A Homology-Based Post-Quantum Secret Handshake Method
Through the homologous post-quantum secret handshake method, the problems of high communication costs and insufficient security in the prior art are solved, and an efficient and secure secret handshake protocol in the quantum computing environment is realized, with traceability and unlinkability.
Patent Information
- Application Number
- CN202211558046.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-06
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2042-12-06
AI Technical Summary
The existing post-quantum secret handshake schemes are too expensive to communicate, cannot be tolerated in current devices, and cannot effectively resist quantum computing attacks.
The post-quantum secret handshake method based on homolog is adopted, and global parameters are generated through initialization, group organizations are created, new users join groups, secret handshakes are carried out between users, and zero-knowledge proof and administrator tracking mechanism are introduced to reduce communication overhead and resist quantum computing attacks.
It effectively reduces communication overhead, realizes security and traceability in the quantum computing environment, resists quantum computing attacks, and is unlinkable in a malicious enemy environment.
Smart Images

Figure CN116015628B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cryptographic privacy protection, and more specifically, relates to a post-quantum secret handshake method based on the same source. Background Art
[0002] The secret handshake protocol is a privacy protection authentication protocol in cryptographic applications. For individuals in the same organization, this protocol can perform anonymous two-way authentication and negotiate a session key while protecting the privacy of the individuals themselves. Due to the wide application of the secret handshake scheme in the fields of e-commerce and e-health, the secret handshake scheme has been a research hotspot for many years. Researchers have proposed various secret handshake schemes based on different cryptographic primitives to enhance its functions and performance. Castelluccia et al. proposed an effective secret handshake scheme through CA oblivious encryption. Zhou et al. proposed a secret handshake scheme based on the oblivious signature envelope (OSBE). Xu and Yung et al. provided weak linkability for the secret handshake scheme. Wen Yamin et al. proposed a secret handshake scheme based on identity and message recovery signature. Wang Weijia et al. proposed a method for multi-party secret handshake in a short key environment, and Wang Wenbo et al. proposed a secret handshake scheme based on chaotic mapping. These schemes are all proposed based on traditional number theory difficult problems. Therefore, with the development of quantum computers and quantum computing attacks, these schemes will no longer be secure. Currently, existing post-quantum secret handshake schemes include the lattice-based scheme proposed by Zhao Xingwen et al., the coding-based secret handshake scheme proposed by Zhang Zhuoran et al., and the lattice-based reusable certificate scheme proposed by An Zhiyuan et al. These schemes can effectively resist attacks by quantum algorithms, but the communication cost (100MB) of existing post-quantum secret handshake schemes is far from tolerable for current devices. In this regard, how to reduce the communication cost has become the main problem of post-quantum secret handshake schemes. Summary of the Invention
[0003] The present invention overcomes the above defects in the prior art and provides a post-quantum secret handshake method based on the same source, which effectively reduces the communication overhead in the post-quantum secret handshake scheme.
[0004] To solve the above technical problems, the technical solution adopted by the present invention is: a post-quantum secret handshake method based on the same source, comprising the following steps:
[0005] S1. Initialization: Input a security parameter λ, and generate global parameters par=(p, E0, t, s, r, N) through this security parameter; select two secure hash functions and
[0006] S2. Create a group organization: First, define the group administrator GA. GA takes the global parameter par as input and generates a group G. Then GA runs the key generation method CSI-FiSh.KeyGen based on the same source to generate a group key pair (gpk G , gsk G ) = (pk G , a), where a = [a1,…,a S-1 and a j is an element randomly selected from, where j ∈ [1, S - 1]; where pk G = [E j : j ∈ {1,…, S - 1}], and there is a relationship E j = [a j E0; where [a j E0 is the result of performing a j group actions on E0;
[0007] S3. A new user joins the group organization: For a new user U who needs to join the group G, the user first needs to select a bit string ID u as the user's pseudonymous identity. Then GA runs the signature method CSI-FiSh.Sign(ID u , gsk G ), generates a signature of the group on the new user as the user's certificate, denoted where for i ∈ [1, t], Next, GA sends cred u to the user U and stores (realID u , ID u ) in the member list of the group , where realID u represents the unique identifier of the user U in the system background, and stores the signature of the user U (ID u , cred u ) in the signature list ;
[0008] S4. Secret handshake between users: Suppose a member U has a certificate cred u in group G1, and another member V has a certificate cred v in group G2. Then the secret handshake between user U and V needs to go through the following procedures, specifically including the following four steps:
[0009] S41. The first stage: User U calculates its anonymous authentication information and sends it to user V;
[0010] S42. Second stage: V verifies the legality of the anonymous information sent by U and generates new anonymous information about V and sends it to U;
[0011] S43. Third stage: U→V: (RSP u ); U verifies the legality of the anonymous information sent by V;
[0012] S44. Fourth stage: After user V receives the information RSP u sent by user U in the third stage, user V checks whether it holds; if it holds, user V outputs 1, otherwise outputs 0.
