Method, device, system and equipment for issuing hybrid dual certificates of post-quantum and national secrets

By introducing the issuance method of post-quantum and national secret hybrid dual certificates in the PKI system, hybrid signature certificates and hybrid encryption certificates are generated, which solves the problem that traditional PKI systems are vulnerable to quantum computing attacks and realizes the safe migration from the SM2 dual certificate system to the PQC+SM2 hybrid dual certificate system.

CN118944894BActive Publication Date: 2025-09-05CHINA TELECOM QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411212640.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2025-09-05
Estimated Expiration
2044-08-30

AI Technical Summary

Technical Problem

The public key cryptography algorithms of traditional public key infrastructure (PKI) systems are vulnerable to quantum computing attacks, and existing technologies find it difficult to maintain compatibility with the SM2 dual certificate system during the process of migrating to the post-quantum cryptography (PQC) certificate system.

Method used

A method for issuing a post-quantum and national secret hybrid dual certificate is provided. The certification center receives the hybrid certificate request from the user end, generates a hybrid signature certificate and a hybrid encryption certificate, obtains the target hybrid encryption key information from the key management center, generates a hybrid encryption key envelope, and realizes the migration of the SM2 dual certificate system to the PQC+SM2 hybrid dual certificate system.

Benefits of technology

It has achieved the addition of post-quantum algorithm on the basis of national encryption algorithm, effectively resisting quantum algorithm attacks and ensuring the security and compatibility of hybrid dual certificates issued by the user end.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118944894B_ABST
    Figure CN118944894B_ABST
Patent Text Reader

Abstract

The present application provides a method, device, system and equipment for issuing a post-quantum and national secret hybrid dual certificate, which relates to the field of cryptographic application technology. Applied to the authentication center and user end in a digital certificate authentication system, the method includes: the authentication center issues a hybrid signature certificate to the user end based on the subject information and hybrid signature public key information, obtains the target hybrid encryption key information from the key management center based on the hybrid algorithm identifier of the temporary hybrid encryption public key information, and then processes the target hybrid encryption key information and the subject information, and issues a hybrid encryption certificate, hybrid encryption private key ciphertext and target hybrid encryption public key information to the user end. Since the hybrid dual certificate is a dual certificate issued for a hybrid algorithm, the hybrid algorithm includes the national secret algorithm and the post-quantum algorithm. The addition of the post-quantum algorithm on the basis of the national secret algorithm can effectively resist the attack of the quantum algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cryptographic application technology, and in particular to a method, device, system and equipment for issuing a post-quantum and national secret hybrid dual certificate. Background Art

[0002] With the rapid development of quantum computing technology, the public key cryptography algorithms of traditional Public Key Infrastructure (PKI) systems, which rely on large integer factorization and discrete logarithm problems, are vulnerable to quantum computer attacks and can be cracked in minutes or hours. To address this challenge, security management departments, standardization organizations, and the industry are vigorously promoting research on a new generation of public key cryptography algorithms, namely post-quantum cryptography (PQC), to resist quantum computing attacks.

[0003] Currently, the PKI system uses the National Security Agency's SM2 dual-certificate system and dual-center design. The SM2 dual-certificate system includes a signature certificate and an encryption certificate. The signature certificate is used for identity authentication, while the encryption certificate is used for public key encryption and key exchange. Migrating from the SM2 dual-certificate system to the PQC certificate system primarily requires implementing PQC key generation and PQC certificate issuance. While considering security, compatibility with the SM2 dual-certificate system should also be considered. Summary of the Invention

[0004] The purpose of the present invention is to address the deficiencies in the above-mentioned prior art and provide a method, device, system and equipment for issuing post-quantum and national secret hybrid dual certificates, so that the certification center can issue hybrid signature certificates, hybrid encryption certificates and target hybrid encryption key envelopes to the user terminal based on the subject information and hybrid signature public key information, thereby realizing the migration of the SM2 dual certificate system to the PQC+SM2 hybrid dual certificate system.

[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows:

[0006] In a first aspect, an embodiment of the present application provides a method for issuing a post-quantum and national secret hybrid dual certificate, which is applied to a certification center in a digital certificate authentication system, and the method includes:

[0007] Receive a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information;

[0008] Processing the subject information and the hybrid signature public key information to obtain a hybrid signature certificate;

[0009] Based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, obtaining target hybrid encryption key information from the key management center, the target hybrid encryption key information including: target hybrid encryption public key information and target hybrid encryption private key information;

[0010] Processing the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate;

[0011] Using the temporary hybrid encryption public key information, digitally encapsulate the target hybrid encryption private key information to generate a target hybrid encryption key envelope, wherein the target hybrid encryption key envelope includes: a target hybrid encryption private key ciphertext and the target hybrid encryption public key information;

[0012] The hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key envelope are sent to the user terminal.

[0013] In an optional implementation manner, the processing of the subject information and the hybrid signature public key information to obtain a hybrid signature certificate includes:

[0014] Encapsulating the subject information, the hybrid signature public key information, the preset certificate validity period, the first certificate version number, the hybrid public key algorithm identifier, and the first certificate serial number to obtain first encapsulation information;

[0015] Using the private key information of the hybrid root certificate of the certification authority, signing the first packaged information to obtain a first signature value;

[0016] The first encapsulation information, the first signature value and the hybrid signature algorithm identifier are re-encapsulated to obtain the hybrid signature certificate.

[0017] In an optional implementation manner, the obtaining target hybrid encryption key information from a key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information includes:

[0018] Sending a key application request to the key management center, the key application request including: a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information; the key application request is used to enable the key management center to generate the target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information;

[0019] A key application response sent by the key management center is received, where the key application response includes: the target hybrid encryption key information.

