Smart Card-Based Authentication and Key Exchange Method

The smart card-based authentication and key exchange method using MLWE and error-coordination addresses quantum computing vulnerabilities by generating secure, anonymous identity tags and random numbers, enhancing security against quantum attacks.

CN116405244BActive Publication Date: 2025-07-15Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310154630.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-22
Publication Date
2025-07-15
Estimated Expiration
2043-02-22

AI Technical Summary

Technical Problem

The existing smart card-based authentication and key exchange methods cannot resist the threat of quantum computers and cannot effectively protect user data privacy and security.

Method used

MLWE issues are used to generate the private and public keys of the smart card and server, and the error coordination mechanism is used to authenticate and key exchange, and verification information is generated through anonymous identity and random numbers to prevent identity leakage.

Benefits of technology

It realizes secure authentication and key exchange between smart cards and servers in the era of quantum computers, resists quantum computing attacks, protects user identity privacy, and improves the security and anonymity of authentication and key exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405244B_ABST
    Figure CN116405244B_ABST
Patent Text Reader

Abstract

The present application discloses an authentication and key exchange method based on a smart card. By selecting MLWE as the underlying difficult problem, a two-way authentication scheme between the smart card and the server is constructed, realizing two-way authentication between the user and the server and negotiating a session key. Since the private keys and public keys used by the smart card and the server are both obtained based on the MLWE problem, the current quantum algorithms cannot recover the private keys used by the smart card and the server through the public keys. Similarly, it is even more impossible to recover the intermediate secrets obtained using the error correction mechanism, and thus impossible to recover the user identity information verification, server identity information verification, and the session key negotiated between the two. As a result, the smart card and the server can resist the attacks of quantum computers during the process of authentication and key negotiation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technologies, and more specifically, to an authentication and key exchange method based on a smart card. Background Art

[0002] With the development of Internet services and e-commerce technologies, ensuring secure authentication between a server and a user is of great significance. The identity authentication scheme between Internet users needs to be able to achieve the dual security goals of real identity recognition and session key negotiation.

[0003] A smart card is a miniature electronic device with a storage medium and an integrated circuit, which has the unique advantages of low cost, easy portability, and the ability to improve security through encryption algorithms, and has become another security factor for designing a password authentication scheme. In recent years, authentication and key exchange schemes based on smart cards have been widely applied to e-commerce, smart homes, cloud services, and online payment systems. However, in the current authentication and key exchange schemes based on smart cards, most of the security is based on traditional cryptographic difficult problems such as discrete logarithms or discrete logarithms on elliptic curves. Cryptographic algorithms constructed based on the discrete logarithm problem and the large integer factorization problem have polynomial solution algorithms under quantum computers and cannot resist the threat from quantum computers, and cannot protect the data privacy security of users in the quantum computer era. Summary of the Invention

[0004] In view of this, the present application provides an authentication and key exchange method based on a smart card, which is used to solve the problem that the existing authentication and key exchange method based on a smart card cannot resist the threat from quantum computers and cannot protect the data privacy security of users in the quantum computer era.

[0005] In order to achieve the above object, the following solution is proposed:

[0006] An authentication and key exchange method based on a smart card, which is applied to a smart card. The method includes:

[0007] When it is detected that the user logs in successfully, use a preset sampling algorithm to sample from the distribution on the polynomial ring in the MLWE problem respectively to obtain a private key s0, a noise e0, and a noise e1;

[0008] Based on the s0 and the e0, use the MLWE problem to calculate a public key b0, and based on a public key P generated by a server stored in advance, the s0, and the e1, use the MLWE problem to calculate a public key v;

[0009] Use a preset error correction mechanism to correct the v to obtain an intermediate secret k0 and a signal value c0;

[0010] Encrypt the identity identifier ID corresponding to the user based on the k0, the preset first parameter set, and the preset encryption algorithm i to obtain the anonymized identity identifier AID i ;

[0011] Generate the user identity verification information γ1 based on n1, the ID i and the preset second parameter set, where the n1 is a random number pre-stored by the server when the user registers;

[0012] Send the set M0 to the server, where the M0 includes the AID i , the b0, the γ1, and the c0;

[0013] Receive the set M1 sent by the server, where the M1 includes the public key b1, the signal value c1, and the server identity verification information γ2;

[0014] Calculate the public key w′ based on the b1 and the s0, and use the error correction mechanism to coordinate the w′ and the c1 to obtain the intermediate secret k1′;

[0015] Generate the server identity verification information γ2′ based on the k1′, the n1, and the preset third parameter set;

[0016] If the γ2′ is equal to the γ2, generate the session key sk based on the k1′, the n1, and the preset fourth parameter set c .

[0017] Preferably, it further includes:

[0018] When receiving the ID i and the password PW1′ sent by the client, calculate the password PW2′ = H0(ID i ||n1||PW1′), where the PW1′ is the password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user login, and PW1′ = H0(ID i ||n0||PW0), where the n0 is a random number pre-stored by the client when the user registers, and H0() is a preset hash function;

[0019] When the PW2′ is equal to the stored PW2, determine that the user login is successful, where the PW2 is the password pre-stored by the server when the user registers, and PW2 = H0(ID i ||n1||PW1), where the PW1 is the password obtained by the client when the user registers after obtaining the ID input by the useri and the password calculated after the private password PW0, and PW1 = H0(ID i ||n0||PW0).

[0020] Preferably, after sampling the private key s0, the noise e0, and the noise e1 respectively from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm, it further includes:

[0021] Generate a random number n2;

[0022] The first parameter set includes the b0, the P, and the n2;

[0023] Based on the k0, a preset first parameter set, and a preset encryption algorithm, encrypt the identity identifier ID corresponding to the user i to obtain the anonymized identity identifier AID i , including:

[0024] Calculate γ0 = H1(b0||P||n2||k0), where H1() is a preset hash function;

[0025] Calculate the anonymized identity identifier

[0026] The second parameter set includes the b0, n2, and PW2, and the PW2 is a password pre-stored and generated by the server during the user registration;

[0027] Based on n1, the ID i and a preset second parameter set to generate the user identity verification information γ1, including:

[0028] Calculate the user identity verification information γ1 = H1(ID i ||b0||n1||n2||PW2);

[0029] The M0 further includes n2, and the set M1 further includes the random number n3;

[0030] The third parameter set includes the ID i , the b1, the c1, the n3, and the PW2;

[0031] Based on the k1′, the n1, and a preset third parameter set to generate the server identity verification information γ2′, including:

[0032] Calculate γ2′ = H1(ID i ||b1||c1||n1||n3||k1′||PW2);

[0033] The fourth parameter set includes the IDi and ID s the b0, the b1, the n3, and the PW2, where the ID s is the identifier of the server obtained in advance;

[0034] Generate a session key sk based on the k1′, the n1, and a preset fourth parameter set c , including:

[0035] Calculate sk c = H1(ID i ||ID s ||b0||b1||k1′||n1||n3||PW2).

[0036] Preferably, the use of a preset sampling algorithm to sample respectively from the distributions on the polynomial ring in the MLWE problem to obtain a private key s0, a noise e0, and a noise e1 includes:

[0037] Use the central binomial distribution sampling algorithm to sample from to obtain a private key s0 and a noise e0, use the central binomial distribution sampling algorithm to sample from β η to obtain a noise e1, where the and the β η are both central binomial distributions with a parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix;

[0038] Based on the s0 and the e0, calculate the public key b0 using the MLWE problem, including:

[0039] Calculate the public key b0 = As0 + e0, where the A is a polynomial matrix sampled from the polynomial ring;

[0040] Based on the public key P generated by the server stored in advance, the s0, and the e1, calculate the public key v using the MLWE problem, including:

[0041] Calculate the public key v = P T s0 + e1, where P = A T s s + e s , the s s and the e s are both sampled by the server using the central binomial distribution sampling algorithm from the ;

[0042] Based on the b1 and the s0, calculate the public key w′, including:

[0043] Calculate the public key

[0044] Preferably, the error reconciliation mechanism includes a Perkert-style error reconciliation mechanism;

[0045] Coordinating the v by using a preset error reconciliation mechanism to obtain an intermediate secret k0 and a signal value c0 includes:

[0046] When the modulus q of the polynomial ring is even, calculate the intermediate secret and the signal value c0← <v> q,2 ;

[0047] When q is odd, calculate the doubled public key using the random doubling function, the modulo-rounding function, and the cross-rounding function respectively intermediate secret and signal value

[0048] Use the error reconciliation mechanism to reconcile w' and c1 to obtain the intermediate secret k1', including:

[0049] When q is even, use the reconciliation function to calculate the intermediate secret k1′ = Rec(w′, c1);

[0050] When q is odd, use the reconciliation function to calculate the intermediate secret k1′ = Rec(2w′, c1).

[0051] An authentication and key exchange method based on a smart card, applied to a server, the method includes:

[0052] Receive the set M0 sent by the smart card, where M0 includes the anonymized identity identifier AID i , public key b0, authentication user identity information γ1, and signal value c0;

[0053] Based on b0 and s s calculate the public key v', and use a preset error reconciliation mechanism to reconcile v' and c0 to obtain the intermediate secret k0', where s s is a private key sampled in advance from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm;

[0054] Based on k0', a preset first parameter set, and a preset decryption algorithm, decrypt the AID i to obtain the identity identifier ID i ';

[0055] Based on n1, the ID i ' and a preset second parameter set, generate the authentication user identity information γ1′, where n1 is a random number generated in advance when the user corresponding to the ID i ' is registered;

[0056] If γ1′ is equal to γ1, then use the sampling algorithm to sample from the distribution on the polynomial ring respectively to obtain the private key s1, noise e2, and noise e3;

[0057] Based on s1 and e2, calculate the public key b1 using the MLWE problem, and based on b0, s1, and e3, calculate the public key w using the MLWE problem;

[0058] Use the error coordination mechanism to coordinate the w to obtain an intermediate secret k1 and a signal value c1;

[0059] Generate verification server identity information γ2 based on the k1, the n1, and a preset third parameter set, and generate a session key sk based on the k1, the n1, and a preset fourth parameter set s ;

[0060] Send the set M1 to the smart card, where the M1 includes the b1, the c1, and the γ2.

[0061] Preferably, it further includes:

[0062] When receiving the registration request (ID i , PW1) sent by the user using the client, sample from to obtain the private key s s and noise e s , calculate the public key P = A T s s + e s , where the PW1 is the password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user registration, and PW1 = H0(ID i ||n0||PW0), the n0 is a random number generated by the client during the user registration, H0() is a preset hash function, the is a central binomial distribution with a parameter of η on the polynomial ring, the k is the dimension of the polynomial matrix, and the A is a polynomial matrix sampled from the polynomial ring;

[0063] Generate the random number n1, and calculate the password PW2 = H0(ID i ||n1||PW1);

[0064] Store the n1, the PW2, and the P in a preset smart card SC i for distributing the SC i to the user.

