A Private Key Security Management Method and System Based on Random Number Encryption Keys
By generating private keys and public keys on the user-side device, and using random number encryption mechanism and SMS verification code authentication mechanism, the existing private key management methods are solved, and high security management of private keys is achieved and the operation process is simplified.
Patent Information
- Application Number
- CN202410538557.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-30
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-04-30
AI Technical Summary
The existing private key management methods are complex in ensuring security, and are vulnerable to attacks in frequent authentication and digital signature scenarios, especially when brute-force network cracking.
The user-side device uses a specific algorithm to generate a private key and a public key, and encrypts and protects the private key through an encryption mechanism based on random numbers. Combined with SMS verification code authentication and automatic deletion mechanism, the checksum deletion operation of the private key is completed.
Effectively reduce the risk of private key stolen, enhance the security of the private key usage process, simplify user operation processes, and improve user experience.
Smart Images

Figure CN118400098B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security encryption technology, and particularly to a private key security management method and system based on a random number encryption key. Background Art
[0002] In the digital age, digital signature has become a key technology to ensure the authenticity and integrity of electronic documents. It allows data receivers to verify whether an electronic document has been tampered with and indeed comes from the claimed sender. Digital signature relies on asymmetric encryption technology, where the sender uses a private key for signing, and the receiver uses the corresponding public key for verification. Therefore, the security management of the private key is directly related to the reliability of digital signature and the security of the entire information system.
[0003] Traditionally, the storage and management of private keys mostly rely on physical security devices (such as smart cards, USB security keys, etc.) or password-protected software storage. However, these methods have many limitations. Physical devices are easy to lose or damage, and are inconvenient to use in a multi-device environment; software storage methods are at risk of malware attacks. In recent years, cloud storage has gradually become one of the choices for private key storage due to its convenience, but the security of cloud services is often questioned. Once the cloud service provider suffers a data breach, the user's private key is extremely likely to be leaked, causing irreparable losses.
[0004] Patent No. CN2015101241387 discloses an identity authentication security management system, including a key generation device and a security terminal. The key generation device generates an identity-based key pair through a seed matrix built into the hardware. The security terminal has a built-in unique key pair. The security terminal sends out the device public key, identity, and random number, and signs with the device private key, and then sends it through a data interface or network to the key generation device. The key generation device generates an identity private key according to the identity, encrypts it with the device public key of the security terminal, and signs with the management private key, and then sends it to the security terminal through a data interface or network interface. The identity private key is decrypted and stored inside the security device and cannot be read externally.
[0005] Patent No. CN2022113383694 discloses a cloud password security management method, system, device and storage medium. The method includes: obtaining the request information of a user, calling a random number generation interface according to the request information to generate a key, encrypting the password information in the request information with the key to obtain encrypted information, obtaining the identity information of the user, generating a public key and a private key according to the identity information and an asymmetric encryption algorithm, and encrypting the key with the public key to obtain an encrypted key, integrating the encrypted information, the encrypted key and the public key by using an information integration model to obtain an encrypted string, and processing the encrypted characters according to a preset rule to obtain an encrypted password; the above invention greatly improves the security of user data and effectively reduces the risk of hackers or malicious programs attacking the cloud platform, causing user information and data leakage and resulting in property losses.
[0006] However, the above patent cannot effectively simplify the operation process of users, and the security of the private key will be greatly threatened when an attacker uses brute-force network cracking; therefore, the current challenge is how to simplify the user operation process while ensuring high security, especially in scenarios where identity verification and digital signatures are frequently required. Summary of the Invention
[0007] The purpose of the present invention is to provide a private key security management method and system based on a random number encryption key, which can directly generate a private key and a public key by using a specific algorithm through a user-side device, and encrypt and protect the private key through an encryption mechanism based on a random number, supplemented by a short message verification code authentication mechanism and an automatic deletion mechanism to complete the verification and deletion operations of the private key; the present invention can effectively reduce the risk of the private key being stolen and enhance the security of the private key usage process.
