Communication encryption method, system and storage medium based on two-way secure key exchange
By adopting the DKE basic key exchange system and the two-way secure key exchange method of Dilithium digital signature in communication encryption, the problem of not having anti-quantum security and average situation security in the prior art is solved, and high security and high efficiency communication encryption is achieved.
Patent Information
- Application Number
- CN202410915233.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-09
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-07-09
AI Technical Summary
The existing X3DH key exchange protocol does not have the ability to resist quantum security and average situation security, and there is a possibility of security weaknesses.
A two-way secure key exchange method based on the DKE basic key exchange system and Dilithium digital signature is adopted to generate a shared private key through three DKE basic key exchange and Dilithium signature verification, and the communication content is encrypted using AES-256.
It realizes anti-quantum security and improves the average situation security of encryption protocols, enhances the security and efficiency of communication encryption, and ensures the security of multiple consecutive communication sessions.
Smart Images

Figure CN118869203B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a communication encryption method, system and storage medium based on bidirectional secure key exchange. Background Art
[0002] Real-time chat communication is a basic requirement of social software. Traditional social software such as WeChat and QQ do not include end-to-end encryption functions, that is, chat information is actually always completely exposed to the monitoring of the software server, which increases the risk of personal data privacy leakage. Since 2020, the introduction of laws such as the "Data Security Law" has marked that the Chinese government's attention to personal data privacy protection has risen to a new level. Message encryption, as the most common means of privacy protection, plays an important role in the field of privacy protection in real-time chats. Currently, internationally popular instant messaging software such as Telegram and WhatsApp all provide end-to-end encryption functions. The built-in protocol is generally the X3DH key exchange protocol, which uses the X25519 / X248 elliptic curve and the difficulty of the elliptic curve discrete logarithm problem, combined with digital signatures, to achieve key exchange that is resistant to man-in-the-middle attacks and is used for encrypted chats. However, it has the following shortcomings:
[0003] (1) It cannot provide quantum security. The security of the X3DH key exchange protocol is based on the elliptic curve discrete logarithm problem, which can be effectively solved by Shor's quantum algorithm in polynomial time. That is, if the quantum algorithm can be effectively run on a quantum computer, the security of the X3DH key exchange protocol will no longer exist.
[0004] (2) Specific elliptic curves may still have security weaknesses. Although the X25519 / X248 elliptic curves have been applied to network security, they are elliptic curves with specific parameters and cannot provide security guarantees under average conditions. In other words, in theory, there is still the possibility that the elliptic curves may have security weaknesses due to the specificity of their parameters.
[0005] In order to solve the problem that the existing X3DH key exchange protocol does not have quantum security and average case security, a communication encryption method, system and storage medium based on two-way secure key exchange are proposed. Summary of the Invention
[0006] The embodiments of the present invention provide a communication encryption method, system, and storage medium based on bidirectional secure key exchange, so as to at least solve the problem that the related art lacks quantum security and average case security.
[0007] According to one embodiment of the present invention, a communication encryption method based on bidirectional secure key exchange is proposed, comprising:
[0008] The communicating parties use the DKE basic key exchange system to generate fixed public keys, fixed private keys, pre-public keys and pre-private keys;
[0009] Use the fixed private key to obtain the Dilithium signature of the pre-private key and use it to generate the key parameter set;
[0010] After obtaining the other party's key parameter set, the communicating party uses the other party's fixed public key to verify the Dilithium signature of the pre-private key;
[0011] If the signature verification is successful, the communicating party generates its own temporary public key;
[0012] Perform DKE basic key exchange based on its own fixed public key, temporary public key and the other party's fixed public key and pre-public key;
[0013] Use the KDF function to process the result of the basic key exchange to generate a shared private key;
[0014] Use the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext, and then send the ciphertext or plaintext along with its own fixed public key and temporary public key to the other party;
[0015] Within a preset time period after the completion of the first communication, the communicating parties calculate the key for each communication based on the hash function and use it for subsequent encrypted communications.
[0016] In an exemplary embodiment, the communicating parties generate a fixed public key, a fixed private key, a pre-public key, and a pre-private key using a DKE-based key exchange system, including the following steps:
[0017] Construct a residue class ring R based on a set of polynomials with coefficients modulo q q ;
[0018] According to the randomly uniformly generated ring R q The polynomial a and discrete Gaussian distribution generate the private key and the corresponding fixed public key
[0019] Generate a pre-private key based on discrete Gaussian distribution and the corresponding pre-public key
[0020] In an exemplary embodiment, the method of obtaining the Dilithium signature of the pre-public key using the fixed private key and generating the key parameter set using the signature comprises the steps of:
[0021] Repeatedly randomly select a polynomial vector y with an infinite norm less than γ1 and calculate the high-order bit w1 and low-order bit w0 of a·y with a bound of 2γ2; where γ1 and γ2 are preset parameters;
[0022] Calculate the spherical hash c and calculate the vector z based on the hash value and the fixed private key;
[0023] Repeat the above steps until the infinity norm of vector z is less than γ1-β and w0-2c·s B When the infinite norm of is less than γ2-β, the output signature s=(z, c); where β is a preset parameter;
[0024] Based on the fixed public key FK B , Pre-public key PreK B , signature s generates key parameter set P B .