[0020] In an optional implementation manner, the processing the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate includes:

[0021] Encapsulating the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the subject information, the second certificate version number, and the hybrid public key algorithm identifier to obtain second encapsulation information;

[0022] Using the private key information of the hybrid root certificate of the certification authority, signing the second packaged information to obtain a second signature value;

[0023] The second encapsulation information, the second signature value and the hybrid signature algorithm identifier are re-encapsulated to obtain the hybrid encryption certificate.

[0024] In a second aspect, an embodiment of the present application further provides a method for issuing a hybrid post-quantum and national secret dual certificate, which is applied to a user terminal and includes:

[0025] A hybrid certificate request is sent to a certification center in a digital certificate certification system, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, the hybrid certificate request is used to enable the certification center to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate, based on The hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information is obtained from a key management center, the target hybrid encryption key information including target hybrid encryption public key information and target hybrid encryption private key information, the target hybrid encryption public key information and the subject information are processed to obtain a hybrid encryption certificate, the target hybrid encryption private key information is digitally encapsulated using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope, the target hybrid encryption key envelope including target hybrid encryption private key ciphertext and the target hybrid encryption public key information;

[0026] Receive the hybrid signature certificate, the hybrid encryption certificate and the target hybrid encryption key envelope sent by the certification center.

[0027] In an optional embodiment, before sending the hybrid certificate request to the certification center in the digital certificate authentication system, the method further includes:

[0028] A hybrid signature algorithm is used to generate a hybrid signature key, wherein the hybrid signature key includes: the hybrid signature public key information and the hybrid signature private key information;

[0029] Using a hybrid encryption algorithm to generate a temporary hybrid encryption key, the temporary hybrid encryption key including: the temporary hybrid encryption public key information and the temporary hybrid encryption private key information;

[0030] Generate the public key information according to the hybrid signature public key information and the temporary hybrid encryption public key information;

[0031] Using the hybrid signature private key information, signing the subject information and the public key information to generate signature information;

[0032] The subject information, the public key information, and the signature information are all encapsulated into the hybrid certificate request.

[0033] In an optional embodiment, the method further comprises:

[0034] Using the public key information of the hybrid signature root certificate of the certification authority, respectively verifying the hybrid signature certificate and the hybrid encryption certificate, to obtain a verification result of the hybrid signature certificate and a verification result of the hybrid encryption certificate;

[0035] Using the locally stored temporary hybrid encryption private key information, perform digital envelope decapsulation processing on the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information;

[0036] Obtaining the target hybrid encryption public key information from the target hybrid encryption key envelope;

[0037] The hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key information are stored.

[0038] In a third aspect, an embodiment of the present application further provides a device for issuing a post-quantum and national secret hybrid dual certificate, which is applied to a certification center in a digital certificate authentication system, and the device includes:

[0039] A first receiving module is configured to receive a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information;

[0040] A first processing module is configured to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate;

[0041] an acquisition module, configured to acquire target hybrid encryption key information from a key management center based on a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, wherein the target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information;

[0042] The first processing module is further configured to process the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate;

[0043] an encryption module configured to perform digital envelope encapsulation processing on the target hybrid encryption private key information using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope, wherein the target hybrid encryption key envelope includes: a target hybrid encryption private key ciphertext and the target hybrid encryption public key information;

[0044] The first sending module is configured to send the hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key envelope to the user terminal.

[0045] In the fourth aspect, an embodiment of the present application also provides a digital certificate authentication system, which includes: an authentication center and a key management center, the key management center is used to send target hybrid encryption key information to the authentication center, and the authentication center is used to execute the steps of the method for issuing post-quantum and national secret hybrid dual certificates as described in any of the first aspects.

[0046] In the fifth aspect, an embodiment of the present application also provides a user-end device, comprising: a processor, a storage medium and a bus, wherein the storage medium stores program instructions executable by the processor. When the user-end device is running, the processor and the storage medium communicate through the bus, and the processor executes the program instructions to execute the steps of the method for issuing post-quantum and national secret hybrid dual certificates as described in any one of the second aspects.

[0047] In the sixth aspect, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the method for issuing post-quantum and national secret hybrid dual certificates as described in any one of the second aspects are executed.

[0048] The beneficial effects of this application are:

[0049] The embodiment of the present application provides a method, apparatus, system and device for issuing a post-quantum and national secret hybrid dual certificate, which is applied to the certification center in the digital certificate authentication system. The method includes: receiving a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, processing the subject information and the hybrid signature public key information to obtain a hybrid signature The certificate obtains the target hybrid encryption key information from the key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information. The target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information; the target hybrid encryption public key information and the subject information are processed to obtain a hybrid encryption certificate. The target hybrid encryption private key information is digitally encapsulated using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope. The target hybrid encryption key envelope includes: target hybrid encryption private key ciphertext and target hybrid encryption public key information. The hybrid signature certificate, hybrid encryption certificate and target hybrid encryption key envelope are sent to the user end.

[0050] The method of the present application can issue a hybrid signature certificate to the user terminal based on the subject information and the hybrid signature public key information through the certification center, obtain the target hybrid encryption key information from the key management center based on the hybrid algorithm identifier corresponding to the temporary hybrid encryption public key information, and then process the target hybrid encryption key information and the subject information, so as to issue a hybrid encryption certificate, a hybrid encryption private key ciphertext and a target hybrid encryption public key information to the user terminal, thereby realizing the issuance of a hybrid dual certificate to the user terminal and providing the user terminal with a target hybrid encryption key envelope. In addition, since the hybrid dual certificate is a dual certificate issued for a hybrid algorithm, the hybrid algorithm includes a national secret algorithm and a post-quantum algorithm. The post-quantum algorithm is added on the basis of the national secret algorithm, which can effectively resist the attack of the quantum algorithm. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0052] Figure 1 This is a flowchart of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0053] Figure 2 This is a second flow chart of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0054] Figure 3 Flowchart 3 of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0055] Figure 4 Flowchart 4 of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0056] Figure 5 Flowchart 5 of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0057] Figure 6 Flowchart 6 of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0058] Figure 7 Flowchart 7 of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0059] Figure 8 A schematic diagram of the functional modules of a device for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0060] Figure 9 A schematic diagram of the functional modules of another device for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application;

[0061] Figure 10 A schematic diagram of a user terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments.

