with key type and key identification information.
6. A method for identity authentication based on quantum key according to claim 1, characterized in that: Each authentication key in the authentication key pool and each communication key in the communication key pool are used only once, and are cleared after use, and a new key is used in the next communication.
7. The method for identity authentication based on quantum key according to claim 1, characterized in that: When one of the communication parties initiates an identity authentication request, the user information of the communication party and a locally generated random number are sent, wherein the user information includes at least one of a user name, a user IP address, and a user serial number.
8. The method for identity authentication based on quantum key according to claim 1, characterized in that: The process of the requesting party verifying the identity information of the other party includes: verifying whether the user information of the other party is legal. If the user is illegal, the authentication process is terminated; if the user is legal, the corresponding authentication key is selected from the authentication key pool according to the authentication key identifier, and the message verification code of its own random number is calculated and compared with the received response message. If the comparison fails, the authentication process is terminated and an authentication failure message is sent to the other party; if the comparison is successful, an authentication success message is sent to the other party.
9. The method for identity authentication based on quantum key according to claim 1, characterized in that: The process of the receiver verifying the identity of the requester includes: The identity authentication requester selects a second authentication key from the authentication key pool, uses the second authentication key to calculate a message verification code of another random number sent by the other party, and sends the local user information, the message verification code, and the second authentication key key identifier to the identity authentication receiver; After receiving the message, the identity authentication recipient first verifies the legitimacy of the user information of the identity authentication requester, then selects the corresponding second authentication key according to the authentication key identifier, uses the key to calculate another random number message verification code, and compares it with the received message verification code. If the comparison fails, the authentication process is terminated and a verification failure message is sent to the identity authentication requester; if the comparison is successful, an authentication success message is sent to the identity authentication requester. At this time, the identity authentication of both parties is successful.
Citation Information
Patent Citations
Improved AKA identity authentication system and method based on quantum communication network
CN108599925A
AKA identity authentication system and AKA identity authentication method based on symmetric key pool and relay communication
CN108768632A
Cited By
Communication opposite terminal identity authentication system and method based on shared key
CN121037121A
System and method for authentication of a communication peer based on a shared key
CN121037121B