[0025] In an exemplary embodiment, after obtaining the other party's key parameter set, the communicating party uses the other party's fixed public key to verify the Dilithium signature of the pre-public key, including the steps of:
[0026] The communicating party obtains the other party's key parameter set P from the server B ;
[0027] Calculate the verification vector w1' based on the public key and Dilithium signature;
[0028] If and only if the infinity norm of vector z is less than γ1-β and c=H(PreK B ||w1'), the Dilithium signature verification of the pre-public key is successful.
[0029] In an exemplary embodiment, the communication party generates its own temporary public key, comprising the steps of:
[0030] Generate private keys based on discrete Gaussian distribution
[0031] Generate the corresponding temporary public key based on the temporary private key
[0032] In an exemplary embodiment, performing DKE basic key exchange based on one's own fixed public key, temporary public key, and the other party's fixed public key and pre-public key includes the following steps:
[0033] Confirm the basic DKE key exchange parameters, including the modulus q and dimension n;
[0034] The DKE basic key exchange protocol is used to calculate the first exchange bit string D1=DKE(FK A , PreK B );
[0035] The DKE basic key exchange protocol is used to calculate the second exchange bit string D2 = DKE (TK A, FK B );
[0036] The DKE basic key exchange protocol is used to calculate the third exchange bit string D3 = DKE (TK A , PreK B ).
[0037] In an exemplary embodiment, the use of the KDF function to process the result of the basic key exchange to generate the shared private key is that the communicating parties use SHA-256 HMAC as the KDF function to generate the shared private key SK=KDF(D1||D2||D3).
[0038] In an exemplary embodiment, the method of using the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext and sending the ciphertext or plaintext together with the fixed public key and the temporary public key to the other party includes the following steps:
[0039] The communicating parties use the shared private key SK to perform AES-256 encryption on the first communication message M, obtaining the ciphertext C = Enc(SK, M);
[0040] The communication party sets the parameter set P A :(FK A , TK A , C) send to the other party;
[0041] The other party calls the DKE basic key exchange protocol and KDF function to generate the same shared private key SK and uses the shared private key SK to perform AES-256 decryption on the encrypted communication information C to obtain the original communication information M = Dec(SK, C);
[0042] Complete key exchange and first encrypted communication.
[0043] In an exemplary embodiment, within a preset time period after the completion of the first communication, the communicating parties calculate a key for each communication based on a hash function and use it for subsequent encrypted communications, including the steps of:
[0044] Within a preset time period after the completion of the first communication, both parties use the hash function SHA-256 and the counter mode to calculate the communication key SK for the i-th communication. i =SHA-256(SK||i);
[0045] Both parties use the communication key SK i And the AES-256 symmetric encryption algorithm completes the i-th encrypted communication;
[0046] If the communication between the two parties exceeds the preset time period, the two parties will re-execute the key exchange and generate a new shared key for encrypted communication.
[0047] According to another embodiment of the present invention, a computer-readable storage medium is provided, which stores a computer program for electronic data exchange, wherein the computer program executes the above method.
[0048] According to another embodiment of the present invention, a communication encryption system based on bidirectional secure key exchange is provided, comprising:
[0049] processor;
[0050] Memory;
[0051] as well as
[0052] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, the programs causing the computer to perform the above method.
[0053] The communication encryption method, system and storage medium based on bidirectional secure key exchange of the present invention have the following advantages:
[0054] (1) The present invention is based on DKE basic key exchange and Dilithium digital signature, and integrates the encrypted communication process into it to form an overall encrypted communication protocol. It is derived from the difficulty of the lattice problem. Compared with traditional chat encryption technology, it can have quantum-resistant security characteristics.
[0055] (2) Combining three DKE basic key exchanges and Dilithium digital signatures for initial communication encryption can effectively improve the average security of the encryption protocol compared to traditional chat encryption technology solutions.
[0056] (3) After the two communicating parties perform the initial key exchange process, each subsequent encrypted communication within a certain period of time maintains two-way security. Compared with traditional chat encryption schemes, it can effectively improve the security and efficiency of communication encryption.
