Key agreement method and system

By generating public auxiliary information and pseudo-random numbers through a fuzzy random source and a reusable fuzzy extractor, the problem of key leakage in the AKE protocol is solved, and secure key negotiation without storing long-term private keys is achieved, simplifying key management.

CN117254901BActive Publication Date: 2026-04-17SHANGHAI JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI JIAOTONG UNIV
Filing Date
2022-06-09
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The existing AKE protocol requires the secret storage of the signing private key and inter-round state, which poses a risk of key leakage.

Method used

A fuzzy random source and a reusable fuzzy extractor are used to generate public auxiliary information and pseudo-random numbers. The private key is recovered through a fuzzy regeneration algorithm and a key generation algorithm, avoiding the storage of long-term private keys. Inter-round public auxiliary information is used instead of inter-round state transmission.

Benefits of technology

It completely avoids the risk of key and inter-round state leakage, simplifies key management, and improves security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117254901B_ABST
    Figure CN117254901B_ABST
Patent Text Reader

Abstract

The application relates to the communication technical field, and discloses a key agreement method and system. The method comprises the following steps: an A side obtains a pseudo-random number and inter-round public auxiliary information according to a sampling result of the A side based on a fuzzy generation algorithm, and obtains a regenerated first private key according to the sampling result and stored public auxiliary information based on a fuzzy regeneration algorithm, so as to obtain a message m A and an inter-round state assigned as the inter-round public auxiliary information; after receiving the message m A , a B side regenerates a second private key according to a sampling result of the B side and stored public auxiliary information based on the fuzzy regeneration algorithm, so as to obtain a message m B and an agreement key k B ; after receiving the message m B , the A side regenerates the pseudo-random number according to a second sampling result of the A side and the inter-round public auxiliary information based on the fuzzy regeneration algorithm, and regenerates the first private key according to the second sampling result and stored public auxiliary information based on the fuzzy regeneration algorithm, so as to obtain the agreement key k A . The application does not need to store a long-term private key and an inter-round state, and avoids the risk of key leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a key negotiation method and system. Background Technology

[0002] The Authenticated Key Exchange (AKE) protocol enables two communicating parties to authenticate each other and negotiate a session key.

[0003] In existing technologies, classic AKE protocols (such as the Signed DH protocol) can be used as follows: Figure 1 The process illustrated shows that the typical AKE protocol includes three phases: initialization, registration, and protocol interaction.

[0004] Initialization phase: Calling AKE's initialization algorithm Public parameters of the generation system .

[0005] User registration phase: For users In terms of the system's publicly available parameters and For input, call .

[0006] Protocol Interaction Phase: A traditional AKE protocol interaction process can be represented by the following three steps, in order to... and For example, in an interactive scenario: Step 1, the participants... Calling probabilistic algorithms long-term private key with public parameters , as input, generate message and wheel state Step 2, Participants receive After receiving the message, invoke the probabilistic algorithm. , based on publicly available system parameters private key , public key and Generate a negotiated session key for the input. Acceptance status With message Step 3, Participants receive Message sent Then, the deterministic algorithm is called. To disclose parameters Private key , of information Inter-wheel state As input, generate the negotiated session key. With the state of acceptance .

[0007] However, this classic AKE scheme requires the secret storage of the signing private key and the inter-round state, which places high demands on key management and carries the risk of private key loss or leakage. Summary of the Invention

[0008] The purpose of this application is to provide a key negotiation method and system that eliminates the need to store private keys for extended periods, thereby mitigating the risk of key leakage.

[0009] This application discloses a key negotiation method, the method comprising:

[0010] (a) Initialize the system on the A side and the B side respectively, generate and store the public parameters of the respective system based on the generation algorithm of the classic AKE protocol, and sample the predetermined fuzzy random source of each participant on the A side and the B side respectively to obtain the random feature information of each participant. Obtain the public auxiliary information and public key and private key pair according to the random feature information and public parameters, and store the public auxiliary information and the public key.

