A multi-organization implicit certificate public key generation method
By generating master public-private key pairs and user-declared public keys of multiple trusted institutions, and binding the target user's user public key with the master public keys of multiple trusted institutions, the problem of being unable to simultaneously verify authentication information of multiple institutions in the existing technology is solved, and verification efficiency is improved.
Patent Information
- Application Number
- CN202411407674.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-10
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2044-10-10
AI Technical Summary
The existing implicit certificate public key generation method can only verify the authentication information of a user by one institution at a time, and cannot verify the authentication information of a user by multiple institutions at the same time, resulting in low verification efficiency.
A method for generating implicit certificate public keys for multiple institutions is provided. By generating master public-private key pairs of multiple trusted institutions in the master key stage, generating user-declared public keys in the declared key stage, and binding the target user's user public key with the master public keys of multiple trusted institutions in the public key usage stage, the authentication information of multiple trusted institutions can be verified at one time.
This enables the user to verify the authentication information of the target user by multiple trust agencies at one time, reduces the interactive process of multiple trust agencies authenticating the target user's identity, and meets the target user's needs for authentication by multiple trust agencies.
Smart Images

Figure CN119232381B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cryptographic application, and in particular to a method for generating public keys of implicit certificates of multiple institutions. Background Art
[0002] IoT applications place stringent demands on network and terminal computing resources, making certificate-based applications unsuitable for these scenarios. Implicit certificates are a new digital certificate solution within the Public Key Infrastructure (PKI) system. Based on elliptic curve cryptography, they do not include a certificate signing authority or the signature of the issuing authority during the authentication process. Instead, the verifier must calculate the implicit certificate owner's public key based on the data and perform cryptographic operations using the public key.
[0003] However, existing solutions can only verify the authentication information of a user by one organization at a time, and cannot verify the authentication information of a user by multiple organizations at a time. Summary of the Invention
[0004] The purpose of the present invention is to address the deficiencies in the above-mentioned prior art and provide a multi-institution implicit certificate public key generation method so that the user can simultaneously verify the authentication information of the target user by multiple trust institutions based on the user's public key, effectively meeting the target user's need for authentication by multiple trust institutions.
[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows:
[0006] In a first aspect, an embodiment of the present application provides a multi-institution implicit certificate public key generation method, which is applied to an implicit certificate public key system, wherein the implicit certificate public key system includes: a public key user end, a user end, and an institutional end of multiple trusted institutions, and the method includes:
[0007] In the master key phase, the institutional ends of the multiple trusted institutions respectively generate master public-private key pairs of the multiple trusted institutions, and disclose the master public keys in the master public-private key pairs of the multiple trusted institutions to the public key user end;
[0008] In the key declaration phase, the user terminal generates a user declaration public key corresponding to the target user of the user terminal based on the declared public key components of the multiple trust institutions for the target user and the temporary public key of the target user, and discloses the user declaration public key of the user terminal to the public key user terminal;
[0009] During the public key usage phase, the public key usage end generates the user public key of the target user based on the identifier of the target user, the master public keys of the multiple trust institutions, and the user-declared public key. The user public key of the target user is used to encrypt or verify the implicit certificate of the target user.
[0010] In an optional embodiment, the institutional ends of the multiple trusted institutions respectively generate the master public-private key pairs of the multiple trusted institutions, including:
[0011] The institutional ends of the multiple trust institutions generate the master public keys of the multiple trust institutions based on the first random numbers generated by each of them, wherein the master public-private key pair of each trust institution includes: the master public key of each trust institution and the first random number.
[0012] In an optional embodiment, the method further comprises:
[0013] In the key declaration phase, the user terminal sends a request for obtaining the target user's key declaration to the institution terminal of each trusted institution;
[0014] The institution end of each trust institution generates, based on the second random number generated by each trust institution, and returns to the user end a declared public key component of each trust institution for the target user.
[0015] In an optional embodiment, the method further comprises:
[0016] In the master key phase, the institution ends of the multiple trust institutions generate user public key parameters of the target user according to the identifier of the target user;
[0017] In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution;
[0018] During the private key usage phase, the user terminal generates a user private key of the target user based on the user private key components of the target user from the multiple trust institutions and the temporary private key of the target user. The user private key of the target user is used to decrypt or sign the implicit certificate of the target user.
[0019] In an optional embodiment, in the master key stage, the institution end of the multiple trust institutions generates the user public key parameters of the target user according to the identifier of the target user, including:
[0020] In the master key phase, the institution ends of the multiple trust institutions respectively generate user public key parameters of their respective trust institutions for the target user according to the identifier of the target user and the master public key coordinates of their respective trust institutions;
[0021] In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution, including:
[0022] In the key declaration phase, the institutional end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the user public key parameters of the respective trust institution for the target user and the second random number of each trust institution.
[0023] In an optional embodiment, during the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameters of the respective trusted institution for the target user and the second random number of each trusted institution, including:
[0024] In the key declaration phase, the institution end of each trust institution generates the user private key parameters of the respective trust institution for the target user based on the user public key parameters of the respective trust institution for the target user and the declared public key components of the respective trust institutions for the target user;
[0025] The institution end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the user private key parameters of the respective trust institution for the target user and the second random number of each trust institution.