[0057] (4) Due to the anti-collision characteristics of the Hash function SHA-256, even if the i-th communication key SK is obtained i , it is impossible to recover the original shared key SK, and thus it is impossible to calculate other communication keys. Compared with traditional communication encryption technology solutions, it can effectively ensure the security of multiple consecutive communication sessions. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 This is a flow chart of a communication encryption method based on bidirectional secure key exchange according to an embodiment of the present invention;
[0059] Figure 2 is a flowchart of sub-step S01 of an embodiment of the present invention;
[0060] Figure 3 is a flowchart of sub-step S02 of an embodiment of the present invention;
[0061] Figure 4 is a flowchart of sub-step S03 of an embodiment of the present invention;
[0062] Figure 5 is a flowchart of sub-step S04 of an embodiment of the present invention;
[0063] Figure 6 This is a flowchart of sub-step S05 of an embodiment of the present invention.
[0064] Figure 7 is a flowchart of sub-step S07 of an embodiment of the present invention;
[0065] Figure 8 is a flowchart of sub-step S08 of an embodiment of the present invention;
[0066] Figure 9 The present invention is a schematic diagram of a communication encryption system based on two-way secure key exchange according to an embodiment of the present invention. DETAILED DESCRIPTION
[0067] The present invention will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the invention, but are not intended to limit the present invention in any form. It should be noted that those skilled in the art may make several changes and modifications without departing from the scope of the present invention. These all fall within the scope of protection of the present invention.
[0068] A communication encryption method based on bidirectional secure key exchange according to an embodiment of the present invention is shown in the flowchart as follows: Figure 1 As shown, the steps include:
[0069] Step S01: The communicating parties use the DKE basic key exchange system to generate a fixed public key, a fixed private key, a pre-public key, and a pre-private key;
[0070] Step S02: Use the fixed private key to obtain the Dilithium signature of the pre-private key and generate a key parameter set based on it;
[0071] Step S03: After obtaining the other party's key parameter set, the communicating party uses the other party's fixed public key to verify the Dilithium signature of the pre-private key;
[0072] Step S04: If the signature verification is successful, the communication party generates its own temporary public key;
[0073] Step S05: Perform DKE basic key exchange based on its own fixed public key, temporary public key and the other party's fixed public key and pre-public key;
[0074] Step S06: Use the KDF function to process the result of the basic key exchange to generate a shared private key;
[0075] Step S07: Use the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext, and send the ciphertext or plaintext along with its own fixed public key and temporary public key to the other party;
[0076] Step S08: Within a preset time period after the completion of the first communication, the communicating parties calculate the key for each communication according to the hash function and use it for subsequent encrypted communications.
[0077] In an exemplary embodiment, step S01, the communicating parties use the DKE basic key exchange system to generate a fixed public key and a fixed private key, a pre-public key and a pre-private key, as shown in the flowchart. Figure 2 As shown, the steps include:
[0078] Step S011: Construct a residue class ring R based on a set of polynomials whose coefficients are modulo q q ;
[0079] Step S012: Based on the randomly uniformly generated ring R q The polynomial and discrete Gaussian distribution generate the private key SFK B and the corresponding fixed public key FK B ;
[0080] Step S013: Generate a pre-private key SPreK according to discrete Gaussian distribution B And the corresponding pre-public key PreK B .
[0081] In this embodiment, the two parties in the communication (i.e., voice, text, or other chat sessions) are Alice and Bob;
[0082] Using the DKE basic key exchange system, according to the modulus q, dimension n, and preset parameter σ; let Z q [X] represents the set of all polynomials with coefficients modulo q, constructing the residue class ring R q =Z q [X] / (X n +1), indicating Z q All polynomials in [X] modulo polynomial X n +1 constitutes a ring;
[0083] The communication party Bob randomly and uniformly generates R q Polynomial a on the discrete Gaussian distribution Generate a private key Corresponding public key
[0084] The communicating party Bob calculates another discrete Gaussian distribution Pre-private key Generate the corresponding pre-public key
[0085] Similarly, the communicating party Alice generates her fixed private key based on the DKE basic key exchange system And generate the corresponding fixed public key
[0086] In an exemplary embodiment, step S02 uses a fixed private key to obtain the Dilithium signature of the pre-private key and generates a key parameter set based on it. The flow chart is as follows: Figure 3 As shown, the steps include:
[0087] Step S021, repeatedly randomly select a polynomial vector y whose infinite norm is less than γ1 and calculate the high-order bit w1 and low-order bit w0 of a·y with 2γ2 as the bound; where γ1 and γ2 are preset parameters;
[0088] Step S022, calculate the spherical hash c and calculate the vector z according to the hash value and the fixed private key;
[0089] Step S023, repeat the above steps until the infinite norm of vector z is less than γ1-β and w0-2c·s B When the infinite norm of is less than γ2-β, the output signature s=(z, c); where β is a preset parameter;
[0090] Step S024: According to the fixed public key FK B , Pre-public key PreK B , signature s generates key parameter set P B .