[0011] (b) Participant A samples a predetermined fuzzy random source to obtain second random feature information, and uses this second random feature information as input to obtain pseudo-random numbers and inter-round public auxiliary information based on a fuzzy generation algorithm. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as a random number. The system retrieves the wheel-to-wheel status, assigns the wheel-to-wheel status value to the publicly available auxiliary information for that wheel, and sends a message. To participant B's side;

[0012] (c) In response to receiving a message Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message To the side of participant A;

[0013] (d) In response to receiving a message Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using this fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, a regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key .

[0014] In a preferred embodiment, the method further includes:

[0015] When participant A initiates a session with participant B for the first time, steps (a) to (d) are executed, and when participant A initiates a session with participant B again, steps (b) to (d) are executed.

[0016] In a preferred embodiment, the method further includes:

[0017] For each session between participant A and participant B, corresponding inter-round public auxiliary information is generated and stored for key negotiation in the corresponding session; or, for each session between participant A and participant B, corresponding inter-round public auxiliary information is generated and stored for key negotiation in each session.

[0018] In a preferred embodiment, step (a) further includes:

[0019] Each participant generates public auxiliary information and pseudo-random numbers based on a fuzzy generation algorithm, using their random feature information and public parameters as inputs. A key generation algorithm generates public and private key pairs for each participant, using their pseudo-random numbers and stored public parameters as inputs. The public auxiliary information and public key for each participant are then stored.

[0020] In a preferred embodiment, the predetermined fuzzy random source is the specific biometric information of each participant;

[0021] The method further includes:

[0022] For participant A and participant B, respectively, random feature information is extracted using a feature extraction network based on the specific biological information.

[0023] In a preferred embodiment, the predetermined fuzzy random source is a specific physically unclonable function corresponding to each participant;

[0024] The method further includes:

[0025] For participant A and participant B, their respective random feature information is extracted using a fuzzy extractor based on the specific physical non-cloning function. The fuzzy extractor consists of a security profile and a strong extractor.

[0026] This application also discloses a key negotiation system including a first subsystem on the side of participant A and a second subsystem on the side of participant B;

[0027] The first subsystem includes:

[0028] The first initialization module is used to generate the public parameters of this subsystem based on the generation algorithm of the classic AKE protocol;

[0029] The first registration module is used to sample the predetermined fuzzy random source of participant A to obtain its own random feature information, and obtain the public auxiliary information and public key and private key pair of participant A based on the random feature information and public parameters of participant A.

[0030] The first storage module is used to store the public parameters, the public auxiliary information of participant A, and the public key;

[0031] The first protocol interaction module is used by participant A to sample a predetermined fuzzy random source to obtain second random feature information, and then uses this second random feature information as input to obtain pseudo-random numbers and inter-round public auxiliary information based on a fuzzy generation algorithm. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as a random number. The system retrieves the wheel-to-wheel status and assigns it to publicly available auxiliary information for that wheel, and responds to received messages. Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using this fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, a regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key ;

[0032] The first sending module is used to send messages. To the second subsystem;

[0033] The first receiving module is used to receive messages from the second subsystem. ;

[0034] The second subsystem includes:

[0035] The second initialization module is used to generate the public parameters of the subsystem based on the generation algorithm of the classic AKE protocol;

[0036] The second registration module is used to sample a predetermined fuzzy random source of participant B to obtain the random feature information of participant B, and to obtain the public auxiliary information and public key and private key pair of participant B based on the random feature information of participant B and the public parameters.

[0037] The second storage module is used to store the public parameters, the public auxiliary information of participant B, and the public key;

[0038] The second receiving module is used to receive the message from the first subsystem. ;

[0039] The second protocol interaction module is used to respond to received messages. Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message To the side of participant A;

[0040] The second sending module is used to send the message. To the first subsystem.

[0041] In a preferred embodiment, the first registration module and the second registration module are further configured to generate the public auxiliary information and pseudo-random number of each participant based on a fuzzy generation algorithm with the random feature information and public parameters of each participant as input, and to generate the public key and private key pair of each participant based on a key generation algorithm with the pseudo-random number of each participant and the stored public parameters as input.