[0008] The present invention uses the following technical solutions:
[0009] A private key security management system based on a random number encryption key, including a key expansion module, a random number generation module, a random key generation module, an encryption module, a communication module, a certificate application module, a decryption module and a cleaning module; wherein,
[0010] The key expansion module is used to generate a private key and a public key according to the system environment information and biometric information of the user-side device;
[0011] The user-side device includes a laptop computer, a tablet computer and a mobile phone; the system environment information includes the system version number, system type, system architecture and system performance; the biometric information includes fingerprint information, voice information and facial information;
[0012] The random number generation module is used to generate a group of N-bit random numbers U;
[0013] A random key generation module, which is used to perform a hashing operation on the generated N-bit random number U to form an encryption key;
[0014] An encryption module, which is used to encrypt the private key by using the encryption key and the chaotic sequence to generate an encrypted private key;
[0015] A communication module, which is used to notify the cloud service system to send a short message verification code to the user-side device; the short message verification code is a group of N-bit random numbers U;
[0016] A certificate application module, which is used to generate an application for a temporary certificate according to the obtained public key;
[0017] A decryption module, which is used to perform a signature operation by using the encrypted private key on the user-side device after the user inputs the short message verification code;
[0018] A cleaning module, which is used for the user-side device to automatically delete the private key and the temporary certificate.
[0019] Preferably, the working process of the key expansion module is as follows:
[0020] First, the key expansion module integrates the system environment information and biometric information of the user-side device into environmental parameters:
[0021] E = DF ⊕ NP ⊕ OSV(1)
[0022] Wherein, E represents the environmental parameter, DF represents the fingerprint hash value, NP represents the network address hash value, OSV represents the type and version number of the operating system, and ⊕ represents the exclusive OR symbol;
[0023] Then, the key expansion module generates an expansion key according to the user's original key and the environmental parameters, and divides the expansion key into a public key and a private key:
[0024]
[0025] Wherein, EK represents the expansion key, H() represents the hash function, K represents the user's original key, P represents the public key, and S represents the private key.
[0026] Preferably, the working process of the encryption module is as follows:
[0027] First, the encryption module initializes the chaotic sequence by using the chaotic function:
[0028] x (k,i+1) = foreach(Chaos k (x (k,i) ),k)(3)
[0029] Wherein, x represents the chaotic sequence, k represents the k-th dimension of the chaotic sequence, i represents the i-th item of the chaotic sequence, x(k,i+1) represents the i-th item of the chaotic sequence in the k-th dimension, foreach() represents the loop function, and Chaos k () represents the chaotic function in the k-th dimension;
[0030] Subsequently, the encryption module dynamically generates the substitution box function and the permutation box function by using the chaotic sequence and the extended key:
[0031] ABox = GenerateBoxes(x (1,t) ,…,x (m,t) , EK, C)(4)
[0032] SBox = GenerateBoxes(x (m,1) ,…,x (m,t) , EK, C)(5)
[0033] where ABox represents the permutation box function, GenerateBoxes() represents the box generation function, t represents the total number of items in the chaotic sequence, m represents the total number of dimensions of the chaotic sequence, C represents the total number of decryptions, and SBox represents the substitution box function;
[0034] Then, the encryption module performs non-linear processing on the encryption key by using the substitution box function and the permutation box function to obtain the confused ciphertext:
[0035] MP j = SBox[ABox[M j ⊕x (k,i) (6)
[0036] where MP represents the confused ciphertext, j represents the j-th item of the confused ciphertext, MP j represents the j-th item of the confused ciphertext, M represents the encryption key, and M j represents the j-th item of the encryption key;
[0037] Finally, the encryption module encrypts the private key according to the obtained confused ciphertext to obtain the encrypted private key:
[0038]
[0039] where CT represents the ciphertext of the encrypted private key, n represents the total number of items in the confused ciphertext, represents the Hadamard inner product, and ∏ represents the product of N items.
[0040] Preferably, the working process of the decryption module is as follows:
[0041] First, the decryption module extracts the remaining number of decryptions in the substitution box function and the permutation box function and performs verification:
[0042] C = ExtractC(SBox, ABox, EK)(8)
[0043] Among them, ExtractC() represents the extraction function;
[0044] Then, the decryption module performs inverse processing on the substitution box function and the permutation box function to decrypt the confused ciphertext:
[0045]
[0046] Among them, ⊙ represents the Hadamard outer product; the superscript -1 represents the inverse function of the corresponding function;
[0047] Subsequently, the decryption module obtains the encryption key and updates the substitution box function, the permutation box function, and the remaining decryption times:
[0048]
[0049] Among them, ECC -1 () represents the inverse elliptic curve function, DCT -1 () represents the inverse discrete cosine function, DFT -1 () represents the inverse Fourier transform function;
[0050] C , = C - 1(11)
[0051] ABox , = GenerateBoxes(x (1,t) , …, x (m,t) , EK, C , )(12)
[0052] SBox , = GenerateBoxes(x (m,1) , …, x (m,t) , EK, C , )(13)
[0053] Among them, C , represents the updated remaining decryption times, ABox , represents the updated permutation box function, SBox , represents the updated substitution box function;
[0054] Finally, the user uses the encryption private key to perform a signature operation through the user - side device.