[0063] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.

[0064] In the description of this application, it should be noted that if the terms "upper", "lower", etc. appear, the orientation or position relationship indicated is based on the orientation or position relationship shown in the accompanying drawings, or is the orientation or position relationship in which the product of the application is usually placed when in use. It is only for the convenience of describing this application and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on this application.

[0065] In addition, the terms "first," "second," and the like in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0066] It should be noted that, in the absence of conflict, the features in the embodiments of this application can be combined with each other.

[0067] Public Key Infrastructure (PKI) is a key management platform that follows established standards. It can provide cryptographic services such as encryption and digital signatures, as well as the necessary key and certificate management system for all network applications. In other words, PKI is an infrastructure that provides security services built using public key theory and technology.

[0068] Currently, the PKI system uses the SM2 dual-certificate system, a dual-center design, based on the national cryptographic algorithm. The SM2 dual certificates include an SM2 signature certificate and an SM2 encryption certificate. The SM2 signature certificate is used for identity authentication, while the SM2 encryption certificate is used for public key encryption and key exchange. The issuance process for the SM2 dual certificates includes: the user generates an SM2 signature key and submits a certificate request to the digital certificate authentication system. The digital certificate authentication system, part of the PKI system, consists of a certification center and a key management center. The key management center generates an SM2 encryption key, which is then issued by the certification center. Finally, the certification center distributes the SM2 dual certificate and SM2 encryption key to the user, completing the issuance of the SM2 dual certificate.

[0069] With the rapid development of quantum computing technology, the public key cryptography algorithms of traditional PKI systems, such as the SM2 algorithm, rely on large integer decomposition and discrete logarithm problems and are vulnerable to quantum computing attacks. Therefore, this application adds a post-quantum cryptography algorithm (Post-Quantum Cryptography, PQC) on the basis of traditional cryptographic algorithms to resist quantum computing attacks.

[0070] However, the current PQC single certificate system can only issue PQC signature certificates, but not PQC encryption certificates. Therefore, the present application provides a method for issuing a post-quantum and national secret hybrid dual certificate to solve the above problem and generate a hybrid signature certificate, a hybrid encryption certificate, and a target hybrid encryption key envelope corresponding to the hybrid certificate request for the user terminal, wherein the hybrid signature certificate indicates a post-quantum and national secret hybrid signature certificate, and the hybrid encryption certificate indicates a post-quantum and national secret hybrid encryption certificate.

[0071] The following is an example of the issuance method of the hybrid dual certificate provided by this application with multiple examples in conjunction with the accompanying drawings. The issuance method of the hybrid dual certificate is applied to the certification center in the digital certificate authentication system. Figure 1 This is a flow chart of a method for issuing a hybrid post-quantum and national secret dual certificate provided in an embodiment of the present application. Figure 1 As shown, the method includes:

[0072] S101: Receive a hybrid certificate request sent by a user terminal.

[0073] Among them, the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information.

[0074] In this embodiment, the user end encapsulates the hybrid signature public key information and the temporary hybrid encryption public key information in a hybrid certificate request, and stores the hybrid signature private key information and the temporary hybrid encryption private key information on the user end.

[0075] If the post-quantum signature algorithm is determined to be the lattice-based post-quantum cryptography algorithm Dilithium, and the national secret signature algorithm is the SM2 algorithm, then the hybrid signature public key information consists of two public key components of Dilithium and SM2.

[0076] If the temporary post-quantum encryption algorithm is determined to be the lattice-based post-quantum cryptography algorithm Kyber, and the temporary national secret encryption algorithm is the SM2 algorithm, then the temporary hybrid encryption public key information consists of two public key components of Kyber and SM2.

[0077] It should be noted that the hybrid certificate request also includes signature information, which is information obtained by signing the subject information and public key information in the hybrid certificate request using the hybrid signature private key.

[0078] S102: Process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate.

[0079] Specifically, the authentication center reads the subject information and hybrid signature public key information in the hybrid certificate request, where the subject information includes: user information of the user end, and then the authentication center signs the subject information and hybrid signature public key information to obtain a hybrid signature certificate.

[0080] S103. Obtain target hybrid encryption key information from a key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information.

[0081] The target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information.

[0082] The key management center generates target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information and sends it to the authentication center.

[0083] S104: Process the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate.

[0084] S105: Use the temporary hybrid encryption public key information to perform digital envelope encapsulation processing on the target hybrid encryption private key information to generate a target hybrid encryption key envelope.

[0085] The target hybrid encryption key envelope includes: target hybrid encryption private key ciphertext and target hybrid encryption public key information.

[0086] Specifically, the digital envelope encapsulation processing includes: using a temporary symmetric key to encrypt the target hybrid encryption private key information to obtain the target hybrid encryption private key ciphertext, and then using the temporary hybrid encryption public key information to encrypt the temporary symmetric key to obtain the temporary symmetric key ciphertext, and generating the target hybrid encryption key envelope according to the target hybrid encryption private key ciphertext, the target hybrid encryption public key information and the temporary symmetric key ciphertext.

[0087] S106: Send the hybrid signature certificate, hybrid encryption certificate, and target hybrid encryption key envelope to the user terminal.

[0088] Among them, the key management center is used to generate target hybrid encryption key information for the user terminal. The authentication center issues a hybrid signature certificate, a hybrid encryption certificate and a target hybrid encryption public key information to the user terminal based on the hybrid certificate request sent by the user terminal, realizes the issuance of hybrid dual certificates, and digitally encapsulates the target hybrid encryption private key information in the target hybrid encryption key information, generates a target hybrid encryption key envelope, and sends the target hybrid encryption key envelope to the user terminal.

