Cpk key secure transmission method, storage method and device

CN116722973BActive Publication Date: 2026-08-18BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310679114.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-08
Publication Date
2026-08-18
Estimated Expiration
2043-06-08

AI Technical Summary

Technical Problem

目前缺少设计合理的密钥分发及存储方式

Benefits of technology

[0028] (1) Through the rational design of applications and instructions, the data transmission length can be flexibly adjusted for different chips and application scenarios, thereby improving the compatibility of security chips.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116722973B_ABST
    Figure CN116722973B_ABST
Patent Text Reader

Abstract

The application relates to the field of password security technology, and provides a CPK key secure transmission method, a storage method and a device. The CPK key secure transmission method is applied to a CPK key issuing end, and the method comprises the following steps: a public key matrix in the CPK key is divided into a plurality of public key matrix components; first feature data is obtained according to the distribution of the public key matrix components; a public key matrix component is taken as the load of a transmission instruction, a header of the transmission instruction is generated according to second feature data of the load, and a transmission instruction is formed; and the first feature data and the transmission instruction are transmitted to a counter terminal. The embodiments provided by the application improve the transmission efficiency and security in CPK key distribution and storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cryptographic security technology, specifically to a CPK key secure transmission method, a CPK key secure storage method, a CPK key secure transmission device, a CPK key secure storage device, a CPK key issuance system, an electronic device, and a corresponding storage medium. Background Technology

[0002] Security chips typically store keys using key files, which are files that store key records and cannot be read from outside the system. When the file has permission to add a key, a key record can be written to it; when the file has permission to use a key, corresponding cryptographic operations can be performed within the encrypted storage security module; when the file has permission to modify a key (except for password keys), that key can be modified. Key files can use fixed-length or variable-length record formats and are internal security files. Key information includes a key header and key values, where the key header contains key attribute information such as key ID, key permissions, and key usage algorithm. However, this storage method is not well-suited for the public key matrix and private keys in the CPK key system. The storage capacity requirements for these two types of keys differ, and their subsequent usage methods also differ. Currently, there is a lack of a reasonably designed key distribution and storage method.

[0003] CPK (Combined Public Key Cryptosystem): A combined public key system, it is an identifier-based asymmetric public key system implemented based on Elliptic Curve Cryptography (ECC). It consists of a combining matrix and a separating key sequence. The combining matrix is ​​divided into a private key matrix and a public key matrix. The separating key sequence consists of a certain number of separating keys, and key pairs are labeled (ssk, SPK). Summary of the Invention

[0004] The purpose of this invention is to provide a secure transmission method, storage method, and apparatus for CPK keys. Addressing the characteristics of a large public key matrix data volume and high confidentiality requirements for private key data in CPK keys, this invention employs dedicated transmission instructions and other measures to at least solve some of the problems in the background art.

[0005] To achieve the above objectives, this invention provides a CPK key secure transmission method, applied to a CPK key issuing end, the method comprising:

[0006] The public key matrix in the CPK key is divided into several public key matrix components; first feature data is obtained according to the distribution of the public key matrix components; the public key matrix components are used as the payload of the transmission instruction, and the header of the transmission instruction is generated according to the second feature data of the payload to form the transmission instruction; the first feature data and the transmission instruction are transmitted to the other end.

[0007] Preferably, the first feature data includes: the size of the public key matrix components, the total number N of the public key matrix components, and the digest values ​​of the public key matrix and / or the public key matrix components.

[0008] Preferably, the number of public key matrix components in the payload is one or more.

[0009] Preferably, generating the header of the transmission instruction based on the second characteristic data of the payload includes: generating a data group number in the header based on the sequence number of the public key matrix component in the public key matrix; generating the number of public key matrix components in the header based on the number of public key matrix components contained in the payload; and generating a length indication in the header based on the size of the data in the payload.

[0010] Preferably, the method further includes: generating a private key in the CPK key based on the received identity identifier, and encrypting and transmitting the private key to the peer.