[0065] Preferably, the M0 further includes a random number n2;

[0066] The first parameter set includes the b0, P, and the n2, where the P is the public key generated in advance during the user registration;

[0067] Based on the k0′, a preset first parameter set, and a preset decryption algorithm, for the AID i Decrypt to obtain the identity identifier ID i ', including:

[0068] Calculate γ0′ = H1(b0||P||n2||k0′), where H1() is a preset hash function;

[0069] Calculate the identity identifier

[0070] The second parameter set includes the b0, the n2, and PW2, where PW2 is a password generated in advance during user registration;

[0071] Based on n1, the ID i ′ and a preset second parameter set to generate the user identity verification information γ1′, including:

[0072] Calculate the user identity verification information γ1′ = H1(ID i ′||b0||n1||n2||PW2);

[0073] After sampling from the distribution on the polynomial ring using the sampling algorithm to obtain the private key s1, the noise e2, and the noise e3, it further includes:

[0074] Generate a random number n3;

[0075] The third parameter set includes the ID i ′, the b1, the c1, the n3, and the PW2;

[0076] Based on the k1, the n1, and a preset third parameter set to generate the server identity verification information γ2, including:

[0077] Calculate the server identity verification information γ2 = H1(ID i ′||b1||c1||n1||n3||k1||PW2);

[0078] The fourth parameter set includes the ID i ′, ID s 、 the b0, the b1, the n3, and the PW2, where the ID s is its own identifier;

[0079] Based on the k1, the n1, and a preset fourth parameter set to generate the session key sk s , including:

[0080] Calculate the session key sk s = H1(ID i ′||ID s ||b0||b1||k1||n1||n3||PW2).

[0081] Preferably, based on the b0 and s s Calculating the public key v', includes:

[0082] Calculating the public key

[0083] Using the sampling algorithm to sample from the distribution on the polynomial ring respectively to obtain the private key s1, the noise e2 and the noise e3, includes:

[0084] Using the central binomial distribution sampling algorithm to sample from to obtain the private key s1 and the noise e2, using the central binomial distribution sampling algorithm to sample from β η to obtain the noise e3, where the and the β η are both central binomial distributions with a parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix;

[0085] Based on the s1 and the e2, using the MLWE problem to calculate the public key b1, includes:

[0086] Calculating the public key b1 = A T s1 + e2, where the A is a polynomial matrix sampled from the polynomial ring;

[0087] Based on the b0, the s1 and the e3, using the MLWE problem to calculate the public key w, includes:

[0088] Calculating the public key

[0089] Preferably, the error correction mechanism includes the Perkert - type error correction mechanism;

[0090] Coordinating the v' and the c0 using the preset error correction mechanism to obtain the intermediate secret k0', includes:

[0091] When the modulus q of the polynomial ring is even, using the coordination function to calculate the intermediate secret k0' = Rec(v′, c0);

[0092] When the q is odd, using the coordination function to calculate the intermediate secret k0' = Rec(2v′, c0);

[0093] Coordinating the w using the error correction mechanism to obtain the intermediate secret k1 and the signal value c1, includes:

[0094] When the q is even, using the floor function and the cross - floor function to calculate the intermediate secret respectively And signal value c1 ← <w> q,2 ;

[0095] When q is odd, use the random doubling function, the modulo rounding function, and the cross rounding function to calculate the doubled public key Intermediate secret and signal value

[0096] As can be seen from the above technical solution, the authentication and key exchange method based on a smart card provided by the embodiments of the present application selects MLWE as the underlying difficult problem to construct a two-way authentication scheme between the smart card and the server, realizing two-way authentication between the user and the server and negotiating a session key. Since the private key s0, the public key b0, and the public key v used by the smart card, the private key s1, the private key s s , the public key b1, and the public key w used by the server are all generated based on the MLWE problem, the current quantum algorithm cannot recover the private keys used by the smart card and the server through the public key. Similarly, it is even more impossible to recover the intermediate secrets k0, k0′, k1, and k1′ obtained by using the error correction mechanism and recover the ID i identical to ID i ′, and thus it is impossible to recover the user identity verification information γ1 and γ1′, the server identity verification information γ2 and γ2′, and the session key sk c and sk s . Therefore, the smart card and the server can resist the attack of quantum computers during the authentication and key negotiation process.

[0097] Furthermore, since the user identity verification information γ1 and γ1′, the server identity verification information γ2 and γ2′, and the session key sk c and sk s are all generated based on the random number n1, and n1 is a random number generated by the server during user registration. Only the smart card and the server know n1 and it will not be transmitted over the channel. An adversary cannot capture n1. Due to the randomness of the random number, it is even more impossible for the adversary to guess n1. Therefore, the difficulty of recovering information such as γ1 and γ1′, γ2 and γ2′, sk c and sk s is greatly increased, making the authentication and key exchange more secure. In addition, the smart card and the server do not directly transmit the user identity identifier, but transmit the encrypted and anonymized identity identifier of the user identity identifier, which can prevent attackers from confirming the user identity by listening to the channel, realizing anonymity for attackers, and making the authentication and key exchange more secure. BRIEF DESCRIPTION OF THE DRAWINGS

[0098] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided drawings.

[0099] Figure 1 Flowchart of an authentication and key exchange method based on a smart card disclosed in an embodiment of the present application;

[0100] Figure 2 Another flowchart of an authentication and key exchange method based on a smart card disclosed in an embodiment of the present application;

[0101] Figure 3 Schematic diagram of the specific process of an authentication and key exchange based on a smart card disclosed in an embodiment of the present application;

[0102] Figure 4 Schematic diagram of the structure of an authentication and key exchange device based on a smart card disclosed in an embodiment of the present application;

[0103] Figure 5 Another schematic diagram of the structure of an authentication and key exchange device based on a smart card disclosed in an embodiment of the present application;

[0104] Figure 6 Hardware structure block diagram of an authentication and key exchange device based on a smart card disclosed in an embodiment of the present application. Detailed implementation manners

[0105] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0106] To facilitate the description of the smart card-based authentication and key exchange method provided by the present application, some symbols and the definition of the MLWE problem involved in this article will be introduced first.

[0107] In the formula H(m||n), H() is a hash function, and "H(m||n)" represents performing a hash operation on m and n. For m←M, if M is a function, "m←M" means assigning the output value of the function M to m. If M is a polynomial ring or a distribution on a polynomial ring, then "m←M" means sampling m from M. is the exclusive OR operation, M T represents the transpose of M.

[0108] Definition of the MLWE problem: Polynomial ring Z q [x] is a polynomial modulo q, and f(x) is an irreducible polynomial x n +1, n is the dimension of the vector, x is the variable of the polynomial, and a polynomial matrix is randomly selected Secret key Noise is a Gaussian distribution over, and calculate the public key The decision-type MLWE hard problem can be regarded as distinguishing the following two distributions:

[0109] Distribution (A, B), where a polynomial matrix is randomly selected

[0110] Distribution (A, B), where a polynomial matrix is randomly selected Sampling B = As + e;

[0111] The search-type MLWE problem is to solve s from the given distribution (A, B).

[0112] This application provides an authentication and key exchange method based on a smart card, which can be applicable to various smart cards, such as induction cards, contact cards, dual-interface cards, etc.

[0113] The embodiments of this application provide an authentication and key exchange scheme based on a smart card. Next, through the attached Figure 1 From the perspective of the smart card, the authentication and key exchange method based on the smart card of this application is described. As Figure 1 shown, the method may include:

[0114] When it is detected that the user logs in successfully, the following step S100 is executed.

[0115] Step S100: Use a preset sampling algorithm to sample from the distributions on the polynomial ring in the MLWE problem respectively, to obtain the private key s0, the noise e0, and the noise e1.

[0116] Specifically, the embodiments of the present application find that when the user needs the server to provide corresponding services after successfully logging in to the smart card, a two-way authentication between the user and the server can be established based on the smart card to ensure the legality of the identities of both parties and negotiate a session key. Therefore, when the smart card detects that the user has successfully logged in, it can first obtain the relevant private key and noise, so as to generate relevant information based on the obtained private key and noise to complete the two-way authentication with the server and negotiate a session key. Considering that an adversary cannot recover the private key and noise sampled from the distribution on the polynomial ring in the MLWE problem, a preset sampling algorithm is used to sample from the distribution on the polynomial ring in the MLWE problem respectively to obtain the private key s0, the noise e0, and the noise e1.

[0117] Step S110: Calculate the public key b0 using the MLWE problem based on the s0 and the e0, and calculate the public key v using the MLWE problem based on the public key P generated by the server stored in advance, the s0, and the e1.

[0118] Specifically, the public key b0 can be calculated by using the calculation method in the MLWE problem based on the generated private key s0 and the noise e0, and the public key v can be calculated by using the calculation method in the MLWE problem based on the public key P generated by the server stored in advance, the generated private key s0, and the noise e1. The purpose of introducing noise when calculating the public key is to improve security. Errors play a key role in the hardness of the MLWE problem under the quantum computing model. The public key v can be used to calculate the intermediate secret and the signal value. The public key b0 and the signal value are used to enable the server to recover the intermediate secret calculated based on the public key v, so as to complete the calculation of relevant information in the authentication and key exchange process. And since both the public key b0 and the public key v are calculated using the MLWE problem, an adversary cannot recover the public key b0 and the public key v without the smart card providing the public key b0 and the public key v. And even if the public key b0 sent by the smart card to the server in the subsequent steps is captured by the adversary, the adversary cannot recover the private key s0 based on the public key b0.

[0119] Step S120: Coordinate the v using a preset error correction mechanism to obtain the intermediate secret k0 and the signal value c0.

[0120] Specifically, in the embodiments of the present application, it is found that since noise e1 is introduced when calculating the public key v, this not only makes it impossible for the adversary to recover the public key v, but also makes it impossible for the server to recover the public key v. The existence of the noise only allows the server to recover a value similar to the public key v, resulting in the inability of the smart card and the server to communicate normally. To ensure normal communication between the smart card and the server, a preset error correction mechanism can be used to correct the public key v to obtain the intermediate secret k0 and the signal value c0, and relevant authentication information and session keys are calculated based on the intermediate secret k0. In this way, the server can also use this error correction mechanism to recover the intermediate secret k0' that is consistent with the intermediate secret k0, ensuring normal communication between the two parties.

[0121] Step S130, encrypt the identity identifier ID corresponding to the user based on the k0, a preset first parameter set, and a preset encryption algorithm i to obtain the anonymized identity identifier AID i .