[0042] In a preferred embodiment, the predetermined fuzzy random source is the specific biometric information of each participant;

[0043] The first protocol interaction module is further configured to extract corresponding random feature information for participant A based on the specific biological information using a feature extraction network, and the second protocol interaction module is further configured to extract corresponding random feature information for participant B based on the specific biological information using a feature extraction network.

[0044] In a preferred embodiment, the predetermined fuzzy random source is a specific physically unclonable function corresponding to each participant;

[0045] The first protocol interaction module is further configured to extract corresponding random feature information for participant A based on the specific physical non-cloning function using a reusable fuzzy extractor, and the second protocol interaction module is further configured to extract corresponding random feature information for participant B based on the specific physical non-cloning function using a reusable fuzzy extractor.

[0046] In a preferred embodiment, the reusable fuzz extractor consists of a security profile, a strong extractor, and a key expansion function.

[0047] In this embodiment, a fuzzy random source with high entropy (besides biological information, physically unclonable functions (PUFs) can also be used as the source of random numbers. Each participant samples the fuzzy random source and, based on a reusable fuzzy extractor generation algorithm and a regeneration algorithm, uses the sampling results combined with pre-stored public auxiliary information to reconstruct the private key and pseudo-random numbers. Furthermore, it eliminates the need to store long-term private keys and inter-round states, completely avoiding the risk of key and inter-round state leakage and simplifying key management. In particular, in existing technologies, during round interactions between participant A and participant B, the inter-round state generated in the current round needs to be passed to the next round, posing a risk of leakage. This embodiment uses a fuzzy generation algorithm with participant A's initial sampling result as input to obtain pseudo-random numbers and inter-round public auxiliary information. A probabilistic algorithm based on the classic AKE protocol generates messages by taking the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as a random number. The inter-round state is determined and assigned as the inter-round public auxiliary information. In the next round, the pseudo-random number is generated based on the fuzzy regeneration algorithm, using the secondary sampling result of participant A and the inter-round public auxiliary information as input. The negotiation key is then generated based on the deterministic algorithm of the classic AKE protocol, using the pseudo-random number as input. This allows publicly available auxiliary information between rounds, which poses no risk of leakage, to be passed to the next round instead of the round-to-round state during the execution of the same protocol. This completely avoids the risk of key and round-to-round state leakage during the execution of the same protocol and simplifies key management. Attached Figure Description

[0048] Figure 1 This is a classic AKE protocol process flowchart in the existing technology.

[0049] Figure 2 This is a schematic flowchart of a key negotiation method according to the first embodiment of this application.

[0050] Figure 3 This is a block diagram of the key negotiation process according to the first embodiment of this application.

[0051] Figure 4 This is a schematic diagram of the key negotiation system structure according to the second embodiment of this application. Detailed Implementation

[0052] In the following description, numerous technical details are presented to better understand this application. However, those skilled in the art will understand that the technical solutions claimed in this application can be implemented even without these technical details and various variations and modifications based on the following embodiments.

[0053] Explanation of some concepts:

[0054] Session: An interaction between two users to negotiate authentication keys.

[0055] Long-term private key / long-term key: Information that a user secretly stores for a long period of time;

[0056] Inter-round state: During the execution of the same protocol, in order for the next round to be executed, the user needs to pass information to the next round.

[0057] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0058] The first embodiment of this application relates to a key negotiation method, the process of which is as follows: Figure 2 and 3 As shown, the method includes the following steps:

[0059] Step 201 involves initializing both participant A and participant B. Public parameters for their respective systems are generated and stored using the generation algorithm based on the classic AKE protocol. Then, on both sides, a predetermined fuzzy random source is sampled to obtain random characteristic information for each participant. Based on this random characteristic information and the public parameters, public auxiliary information, public key, and private key pairs are obtained and stored. It should be noted that step 201 is executed only once when participant A initiates its first session with participant B, storing the obtained public parameters, public auxiliary information, and public key. Subsequent sessions between participant A and participant B do not require re-execution of step 201; instead, the stored public parameters, public auxiliary information, and public key are directly accessed.