[0091] In this embodiment, for the communication party Bob, parameters γ1, γ2, β are set, and Bob uses the private key SFK B PreK B Execute Dilithium signature, that is, repeatedly randomly select polynomial vector y∈R with infinite norm less than γ1 q , calculate the high bit w1 and low bit w0 of a·y with 2γ2 as the boundary, and calculate the spherical hash c= and z = y + 2cs B , until the infinity norm of z is less than γ1-β and w0-2cs B When the infinite norm of is less than γ2-β, the output signature s=(z,c); Bob will FK B , PreK B , s are packaged into a key parameter set P B , submitted to the server.
[0092] Similarly, any communicating party in the system performs the same steps to generate a key parameter set and submits it to the server.
[0093] In an exemplary embodiment, step S03, the communicating party obtains the other party's key parameter set and uses the other party's fixed public key to verify the Dilithium signature of the pre-public key. The flow chart is as follows: Figure 4 As shown, the steps include:
[0094] Step S031: The communicating party obtains the other party's key parameter set P from the server. B ;
[0095] Step S032: Calculate the verification vector w1' based on the public key and the Dilithium signature;
[0096] Step S033: If and only if the infinite norm of vector z is less than γ1-β and c=H(PreK B ||w1'), the Dilithium signature verification of the pre-public key is successful.
[0097] In this embodiment, after Alice confirms to chat with Bob, the first message M will be sent from Alice to Bob. At this time, the communication party is Alice, and Alice uses the fixed public key FK B =(a,b B =a·s B +2e B ) Verify the pre-public key PreK B Dilithium signature s = (z, c), that is, calculate w′1 as FK B [0]·zc·FK B [1] The high-order bits are bounded by 2γ2, where FK B [i] indicates FK B The i-th component of , if and only if the infinite norm of z is less than γ1-β and c=H(PreK B ||w′1), the Dilithium signature of Bob’s pre-public key is verified successfully.
[0098] In an exemplary embodiment, in step S04, the communication party generates its own temporary public key, as shown in the flowchart. Figure 5 As shown, the steps include:
[0099] Step S041: Generate a temporary private key SFK based on discrete Gaussian distribution A ;
[0100] Step S042: Generate a corresponding temporary public key TK based on the temporary private key A .
[0101] In this embodiment, Alice randomly generates a temporary public key TK in the DKE basic key exchange A , that is, according to the discrete Gaussian distribution Generate a temporary private key And generate the corresponding temporary public key
[0102] In an exemplary embodiment, the step S05 performs DKE basic key exchange based on the fixed public key, temporary public key and the other party's fixed public key and pre-public key. The flow chart is as follows: Figure 6 As shown, the steps include:
[0103] Step S051: confirm the DKE basic key exchange parameters, including the modulus q and the dimension n;
[0104] Step S052: Calculate a first exchange bit string D1 based on the DKE basic key exchange protocol according to the fixed public key of the user and the pre-public key of the other party;
[0105] Step S053: Calculate a second exchange bit string D2 based on the DKE basic key exchange protocol according to the temporary public key and the other party's fixed public key;
[0106] Step S054: Calculate a third exchange bit string D3 using the DKE basic key exchange protocol according to its own temporary public key and the other party's pre-public key.
[0107] In this embodiment, Alice calls the DKE basic key exchange protocol three times, namely: using the DKE basic key exchange protocol to calculate the first exchange bit string D1=DKE(FK A , PreK B ), using the DKE basic key exchange protocol to calculate the second exchange bit string D2 = DKE (TK A , FK B ), using the DKE basic key exchange protocol to calculate the third exchange bit string D3 = DKE (TK A , PreK B ).
[0108] The DKE basic key exchange protocol is described as follows:
[0109] For the public-private key pair (K1, SK1) owned by participant 1 and the public-private key pair (K2, SK2) owned by participant 2, the basic key exchange protocol D=DKE(K1, K2) is run as follows:
[0110] (1) Participant 1 calculates s1 = SK1[0]·K2[1] or Participant 2 calculates s2 = K1[1]·SK2[0];
[0111] (2) Participant 1 or Participant 2 performs error elimination on the obtained polynomial s1 or s2;
[0112] (3) For the polynomial after error elimination, take out each coefficient, modulo 2, and then concatenate them to obtain a bit string D of length n.
[0113] In an exemplary embodiment, in step S06, using a KDF function to process the result of the basic key exchange to generate a shared private key, the communicating parties use SHA-256 HMAC as a KDF function to generate a shared private key SK=KDF(D1||D2||D3).
[0114] In this embodiment, Alice calls HMAC based on SHA-256 as the KDF function to generate a shared private key SK=KDF(D1||D2||D3).