[0013] The present invention modifies the Fiat-Shamir paradigm in zero-knowledge proof and utilizes the technology from the CSI-FiSh signature and its corresponding zero-knowledge proof system. Meanwhile, for each zero-knowledge identification record, the present invention embeds part of the information of the CSIDH temporary private key into the challenge, that is, the information is divided into several parts, and the new challenge is the exclusive OR of the partial information and the hash value. Therefore, although the receiver cannot verify whether the signature is valid, the temporary private key can be recovered from all the hidden information. If the participants are in the same group, this temporary private key will be used as the session key negotiated between the two users.
[0014] Furthermore, it also includes the administrator tracking users. When certain disputes occur, GA will use its tracking privilege to retrieve the handshake records of users U and V; GA can obtain the user pseudonym identities ID′ u and ID′ v from a certain secret handshake instance between users U and V. Among them, GA will record all the communication messages of a certain secret handshake between users U and V during the secret handshake process, that is RSP v , RSP u ; GA determines whether the pseudonym identities ID′ and ID′ u exist in the secret handshake process by looking up the signature list. If they exist, the corresponding users can be found in the user identity list v . If they do not exist, it means that ID′ u is not in group G or is a malicious user. Through this method, GA can identify which user the pseudonym identity of a certain handshake corresponds to, and further identify which users have performed malicious secret handshakes.
[0015]
[0015] Furthermore, when there is a need to remove group members, GA can modify or update the CRL list after tracking malicious group members; if it is necessary to remove user U from group G, GA will do so in the member list According to realID u Find all (realID u , ID u ), and remove all IDs of user U from the signature list The corresponding signatures (ID u , cred u , u ); then GA adds all IDs u to the CRL and distributes a warning notice to the members in all other groups through an authenticated anonymous channel. The notice tells the members of the group that when performing a secret handshake, if the other party uses any pseudonymous identity that appears in the CRL, do not continue to execute the handshake protocol.
[0016] Furthermore, the specific steps of step S41 include:
[0017] S411. User U randomly samples an integer on and then calculates the key exchange information E =[γ u E0, let E u :y u =x 2 +m 3 x u x 2 +x, and then user U divides m u into t parts
[0018] S412. For i ∈ [1, t], user U selects according to the group public key that is, selects the curve with the subscript of in and calculates the curve
[0019] S413. For i ∈ [1, t], user U randomly samples r integers on where k ∈ [1, r], and then calculates and then calculates and then calculates
[0020] S414. For i ∈ [1, t] and k ∈ [1, r], user U calculates
[0021]
[0022] Therefore, there is
[0023] S415. User U generates anonymous authentication information and sends PR uSent to user V.
[0024] Furthermore, the specific steps of step S42 include:
[0025] S421. After user V receives the anonymous information PR sent by user U in the first stage u , calculate
[0026]
[0027] S422. For i ∈ [1, t] and k ∈ [1, r], user V selects according to the group public key That is, select the curve with the subscript in , and then calculate
[0028]
[0029] Then user V calculates
[0030] S423. For i ∈ [1, t], user V calculates Merge to obtain Thus, the elliptic curve is obtained. If is not a supersingular curve, then user V sends a random text to user U and ends the second stage of the secret handshake protocol;
[0031] S424. User V randomly samples an integer on , and then calculates the key exchange information E v = [γ v E0 and where E v ∶ y 2 = 3 + v x 2 +, and user V divides the message m v into t parts Next, user V calculates and sends RSP v to U;
[0032] S425. For i ∈ [1, t], user V selects according to the group public key That is, select the curve with the subscript in , calculate the curve
[0033] S426. For i ∈ [1, t], user V is on Randomly sample r integers where k ∈ [1, r]; then calculate Then calculate
[0034] S427. For i ∈ [1, t] and k ∈ [1, r], user V calculates
[0035]
[0036] Therefore, there is
[0037] S428. User V generates anonymous authentication information and sends PR v to user U.