[0122] Specifically, in the embodiments of the present application, it is found that when a user needs the server to provide services, the server needs to confirm the identity of the user. If the identity identifier of the user is directly sent to the server, user anonymity cannot be achieved. Therefore, in the embodiments of the present application, the identity identifier ID corresponding to the user is encrypted based on the generated intermediate secret k0, a preset first parameter set, and a preset encryption algorithm i to obtain the anonymized identity identifier AID i , so as to send the anonymized identity identifier AID i to the server. The server decrypts the anonymized identity identifier AID i to confirm the identity of the user. In this way, the identity identifier ID corresponding to the user is not directly transmitted i , and user anonymity can be achieved. Moreover, since the anonymized identity identifier AID i is generated based on the intermediate secret k0, the adversary cannot crack the intermediate secret k0, and thus cannot crack the identity identifier ID i from the anonymized identity identifier AID i . Only the server can recover k0' that is consistent with the intermediate secret k0, and thus calculate the identity identifier ID i ' based on k0', protecting the security of the user's identity information. In addition, the anonymized identity identifier AID i is also generated based on a preset first parameter set. The first parameter set may include some other parameters, thereby improving the security and integrity of the generated anonymized identity identifier AID i .

[0123] Step S140, based on n1 and the ID i Generate the user identity verification information γ1 based on the random number n1, the identity identifier ID, and the preset second parameter set.

[0124] Wherein, the n1 is a random number pre-stored by the server when the user registers.

[0125] Specifically, the embodiments of the present application find that if two-way identity authentication with the server is to be completed, first, information for verifying the user's identity needs to be generated. The server also calculates the information for verifying the user's identity based on relevant information and compares it with the information for verifying the user's identity calculated by the smart card. If they are equal, it means the user's identity is legal, and only then can the authentication of the server's identity and the calculation of the session key be performed. Therefore, the embodiments of the present application generate the user identity verification information γ1 based on the random number n1, the identity identifier ID i and the preset second parameter set. The user identity verification information γ1 is the information for verifying the user's identity. Since the user's identity identifier ID i is only known to the smart card and is not transmitted on the transmission channel, only the server can recover the identity identifier ID i identical to the identity identifier ID i ′. Therefore, the verification user identity information γ1 can be generated based on ID i . Further, since the random number n1 is a random number pre-stored by the server when the user registers and is only known to the smart card and the server, and the adversary cannot guess the random number n1, it can be used to generate the verification user identity information γ1. When the server finds the corresponding random number n1 according to the calculated identity identifier ID i ′, if the random number n1 found by the server is inconsistent with the random number n1 used by the smart card to calculate γ1, then the verification user identity information γ1′ calculated by the server is also inconsistent with the received verification user identity information γ1, indicating that the user identity authentication fails. In addition, the verification user identity information γ1 is also generated based on the preset second parameter set, and the second parameter set may include some other parameters to improve the security and integrity of the generated verification user identity information γ1.

[0126] Step S150: Send the set M0 to the server.

[0127] Wherein, the M0 includes the AID i , the b0, the γ1, and the c0.

[0128] Specifically, after completing the calculations of the above steps, send the calculated anonymized identity identifier AID i , the public key b0, the user identity verification information γ1, and the signal value c0 to the server so that the server can perform relevant authentication and session key calculation work based on the received information.

[0129] Step S160: Receive the set M1 sent by the server.

[0130] The M1 includes the public key b1, the signal value c1, and the verification server identity information γ2.

[0131] Specifically, when receiving the set M1 sent by the server, it indicates that the server has determined that the user identity is legal. At this time, it is also necessary to verify the legality of the server identity based on the public key b1, the signal value c1, and the verification server identity information γ2 in the set M1.

[0132] Step S170: Calculate the public key w′ based on the b1 and the s0, and use the error correction mechanism to correct the w′ and the c1 to obtain the intermediate secret k1′.

[0133] Specifically, if it is necessary to verify the legality of the server identity, it is necessary to calculate the verification server identity information γ2′, and determine whether the server identity is legal by comparing the calculated verification server identity information γ2′ with the received verification server identity information γ2. Since γ2 is generated based on the intermediate secret k1, it is first necessary to calculate the intermediate secret k1′. The public key w′ can be calculated based on the received b1 and the self-generated private key s0, and then the error correction mechanism is used to correct the w′ and the received signal value c1 to obtain the intermediate secret k1′. Due to the participation of the error correction mechanism, when the smart card and the server honestly calculate and transmit relevant information, the calculated intermediate secret k1′ can be the same as k1.

[0134] Step S180: Generate the verification server identity information γ2′ based on the k1′, the n1, and the preset third parameter set.

[0135] Specifically, since the server generates γ2 based on k1, the random number n1 generated during the user registration, and the preset third parameter set, it is necessary to generate the verification server identity information γ2′ based on the above calculated k1′, the randomly generated number n1 stored in advance by the server during the user registration, and the preset third parameter set at this time, so as to verify the server identity information.

[0136] If the γ2′ is equal to the γ2, execute the following step S190.

[0137] Step S190: Generate the session key sk based on the k1′, the n1, and the preset fourth parameter set c .

[0138] Specifically, if the calculated verification server identity information γ2′ is equal to the received verification server identity information γ2, it indicates that the server identity is legal. The mutual authentication between the user and the server established based on the smart card passes, and both the user and server identities are legal. At this time, the session key sk can be negotiated. c , To improve the security and integrity of the negotiated session key sk c , the session key sk can be generated based on k1′, n1, and a preset fourth parameter set. c , If the mutual authentication with the server passes, the session key sk calculated by the server s and sk c are consistent, and subsequent message transmission can be carried out using the session key.

[0139] In the authentication and key exchange method based on a smart card provided by the embodiments of the present application, since the private key s0, public key b0, public key v, etc. used by the smart card are all generated based on the MLWE problem, the current quantum algorithm cannot recover the private key used by the smart card through the public key. Similarly, it is even more impossible to recover the intermediate secrets k0 and k1′ obtained using the error correction mechanism and recover the ID i identical to ID i ′, and thus it is impossible to recover the verification user identity information γ1, verification server identity information γ2′, and the negotiated session key sk c . Therefore, the smart card and the server can resist the attack of quantum computers during the authentication and key negotiation process.

[0140] Furthermore, since the verification user identity information γ1, verification server identity information γ2′, and session key sk c are all generated based on the random number n1, and n1 is a random number generated by the server during user registration. Only the smart card and the server know n1 and it will not be transmitted over the channel. An adversary cannot capture n1. Due to the randomness of the random number, it is even more impossible for the adversary to guess n1. Furthermore, this greatly increases the difficulty of recovering information such as γ1, γ2′, and sk c , making the authentication and key exchange more secure. Also, the smart card and the server do not directly transmit the user identity identifier, but instead transmit the anonymously encrypted user identity identifier, which can prevent attackers from confirming the user identity by eavesdropping on the channel, achieving anonymity for the attacker and making the authentication and key exchange more secure.

[0141] In some embodiments of the present application, the process of a user logging in to the smart card is introduced. When a user wants to log in to the smart card, the user will first enter the identity identifier ID i and the private password PW0 in the interface provided by the client. The client will calculate the password PW1′ = H0(ID i ||n0||PW0), and send the identity ID i and the password PW1' to the smart card. When the smart card receives the identity ID i and the password PW1' sent by the client, it means that the user is requesting to log in. Since the password PW2 generated by the server during the user's registration is stored, and PW2 = H0(ID i ||n1||PW1), so the password PW2' = H0(ID i ||n1||PW1') can be calculated. If PW2' is not equal to the stored PW2, it means that the user has entered the private password incorrectly, and the user cannot log in successfully at this time. If they are equal, it means that the user is legal and the user can log in successfully.

[0142] Wherein, the n0 is a random number generated during the user's registration and pre-stored by the client, H0() is a preset hash function, and the PW1 is the password calculated by the client after obtaining the ID i and the PW0 during the user's registration, and PW1 = H0(ID i ||n0||PW0).

[0143] In the embodiment of the present application, the user is authenticated during the user's login to the smart card. Only when the authentication is successful can the user log in successfully. The user can log in successfully only by entering the correct private password PW0, which improves the security. And the password PW2 is stored in the smart card, and the user's identity is verified by verifying whether PW2' is equal to PW2, rather than directly verifying whether the PW0 sent by the client is equal to the stored PW0 by storing the private password PW0. Even if an adversary obtains the smart card, they cannot obtain the user's private password PW0, protecting the security of user data.

[0144] Optionally, the embodiment of the present application finds that in order to prevent replay attacks, after using a preset sampling algorithm to sample from the distribution on the polynomial ring in the MLWE problem to obtain the private key s0, the noise e0, and the noise e1 in the above step S100, it may further include:

[0145] Generate a random number n2.

[0146] Based on this, the above first parameter set may include the b0, the P, and the n2.

[0147] The above step S130 encrypts the identity ID corresponding to the user i using the k0, a preset first parameter set, and a preset encryption algorithm to obtain the anonymized identity AID i The process may include:

[0148] Calculate γ0 = H1(b0||P||n2||k0), where H1() is a preset hash function.

[0149] Calculate the anonymized identity identifier

[0150] Specifically, including the random number n2 in the first parameter set can make the γ0 and the anonymized identity identifier AID obtained each time i both inconsistent, which can prevent replay attacks. Further, it can also prevent desynchronization attacks. Including the public key b0 and the public key P can provide a certain degree of integrity protection for the calculated anonymized identity identifier AID i Since γ0 is calculated through a hash function, according to the characteristics of the hash function, only the number that is exactly the same as b0, P, n2, and k0 can be used as the input of the above hash function to obtain a value exactly the same as γ0, and b0, P, n2, and k0 cannot be recovered from γ0, which can greatly increase the security.

[0151] The above second parameter set includes the b0, n2, and PW2, where PW2 is a password pre-stored and generated by the server during the user registration.

[0152] The above step 140 generates the process of verifying the user identity information γ1 based on n1, the ID i and a preset second parameter set, which may include:

[0153] Calculate the verification user identity information γ1 = H1(ID i ||b0||n1||n2||PW2).

[0154] Specifically, including n2 in the second parameter set can make the γ1 calculated each time inconsistent, which can prevent replay attacks. Including b0 can provide a certain degree of integrity protection for the calculated γ1. Since PW2 is a password pre-stored and generated by the server during the user registration and is known only to the smart card and the server, the second parameter set also includes PW2 for verifying the user's identity. Similarly, calculating γ1 through a hash function, based on the characteristics of the hash function, greatly increases the security.

[0155] Based on this, in order for the server to calculate γ0′ and γ1′, n2 also needs to be sent to the server, so the above M0 may also include n2.

[0156] Further, in order to prevent replay attacks, the set M1 sent by the server may also include a random number n3.

[0157] Based on this, the above third parameter set includes the ID i , the b1, the c1, the n3, and the PW2.

[0158] The process of generating the verification server identity information γ2′ in the above step S180 based on the k1′, the n1, and a preset third parameter set may include:

[0159] Calculate γ2′ = H1(ID i ||b1||c1||n1||n3||k1′||PW2).

[0160] Specifically, the received γ2 is obtained by the server calculating H1(ID i ′||b1||c1||n1||n3||k1||PW2), so the third parameter set includes ID i , b1, c1, n3, and PW2, and calculate γ2′ = H1(ID i ||b1||c1||n1||n3||k1′||PW2). Including n3 can make each calculated γ2′ inconsistent, which can prevent replay attacks. Similarly, calculating γ2′ through a hash function greatly increases the security.