[0011] This invention provides a secure CPK key storage method applied to a CPK key receiver. The method includes: allocating a storage area for the public key matrix in a CPK key to be received based on received first feature data; in response to receiving a transmission command, verifying the public key matrix component in the transmission command payload based on second feature data in the transmission command header; if the verification is successful, determining whether the data block number in the transmission command header is equal to the total block number of the data blocks; if they are equal, determining whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data; and if they are equal, determining that the public key matrix reception is complete.

[0012] Preferably, the method further includes: after determining that the public key matrix has been received, calculating a digest for the storage area, and determining whether the calculated digest is equal to the data digest in the first feature data; if the digest is equal to the data digest in the first feature data, determining that the public key matrix has been successfully received.

[0013] Preferably, the method further includes: sending the identity identifier of the CPK key receiver to the CPK key issuer; and using the private key generated by the CPK key issuer based on the received identity identifier as the private key in the CPK key.

[0014] This invention also provides a CPK key secure transmission device, applied to a CPK key issuing end. The device includes: a matrix segmentation module for dividing the public key matrix in the CPK key into several public key matrix components; a feature extraction module for obtaining first feature data based on the distribution of the public key matrix components; an instruction generation module for generating a transmission instruction header based on the second feature data of the public key matrix components as the payload of the transmission instruction, thus forming the transmission instruction; and a data transmission module for transmitting the first feature data and the transmission instruction to the other end.

[0015] Preferably, the first feature data includes: the size of the public key matrix components, the total number of public key matrix components, and the digest values ​​of the public key matrix and / or the public key matrix components.

[0016] Preferably, the number of public key matrix components in the payload is one or more.

[0017] Preferably, generating the header of the transmission instruction based on the second characteristic data of the payload includes: generating a data group number in the header based on the sequence number of the public key matrix component in the public key matrix; generating the number of public key matrix components in the header based on the number of public key matrix components contained in the payload; and generating a length indication in the header based on the size of the data in the payload.

[0018] Preferably, the device further includes a private key generation and transmission module, used to generate a private key in the CPK key based on the received identity identifier, and to encrypt and transmit the private key to the peer.

[0019] This invention also provides a CPK key secure storage device applied to a CPK key receiving end. The device includes: a storage allocation module for allocating storage areas for the public key matrix in a CPK key to be received based on received first feature data; a block verification module for verifying the public key matrix component in the transmission command payload based on second feature data in the transmission command header in response to a received transmission command; a block number confirmation module for determining whether the data group number in the transmission command header is equal to the total block number of the data blocks if the verification passes; a component confirmation module for determining whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data if both are equal; and a completion confirmation module for determining that the public key matrix reception is complete if both are equal.

[0020] Preferably, the apparatus further includes: a digest processing module, configured to calculate a digest for the storage area after determining that the public key matrix has been received, and determine whether the calculated digest is equal to the data digest in the first feature data; if the digest is equal to the data digest in the first feature data, determine that the public key matrix has been successfully received.

[0021] Preferably, the device further includes: a data interaction module, used to send the identity identifier of the CPK key receiver to the CPK key issuer; and to use the private key generated by the CPK key issuer based on the received identity identifier as the private key in the CPK key.

[0022] Preferably, the device is a security chip.

[0023] The present invention also provides a CPK key issuance system, including the aforementioned CPK key secure transmission device and the aforementioned CPK key secure storage device.

[0024] The present invention also provides an electronic device, comprising: at least one processor; and a memory connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the at least one processor implements the steps of the aforementioned CPK key secure transmission method and / or the steps of the aforementioned CPK key secure storage method by executing the instructions stored in the memory.

[0025] The present invention also provides a machine-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the steps of implementing the aforementioned CPK key secure transmission method and / or the steps of implementing the aforementioned CPK key secure storage method.