[0026] In an optional embodiment, in the master key stage, the institution end of the multiple trust institutions generates the user public key parameters of the target user according to the identifier of the target user, including:
[0027] In the master key phase, the institution ends of the multiple trusted institutions generate common user public key parameters of the target user based on the identifier of the target user and the master public key coordinates of all trusted institutions;
[0028] In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution, including:
[0029] In the key declaration phase, the institution end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the common user public key parameters of the target user and the second random number of each trust institution.
[0030] In an optional embodiment, during the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the common user public key parameter of the target user and the second random number of each trusted institution, including:
[0031] In the key declaration phase, the institution end of each trust institution generates a common user private key parameter for the target user based on the common user public key parameter of the target user and the user declared public key;
[0032] The institution end of each trusted institution generates, based on the common user private key parameter and the second random number of each trusted institution, a user private key component of each trusted institution for the target user and returns it to the user end.
[0033] In an optional embodiment, the method further comprises:
[0034] In the key declaration phase, the user terminal further discloses the declared public key components of the multiple trusted institutions for the target user to the public key user terminal;
[0035] In the public key usage phase, the public key usage terminal generates a user public key of the target user according to the identifier of the target user, the master public keys of the multiple trust institutions, and the user-declared public key, including:
[0036] During the public key usage phase, the public key usage end generates a user public key of the target user based on the identifier of the target user, the master public keys of the multiple trust institutions, the user declared public key, and the declared public key components of the multiple trust institutions for the target user.
[0037] In an optional embodiment, the method further comprises:
[0038] During the private key usage phase, the user terminal generates a user public key of the target user based on the user private key of the target user.
[0039] In the second aspect, an embodiment of the present application also provides an implicit certificate public key system, which includes: a public key usage end, a user end, and an institutional end of multiple trusted institutions. The implicit certificate public key system is used to execute the steps of the multi-institution implicit certificate public key generation method described in any of the above-mentioned first aspects.
[0040] The beneficial effects of this application are:
[0041] The embodiment of the present application provides a method for generating a public key for an implicit certificate of multiple institutions, which is applied to an implicit certificate public key system. The method includes: in the master key stage, the institutional ends of multiple trust institutions respectively generate master public-private key pairs of multiple trust institutions, and disclose the master public keys in the master public-private key pairs of multiple trust institutions to the public key user end; in the declaration key stage, the user end generates and discloses the user declaration public key corresponding to the target user of the user end to the public key user end based on the declared public key components of the target user by multiple trust institutions and the temporary public key of the target user; in the public key use stage, the public key user end generates the user public key of the target user based on the identifier of the target user, the master public keys of multiple trust institutions and the user declaration public key; the user public key of the target user is used to encrypt or verify the implicit certificate of the target user. The method of the present application expands the implicit certificate public key system of a single institution to be used by multiple trust institutions, binds the user public key of the target user to the master public keys of multiple trust institutions, and the user end can simultaneously verify the authentication information of the target user by multiple trust institutions based on the user public key, thereby reducing the interactive process of multiple trust institutions authenticating the identity of the target user, and effectively meeting the needs of the target user for authentication by multiple trust institutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 A schematic diagram of a multi-organization implicit certificate public key generation method provided in an embodiment of the present application;
[0044] Figure 2 A schematic diagram of another multi-organization implicit certificate public key generation method provided in an embodiment of the present application;
[0045] Figure 3 A complete schematic diagram of the generation of implicit certificate public keys for multiple organizations and multiple declared public keys provided in an embodiment of the present application;
[0046] Figure 4 A schematic diagram of another method for generating a public key for a multi-organization implicit certificate provided in an embodiment of the present application;
[0047] Figure 5 A complete schematic diagram of the generation of implicit certificate public keys for a multi-organization single-declaration public key provided in an embodiment of the present application. DETAILED DESCRIPTION
[0048] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments.
[0049] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0050] In the description of this application, it should be noted that if the terms "upper", "lower", etc. appear, the orientation or position relationship indicated is based on the orientation or position relationship shown in the accompanying drawings, or is the orientation or position relationship in which the product of the application is usually placed when in use. It is only for the convenience of describing this application and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on this application.
[0051] In addition, the terms "first," "second," and the like in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.
[0052] It should be noted that, in the absence of conflict, the features in the embodiments of this application can be combined with each other.
[0053] Elliptic Curve Qu-Vanstone Implicit Certificate (ECQV) is a certificate authentication mechanism based on elliptic curves. It does not include the signature of the certificate issuing authority, and the verifier needs to calculate the public key of the implicit certificate owner based on the certificate data and perform cryptographic operations using the public key.