[0161] The above fourth parameter set includes the ID i , ID s , the b0, the b1, the n3, and the PW2, where the ID s is the identifier of the server obtained in advance.

[0162] The process of generating the session key sk c in the above step S190 based on the k1′, the n1, and a preset fourth parameter set may include:

[0163] Calculate sk c = H1(ID i ||ID s ||b0||b1||k1′||n1||n3||PW2).

[0164] Specifically, the fourth parameter set includes the ID i , ID s , the b0, and the b1, which can play a role in integrity protection. Including n3 can make each calculated sk c inconsistent, which can prevent replay attacks. Including PW2 can improve security because only the smart card and the server know PW2. Similarly, calculating sk c through a hash function greatly increases the security.

[0165] In the embodiment of the present application, since a random number n2 is generated after detecting that the user logs in successfully, and the random number n3 sent by the server is received, and when calculating the anonymized identity identifier AID i and verifying the user identity information γ1, the random number n2 is added to both. When calculating and verifying the server identity information γ2' and the session key sk c , the random number n3 is added to both. This makes the above information calculated by the user each time they log in inconsistent, which can effectively resist replay attacks. The AID i calculated each time is inconsistent, which can also prevent desynchronization attacks, and the above information is calculated using a hash function, greatly improving security.

[0166] The embodiment of the present application provides an authentication and key exchange scheme based on a smart card. Next, through the attached Figure 2 from the perspective of the server, the authentication and key exchange method based on the smart card of the present application will be described. As Figure 2 shown, the method may include:

[0167] Step S200: Receive the set M0 sent by the smart card.

[0168] Wherein, the M0 includes the anonymized identity identifier AID i , the public key b0, the user identity verification information γ1, and the signal value c0.

[0169] Step S210: Calculate the public key v' based on the b0 and s s , and use a preset error correction mechanism to correct the v' and the c0 to obtain the intermediate secret k0'.

[0170] Wherein, the s s is a private key sampled in advance from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm.

[0171] Specifically, if it is necessary to verify the legality of the user identity, it is necessary to calculate the user identity verification information γ1'. By comparing γ1' with γ1, it can be determined whether the user identity is legal. Since γ1 is generated based on the intermediate secret k0, it is first necessary to calculate the intermediate secret k0'. The public key v s can be calculated based on the received b0 and the self-generated private key s ′ , and then the preset error correction mechanism is used to correct v' and the received signal value c0, and the intermediate secret k0' can be obtained. Due to the participation of the error correction mechanism, when the smart card and the server honestly calculate and transmit relevant information, the calculated intermediate secret k0' can be the same as k0. Here, the error correction mechanism is the same as the error correction mechanism used by the smart card.

[0172] Step S220: Decrypt the AID based on the k0′, the preset first parameter set, and the preset decryption algorithm i to obtain the identity identifier ID i '.

[0173] Specifically, before authentication, the server first needs to confirm the user's identity. From the calculation method of the anonymized identity identifier AID i , it can be known that the AID i can be decrypted based on the k0′, the preset first parameter set, and the preset decryption algorithm i to obtain the identity identifier ID i ′. The user's identity can be confirmed according to ID

[0174] ′, where the decryption algorithm corresponds to the encryption algorithm of the smart card.

[0174] Step S230: Generate the user identity verification information γ1′ based on n1, the ID i ′, and the preset second parameter set.

[0175] Among them, the n1 is a random number generated in advance when the user corresponding to the ID i ' is registered.

[0176] Specifically, since the user identity verification information γ1 is generated by the smart card based on the pre-stored n1 generated by the server when the user is registered, the ID i , and the preset second parameter set, it is necessary to generate the user identity verification information γ1′ based on the random number n1 generated in advance when the user corresponding to the ID i ′ is registered, the ID i ′, and the preset second parameter set.

[0177] Optionally, after the user registration is completed, the mapping relationship between the user's corresponding identity identifier and the generated random number can be stored, so that the n1 corresponding to the ID i ′ can be found according to the mapping relationship.

[0178] If the γ1′ is equal to the γ1, then execute the following step S240.

[0179] Step S240: Use the sampling algorithm to sample from the distribution on the polynomial ring respectively to obtain the private key s1, the noise e2, and the noise e3.

[0180] Specifically, if γ1′ is equal to γ1, it indicates that the user authentication is passed. At this time, it is necessary to generate the verification server identity information. First, relevant private keys and noises can be obtained to generate relevant information based on the obtained private keys and noises. Considering that the adversary cannot recover the private keys and noises sampled from the distribution on the polynomial ring in the MLWE problem, the preset sampling algorithm is used to sample from the distribution on the polynomial ring in the MLWE problem respectively, and the private key s1, the noise e2, and the noise e3 are obtained.

[0181] Step S250: Calculate the public key b1 using the MLWE problem based on the s1 and the e2, and calculate the public key w using the MLWE problem based on the b0, the s1, and the e3.

[0182] Specifically, the public key w can be used to calculate the intermediate secret and the signal value. The public key b1 and the signal value can be used to enable the smart card to recover the intermediate secret calculated according to the public key w, so as to complete the calculation of relevant information in the authentication and key exchange process. And since both the public key b1 and the public key w are calculated using the MLWE problem, the adversary cannot recover the public key b1 and the public key w without the server providing the public key b1 and the public key w. And even if the public key b1 sent by the service to the smart card reader is captured by the adversary later, the adversary cannot recover the private key s1 based on the public key b1.

[0183] Step S260: Coordinate the w using the error correction mechanism to obtain the intermediate secret k1 and the signal value c1.

[0184] Specifically, the w is coordinated using the error correction mechanism to obtain the intermediate secret k1 and the signal value c1. The relevant authentication information and the session key are calculated based on the intermediate secret k1. In this way, the smart card can also use this error correction mechanism to recover k1′ that is consistent with the intermediate secret k1, ensuring normal communication between the two.

[0185] Step S270: Generate the verification server identity information γ2 based on the k1, the n1, and the preset third parameter set, and generate the session key sk based on the k1, the n1, and the preset fourth parameter set. s 。

[0186] Specifically, since only a legitimate smart card can recover k1' that is consistent with k1, the verification server identity information γ2 can be generated based on k1. Since the random number n1 is a random number generated in advance during the user registration, only the smart card and the server know it, and an adversary cannot guess the random number n1, so the verification server identity information γ2 can be generated based on n1. In addition, γ2 is also generated based on a preset third parameter set, which may include some other parameters to improve the security and integrity of the generated γ2. To improve the security and integrity of the negotiated session key sk s the security and integrity of can be generated based on k1, n1, and a preset fourth parameter set s the session key sk. If the mutual authentication with the smart card passes, the session key sk calculated by the smart card c is consistent with sk s and subsequent message transmission can be carried out using the session key.

[0187] Step S280: Send the set M1 to the smart card.

[0188] Wherein, the M1 includes the b1, the c1, and the γ2.

[0189] Specifically, after completing the calculations of the above steps, the calculated b1, c1, and γ2 are sent to the smart card so that the smart card can perform relevant authentication and session key calculation work based on the received information.

[0190] In the authentication and key exchange method based on a smart card provided in the embodiments of the present application, since the private key s1, the private key s s , the public key b1, the public key w, etc. used by the server are all generated based on the MLWE problem, it makes it impossible for current quantum algorithms to recover the private key used by the server through the public key. Similarly, it is even more impossible to recover the intermediate secrets k0' and k1 obtained using the wrong reconciliation mechanism and recover ID i identical to ID i ', and further impossible to recover the verification user identity information γ1', the verification server identity information γ2, and the negotiated session key sk s , so that the smart card and the server can resist the attack of quantum computers during the process of authentication and key negotiation.

[0191] Furthermore, since the verification user identity information γ1', the verification server identity information γ2, and the session key sk s They are all generated based on the random number n1, where n1 is a random number generated by the server during user registration. Only the smart card and the server know n1, and it will not be transmitted over the channel. An adversary cannot capture n1. Due to the randomness of the random number, the adversary is even less likely to guess n1, thereby making it much more difficult to recover information such as γ1′, γ2, and sk s This greatly increases the difficulty of obtaining information such as γ1′, γ2, and sk, making the authentication and key exchange more secure. In addition, the smart card and the server do not directly transmit the user identity identifier. Instead, they transmit the encrypted and anonymized user identity identifier, which can prevent attackers from confirming the user identity by eavesdropping on the channel, achieving anonymity for attackers, and making the authentication and key exchange more secure.

[0192] In some embodiments of the present application, the process of a user requesting registration from the server is introduced. When a user wants to register with the server, the user will first enter the identity identifier ID i and the private password PW0 in the interface provided by the client. The client will respond to the user's operation, generate a random number n0, and calculate the password PW1 = H0(ID i ||n0||PW0), save the random number n0, and send a registration request (ID i , PW1) to the server. Therefore, when the server receives the registration request (ID i , PW1) sent by the user using the client, it samples from using the above sampling algorithm to obtain the private key s s and the noise e s , calculates the public key P = A T s s +e s , where H0() is a preset hash function, is a centered binomial distribution with parameter η on the above polynomial ring, k is the dimension of the polynomial matrix, A is a polynomial matrix sampled from the polynomial ring, generates a random number n1, and calculates the password PW2 = H0(ID i ||n1||PW1), and stores the n1, PW2, and P in a preset smart card SC i for distributing the SC i to the user.

[0193] In the embodiments of the present application, since the private password PW0 entered by the user during registration is not directly sent to the server by the client, but PW1 is sent to the server, it protects the user's privacy, prevents an adversary from obtaining the user's private password, and stores the calculated n1, PW2, and P in the smart card, facilitating the relevant calculations when the user logs in to the smart card and the relevant calculations in the subsequent authentication and key exchange process.

[0194] Optionally, to prevent replay attacks, the above set M0 sent by the smart card may further include a random number n2.

[0195] Based on this, the above first parameter set includes the b0, P, and the n2, where the P is a public key generated in advance during the user registration.

[0196] The above step S220 decrypts the AID i to obtain the identity ID i ′ based on the k0′, a preset first parameter set, and a preset decryption algorithm, and may include:

[0197] Calculate γ0′ = H1(b0||P||n2||k0′), where H1() is a preset hash function.

[0198] Calculate the identity

[0199] Specifically, from the process of calculating the AID i obtained by the above smart card, it can be seen that first, γ0′ = H1(b0||P||n2||k0′) needs to be calculated, and then The inclusion of the random number n2 in the first parameter set can make each calculated γ0′ inconsistent, which can prevent replay attacks. Calculating γ0′ through the hash function greatly increases the security.

[0200] The second parameter set includes the b0, the n2, and PW2, where the PW2 is a password generated in advance during the user registration.

[0201] The above step S230 generates the verification user identity information γ1′ based on n1, the ID i ′, and a preset second parameter set, and may include:

[0202] Calculate the verification user identity information γ1′ = H1(ID i ′||b0||n1||n2||PW2).