[0026] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the aforementioned CPK key secure transmission method and / or the steps of the aforementioned CPK key secure storage method.

[0027] The above technical solution has the following beneficial effects:

[0028] (1) Through the rational design of applications and instructions, the data transmission length can be flexibly adjusted for different chips and application scenarios, thereby improving the compatibility of security chips.

[0029] (2) For public key matrix (PKM) with large data volume, a two-level verification method of single frame data and overall data is adopted to improve the correctness of transmission and prevent data tampering or loss.

[0030] (3) Different protection mechanisms are adopted for the public key matrix and the user's private key to improve data transmission efficiency while ensuring data integrity and confidentiality.

[0031] (4) Supports retransmission of public key matrix components to avoid the failure of the entire distribution process due to the loss of a certain component, thereby improving the efficiency of key distribution.

[0032] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0033] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0034] Figure 1 The schematic diagram illustrates the steps of a CPK key secure transmission method according to an embodiment of the present invention;

[0035] Figure 2 This illustration shows a schematic diagram of the private key storage process for the CPK key according to an embodiment of the present invention;

[0036] Figure 3 The illustration shows a schematic diagram of an implementation of the CPK key secure storage method according to an embodiment of the present invention;

[0037] Figure 4 The schematic diagram illustrates the structure of a CPK key secure transmission device according to an embodiment of the present invention;

[0038] Figure 5 A schematic diagram of the CPK key transmission system according to an embodiment of the present invention is shown. Detailed Implementation

[0039] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.

[0040] Figure 1 The diagram illustrates the steps of a CPK key secure transmission method according to an embodiment of the present invention. Figure 1 As shown, a CPK key secure transmission method is applied to the CPK key issuing end. The method includes:

[0041] S01. Divide the public key matrix in the CPK key into several public key matrix components;

[0042] S02. Obtain the first feature data based on the distribution of the components of the public key matrix;

[0043] S03. The public key matrix components are used as the payload of the transmission instruction. The second feature data of the payload is used to generate the header of the transmission instruction to form the transmission instruction.

[0044] S04. Transmit the first feature data and the transmission instruction to the other end.

[0045] Through the above embodiments of the present invention, a dedicated instruction for public key matrix transmission is used to transmit the public key matrix, and the size of the transmitted data block can be dynamically controlled through instruction parameters.

[0046] In some embodiments provided by this invention, the first feature data includes: the size of the public key matrix component, the total number of public key matrix components, and the digest value of the public key matrix and / or the public key matrix component. The size of the public key matrix component is used to characterize the data size of the public key matrix component; the total number of public key matrix components is used by the receiving end to verify whether the reception of the public key matrix component is complete; and the digest value of the public key matrix and / or the public key matrix component is used by the receiving end to verify whether the received public key matrix component is correct.

[0047] In some embodiments provided by this invention, the number of public key matrix components in the payload is one or more. Since the size of the public key matrix varies, and the length of data received by a single transmission command varies, the number of public key matrix components in the payload of each transmission command can be set according to actual conditions, thereby improving compatibility and transmission speed. When a transmission command contains only one public key matrix component, a number of transmission commands equal to the total number of public key matrix components are required to complete the transmission of the public key matrix. When a transmission command contains multiple public key matrix components, the required number of transmission commands is less than the total number of public key matrix components.

[0048] In some embodiments provided by this invention, generating a header for a transmission instruction based on the second characteristic data of the payload includes: generating a data group number in the header based on the sequence number of the public key matrix component in the public key matrix; generating a number of public key matrix components in the header based on the number of public key matrix components contained in the payload; and generating a length indicator in the header based on the size of the data in the payload. Specific parameters are shown in the table below.