[0055] Preferably, the cleaning module further includes an automatic deletion mechanism: if the user does not use the private key within the preset time or has completed the signature operation, the user - side device will automatically delete the private key and the temporary certificate; the preset time is automatically determined by the user - side device according to the security policy.
[0056] Preferably, the random number generation module generates a set of N - bit random numbers U using a security algorithm; N is 6.
[0057] Preferably, the SMS verification code is used to verify the user's identity to authorize the user to perform a signature operation using the encryption private key.
[0058] It also includes a private key security management method based on a random number encryption key, including the following steps:
[0059] S1: The user - side device generates a pair of private key and public key through the key expansion module;
[0060] S2: Generate a set of N - bit random numbers U through the random number generation module, and perform a hash operation on the N - bit random numbers through the random key generation module to form an encryption key;
[0061] S3: Use the encryption key and the chaotic sequence to encrypt the private key through the encryption module to generate an encrypted private key;
[0062] S4: Notify the cloud service system to send an SMS verification code to the user - side device through the communication module, and generate an application for a temporary certificate according to the generated public key through the certificate application module;
[0063] S5: After the user inputs the SMS verification code, the decryption module enables the user to perform a signature operation using the encrypted private key through the user - side device;
[0064] S6: If the user does not use the private key or complete the signature operation within the preset time, the user - side device automatically deletes the private key and the temporary certificate through the cleaning module.
[0065] In the present invention, the system environment information and biometric information of the user - side device are combined through the key expansion module to generate a private key and a public key; the private key is non - linearly processed by the encryption module using the chaotic sequence and the extended key to obtain the encrypted private key; the encrypted key is obtained by decrypting the confused ciphertext through the decryption module using the substitution box and the permutation box, and at the same time, the substitution box, the permutation box and the remaining decryption times are updated; the security risk of long - term storage of the private key is reduced through the automatic deletion mechanism, the security of the private key usage process is enhanced, and the convenience of user operation is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0067] Figure 1Schematic diagram of a private key security management system based on a random number encryption key;
[0068] Figure 2 Principle block diagram of a private key security management method based on a random number encryption key. Specific implementation mode
[0069] The present invention will be described in detail below in conjunction with the accompanying drawings and embodiments:
[0070] As Figure 1 shown, a private key security management system based on a random number encryption key according to the present invention includes a key expansion module, a random number generation module, a random key generation module, an encryption module, a communication module, a certificate application module, a decryption module, and a cleaning module;
[0071] In the present invention, the key expansion module is used to generate corresponding private keys and public keys according to the system environment information and biometric information of the user-side device;
[0072] Among them, the user-side device includes a laptop computer, a tablet computer, and / or a mobile phone; the system environment information includes a system version number, a system type, a system architecture, and / or a system performance; the biometric information includes fingerprint information, voice information, and / or facial information;
[0073] In this embodiment, the working process of the key expansion module is as follows:
[0074] First, the key expansion module integrates the system environment information and biometric information of the user-side device into an environmental parameter:
[0075] E = DF ⊕ NP ⊕ OSV(1)
[0076] Among them, E represents the environmental parameter, DF represents the fingerprint hash value, NP represents the network address hash value, OSV represents the type and version number of the operating system, and ⊕ represents the exclusive OR symbol;
[0077] Then, the key expansion module generates an extended key according to the user's original key and the environmental parameter, and divides the extended key into a public key and a private key:
[0078]
[0079] Among them, EK represents the extended key, H() represents the hash function, K represents the user's original key, P represents the public key, and S represents the private key;
[0080] In the present invention, the random number generation module is used to generate a set of N-bit random numbers U;
[0081] In this embodiment, N can take 6, and the random number generation module uses a security algorithm to generate a set of N-bit random numbers U;