[0089] In summary, the embodiment of the present application provides a method for issuing a post-quantum and national secret hybrid dual certificate, which is applied to the certification center in the digital certificate authentication system. The method includes: receiving a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, processing the subject information and the hybrid signature public key information to obtain a hybrid signature certificate, based on The target mixed encryption key information is obtained from the key management center using a mixed encryption algorithm identifier corresponding to the temporary mixed encryption public key information, the target mixed encryption key information including: target mixed encryption public key information and target mixed encryption private key information; the target mixed encryption public key information and the subject information are processed to obtain a mixed encryption certificate, the temporary mixed encryption public key information is used to perform digital envelope encapsulation processing on the target mixed encryption private key information to generate a target mixed encryption key envelope including: target mixed encryption private key ciphertext and target mixed encryption public key information, and the mixed signature certificate, mixed encryption certificate and target mixed encryption key envelope are sent to the user end.

[0090] The method of the present application can issue a hybrid signature certificate to the user terminal based on the subject information and the hybrid signature public key information through the certification center, obtain the target hybrid encryption key information from the key management center based on the hybrid algorithm identifier corresponding to the temporary hybrid encryption public key information, and then process the target hybrid encryption key information and the subject information, so as to issue a hybrid encryption certificate, a target hybrid encryption private key ciphertext and a target hybrid encryption public key information to the user terminal, thereby realizing the issuance of a hybrid dual certificate to the user terminal and providing the user terminal with a target hybrid encryption key envelope. At the same time, since the hybrid dual certificate is a dual certificate issued for a hybrid algorithm, the hybrid algorithm includes a national secret algorithm and a post-quantum algorithm. The post-quantum algorithm is added on the basis of the national secret algorithm, which can effectively resist the attack of the quantum algorithm.

[0091] This application embodiment also provides another possible implementation of the issuance method of a hybrid post-quantum and national secret dual certificate. Figure 2This is a flow chart of the second method for issuing a post-quantum and national secret hybrid dual certificate provided in the embodiment of this application. Figure 2 As shown, the subject information and the hybrid signature public key information are processed to obtain a hybrid signature certificate, including:

[0092] S201. Encapsulate the subject information, the hybrid signature public key information, the preset certificate validity period, the first certificate version number, the hybrid public key algorithm identifier, and the first certificate serial number to obtain first encapsulation information.

[0093] S202: Use the private key information of the hybrid root certificate of the certification authority to sign the first packaged information to obtain a first signature value.

[0094] S203: Re-encapsulate the first encapsulation information, the first signature value, and the hybrid signature algorithm identifier to obtain a hybrid signature certificate.

[0095] In this embodiment, the certification center reads the subject information and public key information in the hybrid certificate request, and then determines the hybrid signature public key information from the public key information.

[0096] The certification center encapsulates the subject information, hybrid signature public key information, preset certificate validity period, first certificate version number, hybrid public key algorithm identifier and first certificate serial number to obtain first encapsulation information.

[0097] Then, the private key information of the hybrid root certificate of the certification authority is used to sign the first packaged information to obtain a first signature value. The hybrid root certificate is the basis for the certification authority to establish a trust relationship with the user terminal. When the certification authority issues a hybrid signature certificate, it needs to call the private key information of the hybrid root certificate to digitally sign the subject information and the hybrid signature public key information.

[0098] Finally, the first encapsulation information, the first signature value and the hybrid signature algorithm identifier are encapsulated again to obtain a hybrid signature certificate.

[0099] In the method provided in the embodiment of the present application, the subject information and hybrid signature public key information, the preset certificate validity period, the first certificate version number, the hybrid public key algorithm identifier and the first certificate serial number are encapsulated to obtain the first encapsulated information, and then the private key information of the hybrid root certificate of the certification authority is used to sign the first encapsulated information to obtain the first signature value, and finally the first encapsulated information, the first signature value and the hybrid signature algorithm identifier are encapsulated again to obtain the hybrid signature certificate, thereby realizing the issuance of the hybrid signature certificate.

[0100] This application embodiment also provides another possible implementation of the issuance method of a hybrid post-quantum and national secret dual certificate. Figure 3This is a flow chart of the third method for issuing a post-quantum and national secret hybrid dual certificate provided in the embodiment of this application. Figure 3 As shown, based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, the target hybrid encryption key information is obtained from the key management center, including:

[0101] S301. Send a key application request to a key management center.

[0102] Among them, the key application request includes: the hybrid algorithm identifier corresponding to the temporary hybrid encryption public key information; the key application request is used to enable the key management center to generate the target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information.

[0103] In this embodiment, the certification center reads the temporary hybrid encryption public key information in the hybrid certificate request and applies to the key management center for the target hybrid encryption key information corresponding to the hybrid encryption algorithm identified by the temporary hybrid encryption public key information, where the target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information. The certification center then designates the temporary hybrid encryption public key information as the protection key for the target hybrid encryption key information.

[0104] The key management center reads the received key application request and generates target hybrid encryption key information corresponding to the hybrid algorithm identifier of the temporary hybrid encryption public key information.

[0105] S302: Receive a key request response sent by a key management center.

[0106] The key request response includes the target hybrid encryption key information, and the key management center returns the target hybrid encryption key information to the authentication center.

[0107] In the method provided in the embodiment of the present application, a key application request is sent to a key management center, the key application request including: a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information; the key application request is used to enable the key management center to generate target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information; a key application response sent by the key management center is received, the key application response including: target hybrid encryption key information. The key management center generates target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, and returns the target hybrid encryption key information to the authentication center, so that the authentication center can process the target hybrid encryption key information to generate a hybrid encryption certificate.