[0054] The current certificateless and implicit certificate public key generation scheme based on the elliptic curve cryptography algorithm SM2 includes the following steps: a single institution first generates the institution's master public-private key pair, the user generates a temporary user public-private key pair, and then the institution generates the user's declared public key and user private key components based on the user's identification information, the user's temporary public key, and the institution's master public-private key pair. The user generates the user's private key based on the temporary user private key and the user's private key components. The user calculates the user's public key based on the user's declared public key and the institution's master public key. This user public key is the public key for certificateless and implicit certificates. This scheme binds the generated user public key to the institution's public key to achieve a similar effect to a certificate. However, this scheme can only authenticate the user's identity by one institution, and cannot authenticate the user's identity by multiple institutions simultaneously. When a user requires authentication from multiple institutions, the existing scheme can only be adopted, with multiple institutions verifying the user's identity in sequence, resulting in low verification efficiency.
[0055] Therefore, an embodiment of the present application provides a method for generating implicit certificate public keys for multiple institutions, which binds the user public key of the target user with the master public keys of multiple trust institutions. The user end can simultaneously verify the authentication information of the target user by multiple trust institutions based on the user public key, thereby reducing the interactive process of multiple trust institutions authenticating the identity of the target user, and effectively meeting the needs of the target user for authentication by multiple trust institutions.
[0056] An embodiment of the present application also provides an implicit certificate public key system for executing the multi-institution implicit certificate public key generation method provided in the embodiment of the present application, wherein the implicit certificate public key system includes: a public key usage end, a user end, and an institution end of multiple trust institutions, wherein the public key usage end is used to generate a user public key of a target user according to the identifier of the target user, the master public keys of multiple trust institutions, and the user-declared public key during the public key usage phase; the user end is used to generate and disclose to the public key usage end the user-declared public key of the target user corresponding to the user end according to the declared public key components of the target user for multiple trust institutions and the temporary public key of the target user during the key declaration phase; the institution ends of multiple trust institutions are used to respectively generate master public-private key pairs of multiple trust institutions during the master key phase, and disclose the master public keys in the master public-private key pairs of multiple trust institutions to the public key usage end.
[0057] The following is a detailed explanation of the method for generating a multi-institution implicit certificate public key provided by the embodiment of the present application through specific examples in conjunction with the accompanying drawings. The method is applied to an implicit certificate public key system, which includes: a public key user end, a user end, and an institutional end of multiple trusted institutions. Figure 1 This is a schematic diagram of a method for generating a public key for an implicit certificate of multiple institutions provided in an embodiment of the present application. Figure 1 As shown, the method includes:
[0058] S101. In the master key phase, the institutional ends of multiple trust institutions respectively generate master public-private key pairs of multiple trust institutions, and disclose the master public keys in the master public-private key pairs of the multiple trust institutions to the public key user end.
[0059] S102. In the key declaration phase, the user terminal generates and discloses the user declaration public key corresponding to the target user to the public key user terminal based on the declared public key components of the target user by multiple trust institutions and the temporary public key of the target user.
[0060] S103. In the public key usage phase, the public key user generates a user public key of the target user based on the target user's identifier, the master public keys of multiple trust institutions, and the user's declared public key. The user public key of the target user is used to encrypt or verify the implicit certificate of the target user.
[0061] In this embodiment, the process of generating implicit certificate public keys for multiple organizations includes multiple phases: the master key phase, the declared key phase, and the public key usage phase. During the master key phase, the organizations of the multiple trusted organizations generate corresponding master public-private key pairs, then publish the master public key from the master public-private key pair and provide it to the public key usage end.
[0062] Optionally, the institutional ends of the multiple trust institutions generate master public keys of the multiple trust institutions based on the first random numbers generated by each of them.
[0063] The master public-private key pair of each trusted institution includes: the master public key of each trusted institution and a first random number.
[0064] Specifically, the institutional ends of multiple trusted institutions generate their own first random numbers respectively. If the number of multiple trusted institutions is k, the institutional ends of k trusted institutions generate their own first random numbers respectively expressed as: (ms1, ms2, ms3, ..., ms k ), and then generate the master public keys of multiple trust institutions based on the first random numbers generated by each of them. For example, the first random number generated by the institution end of the k-th trust institution is ms k , the generated master public key P PUBk Expressed as: P PUBk =[ms k ]G, where G is the base point of SM2.
[0065] Then we get the master public and private key pairs of k trusted institutions (ms1,P PUB1 ),...,(ms k ,P PUBk ), and the master public key (P PUB1 ,P PUB2 ,P PUB3 ,...,P PUBk ) is published to the public key user.
[0066] It should be noted that in the master key phase, the user generates a temporary public-private key pair (d' A ,U A ), where (d' A ,U A )=(Randd' A ,[d' A ]G), d' A is the temporary private key of the target user, U A The temporary public key of the target user.
[0067] In the key declaration phase, the user obtains the target user’s declared public key component W generated by multiple trust agencies. A1 ,...,W Ak , and combined with the temporary public key of the target user, generate the user-declared public key of the target user. Specifically, calculate the sum of the target user's declared public key component and the target user's temporary public key to determine the target user's user-declared public key W A , the user declares the public key expression as W A =U A +W A1 +...+W Ak , and make the user's declared public key public, and provide the user's declared public key to the public key user.