[0038] Furthermore, the specific steps of step S43 include:
[0039] S431. After receiving the information PR v and RSP v sent by user V in the second stage, user U calculates
[0040]
[0041] S432. For i ∈ [1, t] and k ∈ [1, r], user U calculates
[0042]
[0043] Then user U calculates
[0044] S433. For i ∈ [1, t], user U calculates Combine to obtain Thus, the elliptic curve If is not a supersingular curve, then user U randomly generates a value RSP u and sends it to user V, then ends the third stage of the secret handshake protocol;
[0045] S434. User U calculates If holds, then user U outputs 1, and then calculates and sends it to user V; otherwise user U outputs 0, and randomly generates a value RSP u , and then sends RSP u to user V.
[0046] Furthermore, the specific steps of step S3 include:
[0047] User U selects a bit string ID u = 101010 as their pseudonymous identity and sends ID u to GA. Then GA runs the homology-based signature method CSI-FiSh.Sign(ID u , sk G ) to generate a group signature on user U as the certificate of user U; where the signature cred u satisfies the following relationship: for i ∈ [1, t], randomly generate and calculate Calculate Then for i ∈ [1, t], calculate where b i ∈ {0, 1, …, S - 1}, is an element in gsk G ;
[0048] Next, GA sends cred u to user U and stores (D u , ID u ) in the group's member list where realID u represents the unique identifier of user U's system background; and GA will store the signature on user U ([[]] u , red u ) in the signature list ; Similarly, add user V to group G. User V selects a bit string ID v = 1111111 as their pseudonymous identity and sends ID v to GA; then GA generates a group signature on user V as the certificate of user V, then sends cred v to user V and stores (realID v , ID v ) in the group's member list and finally stores the signature on user V (ID v , cred v ) in the signature list .
[0049] The present invention also provides a homology-based post-quantum secret handshake system, including:
[0050] Initialization module: used to input a security parameter λ, generate global parameters par = (p, E0, t, S, r, N) through this security parameter; select two secure hash functions and
[0051] Create group organization module: used to first define the group administrator GA, GA takes the global parameter par as input to generate a group G; then GA runs the key generation method CSI-FiSh.KeyGen based on the same source to generate a group key pair (gpk G , gsk G ) = (pk G , a), where a = [a1,..., a s-1 and a j is an element randomly selected on, where j ∈ [1, S - 1]; where pk G = [E j : j ∈ {1,..., S - 1}], and there is a relationship E j = [a j E0; where [a j E0 is the result of performing a j group actions on E0;
[0052] New user joining group organization module: For a new user U who needs to join the group G, the user first needs to select a bit string ID u as the user's pseudonym identity, then GA runs the signature method CSI-FiSh.Sign(ID u , gsk G ), generates a signature of the group regarding the new user as the user's certificate, denoted as where for i ∈ [1, t], Next, GA sends cred u to the user U, and stores (realID u , ID u ) in the member list of the group , where reallD u represents the unique identifier of the user U in the system background, and stores the signature (ID u , cred u ) of the user U in the signature list ;
[0053] Secret handshake module between users: used to assume that a certain member U has a certificate cred u in the group G1, and another member V has a certificate cred v in the group G2, then the secret handshake between the users U and V needs to go through the following procedures, specifically including the following four units:
[0054] The first unit: User U calculates its anonymous authentication information and sends it to user V;
[0055] Second unit: V verifies the legality of the anonymous information sent by U and generates new anonymous information about V and sends it to U;
[0056] Third unit: U→V:(RSP u ); U verifies the legality of the anonymous information sent by V;
[0057] Fourth unit: After user V receives the information RSP sent by user U in the third stage u , user V checks whether it holds; if it holds, user V outputs 1, otherwise outputs 0;
[0058] Administrator tracking user module: When some disputes occur, GA will use its tracking permission to retrieve the handshake records of users U and V; GA can obtain the user pseudonym identity ID′ u and ID′ v from a certain secret handshake instance between users U and V. During the secret handshake, GA will record all communication messages between users U and V in a certain secret handshake, that is GA determines whether the pseudonym identities ID′ and ID′ u and ID′ v exist in the secret handshake process by looking up the signature list. If they exist, the corresponding users will be found in the user identity list . If they do not exist, it means that ID′ u is not in group G or is a malicious user;
[0059] Remove group member module: When there is a need to remove a group member, GA can modify or update the CRL list after tracking malicious group members; if it is necessary to remove user U from group G, GA will search for all (realID in the member list according to realID u ,ID u ,ID u ), and remove all signatures of user U's ID in the signature list u corresponding to (ID u ,cred u ); then GA adds all ID u to the CRL and distributes a warning notice to all other group members through an authenticated anonymous channel. This notice tells the group members that when performing a secret handshake, if the other party uses any pseudonym identity that appears in the CRL, do not continue to execute the handshake protocol.