[0108] This application embodiment also provides another possible implementation of the issuance method of a hybrid post-quantum and national secret dual certificate. Figure 4This is a flowchart of a method for issuing a post-quantum and national secret hybrid dual certificate provided in an embodiment of the present application. Figure 4 As shown, the target hybrid encryption public key information and subject information are processed to obtain a hybrid encryption certificate, including:

[0109] S401. Encapsulate the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the subject information, the second certificate version number and the hybrid public key algorithm identifier to obtain second encapsulation information.

[0110] S402: Use the private key information of the hybrid root certificate of the certification authority to sign the second packaged information to obtain a second signature value;

[0111] S403: Re-encapsulate the second encapsulation information, the second signature value, and the hybrid signature algorithm identifier to obtain a hybrid encryption certificate.

[0112] In this embodiment, the authentication center receives the target hybrid encryption public key information, and then the authentication center encapsulates the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the user information of the user terminal, the certification authority information of the certification authority, the second certificate version number and the hybrid public key algorithm identifier to obtain the second encapsulation information.

[0113] Then, the private key information of the hybrid root certificate of the certification authority is used to sign the second packaged information to obtain a second signature value. Finally, the second packaged information, the second signature value and the hybrid signature algorithm identifier are packaged again to obtain a hybrid encryption certificate.

[0114] In the method provided in the embodiment of the present application, the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the subject information, the second certificate version number and the hybrid public key algorithm identifier are encapsulated to obtain the second encapsulation information, and then the private key information of the hybrid root certificate of the certification authority is used to sign the second encapsulation information to obtain the second signature value, and finally the second encapsulation information, the second signature value and the hybrid signature algorithm identifier are encapsulated again to obtain the hybrid encryption certificate, thereby realizing the issuance of the hybrid encryption certificate.

[0115] The embodiment of the present application also provides another possible implementation of a method for issuing a hybrid dual certificate of post-quantum and national encryption. The hybrid dual certificate issuance method is applied to the user end. Figure 5 This is a flowchart of a method for issuing a post-quantum and national secret hybrid dual certificate provided in an embodiment of the present application. Figure 5 As shown, the method includes:

[0116] S501. Send a hybrid certificate request to a certification center in a digital certificate authentication system.

[0117] Among them, the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, the hybrid certificate request is used to enable the certification center to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate, based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, obtain the target hybrid encryption key information from the key management center, the target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information, and process the target hybrid encryption public key information and subject information to obtain a hybrid encryption certificate, use the temporary hybrid encryption public key information to digitally encapsulate the target hybrid encryption private key information to generate a target hybrid encryption key envelope, the target hybrid encryption key envelope includes: target hybrid encryption private key ciphertext and target hybrid encryption public key information.

[0118] S502: Receive the hybrid signature certificate, hybrid encryption certificate, and target hybrid encryption key envelope sent by the certification center.

[0119] In this embodiment, the user end encapsulates the hybrid signature public key information and the temporary hybrid encryption public key information in a hybrid certificate request, and stores the hybrid signature private key information and the temporary hybrid encryption private key information on the user end.

[0120] If the post-quantum signature algorithm is determined to be the lattice-based post-quantum cryptography algorithm Dilithium, and the national secret signature algorithm is the SM2 algorithm, then the hybrid signature public key information is composed of the two public key components of Dilithium and SM2. If the temporary post-quantum encryption algorithm is determined to be the lattice-based post-quantum cryptography algorithm Kyber, and the temporary national secret encryption algorithm is the SM2 algorithm, then the temporary hybrid encryption public key information is composed of the two public key components of Kyber and SM2.

[0121] The process of the certification center issuing a hybrid signature certificate, a hybrid encryption certificate, and generating a target hybrid encryption key envelope is recorded in detail in the above steps S101-S403 and will not be repeated here.

[0122] The user end finally receives the hybrid signature certificate, hybrid encryption certificate and target hybrid encryption key envelope sent by the certification center, completing the issuance of the hybrid dual certificate.

[0123] In summary, the embodiment of the present application provides a method for issuing a post-quantum and national secret hybrid dual certificate, which is applied to the user end. The method includes: sending a hybrid certificate request to the certification center in the digital certificate certification system, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, the hybrid certificate request is used to enable the certification center to process the subject information and the hybrid signature public key information to obtain a hybrid signature. The system obtains the target hybrid encryption key information from the key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information. The target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information. The target hybrid encryption public key information and subject information are processed to obtain a hybrid encryption certificate. The target hybrid encryption private key information is digitally encapsulated using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope. The target hybrid encryption key envelope includes: target hybrid encryption private key ciphertext and target hybrid encryption public key information. The system receives the hybrid signature certificate, hybrid encryption certificate, and target hybrid encryption key envelope sent by the certification center. The certification center issues a hybrid signature certificate to the user terminal based on the subject information and the hybrid signature public key information. The target hybrid encryption key information and subject information sent by the key management center are then processed and a hybrid encryption certificate is issued to the user terminal, thereby achieving the issuance of hybrid dual certificates and the distribution of the target hybrid encryption key envelope.

[0124] This application embodiment also provides another possible implementation of the issuance method of a hybrid post-quantum and national secret dual certificate. Figure 6 This is a flowchart of a method for issuing a post-quantum and national secret hybrid dual certificate provided in an embodiment of the present application. Figure 6 As shown, before sending the hybrid certificate request to the certification center in the digital certificate certification system, the method further includes:

[0125] S601: Generate a hybrid signature key using a hybrid signature algorithm.

[0126] The hybrid signature key includes: hybrid signature public key information and hybrid signature private key information.

[0127] S602: Generate a temporary hybrid encryption key using a hybrid encryption algorithm.

[0128] The temporary hybrid encryption key includes: temporary hybrid encryption public key information and temporary hybrid encryption private key information.