[0203] Specifically, since the received γ1 is obtained by the smart card calculating H1(ID i ||b0||n1||n2||PW2), the second parameter set includes the b0, the n2, and PW2, and calculates γ1′ = H1(ID i ′||b0||n1||n2||PW2). The inclusion of n2 can make each calculated γ1′ inconsistent, which can prevent replay attacks. Similarly, calculating γ1′ through the hash function greatly increases the security.

[0204] To prevent replay attacks, after performing the above step S240 of sampling the private key s1, the noise e2, and the noise e3 from the distribution on the polynomial ring using the sampling algorithm, the following steps may further be included:

[0205] Generate a random number n3.

[0206] Based on this, the third parameter set includes the ID i ′, the b1, the c1, the n3, and the PW2.

[0207] The process of generating the verification server identity information γ2 based on the k1, the n1, and the preset third parameter set in the above step S270 may include:

[0208] Calculate the verification server identity information γ2 = H1(ID i ′||b1||c1||n1||n3||k1||PW2).

[0209] Specifically, including n3 in the third parameter set can make each calculated γ2 inconsistent, preventing replay attacks. Including the ID i ′, b1, and c1 can provide a certain degree of integrity protection. Including PW2 can be used for the smart card to verify the server identity because, like n1, only the smart card and the server know PW2, and calculating γ2 through the hash function can greatly enhance the security.

[0210] The fourth parameter set includes the ID i ′, ID s , the b0, the b1, the n3, and the PW2, where the ID s is its own identifier.

[0211] The process of generating the session key sk s based on the k1, the n1, and the preset fourth parameter set in the above step S270 may include:

[0212] Calculate the session key sk s = H1(ID i ′||ID s ||b0||b1||k1||n1||n3||PW2).

[0213] Specifically, the fourth parameter set including the ID i , ID s , the b0, and the b1 can provide integrity protection. Including n3 can make each calculated sk s All are inconsistent, which can prevent replay attacks. Including PW2 can enhance security because only the smart card and the server know PW2. Similarly, the session key sk is calculated through a hash function, s , greatly increasing the security.

[0214] In the embodiments of the present application, since the random number n2 sent by the smart card is received, and the random number n3 is generated after the user authentication is passed, and when calculating the identity identifier ID i ′ and verifying the user identity information γ1′, the random number n2 is added in both cases. When calculating the verification server identity information γ2 and the session key sk s , the random number n3 is added in both cases. This makes the above information calculated each time the user logs in inconsistent, which can effectively resist replay attacks. The calculated ID i ′ are all inconsistent, which can also prevent desynchronization attacks, and using a hash function to calculate the above information greatly improves the security.

[0215] Optionally, the sampling algorithm in the above embodiments may be a central binomial distribution sampling algorithm.

[0216] Based on this, the process of using the preset sampling algorithm in the above step S100 to sample from the distributions on the polynomial ring in the MLWE problem to obtain the private key s0, the noise e0, and the noise e1 may include:

[0217] Using the central binomial distribution sampling algorithm to sample from to obtain the private key s0 and the noise e0, and using the central binomial distribution sampling algorithm to sample from β η to obtain the noise e1.

[0218] Among them, the and the β η are both central binomial distributions with a parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix.

[0219] Specifically, using the central binomial distribution sampling algorithm to sample from , the dimensions of the obtained private key s0 and the noise e0 are both k rows and 1 column. Sampling from β η , the dimension of the obtained noise e1 is 1 row and 1 column.

[0220] The process of the above step S110 calculating the public key b0 based on the s0 and the e0 using the MLWE problem, and calculating the public key v based on the public key P generated by the server stored in advance, the s0, and the e1 using the MLWE problem may include:

[0221] Calculate the public key b0 = As0 + e0, where the A is a polynomial matrix sampled from the polynomial ring.

[0222] Specifically, from the MLWE problem, it can be known that the polynomial matrix A that can be directly sampled from the polynomial ring is used to calculate b0 based on A, s0, and e0. The dimension of A is k rows by k columns, and the dimensions of the private key s0 and the noise e0 are both k rows by 1 column. Therefore, b0 = As0 + e0 can be directly calculated.

[0223] Calculate the public key v = P T s0 + e1, where P = A T s s + e s , and the s s and the e s are both sampled by the server using the central binomial distribution sampling algorithm from the .

[0224] Specifically, since P = A T s s + e s , the dimension of P is k rows by 1 column, while the dimension of the private key s0 is k rows by 1 column, and the dimension of the noise e1 is 1 row by 1 column. Therefore, when calculating the public key v based on P, s0, and e1, v = P T s0 + e1 needs to be calculated.

[0225] The process of calculating the public key w' based on b1 and s0 in the above step S120 may include:

[0226] Calculate the public key

[0227] Specifically, since the server will calculate b1 = A T s1 + e2, the dimension of b1 is k rows by 1 column, and the dimension of the private key s0 is also k rows by 1 column. Therefore, when calculating the public key

[0228] The process of calculating the public key v' based on b0 and s s in the above step S210 may include:

[0229] Calculate the public key

[0230] Specifically, since b0 = As0 + e0, the dimension of b0 is k rows by 1 column, and the dimension of s s is also k rows by 1 column. Therefore,

[0231] The process of using the sampling algorithm to sample from the distribution on the polynomial ring in the above step S240 to obtain the private key s1, the noise e2, and the noise e3 may include:

[0232] Sampling from using the central binomial distribution sampling algorithm to obtain the private key s1 and the noise e2, and sampling from β η using the central binomial distribution sampling algorithm to obtain the noise e3.

[0233] Wherein, the and the β η are both central binomial distributions with a parameter of η on the polynomial ring, and the k is the dimension of the polynomial matrix.

[0234] The above steps S250, the process of calculating the public key b1 based on the s1 and the e2 using the MLWE problem, and calculating the public key w based on the b0, the s1 and the e3 using the MLWE problem may include:

[0235] Calculating the public key b1 = A T s1 + e2, where the A is a polynomial matrix sampled from the polynomial ring.

[0236] Specifically, from the MLWE problem, it can be known that a polynomial matrix A that can be directly sampled from the polynomial ring can be used to calculate b1 based on A, s1 and e2. Since the dimension of A is k rows and k columns, and the dimensions of the private key s1 and the noise e2 are both k rows and 1 column, so b1 = A T s1 + e2 can be calculated.

[0237] Calculating the public key

[0238] Specifically, since the dimension of b0 is k rows and 1 column, the dimension of the private key s1 is k rows and 1 column, and the dimension of the noise e3 is 1 row and 1 column, so the public key

[0239] The embodiment of the present application uses the central binomial distribution sampling algorithm for sampling. The implementation process of sampling is simple, and it does not require the introduction of large tables and high-precision calculations. The sampling efficiency is high, and the dimensions are considered when calculating the public key, so calculation errors will not occur.

[0240] Optionally, the above error reconciliation mechanism may include the Perkert-style error reconciliation mechanism, and the definitions of related functions in the Perkert-style error reconciliation mechanism are as follows:

[0241] Rounding function:

[0242] Modulo rounding function:

[0243] Reconciliation function:

[0244] Random doubling function: Where is a random term, the probability of being 0 is 0.5, the probabilities of being -1 and 1 are 0.5.

[0245] Based on this, the process of coordinating the v by using the preset error reconciliation mechanism in step S170 above to obtain the intermediate secret k0 and the signal value c0 may include:

[0246] When the modulus q of the polynomial ring is even, calculate the intermediate secret and the signal value c0← <v> q,2 ;

[0247] Specifically, according to the Perkert error reconciliation mechanism, when q is an even number, the modulo rounding function in the Perkert error reconciliation mechanism can be directly used to calculate the intermediate secret Calculate the signal value c0← using the cross-rounding function <v> q,2 。

[0248] When q is odd, use the random doubling function, the modulo rounding function, and the cross rounding function to calculate the doubled public key intermediate secret and signal value

[0249] Specifically, according to the Perkert-style error reconciliation mechanism, when q is odd, first use the random doubling function to calculate the doubled public key Then use the modulo rounding function and the cross rounding function to calculate the intermediate secret and signal value

[0250] The process of using the error reconciliation mechanism in step S170 to reconcile w′ and c1 to obtain the intermediate secret k1′ may include:

[0251] When q is even, use the reconciliation function to calculate the intermediate secret k1′ = Rec(w′, c1).

[0252] Specifically, according to the Perkert-style error reconciliation mechanism, when q is even, the reconciliation function can be used to calculate the intermediate secret k1′ = Rec(w′, c1), so that the intermediate secret k1′ is consistent with the intermediate secret k1 calculated by the server.

[0253] When q is odd, use the reconciliation function to calculate the intermediate secret k1′ = Rec(2w′, c1).

[0254] Specifically, according to the Perkert-style error reconciliation mechanism, when q is odd, the reconciliation function can be used to calculate the intermediate secret k1′ = Rec(2w′, c1), so that the intermediate secret k1′ is consistent with the intermediate secret k1 calculated by the server.

[0255] The process of using the preset error reconciliation mechanism in step S210 to reconcile v′ and c0 to obtain the intermediate secret k0′ may include:

[0256] When q is even, use the reconciliation function to calculate the intermediate secret k0′ = Rec(v′, c0).

[0257] Specifically, according to the Perkert-style error reconciliation mechanism, when q is even, the reconciliation function can be used to calculate the intermediate secret k0′ = Rec(v′, c0), so that the intermediate secret k0′ is consistent with the intermediate secret k0 calculated by the smart card.

[0258] When q is odd, use the reconciliation function to calculate the intermediate secret k0′ = Rec(2v′, c0).

[0259] Specifically, according to the Perkert error reconciliation mechanism, when q is odd, the reconciliation function can be used to calculate the intermediate secret k0′ = Rec(2v′, c0), so that the intermediate secret k0′ is consistent with the intermediate secret k0 calculated by the smart card.

[0260] The process of using the error reconciliation mechanism to reconcile w in step S260 to obtain the intermediate secret k1 and the signal value c1 may include:

[0261] When q is even, use the floor function and the cross-rounding function to calculate the intermediate secret and the signal value

[0262] Specifically, according to the Perkert error reconciliation mechanism, when q is even, the floor function in the Perkert error reconciliation mechanism can be directly used to calculate the intermediate secret Use the cross-rounding function to calculate the signal value c1 ← <w> q,2 。

[0263] When q is odd, the doubled public key is calculated using the random doubling function, the modulo rounding function, and the cross-rounding function respectively intermediate secret and signal value

[0264] Specifically, according to the Perkert-style error reconciliation mechanism, when q is odd, it is first necessary to calculate the doubled public key using the random doubling function and then calculate the intermediate secret using the modulo rounding function and the cross-rounding function respectively and signal value

[0265] In the embodiments of the present application, the Perkert-style error reconciliation mechanism is used, so that the smart card can recover k1' consistent with k1 according to this mechanism, and the server can recover k0' consistent with k0 according to this mechanism.