[0068] During the public key usage phase, the public key user generates the target user's user public key based on the target user's identifier, the master public keys of multiple trust institutions, and the user's declared public key. The target user's user public key is used to encrypt or verify the target user's implicit certificate. The target user's user public key is bound to the master public keys of multiple trust institutions, and the target user's implicit certificate public key is also obtained. It can be used to verify the signature through the target user's public key, and verify the authentication information of the target user by multiple trust institutions at one time.
[0069] In summary, an embodiment of the present application provides a method for generating a public key for an implicit certificate of multiple institutions, which is applied to an implicit certificate public key system. The method includes: in the master key stage, the institutional ends of multiple trust institutions respectively generate master public-private key pairs of multiple trust institutions, and disclose the master public keys in the master public-private key pairs of multiple trust institutions to the public key user end; in the declaration key stage, the user end generates and discloses the user declaration public key of the target user corresponding to the user end to the public key user end based on the declared public key components of the target user by multiple trust institutions and the temporary public key of the target user; in the public key use stage, the public key user end generates the user public key of the target user based on the identifier of the target user, the master public keys of multiple trust institutions and the user declaration public key; the user public key of the target user is used to encrypt or verify the implicit certificate of the target user. The method of the present application expands the implicit certificate public key system of a single institution to be used by multiple trust institutions, binds the user public key of the target user to the master public keys of multiple trust institutions, and the user end can simultaneously verify the authentication information of the target user by multiple trust institutions based on the user public key, thereby reducing the interactive process of multiple trust institutions authenticating the identity of the target user, and effectively meeting the needs of the target user for authentication by multiple trust institutions.
[0070] The present application embodiment also provides another possible implementation of the method for generating a public key of an implicit certificate of a multi-organization. Figure 1 , the method further comprises:
[0071] S201. In the key declaration phase, the user terminal sends a key declaration acquisition request of the target user to the institution terminal of each trusted institution.
[0072] S202. The institution end of each trust institution generates and returns to the user end a declared public key component of each trust institution for the target user based on the second random number generated by the trust institution.
[0073] In this embodiment, after receiving the target user's declared key acquisition request sent by the user end, each trust institution generates a second random number. For example, the second random numbers generated by the institution end of k trust institutions are represented as w1,...,w k , the institutional ends of the k trust institutions generate their own second random numbers w1,...,w k , generate k trusted institutions’ declared public key components W for the target user A1 ,...,W Ak , where W A1 =[w1]G,...,W Ak =[w k ]G. And return to the user side the declared public key components of k trusted institutions for the target user.
[0074] Continue to refer Figure 1 , the method further comprises:
[0075] S301. In the master key phase, the institutional ends of multiple trust institutions generate user public key parameters of the target user according to the identifier of the target user.
[0076] S302. In the key declaration phase, each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameters of the target user and the second random number of each trusted institution.
[0077] S303. In the private key usage phase, the user terminal generates a user private key of the target user based on the target user's identifier, the user private key components of the target user from multiple trust institutions, and the target user's temporary private key. The user private key of the target user is used to decrypt or sign the implicit certificate of the target user.
[0078] In this embodiment, in the master key phase, the institutional ends of multiple trust institutions further generate the target user's user public key parameters according to the target user's identifier. Then, in the key declaration phase, the institutional end of each trust institution generates the target user's user private key component according to the target user's user public key parameters and the second random number of each trust institution. For example, the user private key components generated by the institutional ends of k trust institutions are expressed as: A1 ,...,t Ak , then sum the generated user private key components and return the summed user private key components to the user end, that is, calculate t A =t A1 +...+t Ak , and t A Sent to the user end.
[0079] In the private key usage phase, the user side generates the target user's private key based on the target user's private key components from multiple trust institutions and the target user's temporary private key. The user private key generation expression is: A =t A +d' A modn. The target user's private key is used to decrypt or sign the target user's implicit certificate.
[0080] Optionally, during the private key usage phase, the user terminal generates a user public key of the target user based on the user private key of the target user.
[0081] Specifically, the user public key expression generated by the user end is: P A =[d A ]G.
[0082] The public key user can also generate the target user's user public key based on the target user's identification, the master public keys of multiple trust institutions, and the user's declared public key, and then compare it with the target user's user public key generated by the user end to determine whether they are consistent. If they are consistent, the verification is passed.
[0083] The present application embodiment also provides another possible implementation of a multi-organization implicit certificate public key generation method. Figure 2 A schematic diagram of another method for generating a public key for an implicit certificate of multiple institutions provided in an embodiment of the present application is shown as follows: Figure 2 As shown, in the master key phase, multiple trust institutions generate the target user's public key parameters based on the target user's identity, including:
[0084] S401. In the master key phase, the institutional ends of multiple trust institutions generate user public key parameters of their respective trust institutions for the target user based on the identifier of the target user and the master public key coordinates of their respective trust institutions.
[0085] In this embodiment, the k trust institutions generate their own trust institution user public key parameters for the target user, which are expressed as: H A1 =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x PUB1 ||y PUB1 ),...,H Ak =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x PUBk ||y PUBk ), where H Ak Represents the user public key parameter of the target user generated by the institution side of the k-th trust institution, H 256 () represents a digest function that outputs 256 bits, ID A Represents the identity of target user A, x G ,y G Expressed as the coordinates of the base point, x PUBk ,y PUBk Represented as the master public key coordinates of the k-th trusted authority.