[0060] The present invention also provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the computer program to implement the above-mentioned homologous-based post-quantum secret handshake method.
[0061] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned homologous-based post-quantum secret handshake method is implemented.
[0062] Compared with the prior art, the beneficial effects are as follows: The method of the present invention realizes the homologous-based secret handshake method for the first time, introduces the homologous-based method into the existing post-quantum secret handshake methods, thereby effectively reducing the communication overhead required for secret handshake. At the same time, the use of one-time pseudonyms with basic security attributes realizes the traceability of GA and the unlinkability in the environment of malicious adversaries. In addition, due to the use of the homologous-based cryptographic scheme, the method of the present invention can resist possible quantum computing attacks, so the present invention is also a post-quantum secret handshake method. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 is a schematic flowchart of the method of the present invention.
[0064] Figure 2 is a schematic diagram of a group member joining a group proposed by the method of the present invention.
[0065] Figure 3 is a schematic diagram of secret handshake interaction proposed by the method of the present invention.
[0066] Figure 4 is a schematic diagram of partial interaction of secret handshake user U proposed by the method of the present invention.
[0067] Figure 5 is a schematic diagram of partial interaction of secret handshake user V proposed by the method of the present invention.
[0068] Figure 6 is a schematic diagram of the steps for the group administrator to track users proposed by the method of the present invention.
[0069] Figure 7 is a schematic diagram of the steps for the group administrator to remove users proposed by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The present invention will be described in one of the specific embodiments below. Among them, the accompanying drawings are only for illustrative purposes, showing only schematic diagrams, rather than physical diagrams, and cannot be construed as a limitation of this patent; in order to better illustrate the embodiments of the present invention, some components in the accompanying drawings will be omitted, enlarged or reduced, and do not represent the size of the actual product; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the accompanying drawings may be omitted.
[0071] In the description of the present invention, it should be understood that if there are terms such as "upper", "lower", "left", "right", etc. indicating the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, it is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, the terms describing the positional relationship in the accompanying drawings are only for illustrative purposes and cannot be construed as a limitation of this patent. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances. In addition, if there is a description involving "first", "second", etc. in the embodiments of the present invention, the description of "first", "second", etc. is only for descriptive purposes and cannot be construed as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the meaning of "and / or" appearing throughout the text is that it includes three parallel solutions. Taking "A and / or B" as an example, it includes solution A, or solution B, or a solution that satisfies both A and B simultaneously.
[0072] Embodiment 1:
[0073] First, the parameter settings and symbols in this embodiment will be described:
[0074] ■ p = 5326738796327623094747867617954605554069371494832722337612446642054009560026576537626892113026381253624626941643949444792662881241621373288942880288065659;
[0075] ■ λ = 128;
[0076] ■ E0∶y 2 = x 3 + x;
[0077] ■r = 128;
[0078] ■t = 16;
[0079] ■S = 64;
[0080] ■N = 254652442229484275177030186010639202161620514305486423592570860975597611726191;
[0081] ■ The hash function is defined as: taking the first 128 bits of sha256;
[0082] ■ The hash function is defined as: taking the first 96 bits of sha384;
[0083] ■ is defined as: the ring of integers modulo N;
[0084] ■ The definition of j(E) is: the j - invariant of the elliptic curve E;
[0085] ■ All elliptic curves involved in the inventive method are defined over F p this finite field.