[0060] The types of predetermined fuzzy random sources are diverse. Optionally, the predetermined fuzzy random source can be specific biometric information of each participant. Optionally, the predetermined fuzzy random source can be a specific physically non-cloning function corresponding to each participant. It is not limited to these. Specific biometric information includes, but is not limited to, pre-agreed facial or fingerprint information.

[0061] In one embodiment, for participant A and participant B, corresponding random feature information can be extracted respectively based on the predetermined biometric information using a feature extraction network. For example, in the case where the predetermined biometric information is a face, the feature extraction network can be a high-performance network such as FaceNet or InsightFace designed for faces. In another embodiment, for participant A and participant B, their respective random feature information can be extracted based on the predetermined biometric information using a fuzzy extractor. This fuzzy extractor can be a reusable fuzzy extractor, which can be, for example, but not limited to, composed of an existing security profile (such as a linear code), a strong extractor (such as a toeplitz matrix), and a key expansion function (such as a hash function SHA3, SM3 series). Further, suppose... For the metric space where the information source is located, For metric space A distribution on, The space where the extracted string is located. This indicates the error tolerance of the fuzz extractor. For random sources Minimum entropy requirement. Reusable. An example reusable fuzzy extractor algorithm rFE consists of two PPT algorithms: the generation algorithm rFE.Gen and the fuzzy regeneration algorithm rFE.Rep. For a (M,m,R,t,ϵ)-reusable fuzzy extractor on a distribution W, the two algorithms are described in detail below:

[0062] Generation Algorithm Input string (One sample from a fuzzy random source) Output a string and a public auxiliary information .

[0063] Fuzzy Regeneration Algorithm Input string (Another sampling from a fuzzy random source) Output a string .

[0064] Specifically, the fuzzy generation algorithm and fuzzy regeneration algorithm of this application can be generation and regeneration algorithms of a reusable fuzzy extractor. Furthermore, the reusability of the fuzzy extractor means that pseudo-random numbers can be extracted multiple times from the same random source.

[0065] In one embodiment, public auxiliary information and pseudo-random numbers of each participant are generated based on a fuzzy generation algorithm using the random feature information and public parameters of each participant as input. Public key and private key pairs of each participant are generated based on a key generation algorithm using the pseudo-random numbers of each participant and the stored public parameters as input. The public auxiliary information and public key of each participant are then stored.

[0066] Step 202: Participant A samples a predetermined fuzzy random source to obtain second random feature information. Based on the fuzzy generation algorithm, using this second random feature information as input, pseudo-random numbers and inter-round public auxiliary information are obtained. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs, based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as the random number. The system retrieves the wheel-to-wheel status, assigns the wheel-to-wheel status value to the publicly available auxiliary information for that wheel, and sends a message. To participant B. The first private key for regeneration is obtained by using the second random feature information and stored public auxiliary information as inputs, based on the fuzzy regeneration algorithm and the key generation algorithm. This is further implemented as follows: the output result is obtained based on the fuzzy regeneration algorithm using the second random feature information and stored public auxiliary information as inputs; the first private key is generated based on the key generation algorithm using the output result as input.

[0067] Optionally, corresponding inter-round public auxiliary information is generated and stored for each session, used for key negotiation in this session. Optionally, corresponding inter-round public auxiliary information is generated and stored for the first access, used for key negotiation in subsequent sessions.

[0068] Step 203, in response to receiving the message Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message On the side of participant A, the second private key obtained by using the third random feature information and the stored public auxiliary information as input, based on the fuzzy regeneration algorithm and the key generation algorithm, is further implemented as follows: the output result is obtained by using the third random feature information and the stored public auxiliary information as input based on the fuzzy regeneration algorithm, and the second private key is generated by using the output result as input based on the key generation algorithm.

[0069] Step 204, in response to receiving the message Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using the fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, the regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key The process of obtaining the regenerated first private key based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, is further implemented as follows: the fuzzy regeneration algorithm is used as input to obtain the output result, and the key generation algorithm is used as input to generate the first private key.