[0086] Based on the above, in the key declaration phase, each trusted institution generates and returns to the user end the user private key component of each trusted institution for the target user based on the user public key parameters of the target user and the second random number of each trusted institution, including:
[0087] S402. In the key declaration phase, each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameters of each trusted institution for the target user and a second random number of each trusted institution.
[0088] Optionally, in the key declaration phase, the institutional end of each trust institution generates the user private key parameters of each trust institution for the target user based on the user public key parameters of each trust institution for the target user and the declared public key components of each trust institution for the target user.
[0089] Specifically, the institutional side of k trust institutions generates the user private key parameters of their respective trust institutions for the target user as follows:
[0090] λ1=H 256 (x WA1 ||y WA1 ||H A1 )mod n,...,λ k =H 256 (x WAk ||y WAk ||H Ak )mod n
[0091] Among them, λ k Represents the user private key parameter of the target user generated by the institution side of the k-th trust institution, H 256 () represents a summary function that outputs 256 bits, x WAk ,y WAk It is represented as the coordinates of the declared public key component of the k-th trusted authority for the target user.
[0092] The institution end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the user private key parameters of each trust institution for the target user and the second random number of each trust institution.
[0093] Specifically, the institutional ends of the k trust institutions further generate a user private key component for the target user based on the first random number of each trust institution, and the user private key component t A1 ,...,t Ak Respectively expressed as:
[0094] t A1 =w1+λ1·ms1modn,...,t Ak =w k +λ k ·ms k modn
[0095] Among them, tAk It represents the user private key component for the target user generated by the institution side of the k-th trust institution, w k Represented as the second random number of the k-th trust institution, ms k Denoted as the first random number of the k-th trusted authority.
[0096] Optionally, continue to refer to Figure 2 , the method further comprises:
[0097] S501: In the key declaration phase, the user terminal also discloses the declared public key components of multiple trust institutions for the target user to the public key user terminal.
[0098] Based on the above, in the public key usage phase, the public key user generates the target user's user public key based on the target user's identifier, the master public keys of multiple trusted institutions, and the user's declared public key, including:
[0099] S502. In the public key usage phase, the public key usage terminal generates a user public key of the target user based on the target user's identifier, the master public keys of multiple trust institutions, the user's declared public key, and the declared public key components of multiple trust institutions for the target user.
[0100] Specifically, the public key user first calculates the user private key parameters λ1,...,λ of each trust institution for the target user based on the target user's identifier, the master public keys of multiple trust institutions, and the declared public key components of multiple trust institutions for the target user. k , the expression is as follows:
[0101] λ1=H 256 (x WA1 ||y WA1 ||H A1 )modn,...λ k =H 256 (x WAk ||y WAk ||H Ak )modn,
[0102] in:
[0103] H A1 =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x PUB1 ||y PUB1 ), ...
[0105] H Ak =H 256 (ENTLA ||ID A ||a||b||x G ||y G ||x PUBk ||y PUBk ).
[0106] Then, the public key user generates the target user's public key based on the master public keys of multiple trust institutions, the user's declared public key, and the user private key parameters of each trust institution for the target user. The calculation formula is as follows:
[0107] P A =W A +[λ1]P PUB1 +...+[λ k ]P PUBk .
[0108] The public key user uses the target user's ID A , the master public key of multiple trust institutions (P PUB1 ,P PUB2 ,P PUB3 ,...,P PUBk ), user declares public key W A And multiple trusted institutions for the target user's declared public key component W A1 ,...,W Ak , can generate the target user's public key P A .
[0109] It should be noted that the user public key expression generated by the user end is: P A =[d A ]G, the public key user can compare it with the target user's public key generated by the user end to determine whether they are consistent. If they are consistent, the verification is passed. Specifically, the comparison method is as follows:
[0110] [d A ]G=(t A +d' A )·G
[0111] =(t A1 +...+t Ak )·G+d' A ·G
[0112] =(w1+λ1·ms1+...+w k +λ k ·ms k )·G+U A
[0113] =(w1+...+w k)·G+(λ1·ms1+...+λ k ·ms k )*G+U A
[0114] =(w1·G+...+w k ·G)+(λ1·ms1·G+...+λ k ·ms k ·G)+U A
[0115] =W A1 +...+W Ak +(λ1·P PUB1 +...+λ k ·P PUBk )+U A
[0116] =W A +λ1·P PUB1 +...+λ k ·P PUBk
[0117] =P A
[0118] Figure 3 A complete schematic diagram of the generation of implicit certificate public keys for multiple organizations and multiple declaration public keys provided in the embodiment of this application is as follows: Figure 3 As shown in the master key phase, the institutional ends of k trust institutions generate the master public-private key pairs (ms1, P PUB1 ),...,(ms k ,P PUBk ), and based on the target user's ID A and the master public key coordinates of each trust institution, and generate the user public key parameters (H A1 ,H A2 ,...,H Ak ), and then the master public key of k trusted institutions (P PUB1 ,P PUB2 ,P PUB3 ,...,P PUBk ) is published to the public key user. At the same time, in the master key phase, the user generates a temporary public-private key pair (d' A ,U A ).