[0086] ■ For bitstrings or integers x, y, x||y respectively represent the exclusive - or and concatenation of the bitstrings of x and y;
[0087] As Figure 1 shown, the function of process 2 can only be executed after process 1 is executed, and the function of process 3 can only be executed after process 2 is executed; A post - quantum secret handshake method based on homology provided in this embodiment includes the following steps:
[0088] Step 1. System initialization: For the input security parameter λ, and generate the global parameter par = (p, E0, t, S, r, N). Select the above - mentioned hash function and
[0089] Step 2. Create a group organization: The group manager GA takes the global parameter par as input to generate a group G. Then GA runs the homology - based signature method CSI - FiSh.KeyGen to generate a group key pair (gpk G , gsk G ) = (pk G , a) = ([E1,..., E S-1 , [a1,..., a S-1 ). Among them, the key pair (gpk G, gsk G ) satisfies the following relationship: For and there is E j = [a j E0;
[0090] Step 3. New user joins the group: The process is as Figure 2 shown. User U selects the bit string ID u = 101010 as its pseudonymous identity and sends ID u to GA. Then GA runs the homology-based signature method CSI-FiSh.Sign(ID u , gsk G ), generates a signature of the group for user U as the certificate of user U. Among them, the signature cred u satisfies the following relationship: For i ∈ [1, t], randomly generate and calculate Calculate Then for i ∈ [1, t], calculate where b i ∈ {0, 1,..., S - 1}, is an element in gsk G .
[0091] Next, GA sends cred u to user U and stores (D u , ID u ) in the member list of the group , where realID u represents the unique identifier of user U in the system background. And GA will store the signature of user U ([[]] u , red u ) in the signature list . Similarly, add user V to the group G. User V selects a bit string ID v = 1111111 as its pseudonymous identity and sends ID v to GA. Then GA generates a signature of the group for user V as the certificate of user V, then sends cred v to user V, and stores (D v , D v ) in the member list of the group , and finally stores the signature of user V ([[]] v , red v ) in the signature list .
[0092] Step 4. Secret handshake between users: Member U belonging to group G1 and member V belonging to group G2 execute a secret handshake protocol, as Figure 3 , shown in Figures 4 and 5, specifically including the following four steps:
[0093] S41. The first stage: User U calculates anonymous authentication information and sends it to user V;
[0094] S411. User U randomly samples an integer on and then calculates the key exchange information E u =[γ u E0, let E u : 2 = 3 + u x 2 +, then m u can be obtained, and then user U divides m u into t parts
[0095] S412. For i ∈ [1, t], user U selects according to the group public key, that is, selects the curve with subscript in and calculates the curve
[0096] S413. For i ∈ [1, t], user U randomly samples r integers on where k ∈ [1, r], and then calculates and then calculates
[0097] S414. For i ∈ [1, t] and k ∈ [1, r], user U calculates
[0098]
[0099] Therefore, there is
[0100] S415. User U generates anonymous authentication information and sends PR u to user V.
[0101] S42. The second stage: V verifies the legality of the anonymous information sent by U and generates new anonymous information about V and sends it to U;
[0102] S421. After receiving the anonymous information PR u sent by user U in the first stage, user V calculates
[0103]
[0104] S422. For \(i\in[1,t]\) and \(k\in[1,r]\), user V selects according to the group public key That is, select the curve with subscript in and then calculate
[0105]
[0106] Then user V calculates
[0107] S423. For \(i\in[1,t]\), user V calculates Merge to obtain Thus, the elliptic curve If is not a supersingular curve, then user V sends a random text to user U and ends the second stage of the secret handshake protocol;
[0108] S424. User V randomly samples an integer on Here, let \(\gamma\) v , and then calculate the key exchange information E v = \([\gamma\) v E0 and where E v ∶y 2 = 3 + v x 2 +, and user V divides the message m v into t parts Next, user V calculates and sends RSP v to U;
[0109] S425. For \(i\in[1,t]\), user V selects according to the group public key That is, select the curve with subscript in and calculate the curve
[0110] S426. For \(i\in[1,t]\), user V randomly samples r integers on where \(k\in[1,r]\); then calculate Then calculate
[0111] For \(i\in[1,t]\) and \(k\in[1,r]\), user \(V\) calculates
[0112]
[0113] Therefore, there is
[0114] S428. User \(V\) generates anonymous authentication information and sends \(PR\) v to user \(U\).