[0070] It is understandable that the first private key and pseudo-random number used in step 204 are not the first private key stored in step 202, but rather are obtained upon receiving a message from participant B. Afterwards, participant A is resampled to obtain the fourth random feature information, and the first private key and pseudo-random number are reconstructed using this resampled fourth random feature information. That is to say, step 204 does not store the first private key and pseudo-random number generated therein (in fact, both were deleted after step 202 was completed). This avoids the risk of leakage of private key and inter-round state if step 202 stores the first private key and pseudo-random number and applies them to step 204.

[0071] In one embodiment, steps (a) to (d) are performed when participant A initiates a session with participant B for the first time, and steps (b) to (d) are performed when participant A initiates a session with participant B again.

[0072] In one embodiment, corresponding inter-round public auxiliary information is generated and stored for each session between participant A and participant B, for key negotiation in that session. In another embodiment, corresponding inter-round public auxiliary information is generated and stored for each session between participant A and participant B, for key negotiation in that session.

[0073] To better understand the technical solution of this application, a specific example is provided below. The details listed in this example are mainly for ease of understanding and are not intended to limit the scope of protection of this application. This example includes three stages: the initialization stage, the registration stage, and the protocol interaction stage.

[0074] I. Initialization Phase: Calling the initialization algorithm Public parameters of the generation system .

[0075] II. Registration Phase: For users In terms of his ambiguous source and the system's public parameters As input, the sampling algorithm is first called to sample the fuzzy source. Sampling Then call the fuzzy generation algorithm. Generate public auxiliary information With pseudo-random numbers Using pseudo-random numbers and publicly available parameters As Input, generate key pair .return .

[0076] III. Protocol Interaction Phase: The protocol interaction process of the bio-information-based key negotiation protocol can be represented by the following three steps, with the user... and Taking interaction as an example, they each have their own resources. and :

[0077] Step 1, Participants First, call the function. Fuzzy random source for users (This can be biometric information such as faces, fingerprints, etc., or physically non-clonable functions, etc.) Sampling is performed to obtain samples. ; to sample and public auxiliary information As input, call the fuzzy regeneration algorithm. generate Then call Recover private key Simultaneously, the generation algorithm of the reusable fuzz extractor is invoked. Obtain pseudo-random numbers Inter-wheel public auxiliary information Then, with public parameters private key ,user public key For input, As an explicit input of random numbers, similar to the classic AKE call. Generate message and wheel-to-wheel state and wheel-to-wheel state Assigning values ​​to public auxiliary information between rounds .

[0078] Step Two, Participants receive Message sent Then, first call the function. Fuzzy random source for users (This can be biometric information such as faces, fingerprints, etc., or physically non-clonable functions, etc.) Sampling is performed to obtain samples. ; to sample and public auxiliary information As input, the regeneration algorithm of the reusable fuzz extractor is invoked. generate Then call Recover private key ; with public parameters private key ,user public key ,information For input, similar to the classic AKE call. Generate message Accepting status and negotiation key .

[0079] Step 3: Participant A receives a message from B. Then, first call the function. Fuzzy random source for users (This can be biometric information such as faces, fingerprints, etc., or physically non-clonable functions, etc.) Sampling is performed to obtain samples. ; to sample and inter-wheel public auxiliary information As input, the regeneration algorithm of the reusable fuzz extractor is invoked. regeneration Then, a similar algorithm to the classic AKE call is used to determine the algorithm. Generate an acceptance state and negotiation key .

[0080] The second embodiment of this application relates to a key negotiation system, the structure of which is as follows: Figure 4 As shown, the key negotiation system includes a first subsystem on the side of participant A and a second subsystem on the side of participant B.