[0119] In the key declaration phase, the second random numbers generated by the k trusted institutions are represented as w1,...,w kThen, based on the second random number generated by each, k trust institutions generate the declared public key component W for the target user A1 ,...,W Ak , where W A1 =[w1]G,...,W Ak =[w k ]G. And return the declared public key components of k trust institutions for the target user to the user end, and then the user end calculates the declared public key components W of k trust institutions for the target user. A1 ,...,W Ak And the target user's temporary public key U A , generate the user-declared public key W corresponding to the target user on the user side A , the user declares the public key expression as W A =U A +W A1 +...+W Ak , and the user's declared public key W A And multiple trusted institutions for the target user's declared public key component W A1 ,...,W Ak Public, providing the user's declared public key W to the public key user A And multiple trusted institutions for the target user's declared public key component W A1 ,...,W Ak .
[0120] In the public key usage phase, the public key user uses the target user's ID A , the master public key of multiple trust institutions (P PUB1 ,P PUB2 ,P PUB3 ,...,P PUBk ), user declares public key W A And multiple trusted institutions for the target user's declared public key component W A1 ,...,W Ak , can generate the target user's public key P A , the public key using end generates the target user's public key as: P A =W A +[λ1]P PUB1 +...+[λ k ]P PUBk , used to encrypt or verify the implicit certificate of the target user.
[0121] In addition, in the key declaration phase, the k trust institutions’ institutional ends use the public key parameters (H A1 ,H A2 ,...,H Ak) and the declared public key component W of each trust institution for the target user A1 ,...,W Ak , generate the user private key parameters λ1,...,λ of each trust institution for the target user k Respectively expressed as:
[0122] λ1=H 256 (x WA1 ||y WA1 ||H A1 )mod n,...,λ k =H 256 (x WAk ||y WAk ||H Ak )mod n
[0123] Then, the institutional side of k trust institutions uses the user private key parameters λ1,...,λ k , the second random number w1,...,w of each trust institution k , and the first random number ms1,...,ms of each trust institution k , generate the user private key component t for the target user A1 ,...,t Ak Respectively expressed as:
[0124] t A1 =w1+λ1·ms1 mod n,...,t Ak =w k +λ k ·ms k mod n
[0125] The generated user private key component t A1 ,...,t Ak Sum the user's private key components and return them to the user, that is, calculate t A =t A1 +...+t Ak , and t A Sent to the user end.
[0126] In the private key usage phase, the user end uses the private key components of the target user according to the k trust institutions and the temporary private key d' of the target user. A , generate the target user's private key d A , the user private key generation expression is: d A =t A +d' Amod n. The target user's private key is used to decrypt or sign the target user's implicit certificate. The user end can also generate the target user's public key based on the target user's private key. The expression for generating the target user's public key by the user end is: P A =[d A ]G.
[0127] The present application embodiment also provides another possible implementation of a multi-organization implicit certificate public key generation method. Figure 4 A schematic diagram of another method for generating a public key for an implicit certificate of multiple institutions provided in an embodiment of the present application is shown as follows: Figure 4 As shown, in the master key phase, multiple trust institutions generate the target user's public key parameters based on the target user's identity, including:
[0128] S601. In the master key phase, the institutional ends of multiple trust institutions generate common user public key parameters of the target user based on the identifier of the target user and the master public key coordinates of all trust institutions.
[0129] In this embodiment, the common user public key parameters generated by the k trust institutions for the target user are expressed as: H A =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x PUB1 ||y PUB1 ||...||x PUBk ||y PUBk ), where H A H represents the common public key parameter of the target user generated by the institution side of k trust institutions, 256 () represents a digest function that outputs 256 bits, ID A Represents the identity of target user A, x G ,y G Expressed as the coordinates of the base point, x PUBk ,y PUBk Represented as the master public key coordinates of the k-th trusted authority.
[0130] Based on the above, in the key declaration phase, each trusted institution generates and returns to the user end the user private key component of each trusted institution for the target user based on the user public key parameters of the target user and the second random number of each trusted institution, including:
[0131] S602. In the key declaration phase, each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the common user public key parameters of the target user and the second random number of each trusted institution.
[0132] Optionally, in the key declaration phase, the institutional end of each trust institution generates common user private key parameters for the target user based on the common user public key parameters of the target user and the user's declared public key.
[0133] Specifically, the institutional side of k trust institutions generates the user private key parameter of their respective trust institutions for the target user, which is expressed as: λ = H 256 (x WA ||y WA ||H A )modn, where λ represents the common user private key parameter of the target user generated by the institution side of k trust institutions, and H 256 () represents a summary function that outputs 256 bits, x WA ,y WA Indicates the coordinates of the public key declared for the user.
[0134] The institution end of each trusted institution generates and returns to the user end the user private key component of each trusted institution for the target user based on the common user private key parameter and the second random number of each trusted institution.