[0266] In some embodiments of the present application, the specific process of smart card-based authentication and key exchange using the Perkert-style error reconciliation mechanism and the central binomial distribution sampling algorithm when the modulus q is odd is introduced. See Figure 3 , Figure 3 which shows the specific process of authentication and key exchange. The specific process is described as follows:

[0267] Smart card SC i detects that user U i has logged in successfully, samples generates a random number n2, calculates the public key b0 = As0 + e0 and v = P T s0 + e1 using s0, where A is a polynomial matrix sampled from the polynomial ring and P is the public key pre-stored and generated by the server S, P = A T s s + e s Then, the doubled public key signal value and intermediate secret are calculated using the random doubling function, the cross-rounding function, and the modulo rounding function respectively. Calculate γ0 = H1(b0||P||n2||k0), and calculate the anonymized identity identifier AID i for the server S to confirm the identity of user U i while preventing an attacker from confirming the identity of user U by eavesdropping on the channel i Identity to anonymize the attacker, calculate the verification of user identity information γ1 = H1(ID i ||b0||n1||n2||PW2) using the pre-stored random number n1 and password PW2 generated by server S for server S to verify the identity of user U i and send M0 = (AID i ,b0,n2,c0,γ1) to server S.

[0268] After receiving M0, server S first calculates the public key through the received b0 Calculate the intermediate secret k0′ = Rec(2v′,c0) using the coordination function, calculate γ0′ = H1(b0||P||n2||k0′), and use the received AID i to calculate the identity identifier According to ID i ′ to find the corresponding password PW2 and random number n1, calculate the verification of user identity information γ1′ = H1(ID i ′||b0||n1||n2||PW2), and verify: γ1′? = γ1, "? =" means whether it is equal. If so, it means that the identity authentication of user U i passes, and continue to sample Generate a random number n3, calculate the public key b1 = A T s1 + e2, Calculate the doubled public key using the random doubling function, cross-rounding function and modulo-rounding function Signal value and intermediate secret Calculate the verification of server identity information γ2 for smart card SC i to verify the identity of server S, γ2 = H1(ID i ′||b1||c1||n1||n3||k1||PW2), calculate the session key sk s = H1(ID i ′||ID s ||b0||b1||k1||n1||n3||PW2), and send M1 = (b1, c1,n3,γ2) to smart card SC i .

[0269] Smart card SC i After receiving M1, calculate the public key Use the coordination function to calculate the intermediate secret k1′ = Rec(2w′,c1), and calculate the verification of server identity information γ2′ = H1(ID i ||b1||c1||n1||n3||k1′||PW2), verify: γ2′? = γ2, if so, the identity authentication of the server passes, and calculate the session key sk c = H1(ID i ||ID s ||b0||b1||k1′||n1||n3||PW2).

[0270] If the smart card SC i and the server S honestly calculate and transmit relevant information, then sk c = sk s , now give the correctness proof of sk c = sk s :

[0271] k1′ = Rec(2w′,c1)

[0272]

[0273]

[0274]

[0275] Take k = 2 as an example,

[0276]

[0277]

[0278] Because the polynomial ring has commutativity, so s 10 a 00 s 00 = s 00 a 00 s 10 , from which we can get Therefore Also Then From the central binomial distribution sampling algorithm, it can be obtained that all the coefficients of the obtained polynomial are not in [-q / 4, q / 4), and from the Peikert error reconciliation mechanism, it can be obtained that k1 = k1′, then sk c = sk s .

[0279] Suppose that for all authentication and key exchange schemes, the size of the user identity is 64 bytes, the output length of the hash function is 256 bits, and the size of the nonce is taken as 256 bits. In the existing Ding's scheme based on RLWE and the DING-style error reconciliation mechanism, no specific implementation parameters were selected in its original text. In the research of the embodiments of this application, the scheme was implemented using the parameters (n, σ, q) = (1024, 3.192, 1073479681), where σ is the standard deviation of the discrete Gaussian distribution. The authentication and key exchange scheme provided by the above embodiment based on MLWE and Peikert error reconciliation design can have parameters selected as (n, k, η, q) = (256, 3, 4, 7681). Based on this, the embodiments of this application show a comparison between the scheme proposed in this application and the existing Ding's scheme and the scheme in Shu's literature through Table 1. Among them, Ding's scheme is the one disclosed in "J. Ding, S. Alsayigh, J. Lancrenon, R. V. Saraswathy, and M. Snook Provably Secure Password Authenticated Key Exchange Based on RLWE for the Post-Quantum World, 2017.", and the scheme in Shu's literature is the one in "Shu Qin, Wang Shengbao, Lu Fanyi, Han Lidong, Tan Xiao, Universal Composable Two-Party Password-Authenticated Key Exchange Protocol Based on Ideal Lattices, Journal of Electronics and Information Technology, vol. 43, no. 06, pp. 1756 - 1763, 2021."”The solutions disclosed in [reference] are shown in Table 1. The PAK and PPK schemes in Ding's scheme based on RLWE and the DING - type error - reconciliation mechanism, as well as the scheme in Shu's literature based on RLWE and the Peikert error - reconciliation mechanism, do not achieve anonymity, while this scheme achieves anonymity. The public - key lengths in Ding's scheme and Shu's literature are both 3840 Byte, and the public - key length in this scheme is 1248 Byte. In the PAK scheme of Ding's scheme, the communication overhead for the client to send a message to the server is 3936, the communication overhead for the server to send a message to the client is 4000, and the number of message - exchange rounds is 3. In the PPK scheme of Ding's scheme, the communication overhead for the client to send a message to the server is 3904, the communication overhead for the server to send a message to the client is 4000, and the number of message - exchange rounds is 2. In Shu's literature's scheme, the communication overhead for the client to send a message to the server is 3936, the communication overhead for the server to send a message to the client is 4032, and the number of message - exchange rounds is 3. In this scheme, the communication overhead for the smart card to send a message to the server is 1408, the communication overhead for the server to send a message to the client is 1344, and the number of message - exchange rounds is 2. As can be seen from Table 1, in the authentication and key - exchange scheme proposed in this paper based on MLWE and the Peikert error - reconciliation design, user - identity anonymity can be achieved in terms of security, the communication overhead is much lower than other implementation schemes, and the communication efficiency is much higher than other implementation schemes.

[0280] Table 1

[0281]

[0282] Furthermore, for the authentication and key - exchange scheme based on MLWE and the Peikert error - reconciliation design provided in the above - mentioned embodiment, when the parameters are selected as (n,k,η,q)=(256,3,4,7681), the LWE_ESTIMATOR tool is used to estimate the security of the selected parameters, which can reach 202 post - quantum - bit security and can fully resist the attack of quantum computers.

[0283] Next, the authentication and key - exchange device based on a smart card provided in the embodiments of the present application will be described. The authentication and key - exchange device based on a smart card described below can be correspondingly referred to the authentication and key - exchange method based on a smart card described above.

[0284] First, in combination with Figure 4 , the authentication and key - exchange device based on a smart card applied to the smart card will be introduced. As Figure 4 shown, the authentication and key - exchange device based on a smart card may include:

[0285] The first private key and noise generation unit 10 is configured to, when detecting that the user logs in successfully, sample from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm to obtain a private key s0, a noise e0, and a noise e1;

[0286] The first public key calculation unit 11 is configured to calculate a public key b0 based on the s0 and the e0 using the MLWE problem, and calculate a public key v based on a public key P generated by the server and pre-stored, the s0, and the e1 using the MLWE problem;

[0287] The first coordination unit 12 is configured to coordinate the v using a preset error coordination mechanism to obtain an intermediate secret k0 and a signal value c0;

[0288] The anonymized identity identifier calculation unit 13 is configured to encrypt the identity identifier ID corresponding to the user based on the k0, a preset first parameter set, and a preset encryption algorithm i to obtain an anonymized identity identifier AID i ;

[0289] The first verification user identity information generation unit 14 is configured to generate verification user identity information γ1 based on n1, the ID i and a preset second parameter set, where the n1 is a random number generated by the server during the user registration and pre-stored;

[0290] The first set sending unit 15 is configured to send a set M0 to the server, where the M0 includes the AID i , the b0, the γ1, and the c0;

[0291] The first set receiving unit 16 is configured to receive a set M1 sent by the server, where the M1 includes a public key b1, a signal value c1, and verification server identity information γ2;

[0292] The second coordination unit 17 is configured to calculate a public key w′ based on the b1 and the s0, and coordinate the w′ and the c1 using the error coordination mechanism to obtain an intermediate secret k1';

[0293] The verification server identity information generation unit 18 generates verification server identity information γ2′ based on the k1', the n1, and a preset third parameter set;

[0294] The session key generation unit 19, if the γ2′ is equal to the γ2, generates a session key sk based on the k1′, the n1, and a preset fourth parameter set c .

[0295] Optionally, the smart card-based authentication and key exchange device may further include:

[0296] The first password calculation unit is configured to calculate password PW2' = H0(ID i ||n1||PW1') when receiving the ID i and password PW1' sent by the client, where PW1' is the password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user login, and PW1' = H0(ID i ||n0||PW0), where n0 is a random number generated by the client and stored in advance during the user registration, and H0() is a preset hash function;

[0297] The user login status determination unit is configured to determine that the user logs in successfully when PW2' is equal to the stored PW2, where PW2 is a password generated by the server and stored in advance during the user registration, and PW2 = H0(ID i ||n1||PW1), where PW1 is the password calculated by the client after obtaining the ID i input by the user and the private password PW0 during the user registration, and PW1 = H0(ID i ||n0||PW0).

[0298] Optionally, the smart card-based authentication and key exchange device may further include:

[0299] The first random number generation unit is configured to generate a random number n2.

[0300] Optionally, the first parameter set may include b0, P, and n2;

[0301] The process of encrypting the identity identifier ID corresponding to the user by the anonymous post-identity identifier calculation unit based on k0, a preset first parameter set, and a preset encryption algorithm i to obtain the anonymous post-identity identifier AID i may include:

[0302] Calculate γ0 = H1(b0||P||n2||k0), where H1() is a preset hash function;

[0303] Calculate the anonymous post-identity identifier

[0304] Optionally, the second parameter set may include b0, n2, and PW2, where PW2 is a password generated by the server and stored in advance during the user registration;

[0305] The first verification user identity information generation unit verifies the user identity information based on n1, the ID i and the preset second parameter set to generate the process of the verification user identity information γ1, which may include:

[0306] Calculate the verification user identity information γ1 = H1(ID i ||b0||n1||n2||PW2).

[0307] The M0 may further include n2, and the set M1 may further include a random number n3;

[0308] Optionally, the third parameter set may include the ID i 、the b1, the c1, the n3 and the PW2;

[0309] The process of the verification server identity information generation unit generating the verification server identity information γ2' based on the k1', the n1 and the preset third parameter set may include:

[0310] Calculate γ2' = H1(ID i ||b1||c1||n1||n3||k1'||PW2).