[0081] The first subsystem includes a first initialization module, a first registration module, a first storage module, a first protocol interaction module, a first sending module, and a first receiving module. Specifically, the first initialization module generates the subsystem's public parameters based on a generation algorithm using the classic AKE protocol; the first registration module samples a predetermined fuzzy random source from participant A to obtain its own random feature information, and obtains participant A's public auxiliary information and public / private key pairs based on participant A's random feature information and public parameters; the first storage module stores participant A's public parameters, public auxiliary information, and public key; and the first protocol interaction module samples a predetermined fuzzy random source from participant A to obtain second random feature information, and uses this second random feature information as input to generate pseudo-random numbers and inter-round public auxiliary information based on a fuzzy generation algorithm. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs, based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as the random number. The system retrieves the wheel-to-wheel status and assigns it to publicly available auxiliary information for that wheel, and responds to received messages. Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using the fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, the regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key .

[0082] In one embodiment, the first registration module is further configured to generate the public auxiliary information and pseudo-random number of participant A based on the random feature information and public parameters of participant A using a fuzzy generation algorithm, and to generate the public key and private key pair of participant A based on the pseudo-random number of participant A and the stored public parameters using a key generation algorithm.

[0083] The second subsystem includes a second initialization module, a second registration module, a second storage module, a second receiving module, a second protocol interaction module, and a second sending module. Specifically, the second initialization module generates the public parameters of the subsystem based on the generation algorithm of the classic AKE protocol; the second registration module samples a predetermined fuzzy random source from participant B to obtain the random characteristic information of participant B, and obtains the public auxiliary information and public key / private key pair of participant B based on the random characteristic information and the public parameters; the second storage module stores the public parameters, public auxiliary information, and public key of participant B; and the second receiving module receives the message from the first subsystem. The second protocol interaction module is used to respond to received messages. Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message To participant A's side; the second sending module is used to send the message. To the first subsystem.

[0084] In one embodiment, the second registration module is further configured to generate the public auxiliary information and pseudo-random number of participant B based on the random feature information and public parameters of participant B using a fuzzy generation algorithm, and to generate the public key and private key pair of participant B based on the pseudo-random number of participant B and the stored public parameters using a key generation algorithm.

[0085] The types of predetermined fuzzy random sources are diverse. Optionally, the predetermined fuzzy random source can be specific biometric information of each participant. Optionally, the predetermined fuzzy random source can be a specific physically non-cloning function corresponding to each participant. It is not limited to these. The specific biometric information can be pre-agreed biometric information, such as, but not limited to, facial features, fingerprints, etc.

[0086] In one embodiment, for participant A and participant B, corresponding random feature information can be extracted based on the predetermined biometric information using a feature extraction network. For example, if the predetermined biometric information is a face, the feature extraction network can be a high-performance network such as FaceNet or InsightFace designed for faces. In another embodiment, for participant A and participant B, their respective random feature information can be extracted based on the predetermined biometric information using a reusable fuzzy extractor. The reusable fuzzy extractor can be, for example, but not limited to, an existing security profile (such as a linear code), a strong extractor (such as a toeplitz matrix), and a key expansion function (such as a hash function SHA3, SM3 series).

[0087] The first embodiment is a method embodiment corresponding to this embodiment. The technical details in the first embodiment can be applied to this embodiment, and the technical details in this embodiment can also be applied to the first embodiment.

[0088] Furthermore, the key negotiation method and system of this application are applicable to application scenarios where both parties need to conduct a large amount of encrypted communication. In scenarios requiring a large amount of encrypted communication, asymmetric encryption is generally not used for direct message encryption due to its slow speed. The common practice is for both parties to first negotiate a symmetric key using a public-key authentication key negotiation protocol, and then communicate using symmetric encryption. For example, in e-commerce transactions, the communication between sellers and buyers has extremely high privacy requirements, and the content of the calls is extensive. After registering with their biometric information within the system, both parties generate their own private keys and some locally stored long-term data (for subsequent key recovery). If a buyer wants to initiate a transaction with a seller, they proactively initiate a session with the seller, and the two parties conduct a biometric authentication key negotiation to securely negotiate a session key for subsequent secure communication. In addition, this key negotiation method and system can also be applied to applications such as Bluetooth communication and Transport Layer Security (TLS).