[0135] Specifically, the institutional ends of the k trust institutions further generate a user private key component for the target user based on the first random number of each trust institution, and the user private key component t A1 ,...,t Ak Respectively expressed as:
[0136] t A1 =w1+λ·ms1modn,...,t Ak =w k +λ·ms k modn
[0137] Among them, t Ak It represents the user private key component for the target user generated by the institution side of the k-th trust institution, w k Represented as the second random number of the k-th trust institution, ms k Denoted as the first random number of the k-th trusted authority.
[0138] It should be noted that, during the public key usage phase, the public key user generates the target user's user public key based on the target user's identifier, the master public keys of multiple trust institutions, and the user's declared public key.
[0139] Specifically, the public key user first calculates the common user private key parameter λ for the target user based on the target user's identifier, the master public keys of multiple trusted institutions, and the user's declared public key. The expression is as follows:
[0140] λ=H 256 (x WA ||y WA ||H A )modn
[0141] Among them, H A =H 256 (ENTL A ||ID A ||a||b||x G ||y G ||x PUB1 ||y PUB1 ||...||x PUBk ||y PUBk ).
[0142] Then, the public key user generates the target user's user public key based on the master public keys of multiple trust institutions, the user's declared public key, and the common user private key parameters for the target user. The calculation formula is as follows:
[0143] P A =W A +[λ]P PUB
[0144] Among them, P PUB =P PUB1 +...+P PUBk .
[0145] The public key user uses the target user's ID A , the master public key of multiple trust institutions (P PUB1 ,P PUB2 ,P PUB3 ,...,P PUBk ), user declares public key W A , generate the target user's public key P A .
[0146] It should be noted that the user public key expression generated by the user end is: P A =[d A ]G, the public key user can compare it with the target user's public key generated by the user end to determine whether they are consistent. If they are consistent, the verification is passed. Specifically, the comparison method is as follows:
[0147] [d A ]G=(t A +d' A )·G
[0148] =(t A1 +...+t Ak )·G+d' A ·G
[0149] =(w1+λ·ms1+...+w k +λ·ms k )·G+U A
[0150] =(w1+...+w k )·G+λ·(ms1+...+ms k )*G+U A
[0151] =(w1·G+...+w k ·G)+λ·(ms1·G+...+ms k ·G)+U A
[0152] =W A1 +...+W Ak +λ·(P PUB1 +...+P PUBk )+U A
[0153] =(W A1 +...+W Ak +U A )+λ·P PUB
[0154] =W A +λ·P PUB
[0155] =P A
[0156] Figure 5 A complete schematic diagram of the generation of implicit certificate public key for a multi-organization single declaration public key provided in the embodiment of this application is as follows: Figure 5 As shown in the master key phase, the institutional ends of k trust institutions generate the master public-private key pairs (ms1, P PUB1 ),...,(ms k ,P PUBk ), and based on the target user's ID A and the master public key coordinates of each trusted institution to generate the common user public key parameters H of the target user A , and then the master public key of k trusted institutions (P PUB1 ,P PUB2 ,P PUB3 ,...,PPUBk ) and P PUB =P PUB1 +...+P PUBk , get the master public key P PUB , and published to the public key user. At the same time, in the master key phase, the user generates a temporary public-private key pair (d' A ,U A ).
[0157] In the key declaration phase, the second random numbers generated by the k trusted institutions are represented as w1,...,w k Then, based on the second random number generated by each, k trust institutions generate the declared public key component W for the target user A1 ,...,W Ak , where W A1 =[w1]G,...,W Ak =[w k ]G. And return the declared public key components of k trust institutions for the target user to the user end, and then the user end calculates the declared public key components W of k trust institutions for the target user. A1 ,...,W Ak And the target user's temporary public key U A , generate the user-declared public key W corresponding to the target user on the user side A , the user declares the public key expression as W A =U A +W A1 +...+W Ak , and the user's declared public key W A Public, providing the user's declared public key W to the public key user A .
[0158] In the public key usage phase, the public key user uses the target user's ID A , the master public key P of multiple trust institutions PUB , user declares public key W A , can generate the target user's public key P A , the public key using end generates the target user's public key as: P A =W A +[λ]P PUB , used to encrypt or verify the implicit certificate of the target user.
[0159] In addition, in the key declaration phase, the institutional side of k trust institutions uses the common user public key parameter H for the target user. A And the user's declared public key W A , generate the common user private key parameter λ for the target user as: λ=H256 (x WA ||y WA ||H A )mod n.
[0160] Then, according to the common user private key parameter λ for the target user, the second random numbers w1,...,w k , and the first random number ms1,...,ms of each trust institution k , generate the user private key component t for the target user A1 ,...,t Ak Respectively expressed as:
[0161] t A1 =w1+λ·ms1 mod n,...,t Ak =w k +λ·ms k mod n
[0162] The generated user private key component t A1 ,...,t Ak Sum the user's private key components and return them to the user, that is, calculate t A =t A1 +...+t Ak , and t A Sent to the user end.
[0163] In the private key usage phase, the user end uses the private key components of the target user according to the k trust institutions and the temporary private key d' of the target user. A , generate the target user's private key d A , the user private key generation expression is: d A =t A +d' A mod n. The target user's private key is used to decrypt or sign the target user's implicit certificate. The user end can also generate the target user's public key based on the target user's private key. The expression for generating the target user's public key by the user end is: P A =[d A ]G.