[0082] In the present invention, a random key generation module is configured to form an encryption key by performing a hash operation on the generated N-bit random numbers;
[0083] In the present invention, an encryption module is configured to encrypt a private key by using the encryption key and a chaotic sequence to generate an encrypted private key;
[0084] In this embodiment, the working process of the encryption module is as follows:
[0085] First, the encryption module initializes the chaotic sequence by using a chaotic function:
[0086] x (k,i+1) = foreach(Chaos k (x (k,i) ), k)(3)
[0087] where x represents the chaotic sequence, k represents the k-th dimension of the chaotic sequence, i represents the i-th item of the chaotic sequence, x (k,i+1) represents the i-th item of the chaotic sequence in the k-th dimension, foreach() represents a loop function, and Chaos k () represents the chaotic function in the k-th dimension;
[0088] Subsequently, the encryption module dynamically generates a substitution box function and a permutation box function by using the chaotic sequence and an extended key:
[0089] ABox = GenerateBoxes(x (1,t) , …, x (m,t) , EK, C)(4)
[0090] SBox = GenerateBoxes(x (m,1) , …, x (m,t) , EK, C)(5)
[0091] where ABox represents the permutation box function, GenerateBoxes() represents a box generation function, t represents the total number of items of the chaotic sequence, m represents the total number of dimensions of the chaotic sequence, C represents the total number of decryptions, and SBox represents the substitution box function;
[0092] Then, the encryption module performs a non-linear process on the encryption key by using the substitution box function and the permutation box function to obtain a confused ciphertext:
[0093] MP j = SBox[ABox[M j ⊕ x (k,i) (6)
[0094] where MP represents the confused ciphertext, j represents the j-th item of the confused ciphertext, MP jDenote the j-th item of the obfuscated ciphertext, M represents the encryption key, M j Denote the j-th item of the encryption key;
[0095] Finally, the encryption module encrypts the private key according to the obtained obfuscated ciphertext to obtain the encrypted private key:
[0096]
[0097] Among them, CT represents the ciphertext of the encrypted private key, n represents the total number of items of the obfuscated ciphertext, Denote the Hadamard inner product, ∏ represents the product of N items;
[0098] In this embodiment, the chaotic sequence is a sequence with chaotic characteristics generated by a chaotic model; the chaotic sequence can be generated through multiple iterations by the following methods: Logistic mapping, PWLCM mapping, Singer mapping, Sine mapping, Gaussian mapping, tent mapping, and so on;
[0099] The communication module is used to notify the cloud service system to send a short message verification code to the user-side device; the short message verification code is a group of N-bit random numbers U;
[0100] The certificate application module is used to generate an application for a temporary certificate according to the obtained public key;
[0101] The decryption module is used for the user to perform a signature operation using the encrypted private key through the user-side device after the user inputs the short message verification code;
[0102] In this embodiment, the working process of the decryption module is as follows:
[0103] First, the decryption module extracts the remaining decryption times in the substitution box function and the permutation box function and performs verification:
[0104] C = ExtractC(SBox, ABox, EK)(8)
[0105] Among them, ExtractC() represents the extraction function;
[0106] Then, the decryption module performs inverse processing on the substitution box function and the permutation box function to decrypt the obfuscated ciphertext:
[0107]
[0108] Among them, ⊙ represents the Hadamard outer product; the superscript -1 represents the inverse function of the corresponding function;
[0109] Subsequently, the decryption module obtains the encryption key and updates the substitution box function, the permutation box function, and the remaining decryption times:
[0110]
[0111] Among them, ECC -1 () represents the inverse elliptic curve function, and DCT -1 () represents the inverse discrete cosine function, and DFT -1 () represents the inverse Fourier transform function;
[0112] C , = C-1(11)
[0113] ABox , = GenerateBoxes(x (1,t) ,…,x (m,t) , EK, C , )(12)
[0114] SBox , = GenerateBoxes(x (m,1) ,…,x (m,t) , EK, C , )(13)
[0115] Among them, C , represents the updated remaining decryption times, ABox , represents the updated substitution box function, and SBox , represents the updated substitution box function;
[0116] Finally, the user uses the encryption private key for signature operation through the user-side device;
[0117] The cleaning module is used for the user-side device to automatically delete the private key and the temporary certificate;
[0118] In this embodiment, the cleaning module includes an automatic deletion mechanism: if the user does not use the private key within the preset time or has completed the signature operation, the user-side device will automatically delete the private key and the temporary certificate; the preset time is automatically determined by the user-side device according to the security policy.