[0049] code numerical values CLA ‘80’ INS ‘2A’ P1 The serial numbers start from 01 and increment. P2 Number of components in the public key matrix Lc Length DATA Public key matrix components

[0050] Where P1 represents the data packet number issued by the public key matrix, starting from 01 and continuously increasing. P2 represents the number of public key matrix components in this transmission command. Since the size of the public key matrix varies, the length of data received by a single transmission command varies; therefore, the size of P2 can be set according to actual needs to improve compatibility and transmission speed. Lc indicates variable data length, i.e., a length indicator. DATA represents the payload.

[0051] In some embodiments of the present invention, the specific steps of the key issuing end include: the key issuing end preparing CPK public key matrix (PKM) data; calculating PKM initialization data, such as matrix component size, total number of matrix components, and matrix digest value; issuing PKM data, with specific instructions as shown in the table below; the security chip processing the received data, with the processing flow described below; and the issuance process ending after all PKM data processing is complete.

[0052] In some embodiments provided by the present invention, the method further includes: generating a private key in the CPK key based on the received identity identifier, and encrypting and transmitting the private key to the peer. Figure 2 This diagram illustrates an implementation of the private key storage process for the CPK key according to an embodiment of the present invention. Figure 2 As shown, the security chip and other key receivers read the unique identifier ID from their internal dedicated storage area; send the ID data to the key issuer; the key issuer generates a private key based on the identifier ID; and protects the private key using symmetric encryption. The protection key here can be a dedicated symmetric key or a session key generated using a digital envelope; the security chip verifies the confidentiality and integrity of the data; if verification is successful, it proceeds to the next step; otherwise, it returns an error; the key receiver securely stores the private key.

[0053] Corresponding to the aforementioned secure CPK key transmission method, this invention also provides a secure CPK key storage method, applied at a CPK key receiving end, the method comprising:

[0054] Based on the received first feature data, a storage area is allocated for the public key matrix in the CPK key to be received; in response to receiving a transmission command, the public key matrix component in the transmission command payload is verified based on the second feature data in the transmission command header; if the verification is successful, it is determined whether the data block number in the transmission command header is equal to the total block number of the data block; if the two are equal, it is determined whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data; if the two are equal, it is determined that the public key matrix reception is complete.

[0055] In some optional implementations, after confirming that the public key matrix has been received, a digest is calculated for the storage area, and it is determined whether the calculated digest is equal to the data digest in the first feature data; if the digest is equal to the data digest in the first feature data, it is determined that the public key matrix has been successfully received.

[0056] Figure 3 The illustration schematically depicts an implementation diagram of the CPK key secure storage method according to an embodiment of the present invention. For example... Figure 3As shown, the processing flow of CPK key receivers such as security chips includes space allocation, data processing, logic control, and fault-tolerant design. Specific steps include:

[0057] (1) Receive initialization data, namely the aforementioned first feature data, and place information such as the total number of matrix components and the summary value in a dedicated storage area for subsequent verification of the entire PKM storage process;

[0058] (2) Allocate chip data space according to the storage requirements of PKM;

[0059] (3) Receive PKM component data and verify the command parameters, such as: verifying the continuity and increment of the P1 parameter; verifying whether the number of components specified by P2 is consistent with the actual transmitted data, etc.

[0060] (4) Verify the integrity of the instruction, which can be done using methods such as HASH or MAC. If the verification is correct, continue to step 3; if the verification fails, return an error to the key issuer, which can then resend the corresponding matrix component.

[0061] (5) Determine if the data block number is the total block number. If it is, proceed to the next step; otherwise, continue to steps (3) and (4) to receive data.

[0062] (6) Verify that the total number of PKM component transmissions is equal to the total number at initialization. Calculate the digest for the entire PKM storage area and determine if it is equal to the digest value at initialization. If they are consistent, the transmission is successful; otherwise, the transmission fails.

[0063] In some embodiments of the present invention, the method further includes: sending the identity identifier of the CPK key receiver to the CPK key issuer; and using the private key generated by the CPK key issuer based on the received identity identifier as the private key in the CPK key. At the CPK key receiver, the processing flow for the private key portion is similar to... Figure 2 As shown, it will not be repeated here.