[0115] S43. The third stage:
[0116] S431. After receiving the information \(PR\) v and \(RSP\) v sent by user \(V\) in the second stage, user \(U\) calculates
[0117]
[0118] S432. For \(i\in[1,t]\) and \(k\in[1,r]\), user \(U\) calculates
[0119]
[0120] Then user \(U\) calculates
[0121] S433. For \(i\in[1,t]\), user \(U\) calculates Combined to obtain Thus, the elliptic curve If is not a supersingular curve, user \(U\) randomly generates a value \(RSP\) u and sends it to user \(V\), then ends the third stage of the secret handshake protocol;
[0122] S434. User \(U\) calculates If holds, user \(U\) outputs \(1\), then calculates and sends it to user \(V\); otherwise user \(U\) outputs \(0\) and randomly generates a value \(RSP\) u , then sends \(RSP\) u to user \(V\).
[0123] S44. The fourth stage: After receiving the information \(RSP\) u sent by user \(U\) in the third stage, user \(V\) checks whether it holds; if it holds, user \(V\) outputs \(1\), otherwise outputs \(0\).
[0124] Step 5. Administrator tracks users: If Figure 6As shown, GA will retrieve the handshake records of users U and V using its tracking permissions. Here, GA retrieves the handshake records of the above-mentioned users U and V. Based on the records of the completed handshake protocol, GA first obtains the pseudonymous identities ID′ of users U and V from the handshake records u = 101010 and ID v ′ = 1111111. Then GA discovers the existence of signatures ( ) by looking up the signature list u = 101010, cred u ) that satisfy ID u = D′ u , and signatures ( v = 101010, cred v ) that satisfy ID v = D v ′. Therefore, by looking up the corresponding users in the member list , it is found that the ID u in ( u , D u ) satisfies ID u = D′ u , and the ID v in ( v , D v ) satisfies ID v = D v ′. The identification has traced the two users U and V identified by realID u and realID v , and there are no malicious users.
[0125] Step 6. Remove group members: As Figure 7 shown, it is necessary to remove user U from the group. First, GA looks for all ( ) in the member list according to realID u , and removes all signatures ( u , D u ) corresponding to the ID of user U in the signature list. Then GA adds all the retrieved ID u to the CRL and sends a warning notice to user V through an authenticated anonymous channel. When user V needs to perform a secret handshake with user U again, user V will reject continuing the secret handshake with user U when user V finds that the ID u used by U for the secret handshake appears in the CRL. u ) in the signature list. Then GA adds all the retrieved ID u to the CRL and sends a warning notice to user V through an authenticated anonymous channel. When user V needs to perform a secret handshake with user U again, user V will reject continuing the secret handshake with user U when user V finds that the ID u used by U for the secret handshake appears in the CRL.
[0126] Example 2
[0127] This embodiment provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. The processor executes the computer program to implement the method for post-quantum secret handshake based on the same source described in Embodiment 1.
[0128] Embodiment 3
[0129] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for post-quantum secret handshake based on the same source described in Embodiment 1 is implemented.
[0130] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limitations on the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or variations can be made based on the above description. It is not necessary and impossible to enumerate all the implementation manners here. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the claims of the present invention.
Claims
1. A homology-based post-quantum secret handshake method, characterized in that It includes the following steps: S1. Initialization: Input a security parameter λ, and generate global parameters par = (p, E0, t, S, r, N) through this security parameter; Select two secure hash functions and S2. Create a group organization: First, define the group administrator GA. GA takes the global parameter par as input to generate a group G. Then GA runs the homology-based key generation method CSI-FiSh.KeyGen to generate a group key pair (gpk G , gsk G ) = (pk G , a), where a = [a1,..., a S-1 and a j is an element randomly selected from, where j ∈ [1, S - 1]; where pk G = [E j : j ∈ {1,..., S - 1}], and there is a relationship E j = [a j E0; where [a j E0 is the result of applying the group action of a j times to E0; S3. New user joins the group organization: For a new user U who needs to join group G, the user first needs to select a bit string ID u as the user's pseudonym identity. Then GA runs the homology-based signature method CSI-FiSh.Sign(ID u , gsk G ) to generate a signature of the group for the new user as the user's certificate, denoted as where for i ∈ [1, t], Next, GA sends cred u to user U, and stores (realID u , ID u ) in the group's member list , where realID u represents the unique identifier of user U in the system background, and stores the signature of user U (ID u , cred u ) in the signature list ; S4. Secret Handshake between Users: Assume that a member U has a certificate cred in group G1 u , and another member V has a certificate cred in group G2 v . Then, the following procedure is required for a secret handshake between users U and V, which specifically includes the following four steps: S41. The first stage: U → V; User U calculates its anonymous authentication information and sends it to user V; S42. The second stage: V → U; V verifies the legality of the anonymous information sent by U, and generates new anonymous information about V and sends it to U; S43. The third stage: U → V; U verifies the legality of the anonymous information sent by V; S44. The fourth stage: After user V receives the information sent by user U in the third stage, user V checks whether the equation holds; if it holds, user V outputs 1, otherwise outputs 0.