[0089] It should be noted that those skilled in the art should understand that the implementation functions of each module shown in the above-described key negotiation system implementation can be understood with reference to the relevant description of the aforementioned key negotiation method. The functions of each module shown in the above-described key negotiation system implementation can be implemented by a program (executable instructions) running on a processor, or by specific logic circuits. If the above-described key negotiation system in this application is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application embodiment, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the method of each embodiment of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, mobile hard drive, read-only memory (ROM), magnetic disk, or optical disk. Thus, this application embodiment is not limited to any specific hardware and software combination.

[0090] It should be noted that in this patent application, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. In this patent application, if it refers to performing an action according to an element, it means performing the action at least according to that element, including two cases: performing the action only according to that element, and performing the action according to that element and other elements. Expressions such as "multiple," "repeatedly," and "various" include two, two times, two kinds, and more than two, more than two times, and more than two kinds.

[0091] All documents mentioned in this application are considered to be incorporated integrally into the disclosure of this application so that they can serve as the basis for modifications if necessary. Furthermore, it should be understood that the above descriptions are merely preferred embodiments of this specification and are not intended to limit the scope of protection of this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of one or more embodiments of this specification should be included within the scope of protection of one or more embodiments of this specification.

Claims

1. A method of key agreement, characterized by, The method includes the following steps: (a) Initialize the system on the A side and the B side respectively, generate and store the public parameters of the system on each side based on the initialization algorithm of the classic AKE protocol, and sample the predetermined fuzzy random source of each participant on the A side and the B side respectively to obtain the random feature information of each participant, obtain the public auxiliary information and public key and private key pair according to the random feature information and public parameters, and store the public auxiliary information and the public key. (b) Participant A samples a predetermined fuzzy random source to obtain second random feature information, and uses this second random feature information as input to obtain pseudo-random numbers and inter-round public auxiliary information based on a fuzzy generation algorithm. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as a random number. The system retrieves the wheel-to-wheel status, assigns the wheel-to-wheel status value to the publicly available auxiliary information for that wheel, and sends a message. To participant B's side; (c) In response to receiving a message Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message To the side of participant A; (d) In response to receiving a message Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using this fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, a regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key .

2. The key negotiation method as described in claim 1, characterized in that, The method further includes: When participant A initiates a session with participant B for the first time, steps (a) to (d) are executed, and when participant A initiates a session with participant B again, steps (b) to (d) are executed.

3. The key negotiation method as described in claim 1, characterized in that, The method further includes: For each session between participant A and participant B, corresponding inter-round public auxiliary information is generated and stored for key negotiation in the corresponding session; or, for each session between participant A and participant B, corresponding inter-round public auxiliary information is generated and stored for key negotiation in each session.

4. The key negotiation method as described in claim 1, characterized in that, Step (a) further includes: Each participant generates public auxiliary information and pseudo-random numbers based on a fuzzy generation algorithm, using their random feature information and public parameters as inputs. A key generation algorithm generates public and private key pairs for each participant, using their pseudo-random numbers and stored public parameters as inputs. The public auxiliary information and public key for each participant are then stored.

5. The key negotiation method as described in claim 1, characterized in that, The predetermined fuzzy random source is the specific biological information of each participant; The method further includes: For participant A and participant B, respectively, random feature information is extracted using a feature extraction network based on the specific biological information.

6. The key negotiation method as described in claim 1, characterized in that, The predetermined fuzzy random source is a specific physical non-clonable function corresponding to each participant; The method further includes: For participant A and participant B, their respective random feature information is extracted using a reusable fuzzy extractor based on the specific physical non-cloning function. The reusable fuzzy extractor consists of a security profile, a strong extractor, and a key expansion function.