[0064] Through the above implementation methods and the rational design of applications and instructions, the data transmission length can be flexibly adjusted for different chips and application scenarios, improving the compatibility of security chips. For public key matrices (PKMs) with large data volumes, a two-level verification method—single-frame data and overall data—is adopted to improve transmission correctness and prevent data tampering or loss. Different protection mechanisms are used for the public key matrix and user private keys to improve data transmission efficiency while ensuring data integrity and confidentiality. By splitting the data into individual transmission instructions, retransmission of public key matrix components is supported, preventing the entire distribution process from failing due to the loss of a single component, thus improving the efficiency of key distribution.

[0065] Based on the same inventive concept, the present invention also provides a CPK key secure transmission device, which is applied to the CPK key issuing end. Figure 4 A schematic diagram of a CPK key secure transmission device according to an embodiment of the present invention is shown. Figure 4 As shown, the device includes: a matrix segmentation module for dividing the public key matrix in the CPK key into several public key matrix components; a feature extraction module for obtaining first feature data based on the distribution of the public key matrix components; an instruction generation module for generating a header of the transmission instruction based on the second feature data of the payload, using the public key matrix components as the payload of the transmission instruction, to form the transmission instruction; and a data transmission module for transmitting the first feature data and the transmission instruction to the other end.

[0066] In some alternative implementations, the first feature data includes: the size of the public key matrix components, the total number N of the public key matrix components, and the digest values ​​of the public key matrix and / or the public key matrix components.

[0067] In some alternative implementations, the number of public key matrix components in the payload is one or more.

[0068] In some optional implementations, generating a header for a transmission instruction based on the second characteristic data of the payload includes: generating a data group number in the header based on the sequence number of the public key matrix component in the public key matrix; generating a number of public key matrix components in the header based on the number of public key matrix components contained in the payload; and generating a length indication in the header based on the size of the data in the payload.

[0069] In some alternative embodiments, the apparatus further includes a private key generation and transmission module, configured to generate a private key in the CPK key based on the received identity identifier, and encrypt and transmit the private key to the peer.

[0070] Correspondingly, this invention also provides a CPK key secure storage device, applied to a CPK key receiving end. The device includes: a storage allocation module, configured to allocate storage areas for the public key matrix in the CPK key to be received based on received first feature data; a block verification module, configured to verify the public key matrix component in the transmission command payload based on second feature data in the transmission command header in response to a received transmission command; a block number confirmation module, configured to determine whether the data group number in the transmission command header is equal to the total block number of the data blocks if the verification passes; a component confirmation module, configured to determine whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data if both are equal; and a completion confirmation module, configured to determine that the public key matrix reception is complete if both are equal.

[0071] In some optional embodiments, the apparatus further includes: a digest processing module, configured to calculate a digest for the storage area after determining that the reception of the public key matrix is ​​complete, and determine whether the calculated digest is equal to the data digest in the first feature data; if the digest is equal to the data digest in the first feature data, determine that the public key matrix has been successfully received.

[0072] In some optional embodiments, the apparatus further includes: a data interaction module, configured to send the identity identifier of the CPK key receiver to the CPK key issuer; and to use the private key generated by the CPK key issuer based on the received identity identifier as the private key in the CPK key.

[0073] In some alternative implementations, the device is a security chip.

[0074] The specific limitations of each functional module in the aforementioned CPK key secure transmission device and CPK key secure storage device can be found in the limitations of the CPK key secure transmission method and CPK key secure storage method described above, and will not be repeated here. Each module in the aforementioned device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0075] The present invention also provides a CPK key issuance system, including the aforementioned CPK key secure transmission device and the aforementioned CPK key secure storage device, which are connected to each other via a wired or wireless communication link. Figure 5 A schematic diagram illustrating the flow of a CPK key transmission system according to an embodiment of the present invention is shown. Figure 5 As shown, the key issuing end first initializes the CPK public key matrix (PKM) by sending the initialization data to a secure storage device such as a security chip. Then, it sends the PKM data via multiple transmission commands, and the security chip stores the received PKM. After the key issuing end finishes sending the data, the security chip verifies the integrity of the PKM and then sends a storage completion response. This process enables the distribution of the CPK public key matrix (PKM) and achieves the aforementioned beneficial effects.