[0129] S603: Generate public key information according to the mixed signature public key information and the temporary mixed encryption public key information.

[0130] In this embodiment, the hybrid signature algorithm uses the PQC signature algorithm and the SM2 algorithm to implement dual digital signatures. The PQC signature algorithm can be selected from Dilithium, the Fast Fourier Transform-based Post-Quantum Digital Signature Algorithm (FALCON), and the Stateless Hash-based Digital Signature (SPHINCS+). The hybrid signature key consists of two key components, PQC and SM2. During signing, the two private key components of PQC and SM2 are used to perform a dual signature operation. The signature result consists of two signature values, PQC and SM2. During signature verification, the two public key components of PQC and SM2 are used to verify the two signature values. Verification is considered successful only when both signature values ​​are successfully verified. The hybrid signature public key information includes the two public key components of PQC and SM2, and the hybrid signature private key information includes the two private key components of PQC and SM2.

[0131] The hybrid encryption algorithm uses the PQC encryption algorithm and the SM2 algorithm to implement hybrid key encapsulation. The PQC encryption algorithm can optionally use the Kyber algorithm. The temporary hybrid encryption key consists of two key components, PQC and SM2. During encryption, the two public key components of PQC and SM2 are used to perform a hybrid key encapsulation operation on the message plaintext. The encryption result includes the two ciphertext components of PQC and SM2, as well as the message ciphertext. During decryption, the two private key components of PQC and SM2 are used to perform a hybrid key decapsulation operation to obtain the message plaintext. The temporary hybrid encryption public key information includes the two public key components of PQC and SM2, and the temporary hybrid encryption private key information includes the two private key components of PQC and SM2.

[0132] The mixed signature public key information and the temporary mixed encryption public key information are then encapsulated to generate public key information.

[0133] S604: Use the hybrid signature private key information to sign the subject information and the public key information to generate signature information.

[0134] S605: Encapsulate the subject information, public key information, and signature information into a hybrid certificate request.

[0135] The subject information includes: user information of the user end.

[0136] The certification center verifies the signature information in the hybrid certificate request by using the hybrid signature public key information to confirm the user identity and verify the integrity of the certificate request.

[0137] In the method provided in the embodiment of the present application, a hybrid signature algorithm is used to generate a hybrid signature key, which includes: hybrid signature public key information and hybrid signature private key information; a hybrid encryption algorithm is used to generate a temporary hybrid encryption key, which includes: temporary hybrid encryption public key information and temporary hybrid encryption private key; public key information is generated based on the hybrid signature public key information and the temporary hybrid encryption public key information; the hybrid signature private key information is used to sign the subject information and the public key information to generate signature information; the subject information, public key information and signature information are all encapsulated into a hybrid certificate request, so that the authentication center generates a hybrid dual certificate corresponding to the hybrid certificate request.

[0138] This application embodiment also provides another possible implementation of the issuance method of a hybrid post-quantum and national secret dual certificate. Figure 7 This is a flowchart of a method for issuing a post-quantum and national secret hybrid dual certificate provided in an embodiment of the present application. Figure 7 As shown, the method further includes:

[0139] S701. Use the public key information of the hybrid root certificate of the certification authority to verify the hybrid signature certificate and the hybrid encryption certificate to obtain the verification results of the hybrid signature certificate and the verification results of the hybrid encryption certificate.

[0140] In this embodiment, the hybrid signature certificate is signature verified using the public key information of the hybrid root certificate of the certification authority to obtain a verification result of the hybrid signature certificate. If the verification result is a verification failure, it is determined that the hybrid signature certificate and the identity of the certificate issuer do not match, and subsequent processing is stopped. The hybrid encryption certificate is signature verified to obtain a verification result of the hybrid encryption certificate. If the verification result is a verification failure, it is determined that the hybrid encryption certificate and the identity of the certificate issuer do not match, and subsequent processing is stopped.

[0141] S702: Use the temporarily hybrid encryption private key information stored locally to perform digital envelope decapsulation processing on the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information.

[0142] If the verification results of the hybrid signature certificate and the hybrid encryption certificate are both successful, it is determined that the hybrid certificate and the certificate issuer identity match, and the locally stored temporary hybrid encryption private key information is used to digitally decapsulate the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information.

[0143] Specifically, the digital envelope decapsulation process includes: using the temporary hybrid encryption private key information to decrypt the temporary symmetric key ciphertext to obtain the temporary symmetric key, and then using the temporary symmetric key to decrypt the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information.

[0144] S703: Obtain target hybrid encryption public key information from the target hybrid encryption key envelope.

[0145] S704: Store the hybrid signature certificate, hybrid encryption certificate, and target hybrid encryption key information.

[0146] The user end stores the hybrid signature certificate, hybrid encryption certificate, and target hybrid encryption key information locally on the user end to complete the issuance of the hybrid dual certificate.

[0147] The following continues to explain the issuance device and user-end device for executing the post-quantum and national secret hybrid dual certificates provided by any of the above embodiments of this application. Its specific implementation process and the technical effects produced are the same as those of the corresponding method embodiments mentioned above. For the sake of brief description, for the parts not mentioned in this embodiment, please refer to the corresponding content in the method embodiment.

[0148] Figure 8 This is a functional module diagram of a device for issuing a post-quantum and national secret hybrid dual certificate provided in an embodiment of the present application. Figure 8 As shown, the issuance device 100 of the post-quantum and national secret hybrid dual certificate is applied to the authentication center in the digital certificate authentication system, and the device includes:

[0149] The first receiving module 110 is configured to receive a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information;

[0150] The first processing module 120 is used to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate;

[0151] An acquisition module 130 is configured to acquire target hybrid encryption key information from a key management center based on a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, wherein the target hybrid encryption key information includes target hybrid encryption public key information and target hybrid encryption private key information;

[0152] The first processing module 120 is further configured to process the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate;

[0153] The encryption module 140 is configured to digitally encapsulate the target hybrid encryption private key information using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope, wherein the target hybrid encryption key envelope includes: a target hybrid encryption private key ciphertext and a target hybrid encryption public key information;

[0154] The first sending module 150 is configured to send the hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key envelope to the user terminal.