7. A key negotiation system, characterized in that, This includes the first subsystem on the side of participant A and the second subsystem on the side of participant B; The first subsystem includes: The first initialization module is used to generate the public parameters of this subsystem based on the generation algorithm of the classic AKE protocol; The first registration module is used to sample the predetermined fuzzy random source of participant A to obtain its own random feature information, and obtain the public auxiliary information and public key and private key pair of participant A based on the random feature information and public parameters of participant A. The first storage module is used to store the public parameters, the public auxiliary information of participant A, and the public key; The first protocol interaction module is used by participant A to sample a predetermined fuzzy random source to obtain second random feature information, and then uses this second random feature information as input to obtain pseudo-random numbers and inter-round public auxiliary information based on a fuzzy generation algorithm. The first private key for regeneration is obtained by using the second random feature information and the stored public auxiliary information as inputs based on the fuzzy regeneration algorithm and the key generation algorithm. A probabilistic algorithm based on the classic AKE protocol generates a message by using the stored public parameters, the first private key, and the public key of participant B as inputs, and explicitly inputting the pseudo-random number as a random number. The system retrieves the wheel-to-wheel status and assigns it to publicly available auxiliary information for that wheel, and responds to received messages. Participant A samples a predetermined fuzzy random source to obtain fourth random feature information. Based on the fuzzy regeneration algorithm, using this fourth random feature information and the inter-round public auxiliary information as input, a regenerated pseudo-random number is obtained. Based on the fuzzy regeneration algorithm and the key generation algorithm, using the fourth random feature information and the stored public auxiliary information as input, a regenerated first private key is obtained. Finally, based on the deterministic algorithm of the classic AKE protocol, using the stored public parameters and the message... The pseudo-random number, the first private key, and the public key of participant B are used as inputs to generate the acceptance state. and negotiation key ; The first sending module is used to send messages. To the second subsystem; The first receiving module is used to receive messages from the second subsystem. ; The second subsystem includes: The second initialization module is used to generate the public parameters of the subsystem based on the generation algorithm of the classic AKE protocol; The second registration module is used to sample a predetermined fuzzy random source of participant B to obtain the random feature information of participant B, and to obtain the public auxiliary information and public key and private key pair of participant B based on the random feature information of participant B and the public parameters. The second storage module is used to store the public parameters, the public auxiliary information of participant B, and the public key; The second receiving module is used to receive the message from the first subsystem. ; The second protocol interaction module is used to respond to received messages. Participant B samples a predetermined fuzzy random source to obtain third random feature information. Based on the fuzzy regeneration algorithm and key generation algorithm, using this third random feature information and stored public auxiliary information as input, a regenerated second private key is obtained. A probabilistic algorithm based on the classic AKE protocol is then used with stored public parameters and messages... The message is generated using the second private key and participant A's public key as input. Acceptance status and negotiation key and send a message To the side of participant A; The second sending module is used to send the message. To the first subsystem.

8. The key negotiation system as described in claim 7, characterized in that, The first registration module and the second registration module are further configured to generate the public auxiliary information and pseudo-random number of each participant based on the random feature information and public parameters of each participant using a fuzzy generation algorithm, generate the public key and private key pair of each participant based on the pseudo-random number of each participant and the stored public parameters using a key generation algorithm, and store the public auxiliary information and public key of each participant.

9. The key negotiation system as described in claim 7, characterized in that, The predetermined fuzzy random source is the specific biological information of each participant; The first protocol interaction module is further configured to extract corresponding random feature information for participant A based on the specific biological information using a feature extraction network, and the second protocol interaction module is further configured to extract corresponding random feature information for participant B based on the specific biological information using a feature extraction network.

10. The key negotiation system as described in claim 7, characterized in that, The predetermined fuzzy random source is a specific physical non-clonable function corresponding to each participant; The first protocol interaction module is further configured to extract the corresponding random feature information of participant A based on the specific physical non-cloning function using a reusable fuzzy extractor, and the second protocol interaction module is further configured to extract the corresponding random feature information of participant B based on the specific physical non-cloning function using a reusable fuzzy extractor. The reusable fuzz extractor consists of a security profile, a strong extractor, and a key expansion function.

Citation Information

Patent Citations

  • Random number generation, regeneration and tracking method based on non-uniform random source in group, and electronic device

    CN112835554A

  • Physical layer security key extraction method based on fuzzy extractor negotiation

    CN113746624A