[0076] In some embodiments of the present invention, an electronic device is also provided, comprising: at least one processor; and a memory connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which executes the steps of the aforementioned CPK key secure transmission method and / or implements the steps of the aforementioned CPK key secure storage method. The control module or processor here has numerical calculation and logical operation functions, and at least has a central processing unit (CPU) with data processing capabilities, random access memory (RAM), read-only memory (ROM), multiple I / O ports, and an interrupt system. The processor contains a kernel that retrieves corresponding program units from the memory. One or more kernels can be configured, and the aforementioned methods can be implemented by adjusting kernel parameters. The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0077] In one embodiment of the present invention, a machine-readable storage medium is provided, on which instructions are stored, which, when executed by a processor, cause the processor to be configured to perform the steps of the aforementioned CPK key secure transmission method and / or the aforementioned CPK key secure storage method.

[0078] In one embodiment of the present invention, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the aforementioned CPK key secure transmission method and / or the aforementioned CPK key secure storage method.

[0079] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0080] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0081] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0082] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0083] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0084] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0085] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0086] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0087] The above are merely embodiments of the present invention and are not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.

Claims

1. A method for securely storing CPK keys, applied at a CPK key receiving end, characterized in that, The method includes: Storage areas are allocated for the public key matrix in the CPK key to be received based on the received first feature data; the first feature data is obtained based on the distribution of the components of the public key matrix. In response to receiving a transmission instruction, the public key matrix component in the transmission instruction payload is verified according to the second feature data in the transmission instruction header; the transmission instruction uses the public key matrix component as the transmission instruction payload, and a transmission instruction header is generated according to the second feature data of the payload; If the verification passes, determine whether the data packet number in the transmission instruction header is equal to the total block number of the data block; If the two are equal, determine whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data; If the two are equal, it is determined that the public key matrix has been received successfully. If the two are not equal, continue executing the received transmission command; The method further includes: Send the identity identifier of the CPK key receiver to the CPK key issuer; The private key generated by the CPK key issuer based on the received identity identifier is used as the private key in the CPK key.

2. The method according to claim 1, characterized in that, The method further includes: After confirming that the public key matrix has been received, a digest is calculated for the storage area, and it is determined whether the calculated digest is equal to the data digest in the first feature data. If the digest is equal to the data digest in the first feature data, it is determined that the public key matrix has been successfully received.

3. A CPK key secure storage device, applied at a CPK key receiving end, characterized in that, The device includes: The storage allocation module is used to allocate storage areas for the public key matrix in the CPK key to be received based on the received first feature data; the first feature data is obtained according to the distribution of the components of the public key matrix. The block verification module is used to verify the public key matrix component in the payload of the transmission instruction according to the second feature data in the header of the transmission instruction in response to receiving the transmission instruction; the transmission instruction uses the public key matrix component as the payload of the transmission instruction, and generates the header of the transmission instruction according to the second feature data of the payload; The block number confirmation module is used to determine whether the data packet number in the transmission instruction header is equal to the total block number of the data block if the verification is successful. The component confirmation module is used to determine whether the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data, provided that the data packet number in the transmission instruction header is equal to the total block number of the data block. The completion confirmation module is used to determine that the public key matrix reception is complete when the total number of received public key matrix components is equal to the number of public key matrix components in the first feature data. If the two are not equal, continue executing the received transmission command; The device further includes: a data interaction module, used for... Send the identity identifier of the CPK key receiver to the CPK key issuer; The private key generated by the CPK key issuer based on the received identity identifier is used as the private key in the CPK key.