[0115] In an exemplary embodiment, the step S07 uses the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext and sends the ciphertext or plaintext together with its own fixed public key and temporary public key to the other party. The flow chart is as follows: Figure 7 As shown, the steps include:
[0116] Step S071: The communicating parties use the shared private key SK to perform AES-256 encryption on the first communication message M to obtain the ciphertext C=Enc(SK,M);
[0117] Step S072: The communication party sets the parameter P A :(FK A , TK A , C) send to the other party;
[0118] Step S073: The other party calls the DKE basic key exchange protocol and the KDF function to generate the same shared private key SK and uses the shared private key SK to perform AES-256 decryption on the encrypted communication information C to obtain the original communication information M = Dec(SK, C);
[0119] Step S074: Complete key exchange and first encrypted communication.
[0120] In this embodiment, Alice uses the shared private key SK to perform AES-256 encryption on the first chat message M to obtain the ciphertext C = Enc (SK, M); Alice uses the parameter set P A :(FK A , TK A, C) is sent to Bob; Bob receives the parameter set P A After that, get Alice's fixed public key FK A and temporary public key TK A ; Similar to the steps described in the embodiment of step S05, the DKE basic key exchange protocol is called three times to calculate D′1, D′2, and D′3 respectively; Bob also calls the KDF function formed by HMAC based on SHA-256 to generate the same shared private key SK=KDF(D′1||D′2||D′3), and Bob uses the shared private key SK to perform AES-256 decryption on the encrypted chat message C to obtain the original chat message M=Dec(SK, C), completing the key exchange and the first (0th) encrypted chat.
[0121] In an exemplary embodiment, in step S08, after the completion of the first communication, the communicating parties calculate the key for each communication according to the hash function within a preset time period and use it for subsequent encrypted communication. The flow chart is as follows: Figure 8 As shown, the steps include:
[0122] Step S081: Within a preset time period after the completion of the first communication, both parties use the hash function SHA-256 and the counter mode to calculate the communication key SK for the i-th communication. i =SHA-256(SK||i);
[0123] Step S082: Both parties use the communication key SK i And the AES-256 symmetric encryption algorithm completes the i-th encrypted communication;
[0124] Step S083: If the communication between the two parties exceeds the preset time period, the two parties re-execute the key exchange and generate a new shared key for encrypted communication.
[0125] In this embodiment, within a preset time period (key exchange period) after the completion of the first communication, when the two parties will have the i-th chat (i>0), the two parties use the hash function SHA-256 in counter mode to calculate the session key SK of the i-th chat session. i =SHA-256(SK||i); both parties use this session key SK i And the AES-256 symmetric encryption algorithm completes the i-th encrypted chat, that is, the receiver uses the key SK i Encrypt the message and send the ciphertext. The receiver receives the ciphertext and uses SK i Decryption.
[0126] Each communication party needs to regularly change the pre-public key PreK A , PreK BAnd send it to the server. If the time limit for the last key exchange is reached during a certain chat, that is, the preset time period is exceeded, the above steps are re-executed to perform a new key exchange, generate a new shared private key SK', and execute a new encrypted chat process.
[0127] To help better understand the details of the present invention, an implementation example of the key exchange protocol is given below.
[0128] Protocol parameter settings and key data:
[0129] Dimension n = 1024; modulus q = 8380417; parameter σ = 2.6; parameter γ1 = 2 19 =524288; parameter γ2 = (q-1) / 88 = 95232; parameter β = 286; residual class ring Z q {0, 1, ..., q-1} or Represents; the polynomial remainder class ring is R q =Z q [X] / (X n +1).
[0130] All key data tips involved are detailed in the table below:
[0131] Table 1: All key data hints in the protocol
[0132]
[0133]
[0134] Bob uses the DKE basic key exchange system to randomly generate a polynomial a∈R q , and then generate a fixed private key and the corresponding fixed public key And R q The elements in can all be represented by 1024-dimensional vectors. The specific data examples are as follows:
[0135] a=[2554674, 3216321, 2345135, 1797878,…, 4113492, 3761189, 4732942, 628670];
[0136] s B =[2,-1,-2,5,-3,0,-1,5,-2,1,…,-4,-2,2,3,-1,-4,1,-2,2,-2];
[0137] e B=[-3,-5,1,-3,1,-2,-2,1,-2,-2,…,-3,-1,-1,-2,-8,1,-2,-5,2,5];
[0138] b B =[3025316, 5006463, 558111, 1758942, …, 3790024, 3099089, 5895506, 6758710].
[0139] Following the same steps, Bob randomly generates a pre-private key And the corresponding pre-public key in
[0140]
[0141] Next, Bob uses the fixed private key SFK based on the Dilithium signature system B Pre-public key PreK B Generate a signature s = (z, c), where
[0142] z=[444895, 278177, -484878, -500015, ..., 154342, -313932, -68689, 432766];
[0143] c=[0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0 ,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,…,0 ,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,1,0,-1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0].
[0144] Then, Bob adds FK B , PreK B , signature s and other public key parameters are packaged into a key parameter set P B , submitted to the server, including the value of the random matrix a, which will be used as the first part of all subsequent public keys.