[0164] The above are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A method for generating a public key for an implicit certificate of multiple institutions, characterized in that: Applied to an implicit certificate public key system, the implicit certificate public key system includes: a public key user end, a user end, and an institution end of multiple trust institutions, the method includes: In the master key phase, the institutional ends of the multiple trusted institutions respectively generate master public-private key pairs of the multiple trusted institutions, and disclose the master public keys in the master public-private key pairs of the multiple trusted institutions to the public key user end; In the key declaration phase, the user terminal generates a user declaration public key corresponding to the target user of the user terminal based on the declared public key components of the multiple trust institutions for the target user and the temporary public key of the target user, and discloses the user declaration public key of the user terminal to the public key user terminal; During the public key usage phase, the public key usage end generates the user public key of the target user based on the identifier of the target user, the master public keys of the multiple trust institutions, and the user-declared public key. The user public key of the target user is used to encrypt or verify the implicit certificate of the target user.
2. The method according to claim 1, characterized in that The institutional ends of the multiple trusted institutions respectively generate master public and private key pairs of the multiple trusted institutions, including: The institutional ends of the multiple trust institutions generate the master public keys of the multiple trust institutions based on the first random numbers generated by each of them, wherein the master public-private key pair of each trust institution includes: the master public key of each trust institution and the first random number.
3. The method according to claim 1, characterized in that The method further comprises: In the key declaration phase, the user terminal sends a request for obtaining the target user's key declaration to the institution terminal of each trusted institution; The institution end of each trust institution generates, based on the second random number generated by each trust institution, and returns to the user end a declared public key component of each trust institution for the target user.
4. The method according to claim 3, characterized in that The method further comprises: In the master key phase, the institution ends of the multiple trust institutions generate user public key parameters of the target user according to the identifier of the target user; In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution; During the private key usage phase, the user terminal generates a user private key of the target user based on the user private key components of the target user from the multiple trust institutions and the temporary private key of the target user. The user private key of the target user is used to decrypt or sign the implicit certificate of the target user.
5. The method according to claim 4, characterized in that In the master key phase, the institutional end of the multiple trust institutions generates the user public key parameters of the target user according to the identifier of the target user, including: In the master key phase, the institution ends of the multiple trust institutions respectively generate user public key parameters of their respective trust institutions for the target user according to the identifier of the target user and the master public key coordinates of their respective trust institutions; In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution, including: In the key declaration phase, the institutional end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the user public key parameters of the respective trust institution for the target user and the second random number of each trust institution.
6. The method according to claim 5, characterized in that In the key declaration phase, the institution end of each trusted institution generates and returns to the user end the user private key component of each trusted institution for the target user based on the user public key parameter of the respective trusted institution for the target user and the second random number of each trusted institution, including: In the key declaration phase, the institution end of each trust institution generates the user private key parameters of the respective trust institution for the target user based on the user public key parameters of the respective trust institution for the target user and the declared public key components of the respective trust institutions for the target user; The institution end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the user private key parameters of the respective trust institution for the target user and the second random number of each trust institution.
7. The method according to claim 4, characterized in that In the master key phase, the institutional end of the multiple trust institutions generates the user public key parameters of the target user according to the identifier of the target user, including: In the master key phase, the institution ends of the multiple trusted institutions generate common user public key parameters of the target user based on the identifier of the target user and the master public key coordinates of all trusted institutions; In the key declaration phase, the institution end of each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the user public key parameter of the target user and the second random number of each trusted institution, including: In the key declaration phase, the institution end of each trust institution generates and returns to the user end the user private key component of each trust institution for the target user based on the common user public key parameters of the target user and the second random number of each trust institution.
8. The method according to claim 7, characterized in that In the key declaration phase, each trusted institution generates and returns to the user end a user private key component of each trusted institution for the target user based on the common user public key parameter of the target user and the second random number of each trusted institution, including: In the key declaration phase, the institution end of each trust institution generates a common user private key parameter for the target user based on the common user public key parameter of the target user and the user declared public key; The institution end of each trusted institution generates, based on the common user private key parameter and the second random number of each trusted institution, a user private key component of each trusted institution for the target user and returns it to the user end.
9. The method according to claim 1, characterized in that The method further comprises: In the key declaration phase, the user terminal further discloses the declared public key components of the multiple trusted institutions for the target user to the public key user terminal; In the public key usage phase, the public key usage terminal generates a user public key of the target user according to the identifier of the target user, the master public keys of the multiple trust institutions, and the user-declared public key, including: During the public key usage phase, the public key usage end generates a user public key of the target user based on the identifier of the target user, the master public keys of the multiple trust institutions, the user declared public key, and the declared public key components of the multiple trust institutions for the target user.
10. The method according to claim 4, characterized in that The method further comprises: During the private key usage phase, the user terminal generates a user public key of the target user based on the user private key of the target user.
Citation Information
Patent Citations
Implicitly certified public keys
CN103765809A
Generating implicit certificates
EP2582085A1