2. The method for post-quantum secret handshake based on homology according to claim 1, wherein It also includes administrators tracking users. When certain disputes occur, GA will use its tracking authority to retrieve the handshake records of users U and V; GA can obtain the user pseudonym identity ID′ from a secret handshake instance between users U and V u and ID′ v , where GA will record all communication messages between users U and V in a secret handshake, i.e. ID u , ID v , RSP v ,RSP u ;GA finds the signature list Determine the pseudonymous identity ID′ during the secret handshake process u and ID′ v Does it exist? If so, it is in the user identity list. Find the corresponding user in the search result. If it does not exist, it means ID' u Users who are not in group G or are malicious users.
3. The post-quantum secret handshake method based on homology according to claim 2, wherein When there is a need to remove group members, GA can modify or update the CRL list after tracking malicious group members; if user U needs to be removed from group G, GA will search for all (realID in the member list according to realID u and find all (realID u , ID u ), and remove all signatures of user U in the signature list corresponding to the ID u (ID u , cred u ); then GA adds all IDs u to the CRL list and distributes a warning notice to the members in all other groups through an authenticated anonymous channel. The notice tells the members of the group that when performing a secret handshake, if the other party uses any pseudonymous identity that appears in the CRL list, do not continue to execute the handshake protocol.
4. The post-quantum secret handshake method based on homology according to claim 1, wherein The specific steps of step S41 include: User U randomly samples an integer on and then calculates the key exchange information E = [γ u E0, let E u :y u = x 2 + m 3 x u + x, and then user U divides the message m 2 into t parts u S412. For i ∈ [1, t], user U selects according to the group public key that is, selects in the curve with the subscript and calculates the curve S413. For i ∈ [1, t], user U randomly samples r integers on and where For \(k\in[1,r]\), then calculate Then calculate S414. For i ∈ [1, t] and k ∈ [1, r], user U calculates Therefore, there is S415. User U generates anonymous authentication information and sends PR u to user V.
5. The post-quantum secret handshake method based on homology according to claim 4, characterized in that, The specific steps of step S42 include: After user V receives the anonymous information PR sent by user U in the first stage u calculate S422. For \(i\in[1,t]\) and \(k\in[1,r]\), user \(V\) selects according to the group public key i.e., selects in the curve with the subscript and then calculates Then user V calculates S423. For i ∈ [1, t], user V calculates Combined to obtain Thus obtaining the elliptic curve If is not a supersingular curve, then user V sends a random text to user U and ends the second stage of the secret handshake protocol; S424. User V is Randomly sample an integer Then calculate the key exchange information E v =[γ v ]E0 and Where E v :y 2 =x 3 +m v x 2 +x, and user V sends message m v Divide into t parts Next, user V calculates And put RSP v Send to U; S425. For i ∈ [1, t], user V selects according to the group public key That is, selects in the curve with the subscript of and calculates the curve S426. For \(i\in[1,t]\), user \(V\) randomly samples \(r\) integers on where \(k\in[1,r]\); then calculate then calculate then calculate S427. For i ∈ [1, t] and k ∈ [1, r], user V calculates Therefore, there is S428. User V generates anonymous authentication information and sends PR v to User U.
6. The homologue-based post-quantum secret handshake method according to claim 5, wherein The specific steps of step S43 include: S431. User U receives the information PR sent by user V in the second stage v and RSP v and then calculates S432. For i ∈ [1, t] and k ∈ [1, r], user U calculates Then user U calculates S433. For i ∈ [1, t], user U calculates Combined to obtain Thus, the elliptic curve is obtained If is not a supersingular curve, then user U randomly generates a value RSP u and sends it to user V, and then ends the third stage of the secret handshake protocol; S434. User U calculates If holds, User U outputs 1, then calculates and sends it to User V; otherwise User U outputs 0 and randomly generates a value RSP u , then sends RSP u to User V.