[0145] Alice uses the value of a to generate a fixed private key based on the DKE basic key exchange. and the corresponding fixed public key in
[0146] s A =[-6, 2, -1, 2, -4, 0, 1, -2, -2, -5, ..., 0, -3, 2, -1, 1, 3, -1, -4, -2, 1];
[0147] e A =[-4,0,2,0,0,0,1,1,-1,-4,…,-2,-4,1,0,3,4,2,7,-2,-1];
[0148] b A =[3530061, 4202796, 176215, 1905334, …, 8261761, 1476698, 5552364, 3743227].
[0149] Alice obtains Bob's key parameter set from the server and uses Bob's fixed public key FK B Verify the pre-public key PreK B The signature s=(z,c). After the signature is passed, Alice thinks that the pre-public key PreK B Next, Alice uses DKE basic key exchange to generate a temporary private key. And the corresponding temporary public key in
[0150] s′ A =[1,-4,-3,2,3,-4,-5,1,-6,1,…,-1,1,-2,-3,-2,-4,-3,3,-1,-2];
[0151] e′ A =[-1,2,0,0,0,1,-5,-2,-4,1,…,1,0,1,7,0,-1,1,-4,0,0];
[0152] b′ A =[4036903, 5614361, 7816210, 2511834, …, 8023734, 7284560, 4321311, 2930985].
[0153] Alice performs three DKE-based key exchanges: D1 = DKE (FK A , PreK B ), D2=DKE(TKA , FK B ), D3=DKE(TK A , PreK B ), Alice knows the public key FK A , TK A The corresponding private key and public key PreK B , FK B By itself, we can successfully calculate the three keys D1, D2, and D3. Through polynomial multiplication, error elimination, and modulo 2 of each coefficient, we get the following three 1024-bit string keys (expressed in hexadecimal):
[0154] D1=0xe7e1cdaf4865bbbc943dd5cfdc10797c3f8321ea74f26fb7975b8e7b1a7a e36bd5f37e6f58b42ec8213b980c8c93710b0b0c85fc66e2216cdcc9269d6909e2 98c3682adb4dc003838f2db7e5258c86c61b5517c1f91626f49c17c7024c6aefb e31572518c1412527d75b66128fa39682068dd6226bece75699b66e1734246003;
[0155] D2=0x15845551c14a467f69fdfd81d4e1082d4368163935d9ad0f61501d6d2a9a ef7eadd50e8b5e13e4d32181833e8e9ff87165f9b9da925f80c0c637fef657e739 63ef96e7fc350bee0603da8bdd41876131c9d848ecdb49afc89efc7708bec41a4 950a83a3b666819a31136d08530185747144e2853465726c9414267b2ef313900;
[0156] D3=0x440a8fee1929ebab30660f554aab958f1e6f2a0ee2f5b32e3e3f1d47040c de3b451d15c8cf4f6a15509145fc5b9e8760ffe98cd3fdbc27b699c33f8a13171c 0715a35d88c3558549506a646aa5dc7ca054ef583e7cd3300802137ef2337e516 c4d145717764eaba1cee57033b38172a84a3d8854e5afce94a51b868b6ea6af13.
[0157] Alice uses the SHA-256 hash function and counter as the KDF function to generate a 256-bit shared private key SK, that is, SK = SHA-256(D1||D2||D3||0x00000001), which is calculated to be
[0158] SK=0x4e110bca77c86989df87f9e0754d53046cd2ee8d8f7c383a482c8924c30e27cc.
[0159] Alice uses the shared private key SK to perform AES-256 encryption on the first chat message M = "Hello, Bob!", and obtains the ciphertext C = Enc(SK, M) = 0x335b6e6cb8ea56b64b9fb038ac8585e7. Finally, Alice uses the key data parameter set F A :(FK A , TK A , C) sent to Bob.