4. The apparatus according to claim 3, characterized in that, The device further includes: a summary processing module, used for: After confirming that the public key matrix has been received, a digest is calculated for the storage area, and it is determined whether the calculated digest is equal to the data digest in the first feature data. If the digest is equal to the data digest in the first feature data, it is determined that the public key matrix has been successfully received.

5. The apparatus according to claim 3, characterized in that, The device is a security chip.

6. A CPK key issuance system, characterized in that, Includes the CPK key secure storage device and the corresponding CPK key secure transmission device as described in any one of claims 3 to 5, wherein the CPK key secure transmission device is applied at the CPK key issuing end and includes: The matrix segmentation module is used to divide the public key matrix in the CPK key into several public key matrix components; The feature extraction module is used to obtain the first feature data based on the distribution of the components of the public key matrix; The instruction generation module is used to generate a header for the transmission instruction, using public key matrix components as the payload, and to compose the transmission instruction based on the second feature data of the payload; and The data transmission module is used to transmit the first feature data and the transmission instruction to the other end.

7. The system according to claim 6, characterized in that, The first feature data includes: the size of the public key matrix components, the total number of public key matrix components, and the digest values ​​of the public key matrix and / or its components.

8. The system according to claim 6, characterized in that, The number of public key matrix components in the payload is one or more.

9. The system according to claim 6, characterized in that, Generate a header for the transmission instruction based on the second characteristic data of the payload, including: The data packet number in the header is generated based on the sequence number of the public key matrix component in the payload within the public key matrix. The number of public key matrix components in the header is generated based on the number of public key matrix components contained in the payload; The length indication in the header is generated based on the amount of data in the payload.

10. The system according to claim 6, characterized in that, The CPK key secure transmission device further includes a private key generation and transmission module, which generates a private key in the CPK key based on the received identity identifier and transmits the private key to the peer in encrypted form.

11. A method for secure transmission of CPK keys, characterized in that, The method, applied to the CPK key secure transmission device in the CPK key issuance system according to any one of claims 6 to 10, comprises: The public key matrix in the CPK key is divided into several public key matrix components; The first feature data is obtained based on the distribution of the components of the public key matrix; The public key matrix components serve as the payload for transmitting instructions. A header for the transmission instructions is generated based on the second feature data of the payload, thus forming the transmission instructions. The first feature data and the transmission command are transmitted to the other end.

12. The method according to claim 11, characterized in that, The first feature data includes: the size of the public key matrix components, the total number of public key matrix components, and the digest values ​​of the public key matrix and / or its components.

13. The method according to claim 11, characterized in that, The number of public key matrix components in the payload is one or more.

14. The method according to claim 11, characterized in that, Generate a header for the transmission instruction based on the second characteristic data of the payload, including: The data packet number in the header is generated based on the sequence number of the public key matrix component in the payload within the public key matrix. The number of public key matrix components in the header is generated based on the number of public key matrix components contained in the payload; The length indication in the header is generated based on the amount of data in the payload.

15. The method according to claim 11, characterized in that, The method further includes: Generate the private key in the CPK key based on the received identity identifier, and encrypt and transmit the private key to the peer.

16. An electronic device, characterized in that, include: At least one processor; A memory connected to the at least one processor; The memory stores instructions executable by the at least one processor, which executes the instructions stored in the memory to implement the steps of the CPK key secure transmission method according to any one of claims 12 to 15, and / or the steps of the CPK key secure storage method according to any one of claims 1 to 2.

17. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores instructions that, when executed by a processor, cause the processor to be configured to implement the CPK key secure transmission method of any one of claims 12 to 15 and / or the CPK key secure storage method of any one of claims 1 to 2.

Citation Information

Patent Citations

  • Combined key managing method and system based on ID

    CN1905438A

  • Secure key management

    US20120281837A1