[0155] Optionally, the first processing module 120 is also used to encapsulate the subject information and hybrid signature public key information, the preset certificate validity period, the first certificate version number, the hybrid public key algorithm identifier and the first certificate serial number to obtain first encapsulation information; use the private key information of the hybrid root certificate of the certification authority to sign the first encapsulation information to obtain a first signature value; and re-encapsulate the first encapsulation information, the first signature value and the hybrid signature algorithm identifier to obtain a hybrid signature certificate.

[0156] Optionally, the acquisition module 130 is also used to send a key application request to the key management center, the key application request includes: a mixed encryption algorithm identifier corresponding to the temporary mixed encryption public key information; the key application request is used to enable the key management center to generate target mixed encryption key information based on the mixed encryption algorithm identifier corresponding to the temporary mixed encryption public key information; and receive a key application response sent by the key management center, the key application response includes: target mixed encryption key information.

[0157] Optionally, the first processing module 120 is also used to encapsulate the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the subject information, the second certificate version number and the hybrid public key algorithm identifier to obtain second encapsulation information; use the private key information of the hybrid root certificate of the certification authority to sign the second encapsulation information to obtain a second signature value; and re-encapsulate the second encapsulation information, the second signature value and the hybrid signature algorithm identifier to obtain a hybrid encryption certificate.

[0158] Figure 9 This is a functional module diagram of another device for issuing a hybrid dual certificate of post-quantum and national secrets provided in an embodiment of the present application. Figure 9 As shown, the issuing device 200 of the post-quantum and national secret hybrid dual certificate is applied to the user end, including:

[0159] The second sending module 210 is used to send a hybrid certificate request to the certification center in the digital certificate certification system, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, the hybrid certificate request is used to enable the certification center to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate, obtain target hybrid encryption key information from the key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, the target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information, and process the target hybrid encryption public key information and subject information to obtain a hybrid encryption certificate, use the temporary hybrid encryption public key information to perform digital envelope encapsulation processing on the target hybrid encryption private key information to generate a target hybrid encryption key envelope, and the target hybrid encryption key envelope includes: target hybrid encryption private key ciphertext and target hybrid encryption public key information;

[0160] The second receiving module 220 is used to receive the hybrid signature certificate, hybrid encryption certificate and target hybrid encryption key envelope sent by the certification center.

[0161] Optionally, the issuing device 200 of the post-quantum and national secret hybrid dual certificate further includes:

[0162] A generation module is used to use a hybrid signature algorithm to generate a hybrid signature key, which includes: hybrid signature public key information and hybrid signature private key information; use a hybrid encryption algorithm to generate a temporary hybrid encryption key, which includes: temporary hybrid encryption public key information and temporary hybrid encryption private key information; generate public key information based on the hybrid signature public key information and the temporary hybrid encryption public key information; use the hybrid signature private key information to sign the subject information and public key information to generate signature information; and encapsulate the subject information, public key information and signature information into a hybrid certificate request.

[0163] Optionally, the post-quantum and national secret hybrid dual certificate issuance device 200 is applied to the user end, including:

[0164] The second processing module is used to use the public key information of the hybrid root certificate of the certification authority to verify the hybrid signature certificate and the hybrid encryption certificate, and obtain the verification results of the hybrid signature certificate and the hybrid encryption certificate; use the locally stored temporary hybrid encryption private key information to digitally decapsulate the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information; obtain the target hybrid encryption public key information from the target hybrid encryption key envelope; store the hybrid signature certificate, hybrid encryption certificate and target hybrid encryption key information.

[0165] The above-mentioned device is used to execute the method provided in the above-mentioned embodiment. Its implementation principle and technical effect are similar and will not be repeated here.

[0166] The above modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors, or one or more field programmable gate arrays (FPGAs). For another example, when a module is implemented by scheduling program code through a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0167] Figure 10 This is a schematic diagram of a user terminal device provided in an embodiment of the present application, which can be used to issue a hybrid dual certificate of post-quantum and national encryption. Figure 10 As shown, the user terminal device includes: a processor 310, a storage medium 320, and a bus 330.

[0168] Storage medium 320 stores machine-readable instructions executable by processor 310. When the user terminal device is running, processor 310 communicates with storage medium 320 via bus 330, and processor 310 executes the machine-readable instructions to perform the steps of the above method embodiment. The specific implementation methods and technical effects are similar and will not be repeated here.

[0169] Optionally, the present application further provides a storage medium 320 on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method embodiment are executed. The specific implementation and technical effects are similar and will not be repeated here.

[0170] In the several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0171] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0172] In addition, the functional units in various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional units.

[0173] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor (English: processor) to perform some steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: a USB flash drive, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviated: ROM), a random access memory (English: Random Access Memory, abbreviated: RAM), a magnetic disk or an optical disk, and other media that can store program code.

[0174] The above are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A method for issuing a hybrid post-quantum and national secret dual certificate, characterized in that: Applied to an authentication center in a digital certificate authentication system, the method comprises: Receive a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information; Processing the subject information and the hybrid signature public key information to obtain a hybrid signature certificate; Based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, obtaining target hybrid encryption key information from the key management center, the target hybrid encryption key information including: target hybrid encryption public key information and target hybrid encryption private key information; Processing the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate; Using the temporary hybrid encryption public key information, digitally encapsulate the target hybrid encryption private key information to generate a target hybrid encryption key envelope, wherein the target hybrid encryption key envelope includes: a target hybrid encryption private key ciphertext and the target hybrid encryption public key information; The hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key envelope are sent to the user terminal.