[0160] Bob receives a set of parameters P A After that, get Alice's fixed public key FK A and temporary public key TK A , together with the public key PreK B , FK B The corresponding private key also performs three DKE basic key exchanges D′1=DKE(FK A , PreK B ), D′2=DKE(TK A , FK B ), D′3=DKE(TK A , PreK B ), and the three 1024-bit string keys are also obtained as follows: <h2 style=";text-align:left;direction:ltr">
[0161] <h2 style=";text-align:left;direction:ltr"> D′1 = 0xe7e1cdaf4865bbbc943dd5cfdc10797c3f8321ea74f26fb7975b8e7b1a7ae36bd5f37e6f58b42ec8213b980c8c93710b0b0c85fc66e2216cdcc9269d6909e 298c3682adb4dc003838f2db7e5258c86c61b5517c1f91626f49c17c7024c6aefbe31572518c1412527d75b66128fa39682068dd6226bece75699b66e1734246003;<h2 style=";text-align:left;direction:ltr"> <h2 style=";text-align:left;direction:ltr">
[0162] <h2 style=";text-align:left;direction:ltr"> D′2 = 0x15845551c14a467f69fdfd81d4e1082d4368163935d9ad0f61501d6d2a9aef7eadd50e8b5e13e4d32181833e8e9ff87165f9b9da925f80c0c637fef657e73 963ef96e7fc350bee0603da8bdd41876131c9d848ecdb49afc89efc7708bec41a4950a83a3b666819a31136d08530185747144e2853465726c9414267b2ef313900;<h2 style=";text-align:left;direction:ltr"> <h2 style=";text-align:left;direction:ltr">
[0163] <h2 style=";text-align:left;direction:ltr"> D′3=0x440a8fee1929ebab30660f554aab958f1e6f2a0ee2f5b32e3e3f1d47040 cde3b451d15c8cf4f6a15509145fc5b9e8760ffe98cd3fdbc27b699c33f8a13171 c0715a35d88c3558549506a646aa5dc7ca054ef583e7cd3300802137ef2337e516c4d145717764eaba1cee57033b38172a84a3d8854e5afce94a51b868b6ea6af13。<h2 style=";text-align:left;direction:ltr"> <h2 style=";text-align:left;direction:ltr">
[0164] Bob then uses the SHA-256 hash function and a counter to generate a 256-bit shared private key SK, where SK = 0x4e110bca77c86989df87ff9e0754d53046cd2ee8d8f7c383a482c8924c30e27cc. Finally, Bob uses SK to perform AES-256 decryption on the encrypted message C, obtaining the plaintext M = "Hello, Bob!", completing the key exchange and the zeroth encrypted chat.
[0165] When the two parties chat for the i-th time, they use the hash function SHA-256 and the counter to calculate the i-th chat session key SK i = SHA-256(SK||i), used for message encryption in the i-th encrypted chat. For i=1,…,10, the session key is as follows:
[0166] SK1=0x9b09cd0bf9350266bcc0ba46dbf5e946cd018db805fa4877aaa209870781fa4a,
[0167] SK2=0x9dbcb3e07fb494a9158335b132c2fa95e8169f448283b647be593f4a81446c51,
[0168] SK3=0x303ea024d21e7e015a59a023f86cbef9e4a3a87ad7fcc29a3a1146ddb17788a9,
[0169] SK4=0x8eebcd14e901941d29d07b037019a9362d1a62fc4081d2414ba20cdb28c3ba60,
[0170] SK5=0xa25b434f2413eb2eeddf43ebd385f28c0a0c15bb7286165e8516bb8fdca3bdf1,
[0171] SK6=0x8afe6d6a9610598de877d13d2dc5c6cb05af43e9cc4c52e01cfd718914cdb0e2,
[0172] SK7=0x738365cad287164d79c0428a59d52bc7bb9cbe1b60e636f476cbf0bcd857bbde,
[0173] SK8=0xe5ba2e7d11791717ebc81ed5e3c93f1e0750cd799d4012daaab379e4cdaed3c2,
[0174] SK9=0x721620ba4a8e8326e99d3d652cea84f8514dbc0b4e6e445ebf7303975262aeb1,
[0175] SK 10 =0x1d8b925bf4865bb5f8e1ba676705e830d8a3e2b73d55eb5632d66ab886ae2ff0.
[0176] An embodiment of the present invention provides a computer-readable storage medium storing a computer program for electronic data exchange, wherein the computer program causes a computer to execute the method of the above-described embodiment. The computer-readable storage medium of this embodiment can serve as any one or more of the storage medium of a communication client, the storage medium of a communication cloud server, the storage medium of a communication backend server, or the storage medium of a database.
[0177] A communication encryption system based on bidirectional secure key exchange according to an embodiment of the present invention is shown in the structural diagram. Figure 9 Shown, including:
[0178] processor;
[0179] Memory;
[0180] as well as
[0181] One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the processor, the programs causing the computer to perform the method of the above-described embodiment. The processor can serve as any one or more of a processor of a communication client, a processor of a communication cloud server, a processor of a communication backend server, or a processor of a database.
[0182] Of course, those skilled in the art should realize that the above embodiments are only used to illustrate the present invention and are not intended to limit the present invention. As long as they are within the scope of the present invention, any changes or modifications to the above embodiments will fall within the scope of protection of the present invention.