[0311] Optionally, the fourth parameter set may include the ID i 、ID s 、the b0, the b1, the n3 and the PW2, where the ID s is the identifier of the server obtained in advance;

[0312] The process of the session key generation unit generating the session key sk c based on the k1', the n1 and the preset fourth parameter set may include:

[0313] Calculate sk c = H1(ID i ||ID s ||b0||b1||k1'||n1||n3||PW2).

[0314] Optionally, the process of the first private key and noise generation unit sampling from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm to obtain the private key s0, the noise e0 and the noise e1 may include:

[0315] Using the central binomial distribution sampling algorithm to sample from to obtain the private key s0 and the noise e0, and using the central binomial distribution sampling algorithm to sample from β η to obtain the noise e1, where the and the said β η are both central binomial distributions with parameter η on the said polynomial ring, and the said k is the dimension of the polynomial matrix.

[0316] Optionally, the process of calculating the public key b0 by the first public key calculation unit based on the s0 and the e0 using the MLWE problem may include:

[0317] Calculating the public key b0 = As0 + e0, where the said A is a polynomial matrix sampled from the said polynomial ring.

[0318] Optionally, the process of calculating the public key v by the first public key calculation unit based on the public key P generated by the server stored in advance, the s0 and the e1 using the MLWE problem may include:

[0319] Calculating the public key v = P T s0 + e1, where P = A T s s + e s and the said s s and the said e s are both sampled from the by the server using the central binomial distribution sampling algorithm.

[0320] Optionally, the process of calculating the public key w′ by the second coordination unit based on the b1 and the s0 may include:

[0321] Calculating the public key

[0322] Optionally, the error coordination mechanism may include the Perkert - type error coordination mechanism;

[0323] Based on this, the process of the first coordination unit coordinating the v using the preset error coordination mechanism to obtain the intermediate secret k0 and the signal value c0 may include:

[0324] When the modulus q of the polynomial ring is even, respectively use the modulo - rounding function and the cross - rounding function to calculate the intermediate secret and the signal value c0← <v> q,2 ;

[0325] When q is odd, use the random doubling function, the modulo rounding function, and the cross rounding function to calculate the doubled public key intermediate secret and signal value

[0326] Optionally, the process of the second coordination unit using the error coordination mechanism to coordinate the w' and the c1 to obtain the intermediate secret k1' may include:

[0327] When q is even, use the coordination function to calculate the intermediate secret k1' = Rec(w', c1);

[0328] When q is odd, use the coordination function to calculate the intermediate secret k1' = Rec(2w', c1).

[0329] Furthermore, in combination with Figure 5 , introduce the smart card-based authentication and key exchange device applied to the server, as Figure 5 shown, the smart card-based authentication and key exchange device may include:

[0330] A second set receiving unit 20, configured to receive a set M0 sent by the smart card, where the M0 includes an anonymized identity identifier AID i , public key b0, authentication user identity information γ1, and signal value c0;

[0331] A third coordination unit 21, configured to calculate a public key v' based on the b0 and s s and use a preset error coordination mechanism to coordinate the v' and the c0 to obtain an intermediate secret k0', where the s s is a private key sampled in advance from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm;

[0332] An identity identifier calculation unit 22, configured to decrypt the AID i based on the k0', a preset first parameter set, and a preset decryption algorithm to obtain an identity identifier ID i ';

[0333] A second authentication user identity information unit 23, configured to generate authentication user identity information γ1' based on n1, the ID i ' and a preset second parameter set, where the n1 is a random number generated in advance when the user corresponding to the ID i ' is registered;

[0334] The second private key and noise generation unit 24 is configured to, if the γ1' is equal to the γ1, use the sampling algorithm to sample from the distribution on the polynomial ring respectively to obtain a private key s1, a noise e2, and a noise e3;

[0335] The second public key calculation unit 25 is configured to calculate a public key b1 using the MLWE problem based on the s1 and the e2, and calculate a public key w using the MLWE problem based on the b0, the s1, and the e3;

[0336] The fourth coordination unit 26 is configured to coordinate the w using the error coordination mechanism to obtain an intermediate secret k1 and a signal value c1;

[0337] The verification information and session key generation unit 27 is configured to generate verification server identity information γ2 based on the k1, the n1, and a preset third parameter set, and generate a session key sk based on the k1, the n1, and a preset fourth parameter set s ;

[0338] The second set sending unit 28 is configured to send a set M1 to the smart card, where the M1 includes the b1, the c1, and the γ2.

[0339] Optionally, the authentication and key exchange device based on the smart card may further include:

[0340] The registration request processing unit is configured to, when receiving a registration request (ID i , PW1) sent by the user using the client, sample from to obtain the private key s s and the noise e s , calculate a public key P = A T s s + e s , where the PW1 is a password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user registration, and PW1 = H0(ID i || n0 || PW0), the n0 is a random number generated by the client during the user registration, H0() is a preset hash function, the is a centered binomial distribution with a parameter η on the polynomial ring, the k is the dimension of the polynomial matrix, and the A is a polynomial matrix sampled from the polynomial ring;

[0341] The second password calculation unit is configured to generate the random number n1 and calculate a password PW2 = H0(ID i || n1 || PW1);

[0342] A relevant data storage unit for storing the n1, the PW2, and the P into a preset smart card SC i so as to distribute the SC i to the user.

[0343] Optionally, the M0 may further include a random number n2.

[0344] Based on this, the first parameter set may further include the b0, the P, and the n2, where the P is a public key generated in advance during the user registration;

[0345] The process of the identity identification calculation unit decrypting the AID based on the k0′, a preset first parameter set, and a preset decryption algorithm i to obtain the identity identification ID i ′ may include:

[0346] Calculating γ0′ = H1(b0||P||n2||k0′), where H1() is a preset hash function;

[0347] Calculating the identity identification

[0348] Optionally, the second parameter set may include the b0, the n2, and PW2, where the PW2 is a password generated in advance during the user registration;

[0349] The process of the second user identity information verification unit generating the user identity verification information γ1′ based on n1, the ID i ′ and a preset second parameter set may include:

[0350] Calculating the user identity verification information γ1′ = H1(ID i ′||b0||n1||n2||PW2).

[0351] Optionally, the smart card-based authentication and key exchange device may further include:

[0352] A second random number generation unit for generating a random number n3.

[0353] Optionally, the third parameter set includes the ID i ′, the b1, the c1, the n3, and the PW2;

[0354] The process of the verification information and session key generation unit generating the server identity verification information γ2 based on the k1, the n1, and a preset third parameter set may include:

[0355] Calculate the verification server identity information γ2 = H1(ID i '||b1||c1||n1||n3||k1||PW2).

[0356] Optionally, the fourth parameter set includes the ID i ', ID s , the b0, the b1, the n3, and the PW2, where the ID s is its own identifier;

[0357] The verification information and session key generation unit generates a session key sk based on the k1, the n1, and a preset fourth parameter set s The process may include:

[0358] Calculate the session key sk s = H1(ID i '||ID s ||b0||b1||k1||n1||n3||PW2).

[0359] Optionally, the process of the third coordination unit calculating the public key v' based on the b0 and s s may include:

[0360] Calculate the public key

[0361] The process of the second private key and noise generation unit sampling from the distribution on the polynomial ring using the sampling algorithm to obtain the private key s1, the noise e2, and the noise e3 may include:

[0362] Use the central binomial distribution sampling algorithm to sample from to obtain the private key s1 and the noise e2, and use the central binomial distribution sampling algorithm to sample from β η to obtain the noise e3, where the and the β η are both central binomial distributions with a parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix.

[0363] Optionally, the process of the second public key calculation unit calculating the public key b1 based on the s1 and the e2 using the MLWE problem may include:

[0364] Calculate the public key b1 = A T s1 + e2, where the A is a polynomial matrix sampled from the polynomial ring.

[0365] Optionally, the process of calculating the second public key by the second public key calculation unit based on the b0, the s1, and the e3 using the MLWE problem may include:

[0366] Calculate the public key

[0367] Optionally, the error reconciliation mechanism may include a Perkert-style error reconciliation mechanism;

[0368] Based on this, the process of the third reconciliation unit using a preset error reconciliation mechanism to reconcile the v' and the c0 to obtain the intermediate secret k0' may include:

[0369] When the modulus q of the polynomial ring is even, use the reconciliation function to calculate the intermediate secret k0′ = Rec(v′, c0);

[0370] When the q is odd, use the reconciliation function to calculate the intermediate secret k0′ = Rec(2v′, c0);

[0371] Optionally, the process of the third reconciliation unit using the error reconciliation mechanism to reconcile the w to obtain the intermediate secret k1 and the signal value c1 may include:

[0372] When the q is even, use the floor function and the cross-rounding function to calculate the intermediate secret and the signal value c1 ← <w> q,2 ;

[0373] When q is odd, the doubled public key is calculated by using the random doubling function, the modulo rounding function, and the cross-rounding function respectively Intermediate secret and signal value

[0374] The authentication and key exchange device based on a smart card provided by the embodiments of the present application can be applied to an authentication and key exchange device based on a smart card. The authentication and key exchange device based on a smart card can be a smart card or a server. Figure 6 shows a hardware structure block diagram of an authentication and key exchange device based on a smart card. Referring to Figure 6 , the hardware structure of a screen mirroring device between Android handheld devices may include: at least one processor 1, at least one communication interface 2, at least one memory 3, and at least one communication bus 4;

[0375] In the embodiments of the present application, the number of the processor 1, the communication interface 2, the memory 3, and the communication bus 4 is at least one, and the processor 1, the communication interface 2, and the memory 3 complete mutual communication through the communication bus 4;

[0376] The processor 1 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention, etc.;

[0377] The memory 3 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory;

[0378] Wherein, the memory stores a program, and the processor can call the program stored in the memory, and the program is used to: implement each processing flow of the foregoing smart card in the authentication and key exchange scheme based on a smart card, or implement each processing flow of the foregoing server in the authentication and key exchange scheme based on a smart card.

[0379] The embodiments of the present application also provide a storage medium, which can store a program suitable for a processor to execute, and the program is used to: implement each processing flow of the foregoing smart card in the authentication and key exchange scheme based on a smart card, or implement each processing flow of the foregoing server in the authentication and key exchange scheme based on a smart card.

[0380] The embodiments of the present application also disclose an authentication and key exchange system based on a smart card. The authentication and key exchange system based on a smart card includes a smart card and a server. The specific implementation logics of the smart card and the server can refer to the relevant introductions in the foregoing part of the authentication and key exchange method based on a smart card, which will not be elaborated here.

[0381] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0382] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.