[0119] As Figure 2 shown, it also includes a private key security management method based on a random number encryption key, including the following steps:
[0120] S1: The user-side device generates a pair of private key and public key through the key expansion module;
[0121] S2: Generate a set of N-bit random numbers U through the random number generation module, and perform a hash operation on the N-bit random numbers through the random key generation module to form an encryption key;
[0122] S3: Encrypt the private key through the encryption module using the encryption key and the chaotic sequence to generate an encrypted private key;
[0123] S4: Notify the cloud service system via the communication module to send a SMS verification code to the user-side device, and generate an application for a temporary certificate by the certificate application module based on the generated public key.
[0124] S5: After the user inputs the SMS verification code, the decryption module enables the user to perform a signature operation using the encryption private key on the user-side device.
[0125] S6: If the user does not use the private key or complete the signature operation within the preset time, the user-side device automatically deletes the private key and the temporary certificate through the cleaning module.
[0126] Embodiment:
[0127] The user-side device integrates the system environment information and biometric information of the user-side device into environmental parameters through the key expansion module, and generates an extended key based on the user's original key and environmental parameters. At the same time, the extended key is divided into a public key and a private key; wherein, the user-side device includes a laptop, a tablet computer, and a mobile phone; the system environment information includes the system version number, system type, system architecture, and system performance; the biometric information includes fingerprint information, voice information, and facial information; a set of N-bit random numbers are generated by the random number generation module using a security algorithm, and N can take 6; the generated N-bit random numbers are subjected to a hash operation by the random key generation module to form an encryption key.
[0128] Then, the encryption module initializes the chaotic sequence using the chaotic function; then dynamically generates a substitution box function and a permutation box function using the chaotic sequence and the extended key; and performs non-linear processing on the encryption key using the substitution box and the permutation box to obtain the confused ciphertext; at the same time, encrypts the private key according to the obtained confused ciphertext to obtain the encrypted private key; then, notifies the cloud service system via the communication module to send a SMS verification code to the user-side device; the SMS verification code is a set of N-bit random numbers; at the same time, generates an application for a temporary certificate by the certificate application module according to the obtained public key.
[0129] Finally, after the user inputs the SMS verification code, the SMS verification code verifies the user's identity to authorize the user to perform a signature operation using the encrypted private key; extracts and verifies the remaining decryption times in the substitution box and the permutation box through the decryption module; and performs an inverse process on the substitution box and the permutation box to decrypt the confused ciphertext; obtains the encryption key, and updates the substitution box, the permutation box, and the remaining decryption times; uses the automatic deletion mechanism through the cleaning module: if the user does not use the private key or has completed the signature operation within the preset time, the user-side device will automatically delete the private key and the temporary certificate; wherein, the preset time is automatically determined by the user-side device according to the security policy.
Claims
1. A private key security management system based on random number encryption keys, characterized in that: It includes a key expansion module, a random number generation module, a random key generation module, an encryption module, a communication module, a certificate application module, a decryption module and a cleaning module; wherein, A key expansion module, used to generate a private key and a public key according to the system environment information and biometric information of the user-side device; User-side devices include laptops, tablets, and mobile phones; system environment information includes system version number, system type, system architecture, and system performance; biometric information includes fingerprint information, voice information, and facial information; A random number generation module, used to generate a set of N-bit random numbers U; A random key generation module, used for performing a hash operation on the generated N-bit random number U to form an encryption key; An encryption module, used for encrypting a private key using an encryption key and a chaotic sequence to generate an encrypted private key; The communication module is used to notify the cloud service system to send a text message verification code to the user's device; the text message verification code is a set of N-digit random numbers U; The certificate application module is used to generate an application for a temporary certificate based on the obtained public key; The decryption module is used to enable the user to sign using the encrypted private key through the user-side device after the user enters the SMS verification code; The cleaning module is used for the user-side device to automatically delete the private key and temporary certificate; The workflow of the encryption module is: First, the encryption module uses the chaotic function to initialize the chaotic sequence: x (k,i+1) =foreach(Chaos k (x (k,i) ),k) (3) Among them, x represents the chaotic sequence, k represents the kth dimension of the chaotic sequence, i represents the i-th item of the chaotic sequence, and x (k,i+1) represents the i-th item of the chaotic sequence of the k-th dimension, foreach() represents a loop function, Chaos k () represents the chaotic function of the kth dimension; Subsequently, the encryption module uses the chaotic sequence and the extended key to dynamically generate the substitution box function and the permutation box function: ABox=GenerateBoxes(x (1,t) ,…,x (m,t) ,EK,C) (4) SBox=GenerateBoxes(x (m,1) ,…,x (m,t) ,EK,C) (5) Among them, ABox represents the substitution box function, GenerateBoxes() represents the box generation function, t represents the total number of terms in the chaotic sequence, m represents the total number of dimensions in the chaotic sequence, C represents the total number of decryptions, SBox represents the substitution box function, and EK represents the extended key; Then, the encryption module uses the substitution box function and the permutation box function to perform nonlinear processing on the encryption key to obtain the obfuscated ciphertext: Among them, MP represents the obfuscated ciphertext, j represents the jth item of the obfuscated ciphertext, and MP j represents the jth item of the obfuscated ciphertext, M represents the encryption key, and M j represents the jth item of the encryption key; Finally, the encryption module encrypts the private key according to the obtained obfuscated ciphertext to obtain the encrypted private key: Among them, CT represents the ciphertext of the encrypted private key, n represents the total number of obfuscated ciphertext items, represents the Hadamard inner product, Π represents the N-term product, and S represents the private key.