Claims
1. A communication encryption method based on two-way secure key exchange, characterized in that: include: The communicating parties use the DKE basic key exchange system to generate fixed public keys, fixed private keys, pre-public keys and pre-private keys; The two communicating parties use the DKE basic key exchange system to generate a fixed public key and a fixed private key, a pre-public key and a pre-private key, including the steps of: constructing a residual class ring R according to a set of polynomials with coefficients modulo q q ; According to the randomly uniformly generated ring R q The polynomial a and discrete Gaussian distribution generate the private key and the corresponding fixed public key Generate a pre-private key based on discrete Gaussian distribution And the corresponding pre-public key Use the fixed private key to obtain the Dilithium signature of the pre-public key and use it to generate a key parameter set; The method uses a fixed private key to obtain a Dilithium signature of a pre-public key and generates a key parameter set based on it, including the following steps: repeatedly randomly selecting a polynomial vector y with an infinite norm less than γ1 and calculating a high-order bit w1 and a low-order bit w0 of a·y as a bound of 2γ2; wherein γ1 and γ2 are preset parameters; calculating a spherical hash c and calculating a vector z according to the hash value and the fixed private key; repeating the above steps until the infinite norm of vector z is less than γ1-β and w0-2c·s B When the infinite norm of is less than γ2-β, the output signature s = (z, c); where β is a preset parameter; according to the fixed public key FK B , Pre-public key PreK B , signature s generates key parameter set P B ; After the communicating party obtains the other party's key parameter set, it uses the other party's fixed public key to verify the Dilithium signature of the pre-public key; If the signature verification is successful, the communicating party generates its own temporary public key; Perform DKE basic key exchange based on its own fixed public key, temporary public key and the other party's fixed public key and pre-public key; Use the KDF function to process the result of the basic key exchange to generate a shared private key; Use the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext and send the ciphertext or plaintext together with its own fixed public key and temporary public key to the other party; Within a preset time period after the completion of the first communication, the communicating parties calculate the key for each communication according to the hash function and use it for subsequent encrypted communications.
2. The communication encryption method based on two-way secure key exchange according to claim 1, characterized in that: After obtaining the other party's key parameter set, the communicating party uses the other party's fixed public key to verify the Dilithium signature of the pre-public key, including the steps of: The communicating party obtains the other party's key parameter set P from the server B ; Calculate the verification vector w1' based on the public key and Dilithium signature; If and only if the infinity norm of vector z is less than γ1-β and c = H(PreK B ||w1'), the Dilithium signature verification of the pre-public key is passed.
3. The communication encryption method based on two-way secure key exchange according to claim 2 is characterized in that: The communication party generates its own temporary public key, including the steps of: Generate private key based on discrete Gaussian distribution Generate a corresponding temporary public key based on the temporary private key 4. The communication encryption method based on two-way secure key exchange according to claim 3 is characterized in that: The DKE basic key exchange is performed according to the fixed public key, temporary public key and the fixed public key and pre-public key of the other party, including the following steps: Confirm the DKE basic key exchange parameters, including the modulus q and dimension n; The DKE basic key exchange protocol is used to calculate the first exchange bit string D1=DKE(FK A , PreK B ); The DKE basic key exchange protocol is used to calculate the second exchange bit string D2 = DKE (TK A , FK B ); The DKE basic key exchange protocol is used to calculate the third exchange bit string D3 = DKE (TK A , PreK B ).
5. The communication encryption method based on two-way secure key exchange according to claim 4 is characterized in that: The method of using the KDF function to process the result of the basic key exchange to generate a shared private key is that the communication party uses the HMAC of SHA-256 as the KDF function to generate a shared private key SK=KDF(D1||D2||D3); The method of using the shared private key to perform AES-256 encryption or decryption on the communication content to obtain ciphertext or plaintext and sending the ciphertext or plaintext together with its own fixed public key and temporary public key to the other party includes the following steps: The communicating parties use the shared private key SK to perform AES-256 encryption on the first communication message M, and obtain the ciphertext C = Enc(SK,M); The communication party sets the parameter set P A :(FK A ,TK A ,C) sent to the other party; The other party calls the DKE basic key exchange protocol and KDF function to generate the same shared private key SK and uses the shared private key SK to perform AES-256 decryption on the encrypted communication information C to obtain the original communication information M = Dec(SK, C); Complete key exchange and first encrypted communication.
6. The communication encryption method based on two-way secure key exchange according to claim 5, characterized in that: Within a preset time period after the completion of the first communication, the communicating parties calculate the key for each communication according to the hash function and use it for subsequent encrypted communication, including the steps of: Within a preset period of time after the completion of the first communication, both parties use the hash function SHA-256 and the counter mode to calculate the communication key SK for the i-th communication i = SHA-256(SK||i); Both parties use the communication key SK i And the AES-256 symmetric encryption algorithm completes the i-th encrypted communication; If the communication between the two parties exceeds the preset time period, the two parties will re-execute the key exchange and generate a new shared key for encrypted communication.
7. A computer-readable storage medium storing a computer program for electronic data exchange, wherein: The computer program enables a computer to execute the method according to any one of claims 1 to 6.
8. A communication encryption system based on two-way secure key exchange, characterized in that include: processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the processor, the programs causing the computer to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Authentication key exchange method based on message recovery signature
CN109995509A
Anti-quantum computing RFID authentication method and system based on symmetric key pool and online and offline signatures
CN110650004A