[0383] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.< / w> < / v> < / w> < / v> < / v> < / w> < / v>

Claims

1. An authentication and key exchange method based on a smart card, characterized in that, Applied to a smart card, the method includes: When it is detected that the user logs in successfully, use a preset sampling algorithm to sample from the distribution on the polynomial ring in the MLWE problem respectively to obtain the private key s0, the noise e0 and the noise e1; Based on the s0 and the e0, use the MLWE problem to calculate the public key b0, and based on the public key P generated by the server stored in advance, the s0 and the e1, use the MLWE problem to calculate the public key v; Use a preset error reconciliation mechanism to reconcile the v to obtain the intermediate secret k0 and the signal value c0; Based on the k0, a preset first parameter set, and a preset encryption algorithm, encrypt the identity identifier ID corresponding to the user i to obtain an anonymized identity identifier AID i ; Based on n1 and the said ID i generate the user identity information γ1 based on the preset second parameter set, where n1 is a random number pre-stored by the server when the user registers; Send the set M0 to the server, where M0 includes the AID i , the b0, the γ1, and the c0; Receive the set M1 sent by the server, where the M1 includes the public key b1, the signal value c1 and the verification server identity information γ2; Based on the b1 and the s0, calculate the public key w′, and use the error reconciliation mechanism to reconcile the w′ and the c1 to obtain the intermediate secret k1'; Generate the verification server identity information γ2′ based on the k1', the n1 and a preset third parameter set; If the γ2′ is equal to the γ2, a session key sk is generated based on the k1', the n1 and a preset fourth parameter set c .

2. The method according to claim 1, characterized in that, It further includes: When receiving the ID sent by the client i and the password PW1′, calculate the password PW2′ = H0(ID i ||n1||PW1′), where PW1' is the password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user login, and PW1′ = H0(ID i ||n0||PW0), where n0 is a random number generated by the client and stored in advance during the user registration, and H0() is a preset hash function; When the PW2′ is equal to the stored PW2, it is determined that the user has logged in successfully, where the PW2 is a password pre-stored and generated by the server during the user registration, and PW2 = H0(ID i ||n1||PW1), the PW1 is a password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user registration, and PW1 = H0(ID i ||n0||PW0).

3. The method according to claim 1, wherein After using a preset sampling algorithm to sample from the distribution on the polynomial ring in the MLWE problem respectively to obtain the private key s0, the noise e0 and the noise e1, it further includes: Generate a random number n2; The first parameter set includes the b0, the P and the n2; Encrypt the identity identifier ID corresponding to the user based on the k0, a preset first parameter set, and a preset encryption algorithm i to obtain an anonymized identity identifier AID i , including: Calculate γ0 = H1(b0||P||n2||k0), where H1() is a preset hash function; Calculated anonymized identity identifier The second parameter set includes the b0, n2 and PW2, where the PW2 is the password generated by the server during the user registration and stored in advance; Based on n1 and the said ID i and a preset second parameter set to generate the user identity information γ1 for verification, including: Calculate and verify the user identity information γ1 = H1(ID i ||b0||n1||n2||PW2); The M0 further includes n2, and the set M1 further includes a random number n3; The third parameter set includes the ID i , the b1, the c1, the n3, and the PW2; Generating the verification server identity information γ2′ based on the k1', the n1 and a preset third parameter set includes: Calculate γ2′ = H1(ID i ||b1||c1||n1||n3||k1′||PW2); The fourth parameter set includes the ID i , ID s , the b0, the b1, the n3, and the PW2, where the ID s is the identifier of the server obtained in advance; Generate a session key sk based on the k1', the n1, and a preset fourth parameter set c , including: Calculate sk c = H1(ID i || ID s || b0 || b1 || k1' || n1 || n3 || PW2).

4. The method according to claim 1, characterized in that Using a preset sampling algorithm to sample from the distribution on the polynomial ring in the MLWE problem respectively to obtain the private key s0, the noise e0 and the noise e1, It includes: Sampling from using the central binomial distribution sampling algorithm to obtain the private key s0 and the noise e0, and sampling from β η using the central binomial distribution sampling algorithm to obtain the noise e1, where both the and the β η are central binomial distributions with a parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix; Based on the s0 and the e0, using the MLWE problem to calculate the public key b0 includes: Calculate the public key b0 = As0 + e0, where the A is a polynomial matrix sampled from the polynomial ring; Based on the public key P generated by the server stored in advance, the s0 and the e1, using the MLWE problem to calculate the public key v includes: Calculate the public key v = P T s0 + e1, where P = A T s s + e s and both the s s and the e s are sampled by the server using the central binomial distribution sampling algorithm from the ; Based on the b1 and the s0, calculating the public key w′ includes: Calculate public key 5. The method according to any one of claims 1-4, characterized in that, The error reconciliation mechanism includes the Perkert - type error reconciliation mechanism; Using a preset error reconciliation mechanism to reconcile the v to obtain the intermediate secret k0 and the signal value c0 includes: When the modulus q of the polynomial ring is even, the intermediate secret is calculated using the floor function and the ceiling function respectively and the signal value c0 ← <v> q,2 ;< / v> When q is odd, calculate the doubled public key by using the random doubling function, the modulo rounding function, and the cross-rounding function respectively Intermediate secret And signal value Using the error reconciliation mechanism to reconcile the w′ and the c1 to obtain the intermediate secret k1' includes: When the q is even, use the reconciliation function to calculate the intermediate secret k1′ = Rec(w′, c1); When the q is odd, use the reconciliation function to calculate the intermediate secret k1′ = Rec(2w′, c1).

6. A smart card-based authentication and key exchange method, characterized in that, Applied to a server, the method includes: Receive the set M0 sent by the smart card, where M0 includes the anonymized identity identifier AID i , the public key b0, the user identity verification information γ1, and the signal value c0; Based on the said b0 and s s Calculate the public key v', and use a preset error reconciliation mechanism to reconcile the v' and the c0 to obtain an intermediate secret k0', where the s s is a private key sampled in advance from the distribution on the polynomial ring in the MLWE problem using a preset sampling algorithm; Decrypt the AID based on the k0', a preset first parameter set, and a preset decryption algorithm i to obtain an identity identifier ID i '; Based on n1 and the ID i ' and the preset second parameter set to generate the user identity information γ1 for verification', where n1 is a random number generated in advance when the user corresponding to the ID i ' registers; If the γ1' is equal to the γ1, then use the sampling algorithm to sample from the distribution on the polynomial ring respectively to obtain the private key s1, the noise e2 and the noise e3; Compute public key \(b_1\) using the MLWE problem based on the said \(s_1\) and the said \(e_2\), and compute public key \(w\) using the MLWE problem based on the said \(b_0\), the said \(s_1\) and the said \(e_3\); Use the error reconciliation mechanism to reconcile the said \(w\) to obtain the intermediate secret \(k_1\) and the signal value \(c_1\); Generate the verification server identity information γ2 based on the k1, the n1, and a preset third parameter set, and generate the session key sk based on the k1, the n1, and a preset fourth parameter set s ; Send the set \(M_1\) to the smart card, where the \(M_1\) includes the said \(b_1\), the said \(c_1\) and the said \(\gamma_2\).

7. The method according to claim 6, wherein Also included are: When receiving the registration request (ID i , PW1) sent by the user using the client, sample from using the sampling algorithm to obtain the private key s s and the noise e s , calculate the public key P = A T s s + e s , where the PW1 is the password calculated by the client after obtaining the ID i and the private password PW0 input by the user during the user registration, and PW1 = H0(ID i || n0 || PW0), the n0 is a random number generated by the client during the user registration, H0() is a preset hash function, the is a central binomial distribution with parameter η on the polynomial ring, the k is the dimension of the polynomial matrix, and the A is a polynomial matrix sampled from the polynomial ring; Generate the random number n1, and calculate the password PW2 = H0(ID i ||n1||PW1); Store the n1, the PW2, and the P in a preset smart card SC i so as to distribute the SC i to the user.

8. The method according to claim 6, wherein The said \(M_0\) also includes the random number \(n_2\); The first parameter set includes the said \(b_0\), \(P\) and the said \(n_2\), where \(P\) is a public key generated in advance during the user registration; Decrypt the AID based on the k0′, a preset first parameter set, and a preset decryption algorithm i to obtain an identity identifier ID i ', including: Compute \(\gamma_0' = H_1(b_0||P||n_2||k_0')\), where \(H_1()\) is a preset hash function; Calculated identity identifier The second parameter set includes the said \(b_0\), the said \(n_2\) and \(PW_2\), where \(PW_2\) is a password generated in advance during the user registration; Based on n1 and the said ID i Generate the user identity information γ1' for verification based on ′ and a preset second parameter set, including: Calculate and verify the user identity information γ1′ = H1(ID i ′||b0||n1||n2||PW2); After sampling the private key \(s_1\), the noise \(e_2\) and the noise \(e_3\) respectively from the distribution on the polynomial ring using the said sampling algorithm, also included are: Generate a random number \(n_3\); The third parameter set includes the ID i ′, the b1, the c1, the n3, and the PW2; Generate the verification server identity information \(\gamma_2\) based on the said \(k_1\), the said \(n_1\) and a preset third parameter set, including: Calculate the verification server identity information γ2 = H1(ID i ′||b1||c1||n1||n3||k1||PW2); The fourth parameter set includes the ID i ′, ID s , the b0, the b1, the n3, and the PW2, where the ID s is its own identifier; Generate a session key sk based on the k1, the n1, and a preset fourth parameter set s , including: Calculate the session key sk s = H1(ID i ′||ID s ||b0||b1||k1||n1||n3||PW2).

9. The method according to claim 6, wherein Based on the said b0 and s s Calculate the public key v′, including: Calculate public key Sample the private key \(s_1\), the noise \(e_2\) and the noise \(e_3\) respectively from the distribution on the polynomial ring using the said sampling algorithm, including: Sampling from using the central binomial distribution sampling algorithm to obtain the private key s1 and the noise e2, sampling from β η using the central binomial distribution sampling algorithm to obtain the noise e3, where and the β η are both central binomial distributions with parameter η on the polynomial ring, and the k is the dimension of the polynomial matrix; Compute the public key \(b_1\) using the MLWE problem based on the said \(s_1\) and the said \(e_2\), including: Calculate the public key b1 = A T s1 + e2, where A is a polynomial matrix sampled from the polynomial ring; Compute the public key \(w\) using the MLWE problem based on the said \(b_0\), the said \(s_1\) and the said \(e_3\), including: Calculate public key 10. The method according to any one of claims 6-9, characterized in that, The error reconciliation mechanism includes the Perkert - type error reconciliation mechanism; The use of a preset error reconciliation mechanism to reconcile the said \(v'\) and the said \(c_0\) to obtain the intermediate secret \(k_0'\), including: When the modulus \(q\) of the polynomial ring is even, use the reconciliation function to compute the intermediate secret \(k_0' = Rec(v',c_0)\); When the \(q\) is odd, use the reconciliation function to compute the intermediate secret \(k_0' = Rec(2v',c_0)\); Use the error reconciliation mechanism to reconcile the said \(w\) to obtain the intermediate secret \(k_1\) and the signal value \(c_1\), including: When q is an even number, the intermediate secret is calculated using the modulo rounding function and the cross rounding function respectively and the signal value c1 ← <w> q,2 ;< / w> When q is odd, calculate the doubled public key by using the random doubling function, the modulo rounding function, and the cross rounding function respectively Intermediate secret and signal value