2. The method according to claim 1, characterized in that The processing of the subject information and the hybrid signature public key information to obtain a hybrid signature certificate includes: Encapsulating the subject information, the hybrid signature public key information, the preset certificate validity period, the first certificate version number, the hybrid public key algorithm identifier, and the first certificate serial number to obtain first encapsulation information; Using the private key information of the hybrid root certificate of the certification authority, signing the first packaged information to obtain a first signature value; The first encapsulation information, the first signature value and the hybrid signature algorithm identifier are re-encapsulated to obtain the hybrid signature certificate.

3. The method according to claim 1, characterized in that The obtaining target hybrid encryption key information from a key management center based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information includes: Sending a key application request to the key management center, the key application request including: a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information; the key application request is used to enable the key management center to generate the target hybrid encryption key information based on the hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information; A key application response sent by the key management center is received, where the key application response includes: the target hybrid encryption key information.

4. The method according to claim 1, wherein The processing of the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate includes: Encapsulating the target hybrid encryption public key information, the preset certificate validity period, the second certificate serial number, the subject information, the second certificate version number, and the hybrid public key algorithm identifier to obtain second encapsulation information; Using the private key information of the hybrid root certificate of the certification authority, signing the second packaged information to obtain a second signature value; The second encapsulation information, the second signature value and the hybrid signature algorithm identifier are re-encapsulated to obtain the hybrid encryption certificate.

5. A method for issuing a hybrid post-quantum and national secret dual certificate, characterized in that: Applied to a user terminal, the method includes: A hybrid certificate request is sent to a certification center in a digital certificate certification system, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information, the hybrid certificate request is used to enable the certification center to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate, based on obtaining target hybrid encryption key information from a key management center based on a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, the target hybrid encryption key information including target hybrid encryption public key information and target hybrid encryption private key information, processing the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate, performing digital envelope encapsulation processing on the target hybrid encryption private key information using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope, the target hybrid encryption key envelope including target hybrid encryption private key ciphertext and the target hybrid encryption public key information; Receive the hybrid signature certificate, the hybrid encryption certificate and the target hybrid encryption key envelope sent by the certification center.

6. The method according to claim 5, characterized in that Before sending the hybrid certificate request to the authentication center in the digital certificate authentication system, the method further includes: A hybrid signature algorithm is used to generate a hybrid signature key, wherein the hybrid signature key includes: the hybrid signature public key information and the hybrid signature private key information; Using a hybrid encryption algorithm to generate a temporary hybrid encryption key, the temporary hybrid encryption key including: the temporary hybrid encryption public key information and the temporary hybrid encryption private key information; Generate the public key information according to the hybrid signature public key information and the temporary hybrid encryption public key information; Using the hybrid signature private key information, signing the subject information and the public key information to generate signature information; The subject information, the public key information, and the signature information are all encapsulated into the hybrid certificate request.

7. The method according to claim 6, characterized in that The method further comprises: Using the public key information of the hybrid root certificate of the certification authority, respectively verifying the hybrid signature certificate and the hybrid encryption certificate, to obtain a verification result of the hybrid signature certificate and a verification result of the hybrid encryption certificate; Using the locally stored temporary hybrid encryption private key information, perform digital envelope decapsulation processing on the hybrid encryption private key ciphertext to obtain the plaintext of the target hybrid encryption private key information; Obtaining the target hybrid encryption public key information from the target hybrid encryption key envelope; The hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key information are stored.

8. A device for issuing a hybrid post-quantum and national secret dual certificate, characterized in that: The device is applied to an authentication center in a digital certificate authentication system, and comprises: A first receiving module is configured to receive a hybrid certificate request sent by a user terminal, wherein the hybrid certificate request includes: subject information and public key information, the public key information includes: hybrid signature public key information and temporary hybrid encryption public key information, the hybrid signature public key information includes: post-quantum signature algorithm public key information and national secret signature algorithm public key information, and the temporary hybrid encryption public key information includes: temporary post-quantum encryption algorithm public key information and temporary national secret encryption algorithm public key information; A first processing module is configured to process the subject information and the hybrid signature public key information to obtain a hybrid signature certificate; an acquisition module, configured to acquire target hybrid encryption key information from a key management center based on a hybrid encryption algorithm identifier corresponding to the temporary hybrid encryption public key information, wherein the target hybrid encryption key information includes: target hybrid encryption public key information and target hybrid encryption private key information; The first processing module is further configured to process the target hybrid encryption public key information and the subject information to obtain a hybrid encryption certificate; an encryption module configured to perform digital envelope encapsulation processing on the target hybrid encryption private key information using the temporary hybrid encryption public key information to generate a target hybrid encryption key envelope, wherein the target hybrid encryption key envelope includes: a target hybrid encryption private key ciphertext and the target hybrid encryption public key information; The first sending module is configured to send the hybrid signature certificate, the hybrid encryption certificate, and the target hybrid encryption key envelope to the user terminal.

9. A digital certificate authentication system, characterized in that: The digital certificate authentication system includes: an authentication center and a key management center, the key management center is used to send target hybrid encryption key information to the authentication center, and the authentication center is used to execute the steps of the method for issuing post-quantum and national encryption hybrid dual certificates as described in any one of claims 1 to 4.

10. A user terminal device, characterized in that: include: A processor, a storage medium and a bus, wherein the storage medium stores program instructions executable by the processor. When the user terminal device is running, the processor and the storage medium communicate through the bus, and the processor executes the program instructions to perform the steps of the method for issuing post-quantum and national secret hybrid dual certificates as described in any one of claims 5 to 7.

Citation Information

Patent Citations

  • Post-quantum security enhancement digital envelope method, device and system

    CN112118098A

  • Certificate authentication system and authentication method based on post-quantum signature

    CN116388986A