7. The method for post-quantum secret handshake based on homology according to any one of claims 1 to 6, characterized in that, The specific steps of step S3 include: User U selects the bit string ID u = 101010 as their pseudonymous identity and sends the ID u to GA. Then GA runs the homology-based signature method CSI-FiSh.Sign(ID u , gsk G ) to generate a group signature for user U as the certificate of user U; where the signature cred u satisfies the following relationship: for i ∈ [1, t], randomly generate and calculate Calculate Then for i ∈ [1, t], calculate where b i ∈ {0, 1, …, S - 1}, is an element in gsk G ; Next, GA sends cred u to user U, and stores (realID u , ID u ) in the member list of the group , where realID u represents the unique identifier of user U in the system background; and GA stores the signature of user U (ID u , cred u ) in the signature list ; Similarly, user V is added to group G. User V selects a bit string ID v = 1111111 as their pseudonymous identity and sends ID v to GA; then GA generates a signature of the group for user V as the certificate of user V, then sends cred v to user V, and stores (realID v , ID v ) in the member list of the group , and finally stores the signature of user V (ID v , cred v ) in the signature list .
8. A homology-based post-quantum secret handshake system, characterized in that, It includes: Initialization module: used to input a security parameter λ, and generate global parameters par = (p, E0, t, S, r, N) through this security parameter; select two secure hash functions and Create group organization module: First, it is used to define the group administrator GA. GA takes the global parameter par as input to generate a group G. Then GA runs the homomorphic key generation method CSI-FiSh.KeyGen to generate a group key pair (gpk G , gsk G ) = (pk G , a), where a = [a1,..., a S-1 and a j is an element randomly selected from, where j ∈ [1, S - 1]; where pk G = [E j : j ∈ {1,..., S - 1}], and there is a relationship E j = [a j E0; where [a j E0 is the result of performing the group action of a j times on E0; New user joining the group organization module: For a new user U who needs to join group G, the user first needs to select a bit string ID u as the user's pseudonym identity. Then GA runs the homology-based signature method CSI-FiSh.Sign(ID u , gsk G ) to generate a signature of the group for the new user as the user's certificate, denoted as where for i ∈ [1, t], Next, GA sends cred u to user U and stores (realID u , ID u ) in the group's member list , where realID u represents the unique identifier of user U in the system background. And the signature of user U (ID u , cred u ) is stored in the signature list ; Secret Handshake Module between Users: It is used to assume that a member U has a certificate cred in group G1 u , and another member V has a certificate cred in group G2 v , then the following procedures are required for a secret handshake between users U and V, specifically including the following four units: The first unit: U → V; User U calculates its anonymous authentication information and sends it to user V; The second unit: V → U; V verifies the legality of the anonymous information sent by U, and generates new anonymous information about V and sends it to U; The third unit: U → V; U verifies the legality of the anonymous information sent by V; The fourth unit: After user V receives the information sent by user U in the third stage, user V checks whether the equation holds; if it holds, user V outputs 1, otherwise outputs 0; Administrator Tracking User Module: When certain disputes occur, GA will retrieve the handshake records of users U and V using its tracking permissions; GA can obtain the pseudonymous identity ID' of users from a certain secret handshake instance between users U and V. u and ID' v , where GA will record all communication messages of users U and V during a certain secret handshake, namely ID u , ID v , RSP v ,RSP u ; GA determines the pseudonymous identities ID' and ID' u during the secret handshake process by looking up the signature list v to check if they exist. If they exist, the corresponding users are found in the user identity list . If they do not exist, it means that ID' u is not in group G or is a malicious user. Remove group member module: When there is a need to remove group members, GA can modify or update the CRL list after tracking malicious group members; if user U needs to be removed from group G, GA will add it to the member list. According to realID u Find all (realID u ,ID u ) and in the signature list Remove all IDs of user U from u The corresponding signature (ID u ,cred u );Then GA takes all IDs u Add to the CRL list and distribute warning notices to all other group members through authenticated anonymous channels. The notice tells group members not to continue the handshake protocol if the other party uses any pseudonymous identity that appears in the CRL list during the secret handshake.
9. An electronic device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to implement the homologous-based post-quantum secret handshake method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the homologous-based post-quantum secret handshake method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Authentication and key agreement protocol method for Internet of Things equipment in distributed cloud computing architecture
CN113765658A
Public key authentication deniable encryption method and system
CN114189329A