2. The private key security management system based on random number encryption key according to claim 1, characterized in that: The workflow of the key expansion module is: First, the key expansion module integrates the system environment information and biometric information of the user-side device into environmental parameters: Where E represents the environment parameter, DF represents the fingerprint hash value, NP represents the network address hash value, OSV represents the type and version number of the operating system, and ⊕ represents the XOR symbol; The key expansion module then generates an extended key based on the user's original key and environment parameters, and divides the extended key into a public key and a private key: Among them, H() represents the hash function, K represents the user's original key, and P represents the public key.
3. The private key security management system based on random number encryption key according to claim 1, characterized in that: The workflow of the decryption module is: First, the decryption module extracts the remaining decryption times in the substitution box function and the permutation box function and verifies them: C=ExtractC(SBox,ABox,EK) (8) Among them, ExtractC() represents the extraction function; Then, the decryption module inverses the substitution box function and the permutation box function to decrypt the obfuscated ciphertext: Among them, ⊙ represents the Hadamard outer product; the superscript -1 represents the inverse function of the corresponding function; Then, the decryption module obtains the encryption key and updates the substitution box function, replacement box function and remaining decryption times: Among them, ECC -1 () represents the inverse elliptic curve function, DCT -1 () represents the inverse discrete cosine function, DFT -1 () represents the inverse Fourier transform function; C'=C-1 (11) ABox’=GenerateBoxes(x (1,t) ,…,x (m,t) ,EK,C’) (12) SBox’=GenerateBoxes(x (m,1) ,…,x (m,t) ,EK,C’) (13) Wherein, C' represents the remaining number of decryption times after the update, ABox' represents the updated substitution box function, and SBox' represents the updated substitution box function; Finally, the user uses the encrypted private key to perform the signing operation through the user-side device.
4. The private key security management system based on random number encryption key according to claim 1, characterized in that: The cleaning module also includes an automatic deletion mechanism: if the user does not use the private key or completes the signing operation within a preset time, the user-side device will automatically delete the private key and temporary certificate; the preset time is automatically determined by the user-side device according to the security policy.
5. The private key security management system based on random number encryption key according to claim 1, characterized in that: The random number generation module generates a set of N-bit random numbers U using a security algorithm; N is 6.
6. The private key security management system based on random number encryption key according to claim 1, characterized in that: The SMS verification code is used to verify the user's identity in order to authorize the user to use the encrypted private key for signing operations.
7. A private key security management method based on a random number encryption key, applied to the private key security management system according to any one of claims 1 to 6, characterized in that: The following steps are involved: S1: The user-side device generates a pair of private key and public key through the key expansion module; S2: Generate a set of N-bit random numbers U through the random number generation module, and perform a hash operation on the N-bit random numbers through the random key generation module to form an encryption key; S3: Encrypting the private key by using the encryption key and the chaotic sequence through the encryption module to generate an encrypted private key; S4: Notify the cloud service system through the communication module to send a text message verification code to the user-side device, and generate an application for a temporary certificate based on the generated public key through the certificate application module; S5: After the user enters the SMS verification code, the decryption module uses the encrypted private key to perform a signing operation through the user-side device; S6: After the user does not use the private key or complete the signing operation within a preset time, the user-side device automatically deletes the private key and temporary certificate through the cleanup module.
Citation Information
Patent Citations
Bidirectional authentication method, terminal and server
CN111931158A
Intelligent encryption method and system for message
CN116707908A